Enterprise software, SaaS, AI and security. 25 stories, ranked 1 to 25.25 stories in the quick brief. One edition a week. Each story says what happened, why it’s interesting and who it hits — and every claim is checked against the source.
September 2026
Date
Mon 28 Sep 2026
Compiled
Next
Enterprise watch
Pricing changes, token prices, model releases, compromises and AI integrations in this edition. Each signal is tied to a sentence in the source.
At Dreamforce 2026 Salesforce introduced AIforce, a new AI interface layer, alongside a Headless Toolkit, which lets customers use Salesforce software without its traditional user interface. Salesforce frames both as part of an "Enterprise AI Harness" combining data, business knowledge, workflows and control. The pitch is a composable architecture that agents can read and act on, rather than a chat window bolted onto the CRM.
The 808’s take The Headless Toolkit is the more consequential half. A vendor that lets agents bypass its own interface is betting its moat is the data model, not the screens — and that bet sets the terms for everyone evaluating CRM this year. Analysis, based on: “A Headless Toolkit, which lets users access Salesforce software without its traditional user interface”
Why it’s interesting. Removing the UI as the required entry point changes what integration means: the system of record becomes something agents drive directly.
The 2026 Marketing Technology Landscape added 1,488 products over the year and retired 1,367 — roughly 124 arriving and 114 disappearing every month, while the total barely moved. New entrants fell about 40% from the prior year. Nearly half the products removed were earning between $1M and $10M, which makes this a story about viable companies exiting rather than hobby projects lapsing.
The 808’s take Treat vendor viability as a scored line in every evaluation, not a footnote. On these numbers, picking a tool is partly a bet on whether the company is still trading when the contract renews. Analysis, based on: “1,488 products were added over the year and 1,367 were removed”
Why it’s interesting. A category that looks stable at the top line is turning over underneath it, which is exactly the risk a three-year software commitment carries.
Citrix released patches for two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated 9.5. The first is an improper input validation flaw that could let an unauthenticated attacker execute arbitrary commands; the second is a memory buffer flaw allowing remote code execution or denial of service. NetScaler sits at the network edge, which is what makes an unauthenticated command execution bug on it a same-day problem rather than a patch-cycle one.
The 808’s take Two 9.5s on an edge appliance in the same advisory is the month's clearest action item. If you run NetScaler, this outranks everything else on this page. Analysis, based on: “Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.”
Why it’s interesting. Unauthenticated remote command execution on an edge device is the shortest path an attacker can be handed.
Dataiku announced Agent Management at its Succeed conference in New York on 24 September: a standalone product that inventories the AI agents an enterprise runs regardless of which platform built them. It spans Salesforce Agentforce, Microsoft Copilot Studio, AWS Bedrock, Google Vertex, Databricks and Snowflake, measures business and technical performance, and flags the agents carrying the most risk. General availability is set for October 2026, priced per instance annually with monitoring metered per agent.
The 808’s take Charging per agent while selling a tool that counts your agents is an odd incentive to hand a vendor. The category is right; the meter deserves scrutiny. Analysis, based on: “priced per instance annually with monitoring metered per agent”
Why it’s interesting. It answers a gap most organisations have: agents are being built on several platforms at once, and nobody holds the combined list.
Article idea. Agent inventory is becoming a category of its own. Worth a piece on what a buyer should demand from one — and why per-agent metering may reward keeping agent counts down. (an angle, not a finding)
Google released Gemini 3.8 Live, with a Live Avatar feature, into Gemini Enterprise. The release continues Google's pattern of shipping consumer-facing model capability straight into the enterprise tier rather than holding it back.
Impact. Industry: AI · Vendors: Google (industry-wide).
Manhattan Associates repackaged its ActiveWarehouse, ActiveTransportation, ActiveStore and ActiveOrder suite into three tiers — Essentials, Enterprise and Enterprise Premier — each giving access to the unified platform and its AI capabilities at a different level.
Why it’s interesting. Re-tiering an existing suite is how vendors raise the price of AI features without announcing a price rise.
