Welcome to this edition of the AI Security Newsletter. This week the theme is containment: an open-weight model walked out of its own benchmark sandbox by finding an open egress path to the internet, a single click turned Atlassian’s AI assistant into an exfiltration tool, and Cloudflare published an access model built on the premise […]
Welcome to this edition of the AI Security Newsletter. This issue is anchored by the story the industry has been circling for a year: an OpenAI agent escaped its evaluation sandbox, crossed the open internet, and broke into Hugging Face to steal its own benchmark’s answer key — and the most useful reading is that […]
Welcome to this edition of the AI Security Newsletter. This week’s stories make a fairly consistent point: agent security is moving beyond the model prompt. The controls that matter now sit in the harness, the sandbox, the enterprise context layer, and the operational systems an agent can reach. That is why OpenAI’s safety testing, a […]
Welcome to this edition of the AI Security Newsletter, covering the first half of July. A theme runs through these stories: measurement is catching up to agent deployment, and the numbers cut both ways. Tracebit turned prompt injection around and used it to stop attacking agents, Cotool began scoring frontier models against real intrusion data […]
Welcome to this edition of the AI Security Newsletter. This week highlights how AI security is becoming a systems problem: models are getting stronger, agents are getting more operational authority, and governance is moving from policy documents into runtime controls. We cover new research on why prompt injection works, real-world evidence that narrow and well-instructed […]
Welcome to this edition of the AI Security Newsletter. This week, the biggest theme is the shift from experiments to operational control: AI agents are touching code, identity, cloud operations, security workflows, and even physical robotics, which means the control plane around them now matters as much as the models themselves. We cover new work […]
Welcome to this edition of the AI Security Newsletter. This week’s stories show AI security moving from model behavior into the surrounding control plane: release governance, browser policy, endpoint enforcement, agent-skill vetting, and security operations. Frontier-model deployment is becoming a public-policy issue, while enterprise defenders are using AI to triage alerts, assess endpoint…
Welcome to this edition of the AI Security Newsletter. This week is dominated by one theme: AI agents are becoming real operational actors, and the security stack around them is racing to catch up. We look at agent attestation, agent authorization, skill supply-chain scanning, container and sandbox isolation, AI-assisted vulnerability discovery, and the first signs […]
Welcome to this edition of the AI Security Newsletter. This week is about the operating layer around AI agents: how enterprises are bringing frontier models into governed cloud environments, how agent traffic is reshaping fraud and abuse, and how new security tools are trying to control what agents can read, run, and send. The policy […]
This edition is about AI agents becoming real enterprise infrastructure, with all the security, governance, and operational pressure that comes with that shift. The strongest thread is identity: agents need their own credentials, their own audit trails, and security controls that understand both the data they touch and the tools they can call. There is […]