{"data":{"id":"b984f66e-93d4-42d1-82c0-b26e74d93f59","title":"AWS takes aim at runaway AI agent behavior with Strands Box","summary":"AWS has released Strands Box, an open-source sandbox for AI agents, in developer preview under the Apache 2.0 license. It combines operating system-level isolation with policies written in Dogwood, an AWS-developed policy language, that can factor in an agent's prior activity across tools, and currently supports Macs with Apple silicon running macOS 15 or later. Dogwood does not evaluate files accessed directly through an agent harness's built-in tools, and the shell and Python interpreters run outside the sandbox as a trusted process.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"https://www.csoonline.com/article/4232446/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box-2.html","publishedAt":"2026-10-08T10:17:15.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["Amazon"],"affectedVendorsRaw":["AWS","Strands Box","Dogwood","Amazon Bedrock AgentCore","Amazon ECS","Kubernetes","Apple silicon"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-08T10:17:15.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}