Friday is about blast radius and who you let in. The scariest bug this week wasn't clever: an agent could reach a metadata endpoint, and its default role could do far too much. The rest of the day is the same question from the other side. Anthropic wants to scan your open-source repo for free, Mistral wants you to own the weights, and Google wants your product to be a tool its agent can call.
No sponsored or affiliate links in this digest — the links below are sources only.
Story I
AgentCorruption: one prompt to one public AgentCore agent was enough to take over every agent in the region
Zenity Labs published the full chain on Thursday. Agents on Amazon Bedrock AgentCore run in Firecracker microVMs that, per Zenity, lacked enough network isolation to keep them away from the instance metadata service at 169.254.169.254. So anyone with chat access to one exposed agent could prompt-inject it into fetching its own IMDS credentials. Then the second problem kicked in: the default execution role was scoped region-wide and included bedrock-agentcore:InvokeAgentRuntime, bedrock-agentcore:ListEvents, bedrock-agentcore:GetResourceApiKey and secretsmanager:GetSecretValue. That's other agents, their private conversations and the API keys and OAuth tokens AgentCore tells you to keep in Secrets Manager.
The timeline is the part worth reading. Zenity reported the IMDS issue on December 25, 2025. AgentCore moved to IMDSv2-only for new agents on February 14, and AWS closed the first report as "informative" in April. Zenity says the default role was still unchanged in June, and only on September 29 did it see AWS strip cross-agent invocation, conversation reading and Secrets Manager access. The Decoder reports AWS has patched the issue and "significantly tightened" default permissions. Neither source says whether agents deployed before that change had their roles rewritten.
For builders
Don't assume the fix reached you. Open IAM, find every role attached to an AgentCore runtime, and look for secretsmanager:GetSecretValue, GetResourceApiKey or InvokeAgentRuntime on Resource: "*". Scope each one to that agent's own secret ARNs, or drop it. Redeploy anything created before February so it gets IMDSv2. And for every agent with a public chat surface, write down what a fully hijacked version of it could touch. If that list is longer than one line, split the role.
Story II
Anthropic opens OSS Scanner: free, periodic, model-written vulnerability reports for critical open-source projects
Anthropic launched OSS Scanner, an opt-in service that gives eligible open-source projects "thorough, periodic security scans by our strongest models at no cost," including Claude Mythos. Eligibility borrows from OSS-Fuzz: projects with a critical impact on infrastructure and user security, decided case by case. Core maintainers enroll by opening a PR against anthropics/oss-scanner on GitHub. The reports are fully model-generated with no human review or triage, which Anthropic says plainly means some will be wrong. Human-verified findings still go through its normal coordinated disclosure process.
Anthropic's own numbers from the pilot explain why it's skipping the humans: more than 29,000 candidate vulnerabilities, about 6,000 manually triaged, and 97 critical or high-severity bugs validated across 48 projects (85 went to disclosure, 11 were real duplicates, 1 was invalid). The Verge points out the timing. Maintainers, Linus Torvalds among them, have been complaining about the flood of AI-generated bug reports, and Google recently paused an open-source bug bounty over AI slop.
For builders
If you maintain something people depend on, enroll, but decide your triage rules first. Add a SECURITY.md line saying model-generated reports are handled in a separate queue, set a label for them, and give each one a 15-minute reproduction check before it gets a human reply. A report you can't reproduce in that window gets closed with a note, not a debate. That keeps the 97 real bugs from drowning in the rest.
Story III
Mistral Large 4 "Le Chonk": 1 trillion parameters, 49 billion active, open weights promised by the end of October
Mistral put Large 4 into public preview on October 6 through the API in Mistral Studio. AlternativeTo lists it as a mixture-of-experts model with 1 trillion total and 49 billion active parameters, natively multimodal, at $1.36 per million input tokens and $4.18 per million output. Full weights are due by the end of the month; until then Mistral is red-teaming it with vetted partners and state authorities who get expanded cyber capabilities. The license for the final weights isn't stated in the coverage we read.
Mistral says it trained the model from scratch and tuned it for coding and cyberdefense plus niches like manufacturing, finance and electrical engineering. Its pitch, per WIRED via Ars Technica, is less about benchmarks than control. "If you use a closed model, there is no guarantee it will still be there tomorrow," cofounder Guillaume Lample said, pointing at US restrictions on frontier model distribution this year. Mistral publishes no head-to-head numbers in either piece, so treat "very, very close" to proprietary models as a claim until independent evals land.
For builders
Run your own eval on the preview this week, while it's cheap to find out. Take 50 real prompts from your hardest workload, run them against Large 4 and your current model through the API, and log cost per task, not per token. If it holds up, start sizing the self-host now: at 49B active and 1T total, you need the memory for the whole trillion even if compute only touches a fraction. Know that answer before the weights drop, not after.
Story IV
Google's Gemini agent takes objectives, delegates to subagents, and works with any MCP server, starting with businesses
At a Google Cloud event on Thursday, Google announced a single Gemini agent for businesses, with consumers later. Thomas Kurian said it takes "objectives, not just instructions": it plans, loads custom skills, calls tools, and hands work to subagents. It connects to Workspace, Microsoft 365, Slack, Jira, Confluence, Git, BigQuery, Databricks, Postgres and Snowflake, and works with any Model Context Protocol server inside or outside a company network, per TechCrunch. It picks a model by default, but users can choose third-party ones, starting with Anthropic's Claude.
Two design choices stand out. The agent gets its own Workspace account and email address, and audit trails are written under the agent's name rather than a person's. And there's a tasks inbox showing its reasoning, delegation, loaded skills and code. Google also mentioned real-time spend caps and smart routing for cost control. TechCrunch gives no price and no general availability date.
For builders
If your product sells to companies on Workspace or Microsoft 365, the shortest path into this agent is an MCP server. Ship a read-only one first: three or four tools that answer the questions customers already email you about, authenticated per user, with no write actions. Log every call with the caller identity, because with the agent holding its own account, your logs will be the only place that ties an action back to a person.
— The Vibe Gate news desk. We read the firehose so you can keep building.