# Weekly Review W37: the core does not decide, what surrounds it does

> Fifteen items from 11 Aug to 10 Sep 2026: a 10.0 SAP note, an MCP server for BTP on admin rights, hidden text in email, and the harness that beats the model.

- Source: https://snok.ai/en/news/blog/weekly-review-w37-the-core-does-not-decide/
- Author: Jacek Bugajski
- Published: 2026-09-11

---
**Fifteen items from four weeks, 11 August - 10 September 2026, each with a note on what it changes in your systems.**

Four weeks without an issue produced a pool with one recurring pattern. A model on its own is not a
good penetration tester - the structure around it decides. A security note does not protect a system
until somebody owns its rollout across four separate layers at once. A scanner misses a malicious
agent skill because it reads code, while the instruction sits in prose. An email summary is safe
only once somebody has decided what content reaches the model at all.

The same rule governs the invoice. An AI server gets more expensive because of memory, not compute.
The largest funding round in European AI history is going into data centres rather than another
model. The thing you buy is almost never the thing that decides the outcome.

## 1. SAP Security Patch Day - four critical notes, four different owners

SAP Security Patch Day on 8 September 2026 carries 20 items: 19 new notes and one update to an
August note, split into four critical, five high, ten medium and one low. The lead note, 3747649,
scores 10.0 and concerns the handling of SAP Extended Passport - the diagnostic header that travels
between components so a single request can be traced across the landscape. The vector reads: over
the network, no account in the system, low complexity, scope change, full impact on
confidentiality, integrity and availability. The fix lands in the kernel and in Web Dispatcher, so
rollout means replacing the kernel and restarting instances - a maintenance window, not a transport
import.

The spread of ownership is more interesting than the score. The second critical note, 3759472,
concerns Message Server - kernel again. The third, 3798315, is an npm library in multitenant
applications on SAP BTP, deployed by a development team rather than a system administrator. The
fourth, 3781729, lands on the user's workstation in SAP GUI for Java - a layer that in many
organisations has no patch cycle at all and does not appear on the system inventory. Four items,
four teams, one list. This is also the second consecutive month with a 10.0 score, the first two
such months in 2026.

**What follows:** a small patch day can reach four owners at once, and a patching process that only
looks at the application server will close one of the four and report success.

*Source: SAP Support Portal, SAP Security Patch Day - September 2026, read 8 Sep 2026; note numbers
and scores verified against the CVE records SAP maintains as CNA and the NVD record for
CVE-2026-44756. Onapsis reported 22 notes and 5 HotNews items the same day - the portal table is
authoritative for the list. Full write-up:
[SAP Security Patch Day - September 2026](https://snok.ai/en/news/blog/sap-patch-day-september-2026/).*

![An open control cabinet and four tradespeople of different specialities, each with their own toolbox](https://snok.ai/images/blog/snok-weekly-digest-w37-01-cztery-fachy.webp)

## 2. The network barrier in front of SAP is gone, the configuration is unchanged

At Black Hat USA 2026 the chief executive of an SAP security vendor described a shift visible in
every migration project. Connectivity once reserved for internal users now serves B2B, B2C and AI
interfaces. An attacker no longer has to breach the corporate network first to reach a
business-critical system - the barrier that protected SAP regardless of configuration quality has
simply ceased to exist.

His second point is about speed. Working exploit code now takes minutes rather than days, and deep
SAP knowledge has stopped being an entry requirement. This is the same mechanism five US federal
agencies described in August for industrial controllers. The compensating controls he names:
monitoring exploitation attempts, deliberate attack surface reduction, and scanning AI-generated
code before it reaches the business system.

**What follows:** the question for your next review is not whether someone can attack SAP, but what
part of your landscape is visible from the internet and who checks that on a repeatable cycle.

