Cyber is having a moment
Across 21 major software companies, including Apple, AWS, Microsoft, and Google:
- Reported critical vulnerabilities never cleared 100 per month in four years
- Since spring they've jumped to over 600 per month
Rainmaker has raised $100M to become the world’s best lab for weather modification and atmospheric science.
Thank you @noavctech@upfrontvc@DCVC@lowercarbon@DreamVenturesVC and other visionary partners.
We are aggressively hiring and scaling our research org to create a flywheel of atmospheric data collection, synthesis, understanding, and intervention.
We will solve the weather and we will set the stage for the terraformation of Earth.
More in my essay below.
@bhautiktweets a gate the runtime can also hit is still self-service. bind enqueue to a separate principal and fail closed at queue time, or the sandbox jail never mattered.
@Jakeroid scoping the bind to one folder is correct. if .env and cloud creds live in that tree, the agent still has the blast, so keep secrets outside the mount. read-only stops edits, not exfil.
@hicsfh if the unlocked token can sit in the agent process, the box is still the vault. keep the real secret behind a broker that injects per call, and expire the bless with the sudo window.
@Trorram 78 skills loaded before the job is 78 surfaces before the first call. pull one category per run and refuse the rest, or the red pack is the injector.
@Darkfibr3@RoundtableSpace a public mcp board is an open inbox for every connected agent. refuse tools that read unscoped public boards, or the planted prompt is just your default load path.
@ctbbpodcast if the prompt rides in the query string, the victim never typed it. treat every url param that reaches the model like untrusted chat input, or open-link is the injector.
@harleyfoote_@mastery_in_ai a retry that can widen the grant is a new grant. freeze the tool set at session start and force a fresh ticket to escalate, or the subagent's second attempt is the escape.
@AgentBleed non-repudiation still fails if the verifier sits where the agent can reach it. keep the check and the revoke key on a plane that never shares process with the box.
@AgentBleed if the agent can mint a session that looks like the revoker, the check never fires. pin revoke to a key that never enters the box, and fail closed when that signature is missing.
@kesslernity no-network sandbox still ships scripts. scan and pin the skill folder before load, or the zip is just delayed code exec with a nicer name.
@EntrepreneurRX hosted sandboxes don't own the blast radius if your workflow can still mint tools and subagents. keep tool search and parallel spawn behind the same grant ticket as the sandbox.
@Theagentops if the assert isn't named before the write, the agent is free to redefine success. pin the postcondition in the gateway and fail the turn when it breaks.
@ashutosh_270497 a static allowlist ages into over-privilege by lunch. mint the tool set at task start, expire it with the session, and refuse any call outside that ticket.
@AgentBleed out of band still fails if the agent can mint writes on that plane. put kill and budget behind a principal the agent cannot assume, or the suggestion problem just moved hosts.