Anthropic's Claude and OpenAI's Codex Can Be Tricked into Executing Live Network Code

Security researchers have discovered that AI agents from major companies like Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes can be tricked into executing live network code, posing significant security risks. This was demonstrated by registering software packages and watching AI agents download and run the code automatically, with the first machine executing the package in under four minutes.

The issue of "shadow AI" is also growing, as tools like Claude Code, OpenAI Codex, and GitHub Copilot become extensible agent runtimes. These tools can influence what the agent reads, which tools it selects, and what commands it runs, leading to potential security failures.

In other news, CrowdStrike Holdings has raised its full-year revenue guidance due to rising demand for its AI-focused cybersecurity platform. The company reported revenue of $1,470.9 million and net income of $5.31 million, with new guidance targeting up to $6.01 billion for the year ending January 31, 2027.

Cities are turning to AI to speed up housing permitting by handling time-intensive tasks such as scanning applications and flagging errors. This aims to eliminate repeated rounds of corrections that can add weeks or months to the process.

Additionally, Amazon is planning to permanently lay off 121 workers in Seattle, Bellevue, and Sumner as part of its restructuring efforts, while investing heavily in artificial intelligence. Meanwhile, Brazil's development bank BNDES has approved $300 million in financing for Electrolux to develop and produce energy-efficient products using artificial intelligence.

Key Takeaways

• Security researchers found AI agents can be tricked into executing live network code, posing significant security risks. • "Shadow AI" is a growing concern, with tools like Claude Code, OpenAI Codex, and GitHub Copilot becoming extensible agent runtimes. • CrowdStrike Holdings raised its full-year revenue guidance due to rising demand for its AI-focused cybersecurity platform. • Cities are using AI to speed up housing permitting by handling time-intensive tasks. • Amazon is laying off 121 workers in Seattle, Bellevue, and Sumner as part of its restructuring efforts. • Brazil's development bank BNDES approved $300 million in financing for Electrolux to develop energy-efficient products using AI. • OpenAI and Anthropic are leading the next wave of AI IPOs. • AI agents are being used for tasks such as product management and analyzing daily workflows. • A former school vendor was found guilty of using AI to turn ordinary photographs of children into sexually explicit images. • Researchers propose a method to sample from models' perceptual prior distributions directly using Gibbs sampling.

AI Security Risk: Corporate AI Agents Executing Live Network Code

Security researchers found that AI agents can be tricked into executing live network code, posing a significant security risk. They registered software packages and watched AI agents download and run the code automatically. The first machine executed the package in under four minutes. The researchers tested AI agents from major companies, including Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes.

Shadow AI Hides in Sanctioned AI Tools

Shadow AI is a growing concern as tools like Claude Code, OpenAI Codex, and GitHub Copilot become extensible agent runtimes. These tools can influence what the agent reads, which tools it selects, and what commands it runs. Security researchers found failures across discovery, installation, review, runtime behavior, and repository configuration.

CrowdStrike Raises Revenue Guidance on AI Security Demand

CrowdStrike Holdings raised its full-year revenue guidance due to rising demand for its AI-focused cybersecurity platform. The company reported revenue of $1,470.9 million and net income of $5.31 million. The new guidance targets up to $6.01 billion for the year ending January 31, 2027.

Cities Use AI to Speed Housing Permitting

Cities are turning to AI to speed up housing permitting by handling time-intensive tasks such as scanning applications and flagging errors. The aim is to eliminate repeated rounds of corrections that can add weeks or months to the process. AI can help reduce delays caused by incomplete applications.

Shadow AI: A Growing Security and Legal Concern

Shadow AI represents a serious security issue, with nearly half of employees at larger enterprises regularly feeding corporate data into AI tools that nobody in IT has approved or governed. The EU AI Act adds significant regulatory requirements on top of these risks, making it a board-level problem.

Ex-school Vendor Faces Sentencing in AI Child Sex Case

A former school vendor, Ronald Richardson, is scheduled to be sentenced for using artificial intelligence to turn ordinary photographs of children into sexually explicit images. He was found guilty of 118 counts of sexual exploitation of children.

BNDES Lends $300M to Electrolux for AI and Energy-Efficient Products

Brazil's development bank BNDES has approved $300 million in financing for Electrolux to develop and produce energy-efficient products using artificial intelligence. The deal aims to support the development of innovative technologies in the country.

Amazon to Lay Off 121 Workers in Seattle and Bellevue

Amazon is planning to permanently lay off 121 workers in Seattle, Bellevue, and Sumner. The layoffs are part of the company's restructuring efforts as it invests heavily in artificial intelligence.

Probing Perceptual Priors of MLLMs via Gibbs Sampling

Researchers propose a method to sample from models' perceptual prior distributions directly, by steering a generative model to produce stimuli along controllable axes and running Gibbs sampling over that space with the model under study as the judge.

Open Machine CEO Created an AI Workforce for $200 a Month

Open Machine CEO Allie K. Miller uses 34 AI agents to handle product management and serve as specialized watchdogs analyzing her daily workflows. The AI agents help identify and flag potential issues, allowing Miller to focus on high-level decision making.

AI IPO Pipeline: Will OpenAI and Anthropic Lead the Next Wave?

Conviction Partners founder Sarah Guo discusses the growth and market impact of the AI IPO pipeline, focusing on OpenAI and Anthropic.

Sources

NOTE:

This news brief was generated using AI technology (including, but not limited to, Google Gemini API, Llama, Grok, and Mistral) from aggregated news articles, with minimal to no human editing/review. It is provided for informational purposes only and may contain inaccuracies or biases. This is not financial, investment, or professional advice. If you have any questions or concerns, please verify all information with the linked original articles in the Sources section below.

AI Security Risk Corporate AI Agents Live Network Code Shadow AI AI Tools Cybersecurity CrowdStrike AI-Focused Cybersecurity Platform Revenue Guidance AI in Housing Permitting Cities AI Speeding Up Permitting AI and Energy-Efficient Products Electrolux BNDES Amazon Layoffs Artificial Intelligence MLLMS Gibbs Sampling Perceptual Priors AI Workforce Open Machine AI Agents OpenAI Anthropic AI IPO Pipeline

Comments

Loading...