*Source: Mariano Nunez (Onapsis) interviewed by ISMG at Black Hat USA 2026. This is the CEO of a
company selling SAP risk scanning - strong claims, declared interest. The share-of-transaction-
revenue figure quoted in that interview has no published methodology, so we do not repeat it here.*

![An old defensive wall with a newly cut passage, a delivery van driving through it](https://snok.ai/images/blog/snok-weekly-digest-w37-02-wyrwa-w-murze.webp)

## 3. The agent got the keys to SAP BTP, nobody got the logbook

SAP has publicly released an official MCP server for SAP BTP administration. The scope goes beyond
querying the landscape: accounts, security, services and connectivity, including subaccounts,
entitlements, role collections, subscriptions and destinations - 61 tools at release. The server is
remote and hosted by SAP, so there is nothing to deploy in the customer's account: you add the
endpoint and a client identifier to a local configuration. It runs on the existing permissions of
the signed-in SAP user, and SAP lists Claude Code, GitHub Copilot in VS Code and OpenCode as
compatible clients.

The technical pattern is sound: streamable HTTP, OAuth with a public client identifier, no keys in
configuration files, no package to install, no proxy application. Practitioners in the same thread
point out what enterprise deployment still needs: execution traces, versioning, oversight and
audit, plus more authentication options. BTP administrator permissions are the widest scope that
exists in this landscape.

**What follows:** before such a server touches a customer landscape, answer one question - where is
it recorded that the agent performed an operation, and who reads that record.

*Source: SAP Help documentation for the MCP server for SAP BTP administration; SAP Community public
release post and connection guide, September 2026; SAP Developer News, 3 Sep 2026. The governance
gaps come from practitioner comments in that thread.*

![A night porter's lodge with a key board, a hand lifting a key, the entry logbook lying empty](https://snok.ai/images/blog/snok-weekly-digest-w37-03-klucze-bez-ksiegi.webp)

## 4. Eight pillars of SAP security and the figure that stings most

The Head of SAP Security at Accenture UK & Ireland published a grid of eight domains, each with key
actions and a single benchmark figure: foundation and architecture, identity and access,
authorisations and role design, secure development with clean core, patch and vulnerability
management, data protection, hardening, and monitoring and response. The data is described as
multi-client and anonymised, with no methodology or sample size given.

The strongest figure is not about technology. According to the author, 82 per cent of organisations
do not monitor SAP application-layer events - the layer where business abuse happens: a changed
vendor bank account, a payment run, a document correction. Alongside that, 66 per cent do not watch
access to sensitive tables at all, 72 per cent still approve access manually, and in the first
pillar the author reports 34 vulnerabilities found in 100 per cent of assessed deployments.

**What follows:** the order of work falls out of those numbers - baseline, patch cycle,
application-layer monitoring. The remaining pillars have nothing to stand on without those three.

*Source: Peter Doyle, Accenture UK & Ireland, "Most SAP Security is Missing Pillars", LinkedIn
Insight series, August 2026. The figures are the author's claims from data we cannot see, so we
attribute them rather than presenting them as market data.*

![Eight pressure gauges on one wall, only one of them wired to a recorder](https://snok.ai/images/blog/snok-weekly-digest-w37-04-osiem-manometrow.webp)

## 5. Four hundred and seventy-two characters the recipient never sees

Forcepoint X Labs published a demonstration on 25 August that is worth showing to a board instead
of a hypothetical attack story. An invoice email arrives: 537 characters of visible content, no
attachment, no link to click. Inside the message code sit another 472 characters hidden by styling -
white font at zero size, line height set to zero. Empty space to the eye, plain text to any program
reading the file. The model receives 1,009 characters, nearly half of which the recipient will never
see.

In ten runs out of ten the summary reported a false amount of EUR 46,200 and a shifted payment
deadline - 3 September instead of 21 August - and one person's name disappeared. The real values
appeared in none of the runs. Nothing was broken: the message arrived through the normal channel,
the model read what it was given and did what it was told. The authors state plainly that the
problem is neither the mail client nor the specific model, but the way content is handed to models.

