CrewCrew
FeedSignalsMy Subscriptions
Get Started
AI Agents: Operator, Browser Agents and MCP

AI Agents: Operator, Browser Agents and MCP — 2026-09-18

  1. Signals
  2. /
  3. AI Agents: Operator, Browser Agents and MCP

AI Agents: Operator, Browser Agents and MCP — 2026-09-18

AI Agents: Operator, Browser Agents and MCP|September 18, 2026(3h ago)2 min read8.4AI quality score — automatically evaluated based on accuracy, depth, and source quality
0 subscribers

This week, security researchers unveiled the "BragJack" attack, demonstrating how a single browser extension can hijack agentic AI features across Chrome, Comet, Edge, and Opera Neon. Meanwhile, Salesforce announced the Koa CRM model and expanded its AgentExchange marketplace at Dreamforce 2026, while Manus reportedly seeks a $4 billion valuation in a new funding round.

AI Agents: Operator, Browser Agents and MCP — 2026-09-18


Top developments


BragJack Attack Hijacks Browser-Based AI Agents

Researchers disclosed "BragJack," a new attack vector that exploits AI assistants built directly into web browsers to access sensitive data and execute malicious actions. The vulnerability affects major Chromium-based products including Chrome, Comet, Edge, and Opera Neon, as well as Claude integrations. This development underscores the immediate security risks of embedding autonomous agents directly into browser infrastructure without rigorous isolation.

Diagram showing how a malicious extension hijacks AI agents in browsers like Chrome and Comet
Diagram showing how a malicious extension hijacks AI agents in browsers like Chrome and Comet


Salesforce Launches Koa Model and Expands AgentExchange

At Dreamforce 2026 (September 15), Salesforce launched Koa, its first CRM reasoning model built on NVIDIA Nemotron, alongside significant updates to its AgentExchange marketplace. The new features include enhanced builders, interfaces, skills, plugins, and MCP servers to help enterprises discover and deploy trusted AI agents. However, reports indicate that the underlying Agentforce platform continues to face ROI challenges in real-world enterprise deployments despite these technical advancements.

Attendees at Salesforce Dreamforce conference
Attendees at Salesforce Dreamforce conference


Manus AI Seeks $4 Billion Valuation in New Funding Round

AI agent startup Manus is reportedly closing a $500 million funding round that would double its valuation to $4 billion, making it one of the most valuable AI agent startups globally. The move follows earlier reports that the founding team, along with investors like Tencent and HSG, repurchased shares from Meta. This capital injection signals strong investor confidence in general-purpose autonomous agents capable of executing multi-step tasks without code.


OpenAI Releases GPT-Live-1 and Public Beta for Agents API

On September 10, OpenAI shipped GPT-Live-1 in its API, priced at $0.05 per voice minute, and launched the Agents API in public beta. These releases provide developers with new infrastructure for building voice-enabled and autonomous agent applications. The Agents API aims to streamline the creation of complex agent workflows, competing directly with other emerging frameworks in the enterprise space.


Local view

cnBeta.com reports that Manus AI is aiming for a $4 billion valuation in its upcoming $500 million funding round, highlighting the intense competition among Chinese AI agent startups. iFeng Tech notes that prior to this round, Manus founders and early investors repurchased all shares from Meta at a $2 billion valuation, indicating a strategic shift toward independent growth for the Chinese agent leader.


Context & numbers

  • Manus Valuation: Targeting $4 billion in a $500 million raise
  • OpenAI GPT-Live-1 Price: $0.05 per voice minute
  • Salesforce Dreamforce: Held September 15, 2026

On the radar

  • MCP Specification Update: The Model Context Protocol blog recently announced the release of version 2026-07-28, with new SDKs available for building clients and servers.
  • Security Research: University of Illinois researchers published a preprint detailing attacks against 12 coding-agent products, promoting hostile project text to escalate privileges.

This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.

Explore related topics
  • QHow does the BragJack attack actually work?
  • QWhat causes the ROI challenges for Agentforce?
  • QWhat are the main features of OpenAI's Agents API?

Powered by

CrewCrew

Sources

Want your own AI intelligence feed?

Create custom signals on any topic. AI curates and delivers 24/7.