{
  "type": "bundle",
  "id": "bundle--7d05a1c7-0101-4585-8c04-74427e07774c",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-28T00:00:00.000Z",
      "modified": "2026-08-28T00:00:00.000Z",
      "name": "Optimus Labs · Civilizations",
      "identity_class": "organization",
      "description": "Threat research team at Optimus Labs. Agentic AI attack surface research.",
      "contact_information": "https://optimuslabs.io/research/briefings"
    },
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--ac4f6fe0-0101-48a9-852b-1c8b7ad50c88",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-28T00:00:00.000Z",
      "modified": "2026-08-28T00:00:00.000Z",
      "name": "Instinct: What an Always-On Personal Agent Gets by Default",
      "description": "Instinct's onboarding asks for full read, write and delete control of your Google account, plus iMessage, WhatsApp, screen, microphone, location and a stored card. The convenience is real, and so is the blast radius.\n\nInstinct pitches itself in friendly terms: its own computer, a password manager that never sees your credentials, infinite memory, \"treat me like a human with a computer.\" What that describes is a machine acting as you on a screen nobody is watching, holding the keys to every account you connect and keeping everything it is told and everything it sees. This brief reproduces the day-one authorization scopes, gives a permission-by-permission minimization table, compares Instinct with Grok Bot and OpenClaw on where data lives and whether you can stop the agent mid-task, and reads the Terms and Privacy Notice that decide what happens to the data afterwards.",
      "published": "2026-08-28T00:00:00.000Z",
      "report_types": [
        "threat-report"
      ],
      "confidence": 85,
      "labels": [
        "Rogue AI",
        "Shadow AI",
        "Agent Permissions",
        "Outside the Agentic Loop",
        "Agentware Lifecycle Security",
        "Cyber Hygiene",
        "severity:high"
      ],
      "object_refs": [
        "indicator--b9aa357c-0103-4de0-8475-67764baadf35",
        "vulnerability--31e57630-0100-48e2-80e5-5ed232e59f12",
        "software--2fabdbdc-0101-4f6f-8eaa-24b330addb4b",
        "software--f1022754-0103-49f9-8ffe-9153f205714d",
        "software--16e71e4f-0101-408e-87e6-cec117e8eedd",
        "software--a75e234c-0101-488e-859a-0243ea8601bd",
        "software--c5148664-0101-4c27-83be-ac5bdc616428",
        "software--1a16bb0f-0101-4f92-8b17-349d1b184aa1",
        "software--d0bc8c58-0101-45e6-82e4-28642d1be823"
      ],
      "external_references": [
        {
          "source_name": "Optimus Labs · Civilizations",
          "url": "https://optimuslabs.io/research/briefings/instinct-agent-safety-default-access"
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9aa357c-0103-4de0-8475-67764baadf35",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-28T00:00:00.000Z",
      "modified": "2026-08-28T00:00:00.000Z",
      "name": "domain: myaccount.google.com",
      "description": "Unexpected entries under myaccount.google.com/connections.",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'myaccount.google.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-28T00:00:00.000Z",
      "labels": [
        "instinct-agent-safety-default-access",
        "rogue-ai",
        "shadow-ai"
      ]
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--31e57630-0100-48e2-80e5-5ed232e59f12",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-28T00:00:00.000Z",
      "modified": "2026-08-28T00:00:00.000Z",
      "name": "CVE-2026-25253",
      "description": "OpenClaw self-hosted deployments affected by CVE-2026-25253.",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-25253"
        }
      ]
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--2fabdbdc-0101-4f6f-8eaa-24b330addb4b",
      "name": "Instinct"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--f1022754-0103-49f9-8ffe-9153f205714d",
      "name": "Spear Street Technology"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--16e71e4f-0101-408e-87e6-cec117e8eedd",
      "name": "Google"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--a75e234c-0101-488e-859a-0243ea8601bd",
      "name": "WhatsApp"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--c5148664-0101-4c27-83be-ac5bdc616428",
      "name": "Apple"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--1a16bb0f-0101-4f92-8b17-349d1b184aa1",
      "name": "xAI"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--d0bc8c58-0101-45e6-82e4-28642d1be823",
      "name": "OpenClaw"
    }
  ]
}