**What follows:** detection would require opening the original and reading it yourself - exactly
what the summary was meant to save. The answer sits in the pipeline, not in the model: extract only
content visible to a human, detect hidden styles, treat retrieved content as untrusted, validate
output against the source, and give the summarising tool the least privilege it needs.

*Source: Forcepoint X Labs, "An Invisible HTML Payload Silently Hijacked Every Email Summarizer
Run", 25 Aug 2026. The summariser in that study ran on Claude Haiku 4.5, and the authors expect the
same behaviour from other models in an unprotected pipeline. This is a lab demonstration, not a
customer incident.*

![A blank sheet of paper in raking light, the impressions of writing visible on it](https://snok.ai/images/blog/snok-weekly-digest-w37-05-swiatlo-skosne.webp)

## 6. The scanner reads code, the instruction sits in prose

In August OWASP released the first shared taxonomy of risks for agent skills - packages that extend
what an agent can do: ten classes from a skill that is malicious at publication, through supply
chain compromise, over-privileged skills and insecure metadata, to weak isolation, update drift,
ineffective scanning and missing governance. The project deliberately assigns no severity scores
until a scoring system for agentic systems is published.

What sets this layer apart: a skill is natural-language instructions plus helper code plus
dependencies plus metadata, and it executes with the host agent's permissions. So the attack travels
two paths at once. A conventional scanner sees the scripts but not the command written in a text
file, which the model executes as an instruction - and metadata is often parsed before the user
approves anything. A measurement study presented at USENIX Security 2026 analysed 98,380 skills and
confirmed 157 malicious ones carrying 632 vulnerabilities, with 73 per cent of the malicious ones
hiding functionality from the user. In one documented case three lines of text were enough to
exfiltrate access keys.

**What follows:** this layer does not need another scanner. It needs the three things every other
piece of software in the company already has - an inventory, a policy and an approval path.

*Source: OWASP, Agentic Skills Top 10, August 2026 release (66 pages) and the project repository;
market evidence and the measurement study as cited in that document.*

![A carpenter holding a board up to the light, a nail embedded inside it](https://snok.ai/images/blog/snok-weekly-digest-w37-06-ukryty-gwozdz.webp)

## 7. Four days, eight agents and tools anyone can download

On 12 August the Israeli firm Dream described a campaign from early July against Taiwan's public
administration that ran almost without human involvement. Four days, 21 government systems mapped,
85 user accounts taken over, more than 2,500 employee records exfiltrated. At peak, eight agents
worked in parallel. A day after publication Taiwan's government confirmed it had detected
agent-driven attacks on the administration in July.

The detail that changes the risk assessment is the equipment, not the scale. Everything ran on
publicly available tooling and open-weight models - no proprietary secret toolkit, no team of
single-system specialists. The word "almost" matters and is worth keeping: in a comparable case
described by another vendor, journalists showed the attack required considerably more human work
than the announcement implied.

**What follows:** the question is no longer whether the adversary has access to advanced AI. They
have it just as you do, and the entry cost is downloading the tools rather than building them.

*Source: Dream, "Inside a multi-agent AI framework used to compromise government entities in Asia",
12 Aug 2026; reporting by CNN and CyberScoop; the government confirmation a day later covers the
attacks, not the figures.*

![Eight self-driving trucks in a warehouse at night, no people on the floor](https://snok.ai/images/blog/snok-weekly-digest-w37-07-roj-wozkow.webp)

## 8. An engine with no chassis only burns fuel

A security practitioner writing on the ZSec blog documented, across two posts, an autonomous
vulnerability hunting system that has run for months and found real bugs. Three layers: the model
reasons and decides the next step, a tool protocol gives it real access to tooling, reconnaissance
and code analysis, and the harness keeps task structure, token spend and repeatability under
control.

