AI Radar for Companies — Thursday, September 10, 2026
noticias radar ia ciberseguridad automatizacion agentes de ia

AI Radar for Companies — Thursday, September 10, 2026

· CompaniesAutomation

Google documents the first known case of a planned attack, built and executed with agents in less than six hours, with malware already writing inside Cursor and Claude configuration folders and prices of stolen AI accounts doubling in 2026. A German company raises 36 million —6 in equity and 30 in bank debt— to buy professional consultancies and inject AI into them. The AEPD opens an investigation into a file containing journalists' ideologies, and the lesson is for CRMs. Meta launches an agent that shops and pays for the user. And a diffusion model responds in 170 milliseconds for fifteen cents per million tokens.

Wednesday's radar was about who controls your traffic; today's is about who controls your agents. Google published the most uncomfortable threat report of the year: an attacker set up and executed a massive credential-stealing campaign in less than six hours using agents, and there is malware already writing inside the configuration folders of your code assistant. In parallel, the money shows a new model: instead of selling software to consultancies, consultancies are being bought and AI is being put inside them, using bank debt to pay for them. And the AEPD opens an investigation that should be read as a CRM warning: what your model infers about a client is also prohibited data. The day closes with a model that responds in 170 milliseconds for fifteen cents per million tokens.

Six hours to set up and execute an entire attack with agents

Google's Threat Intelligence Group published its quarterly report on Tuesday and it brings an unprecedented case: in the second quarter of 2026, a financially motivated attacker compromised an organization's cloud resource and from there planned, built, and executed a massive credential-stealing campaign in less than six hours, compromising thousands of third-party credentials. There's more: the actor UNC6780 has been compromising PyPI, npm, and Docker Hub since March, and its DUSTMAKER malicious program leaves or modifies files within the hidden directories of code assistants —.claude/, .vscode/, .cursor/— and embeds prompt injection to deceive scanners that review with models. The average price of a stolen AI account on the black market has more than doubled in 2026. Google clarifies the important point: it has not yet seen fully autonomous attack chains against real targets; what it sees is gradual maturation. For your company: those hidden folders are not in your inventory, your antivirus doesn't look at them, and they don't usually go to version control, and whoever touches them doesn't need your password: it's enough to change the instructions your assistant follows. Three things this week. Put those directories in the repository and review their differences as you review code. Treat your AI API keys like bank keys: rotation, spending limits, and anomalous consumption alerts, because they now have a market price. And take advantage of the fact that on the same day GitHub opened the enterprise-managed sandbox in Copilot for JetBrains, which centrally sets access to files, network, and tools and overrides whatever the developer puts in their IDE. Source.

36 million to buy consultancies and put AI inside them

Limetax, a Berlin-based company only eight months old, has raised 36 million euros with a structure that is the news: 6 million in seed capital led by Motive Partners and 30 million in a credit line from a consortium of German banks intended to buy firms. They already have four consultancies, seven offices, and about 150 employees, with double-digit million annualized revenue. It doesn't sell software to consultancies: it buys them, keeps the brand and the portfolio, and puts accounting, payroll, and annual accounts automation inside. The contrast on the same day comes from the top: Cognition raised 2 billion dollars at a 48 billion valuation and Harvey 550 million at 15.6 billion, also taking the opportunity to buy Guardrails AI. For your company: the pattern is replicable in Spain tomorrow and goes straight to tax, labor, and legal consultancies, clinics, and agencies. If you run one of those businesses, calculate two numbers this week —cost per client per month, and person-hours per monthly closing— because those are exactly what a buyer looks at and what will decide if you are the buyer or the bought. If you are a provider, the reading is that the margin is no longer in the license but in the operation. And note the signal from Harvey: agent security and observability is ceasing to be a standalone category you can hire separately and is becoming a standard feature within the vertical platform. Source.

