Welcome to The Cybersecurity Pulse (TCP)! I’m Darwin Salazar, Head of Growth at Monad and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! 📧
Howdy 👋🏽
I hope you’re having an excellent week! I must say that, after 140+ issues of TCP and 200+ pieces of content incl. podcasts, a book, conference presos, etc. over the past 3 years, it’s still not easy. Some days you find flow state, and on other days, you feel like you’re pushing a boulder up a mountain. Regardless, the process is invigorating because I always learn a ton with every piece of content and the discipline required creates a better me.
That said, this was one of the harder issues to produce as it’s been a loaded week so I hope you enjoy!
A few updates and chances to hang out for my East Coast folks:
I’m presenting at BSides NYC on October 17 on native logging and detection opps for tools like Claude Code, Codex, Cursor etc.
TCP and friends are also hosting a Gatsby-themed party the night before, October 16. I’ll be DJng an hour of Jazzy House. Shaping out to be fun evening. Would love to see you there! RSVP here.
Quick shoutout to this week’s sponsor, Fencer.dev. They’ve built a pretty nifty autonomous pentesting product and are giving away a few pentests each week through October. More on that in the coming sections!
Aside from that, a lot landed this week: Jev has developers rethinking cost + how agents make decisions, compromised AI packages, and the agent-security launches keep coming. We’ve also got another big Cyera raise and a new podcast from a friend of TCP. Let’s get into it.
🗞️ TL;DR
🛸 Gemini’s test got a little too real: Google confirmed its model reached three real companies during a May security evaluation. The test boundaries didn’t hold.
⚙️ Another $400M for Cyera: Goldman Sachs backs a Series G extension as Cyera doubles down on securing agents and the data they touch.
🔐 Okta gives agents the identity treatment: Oktane brought agent SSO and access reviews. A gateway to control tool calls and an expanded kill switch are still coming.
⚒️ Check Point: two flaws, two fixes: Both are under active attack, and the earlier VPN patch leaves the separate management flaw open.
🤝 Upwind buys Aegis: Its new 12-person AI Security Labs team will dig into attacks on agents, skills, and plugins.
💰 Jamf buys Keep Aware: Browser security joins the lineup, including visibility into AI use and data sharing. Congrats to Keep Aware, past TCP sponsors!
⚙️ Jev makes agent decisions dirt cheap: The AI model scores choices for apps and agents, but prompt injection can still sway the answer.
⚒️ MemTensor packages hid a credential stealer: Compromised releases of its OpenClaw plugin and MemoryOS targeted developer and cloud credentials.
Plus: OpenAI’s Defense Factory, a military AI close call, and our friend Yonesy’s podcast debut.
⚒️ Picks of the Week
Gemini crossed the test boundary
Google’s Gemini accessed three real companies during a May cybersecurity evaluation, Google and testing firm Irregular confirmed to Reuters last week.
Google says the model used public information and guessed credentials, believing the targets were in scope. The companies were notified; Irregular says the known issues were resolved weeks ago.
The model’s belief that it was still inside the test didn’t match where it actually went.
#MoarSandboxEscapes
Run a pentest when your code changes, not when your calendar says so
Fencer runs autonomous pentests on demand. Its agents chain weaknesses into validated attack paths, showing how an attacker could get in and what they could reach. Skip copying findings out of a 40-page PDF. Turn them directly into Jira or Linear tickets with context and remediation guidance. Ship the fix, then retest to verify it worked.
TCP readers can also enter to win one of two free pentests each week through November 1.
Cyera raises $400M from Goldman Sachs
Cyera announced a $400M extension to its Series G from Growth Equity at Goldman Sachs Alternatives on September 22. The equity investment will fund AI-security products, federal expansion, and international growth. Interestingly enough, I think that’s how much they acquired Oasis Security for.
The announcement lists Cyera’s valuation at more than $12 billion. Cyera has built a great platform on agentic AI identity + data security. Can they grow into the $12B valuation? Is the plan to go public?
Why Jev has the eng world talking
Jev is an AI model built to make quick decisions inside apps and AI agents. TypeSafe AI launched it on September 15. Developers send it information and a set of possible answers; Jev returns probabilities for those choices.
A coding agent, for example, could ask whether a command should be allowed, blocked, or reviewed. The app uses Jev’s scores to decide what happens next.
The appeal is speed and price. TypeSafe charges 4.2 cents per million input tokens, with free output, and reports responses in 70–500 milliseconds. Vercel says nearly 13% of its paid AI Gateway teams used Jev within 24 hours, its fastest model adoption yet.
The security connection is already here: LangChain offers experimental middleware that uses Jev to judge risky tool calls. TypeSafe’s own documentation says injected instructions can influence its answers. A perfectly formatted “allow” can still be the wrong call.
Our friend Yonesy launched a podcast!
Yonesy Núñez launched Below the Surface, with Pete Chronis joining the first episode. Pete’s a former CISO at Paramount, WarnerMedia and now an operating partner at Cyberstarts.
Give the first episode a listen. Lots of wisdom in it. And go show Yonesy some love!
Inside OpenAI’s Defense Factory
OpenAI shared a look at how it uses agents to find and fix security issues. Its Defense Factory writeup walks through the whole job: map services, find bugs, reproduce them, get fixes to the right owners, and check that they worked.
Humans review changes that carry real risk, and fixes get tested again after deployment. OpenAI also describes early snags with missing dependencies, inconsistent severity ratings, and duplicate findings.
OpenAI says its internal security sprint brought together more than 250 people across over 100 service areas. The company reports closing 53 urgent or high-priority issues on day one.