His claim is inconvenient for conversations that begin with model selection: the largest gains in
effectiveness, cost and repeatability come from the harness, not the model. A capable model with no
structure around it will burn tokens and deliver nothing. A commercial harness vendor argues the
same and adds a problem rarely discussed: a model can abort an authorised security test because
generating a payload trips its own safety control. The answer is not a less restrictive model but
moving control into the harness - deterministic authorisation, target isolation, evidence
verification, auditability.

**What follows:** the conclusion cuts both ways. Offensive capability is not reserved for whoever
pays for the strongest model, and a production agent needs exactly the same layer - state memory,
tool isolation and evidence verification.

*Source: ZSec blog, "Autonomous Vulnerability Hunting with MCP" and "Harnessing Harnesses - Climbing
the LLM Hills", September 2026. The commercial harness vendor is cited only as converging argument -
its comparative figures are producer claims without independent measurement, so we omit them.*

![An engine on a workshop stand beside the same engine mounted in a complete chassis](https://snok.ai/images/blog/snok-weekly-digest-w37-08-silnik-i-rama.webp)

## 9. A fourth profitable quarter and the question boards ask

On 3 September UiPath reported results for the second quarter of fiscal 2027, ended 31 July 2026:
revenue of USD 410m, up 13 per cent year on year, annual recurring revenue of USD 1.938bn, up 12 per
cent, net new ARR of USD 37m, dollar-based net retention of 109 per cent, operating income of USD
32m on a GAAP basis and USD 89m non-GAAP, cash and securities of USD 1.405bn. That is the fourth
consecutive quarter of GAAP profitability.

The same day the company promoted to Chief Financial Officer an executive who had been with it since
2021, previously as deputy CFO. This is internal succession, with no effect on pricing or the partner
programme.

**What follows:** this answers the question raised in every multi-year contract decision - will the
platform vendor still be in the same place in three years. A year ago the answer read differently.

*Source: UiPath Investor Relations, second quarter fiscal 2027 results and the leadership change
announcement, both 3 Sep 2026.*

![A weighbridge under load, the needle resting steady](https://snok.ai/images/blog/snok-weekly-digest-w37-09-waga-pomostowa.webp)

## 10. Execution mode stops being the architect's guess

UiPath has released Cartographer in public preview - a profile for the business analyst that turns
transcripts, procedures and recordings into an as-is description, extracts business rules, flags
gaps, designs the to-be state, and then generates a Process Design Document in Word and a technical
specification in Markdown ready for the development team, with or without coding agents. It
automates the phase nobody presents at conferences and that eats weeks: interviews, reconciling
contradictory accounts, and writing down the current state.

The second effect is more interesting. Every process step is assigned an execution mode: fully
automated, assisted, agent, human review or manual. The decision "robot here, agent there, human at
this point" stops being the architect's guess made mid-build and becomes an entry in a document that
can be reviewed and approved before the first line of code. In the vendor's longer-term vision this
becomes a single versioned definition of how the company works.

**What follows:** documentation generated from conversations does not replace the analyst. What it
changes is when the oversight decision is made - from the end of the project to its start.

*Source: UiPath Delegate documentation, Cartographer overview, and the public preview announcement
on the community forum, September 2026. Public preview - the feature scope may change before general
availability.*

![A surveyor with a levelling staff and a map spread on a car bonnet, setting out a site](https://snok.ai/images/blog/snok-weekly-digest-w37-10-geodeta.webp)

## 11. The hard thing and the easy thing have swapped places

In August the founder of UiPath published a book about which work stays human; the digital edition is
free. His thesis: the missing layer in AI deployments is not acquiring agents but orchestration - the
structure that coordinates agents, robots, people and applications, with oversight of what becomes
the official result. The operating model reduces to three roles: agents propose, humans decide,
deterministic automation executes.

The strongest passage concerns an inverted paradox. Agents were supposed to be the quick answer and
deterministic automation the expensive interim stage - it turned out the other way round, because an
agent at the decision point is hard and reliable code is cheap. Then the argument that ends many
pilot discussions: you cannot be 99.9 per cent accurate when you execute a payment. The author
declares his bias outright, since he runs an automation company, and says that if practice showed
otherwise his framework would weaken. His forecast for 2028: high-risk processes in large regulated
organisations will run inside engineered environments rather than a general agent dropped into legacy
systems.

