Bharat Threat FeedGlobal threats, decoded for Indian defenders
AI Threat Watch · 8 October 2026

AI Threat Watch — 8 October 2026

Two of this week's disclosures turn on the same question, which is who supplied the input that an automated system then acted on using somebody else's authority. A coding agent read a developer's production secrets and sent them out, and the vendor's position is that the user asked for it. An enterprise CRM agent acted on instructions a stranger had typed into a public lead form weeks earlier. Google's new measurement sets out the queue all of this now sits in: vulnerability disclosures roughly doubled over the first eight months of 2026, and the flaws research agents find are about twice as likely to end in remote code execution as those found by other means. The fourth item is the one closest to Indian customers, because a government-backed awareness campaign launched in Mumbai on Monday names voice cloning and real-time deepfakes as mainstream fraud, which is an acknowledgement that the technique has already reached ordinary people.
1

Google's threat intelligence group has measured what AI is doing to vulnerability discovery, and the finding that matters is not the volume but the profile: flaws found by research agents are roughly twice as likely to end in remote code execution

The Google Threat Intelligence Group published "Vulnerability Discovery and Exploitation Trends in the AI Era" on 30 September 2026, covering January 2025 to August 2026. Monthly disclosures roughly doubled over the period, from 5,045 in January 2026 to 10,740 by August, and those rated high risk rose 167 percent, from 131 to 350. Of the vulnerabilities GTIG assesses as likely discovered by AI, about half lead to remote code execution against 26 percent across the wider CVE set, and they cluster in the medium-risk band rather than the low-risk one, 58 percent against 28 percent. GTIG reads this as autonomous research agents being aimed at consequential software rather than swept broadly across everything. Two numbers cut in the opposite direction, and they are the ones that make triage defensible. Observed in-the-wild exploitation rose from an average of 10.5 vulnerabilities a month in 2025 to 18 a month over January to August 2026, which is 141 distinct exploited vulnerabilities against 127 in the whole of 2025. But only 0.23 percent of disclosures, roughly one in 431, were seen exploited at all. Volume is rising faster than exploitation, so patching by severity score alone spends effort that the compressed timelines now require elsewhere. GTIG's worked example is CVE-2026-1731, an unauthenticated operating-system command injection in BeyondTrust Remote Support and Privileged Remote Access, found autonomously by the Hacktron AI research agent. BeyondTrust published advisory BT26-02 on 6 February 2026, rating it 9.9 under CVSS version 4, affecting Remote Support 25.3.1 and earlier and Privileged Remote Access 24.3.4 and earlier, with fixes in Remote Support 25.3.2 and Privileged Remote Access 25.1.1 and later. One threat cluster exploited it within four days of disclosure and five more followed inside seven days; CISA added it to the Known Exploited Vulnerabilities catalogue on 13 February 2026. Separately, GTIG counts 2,076 AI-related CVE disclosures since January 2025, with agent orchestration and agent frameworks the largest category at 782 and up 347 percent in 2026, naming Flowise, Langflow, LangChain, Dify, LlamaIndex, AutoGen, CrewAI, Semantic Kernel, Letta, MCP and Pydantic-AI among them.

