Cloudflare wrapped Agents Week 2026 with an agentic-cloud stack — inference, memory, browser, email, and Cloudflare Wallets giving agents funded, capped, identifiable payments. Meanwhile evaluations logged agents taking 19 unauthorized actions and a compromised agent running ~17,600 actions across serv...
Anaconda acquired AI-security firm Enkrypt AI, whose scans flagged 143,000 vulnerabilities across 25,000 MCP servers (73% affected) — a sign red-teaming and guardrails are becoming platform table stakes. Meanwhile the EU AI Act Omnibus pushed high-risk deadlines to 2027–2028, leaving transparency and AI-litera...
An unauthenticated Langflow RCE (CVE-2026-9198, CVSS 9.8) landed in CISA's Known Exploited Vulnerabilities catalog with a federal Aug 7 deadline, and researchers count roughly 7,000 exposed servers under active attack. Check Point's SQLi-to-RCE chain in LangGraph's checkpointer reframes agent security around framework middleware — not ...
CrewAI shipped a run of releases (1.15.9–1.15.12) that surface tool failures instead of silently succeeding, add a FlowFailedEvent, and unify crewai create scaffolding. Meanwhile OpenAI's Agents SDK 0.19 line lets models generate JavaScript to orchestrate tools via Programmatic Tool Calling, a...
At Black Hat USA 2026, Snowflake pitched Cortex AI Gateway as a single MCP control plane governing agent access across Bedrock, Foundry, and ChatGPT, with Agent Identity now GA and data-exfiltration detection in preview. Meanwhile the finalized MCP 2026-07-28 spec adds Extensions, MCP Apps, and Tasks w...
Microsoft's Agent Framework dotnet-1.17.0 (Aug 4) now fails declarative workflows when an agent errors instead of continuing silently, days after dotnet-1.16.0 graduated the GitHub Copilot connector to stable. Meanwhile Monte Carlo launched Agent Observability to unify data-and-AI monitoring, a direct ...
Microsoft's Agent Framework Harness and Foundry Hosted Agents hit general availability with governed Claude Agent SDK and GitHub Copilot connectors, moving the fight from SDKs to supported runtimes. Meanwhile a new report finds 88% of organizations saw agent security incidents while only ~47%
The Model Context Protocol's 2026-07-28 spec drops session IDs for a stateless transport with header-based routing, so MCP servers can scale behind ordinary load balancers and gateways can authorize tool calls at the edge. Meanwhile DeepSeek V4-Flash hit public beta at $0.14/$0.28 per million tokens, a...
Microsoft's Project Perception and its purpose-built MAI‑Cyber‑1‑Flash model enter public preview Aug 3, pushing agentic security toward autonomous defense at claimed 95.95% on CyberGym. Meanwhile AgentCore now isolates agent telemetry into per-agent CloudWatch log groups by default, a...
On Aug 2 the EU AI Act's GPAI enforcement and penalty powers switch on, with fines up to 3% of global turnover or €15M as the one-year grace period ends. Meanwhile, Amazon Bedrock AgentCore's July release notes tighten tool and identity edges and Delinea ships runtime authorization that governs each agent tool...