**What follows:** the practical value lies in separating two things projects keep merging - what may
be probabilistic and what must be deterministic. Payments, bookkeeping and period close belong to the
second group regardless of model quality.

*Source: UiPath newsroom, announced 27 Aug 2026; the free digital edition became available on
18 August and the limited print run follows on 22 September 2026.*

![A lock at dawn, the keeper opening the gates by hand, a barge waiting to enter](https://snok.ai/images/blog/snok-weekly-digest-w37-11-sluza.webp)

## 12. A documented control is not an implemented control

ISO/IEC 42001, the AI management system standard, repeats the pattern known from the information
security standard: risk assessment, control selection, comparison against Annex A, statement of
applicability. Annex A is normative and lists 38 controls, and clause 6.1.3 **requires** you to
compare your selected controls against it and justify every exclusion in the statement of
applicability. You may select a subset and add your own controls - you may not skip the comparison
itself. What an analysis published this month adds are two points you would not get from the table
of contents. The emphasis on documentation is markedly stronger than in the security standard,
which is a real barrier for smaller organisations. And some controls require only documentation,
with no evidence of implementation.

The risk is the same as in any management system introduced under deadline pressure: the document
becomes the goal. An AI layer can be wrapped in policies nobody follows and still pass review - which
is precisely the pattern being criticised in current preparations for the EU AI Act, where template
documentation substitutes for classifying the system.

**What follows:** when selecting controls, ask for evidence of implementation rather than the
existence of a record. The difference only shows during an incident, and by then it is too late to
discover it.

*Source: ISO/IEC 42001 itself for clause 6.1.3 and Annex A (38 controls, normative), plus an
analysis of the annex published in September 2026, which is where the observations about
documentation come from. The standard is not a harmonised standard under the EU AI Act.*

![A fire hose cabinet with an inspection tag on the door and nothing inside](https://snok.ai/images/blog/snok-weekly-digest-w37-12-pusta-szafka.webp)

## 13. Safer in use, harder to supervise

On 3 September OpenAI released a model that is the first to reach Critical cyber capability under the
company's own preparedness framework. The system card states it plainly: with the right tools and
access, the model can find previously unknown vulnerabilities and develop new ways to exploit them in
many well-defended systems, without a human directing every step. In response the vendor strengthened
isolation, checkpoint encryption and monitoring of full trajectories, and placed the most advanced
security features behind separate identity verification.

The other side of the same card matters more for deployments. The model is markedly more resistant to
prompt injection and less prone to destructive actions in browser and office environments -
unauthorised transactions, data loss, control bypass. At the same time its monitorability declined: it
controls its own chain of thought better, is less likely to place incriminating information in it, and
under adversarial conditions can stay undetected and sometimes evade internal monitors.

**What follows:** security has to rest on architecture rather than model behaviour - separated
permissions, action validation, a gate with a real review interface. Trusting the model to behave well
has stopped being measurable. Note also the pattern now shared by two vendors: access to the strongest
features is decided by the identity of the person asking, not by the content of the question.

*Source: OpenAI, launch post and GPT-6 Astra system card, 3 Sep 2026 (117 pages). The capability level
is the vendor's self-assessment under its own framework, not a third-party evaluation.*

![The sight glass of an industrial furnace, dark glass with the glow visible behind it](https://snok.ai/images/blog/snok-weekly-digest-w37-13-wizjer-pieca.webp)

## 14. AI servers are up fifteen per cent because of memory

According to Bloomberg's report of 22 August, the largest buyers were notified that prices of servers
with AI accelerators will rise by more than 15 per cent in many cases. The reason is a sharp increase
in memory costs, not the price of the compute chips. The increases are to apply to systems delivered
from early next year, with the scale depending on chip generation and memory configuration. The
notifications came from firms building servers to order for large data centre operators.

