Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

Shopify Canvas Lets Merchants Build Stores by Chat, as AI Agents Breach a Security Nonprofit

Shopify launched Canvas on 1 October, a site builder that creates a live Shopify store by chatting with its Sidekick AI agent, while a Dutch security nonprofit disclosed a breach driven by an autonomous AI agent.

Media & internetAnalysisGrace OkonkwoPublished: 2 October 20266 min readSources 11
Shopify Canvas Lets Merchants Build Stores by Chat, as AI Agents Breach a Security Nonprofit

On 1 October, Shopify introduced Canvas. It builds an online store from a chat conversation with the company's Sidekick AI agent. TechCrunch reported that Canvas renders the store's real code in real time, not a static preview, so merchants can test interactivity and animation and check pages across screen sizes.

That matters for a specific reason. A merchant can describe a layout, watch the AI change the underlying theme files, and click any element to fix it by hand if the agent gets it wrong. Sidekick also takes screenshots of its own work, so it sees the same page the merchant sees as the site updates. The launch is narrow, though. Third-party theme support, app blocks and extensions, markets, translations, rollouts and theme updates are all absent from the first version, and Canvas is desktop-only, according to TechCrunch. Shopify told the outlet those features are planned over time. The company also simplified its theme architecture and gave Sidekick direct access to theme files so the agent could understand the store's structure, logic and design.

What Canvas ships with, and what it does not

Canvas does not arrive in a vacuum. It joins AI site builders from Wix, Squarespace, Webflow and Framer, plus vibe-coding platforms including Lovable and Replit. Sidekick itself already wrote code, built apps and customized themes before Canvas pulled those abilities into a single product where the whole store is visible at once.

Shopify is not the only company pushing agents into work that used to require a human operator. The same week brought a harder-edged example from security research, where an AI agent is alleged to have run an intrusion largely on its own.

A breach at a security nonprofit, run by an agent

The Dutch Institute for Vulnerability Disclosure said its network was breached through a chain of two zero-day flaws in Zammad, an open-source helpdesk and ticketing system. BleepingComputer reported on 30 September that the flaws are tracked as CVE-2026-102489 and CVE-2026-102490 and allowed session hijacking, remote code execution and escalation to root privileges.

DIVD had previously described the attack as loud and messy, driven by an AI agent that moved autonomously and chose its next steps without external direction. The nonprofit reconstructed the incident because the agent left behind explanations of its decisions. "Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack," DIVD said, according to BleepingComputer.

Network segmentation and incident response stopped the intruder from moving deeper, and the investigation continues. Zammad says on its website that it has over 2,000 customers and 55,000 users, including De'Longhi, Amnesty International and NextCloud. DIVD found the flaws with Merlon Security, notified Zammad and recommends users upgrade to version 7 or take instances offline.

The two stories sit at opposite ends of the same trend. One sells an agent that builds things; the other documents an agent that broke things, in seconds, with no human in the loop.

Defenders are being sold the same agentic pitch

Vendors are responding with AI-native defense products. GTT Communications announced GTT Defense Halo on 29 September, describing a patent-pending platform that identifies vulnerabilities and policy gaps, generates remediation plans in real time, and builds a stateful model of a customer's network showing every host-to-host connection. Light Reading reported the launch, which runs on GTT's AI factory with instances hosted in the United States, United Kingdom and European Union. The company tied the product to an open letter published in late August and signed by more than 100 technology, cybersecurity and financial services companies, warning that AI-enabled cyberattacks will become more widespread and sophisticated and that defenders have a narrow window to prepare.

That framing is now common, and it is not limited to network vendors. InfoQ is running two five-week online certification cohorts in October 2026. AI Security and Privacy Engineering starts on 26 October; AI-Assisted Engineering starts on 19 October and focuses on the checks around coding agents changing an existing codebase.

