← All digests
✦ AI News for Builders

One prompt to one exposed agent took over every Bedrock AgentCore agent in an AWS region, Anthropic opens free model-run security scans for open source, Mistral previews a 1-trillion-parameter open-weight model, and Google's new Gemini agent plugs into any MCP server

Friday, October 9, 2026·8 min read·4 stories

Friday is about blast radius and who you let in. The scariest bug this week wasn't clever: an agent could reach a metadata endpoint, and its default role could do far too much. The rest of the day is the same question from the other side. Anthropic wants to scan your open-source repo for free, Mistral wants you to own the weights, and Google wants your product to be a tool its agent can call.

Story I

AgentCorruption: one prompt to one public AgentCore agent was enough to take over every agent in the region

Zenity Labs published the full chain on Thursday. Agents on Amazon Bedrock AgentCore run in Firecracker microVMs that, per Zenity, lacked enough network isolation to keep them away from the instance metadata service at 169.254.169.254. So anyone with chat access to one exposed agent could prompt-inject it into fetching its own IMDS credentials. Then the second problem kicked in: the default execution role was scoped region-wide and included bedrock-agentcore:InvokeAgentRuntime, bedrock-agentcore:ListEvents, bedrock-agentcore:GetResourceApiKey and secretsmanager:GetSecretValue. That's other agents, their private conversations and the API keys and OAuth tokens AgentCore tells you to keep in Secrets Manager.

The timeline is the part worth reading. Zenity reported the IMDS issue on December 25, 2025. AgentCore moved to IMDSv2-only for new agents on February 14, and AWS closed the first report as "informative" in April. Zenity says the default role was still unchanged in June, and only on September 29 did it see AWS strip cross-agent invocation, conversation reading and Secrets Manager access. The Decoder reports AWS has patched the issue and "significantly tightened" default permissions. Neither source says whether agents deployed before that change had their roles rewritten.

For builders

Don't assume the fix reached you. Open IAM, find every role attached to an AgentCore runtime, and look for secretsmanager:GetSecretValue, GetResourceApiKey or InvokeAgentRuntime on Resource: "*". Scope each one to that agent's own secret ARNs, or drop it. Redeploy anything created before February so it gets IMDSv2. And for every agent with a public chat surface, write down what a fully hijacked version of it could touch. If that list is longer than one line, split the role.

Story II

Anthropic opens OSS Scanner: free, periodic, model-written vulnerability reports for critical open-source projects

Anthropic launched OSS Scanner, an opt-in service that gives eligible open-source projects "thorough, periodic security scans by our strongest models at no cost," including Claude Mythos. Eligibility borrows from OSS-Fuzz: projects with a critical impact on infrastructure and user security, decided case by case. Core maintainers enroll by opening a PR against anthropics/oss-scanner on GitHub. The reports are fully model-generated with no human review or triage, which Anthropic says plainly means some will be wrong. Human-verified findings still go through its normal coordinated disclosure process.

Anthropic's own numbers from the pilot explain why it's skipping the humans: more than 29,000 candidate vulnerabilities, about 6,000 manually triaged, and 97 critical or high-severity bugs validated across 48 projects (85 went to disclosure, 11 were real duplicates, 1 was invalid). The Verge points out the timing. Maintainers, Linus Torvalds among them, have been complaining about the flood of AI-generated bug reports, and Google recently paused an open-source bug bounty over AI slop.

For builders

If you maintain something people depend on, enroll, but decide your triage rules first. Add a SECURITY.md line saying model-generated reports are handled in a separate queue, set a label for them, and give each one a 15-minute reproduction check before it gets a human reply. A report you can't reproduce in that window gets closed with a note, not a debate. That keeps the 97 real bugs from drowning in the rest.

Story III

Mistral Large 4 "Le Chonk": 1 trillion parameters, 49 billion active, open weights promised by the end of October

Mistral put Large 4 into public preview on October 6 through the API in Mistral Studio. AlternativeTo lists it as a mixture-of-experts model with 1 trillion total and 49 billion active parameters, natively multimodal, at $1.36 per million input tokens and $4.18 per million output. Full weights are due by the end of the month; until then Mistral is red-teaming it with vetted partners and state authorities who get expanded cyber capabilities. The license for the final weights isn't stated in the coverage we read.

Mistral says it trained the model from scratch and tuned it for coding and cyberdefense plus niches like manufacturing, finance and electrical engineering. Its pitch, per WIRED via Ars Technica, is less about benchmarks than control. "If you use a closed model, there is no guarantee it will still be there tomorrow," cofounder Guillaume Lample said, pointing at US restrictions on frontier model distribution this year. Mistral publishes no head-to-head numbers in either piece, so treat "very, very close" to proprietary models as a claim until independent evals land.

For builders

Run your own eval on the preview this week, while it's cheap to find out. Take 50 real prompts from your hardest workload, run them against Large 4 and your current model through the API, and log cost per task, not per token. If it holds up, start sizing the self-host now: at 49B active and 1T total, you need the memory for the whole trillion even if compute only touches a fraction. Know that answer before the weights drop, not after.

Story IV

Google's Gemini agent takes objectives, delegates to subagents, and works with any MCP server, starting with businesses

At a Google Cloud event on Thursday, Google announced a single Gemini agent for businesses, with consumers later. Thomas Kurian said it takes "objectives, not just instructions": it plans, loads custom skills, calls tools, and hands work to subagents. It connects to Workspace, Microsoft 365, Slack, Jira, Confluence, Git, BigQuery, Databricks, Postgres and Snowflake, and works with any Model Context Protocol server inside or outside a company network, per TechCrunch. It picks a model by default, but users can choose third-party ones, starting with Anthropic's Claude.

Two design choices stand out. The agent gets its own Workspace account and email address, and audit trails are written under the agent's name rather than a person's. And there's a tasks inbox showing its reasoning, delegation, loaded skills and code. Google also mentioned real-time spend caps and smart routing for cost control. TechCrunch gives no price and no general availability date.

For builders

If your product sells to companies on Workspace or Microsoft 365, the shortest path into this agent is an MCP server. Ship a read-only one first: three or four tools that answer the questions customers already email you about, authenticated per user, with no write actions. Log every call with the caller identity, because with the agent holding its own account, your logs will be the only place that ties an action back to a person.

Sources

  1. Zenity Labs — AgentCorruption (IMDS access, default role permissions, disclosure timeline)
  2. The Decoder — One public AgentCore agent could hijack every agent in the region; AWS patched and tightened defaults
  3. Anthropic — OSS Scanner (eligibility, PR enrollment, pilot numbers, no human review)
  4. The Verge — Anthropic launches free AI security scans for open-source projects (AI bug-report flood context)
  5. AlternativeTo — Mistral Large 4 specs, pricing, preview and weights timing
  6. Ars Technica (via WIRED) — Mistral on training from scratch, target domains, Lample quotes
  7. TechCrunch — Google's Gemini agent (MCP support, connectors, Claude as an option, agent identity)

— The Vibe Gate news desk. We read the firehose so you can keep building.

← All digests  ·  The blog