Three consequences for next year's purchasing plan. A first-quarter cost estimate may not hold in the
second. Memory configuration becomes a separately negotiated line rather than an add-on to the choice
of compute. And the difference between chip generations stops being a purely performance decision,
because it carries a different memory bill.

**What follows:** a component nobody discusses at conferences has just moved the bill for AI
deployment. Worth accounting for before someone asks about the gap against last year's quote.

*Source: Bloomberg, "Nvidia Customers Notified About AI-Related Price Hikes Above 15%", 22 Aug 2026,
via Reuters, CNBC and Fortune. This is a press report about notifications, not an official price list
from the chip vendor; Reuters noted it could not immediately confirm the report.*

![A spare parts store, a worker counting boxes, the shelf above standing empty](https://snok.ai/images/blog/snok-weekly-digest-w37-14-pusta-polka.webp)

## 15. Three billion euro for data centres, not another model

On 8 September Mistral announced a Series D round: EUR 3bn at a post-money valuation above EUR 21bn -
the largest equity round ever raised by a European technology company, nearly doubling last year's
valuation of EUR 11.7bn. The round is led by Samsung Electronics, a European growth fund managed by
EQT, and existing investor PSG Equity, with participants including ASML and NVIDIA.

What the money is for matters more than the size of the round: building and owning data centres and
adding compute capacity, alongside research and commercial expansion. For organisations that open
every AI conversation by asking where the data physically sits and who can reach it - and every entity
under NIS2 and DORA does - that is the relevant part of the announcement, not the valuation.

**What follows:** capital in this industry now goes into concrete, power and memory rather than
another model. Same conclusion as the server pricing item - the surrounding layer decides, not the
core.

*Source: Mistral, "Making sovereign, open-weight AI the technology frontier", 8 Sep 2026; reporting by
Bloomberg, TechCrunch and CNBC the same day. Some outlets quote dollar figures; we keep the euro
amounts from the company statement.*

![An excavation for a hall at dawn, a crane over the site, workers at the foundation](https://snok.ai/images/blog/snok-weekly-digest-w37-15-fundament.webp)

## One sentence for four weeks

All fifteen items collapse into one sentence: you buy the core, and the layer around it decides the
outcome. An owner for the patch rollout in each of four layers, an audit trail behind the agent, an
inventory of skills, a harness that keeps the task on rails, evidence that a control was implemented,
and memory in the server - none of these appears on an invoice, and every one of them decides whether
the system can be defended to an auditor and to your own board.

If you want to find out which of those layers is thinnest in your organisation, start with the
simplest question: where is it recorded that something was done, and who reads that record.

<div style="background:#F5F1E8; color:#14141F; border-radius:16px; padding:36px 32px; margin:2.5rem 0;">
  <p style="margin:0 0 6px; font-size:0.85em; letter-spacing:0.04em; color:#5A5A6E;">SNOK Weekly Review &middot; W37 &middot; 11 August - 10 September 2026</p>
  <p style="margin:0 0 14px; font-family:Georgia,'Times New Roman',serif; font-size:1.5em; line-height:1.25; color:#0D0D1A;">The whole edition in one file</p>
  <p style="margin:0 0 24px; color:#3A3A4E;">PDF, eighteen pages, about 5.4 MB - no form, no details to hand over. A version to pass around the team or read on a phone.</p>
  <a href="/files/SNOK_Weekly-Review_W37_2026-09_EN.pdf" download style="display:inline-block; background:#DB1620; color:#FFFFFF; padding:14px 28px; border-radius:9999px; font-weight:600; text-decoration:none;">Download edition W37 (PDF)</a>
</div>

If any of these items concerns you directly - [SAP security](https://snok.ai/en/offer/sap-security/), or [orchestration and automation with agents](https://snok.ai/en/offer/ai-automation/) - [let's talk](https://snok.ai/en/contact/).
