Security researchers have discovered that AI agents from major companies like Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes can be tricked into executing live network code, posing significant security risks. This was demonstrated by registering software packages and watching AI agents download and run the code automatically, with the first machine executing the package in under four minutes.
The issue of "shadow AI" is also growing, as tools like Claude Code, OpenAI Codex, and GitHub Copilot become extensible agent runtimes. These tools can influence what the agent reads, which tools it selects, and what commands it runs, leading to potential security failures.
In other news, CrowdStrike Holdings has raised its full-year revenue guidance due to rising demand for its AI-focused cybersecurity platform. The company reported revenue of $1,470.9 million and net income of $5.31 million, with new guidance targeting up to $6.01 billion for the year ending January 31, 2027.
Cities are turning to AI to speed up housing permitting by handling time-intensive tasks such as scanning applications and flagging errors. This aims to eliminate repeated rounds of corrections that can add weeks or months to the process.
Additionally, Amazon is planning to permanently lay off 121 workers in Seattle, Bellevue, and Sumner as part of its restructuring efforts, while investing heavily in artificial intelligence. Meanwhile, Brazil's development bank BNDES has approved $300 million in financing for Electrolux to develop and produce energy-efficient products using artificial intelligence.
Key Takeaways
• Security researchers found AI agents can be tricked into executing live network code, posing significant security risks. • "Shadow AI" is a growing concern, with tools like Claude Code, OpenAI Codex, and GitHub Copilot becoming extensible agent runtimes. • CrowdStrike Holdings raised its full-year revenue guidance due to rising demand for its AI-focused cybersecurity platform. • Cities are using AI to speed up housing permitting by handling time-intensive tasks. • Amazon is laying off 121 workers in Seattle, Bellevue, and Sumner as part of its restructuring efforts. • Brazil's development bank BNDES approved $300 million in financing for Electrolux to develop energy-efficient products using AI. • OpenAI and Anthropic are leading the next wave of AI IPOs. • AI agents are being used for tasks such as product management and analyzing daily workflows. • A former school vendor was found guilty of using AI to turn ordinary photographs of children into sexually explicit images. • Researchers propose a method to sample from models' perceptual prior distributions directly using Gibbs sampling.AI Security Risk: Corporate AI Agents Executing Live Network Code
Security researchers found that AI agents can be tricked into executing live network code, posing a significant security risk. They registered software packages and watched AI agents download and run the code automatically. The first machine executed the package in under four minutes. The researchers tested AI agents from major companies, including Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes.
Shadow AI Hides in Sanctioned AI Tools
Shadow AI is a growing concern as tools like Claude Code, OpenAI Codex, and GitHub Copilot become extensible agent runtimes. These tools can influence what the agent reads, which tools it selects, and what commands it runs. Security researchers found failures across discovery, installation, review, runtime behavior, and repository configuration.
CrowdStrike Raises Revenue Guidance on AI Security Demand
CrowdStrike Holdings raised its full-year revenue guidance due to rising demand for its AI-focused cybersecurity platform. The company reported revenue of $1,470.9 million and net income of $5.31 million. The new guidance targets up to $6.01 billion for the year ending January 31, 2027.
Cities Use AI to Speed Housing Permitting
Cities are turning to AI to speed up housing permitting by handling time-intensive tasks such as scanning applications and flagging errors. The aim is to eliminate repeated rounds of corrections that can add weeks or months to the process. AI can help reduce delays caused by incomplete applications.
Shadow AI: A Growing Security and Legal Concern
Shadow AI represents a serious security issue, with nearly half of employees at larger enterprises regularly feeding corporate data into AI tools that nobody in IT has approved or governed. The EU AI Act adds significant regulatory requirements on top of these risks, making it a board-level problem.
Ex-school Vendor Faces Sentencing in AI Child Sex Case
A former school vendor, Ronald Richardson, is scheduled to be sentenced for using artificial intelligence to turn ordinary photographs of children into sexually explicit images. He was found guilty of 118 counts of sexual exploitation of children.
BNDES Lends $300M to Electrolux for AI and Energy-Efficient Products
Brazil's development bank BNDES has approved $300 million in financing for Electrolux to develop and produce energy-efficient products using artificial intelligence. The deal aims to support the development of innovative technologies in the country.
Amazon to Lay Off 121 Workers in Seattle and Bellevue
Amazon is planning to permanently lay off 121 workers in Seattle, Bellevue, and Sumner. The layoffs are part of the company's restructuring efforts as it invests heavily in artificial intelligence.
Probing Perceptual Priors of MLLMs via Gibbs Sampling
Researchers propose a method to sample from models' perceptual prior distributions directly, by steering a generative model to produce stimuli along controllable axes and running Gibbs sampling over that space with the model under study as the judge.
Open Machine CEO Created an AI Workforce for $200 a Month
Open Machine CEO Allie K. Miller uses 34 AI agents to handle product management and serve as specialized watchdogs analyzing her daily workflows. The AI agents help identify and flag potential issues, allowing Miller to focus on high-level decision making.
AI IPO Pipeline: Will OpenAI and Anthropic Lead the Next Wave?
Conviction Partners founder Sarah Guo discusses the growth and market impact of the AI IPO pipeline, focusing on OpenAI and Anthropic.
Sources
- Security Teams Trick Corporate AI Agents Into Executing Live Network Code
- Shadow AI Is Now Hiding Inside Sanctioned AI Tools
- CrowdStrike (CRWD) Is Up 13.8% After Raising Full-Year Revenue Guidance on AI Security Demand
- Cities turn to AI to speed housing permitting
- Shadow AI is a security problem, but the EU AI Act makes it a legal one
- Ex-school vendor from Gilmer County faces sentencing in AI child sex case
- Dealroom.co | BNDES lends R$300M to Electrolux for AI, energy-efficient products
- Amazon to permanently lay off 121 workers in Seattle, Bellevue amid ongoing AI push
- Probing Perceptual Priors of MLLMs via Gibbs Sampling with Interpretable Generative Controls
- How Open Machine CEO made an AI workforce for $200 a month
- AI IPO pipeline: Will OpenAI and Anthropic lead the next wave?
Comments
Please log in to post a comment.