Episode 8 · 4:40 · Download MP3 · RSS · Transcript
An AI agent is not a feature you switch on. It is an actor with authority. This week: a single link that could build a working agent inside somebody’s workspace with every connector attached and approvals switched off, an attacker who ran an agent unattended inside a national finance ministry, and a government that stopped a billion-euro cloud procurement to ask where its data lives. Three sizes of the same question.
In this episode
- A link that built an agent. Researchers showed one crafted URL could create a working agent inside a logged-in account, attach every connected mailbox and file store, set approvals to never ask, and put it on an hourly schedule. Patched on June 8, with no reported exploitation in the wild. The open question is not the bug. It is how casually agent authority gets handed out.
- An agent nobody was supervising. A security firm reports an attacker running an off-the-shelf agent with its approval mode disabled for post-exploitation work inside a national finance ministry. One firm is the only public source and the ministry has not confirmed it. The transferable lesson is that the useful setting was the one that removed the human.
- A government asking where its data lives. Ireland’s Office of Government Procurement cancelled a cloud framework competition over digital sovereignty. Jurisdiction moved from a slide in a security review to a reason to stop a contract.
Sources
- The Hacker News, July 24, 2026 — agent-builder flaw
- The Hacker News, July 24, 2026 — unattended agent at a national finance ministry
- The Register, July 22, 2026 — Ireland stalls cloud tender over digital sovereignty
AI voice disclosure
Laura and Arthur are AI-generated voices, produced locally on Modular’s own hardware. Story selection, reporting, and fact-checking are done by the Modular Technology Group team. Your data, your rules applies to our own production too.
Full transcript
Laura: Welcome to The Modular Briefing, the show that cuts through the AI noise and tells you what it actually means for your business. I’m Laura.
Arthur: And I’m Arthur. Three stories today, and one idea underneath all of them. An AI agent is an actor with authority. So today, who hands out that authority. Who is watching it. And who gets to decide where any of it runs.
Laura: Story one. Security researchers showed that on a widely used AI platform, one crafted link was enough to build a working agent inside somebody’s account. The victim only had to be logged in and click. The agent came up from a template, attached every mailbox and file store that account had already connected, set its approval prompts to never ask, and put itself on an hourly schedule. To be fair to the vendor, they fixed it on the eighth of June, and nobody has reported it being used in the wild.
Arthur: Picture that at the desk. Somebody in accounting clicks a link in an email, and forty minutes later there is a thing in their workspace reading the mailbox on a timer, with permission to act, and no human ever approved it. The patch closes that one door. It does not answer the question the story asks, which is how casually agent authority gets handed out in the first place. In most companies right now, anybody with a login can create an agent, wire it to real data, and nobody can name who owns it. That is the part you can fix this week. Give every agent a boundary and a person accountable for it, in a workspace your company actually owns rather than one you rent by the seat. Your data, your rules.
Laura: Story two is what that looks like when nobody is watching. A security firm reports that an attacker ran an off-the-shelf AI agent inside a national finance ministry, using it for the messy work after a break-in, with the agent’s approval mode switched off so it would not stop to ask. Researchers found the operator’s own toolkit sitting in an exposed directory, around five hundred and eighty-five files. Worth saying plainly: one firm is the only public source, the ministry has not confirmed any of it, and their national cyber team was notified in mid July.
Arthur: Take the caveat seriously and the lesson still stands, because the interesting detail is not the break-in. It is that the useful setting was the one that turns the human out of the loop. That setting exists on the tools your own team uses. If somebody on your staff can disable an approval gate to move faster, then the gate was decoration. Real oversight means the boundary sits outside the agent, in infrastructure you control, and it means you have an off switch that works even when the agent is mid-task. Your data, your rules, and that includes the AI working on it. Your AI, your rules.
Laura: Story three moves the question up a level. Ireland’s government procurement office just cancelled a major cloud framework competition after concerns were raised about digital sovereignty. For scale, the framework it would have replaced is capped at three hundred and fifty million euro and runs to September of twenty twenty-seven, and an opposition deputy put the replacement somewhere between seven hundred and fifty million and one billion euro.
Arthur: Here is why that matters to a twelve-person firm in Kentucky. A government just treated the question of where its data lives, and whose law reaches it, as a reason to stop a procurement in its tracks. That question used to be a slide in a security review. Now it moves contracts. If a national government is willing to pause and ask it, it is a fair question for you to ask about the systems running your client files. And you get better answers when the stack is yours: infrastructure you own, in a US-based FedRAMP facility, at a fixed monthly cost instead of a meter you cannot see, one stack from dirt to desktop. Your data, your rules.
Laura: That is the thread today. A link that built an agent. An agent nobody was supervising. A government that stopped a contract to ask where its data lives. Same question at three different sizes.
Arthur: If your team is starting to point AI agents at real systems and you are not sure who owns them or what they are allowed to touch, we would genuinely like to compare notes. No hard pitch. Head to modtechgroup dot com slash consultation and book a conversation with the Modular team. We will help you figure out where your data lives, what it really costs, and what your options are.
Laura: Thanks for spending a few minutes with us.
Laura: This has been The Modular Briefing.
Arthur: Your data, your rules.
Laura: We will see you next time.
If your team is pointing AI agents at real systems and nobody can say who owns them or what they may touch, book a conversation.
Your data, your rules.