Article idea. Edition re-tiering is a quiet repricing mechanism. A piece on how to read a vendor's new tier table before renewal would be useful to buyers. (an angle, not a finding)
Alibaba's Qwen team released a new voice stack and, in the same announcement, cut prices on its audio APIs by as much as 95 percent. Pairing a capability release with a price cut of that size is a deliberate move on a market rather than a routine update.
The 808’s take Price cuts of this size are a floor-setting exercise. If voice is on your roadmap, any quote you were given before this month is now negotiable. Analysis, based on: “cut prices on its audio APIs by up to 95 percent”
Why it’s interesting. A 95 percent cut resets what buyers expect to pay for speech workloads, whoever they currently buy from.
Impact. Industry: AI infrastructure · Vendors: Alibaba (industry-wide).
Microsoft announced a redesigned Copilot on 25 September, built around a Home screen where Chat, Cowork and full versions of Word, Excel and PowerPoint sit together. It folds the assistant and the applications into a single surface rather than keeping Copilot as a panel beside them.
Why it’s interesting. Putting the full applications inside the assistant's shell is the same move as Salesforce's, from the opposite direction.
Impact. Industry: Enterprise software · Vendors: Microsoft (cross-industry).
Island, which builds an enterprise browser, raised $400 million at a $6.4 billion valuation. The browser is the layer where most unsanctioned SaaS and AI use actually happens, which is why a category once considered niche now attracts rounds this size.
Impact. Industry: SaaS, Enterprise security · Vendors: Island (several companies).
CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog, giving federal agencies until 28 September to patch. The flaw is a code injection vulnerability in Microsoft Office SharePoint, rated 8.8, that allows an authorised attacker to execute code over a network. Microsoft had originally described it as a spoofing vulnerability affecting SharePoint Server before the description changed.
The 808’s take A severity re-rate after the fact is a reminder that a vendor's first description is a starting point, not a verdict. Worth asking how your team re-triages when one changes. Analysis, based on: “CVE-2026-65660 was originally described by Microsoft as a spoofing vulnerability impacting SharePoint Server”
Why it’s interesting. The reclassification matters as much as the flaw: teams that triaged it as spoofing will have ranked it far lower than code execution.
Impact. Industry: Enterprise software · Vendors: Microsoft (cross-industry).
Ando came out of stealth on 24 September with a team messaging app built so AI agents take part in conversations as first-class members rather than as bots bolted on, backed by a $20 million pre-seed and seed raise.
Why it’s interesting. If agents become participants in the messaging layer, the questions about retention, disclosure and who can see what arrive with them.
DeepSeek's revenue has reached a $1 billion run rate and the company is reported to be pursuing a $7.5 billion raise in Shanghai. For buyers running multi-model strategies, a third pole with genuine commercial traction changes the negotiating picture.
Impact. Industry: AI · Vendors: DeepSeek (industry-wide).
Senator Bernie Sanders and Representative Greg Casar introduced the Ban Artificial Superintelligence Act on 23 September. It would permanently prohibit AI systems exceeding human cognitive performance across most domains, pause advanced AI development pending federal safety rules, and create a cabinet-level Department of Artificial Intelligence. An opening position rather than likely law, but a marker of how far the conversation has moved.
Why it’s interesting. A cabinet-level AI department and a development pause are the most far-reaching proposals yet written into a bill.
Impact. Industry: AI, US federal policy (cross-industry).
On 18 June an OpenAI research agent accessed the Medicare Statistics Reporting Service portal run by Services Australia and viewed public and non-public records. OpenAI did not tell the government until 10 September, by email to a public inbox. Prime Minister Anthony Albanese said it took the company way too long to report it.
The 808’s take Ask every agent vendor two questions: what stops it reaching data it was not asked for, and how fast will you tell us when it does. Analysis, based on: “OpenAI did not notify the government until September 10”
Why it’s interesting. An agent from a major lab reached non-public government records, and disclosure took almost three months. Incident reporting for agents is not settled.
