Agent security on macOS, Warlock ransomware via SharePoint, a GitLab AI Gateway RCE, and ShinyHunters arrests, plus agent cost controls and Okta's re-rating.
AI & Technology
Willison argues cloud and API services need hard spending caps by default as agents can burn money at machine speed. Runaway agent loops are a financial denial-of-service risk that few threat models cover. Anyone running autonomous agents on metered APIs should treat spend limits as a security control.
Microsoft's post targets the gap between an agent claiming task completion and the actual system state. Verifying outcomes against ground truth rather than the agent's self-report is the practical fix for unreliable agent evaluation. Worth reading for anyone building agent harnesses or measuring tool-use success.
Cybersecurity
Gemini on macOS may soon open apps, read any file and browse without per-action approval. Removing the confirmation step turns every prompt injection into a potential local data exfiltration path. The open question is whether Apple's FDA changes constrain it. Connects to: Apple changes full-disk access permissions to curb abuse from AI agents.
A CVSS 9.9 flaw in GitLab's AI Gateway lets a logged-in Duo Agent Platform user run commands on self-hosted gateways. The AI connector layer is becoming a high-value, under-audited attack surface sitting next to source code and credentials. Only self-hosted deployments are affected, so patch exposure depends on who runs their own gateway.
The suspected China-linked Warlock actor keeps weaponizing old and new SharePoint bugs, killing security tools before deploying ransomware. Targets include a water utility, a telecom and a university in Portuguese- and Spanish-speaking countries. That is an espionage-adjacent toolset used for criminal monetization, which blurs attribution-based defense priorities.
TA419 runs adversary-in-the-middle phishing against AI policy experts at think tanks, universities and law firms, impersonating prominent economists and AI figures. AI governance researchers are now a standing espionage target, and AitM defeats standard MFA. Phishing-resistant FIDO2 keys are the relevant mitigation for academics in this space.
Entrepreneurship
SaaStr's agents make 35,000 to 40,000 API calls a day, and a vendor quoted $240,000 for access that a $5 Postgres replica handled. Vendors are starting to price agent traffic that humans never generated, and mirroring data locally is the cheap counter. The pattern also signals where API pricing for agent-heavy workloads is heading.
Okta tripled from its April low on 11% growth, with 14% cRPO growth and 30% of bookings from new products. The market is paying for identity as the control plane for AI agents, not for the core SSO business. A caveat is the roughly 50x forward earnings multiple, which leaves little room for a miss.
Worth Reading
Apple is tightening Full Disk Access after Meta argued FDA is insufficient for its Muse agent to read messages. The dispute shows the OS permission model is now the real control point for agent capability, not the model vendor's policy. Indie macOS developers shipping agentic features should expect stricter entitlement review and re-test any FDA-dependent workflows.
A tech CEO was arrested over an alleged $300M Nvidia chip smuggling scheme into China. Enforcement is shifting from rules on paper to criminal cases against intermediaries, which raises compliance risk for GPU resellers and cloud brokers. Arrests keep arriving, which suggests export-control leakage remains large.