What your model infers about a client is also Article 9 data

The Spanish Data Protection Agency (AEPD) announced yesterday that it is opening an ex officio investigation to analyze the nature, scope, use, and legal basis of the processing contained in a Ministry of the Interior document with names of journalists and notes on their alleged ideology or political tendency. It cites three articles of the Regulation: 5 (purpose limitation), 6 (lawfulness of processing), and 9.1, which prohibits processing special categories of data such as ideology or political opinions. The Agency stresses that opening proceedings does not prejudge that there is an infringement. For your company: the case is political, but the lesson is about CRM. The Regulation does not distinguish whether the note is written by a salesperson or deduced by a model: if your call transcriber, your email summarizer, or your automatic contact scoring records that a client votes for a certain party, is affiliated with a union, is on leave for a specific ailment, or professes a religion, that is Article 9 and is prohibited unless a specific exception applies. Three actions that fit into one morning. Export the free-text fields from your CRM and search for those terms. Review the system instructions of your summarizers to prohibit inferring special categories and to ensure they don't copy them even if the client mentions them. And update the record of processing activities: it has to describe what the model generates, not just what the person types. Source.

The agent filling out your form is no longer a person

Meta presented Muse on Tuesday, its personal agent, built on Muse Spark, the most capable model it has ever made. It opens a browser, fills out forms, sends emails, books trips, and negotiates on behalf of the user; it keeps working with the application closed and returns when something changes or when it needs an approval. The interesting part is the architecture: it runs on a dedicated virtual machine where a second agent, Sentinel, also lives, separated from the first at the system level, and nothing Muse does reaches the internet if Sentinel doesn't approve it. It pays with Link, by Stripe, and is the first agent covered by its purchase protections. For now only in the United States, for those over 18, free for the basics and with plans for 20 and 100 dollars per month. For your company: two readings and both are from this week. The first: that design is copyable and is the answer to the news above. Separate the agent that acts from the one that authorizes, and make every output to the outside pass through the second; this is what allows moving to the unattended level without gambling the company on every execution. The second is about price: 20 and 100 dollars a month set what the market accepts to pay for personal automation, so if your proposal costs more, it will have to show hours or euros, not features. And decide now what you do when the one filling out your contact form is an agent: do you block it or do you serve it better than anyone? Source.

170 milliseconds for fifteen cents: automated telephone service is no longer expensive

Inception launched Mercury 2.5 today, a diffusion language model that reaches 1,107 tokens per second on standard Nvidia GPUs, with a context window of 260,000 tokens and 40% more intelligence than the previous version. The list price is 0.20 and 0.75 dollars per million input and output tokens, with an 80% launch discount that leaves it at 0.04 and 0.15 dollars, and they are giving away 100 million tokens to try it. The cases it publishes are about latency: a voice agent with a median response close to 170 milliseconds. It is available via its own API, through Baseten, and through OpenRouter. For your company: the figure that matters is not the price, it's the 170 milliseconds. Below about 200, a telephone conversation stops sounding like a machine waiting its turn, and that silence is where half of automated service projects fail, not in the quality of the answers. The test is cheap and can be done in an afternoon: take the twenty calls or two hundred emails you repeat most, run them through a fast model and through the one you use today, and compare three numbers —successes, cost per resolved case, and seconds to the first word—. The distribution rule doesn't change: the fast and cheap model in the first layer, classifying, routing, and answering the repetitive stuff, and the expensive one reserved for the rare case. With one hundred million free tokens, the test costs you time, not money. Source.

What to watch tomorrow?

On Friday the 11th, the clock starts for the Cyber Resilience Act for anyone who manufactures or markets a product with digital elements in the European Union: 24 hours for the early warning of an actively exploited vulnerability or a serious incident, 72 for full notification, and 14 days for the final report. The detail that catches everyone off guard is procedural: notification is through ENISA's single platform, which at its launch has no programming interface —everything is done manually via web— and requires accounts with two-factor authentication and a designated representative. That is prepared before Friday, not when an incident is happening. On Saturday the 12th, the "access by default" of the Data Act also comes into effect for every connected product released to the market from that date onwards.

Watch the 1-minute video