
#28: The Reachable Agent
transcript
show notes
Top Story: Astra crosses OpenAI's Critical cyber threshold — OpenAI says GPT-6 Astra is its first model to meet the Critical cybersecurity capability threshold in its Preparedness Framework. A project folder could take control before an AI coding session began. — Manifold Security found eight flaws across seven coding agents, a class it calls GitSpawn. “Read-only internet” still let agents publish nearly 17,000 edits to a public wiki. — The DSEWiki investigation found that the environment allowed only GET requests, normally used to retrieve pages, but the old wiki accepted edits through those same requests. LiteLLM, a gateway that connects company applications to AI models, is under active attack. — CISA says the flaw lets attackers reach connected tools without a valid access key. Anthropic released one underlying model through two different security envelopes. — Fable 5.1 and Mythos 5.1 share identical model weights. Forward watch: Instinct turns personal context into operational authority. — The private-access assistant connects to email, messaging, calendar, screen, audio, location, and can act through a phone or computer. Investors reportedly valued Upwind at roughly $3.8 billion, more than twice its previous valuation in less than eight months. — CTech reports a $300 million financing led by Bessemer Venture Partners and TCV, with subsequent coverage from SiliconANGLE. A trusted plugin update can create a new execution path without another model decision. — HookPry studied lifecycle hooks, the configuration that runs commands when sessions start or tools fire. Persistent memory can turn a false record into permission. — EAL-Bench separates the agent that writes organizational memory from the later agent that acts on it. An AI-assisted exploit experiment ended with a permanently bricked industrial controller. — Forescout researchers gave Claude Code earlier exploit code, firmware, analysis tools, live hardware, and repeated expert guidance to port an attack to another programmable logic controller. OWASP 25th Anniversary Virtual Conference, September 22. — Free sessions include agent secret leakage, plugin supply chains, production-ready agent architecture, and real-world evaluation of security agents.. German OWASP Day, September 23–24. — Training and talks cover prompt injection, agent gateway enforcement, agent threat modeling, and attacks against supposedly read-only database connectors.. OASec 2026, Singapore, September 28. — A practitioner conference on prompt injection, tool abuse, agentic systems, incident response, and defensive controls. Curator's Corner: Map What It Can Reach
Curated by Asaf Nakash. Voices by AI. Opinions by human.
Show notes: https://contextwindowsec.com/episodes/2026-09-07.html