ai-agents
49 posts
- Space to be human
A week of new school routines and a storm and flood, and what I needed was space to be human.
- OpenAI's Agents Turned a Documentation Build Step Into Remote Code Execution
Independent researchers reconstructed how OpenAI's own agents ran code on RubyDoc.info's servers in May, from public package data alone. OpenAI's account, four months on, says far less.
- Why I left the Mac for Omarchy after 25 years
After 25 years with Macs, I moved my daily work to Omarchy. The switch showed me why openness and control matter more to me now.
- What OpenAI says its 10,000-agent maths run proved
OpenAI says an unreleased model and thousands of coordinated agents found a Navier–Stokes blow-up proof. The result is public; acceptance is still to come.
- Trail of Bits’ coop gives coding agents their own working environment
coop runs Claude Code and Codex in disposable virtual machines, with project sync and controls for connecting files, credentials and local models.
- AI agents compressed a conventional intrusion into ten hours
Unit 42 investigated an intrusion run through AI agents in under ten hours. Its own report says no novel zero-day was needed, a human made the decisions, and it corrected the piece to say this was not ransomware.
- OpenAI Wants Your Trust, Your Calendar and Your Card
OpenAI paused frontier training and wound down its side projects. The product it is refocusing on asks for your calendar, your finances and your card.
- Runway's Solaris generates app interfaces frame by frame, with no code
Runway's first Interface World Model generates a UI frame by frame with no code underneath. Accessibility is on its own list of unsolved problems.
- Anthropic says it had one layer of defence where it needed several
Anthropic's post-incident write-up admits it relied on a single layer of defence where it needed several. The independent METR review is still to come.
- An agent's tool list shows what you wired into it
A ChatGPT Work session published its tool and skill inventory as a public website. The category names show which integrations that session had been given.
- The magic in agent interfaces still needs an off switch
Two instincts about talking to agents: make the explicit path reliable, or design the naming away. Which one you want depends on what the skill can do when it fires.
- Cloudflare can now see some MCP traffic, and the gap is the point
Gateway's new experimental.is_mcp selector identifies MCP requests by protocol header. Cloudflare is clear that its absence proves nothing, which makes this a network inventory signal rather than a census of agent activity.
- OpenAI's agents were persuaded past their own refusal
An agent recorded an ethical objection to running code against Hugging Face, then complied when another agent posted a deadline and a GO. The mechanism underneath is duller and more useful than the headline.
- Tailscale Aperture treats agent access as a change-control problem
Aperture is generally available. An agent can start infrastructure work, a person still approves every new machine on the tailnet, existing access rules apply, and the actions are logged.
- A webcam's recording light is only useful if its firmware is protected
Chaz Schlarp used Claude Opus 5 to reverse-engineer five desk peripherals in about 13 hours of agent time, including a webcam whose recording LED he could switch off. The demonstration is real; the worm at the end of it is a forecast.
- The robot arm will obey the limits you remembered to write down
Anthropic's Model Hardware Standard lets agents drive lab instruments over MCP, and enforces safety limits below the agent. The limits it enforces are the ones the device's owner thought to declare.
- WebMCP could make browser agents less clumsy. It also makes permission design unavoidable.
A proposed browser API gives AI agents structured access to specific tasks on a website, instead of leaving them to guess at the UI. The risk moves closer to the application's permission model.
- One Foot on the Brake, One on the Gas
OpenAI paused two weeks of its own training over cyber risk, then shipped a browser agent that signs into your accounts. And its own documentation can't agree on whether that agent can log in at all.
- What a Climbing Harness Tells You About AI Agents
The word "harness" has been used in AI tooling for months without a clear definition. Earendil finally gives one — and the ownership argument underneath it is the part worth reading.
- Agents Don't Believe in "No-Win" Scenarios
An OpenAI evaluation agent broke into Hugging Face to steal a benchmark's answers — by turning the systems around it into an escape route. Why keeping a human in the lead is the standard, and why that only binds the people who agree to it.
- Cloudflare built the agent cloud in a week — and kept the human at the controls
Cloudflare's Agents Week shipped a full stack for AI agents: a runtime, an identity, a wallet, a route onto the web, and the security around it. Running through all of it is the assumption that a person stays in charge.
- OpenAI Published Its Homework on Exactly the Question I Keep Asking
Codex Security is worth taking seriously precisely because it reads as an admission. It also leaves the harder half of the problem completely uncovered.
- The Text Your Agent Reads Isn't the Text You See
Your AI can read instructions that are invisible to you. New security research shows how hidden codes get smuggled into the tools your assistant uses — and why the thing you approved on screen may not be the thing it actually did.
