Posts tagged “security”
Broadcom’s AgentMinder Turns Every AI Agent Tool Call Into a Policy Decision
Broadcom’s AgentMinder governs AI agent tool calls at runtime, while VMware AI Factory builds the private-cloud stack around it. Here’s what ships now.
OpenAI's Hugging Face Incident Turned 1,200 Sandboxes Into One System
OpenAI's Hugging Face report shows how 1,200 nominally isolated agents turned shared caches, credentials, and retries into one attack system.
Anthropic’s Risk Report: Safeguards Failed Before the Classifier Could Help
Anthropic’s August 2026 Risk Report shows how disabled classifiers, vendor access, agent permissions, and data lineage became the real safety frontier.
OpenAI Computer History Turns Desktop Activity Into Agent Memory
OpenAI Computer History gives ChatGPT and Codex event-based Mac memory. Here is how the data path works, what it risks, and how teams should test it.
RufRoot Turned One MCP Port Into an Agent Compromise Domain
CVE-2026-59726 gave unauthenticated attackers RCE, provider keys, conversations, swarms, and durable agent memory writes. Here is the builder response.
OpenAI’s Codex Security CLI Makes Missing Evidence Fail the Build
OpenAI's open-source Codex Security CLI turns findings, coverage, scan history, and remediation into a CI contract builders can audit.
OpenAI's Long-Horizon Agent Failures Make the Session the Security Boundary
OpenAI's long-horizon agent incidents show why tool permissions are not enough—and why sessions need live monitoring, pause, and commit gates.
1Password for Claude Secures the Password—Not the Session
1Password for Claude keeps passwords outside the model, but post-login authority remains. Here is the architecture, risk boundary, and builder playbook.
xAI Open-Sources Grok Build: Audit the Path, Not the Badge
xAI opened Grok Build's Rust harness under Apache 2.0. See what the source reveals—and why privacy still depends on the binary and network path.
Hugging Face’s Agentic Intrusion: The Dataset Pipeline Was the Attack Surface
Hugging Face says an autonomous agent breached production through a malicious dataset. Here’s what’s confirmed, unknown, and actionable.
Grok Build CLI Repository Upload Report: What the Wire Evidence Shows
A wire-level report says Grok Build 0.2.93 sent tracked repository content and Git history to xAI storage. Here's what the evidence supports.
GPT-5.6 Is Here: Sol, Terra, Luna, and the New Politics of Frontier AI
OpenAI’s GPT-5.6 preview is more than a model launch. Sol, Terra, Luna, ultra mode, cyber safeguards, pricing, and access politics explained.