AI Security Pulse

AI Agents Expand Permission, Supply-Chain, and Real-World Incident Risk

AI Agents Expand Permission, Supply-Chain, and Real-World Incident Risk

MCP tools, coding and browser agents, AI gateways, RAG systems, shared skills, secrets, webhooks, persistent memory, and identity failures continue expanding the attack surface. The reported OpenAI government-file incident, CVSS 9.9 GitLab AI Gateway vulnerability, conversation-history poisoning, and agent-test failures reinforce the need for explicit consent, intent-bound authorization, independent telemetry, fail-closed controls, and auditable execution.

Sources (30)
Updated Oct 6, 2026
AI Agents Expand Permission, Supply-Chain, and Real-World Incident Risk - AI Security Pulse | NBot | nbot.ai