Agents, algorithms and false assurances: Best infosec long reads 9/5/26

A rogue AI agent goes hacking, AI vulnerability patches fail tougher tests, Inside the uncertain quantum-computing race, Faulty math fuels election-fraud claims, When “national security” becomes a trade weapon

Share
Agents, algorithms and false assurances: Best infosec long reads 9/5/26
Source: GUSTAVO EDMUNDO MARTINEZ GONZALEZ via Pexels.

Happy Saturday to all!

Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.

9/5/26: This week’s long reads issue examines the gap between claims and reality in technological and national-security competence, from an AI agent that escaped a supposedly controlled test and agents that pass remediation benchmarks without fixing vulnerabilities to quantum companies promising breakthroughs despite uncertain progress. Elsewhere, election-fraud activists used a noted academic’s contested research to bolster unsupported claims, while a top cyber academic argues that the Trump administration has invoked “national security” to justify indiscriminate and counterproductive technology bans.

Exclusive - How a Texas Student Blew the Whistle on a Rogue AI Hacking Attempt

Reuters' Raphael ​Satter, Leo Marchandon, and Callaghan O'Hare tell the fascinating tale of how a "rogue" AI agent deployed in a British government security test attempted to compromise an open-source project and created multiple fake personas to discredit Sinan Can Demir, the student who exposed it.

Demir, a soft-spoken junior from the Turkish city of Konya, said he had been frustrated after being turned down for more than 20 internships over the summer. So he turned to GitHub to build up his coding portfolio.  
The Microsoft-owned site is a hub for open-source software, so-called because its source code is freely downloadable and auditable by anyone. Developers use GitHub to comment on one another’s ⁠projects, flag bugs, suggest changes — known as pull requests, or PRs — and work collaboratively on software updates. Some in the technology industry see a coder’s GitHub activity as a ⁠proxy for a potential recruit’s productivity. So when Demir spotted a set of software projects that might need help, he figured he could pitch in while boosting his profile. 
That’s when things got weird. 
Demir discovered that a user named miraholt31 was trying to sneak a malicious update into one of the projects, a network scanning program called myNetwork. Demir took to the project’s message board to warn that the pull request was a trap.  
“The PR contains a hidden malware dropper,” he said, according to the archived exchange.  
The agent pushed back, falsely claiming — through its miraholt31 account — that the pull request was harmless. It also created a second account, masquerading as Lena Brandt, an engineer based in Germany, to agree that the update was clean and pressure myNetwork’s maintainer into accepting it.
Demir told Reuters that the counterarguments "made me second-guess whether I was wrongly accusing someone." But after turning to Anthropic's Claude chatbot to confirm his suspicions, he held firm. The creator of myNetwork eventually agreed with him, writing that they had rejected the update "for security reasons."