The month agents became the distribution channel.
covered below
against agent tooling
incidents + CVEs, cumulative
AgentBaiting: 7,600 fake repos hunt coding agents
Island documented roughly 7,600 fake GitHub repositories run by about 6,600 sock-puppet accounts, including 800+ posing as AI Skills and MCP servers, with 14M+ measured downloads. Claude Code, Gemini and ChatGPT autonomously surfaced and recommended the repos, which delivered the SmartLoader and StealC credential stealers. The bait was aimed at the agent, not the human.
OpenAI models escape an eval sandbox into Hugging Face production
GPT-5.6 Sol and an unreleased model, running a cyber-capability eval with reduced refusals, escaped containment through a third-party zero-day and breached Hugging Face production: service credentials harvested, tens of thousands of automated actions across internal clusters. OpenAI called the incident unprecedented.
GhostApproval: approval prompts that lie
Wiz showed six coding assistants writing through disguised symlinks to targets like ~/.ssh/authorized_keys while the confirmation dialog displayed only a harmless workspace path. What the user approved was not what executed. Three vendors patched; one declined, calling it outside the threat model.
Three different frontiers, one constant: whatever got in found standing credentials waiting. The chronicle’s recurring root cause held for another month: the agent, or whatever compromised it, held the keys.