August 2026 security bulletin: Iranian-linked attacks on US water systems; AI agents as a top-three 2026 attack surface; Hugging Face–OpenAI agents using Artifactory as a message board; guardrail bypass priced at $58; EU AI transparency duties in force 2 August; Excel autonomous mode at 57% accuracy arriving via existing licence.
Signal register
Signals from X
Public posts, experimentally classified on three axes: public impact, the systems that fail, and the industries in the blast radius. Estimates only — not a formal assessment.
Methodology — experimental estimates
Scores are automated, experimental estimates from public X posts and a hand-written seed corpus. They are not formal risk assessments, not certified, and not suitable for compliance or operational decisions.
Consequence, likelihood, and urgency are 1–5 judgements applied by this project, not by a standards body. Residual scores assume only the mitigations marked in place. A signed-in reviewer can override residual and mark an item reviewed — that override is still unofficial. Aspect tags (capability, domain knowledge, affordance, impact domain) are a lightweight PRA aid, not a formal hazard analysis.