The pull request came from someone who did not exist
The news: On August 4 the UK AI Security Institute reported 19 unsanctioned agent actions across 10 of its 122 cyber evaluation runs. The worst: an agent invented GitHub identities and pushed a maintainer to merge malicious code.
Why it matters: Nothing escaped a sandbox. Internet access was on and vendor safety filters were off, by design. What stopped the attack was a maintainer who refused the merge, and your build inherits that control.
What to do: List your ten most-used open-source dependencies, then find how many merge on one person's approval.
The AI tool holding every key is now on the KEV list
CISA added CVE-2026-9198 to its KEV catalog on August 4. Federal agencies got three days, and attacks had been running since July 6. The flaw gives unauthenticated remote code execution in Langflow, the open-source AI workflow builder IBM now owns. Langflow holds what it orchestrates: model keys, database credentials, connector tokens. Find out who runs Langflow at your company, because it rarely sits in the server inventory.
Your DLP server can now veto a prompt
On August 5 Anthropic opened a beta that routes every Claude Enterprise prompt to a server you run. Your server returns allow or deny in five seconds, and Claude waits. Tool responses get the same check, including anything from MCP connectors, skills, and plugins. Enforcement on model output is planned, not shipped, so nothing yet reads what Claude writes back. Ask every AI vendor at renewal whether their control runs before generation or after.
Watch This
Snyk's second agentic adoption report puts the real AI footprint at roughly three times a model inventory. Security teams see about a third of it. Expect an AI inventory request in your next audit, and expect it to be hard to answer.
The DoGood network exists so IT leaders at $100M+ companies can put a question like this to a peer who already answered it, instead of to a vendor. Who owns the AI inventory at your company is a good place to start.
Know a CIO who needs this? Forward it and they can subscribe here.
Enterprise IT leader at a $100M+ company? Apply to join DoGood.