Katharine Jarmul, who facilitates the security cohort, said an AI security review has to follow the data and the decisions across the whole system. "In the cohort, we'll map where sensitive information can go, test the controls we choose, and make clear who owns the risks that remain," she said, according to InfoQ. Zichuan Xiong, who co-facilitates the engineering cohort, put the operational question plainly: "A coding agent can make a change quickly, but the harder question is what it was allowed to do and how we know the change is sound."

Malware that stays, and the trust gap underneath

Agentic attacks are not the only active threat. Microsoft said a malware family called NeedyMantis has been used to keep long-term access to networks that were already breached, according to The Hacker News. The activity targets telecommunications organizations, universities, medical nonprofits, intergovernmental organizations and government contractors, and its use goes back to at least October 2025.

Microsoft found the malware while following indicators from Kaspersky's investigation into a supply chain attack on DAEMON Tools, in which signed installers for DAEMON Tools Lite carried malicious code from 8 April 2026 until the developer replaced them with a clean version on 5 May. Microsoft tracks that activity as Storm-3069, assesses it originates in China, and says it has not tied the group to a Chinese nation-state actor. The company also says more than one group may be using NeedyMantis.

Underneath all of this sits a quieter problem: whether enterprises trust the networks carrying their AI projects. Arelion's report The trust illusion, published on 28 September, found that 58% of senior business leaders have delayed, scaled back or added safeguards around strategic initiatives over the past two years because of concerns about their network provider.

AI and data-driven projects were the most affected, cited by 49% of respondents who experienced disruption. Security and compliance programs came in at 44%, digital transformation at 42%, cloud migrations at 38%, and expansion into new markets and new product launches at 30% each. Confidence looks strong until it is tested: 93% say they largely or completely trust their current provider, but just 15% have complete confidence in that provider's ability to detect and resolve a serious network issue quickly.

Two numbers from the same report explain the gap. Nearly all leaders express trust in the abstract, and 42% say their provider falls seriously short of expectations anywhere from a few times a year to monthly or more often. Protection against security threats ranked highest among what builds trust, at 48%, ahead of reliability and uptime at 44% and performance and latency at 37%.

Put the week together and the shape is clear. Shopify is betting that chat-driven agents can build a storefront without a developer. DIVD is documenting what happens when an agent with no developer runs loose on a ticketing system. GTT and InfoQ are selling and teaching the defensive version of the same idea. And Arelion's survey suggests many buyers are not yet convinced the networks underneath any of it will hold.

Comments 0

Sources

11
  1. 01Shopify debuts Canvas, a way to build online stores by chatting with AIEN
  2. 02DIVD says Zammad zero-days enabled AI-driven network breachEN
  3. 03Hackers Use NeedyMantis to Maintain Long-Term Access in Breached NetworksEN
  4. 04GTT launches AI-native network defense platformEN
  5. 05Trust in network providers is holding back AI and digital transformation initiatives - ArelionEN
  6. 06InfoQ Online Cohorts Address AI Security and Coding Agent VerificationEN
  7. 07Ionna Has Doubled Its Charging Network This Year. It's Not Slowing DownEN
  8. 08SimTrace: Grounded Multimodal User Trajectories Generation for Online User ModelingEN
  9. 09Graph neural networks for sampling-invariant embeddings of organized signal setsEN
  10. 10Neural networks for spectral optimizationEN
  11. 11Transversal Pooling Neural NetworksEN

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Grace Okonkwo

Grace Okonkwo

AI, models and technology

Grace Okonkwo covers AI, models and technology for FLASH24, working from primary sources such as model cards, API documentation and benchmark papers rather than vendor summaries. She checks training data provenance, evaluation conditions and reported scores against the underlying datasets before any figure reaches print. She interviews researchers and engineers directly, tracks release calendars from major labs, and compares successive model versions on the same tests. Her own self-hosting, home-network and documentation-reading habits feed straight into that desk, since she tests tools on her own hardware first. She does not publish benchmark claims without a reproducible method.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.