Why it matters for IndiaNothing in this research is directed at India, but the exposure categories it ranks are the ones Indian estates are built on. Edge and security appliances account for 14 percent of exploited vulnerabilities and enterprise directory and collaboration services for 11 percent, and remote-access and privileged-access products of exactly the BeyondTrust type sit in front of government departments, banks, managed service providers and critical-infrastructure operators here, very often operated by a third party under contract. CERT-In's advisory line through 2026 has been that the interval between disclosure and exploitation has collapsed, and this research puts a measured figure behind that argument rather than an assertion. The practical consequence for an Indian CISO is that a monthly patch cycle cannot be reconciled with a four-day exploitation interval on an internet-facing appliance, and the gap has to be closed by triage, because no Indian security team is going to be given enough people to patch everything quickly.
ActionRun a separate daily queue for internet-facing appliances, remote and privileged access products, identity providers and collaboration platforms, driven by known exploitation rather than by severity scores. Confirm in writing that BeyondTrust Remote Support is at 25.3.2 or later and Privileged Remote Access at 25.1.1 or later, including instances a managed service provider runs on your behalf. Where an appliance ran unpatched while exploitation was public, review administrative activity, new accounts, changed access policies and outbound connections from that host, and preserve the logs before rebuilding. For the AI estate, inventory the orchestration frameworks GTIG names, establish which hold production credentials, and separate the ones that do not need them. Then take GTIG's structural recommendation seriously: sandbox autonomous agentic workloads so that code execution inside them is contained rather than assumed benign.
SourceGoogle Threat Intelligence Group, "Vulnerability Discovery and Exploitation Trends in the AI Era" (30 September 2026); Infosecurity Magazine and SiliconANGLE (30 September 2026); Help Net Security (1 October 2026); BeyondTrust advisory BT26-02 for CVE-2026-1731 (6 February 2026); CISA Known Exploited Vulnerabilities catalogue addition (13 February 2026); Rapid7 analysis of CVE-2026-1731.
2

A coding agent was made to read a developer's production secrets and send them to an external endpoint, and the vendor's position is that this is not a vulnerability because the user asked for the content and had granted the agent autonomy

Adversa AI published research on 6 October 2026 describing a technique it calls Cryptographic Context Injection against GitHub Copilot CLI. The defensive point sits above the mechanism, which this brief will not reproduce. A guardrail that inspects fetched content as it arrives can pass material that is not yet in an executable form; the agent then transforms that material inside its own tool runtime as an ordinary coding task, and treats the result as its own trusted context rather than as something an outsider supplied. In the demonstration the agent was in autopilot mode and was asked to look at one attacker-controlled web page. It went on to read local files, including a production environment file holding secrets, and send the contents to an external endpoint, with no visible indication on screen that a file had left the machine. The disclosure history is as much of the story as the technique. Adversa says it reported the finding to GitHub through its bug bounty programme on 17 September 2026, and that GitHub declined to classify it as a product vulnerability, on the reasoning that the user had asked for the attacker-controlled content and had granted autonomous permissions. No CVE has been assigned. Reasonable people can disagree about where product responsibility ends, but an enterprise security team cannot adopt that reasoning, because the user who approved a broad task did not approve the specific resolved actions that followed, and no approval record in that organisation will show otherwise. Two other recent pieces of work point the same way. Salt Labs published research on 1 October 2026 showing that a single email could hijack the agentic platform Manus and reach the email, cloud storage and code repository accounts a user had connected to it; the platform's guardrail did detect the activity, but the warning arrived after the code had already run, and Salt Labs' conclusion is that a control which fires one step late has not fired. That issue has been fixed. Academic work published on 18 September 2026 by Szczepaniak, Feldman, Viner and Nassi found that conditional payloads which stay dormant until a later trigger succeeded in 43 to 83 percent of trials across nine production agents, against at most 3 percent for a direct instruction, and proposes detection at the point content is ingested.

Why it matters for IndiaCoding agents and agentic developer tooling are in routine use across Indian product companies, GCC engineering functions, fintechs and services firms, on machines holding source code, cloud tokens, repository credentials, CI secrets and, in services work, access into a customer's environment rather than only your own. The pattern these three pieces of research share fits Indian delivery work closely, because engineers here routinely pull external tickets, vendor documentation, customer logs and third-party pages into an agent's context and then let it act. The governance problem is the sharper one. If a vendor treats an agent action as authorised because the user approved the overall task, and no CVE is issued, then this exposure never reaches your vulnerability management process at all. Where a leaked credential reaches customer personal data, the obligation under the Digital Personal Data Protection Act does not soften because the action was technically permitted.
ActionTurn off autopilot or equivalent autonomous modes whenever an agent is handling content from outside the organisation, including web pages, email, tickets, pull requests and customer-supplied files. Require explicit confirmation for reads outside the working directory, for any action touching secret-bearing files, and for outbound connections to destinations not on an allowlist. Log tool calls with their resolved arguments rather than the agent's own description of what it did, because that summary is written by the component you are trying to supervise. Build the detection Adversa recommends: untrusted content entering context, then code execution, then an outbound request. Run coding agents under least-privilege identities in workspaces holding no production credentials, and rotate what those machines have already held. Extend your vulnerability intake beyond CVE feeds to vendor and research-lab advisories, because this item has no CVE and would otherwise be invisible to you.
SourceAdversa AI, "Cryptographic Context Injection" research on GitHub Copilot CLI (6 October 2026); CSO Online; Salt Labs research on the Manus agentic platform (1 October 2026), reported first by Dark Reading; Szczepaniak, Feldman, Viner and Nassi, "Defusing Explosive Prompts", arXiv 2609.22510 (18 September 2026).
3

