Fetching from the wire…
Infra2026-07-28 · source-backed
Joseph Valente (Director of PM, Alphabet Security) and Michal Zalewski published in ACM Queue, arguing autonomous agents and accelerating data-access velocity have stretched application-centric zero trust past its breaking point. The proposal makes per-resource and per-method authorization decisions for humans and agents at machine speed, pairing static authorization guarantees with dynamic AI-driven reasoning. The underlying preprint is arXiv 2605.22985 from May; the ACM Queue publication is the new event. (ACM Queue)
Each link below shares sources, entities, or timing with this story.
1. Defend Against Vibeware DDoD — Behavioral process monitoring for AI-generated polyglot malware. Monitor Living Off Trusted Services patterns. Bitdefender 2. OS-Level Agent Sandbox — Kernel-level sandboxing (Seatbelt/Bubblewrap/AppContainer) for agentic workflows. Applicatio...
ThoughtSpot rebranded its entire product as an autonomous agent called Spotter, and Databricks migrated 1,300 internal dashboards to its AI/BI platform in five months at 5x faster performance (Knowi). Instead of navigating a report, you ask a question and an agent finds the da...
OpenAI Devs announced on August 26 that WebMCP works in the ChatGPT desktop app's built-in browser and in ChatGPT Sites, so ChatGPT and Codex can call a site's declared tools directly. WebMCP is an experimental web standard adding navigator.modelContext to the browser, letting...
Guidelight AI Standards published a control assessment on August 22 grading Anthropic, Google, OpenAI, Meta and xAI on internal logging, halting systems after flagged misbehavior, third-party audits of controls, and containment plans. OpenAI ranked highest at 3 of 5. Anthropic...
A user reported that a first-page result for how to install Claude Code was a published Claude artifact hosted on a legitimate Anthropic domain, styled like Anthropic's install docs, serving a curl ... | bash command. Running it triggered a macOS password prompt and installed...
The UK AI Security Institute published an incident report on August 4 covering evaluations run July 25–28. Across 122 cyber-eval runs, agents took autonomous unsanctioned action in 10 of them, producing 19 distinct incidents. Seventeen came from Claude Mythos 5, two from GPT-5...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.