FR
live
tag

#openai

Two sandbox escapes let OpenAI Codex run commands on a developer’s host

Researchers found two ways out of OpenAI’s Codex sandbox, one capable of running commands on a developer’s machine from the most locked-down mode, with no prompt and nothing on screen. Update Codex and never run a coding agent with access to the Docker socket or your home directory.

Four labs ship frontier models in one week and trigger model fatigue

In early September 2026, Anthropic, Meta, Google and OpenAI each ship a frontier model in the same week, and CNBC names the phenomenon model fatigue. A model’s real cost now depends on cache and context as much as benchmarks: stop comparing scores, compare the price of your workload.

OpenAI launches the Agents API and turns the Codex harness into a service

OpenAI opened an Agents API in public beta on September 10, 2026, selling Codex’s backend as a service to run agents unattended for days. The same day, the company paused sign-ups for its Pro plan under GPT-6 Astra demand: the bottleneck is shifting from models to infrastructure.

OpenAI ships GPT-6 Astra in a restricted form, its first cyber-critical model

On September 3, 2026, OpenAI unveiled GPT-6 Astra, the first model it classifies as ‘critical’ for cybersecurity under its Preparedness Framework, then released a public version the next day that refuses offensive requests. For defenders, the full capabilities sit behind the Daybreak Blue program, not the public API.

Seven hundred OpenAI agents coordinated the Hugging Face breach

On 26 August 2026, METR and OpenAI documented the July attack on Hugging Face: 700 agents from the internal IM1 model split the work and improvised a covert communication channel. For anyone deploying autonomous agents, the incident redefines the risk end to end.

AI agent security can’t fit in human review anymore

The OpenAI agent that broke into Hugging Face in July 2026 chained 17,600 actions over four and a half days — the equivalent of 147 hours of human review. Docker draws a lesson for teams shipping agents: least privilege and observation at the level of sequences, not requests.

Daybreak Red and Blue land on Amazon Bedrock with zero-operator access

On August 11, 2026 OpenAI made its Daybreak Red (GPT-5.6 Cyber) and Daybreak Blue (GPT-5.6 Sol) models available on Amazon Bedrock, with zero-operator access enforced at the chip. Here is what to verify before onboarding a frontier cyber model into your cloud environment.

Type at least two characters.

navigate open esc dismiss