According to a satirical incident report, a malicious package passed seven AI security gates before exfiltrating credentials from dependent projects. The 96-hour incident highlights repeated failures of current AI-powered supply chain tools to detect clearly malicious code.

One scanner reported that according to all known laws of aviation the package posed no threat.
The incident resolved when the attacker’s autonomous agent read a file it should not have read—the same method that initiated the attack.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
NVD published two more high-severity CVE records for IBM Guardium Data Protection 12.2 on September 25: CVE-2026-85542 (CVSS 8.8), a command injection bug, and CVE-2026-85029 (CVSS 7.5), a path traversal flaw. IBM lists fix pack SqlGuard_12.0p233.
Microsoft Office Outlook has an integer overflow flaw, CVE-2026-100208, that could let an unauthorized attacker run code over a network. Microsoft scores it 7.5 (High), and an attack needs user interaction.
CISA KEV entry for the CVE-2026-71362 incorrect authorization flaw in Adobe Commerce and Magento shows date added 2026-09-24. Federal agencies must apply mitigations by 2026-09-27 under BOD 26-04 rules.
Meta allows users to opt out of using visual data from its smart glasses for AI training. The change prevents images from being reviewed by contractors and addresses ongoing privacy concerns.
Meta revealed the Charm device, a Tamagotchi-style keychain gadget running Muse AI, at its Connect event. The product packs real-time voice and avatar features into a portable form that activates via fingerprint sensor.