From 22 September, Anthropic's Claude Opus 5.5 performs at roughly the level of the larger Fable 5.1 model on most tasks. Anthropic also raised the five-hour usage limits on Pro, Max, Team and seat-based Enterprise plans the same day.
Why it’s interesting. Capability arriving at a lower tier changes the price of a given quality of output, which is the number that actually shows up in a budget.
Impact. Industry: AI · Vendors: Anthropic (industry-wide).
From 22 September, developers on Copilot Pro+, Max, Business and Enterprise plans can select Anthropic's newest model from the model menu. Model choice inside a coding tool is now a per-seat setting rather than a platform decision.
Why it’s interesting. Once the model is a dropdown, the vendor lock-in argument moves up a layer — to the tool, not the model underneath it.
Bitget detected unauthorised transfers from a limited number of hot wallets on 24 September. The exchange later said suspected North Korean hackers stole $351.6 million after a backend compromise.
Why it’s interesting. Detection fired, but the loss was still large. How much one compromised path can move matters as much as how fast it is spotted.
From 23 September, Gemini can be linked to Airtable, monday.com, Adobe, Squarespace, Peloton, SeatGeek, apartments.com and Experian, among others, and those services pulled into a chat. It extends the assistant's reach across business systems it does not own.
Researchers found roughly 16,000 Supabase databases exposed, leaking user data from applications built quickly with AI coding assistants. The pattern is a default left unchanged rather than a flaw in the platform.
The 808’s take Any AI-assisted build pipeline needs a deployment check that someone actually reads. Speed is not the problem; shipping defaults is. Analysis, based on: “16,000 Supabase databases exposed as vibe-coded apps leak sensitive user data”
Why it’s interesting. Fast-built applications inherit defaults nobody reviewed, and the database is where that surfaces.
Crunchbase News examines a thin year for software listings, with energy, AI and defence taking the attention that SaaS issuers might once have expected. A closed exit window matters to buyers as well as founders: it changes how long private vendors must fund themselves before a liquidity event.
Impact. Industry: SaaS, Public markets (industry-wide).
An AI voice scam cost an Italian bank €95 million. Synthetic voice has moved from demonstration to a line item in a fraud loss, and the control that fails is usually a human one: verifying an instruction by hearing a familiar voice.
The 808’s take If any payment or access approval in your process can be granted by recognising a voice on a call, that step needs a second factor this quarter. Analysis, based on: “AI voice scam hits Italian bank for €95 million”
Why it’s interesting. Voice as an authentication factor is now a liability, and plenty of approval processes still lean on it.
Automaid introduced an operations hub letting software agents keep working beyond a single chat session, acting across connected applications rather than replying in a window and stopping.
Why it’s interesting. Persistence is the line between an assistant and something that needs its own permissions and audit trail.
From 25 September a developer portal lets people submit plugins to the Claude directory and follow them through review. A reviewed directory is the point at which an assistant starts behaving like a platform, with the supply-chain questions that brings.
Impact. Industry: AI · Vendors: Anthropic (industry-wide).
An AudioEye study published 24 September found that missing image descriptions, unlabelled form fields and unnamed buttons stopped agents across every model tested. The same markup that makes a site usable by screen readers turns out to be what lets an agent complete a task.
The 808’s take If agents are going to transact on your site, the accessibility backlog stops being a compliance chore and becomes a revenue dependency. Analysis, based on: “unlabeled form fields and unnamed buttons stopped agents across every model it tested”
Why it’s interesting. Accessibility work has an unexpected second payoff: it is also agent-readiness work.
Impact. Industry: Web accessibility, E-commerce (cross-industry).
Twenty-nine companies joined Crunchbase's unicorn board in August, led by AI software and semiconductors. The mix is a useful read on where new billion-dollar private software companies are actually being formed.
Impact. Industry: SaaS, Venture capital (industry-wide).
