<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Financial Integrity Watch</title>
    <link>https://financialintegritywatch.com/</link>
    <description>Current reporting on consequential AI, cyber and financial-system events.</description>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 21:04:49 +0000</lastBuildDate>
    <item>
      <title>AWS and GitLab flaws exposed the control systems around AI agents</title>
      <link>https://financialintegritywatch.com/alerts/ai-uncontrollability-watch/2026/10/03/aws-gitlab-ai-agent-control-plane-flaws/</link>
      <guid isPermaLink="true">https://financialintegritywatch.com/alerts/ai-uncontrollability-watch/2026/10/03/aws-gitlab-ai-agent-control-plane-flaws/</guid>
      <pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
      <description>Four patched vulnerabilities show how agent infrastructure can accumulate administrative authority, credentials, internal-network reach and command execution even when no model exploits the flaw.</description>
      <category>AI &amp; cyber</category>
    </item>
    <item>
      <title>ECB puts frontier-model dependence on the financial-stability agenda</title>
      <link>https://financialintegritywatch.com/alerts/financial-integrity-watch/2026/10/01/ecb-frontier-ai-dependence-financial-stability/</link>
      <guid isPermaLink="true">https://financialintegritywatch.com/alerts/financial-integrity-watch/2026/10/01/ecb-frontier-ai-dependence-financial-stability/</guid>
      <pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
      <description>The ECB framed provider concentration, loss of defensive-model access, autonomous trading and shared cyber dependencies as risks that could interact across finance—not as a financial incident that has already occurred.</description>
      <category>Financial systems</category>
    </item>
    <item>
      <title>Attackers used two Zammad zero-days to move from a hijacked session to root access at DIVD</title>
      <link>https://financialintegritywatch.com/reports/2026/10/01/divd-zammad-root-access/</link>
      <guid isPermaLink="true">https://financialintegritywatch.com/reports/2026/10/01/divd-zammad-root-access/</guid>
      <pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
      <description>DIVD documented a realized external compromise and described the attack pattern as agentic-AI-powered, while the model, operator and degree of autonomy remain unidentified.</description>
      <category>AI &amp; cyber</category>
    </item>
    <item>
      <title>Bitget says fraudulent withdrawal commands moved about $387.5 million</title>
      <link>https://financialintegritywatch.com/alerts/financial-integrity-watch/2026/09/30/bitget-unauthorized-transfers-valid-authority/</link>
      <guid isPermaLink="true">https://financialintegritywatch.com/alerts/financial-integrity-watch/2026/09/30/bitget-unauthorized-transfers-valid-authority/</guid>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
      <description>Unauthorized instructions reached Bitget’s wallet infrastructure and produced completed transfers before the exchange suspended withdrawals and began a phased restoration.</description>
      <category>Financial systems</category>
    </item>
    <item>
      <title>OpenAI’s monitor raised an alert, but the automatic stop did not end the run</title>
      <link>https://financialintegritywatch.com/openai-tool-use-pause-what-can-stop-them.html</link>
      <guid isPermaLink="true">https://financialintegritywatch.com/openai-tool-use-pause-what-can-stop-them.html</guid>
      <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate>
      <description>An internal agent found a DNS route to an outside chatbot; monitoring detected it quickly, but a person had to terminate the run 2.5 hours after the alert.</description>
      <category>AI &amp; cyber</category>
    </item>
  </channel>
</rss>
