{
  "type": "bundle",
  "id": "bundle--7d05a1c7-0101-4585-8c04-74427e07774c",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-28T00:00:00.000Z",
      "modified": "2026-08-28T00:00:00.000Z",
      "name": "Optimus Labs · Civilizations",
      "identity_class": "organization",
      "description": "Threat research team at Optimus Labs. Agentic AI attack surface research.",
      "contact_information": "https://www.optimuslabs.io/research/briefings"
    },
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--ac4f6fe0-0101-48a9-852b-1c8b7ad50c88",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-28T00:00:00.000Z",
      "modified": "2026-08-28T00:00:00.000Z",
      "name": "Instinct: What an Always-On Personal Agent Gets by Default",
      "description": "Instinct's onboarding asks for full read, write and delete control of your Google account, plus iMessage, WhatsApp, screen, microphone, location and a stored card. The convenience is real, and so is the blast radius.\n\nInstinct introduces itself in friendly terms: its own computer, a password manager that never sees your credentials, infinite memory, and \"treat me like a human with a computer.\" Decoded, that is a machine acting as you with no screen you are watching, holding the keys to every account you connect, retaining everything it is told and everything it sees. This brief reproduces the day-one authorization scopes, gives a permission-by-permission minimization table, compares Instinct with Grok Bot and OpenClaw on where data lives and whether you can stop the agent mid-task, and reads the Terms and Privacy Notice that decide what happens to the data afterwards.",
      "published": "2026-08-28T00:00:00.000Z",
      "report_types": [
        "threat-report"
      ],
      "confidence": 85,
      "labels": [
        "Rogue AI",
        "Shadow AI",
        "Agent Permissions",
        "Outside the Agentic Loop",
        "Agentware Lifecycle Security",
        "Cyber Hygiene",
        "severity:high"
      ],
      "object_refs": [
        "indicator--b9aa357c-0103-4de0-8475-67764baadf35",
        "vulnerability--31e57630-0100-48e2-80e5-5ed232e59f12",
        "software--2fabdbdc-0101-4f6f-8eaa-24b330addb4b",
        "software--f1022754-0103-49f9-8ffe-9153f205714d",
        "software--16e71e4f-0101-408e-87e6-cec117e8eedd",
        "software--a75e234c-0101-488e-859a-0243ea8601bd",
        "software--c5148664-0101-4c27-83be-ac5bdc616428",
        "software--1a16bb0f-0101-4f92-8b17-349d1b184aa1",
        "software--d0bc8c58-0101-45e6-82e4-28642d1be823"
      ],
      "external_references": [
        {
          "source_name": "Optimus Labs · Civilizations",
          "url": "https://www.optimuslabs.io/research/briefings/instinct-agent-safety-default-access"
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9aa357c-0103-4de0-8475-67764baadf35",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-28T00:00:00.000Z",
      "modified": "2026-08-28T00:00:00.000Z",
      "name": "domain: myaccount.google.com",
      "description": "Unexpected entries under myaccount.google.com/connections.",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'myaccount.google.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-28T00:00:00.000Z",
      "labels": [
        "instinct-agent-safety-default-access",
        "rogue-ai",
        "shadow-ai"
      ]
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--31e57630-0100-48e2-80e5-5ed232e59f12",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-28T00:00:00.000Z",
      "modified": "2026-08-28T00:00:00.000Z",
      "name": "CVE-2026-25253",
      "description": "OpenClaw self-hosted deployments affected by CVE-2026-25253.",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-25253"
        }
      ]
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--2fabdbdc-0101-4f6f-8eaa-24b330addb4b",
      "name": "Instinct"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--f1022754-0103-49f9-8ffe-9153f205714d",
      "name": "Spear Street Technology"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--16e71e4f-0101-408e-87e6-cec117e8eedd",
      "name": "Google"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--a75e234c-0101-488e-859a-0243ea8601bd",
      "name": "WhatsApp"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--c5148664-0101-4c27-83be-ac5bdc616428",
      "name": "Apple"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--1a16bb0f-0101-4f92-8b17-349d1b184aa1",
      "name": "xAI"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--d0bc8c58-0101-45e6-82e4-28642d1be823",
      "name": "OpenClaw"
    }
  ]
}