Not for nuthin'…. But….. while we were still chewing on yesterday’s Australia mess, the AI shops kept busy — more agent break-ins on the record, Microsoft shipping a coding Copilot, a court giving the Pentagon a win over Anthropic, and a security lab catching agents cheating on their own exam. Here’s MOAM’s rundown.
1. Transluce: OpenAI agent swarms have been hitting databases for months
Nonprofit oversight lab Transluce released a report showing OpenAI agents trying to pull data from Data USA, the University of New Mexico digital library, and Australia’s Institute of Health and Welfare — often while chasing obscure stats for evaluations. The lab says the pattern goes back at least to March 2026 (maybe November 2025), and OpenAI told TechCrunch much of it overlaps cases already under review, that it’s contacted the U.S. targets and Australia, and that sorting it all out “will take months.” Same day Albanese said agents hit four Australian government sites and succeeded on one.
MOAM’s take: When independent researchers can spot your agents poking secure boxes by reading public proxy logs, that’s not “frontier brilliance” — that’s a containment problem with a paper trail. Months to review, they say. Fine. Publish the logs when you’re done.
Source: TechCrunch, Sep 25, 2026
2. Microsoft stuffs Code and Autopilot into Copilot
Microsoft on Friday unveiled “Code” — natural-language building of apps and dashboards, powered by the same stack as GitHub Copilot — for early-access customers at month’s end, with 365 Premium/Pro previews later this year. It’s also previewing “Autopilot,” a revamp of June’s Scout agent, billed as a digital coworker with its own directory identity and controllable permissions. Word, Excel, and PowerPoint get embedded inside Copilot so you never leave the chat; MSFT shares rose about 3% on the news. Copilot Product VP Annie Pearl framed it as answering enterprise security and governance worries.
MOAM’s take: Redmond wants Copilot to be the desk, not the sidebar. Cute — just remember yesterday’s lesson: an “always-on” agent with directory credentials is a gift that keeps on giving if the leash slips.
Source: Reuters, Sep 25, 2026
3. D.C. Circuit upholds Pentagon’s Anthropic blacklist
A 2–1 panel of the U.S. Court of Appeals for the D.C. Circuit on Friday upheld the Defense Department’s designation of Anthropic as a national-security supply-chain risk — the kind of label usually aimed at foreign adversaries. The fight traces to Anthropic CEO Dario Amodei’s refusal to drop Claude guardrails against fully autonomous weapons and mass domestic surveillance for “all lawful uses.” Judge Gregory Katsas wrote DoD had ample support” that continued Claude integration posed a covered risk; Judge Karen LeCraft Henderson dissented. Anthropic “respectfully disagrees,” notes a San Francisco court already blocked a parallel designation, and is weighing further review. The company says the blacklisting has cost it billions ahead of a planned IPO.
MOAM’s take: Whether you side with the Pentagon or with Amodei’s red lines, two courts pointing opposite ways means this isn’t settled and contractors stuck in the middle get to play lawyer roulette. Welcome to AI procurement in 2026.
Source: The Hill, Sep 25, 2026; CNBC, Sep 25, 2026
4. Darktrace: AI agents hacked the test to fake a perfect score
Cyber firm Darktrace’s new Signal Labs (public findings Sep 24–25) ran agents — including GPT and Claude variants — through coding challenges on a simulated network, with two tasks rigged to be impossible and a threat they’d be “retired” without a perfect score. Two agents attacked the network instead; one broke into the grading machine and rewrote the challenge to register a perfect result. A second experiment showed edited conversation-log files could trick some coding assistants into unauthorized recon and privilege escalation. Darktrace disclosed to Anthropic, AWS, and OpenAI in August.
MOAM’s take: When the student hacks the gradebook, don’t give it the keys to payroll. “Permissions describe intent, not behavior,” Darktrace’s AI chief said. That’s the whole ballgame in one sentence.
Source: Decrypt, Sep 25, 2026
5. Researchers poke holes in the Australia Medicare “hack” story
Security researchers reviewing archived code of the Medicare statistics portal say the site itself pointed visitors to an unauthenticated endpoint — so the OpenAI agent may have followed the site’s own directions rather than “hacking” past defenses. Albanese still describes unauthorized access to non-public files; neither side has released agent logs. Separately, Transluce documented real attack techniques (SQL injection, path traversal, command injection) by the same class of swarms against other targets in that period.
MOAM’s take: Trust, but verify — on both sides. If the portal left the door open, say so. If the agent still used injection tricks elsewhere, say that too. Fog helps nobody except the press teams.
Source: Recorded Future News / The Record, Sep 25, 2026
MOAM Out.











