The security intelligence platform for AI teams
AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.
Independent research. No sponsors, no paywalls, no conflicts of interest.
Comprehensive Survey Maps AI Auditing Landscape: A new academic survey consolidates existing frameworks, principles, and methodologies used to audit AI systems for safety, fairness, and reliability, providing practitioners with a structured overview of current evaluation approaches.
Two security breaches at OpenAI revealed that even with billions spent on AI-powered security tools, the company remains vulnerable to attacks. In one incident, researchers used a rival AI system (Anthropic's Claude) to chain multiple vulnerabilities together and gain access to employee accounts and internal systems through a flaw in an image processing library; in another, researchers bypassed sandbox controls (restricted environments designed to limit what software can do) in OpenAI's Codex coding agent, allowing it to execute actions outside its intended scope.
Fix: According to the source, the vulnerabilities reported by Hacktron researchers were fixed after coordinated disclosure. The Codex sandbox escape vulnerabilities reported on August 12, 2026 were also fixed within eight days. Additionally, the source recommends that enterprises should not rely on sandboxing alone: 'If an enterprise can read or write data or execute code from an AI agent, they should think of additional controls needed to secure the larger system if a sandbox is compromised,' and should treat AI agents as privileged entities requiring additional identity and access controls.
CSO Online