An AI-generated report nearly triggered a military operation
CNN reports that false AI-assisted intelligence nearly prompted a US operation against a Chinese vessel this spring. Officials caught the error before the planned interception. The model is unidentified, and the Pentagon did not respond to CNN’s request for comment.
Hmm…..
🔬Threats & Research
MemTensor’s AI packages carried a credential stealer
SafeDep and Aikido found compromised releases of MemTensor’s OpenClaw plugin and Python library MemoryOS, published overnight on September 23 UTC. The shared implant targets developer and cloud credentials and starts when the packages load. It also contains code to spread into other projects; wider propagation has not been established.
F5 patches an actively exploited BIG-IP APM zero-day
F5 confirmed active exploitation of CVE-2026-94127, a CVSS 9.8 flaw allowing code execution without login. It affects BIG-IP APM configured as an OAuth authorization server; deployments acting only as OAuth clients or resource servers are excluded. Engineering hotfixes are available.
Check Point: two exploited flaws, separate fixes
Check Point’s September 22 advisory covers active exploitation of VPN flaw CVE-2026-85102 and management flaw CVE-2026-93616, both rated CVSS 9.8. The management flaw allows code execution before login and was exploited on July 23. The earlier LivePatch Take 28/29 does not fix the management vulnerability; the two issues require separate fixes.
FBI investigates ShinyHunters breach claims
The FBI told BleepingComputer it is investigating claims of unauthorized activity affecting FBIjobs.gov. ShinyHunters alleges a PeopleSoft zero-day and extensive data theft. Claims that nearly all agents were exposed remain unverified.
Critical Cisco ISE flaw is under active attack
Cisco confirms active exploitation of CVE-2026-76460, a CVSS 10.0 authentication bypass affecting ISE and ISE-PIC regardless of configuration. Attackers may get root. Cisco advises checking every node and external network logs, and reimaging affected nodes if compromise is suspected.
EvilTokens turns stolen inboxes into fraud research
Microsoft links EvilTokens to more than 12,000 compromised inboxes across over 10,000 organizations. Device-code phishing tricks victims into authorizing attacker access through legitimate sign-in flows. AI then analyzes stolen messages for relationships, invoices, and payment approvers to support impersonation and fraud.
Microsoft says it disrupted the operation, but whether the activity has stopped remains unclear.
Hacktron’s OpenAI exploit chain reached an internal repo
Hacktron published this research September 13 about a July incident. Researchers used Claude Opus 5 to help chain a malicious image upload, a Discourse dependency flaw, SSO behavior, and a GitHub connector into a harmless proof PR in OpenAI’s internal repository. OpenAI fixed its side within roughly 14 hours of reporting.
📦 Security Product Releases
Okta adds an agent gateway and a Blueprint Alliance
Ahead of Oktane, Okta announced a runtime gateway and an alliance with AWS, CrowdStrike, and others to help companies secure AI agents. Agent SSO and agent-to-agent connections are generally available; the gateway and expanded runtime kill switch are still on the way.
Opal Zero puts limits on AI agent access
Opal launched Zero to track who owns each agent and give it limited, expiring access. Paladin checks requests against policy and context; Gateway Sync sends those decisions to existing MCP gateways to enforce. Sensitive actions can require human approval.
detections.ai launches Nightwatch
detections.ai recently launched Nightwatch in Enterprise. It checks new threat behavior against existing detection logic, hunts for relevant activity, and drafts rules using the team’s data models and conventions. Analysts can inspect queries, results, and reasoning; humans approve deployment.
Wiz connects agent instructions to cloud activity
Wiz describes a detection engine that looks at model inputs, outputs, and tool activity alongside cloud and runtime events. That helps connect what the agent was told to do, what it tried, and what actually happened. An API log can show an authenticated call without explaining what prompted the agent to make it; Wiz is working to connect those pieces. Bedrock invocation-log support is in private preview for Wiz Defend customers.
Palo Alto makes frontier AI testing continuous
Unit 42 launched Continuous Frontier AI Defense, an annual subscription combining expert-led offensive testing with multiple AI models across applications, APIs, cloud environments, and code. The service includes exploit validation and remediation guidance.
Opus 5.5 routes most security tasks to 4.8
Anthropic launched Claude Opus 5.5 yesterday. Its safeguards route most cybersecurity tasks to Opus 4.8, while routine software bug fixing remains supported. Anthropic plans to expand verified access. For now, the newest model’s launch leaves much of the cybersecurity work with the older model.
🤝 Funding & M&A
Jamf acquires Keep Aware
Jamf acquired Keep Aware, adding browser security to its Apple device management and security business. Keep Aware helps teams spot malicious extensions, browser-based attacks, and sensitive data shared with AI tools. It works inside the browsers employees already use. The deal brings browser activity and endpoint security closer together as Jamf expands its AI governance push. Financial terms weren’t disclosed.
Upwind acquires Aegis
Upwind announced its acquisition of Aegis on September 23 and formed AI Security Labs. Aegis founders Omri Limor and Saar Ankonina will lead the 12-person team researching threats involving AI agents, skills, and plugins. Deal terms were not disclosed.
Dragos closes the NetRise and runZero acquisitions
Dragos completed both acquisitions September 21 following Accenture’s majority investment. runZero adds asset discovery; NetRise adds firmware and binary analysis. Together, the acquisitions expand what Dragos can learn about an industrial device, from finding it on the network to examining the software inside it. The integration work is still ahead.
Interested in sponsoring TCP?
Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries 🌎
Disclaimer
The insights, opinions, and analyses shared in The Cybersecurity Pulse are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.














