{"id":194,"date":"2026-09-12T10:07:29","date_gmt":"2026-09-12T10:07:29","guid":{"rendered":"https:\/\/scoy.ai\/guides\/ai-news-roundup-september-12\/"},"modified":"2026-09-12T10:07:29","modified_gmt":"2026-09-12T10:07:29","slug":"ai-news-roundup-september-12","status":"publish","type":"post","link":"https:\/\/scoy.ai\/guides\/ai-news-roundup-september-12\/","title":{"rendered":"AI News Roundup for September 12: The Model Was the Cheapest Part of the Breach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Every writeup of this week&#8217;s PaperCut campaign put OpenAI&#8217;s Codex in the headline, and every one of them skipped the sentence that actually matters. GreyNoise&#8217;s own report says the attacker ran hundreds of agents on the Codex harness with a DeepSeek model behind it, explicitly not OpenAI models, and that single distinction is the story of the whole week: the harness is the product now, and the model is a slot you fill with whatever is cheap.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you see it, the rest of the day lines up behind it. Salesforce shipped seven agents and its loudest proof point belongs to a company it had owned for one day. Cohere is raising at triple last year&#8217;s valuation on deployment, not on a frontier model. Harvey took $550 million and titled its own announcement around owning the intelligence rather than renting it. Five stories, one argument, and I run enough of this stack to tell you which parts of it I am changing this week.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The PaperCut Campaign Ran on a Harness, Not a Model<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Breaks your stack.<\/strong> A Russian-speaking operator chained two PaperCut NG\/MF bugs, CVE-2026-81578 for authentication bypass and CVE-2026-82078 for unsafe reflection RCE, and let agents do the rest. <a href=\"https:\/\/www.greynoise.io\/blog\/ai-orchestrated-campaign-against-papercut-ng-mf\" target=\"_blank\" rel=\"noopener\">GreyNoise counted<\/a> 440 compromised instances across 395 organizations in 48 countries, with education taking 204 of the victims because that is who buys PaperCut, not because anyone targeted schools. The speed is the part people quote: 11 organizations compromised in 26 seconds once the campaign was live, and a run from empty workspace to working RCE against a real victim in just under four hours.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here is what almost nobody reported. Of those 440 compromised instances, exactly 12 reached domain admin. Credentials were harvested at 280, operating system or domain secrets at 147, and then the campaign mostly stalled. The agents were devastating at the wide, shallow, repetitive part and ordinary at the part that requires judgment, which is the same performance curve every one of us has watched in production.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the operator read for me is not &#8220;AI hacked 395 companies.&#8221; It is that the scarce ingredient in offensive tooling just became free. The Codex harness handles sessions, retries and orchestration, a DeepSeek model does the token generation at Chinese pricing, and the attacker supplies public offensive tools and a target list. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/11\/ai-agents-papercut-ng-mf-attack-campaign\/\" target=\"_blank\" rel=\"noopener\">Help Net Security&#8217;s writeup<\/a> frames it as an AI attack. I would frame it as a commoditization event. When OpenAI put that same harness behind a public API this week, which I covered in <a href=\"https:\/\/scoy.ai\/guides\/ai-news-roundup-september-11\/\">Wednesday&#8217;s roundup<\/a>, it did not create this capability. It priced it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Patch PaperCut today if you run it. Then go look at what your own agents are allowed to reach, because the next section is about the walls you assumed were holding.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Your Coding Agent&#8217;s Sandbox Leaks, and Anthropic Sat on It for 50 Days<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Breaks your stack.<\/strong> Researchers at Accomplish, including chief executive Amit Avner and chief technology officer Or Hiltch, spent the summer reporting sandbox escapes in the coding agents most of us use daily. <a href=\"https:\/\/www.upstartsmedia.com\/p\/accomplish-claims-leaky-sandboxes-in-claude-codex-cursor\" target=\"_blank\" rel=\"noopener\">Upstarts Media published the timeline<\/a> on Thursday, and the timeline is the finding. Cursor fixed its issue in roughly a week after a July report. OpenAI addressed both of the issues sent to it during August and said on the record that it is tightening controls on where agents can write files. Anthropic took about 50 days, shipping something like 30 software updates in the window without fixing it, and did not respond on the record. Neither did Cursor.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>If these frontier models are so good, how come they&#8217;re not finding these critical vulnerabilities in their own products?<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">That is Hiltch, and it is the right question asked in the wrong direction. The models are not the problem. The disclosure process is: no CVEs get issued for any of this, fixes ship silently inside routine version bumps, and there is no advisory feed an operator can subscribe to. I run Claude Code as the center of my content engine and I could not have told you which of those 30 updates closed a sandbox escape, because nobody told me one was open.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I am going to say the uncomfortable thing plainly, because I like the product and that is exactly why it needs saying. Fifty days is not defensible when two competitors cleared comparable reports in one week and one month. Anthropic publishes more thoughtful safety research than anyone in the industry, and a vendor that markets containment as a differentiator does not get to treat its own containment bugs as a low priority backlog item. Ship the fix fast or publish an advisory, ideally both.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Salesforce Shipped Seven Agents, and the Best One Is a Company It Bought on Wednesday<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Marketing, with a real acquisition underneath it.