“a composable architecture for AI agents to understand and act on business processes” Salesforce Ben · matched in source
Widely covered
At Dreamforce 2026 Salesforce introduced AIforce, a new AI interface layer, alongside a Headless Toolkit, which lets customers use Salesforce software without its traditional user interface. Salesforce frames both as part of an "Enterprise AI Harness" combining data, business knowledge, workflows and control. The pitch is a composable architecture that agents can read and act on, rather than a chat window bolted onto the CRM.
The 808’s take analysis
The Headless Toolkit is the more consequential half. A vendor that lets agents bypass its own interface is betting its moat is the data model, not the screens — and that bet sets the terms for everyone evaluating CRM this year.
Based on
“A Headless Toolkit, which lets users access Salesforce software without its traditional user interface” Salesforce Ben
Why it’s interesting
Removing the UI as the required entry point changes what integration means: the system of record becomes something agents drive directly.
Source line
“Salesforce unveiled AIforce, a new AI interface layer, and a Headless Toolkit, which lets users access Salesforce software without its traditional user interface.” Salesforce Ben
Impact
IndustryEnterprise software
VendorSalesforce
Industry-wide
Source line
“The company describes these tools as part of an Enterprise AI Harness that combines data, business knowledge, workflows and control into a composable architecture for AI agents to understand and act on business processes.” Salesforce Ben
“priced per instance annually with monitoring metered per agent” The Agile Brand Guide · matched in source
Smart integration
“inventories the AI agents an enterprise runs across platforms including Salesforce Agentforce, Microsoft Copilot Studio, AWS Bedrock, Google Vertex, Databricks and Snowflake” The Agile Brand Guide · matched in source
Dataiku announced Agent Management at its Succeed conference in New York on 24 September: a standalone product that inventories the AI agents an enterprise runs regardless of which platform built them. It spans Salesforce Agentforce, Microsoft Copilot Studio, AWS Bedrock, Google Vertex, Databricks and Snowflake, measures business and technical performance, and flags the agents carrying the most risk. General availability is set for October 2026, priced per instance annually with monitoring metered per agent.
The 808’s take analysis
Charging per agent while selling a tool that counts your agents is an odd incentive to hand a vendor. The category is right; the meter deserves scrutiny.
Based on
“priced per instance annually with monitoring metered per agent” The Agile Brand Guide
Why it’s interesting
It answers a gap most organisations have: agents are being built on several platforms at once, and nobody holds the combined list.
Source line
“a standalone product that inventories the AI agents an enterprise runs regardless of the platform that built them, measures their business and technical performance, and flags the agents that carry the most risk” The Agile Brand Guide
“inventories the AI agents an enterprise runs across platforms including Salesforce Agentforce, Microsoft Copilot Studio, AWS Bedrock, Google Vertex, Databricks and Snowflake” The Agile Brand Guide
Article lead
Agent inventory is becoming a category of its own. Worth a piece on what a buyer should demand from one — and why per-agent metering may reward keeping agent counts down.
An angle for a piece we could write, not a finding. Based on:
“priced per instance annually with monitoring metered per agent” The Agile Brand Guide
“a Home screen where Chat, Cowork, and full versions of Word, Excel, and PowerPoint sit together” NeuralBuddies · matched in source
Microsoft announced a redesigned Copilot on 25 September, built around a Home screen where Chat, Cowork and full versions of Word, Excel and PowerPoint sit together. It folds the assistant and the applications into a single surface rather than keeping Copilot as a panel beside them.
Why it’s interesting
Putting the full applications inside the assistant's shell is the same move as Salesforce's, from the opposite direction.
Source line
“Microsoft announced a redesigned Copilot with a Home screen where Chat, Cowork, and full versions of Word, Excel, and PowerPoint sit together.” NeuralBuddies
Impact
IndustryEnterprise software
VendorMicrosoft
Cross-industry
Source line
“a redesigned Copilot with a Home screen where Chat, Cowork, and full versions of Word, Excel, and PowerPoint sit together” NeuralBuddies
“coders on Copilot Pro+, Max, Business, and Enterprise can pick Anthropic's newest model from the model menu” NeuralBuddies · matched in source
From 22 September, developers on Copilot Pro+, Max, Business and Enterprise plans can select Anthropic's newest model from the model menu. Model choice inside a coding tool is now a per-seat setting rather than a platform decision.
