Breach of Confidence — 28 September 2026

Breach of Confidence

There was a mass uprising last week in support of moving this newsletter from Friday to Monday. Do not let anyone ever say I’m not a man of the people. Unfortunately, I forgot, so it’s a bit later in the day than I had hoped for.

Right. Let’s see what broke last week.

AI agents and the keys to the kingdom

Developers are handing AWS credentials to AI coding agents like they’re tipping a valet. The agent is brilliant, efficient, and cannot distinguish between your dev environment and production. The autonomy is lovely. The blast radius is not.

https://cybersec.gitguardian.com/s/a-developer-s-guide-to-coding-agent-security-29626

The perfect trust machine

Someone’s built an encrypted upload service where only you hold the keys, then they promise the data’s deleted. Brilliant. You’ve engineered a system where users have no choice but to believe you. It’s not security theatre. It’s security improv.

https://thenextweb.com/news/zai-zcode-encrypted-upload-only-zai-can-verify

100% authentic plagiarism

A university provost writes that institutions must distinguish student work from AI-generated submissions. His op-ed about this? Flagged as 100% AI-written. His defence of that flagging? Also 100% AI-written. The irony is so perfect it almost feels staged. Almost.

https://www.thedartmouth.com/article/2026/09/schnell-ai-writing

When helpfulness becomes a vulnerability

Meta’s AI assistant was asked for an export of its files. It cheerfully sent the entire Linux filesystem, including SSH keys and internal documentation. The assistant did exactly what it was asked to do, which is precisely the problem.

https://mouse.dev/blog/muse-runtime-export/

ChatGPT writes your fraud for you

Banking malware built by AI, phishing pages copy-pasted from ChatGPT responses, victims losing their PINs to code that nobody bothered to write by hand. Even fraud has gotten lazy.

https://www.group-ib.com/blog/remcontrol-android-banking-trojan/

Infostealers and the long game

Malware only needs a short window on your machine to steal passwords, session cookies, cloud keys, and source code credentials. Removing the malware doesn’t remove the exposure. Those stolen logins can fuel attacks months or years later. The infection ends. The compromise continues.

https://api.cyfluencer.com/s/new-research-inside-infostealer-attacks-29625

Runtime: the new install

Attackers worked out that install script defences are watching the wrong moment. So they wait until runtime to detonate. Blocking install scripts is a speed bump, not a wall.

https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/

Europe’s privacy fire sale

The EU is about to let Big Tech help themselves to decades of your personal data, no consent required, all in the name of AI profits. This isn’t regulation. It’s a going-out-of-business sale of European privacy.

https://noyb.eu/en/ai-eu-member-states-plan-digital-expropriation-europeans-interest-ai-companies

Solving for the attack, not the people

Russia’s blocking mobile internet during drone strikes to stop navigation. The problem: it also blocks the warnings telling people to take cover. They’re optimising for the threat, not the humans in the blast zone.

https://therecord.media/russia-internet-shutdowns-disrupt-warnings-about-drone-attacks

Every OS since 2000 has been leaking your activity

File notifications have been quietly telling anyone listening what users are doing across Windows, macOS, Linux, and Android. Microsoft says it’s working as intended. Everyone else is patching. Choose wisely.

https://www.theregister.com/security/2026/09/24/decades-old-file-security-flaws-found-in-android-linux-macos-and-windows/5298672

—

That’s your lot. If any of this made you laugh, wince, or forward it to your CISO with the subject line ‘see?’, reply and let me know. I’m also on Mastodon, Bluesky, Linkedin etc posting into the void with the best of them.

Stay cynical.