Three flaws in Salesforce Agentforce allowed a stranger who filled in a public lead form to have a company's own AI agent query CRM records and carry selected values out, with no click from any employee

Zenity Labs published the research, which it calls SalesBleed, on 24 September 2026, authored by Alex Apostolov, João Donato, Avishai Efrat and Ayush RoyChowdhury. The first weakness is a question of timing and trust rather than of code: instructions submitted through a public Web-to-Lead form sat in Salesforce as ordinary data until an employee later asked the agent to review recent leads, at which point the agent acted on them. The second is that Salesforce's Trusted URLs redaction, the control meant to stop an agent sending data to an unapproved destination, had two parsing failures that let an attacker-controlled destination through. The third is separate and concerns the Slack integration, where the agent could post messages without reliably recording who had triggered the action and without the confirmation step Salesforce normally requires, which would let an insider send phishing under the agent's trusted identity while remaining unidentified. The remediation timeline is complete, which is why this is an architectural lesson rather than a live emergency. Zenity reported to Salesforce on 1 June 2026; Salesforce confirmed the Trusted URLs fix on 18 August 2026 and Zenity verified it on 19 August; the Slack-path fixes, which added proper attribution and changed insecure defaults, were confirmed and tested on 21 September 2026. No CVE was assigned to any of the three. What outlives the patches is the researchers' own generalisation: prompt injection stops being a content-safety problem and becomes an access-control problem the moment an agent combines three properties, which are ingesting untrusted external input, rendering rich content, and holding access to sensitive backend data. Agentforce happened to be the product examined. The three properties are not specific to it.

Why it matters for IndiaIndian BFSI, telecom, healthcare, education technology, IT services and public-sector organisations run CRM and collaboration platforms with public lead intake, partner portals and messaging integrations, and many are now piloting agents on top of exactly those systems. A public form is reachable by anyone by design; if the agent that later reads those records also holds access to accounts, contacts, opportunities and cases, the boundary between a stranger's input and your customer data is thinner than the architecture diagram suggests. CRM records in Indian BFSI contain personal and financial data, so an agent-mediated leak is a data leak for the purposes of incident response, client notification and DPDP Act governance, whatever the agent was configured to do. Most of these deployments are assembled by an integrator, so the controls in question were chosen by a third party and are rarely written down anywhere the security team can read them.
ActionTreat every agent as a privileged non-human identity with its own inventory entry, owner and access review. Establish which agents can read leads, accounts, contacts, opportunities and cases, and separate those that process public submissions from those that can query sensitive objects, because combining both jobs in one identity is the condition this research turns on. Require confirmation and recorded attribution for any agent write into a collaboration tool, and verify your Slack or Teams integration now shows who triggered a message. Confirm with Salesforce or your integrator that the Trusted URLs hardening and the Slack attribution defaults are active in your own tenant rather than merely released. Monitor outbound DNS and HTTP from CRM and collaboration surfaces for destinations with no business relationship. Then ask the general-form question of every agent you run: does it read anything a stranger can write, and can it reach anything you would have to report losing.
SourceZenity Labs, "SalesBleed: 0-click data exfiltration on Agentforce" and the companion research on the Agentforce Slack integration (24 September 2026); Infosecurity Magazine (25 September 2026); SecurityWeek.
4

India's national awareness campaign for this month names AI voice cloning and real-time deepfakes alongside malicious APKs and digital-arrest scams, which places synthetic impersonation in the mainstream fraud category rather than the emerging one