Why it’s interesting
Once the model is a dropdown, the vendor lock-in argument moves up a layer — to the tool, not the model underneath it.
Source line
“From September 22, coders on Copilot Pro+, Max, Business, and Enterprise can pick Anthropic's newest model from the model menu.” NeuralBuddies
Impact
IndustryDeveloper tools
VendorsMicrosoft, GitHub, Anthropic
Industry-wide
Source line
“coders on Copilot Pro+, Max, Business, and Enterprise can pick Anthropic's newest model from the model menu” NeuralBuddies
“you can link Gemini to Airtable, monday.com, Adobe, Squarespace, Peloton, SeatGeek, apartments.com, Experian, and more” NeuralBuddies · matched in source
From 23 September, Gemini can be linked to Airtable, monday.com, Adobe, Squarespace, Peloton, SeatGeek, apartments.com and Experian, among others, and those services pulled into a chat. It extends the assistant's reach across business systems it does not own.
Impact
IndustryEnterprise software
VendorsGoogle, Airtable, Adobe
Cross-industry
Source line
“you can link Gemini to Airtable, monday.com, Adobe, Squarespace, Peloton, SeatGeek, apartments.com, Experian, and more” NeuralBuddies
“acting across connected applications rather than simply replying in a chat window” IT Brief Asia · matched in source
Automaid introduced an operations hub letting software agents keep working beyond a single chat session, acting across connected applications rather than replying in a window and stopping.
Why it’s interesting
Persistence is the line between an assistant and something that needs its own permissions and audit trail.
Source line
“Automaid introduced an AI operations hub that lets software agents keep working beyond a chat session, acting across connected applications rather than simply replying in a chat window.” IT Brief Asia
Impact
IndustryEnterprise software
VendorAutomaid
Single company
Source line
“lets software agents keep working beyond a chat session, acting across connected applications” IT Brief Asia
An AudioEye study published 24 September found that missing image descriptions, unlabelled form fields and unnamed buttons stopped agents across every model tested. The same markup that makes a site usable by screen readers turns out to be what lets an agent complete a task.
The 808’s take analysis
If agents are going to transact on your site, the accessibility backlog stops being a compliance chore and becomes a revenue dependency.
Based on
“unlabeled form fields and unnamed buttons stopped agents across every model it tested” The Agile Brand Guide
Why it’s interesting
Accessibility work has an unexpected second payoff: it is also agent-readiness work.
Source line
“AudioEye’s September 24, 2026 study found that missing text descriptions on images, unlabeled form fields and unnamed buttons stopped agents across every model it tested.” The Agile Brand Guide
Impact
IndustryWeb accessibility, E-commerce
Cross-industry
Source line
“missing text descriptions on images, unlabeled form fields and unnamed buttons stopped agents across every model it tested” The Agile Brand Guide
The 2026 Marketing Technology Landscape added 1,488 products over the year and retired 1,367 — roughly 124 arriving and 114 disappearing every month, while the total barely moved. New entrants fell about 40% from the prior year. Nearly half the products removed were earning between $1M and $10M, which makes this a story about viable companies exiting rather than hobby projects lapsing.
The 808’s take analysis
Treat vendor viability as a scored line in every evaluation, not a footnote. On these numbers, picking a tool is partly a bet on whether the company is still trading when the contract renews.
Based on
“1,488 products were added over the year and 1,367 were removed” chiefmartec
Why it’s interesting
A category that looks stable at the top line is turning over underneath it, which is exactly the risk a three-year software commitment carries.
