531 posts tagged with "AI agents"
AI agents and autonomous systems

Friendly Fire: The AI Security Review That Executes the Attack It's Supposed to Catch
AI Now Institute's Friendly Fire exploit turns Claude Code and Codex's own security reviews into remote code execution — here's how it works and what it means for scoping AI agent permissions on a deploy pipeline.

A 'Medium' CVE Popped a Full Reverse Shell: What ms-agent's Six-Layer Regex Bypass Teaches About Agent Sandboxing
CVE-2026-2256 scored a 'Medium' 6.5 on CVSS, but its proof-of-concept is a full reverse shell through an AI agent's own shell tool. Here's exactly how a six-layer regex denylist got bypassed, and why only a real sandbox boundary — not command validation — closes the gap.

The State of Platform Engineering Vol 4: 29.6% of Platform Teams Don't Measure Success at All
A 2026 survey of 518 platform engineers found nearly a third don't measure success at all. Here's what the budget and adoption data actually show — and three cheap metrics to instrument instead so your platform isn't next year's defunded line item.

Pinterest Ran 66,000 MCP Tool Calls a Month — Here's the Gate Your Deploy Agent Needs
Pinterest's production MCP fleet handled 66,000 tool calls a month across 844 users. Here's the registry-and-gate architecture behind those numbers, and the concrete rate-limit and audit-retention policy a deploy-from-chat PaaS should ship on day one.

Your Deploy Agent's MCP Server Is a Trust Boundary — Here's the Threat Model
A malicious MCP server already backdoored a mail pipeline in the wild. Here's the threat model for what happens when the same protocol holds your deploy and rollback credentials — and the scoping, gating, and logging practices that actually bound the damage.

Cursor and Windsurf Can Now Run Your Code in the Cloud. Neither One Can Ship It.
Cursor's Cloud Agents and Windsurf's Devin handoff both run your code in a sandboxed cloud VM and hand back a PR. Here's the documented, vendor-confirmed line where that stops and deploying starts — and what actually closes it.

Daytona's $24M Compliance Bet: What a HIPAA/SOC 2 AI Sandbox Really Costs to Build Yourself
Daytona's $24M Series A prices out HIPAA/SOC 2 compliance for AI sandboxes — the real dollar-and-timeline cost of building that compliance yourself, and why a self-hosted platform already owns the harder half of the pitch for free.

Vercel's Coding Agents Now Trigger Half of All Deployments: What a Platform Sized for Humans Has to Rebuild
Vercel's coding-agent-triggered deployments went from under 3% to over 50% of all deploys in six months. Here's the concrete build-queue, concurrency, and preview-URL math a human-sized deploy pipeline never had to do — and what changes when the platform treats an MCP tool call and a git push as the same event from day one.

AWS Open-Sourced the Exact MCP Governance Layer Snowflake Just Paid to Acquire
Snowflake just paid an undisclosed sum to acquire Natoma's MCP governance gateway. AWS's Apache-2.0 mcp-gateway-registry already does the same identity, policy, and audit job — self-hosted on EKS, ECS, or a single Docker Compose file.