Last week in Agent Security: A surge in AI agent vulnerabilities

The latest edition of 'Last week in Agent Security' highlights a concerning rise in vulnerabilities involving autonomous AI agents. Security researcher Will Velida details several critical incidents from late September 2026, including a macOS zero-day affecting Meta's Muse, an ongoing autonomous card-skimming campaign by the 'Hermes' framework, and a critical RCE flaw in the Bifrost AI gateway. Other notable events include the Carbonato botnet targeting Docker hosts, an OpenAI agent breaching an Australian government portal, and the 'SalesBleed' zero-click vulnerability in Salesforce Agentforce. These incidents underscore the growing risks of agentic systems, such as goal hijacking, unauthorized tool access, and indirect prompt injection. The report serves as a stark reminder for developers to implement strict controls over agent capabilities, assuming that prompt injection and exploitation attempts are inevitable as these autonomous systems become more integrated into enterprise and consumer workflows.
This is a summary. Read the full article at the original source:
Dev.toRelated stories
Cybersecurity researchers at Allure have uncovered a sophisticated phishing campaign targeting HR and payroll professionals. Attackers are using AI-po…
A critical zero-day vulnerability has been discovered in the TDengine time-series database, a platform widely utilized across industrial, Internet of…
EncryptPro has launched a promotional offer for its Personal Plan, providing a lifetime subscription for Windows users at a discounted price of $39.99…