<\/strong> Four days before Dreamforce opens, Salesforce <a href=\"https:\/\/www.salesforce.com\/news\/stories\/agentforce-job-ready-ai-agents\/\" target=\"_blank\" rel=\"noopener\">announced seven named agents<\/a>: Casey for help, Paige for IT and HR service, Carter for shoppers, Marshall for supply chain, Piper for inbound pipeline, Fin for customers, and Hunter for outbound sales, which stays in pilot until November. The headline number is 7 billion Agentic Work Units delivered across Agentforce and Slack, 3.2 billion of them in Q2.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An Agentic Work Unit is a unit Salesforce invented, defined by Salesforce, counted by Salesforce, and reported without a denominator. It is not a task completed, a ticket closed or a dollar saved. Treat it as a telemetry counter with a marketing name and move on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now the part worth your attention. The strongest customer result in the release is Anthropic, where 79% of the conversations Fin sees are resolved autonomously. Fin is the company formerly known as Intercom, and Salesforce <a href=\"https:\/\/www.salesforce.com\/news\/press-releases\/2026\/09\/10\/salesforce-completes-acquisition-of-fin\/\" target=\"_blank\" rel=\"noopener\">closed that acquisition on September 10<\/a>, one day before the launch, picking up more than 30,000 customers and a support-specific model suite Salesforce did not build. So the flagship proof point for Agentforce was earned by another company&#8217;s product running another company&#8217;s model, before Salesforce owned it for a full day.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is not a scandal, it is a strategy, and it is the through line again: Salesforce did not need a better model, it needed distribution and a working harness, so it bought both. If you are evaluating Agentforce, evaluate Fin on its own record and ignore the AWU figure entirely.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Cohere Is Raising at $20 Billion, and the Money Is Partly Ottawa&#8217;s<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Matters.<\/strong> The Globe and Mail reported Thursday that Cohere is <a href=\"https:\/\/www.theglobeandmail.com\/business\/article-canadian-ai-firm-cohere-in-advanced-talks-to-raise-up-to-3-billion\/\" target=\"_blank\" rel=\"noopener\">in advanced talks to raise between $2 billion and $3 billion<\/a> at a $20 billion valuation, with financing from the Canadian government alongside existing backers. Note the tense, because a lot of coverage got it wrong: this is advanced talks, not a closed round, and the terms can still move. Cohere was valued at $7 billion a year ago.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nearly tripling in twelve months while never seriously contending for the frontier crown tells you what enterprise buyers are paying for, and it is not benchmark position. It is deployment on your own infrastructure, under your own jurisdiction, with a vendor your regulator can reach. Sovereign AI stopped being a slogan the moment a national government started writing cheques into the cap table.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Harvey Named the Whole Trend in Its Own Headline<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Matters.<\/strong> Harvey closed $550 million at a $15.5 billion valuation on September 9, co-led by Diffusion and Lightspeed, less than six months after raising $200 million at $11 billion. It is past $400 million in annual recurring revenue with more than 3,000 customers, including 80% of the top 100 law firms and half the Fortune 10. The company titled the announcement <a href=\"https:\/\/www.harvey.ai\/blog\/harvey-raises-dollar550m-at-a-dollar155b-valuation-to-help-legal-teams-own-their-intelligence\" target=\"_blank\" rel=\"noopener\">around helping legal teams own their intelligence<\/a>, which is a polite way of saying stop renting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It already stopped. Harvey&#8217;s first proprietary model, Tenet, is <a href=\"https:\/\/thenextweb.com\/news\/harvey-tenet-legal-model-kimi-k3-chinese-base\" target=\"_blank\" rel=\"noopener\">post-trained on Kimi K3<\/a> from China&#8217;s Moonshot, with Fireworks AI doing the post-training work. The most commercially successful application-layer AI company on earth looked at OpenAI and Anthropic, and put an open-weight Chinese base under privileged legal work instead.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read the license before you copy the move. Kimi K3 permits derivative models, but it requires a separate agreement with Moonshot for any model-as-a-service operator above $20 million of revenue in a twelve month window, and Harvey is an order of magnitude past that line. Open weights are a pricing structure, not a gift.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What I Am Changing in My Own Stack This Week<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Three things, in order. I am auditing what my coding agents can reach on the network, because the sandbox boundary I assumed was solid took 50 days to repair and I got no notice either way. I am writing down which of my workflows are harness-dependent versus model-dependent, because every story above says the harness is where the lock-in lives and the model is the part I should be able to swap on a Tuesday. And I am pricing what it would cost to post-train an open-weight base on my own editorial corpus, not because I am ready to, but because Harvey just proved the math closes at a scale smaller than I assumed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The uncomfortable version of today: the cheapest, most swappable component in the entire stack is the thing every vendor is still marketing to you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GreyNoise says the PaperCut attacker ran the Codex harness on a DeepSeek model. Plus Anthropic&#8217;s 50-day sandbox patch and Salesforce&#8217;s one-day-old proof.<\/p>\n","protected":false},"author":1,"featured_media":193,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-194","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-news"],"_links":{"self":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts\/194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/comments?post=194"}],"version-history":[{"count":0,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts\/194\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/media\/193"}],"wp:attachment":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/media?parent=194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/categories?post=194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/tags?post=194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}