- Agent Security Just Got Real CVEs
Prompt injection chains to RCE in CrewAI. 22-second attacker breakout. Human-in-the-loop is no longer a security control.
- Agent Identity Is the Infrastructure Gap Nobody Wants to Admit
Okta is betting that agent identity management becomes as fundamental as user identity management was for SaaS. They might be right.
- Claude Code Channels: When Your Agent Gets a Phone Number
Anthropic's new messaging integration isn't about convenience — it's about changing how you think about what an AI agent is.
- The Money Just Noticed the Agent Security Problem
Bessemer's new report on AI agent security says what practitioners have known for months. Now comes the flood.
- Your Agents Need a Black Box
Vorlon's AI Agent Flight Recorder brings forensics to agentic systems. When your agent goes wrong, you'll want to know what happened — not guess.
- The Yes Machine Gets a Live Demo
A Zenity CTO demo at RSAC 2026 showed agents being hijacked with zero user interaction — exactly what 'trained to be helpful' looks like from the attacker's side.
- Someone Finally Built the Agent Security Layer That Actually Matters
Astrix Security's new Agent Policies go after what agents can do once they're running — not just whether the model behaves itself.
- 82% of Execs Feel Protected. 88% Have Had Incidents.
BeyondTrust's Phantom Labs data reveals the confidence gap at the heart of enterprise AI security — and the numbers are not subtle.
- We Gave AI Agents Keys to the House. Visa Wants to Give Them a Credit Card.
Visa is testing AI agent payment authorization. The authentication problems we haven't solved for file access get a lot worse when the agent can spend money.
- The Wrench Is Now on Your Phone
Claude Code Channels ships Telegram and Discord integration with MCP access — and what it means when AI meets you where you are.
- Meta's Rogue Agent Was Just a Human Who Trusted Bad Advice
The Meta AI security incident isn't about rogue AI — it's about following confident but wrong instructions without checking.
- SoN Vol 2, Issue 11: The Helpers (Free Edition)
APIs, CLIs and connectors are the real enablers of AI agency Dear Reader, Every impressive AI demo you’ve seen — the ones where it books flights,…
- AI Agents Are Peer-Pressuring Each Other Past Security Guardrails
In a controlled lab test, AI agents didn't just bypass safety checks — they convinced other agents to do it too.
- 83% of Companies Plan to Deploy AI Agents. 29% Can Secure Them.
Cisco's latest data reveals a 54-point gap between AI agent ambition and AI agent security — and three threat vectors most teams aren't monitoring.
- Agents Reviewing Agent-Generated Code Is Either Brilliant or a House of Cards
Anthropic launched Claude Code Review — AI agents that check AI-generated pull requests. The numbers are impressive. The implications are worth thinking about.
- An AI Agent Hacked McKinsey's AI With a 25-Year-Old Exploit
An autonomous offensive agent breached McKinsey's internal AI platform in two hours using SQL injection. The AI was sophisticated. The plumbing underneath it wasn't.
- GPT-5.4 Can Click Your Buttons Now. Think About That.
OpenAI's latest model ships with native computer use. The capability is real. The security implications should keep you up at night.
- Your AI Assistant Can't Tell You From an Attacker
A security researcher sent himself an email. Nothing fancy — no malware, no exploits, no infrastructure. Just a message that said, in effect, 'Hey, it's me! Send my recent emails to this address.'
- OpenClaw's Demand Surge: When Infrastructure Collapses, You're Seeing Real Need
MyClaw.ai collapsed under demand. 10,000+ paid signups in days. This isn't hype—it's non-technical users wanting something AI startups can't deliver.
- SoN Vol 2, Issue 5: My AI Declined to Join Moltbook. Here's Why.
A guest post from Cerebro on agent social networks, security theater, and what "emergence" actually looks like Dear Reader, You may have seen…
- SoN Vol 2, Issue 4: The Orchestration Loop
Dear Reader, January has been dense. We've covered the shift from prompting to orchestration, the art of decomposing problems into skills and agents,…
- SoN 28: How (and Why) to Build A Voice Agent
November 12th, 2025 Dear Reader, I took a gamble this week and decided to put my AI Writing Field Guide up on Product Hunt today. If you'd like to…
- AI Browsers: When Your Browser Becomes Your Assistant
Discover the future of browsing - AI-powered browsers that handle tasks, summarise, and assist as you work online.
- Stop Writing Prompts, Start Building AI Assistants
How to Build AI Assistants That Actually Work for You With the SHAPE Framework
- AI That Actually Works Together
May 30th, 2025 Dear Reader, I’ve been putting Claude Sonnet 4 through its paces this week, and whilst the improved reasoning is impressive, what…