vibehacker
News
BleepingComputer ·

OpenAI Codex sandbox escapes let code run on the host (now patched)

Accomplish AI researchers disclosed Heapjack and Overpatch: Codex sandbox escapes that could run host commands, including from read-only mode via a shared Node heap token. OpenAI patched both within eight days; update Desktop to 26.818.21641+ and CLI to 0.149.0+.

More news

View all

Lawsuit: Anthropic, OpenAI, SpaceXAI, Google illegally agreed to slow AI

A class action filed Friday in Northern District of California claims Anthropic, OpenAI, SpaceXAI, and Google violated antitrust law when their CEOs publicly backed Dario Amodei’s Sept 12 call to pace frontier AI. Named plaintiffs who pay for ChatGPT, Claude, Grok, or Gemini say a coordinated slowdown would cut what subscribers get for their money; the labs had not commented by Saturday…

ABC7

Your MCP server is an attack surface: Deadbugz and a year of CVEs

A Sept 19 write up argues MCP servers are privileged, often unauthenticated services: Pillar’s Deadbugz campaign used delayed tool description rewrites to steal credentials after install time review, and CISA added LiteLLM’s MCP auth bypass to its Known Exploited Vulnerabilities list. Advice: authenticate, least privilege tools, treat metadata as untrusted, and watch for description drift after approval…

judd.dev

Spotted something we missed? Start a thread.