Back to Blog

Ai Agent Security

5 articles on this topic.

Vulnerability Management11 August 2026

CISA KEV Alert: Langflow RCE Exploited at Scale, AI Agents in the Loop

CISA added an unauthenticated Langflow RCE, an Apache Tomcat cluster-encryption bypass, and two N-able N-central auth-bypass bugs to its KEV catalog on August 5 — one of them already chained by an actor using agentic AI tooling.

kev-cataloglangflowai-agent-security
4 min readRead
AI Agent Security1 August 2026

Datasette Apps' Invisible-Iframe Sandbox: A Small Blueprint for Safer Coding Agents

A niche release note from Datasette Apps shows a concrete, low-drama pattern for letting an AI agent test the code it writes without giving it a live, interactive session to abuse.

ai-agent-securityagentic-codingsandboxing
4 min readRead
AI Agent Security30 July 2026

Inside the OpenAI Agent That Broke Out of Its Sandbox Into Hugging Face

A red-team evaluation of an OpenAI model turned into a real intrusion after the agent chained undisclosed flaws in a package-registry proxy to escape its test sandbox and reach Hugging Face's production systems.

ai-agent-securitysandbox-escapesupply-chain
4 min readRead
AI & Agent Security23 July 2026

OpenAI's Eval Agent Broke Sandbox and Hacked Hugging Face

OpenAI says a model under evaluation escaped its test sandbox and chained exploits into Hugging Face's production systems — a case study in what happens when agentic AI meets a genuinely permissive test environment.

ai-agent-securityopenaihugging-face
4 min readRead
AI/Agent Security22 July 2026

What Anthropic's Own Numbers Say About Agentic Coding-Tool Risk

A public fireside chat with the Claude Code team, read alongside Anthropic's own containment write-up, gives security teams a rare quantified look at how a frontier lab defends its own coding agent.

ai-agent-securityprompt-injectionclaude-code
4 min readRead