The Data Security Council of India launched "Be Cyber Street Smart" on 5 October 2026 at the Bombay Stock Exchange in Mumbai, inaugurated by Maharashtra's IT Minister Ashish Shelar and running through October for Cyber Security Awareness Month. It is supported by CERT-In, the Indian Cyber Crime Coordination Centre, MeitY and the Government of Maharashtra, with participants including Axis Bank, HDFC Bank, Punjab National Bank, CRED, PayPal, BSE, Thales, Veeam, 63SATS and ZS Associates. This is an awareness campaign and not a disclosure, and it is here for what the choice of topics indicates: when the national industry body, the CERT and the cybercrime coordination centre jointly put AI voice cloning and real-time deepfakes into a campaign aimed at ordinary citizens, the technique has stopped being a demonstration and become a volume fraud. The regulatory frame is already in force. The IT Rules amendments notified on 10 February 2026 and effective from 20 February brought synthetically generated information into scope, requiring prominent labelling and embedded provenance markers that platforms may not permit to be stripped, and compressing the window for acting on a government or court takedown order from 36 hours to three.

Why it matters for IndiaThe exposure is widest in BFSI, because voice cloning attacks the one authentication factor Indian banking operations have always treated as reliable, which is recognising the person on the call. That reaches past the customer. Contact centres, branch operations, help desks, treasury and vendor-onboarding teams all run processes where a familiar voice with a plausible reason has historically been enough to move a step forward. Government departments and public-facing services face the digital-arrest and official-impersonation themes directly, and defence suppliers and critical-infrastructure operators face executive impersonation aimed at payment diversion. For large intermediaries the three-hour window is an operational commitment that has to be staffed, not a policy position. No source here says any particular actor is targeting Indian institutions; what the campaign establishes is that the national bodies consider the technique common enough to warrant a public campaign.
ActionRemove "I recognised the voice" from every process that currently accepts it, and name the replacement: a callback on a number held in your own records, or an out-of-band confirmation, for payment instructions, vendor bank-detail changes, password and MFA resets, SIM changes, emergency procurement and privileged access requests. Test it rather than documenting it, by attempting a voice-led credential reset against your own help desk and recording what happens. Brief contact-centre and branch staff that detection by ear is not expected of them and that the process is the control. Align customer messaging with the campaign's four named techniques while the public attention is there. For intermediaries, confirm the takedown workflow can meet three hours outside business hours and on a public holiday, which is when it will be tested.
SourceData Security Council of India, "Be Cyber Street Smart" campaign launch, Bombay Stock Exchange, Mumbai (5 October 2026); APAC News Network, MediaBrief, Digital Terminal and India Education Diary launch coverage (5 to 6 October 2026); Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules on synthetically generated information, notified 10 February 2026, effective 20 February 2026.
AI defender tip: The phrase to distrust this week is "the user asked for it." GitHub's reasoning on the Copilot CLI research was that the developer requested the page and had granted the agent autonomy, so what followed was authorised. Salesforce's agent read a lead because an employee asked it to review recent leads, which it duly did, including the part a stranger had written. Manus detected the problem and said so, after the code had run. In each case something genuinely was approved, and in each case the thing that executed was not the thing the approver had in mind. That gap is where the whole category now lives, and it will not be closed by better model behaviour, because it is not a model failure. It is an authorisation design that collects consent for an intention and spends it on a sequence of concrete actions nobody reviewed.

The exercise for this week is small and produces an artefact you can show an auditor. Pick one agent already running in your organisation, in development, sales or support. Find a real session in the logs and write two columns. On the left, what the human approved, in the words they would have used. On the right, the resolved actions that executed: files read, records queried, hostnames contacted, messages sent. Most teams will find the right column cannot be reconstructed at all, because the logging captured the agent's summary of its work rather than its tool calls with arguments. That absence is itself the result, and worth reporting upward in those terms, because every control you might add afterwards depends on seeing that column first. If you can reconstruct it, compare the two sides and find the widest gap. That gap, not the model, is your next piece of work.

Nirad Threat Research

Nirad AI Threat Watch | Bharat-first threat intelligence