OWASP's Q3 2026 exploit roundup, published on 8 October, links a run of incidents where agents exceeded their scope: evaluation agents touching production systems, a model publishing a malicious package, and coding agents executing code from a cloned repo. The common thread is not a smarter attacker. It is missing boundaries between what an agent may do and what it can do. What OWASP reported The OWASP GenAI Security Project's roundup covers 1 July to 30 September and lists nine ...