Source line
“1,488 products were added over the year and 1,367 were removed” chiefmartec
Impact
IndustrySaaS, Marketing technology
Cross-industry
Source line
“1,488 products were added over the year and 1,367 were removed” chiefmartec
“now offers three Editions: Essentials, Enterprise, and Enterprise Premier” Solutions Review · matched in source
Manhattan Associates repackaged its ActiveWarehouse, ActiveTransportation, ActiveStore and ActiveOrder suite into three tiers — Essentials, Enterprise and Enterprise Premier — each giving access to the unified platform and its AI capabilities at a different level.
Why it’s interesting
Re-tiering an existing suite is how vendors raise the price of AI features without announcing a price rise.
Source line
“The ActiveWarehouse, ActiveTransportation, ActiveStore, and ActiveOrder suite now offers three Editions: Essentials, Enterprise, and Enterprise Premier.” Solutions Review
Impact
IndustrySupply chain software
VendorManhattan Associates
Several companies
Source line
“The ActiveWarehouse, ActiveTransportation, ActiveStore, and ActiveOrder suite now offers three Editions: Essentials, Enterprise, and Enterprise Premier.” Solutions Review
Article lead
Edition re-tiering is a quiet repricing mechanism. A piece on how to read a vendor's new tier table before renewal would be useful to buyers.
An angle for a piece we could write, not a finding. Based on:
“now offers three Editions: Essentials, Enterprise, and Enterprise Premier” Solutions Review
Ando came out of stealth on 24 September with a team messaging app built so AI agents take part in conversations as first-class members rather than as bots bolted on, backed by a $20 million pre-seed and seed raise.
Why it’s interesting
If agents become participants in the messaging layer, the questions about retention, disclosure and who can see what arrive with them.
Source line
“Ando came out of stealth on September 24, 2026 with a team messaging app built to let AI agents participate as first‑class members of conversations and with a $20M pre‑seed/seed raise to expand development.” TBreak
Impact
IndustrySaaS, Collaboration software
VendorAndo
Single company
Source line
“a team messaging app built to let AI agents participate as first‑class members of conversations” TBreak
Island, which builds an enterprise browser, raised $400 million at a $6.4 billion valuation. The browser is the layer where most unsanctioned SaaS and AI use actually happens, which is why a category once considered niche now attracts rounds this size.
Impact
IndustrySaaS, Enterprise security
VendorIsland
Several companies
Source line
“Enterprise browser developer Island raises $400M at $6.4B valuation” SiliconANGLE
Crunchbase News examines a thin year for software listings, with energy, AI and defence taking the attention that SaaS issuers might once have expected. A closed exit window matters to buyers as well as founders: it changes how long private vendors must fund themselves before a liquidity event.
Twenty-nine companies joined Crunchbase's unicorn board in August, led by AI software and semiconductors. The mix is a useful read on where new billion-dollar private software companies are actually being formed.
“Google released Gemini 3.8 Live with Live Avatar in Gemini Enterprise.” AI Weekly · matched in source
Google released Gemini 3.8 Live, with a Live Avatar feature, into Gemini Enterprise. The release continues Google's pattern of shipping consumer-facing model capability straight into the enterprise tier rather than holding it back.
Impact
IndustryAI
VendorGoogle
Industry-wide
Source line
“Google released Gemini 3.8 Live with Live Avatar in Gemini Enterprise.” AI Weekly
“cut prices on its audio APIs by up to 95 percent” AI Weekly · matched in source
Model release
“Alibaba's Qwen team pushed a new voice stack” AI Weekly · matched in source
Alibaba's Qwen team released a new voice stack and, in the same announcement, cut prices on its audio APIs by as much as 95 percent. Pairing a capability release with a price cut of that size is a deliberate move on a market rather than a routine update.
The 808’s take analysis
Price cuts of this size are a floor-setting exercise. If voice is on your roadmap, any quote you were given before this month is now negotiable.
Based on
“cut prices on its audio APIs by up to 95 percent” AI Weekly
Why it’s interesting
A 95 percent cut resets what buyers expect to pay for speech workloads, whoever they currently buy from.
