AgentsSep 29

Image: learn.chatgpt.com
Codex adds reusable cloud workspaces and continuous security scanning
Reusable cloud workspaces in Codex let teams start with approved settings and permissions, then resume development across devices. OpenAI also added voice controls, a multi-task command-line view (a text-based way to control the tool) and code review inside the ChatGPT desktop app. Related API updates add hosted browser use, AWS Bedrock Managed Agents and a Luna-powered Decisions API. OpenAI is rolling out Codex Security Cloud for GitHub scanning and proposed fixes, with access to the Daybreak Blue model. The service can investigate findings, remove duplicates and monitor new code changes while a developer's laptop is closed, producing supporting evidence and patches for human review.
Positive - OpenAI is rolling out GitHub repository scanning and proposed fixes in Codex, bringing security checks into developers' everyday workflows.
AgentsSep 29

Image: The Threshold Report/GPT Image 2.5
Matt Robb says Muse shared his address and accepted an offer
YouTuber Matt Robb says Meta's Muse shared his home address with a Facebook Marketplace buyer and accepted a low offer without separately asking for approval. He had given Muse hands-off control and selected the Allow Always messaging setting. The buyer arrived before Muse told him what it had done, Robb says. Meta referred The Verge to David Singleton, who spoke with Robb; Robb subsequently said Meta was looking to clarify sharing permissions.
Negative - Muse shared a user's home address and accepted an unwanted offer without separate approval, showing that blanket permissions failed to protect sensitive decisions.
AgentsSep 29

Image: bleepingcomputer.com
DIVD reports an intrusion using an autonomous AI agent
An attacker used an autonomous AI agent after exploiting an undisclosed technical vulnerability at Dutch cybersecurity nonprofit DIVD, the organization says. The agent chose successive actions and left extensive evidence. DIVD described the operation as loud and messy, with actions that interfered with the attacker's own work. DIVD notified police, the Dutch data-protection authority and the National Cyber Security Center, issued an update on September 28, 2026, and promised more details on October 1, 2026.
Negative - An attacker breached DIVD and used an autonomous AI agent to carry the intrusion forward, demonstrating the capability against a real victim.
Compute & InfraSep 22

Image: vastdata.com
VAST previews DataEnclave for protected AI processing
DataEnclave is VAST Data's proposed way to run outside models where sensitive enterprise data already resides, without exposing the data to the infrastructure operator or unprotected model files to the customer. Built on NVIDIA Confidential Computing (technology that protects data during processing), DataEnclave verifies the execution environment before releasing keys and decrypting enterprise data or proprietary model files. VAST says protected CPU and GPU processing would keep both assets inaccessible to infrastructure administrators, with separate key control and operation on connected or air-gapped networks (networks isolated from outside connections). The system would record verification and key-release events and provide contained execution environments for agents. VAST plans to release it in the first quarter of 2027.
Positive - VAST previewed a runtime that withholds decryption keys until the execution environment is verified, adding a barrier to administrator access to sensitive data and model weights.
TextSep 28

Image: huntress.com
Attackers use Custom GPTs to lure users into malware infections
Two attacker-created Custom GPTs (customized ChatGPT assistants) posed as a ChatGPT offering and directed users from the legitimate ChatGPT site to a fake verification page, Huntress found. That page persuaded users to run commands that installed malware. Huntress investigated at least 40 related incidents, including two confirmed infections driven by the Custom GPTs. OpenAI removed the first GPT by September 25, 2026, after Huntress flagged it, while a replacement discovered on September 27, 2026, remained active when Huntress published its findings on Sept. 28. The campaign's remote-access malware (software that lets attackers control an infected device) used two methods to maintain access and abused legitimately signed software.
Negative - Attacker-created GPTs led users into confirmed malware infections through fake verification commands, and a replacement remained active after OpenAI removed the first.
TextSep 30

Image: vincenzoiozzo.com
Jev costs less in an independent bulk account-matching test
Vincenzo Iozzo compared TypeSafe's Jev with general-purpose models and traditional matching methods to test the accuracy, cost and speed of linking accounts belonging to the same person. The large-directory tests used samples from four organizations with roughly 30,000 to more than 100,000 accounts each. Jev achieved an overall F1 score (a combined measure of how often matches are correct and how many true matches are found) of 0.948. Systems can use its probability scores to queue uncertain cases for review, and selective Claude checks recovered some links Jev missed. Jev cost $0.62 per 1,000 accounts, with a median processing time of 0.3 seconds per account. It was 19 to 47 times cheaper than the tested Haiku 4.5 and Sonnet 5 configurations.
Positive - Independent tests showed Jev matching accounts to the same person accurately and cheaply, giving security teams a more scalable way to check account ownership.
TextSep 29

Image: theverge.com
Six AI companies sign voluntary monitoring and safety oversight pact
Executives from Google, Anthropic, Meta, OpenAI, xAI and NVIDIA signed the voluntary Joint Commitment on Frontier Responsibilities with President Trump. The companies pledged to monitor what their models can do and whether they behave as intended, assign a team to address problems and appoint an independent external evaluator. An independent board committee would oversee the controls and findings around risks including unauthorized hacking, cyber misuse and biological or chemical threats. They also committed to regular meetings to establish safety standards and practices.
Positive - Six AI companies signed a voluntary accord with the government committing to model monitoring, independent evaluation and board oversight, assigning responsibility for finding and addressing safety problems.