The Intake — Saturday, October 3, 2026

On the substrate

Obot ships Docker quickstart with authentication disabled; three flaws expose stored OAuth credentials for all connected MCP services

NetFoundry Strix.ai (CVE-2026-101084) Strix.ai (CVE-2026-101062)

If you deployed Obot via the Docker quickstart and haven't added explicit authentication or bound the port to localhost, your instance is listening on all network interfaces with authentication off.

Obot is an open-source agent platform that brokers credentials and permissions for connected MCP services — OAuth tokens for third-party systems sit inside it. Three CVEs were published September 25–October 1, 2026. CVE-2026-101065 carries a CVSS score of 9.8. The Docker quickstart configuration binds to 0.0.0.0:8080 with authentication disabled by default. CVE-2026-101084 carries a CVSS score of 9.6. In versions before v0.21.1, the /mcp-connect endpoint did not enforce access control rules. Any authenticated user who knew a server ID could reach restricted MCP servers. Access ran through Obot's stored OAuth credentials. CVE-2026-101062 carries a CVSS score of 8.8. In versions through v0.22.1, OAuth dynamic client registration accepted unauthenticated requests. An attacker could register a malicious client and obtain valid OAuth tokens. Those tokens were valid against any Obot API endpoint. Patches shipped across v0.21.1 and v0.23.0.

If you're running Obot, the Docker quickstart auth default is the first question — before the access control and OAuth registration flaws have a surface, the default configuration already puts the credential broker on the open network.

OpenAI pulls GPT-6.1 Astra launch over safety concerns; three safety researchers dismissed the same week

TechCrunch The Register InsideAI News

If you were planning around GPT-6.1 Astra, OpenAI pulled that launch this week over safety concerns. It also dismissed three safety researchers during the same period.

OpenAI dismissed Jasmine Wang, Tomek Korbak, and Mikita Balesni on or before October 1, 2026. The stated reason was mishandling sensitive information outside established company procedures. Bloomberg reported — referenced via InsideAI News — that at least some material was shared with an external organization that evaluates AI systems. OpenAI denied the terminations were for raising safety concerns. Two researchers were dismissed under similar circumstances in 2024: Leopold Aschenbrenner and Pavel Izmailov.

If you were planning around GPT-6.1 Astra, that launch is off for now. The researcher dismissals carry no near-term practitioner implication beyond naming who is no longer inside the lab.

Google launches Gemini 4 Argon restricted to US government cybersecurity program; output token limit set at one million

The Hacker News SiliconAngle

Google's Gemini 4 Argon launched October 1, 2026, with access restricted to the Fairwind Program — a US government voluntary pre-release cybersecurity access program for trusted defenders. The initial release is not publicly available.

The output token limit is set at one million tokens, up from 64,000 in prior Gemini models. Google disclosed plans for a guardrail-free version available to trusted defenders and internal teams. Safety in that variant would be maintained through chain-of-thought monitoring, Google says. Before broader deployment, Google says the model identified a previously unknown critical vulnerability in widely used healthcare software.

No near-term practitioner implication for most — public API access isn't announced. If you're following Google's model trajectory, the one-million token output limit and the guardrail-free variant for trusted defenders are the specifics this launch establishes.

Nvidia launches Open Agent Safety Platform; Anthropic says it is integrating the containment stack with Claude Managed Agents

Tom's Hardware SiliconAngle

If you're deploying agents at any scale and thinking about containment before something forces the question, Nvidia's platform names a new infrastructure layer to evaluate.

Nvidia launched the Open Agent Safety Platform on September 28, 2026. Nvidia says the platform was built in response to the Hugging Face breach and related rogue-agent incidents. The platform has two components. OpenShell handles formal verification of agent authority scope. Sentry is an on-chip real-time monitoring component. Nvidia says it can quarantine agents in milliseconds. Anthropic says it is integrating the platform with Claude Managed Agents. The integration covers OpenShell and BlueField. SpaceXAI is using the platform. The deployment covers Cursor and Grok models. Nvidia reports 100+ industry partners.

If you're on Claude Managed Agents, the Anthropic integration is the near-term development to watch. The platform has no public enrollment path announced today.

---

For operators

Obot Docker quickstart exposes credential broker to network; upgrade path requires two version steps

NetFoundry Strix.ai (CVE-2026-101084) Strix.ai (CVE-2026-101062)

If you stood up Obot via the Docker quickstart, the default binds to 0.0.0.0:8080 with authentication off. Anyone who can reach that port — on the local network or internet-exposed — reaches the credential broker without credentials.

The three CVEs span two patch versions. CVE-2026-101084 (the /mcp-connect access control bypass) is patched in v0.21.1. CVE-2026-101062 (the unauthenticated OAuth client registration) requires v0.23.0. Upgrading directly to v0.23.0 closes both. If you can't upgrade immediately, binding the service to localhost (127.0.0.1) closes the network exposure from CVE-2026-101065 while you schedule the version upgrade.

If you're running Obot and the Docker quickstart is how you deployed it, the authentication default is the first thing to address — upgrade to v0.23.0 to close all three CVEs, bind to localhost as a temporary mitigation, or disable MCP connections until an upgrade is scheduled.

---