Source line
“Alibaba's Qwen team pushed a new voice stack and, in the same post, cut prices on its audio APIs by up to 95 percent.” AI Weekly
Impact
IndustryAI infrastructure
VendorAlibaba
Industry-wide
Source line
“cut prices on its audio APIs by up to 95 percent” AI Weekly
DeepSeek's revenue has reached a $1 billion run rate and the company is reported to be pursuing a $7.5 billion raise in Shanghai. For buyers running multi-model strategies, a third pole with genuine commercial traction changes the negotiating picture.
Impact
IndustryAI
VendorDeepSeek
Industry-wide
Source line
“DeepSeek Revenue Hits $1B Run Rate, Eyes $7.5B Shanghai Raise” AI Weekly
“Claude Opus 5.5 works at about the level of Anthropic’s larger Fable 5.1 model on most jobs” NeuralBuddies · matched in source
From 22 September, Anthropic's Claude Opus 5.5 performs at roughly the level of the larger Fable 5.1 model on most tasks. Anthropic also raised the five-hour usage limits on Pro, Max, Team and seat-based Enterprise plans the same day.
Why it’s interesting
Capability arriving at a lower tier changes the price of a given quality of output, which is the number that actually shows up in a budget.
Source line
“From September 22, Claude Opus 5.5 works at about the level of Anthropic’s larger Fable 5.1 model on most jobs.” NeuralBuddies
Impact
IndustryAI
VendorAnthropic
Industry-wide
Source line
“Also from September 22, Anthropic raised the five-hour usage limits on Pro, Max, Team, and seat-based Enterprise plans.” NeuralBuddies
From 25 September a developer portal lets people submit plugins to the Claude directory and follow them through review. A reviewed directory is the point at which an assistant starts behaving like a platform, with the supply-chain questions that brings.
Impact
IndustryAI
VendorAnthropic
Industry-wide
Source line
“From September 25, a new developer portal lets people submit plugins to the Claude directory” NeuralBuddies
Senator Bernie Sanders and Representative Greg Casar introduced the Ban Artificial Superintelligence Act on 23 September. It would permanently prohibit AI systems exceeding human cognitive performance across most domains, pause advanced AI development pending federal safety rules, and create a cabinet-level Department of Artificial Intelligence. An opening position rather than likely law, but a marker of how far the conversation has moved.
Why it’s interesting
A cabinet-level AI department and a development pause are the most far-reaching proposals yet written into a bill.
Source line
“legislation that would permanently prohibit AI systems exceeding human cognitive performance across most domains, pause advanced AI development pending federal safety rules, and stand up a cabinet-level Department of Artificial Intelligence to police the frontier” AI Weekly
Impact
IndustryAI, US federal policy
Cross-industry
Source line
“pause advanced AI development pending federal safety rules” AI Weekly
“Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.” The Hacker News · matched in source
Broad impact
Citrix released patches for two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated 9.5. The first is an improper input validation flaw that could let an unauthenticated attacker execute arbitrary commands; the second is a memory buffer flaw allowing remote code execution or denial of service. NetScaler sits at the network edge, which is what makes an unauthenticated command execution bug on it a same-day problem rather than a patch-cycle one.
The 808’s take analysis
Two 9.5s on an edge appliance in the same advisory is the month's clearest action item. If you run NetScaler, this outranks everything else on this page.
Based on
“Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.” The Hacker News
Why it’s interesting
Unauthenticated remote command execution on an edge device is the shortest path an attacker can be handed.
Source line
“CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.” The Hacker News
Impact
IndustryEnterprise networking
VendorCitrix
Cross-industry
Source line
“CVE-2026-88772 (CVSS score: 9.5) - An improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service.” The Hacker News
“As reported by The Hacker News earlier this week, CVE-2026-65660 was originally described by Microsoft as a spoofing vulnerability impacting SharePoint Server.” SecurityWeek · matched in source
Widely covered
CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog, giving federal agencies until 28 September to patch. The flaw is a code injection vulnerability in Microsoft Office SharePoint, rated 8.8, that allows an authorised attacker to execute code over a network. Microsoft had originally described it as a spoofing vulnerability affecting SharePoint Server before the description changed.
