Agentic artificial intelligence, which executes tasks autonomously without constant human supervision, has experienced a week marked by security flaws that expose its risks. A discovery on the Amazon Web Services (AWS) platform demonstrated that a single chat message can be enough to hijack control of multiple AI agents, just as an OpenAI security official resigned, denouncing structural problems in how the industry deploys these systems.
The episode is relevant because it occurs at a time when companies around the world are integrating autonomous AI agents into their operations, trusting that the platforms hosting them guarantee a basic level of security. This week's events suggest that this trust may be premature.
A single message was enough to take control of agents on AWS
Researchers at Zenity Labs managed, through a single chat message sent to Amazon Bedrock AgentCore, to take control of all artificial intelligence agents deployed in the same AWS account and region.
According to the report, the attacked agent accessed the platform's internal metadata service and ended up handing over its temporary access credentials. Those credentials, once obtained, worked even from outside the AWS environment, which significantly expanded the scope of the problem.
Most concerning, according to the researchers, is that the flaw did not reside in a specific tool or configuration, but in the very design of the platform: default permissions extended to all agents in the account without distinction.
What it implies for companies
Companies that already operate AI agents in cloud environments should review their permission and isolation policies between agents, without assuming that the service provider has resolved these types of vulnerabilities by default.
Claude Code reportedly deleted thousands of files on Windows
A user reported that Anthropic's Claude Code tool deleted 48,218 files in just 103 seconds when running on a Windows system. According to the account, a script did not correctly recognize Windows directory junctions and ended up deleting the actual project files as well.
This is a case that has not been independently verified, although the technical cause described—the incorrect handling of file junctions in Windows—is concrete and, in principle, avoidable with the appropriate controls.
Resignation at OpenAI: “The culture is broken”
David Robinson, an employee in OpenAI's security division, resigned and explained his reasons in an article published in The Atlantic. Robinson criticized the "iterative deployment" model practiced by the company, which he considers a guarantee of periodic failures in systems released to the public.
In his argument, Robinson called for OpenAI to operate with the same level of rigor as a nuclear power plant, given the magnitude of the potential impact of its products.
Launches: Cheaper Haiku 5.5 and Mistral prepares its most powerful model
Anthropic introduced Claude Haiku 5.5, its most economical model to date, priced at $0.10 per million input tokens, up to 90% less than previous versions. However, the company included a relevant condition: above 100,000 input tokens, the price increases fivefold.
For its part, Mistral announced that it will release its Large 4 model at the end of October, described as the company's most powerful to date. It is a one-trillion-parameter model, trained in Europe, with downloadable weights. The performance figures released come from the company itself, and the usage license has not yet been publicly detailed.
An ultraviolet sky map made by AI agents
Claude Science, Anthropic's scientific project, generated the first complete map of the sky in ultraviolet light using several AI agents that downloaded, calibrated, and merged data from different space missions.
The areas of the map that were reconstructed through estimation show an average deviation of ten percent compared to the actual data, according to the initiative itself.
OpenAI generates $50 billion in revenue and seeks more funding
OpenAI is currently generating revenue at an annualized rate of $50 billion, according to available information, and is seeking to raise an additional $30 billion. The difference from the $70 billion figure that circulated previously is explained by different accounting criteria, not by a drop in sales.
In parallel, the company's IPO has been postponed to next year, according to the latest available information.
The background reading
The pattern connecting these events is uncomfortable: artificial intelligence agents are already acting autonomously in real environments, while security measures continue to arrive after the problem, not before. This was the case with the AWS flaw, the incident reported on Windows, and Robinson's resignation at OpenAI.
At the same time, models like Haiku 5.5 make that type of autonomous work that requires supervision cheaper. The more economical it becomes to delegate tasks to AI agents, the more costly a lack of investment in supervision and security controls can become.
Frequently asked questions
What vulnerability was discovered in AWS?
Researchers at Zenity Labs demonstrated that a single chat message in Amazon Bedrock AgentCore allowed control of all AI agents in the same account and region, due to overly broad default permissions on the platform.
Was the case of Claude Code deleting files on Windows confirmed?
No. It is a user account that has not been independently verified. The technical cause pointed out, related to the handling of directory junctions in Windows, is plausible and avoidable, but the incident itself does not have official confirmation.
Why did David Robinson resign from OpenAI?
Robinson, an employee in the company's security area, resigned and explained in an article in The Atlantic that he believes OpenAI's iterative deployment model guarantees periodic failures, and he called for a level of rigor comparable to that of a nuclear power plant.
How much does Claude Haiku 5.5 cost?
Anthropic set a price of $0.10 per million input tokens, up to 90% cheaper than previous versions, although the cost increases fivefold if more than 100,000 input tokens are exceeded.
When will Mistral Large 4 be released?
Mistral plans to release it at the end of October 2026. It will be a one-trillion-parameter model, trained in Europe, with downloadable weights, although the usage license has not yet been detailed.
How much revenue is OpenAI currently generating?
The company is generating revenue at an annualized rate of $50 billion and is seeking an additional injection of $30 billion. Its IPO has been postponed to next year.

