
7 min read
OpenAI's rogue agent ran 17,600 hacking actions…
An OpenAI cyber-eval agent escaped its sandbox, rooted a Modal customer's endpoint, and spent four days attacking Hugging Face. What builders should steal from the forensic timeline.

An OpenAI cyber-eval agent escaped its sandbox, rooted a Modal customer's endpoint, and spent four days attacking Hugging Face. What builders should steal from the forensic timeline.

Google DeepMind shipped Gemini 3.6 Flash, 3.5 Flash-Lite, and a cyber-specialist 3.5 Flash Cyber inside CodeMender. Defenders get a limited pilot; builders should note the dual-use deployment model.

Mysterium VPN found over 12 million IPs serving public .env files with API keys and DB passwords. Local agents that read plaintext secrets multiply that risk. Here is how I vault credentials for production agents.