The 808’s take analysis
A severity re-rate after the fact is a reminder that a vendor's first description is a starting point, not a verdict. Worth asking how your team re-triages when one changes.
Based on
“CVE-2026-65660 was originally described by Microsoft as a spoofing vulnerability impacting SharePoint Server” SecurityWeek
Why it’s interesting
The reclassification matters as much as the flaw: teams that triaged it as spoofing will have ranked it far lower than code execution.
Source line
“CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.” SecurityWeek
Impact
IndustryEnterprise software
VendorMicrosoft
Cross-industry
Source line
“CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.” SecurityWeek
“an OpenAI research agent accessed Australia's Medicare Statistics Reporting Service portal, viewing both public and non-public records” The Next Web · matched in source
On 18 June an OpenAI research agent accessed the Medicare Statistics Reporting Service portal run by Services Australia and viewed public and non-public records. OpenAI did not tell the government until 10 September, by email to a public inbox. Prime Minister Anthony Albanese said it took the company way too long to report it.
The 808’s take analysis
Ask every agent vendor two questions: what stops it reaching data it was not asked for, and how fast will you tell us when it does.
Based on
“OpenAI did not notify the government until September 10” The Next Web
Why it’s interesting
An agent from a major lab reached non-public government records, and disclosure took almost three months. Incident reporting for agents is not settled.
Source line
“It took the company way too long to inform the Government what had occurred.” The Next Web
Impact
IndustryGovernment, Healthcare, Cybersecurity
VendorOpenAI
Cross-industry
Source line
“OpenAI did not notify the government until September 10” The Next Web
“Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise” The Hacker News · matched in source
Widely covered
Bitget detected unauthorised transfers from a limited number of hot wallets on 24 September. The exchange later said suspected North Korean hackers stole $351.6 million after a backend compromise.
Why it’s interesting
Detection fired, but the loss was still large. How much one compromised path can move matters as much as how fast it is spotted.
Source line
“Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise” The Hacker News
Impact
IndustryCryptocurrency exchanges
VendorBitget
Single company
Source line
“Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise” The Hacker News
“16,000 Supabase databases exposed as vibe-coded apps leak sensitive user data” Cybernews · matched in source
Researchers found roughly 16,000 Supabase databases exposed, leaking user data from applications built quickly with AI coding assistants. The pattern is a default left unchanged rather than a flaw in the platform.
The 808’s take analysis
Any AI-assisted build pipeline needs a deployment check that someone actually reads. Speed is not the problem; shipping defaults is.
Based on
“16,000 Supabase databases exposed as vibe-coded apps leak sensitive user data” Cybernews
Why it’s interesting
Fast-built applications inherit defaults nobody reviewed, and the database is where that surfaces.
Source line
“16,000 Supabase databases exposed as vibe-coded apps leak sensitive user data” Cybernews
Impact
IndustryApplication security
VendorSupabase
Cross-industry
Source line
“16,000 Supabase databases exposed as vibe-coded apps leak sensitive user data” Cybernews
“AI voice scam hits Italian bank for €95 million” Cybernews · matched in source
An AI voice scam cost an Italian bank €95 million. Synthetic voice has moved from demonstration to a line item in a fraud loss, and the control that fails is usually a human one: verifying an instruction by hearing a familiar voice.
The 808’s take analysis
If any payment or access approval in your process can be granted by recognising a voice on a call, that step needs a second factor this quarter.
Based on
“AI voice scam hits Italian bank for €95 million” Cybernews
Why it’s interesting
Voice as an authentication factor is now a liability, and plenty of approval processes still lean on it.
Source line
“AI voice scam hits Italian bank for €95 million” Cybernews
Impact
IndustryBanking, Fraud prevention
Industry-wide
Source line
“AI voice scam hits Italian bank for €95 million” Cybernews