@KerenKoshman נשמע סביר. כבר היום קלוד קוד הלכו עוד צעד בעקבות פאי ועכשיו ההארנס שלהם גם הוא self-evolving.
אני בהחלט רואה סיטואציה בה עוד חצי שנה המודלים כל כך טובים בלשפר את ההארנס של עצמם כך שאנחנו כבר לא נחשוב על זה.
This is our third sandbox escape writeup, and after Claude Code and Cursor, it's OpenAI's Codex this time!
This one is especially cool, for two reasons:
1. One of the escapes is from the open source codex cli. As an open source project, we found it to be generally much more secure than its competition.
2. The second escape is in the rust-based closed source - and it leverages a sophisticated heap attack.
Kudos to @OpenAIDevs@OpenAI for fixing this super quickly and to @Accomplish_ai researcher @orenyomtov for finding it.
Both fixed now, and here are all of the details:
We're making Git hosting more reliable, performant, and scalable.
This post traces 20 years of Git infrastructure and explains how that history led us to design and operate our Git storage, Origin, as if it were a database.
https://t.co/UW7jHuItSX
Today we are open-sourcing @boundarybench, a new paper, benchmark, and GitHub repo that enterprises can use to find out the REAL performance of their agents.
Boundary-Bench was developed by researchers from @Accomplish_ai and NYU, where we tested 12 frontier agents across roughly 10,000 runs, with realistic enterprise policies, simulating environments with EDR, SASE, and DLP security tools enforcing those policies.
We did this because generic leaderboard scores are being generated under conditions no security team would ever allow, which means orgs are making deployment and risk decisions based on numbers that don't hold up.
The results are surprising >>
Introducing SharedRoot vulnerability: we recently found and reported several sandbox escape vulnerabilities to @AnthropicAI, and today we want to share one of these.
I think most people don't understand the severity of the situation we are facing, with AI-assisted kernel bug-finding industrializing. Sandboxes are structurally one N-day behind, all the time, so containment can't lean on a guest Linux kernel being clean.
SharedRoot enables escaping the Cowork VM (a kernel-level isolated solution, which is considered much more secure than the sandbox that ships with codex or claude code), allowing an attacker to gain unauthorized access to the user’s computer.
Exploiting the SharedRoot vulnerability uncovered by the @Accomplish_ai research team, a user who is certain Cowork only has access to a specific uploaded folder on their computer - actually exposes their entire contents of their computer to an attacker leveraging the Cowork vulnerability.
Read about the full technical details of the attack chain in our blog post by @orenyomtov below -->
few weeks ago, Fable 5 was so advanced it needed the gov and had to be taken offline.
today, we have access to arguably better models for $20/month.
took what? six weeks?
Agentic loops are stubborn, which is why agents are effective.
However, in hardened enterprise environments, things start to break.
How do they break, and how can you steer the agent's pivoting behavior the right way?
Some findings from our research, Fable/Mythos included! 👾