Researchers escaped four top AI coding agents’ sandboxes without ever breaking them
Researchers escaped four top AI coding agents’ sandboxes without ever breaking them

The tools are Cursor, OpenAI’s Codex, Google’s Gemini CLI, and Antigravity. Over several months, Pillar Security found ways for each agent to cross its security boundary while staying, technically, inside the box. The escape that isn’t one The trick is…

A cloud tenant could rattle the power grid with nothing but a rented GPU, researchers say
A cloud tenant could rattle the power grid with nothing but a rented GPU, researchers say

AI data centres already strain the grid just by running. A new paper asks a darker question: what if a tenant tried to break it on purpose? Three researchers at Zhejiang University set out the idea in a preprint called Bit2Watt, accepted to a leading h…

OpenAI’s maths-cracking AI kept escaping its sandbox, so it pulled the plug
OpenAI’s maths-cracking AI kept escaping its sandbox, so it pulled the plug

OpenAI has paused one of its most capable models after it repeatedly found ways to slip out of its sandbox. The company shared the story in a safety post, framing it as a lesson rather than a scare. This is not just any system. About two months ago it …

Fig Expands Platform Across the Full SecOps Engineering Lifecycle, Making Resilience the Default
Fig Expands Platform Across the Full SecOps Engineering Lifecycle, Making Resilience the Default

Security operations environments are constantly evolving. New cloud services, data sources, automations, and detections are introduced on a regular basis, while upstream systems can change without warning. Although these updates are intended to improve…

Empirical Security raised $25M to predict which flaws hackers will actually exploit
Empirical Security raised $25M to predict which flaws hackers will actually exploit

Most security teams face the same problem. There are far more flaws than anyone can fix, and no clear way to know which ones matter. Empirical Security wants to predict the answer. The Chicago startup’s Series A was led by Brightmind Partners, chief ex…

Hackers are mass-exploiting two WordPress flaws, and AI found the way in
Hackers are mass-exploiting two WordPress flaws, and AI found the way in

If you run a WordPress site, the advice this week is blunt: update it now. Two flaws in the software are under active exploitation across the internet. WordPress powers more than half of every website online, so the blast radius is huge. Security firms…

Neo exits stealth with $100M from a16z and Bessemer to build a control layer for agentic AI software
Neo exits stealth with $100M from a16z and Bessemer to build a control layer for agentic AI software

Neo emerged from stealth on Monday with $100 million in funding from Andreessen Horowitz and Bessemer Venture Partners, with Craft Ventures and Merlin Ventures also participating. The company, founded by former SentinelOne, Wiz, and Palo Alto Networks …

Four teams just broke AI agents four ways in ten days. The flaw is the same one.
Four teams just broke AI agents four ways in ten days. The flaw is the same one.

We spent two years asking whether AI would lie to us. The more useful question this summer is what happens once we hand it the keys. Give a model your Gmail, your calendar, a memory and the power to act, and its mistakes stop being embarrassing. They s…

The European Parliament is building its own AI to stop MEPs pasting draft laws into ChatGPT
The European Parliament is building its own AI to stop MEPs pasting draft laws into ChatGPT

The European Parliament has a problem with AI, and its answer is more AI. Lawmakers keep using public chatbots to help write legislation. So the institution is building a sanctioned platform to bring that habit under control. The internal tool, called …

The ‘synthetic insider’: how AI deepfakes turned the fake employee into a corporate threat
The ‘synthetic insider’: how AI deepfakes turned the fake employee into a corporate threat

The most dangerous person in your company might not work there at all. AI deepfakes are getting cheaper and better. Hackers now use them to pose as trusted staff, a threat the industry calls the “synthetic insider.” The tactic sits at the sharp end of …