{
 "date": "2026-10-05",
 "issue": 10,
 "status": "published",
 "incidents": [
  "RL-I-2026-0468",
  "RL-I-2026-0469",
  "RL-I-2026-0491"
 ],
 "removed": 2,
 "examined": 26,
 "windowUntil": "2026-10-05 16:19:08",
 "summary": [
  "AWS has released fixes for four vulnerabilities in its Loom AI agent platform and SageMaker Unified Studio that allow attackers to bypass authentication and steal credentials [1]. Google has suspended its open-source bug bounty program for product vulnerabilities due to a surge in invalid, AI-generated submissions [2, 3]."
 ],
 "main": {
  "headline": "AWS patches flaws in Loom agent platform and SageMaker",
  "paragraphs": [
   "AWS disclosed four vulnerabilities affecting its open-source Loom AI agent orchestration platform and Amazon SageMaker Unified Studio in security bulletins published on October 2, 2026. The flaws allow attackers to bypass authentication, steal OAuth2 tokens and temporary cloud credentials, access internal services, and execute arbitrary code in another user’s SageMaker environment. AWS recommends that Loom users upgrade to version 1.7.0 and that SageMaker customers restart affected Studio Spaces to obtain patched images [1].",
   "The highest-impact Loom flaw, tracked as CVE-2026-103956, affects versions earlier than 1.6.1 and stems from an issue in Loom’s authentication dependency. If a deployment does not have an identity provider configured, any network client could gain complete administrative authority over the agent control plane. An attacker could use this access to register malicious tool servers, retrieve stored integration credentials, and alter IAM role policies associated with managed agent roles. AWS classified the issue under CWE-306, Missing Authentication for Critical Function, and CWE-1188, Insecure Default Initialization of Resource Permissions [1].",
   "AWS fixed CVE-2026-103956 in Loom version 1.6.1, released on August 4, 2026. However, customers should move directly to Loom 1.7.0 because it includes fixes for additional token-disclosure and internal-network access flaws. CVE-2026-103957 affects Loom releases before version 1.7.0 and concerns unsafe OAuth2 discovery processing. An authenticated user with either the `mcp:write` or `a2a:write` scope could configure a malicious well-known discovery URL that makes the backend disclose OAuth2 client secrets or another user’s access token to an attacker-controlled endpoint [1]."
  ]
 },
 "supplementals": [
  {
   "headline": "South Korea investigates bank breaches linked to AI tools",
   "paragraphs": [
    "South Korea's Financial Services Commission held an emergency meeting after confirming a data breach at Shinhan Bank and incidents at Kookmin Bank and Hana Bank. Local media reported that Shinhan Bank leaked details of 25,000 customers, while Kookmin Bank leaked credit card information of 119,000 clients. Authorities launched on-site investigations and instructed financial companies to inspect externally accessible IT systems and reduce unnecessary information exposure [4].",
    "Korean news agency Yonhap reported that a server used in the attacks had an HTML page title containing a Chinese-language string associated with ARTEX AI, an open-source penetration-testing system. The bank and financial authorities have not confirmed its use in the Shinhan breach, and the string does not link the attacks to any particular threat actor. However, Moon Jong-hyun, head of the Genian Security Center, posted on LinkedIn that several threat analysts believe the breaches involved AI-based attack automation tools [4]."
   ]
  },
  {
   "headline": "Google pauses open-source bug bounty over AI spam",
   "paragraphs": [
    "Google has suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) for product vulnerabilities as of October 1, 2026. The company stated that the pause is due to a significant rise in automated submissions, the vast majority of which are not valid [2, 3].",
    "Google added that it is working on readjusting the OSS VRP to address the automated submission issues, with more information to be provided in Q1 2027. In the meantime, researchers are encouraged to submit findings to other VRP programs or the Patch Rewards Program. The OSS VRP, launched in August 2022, incentivizes security researchers to responsibly disclose flaws in open-source projects maintained by Google, including Golang, Angular, and Protocol Buffers [2, 3]."
   ]
  }
 ],
 "references": [
  {
   "n": 1,
   "source": "gbhackers.com",
   "title": "AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials",
   "url": "https://gbhackers.com/aws-ai-agent-vulnerabilities/amp/",
   "published": "2026-10-03",
   "evidenceClass": "independent_confirmation",
   "incidentId": "RL-I-2026-0491",
   "archiveUrl": "https://web.archive.org/web/20261004033208/https://gbhackers.com/aws-ai-agent-vulnerabilities/amp/"
  },
  {
   "n": 2,
   "source": "bleepingcomputer",
   "title": "Google halts open-source bug bounty program amid AI spam surge",
   "url": "https://www.bleepingcomputer.com/news/google/google-halts-open-source-bug-bounty-program-amid-ai-spam-surge/",
   "published": "2026-10-05",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0469",
   "archiveUrl": "https://web.archive.org/web/20261005083301/https://www.bleepingcomputer.com/news/google/google-halts-open-source-bug-bounty-program-amid-ai-spam-surge/"
  },
  {
   "n": 3,
   "source": "helpnetsecurity",
   "title": "AI slop submissions force Google to freeze its open-source bug bounty",
   "url": "https://www.helpnetsecurity.com/2026/10/05/google-ai-generated-vulnerability-reports-pause/",
   "published": "2026-10-05",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0469",
   "archiveUrl": null
  },
  {
   "n": 4,
   "source": "bleepingcomputer",
   "title": "South Korea probes bank breaches amid suspected AI-powered attacks",
   "url": "https://www.bleepingcomputer.com/news/security/south-korea-probes-bank-breaches-amid-suspected-ai-powered-attacks/",
   "published": "2026-10-05",
   "evidenceClass": "analyst_assessment",
   "incidentId": "RL-I-2026-0468",
   "archiveUrl": null
  }
 ]
}
