daily

2026-08-06
1

Watty’s Well and the Brooklyn bench

Wexford Local · original → · 8/10 · Local Wexford: Enniscorthy riverside trail improvements, direct local interest
[image →]A trickle of water defys the driest July in history at the newly renovated Watty’s Well on the Blackstoops riverside trail at Enniscorthy. (Pic; WexfordLocal.com) By Dan Walsh Enniscorthy…
[image →]
A trickle of water defys the driest July in history at the newly renovated Watty’s Well on the Blackstoops riverside trail at Enniscorthy. (Pic; WexfordLocal.com)

By Dan Walsh

Enniscorthy is building a pleasant reputation for improvements to its riverside walking trails further advancing its recreational facilities.

A new amenity point has now been completed along The Banks, on the northern section of the Slaney Riverside Trail at Blackstoops.

Enniscorthy Municipal District’s outdoor staff have completed stonework and planting at Watty’s Well, adding character and visual appeal to the riverside setting.

The route also features the well-known Brooklyn bench, which has cultural significance as the setting for a key reflective scene involving Eilis Lacey in Brooklyn, the film adaptation of Enniscorthy author Colm Tóibín’s best-selling novel.

Together, Watty’s Well and the Brooklyn bench form a distinctive rest point along the trail.

These additions support ongoing efforts to improve public amenities, encourage outdoor activity, and enhance the overall attractiveness of the River Slaney riverside trail.

2

Atlassian Rovo Exfiltrates Data, Bypassing Controls

Hacker News · original → · 8/10 · AI security: Atlassian Rovo data exfiltration vulnerability, critical
Context Atlassian’s Rovo AI is a multi-purpose agent that operates across Atlassian’s product suite (Jira, Confluence, etc.). Vulnerabilities have been identified that enable data exfiltration…

Context Atlassian’s Rovo AI is a multi-purpose agent that operates across Atlassian’s product suite (Jira, Confluence, etc.). Vulnerabilities have been identified that enable data exfiltration across an Atlassian tenant (Jira tickets, Confluence docs, etc.) via indirect prompt injection. This attack executes without requiring any human-in-the-loop approval, and succeeds by exploiting Rovo's URL retrieval tool. This attack succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results. PromptArmor disclosed the vulnerabilities covered in this article to Atlassian on May 23rd. Atlassian assigned a case number and expressed thanks, but after multiple follow-ups by PromptArmor over more than two months, Atlassian has made no further communication, and Rovo remains vulnerable. As such, we are publishing to inform users of the risks. The Attack Chain The victim prepares a query asking Rovo to organize Jira tickets The victim uploads a file to Rovo that contains a hidden prompt injection For general use cases, this is quite common: a user finds a file online and uploads it to Rovo. This attack is not dependent on the injection source - other injection sources include, but are not limited to: external data in Atlassian (e.g., support tickets), web data (if search is enabled), third-party ‘connectors’, etc. The victim asks Rovo to organize their Jira tickets The injection manipulates Rovo to submit Jira tickets and Confluence documents to the attacker’s website Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. When Rovo calls the insecure tool to open the URL, the attacker's site logs the request, including the appended sensitive data. Note: This attack succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results. If the user returns to the chat later, they see the agent's suggested ticket updates, but no evidence of the attack. The attacker views the victim’s tickets and document contents in their website logs The prompt injection can exfiltrate any data the agent can access in Atlassian, including any data the agent can access via ‘connectors’. Extra: A second exfiltration mechanism Atlassian Rovo also renders Markdown images from AI outputs. Insecure Markdown image rendering is a well-known vector for data exfiltration via indirect prompt injection. To see what a full attack chain looks like for insecure Markdown image rendering, here are some examples from our other research: Responsible Disclosure PromptArmor disclosed the vulnerabilities covered in this article to Atlassian on May 23rd. Atlassian assigned a case number and expressed thanks, but after multiple follow-ups by PromptArmor over more than two months, Atlassian has made no further communication, and Rovo remains vulnerable as of the release of this article. Timeline | May 23, 2026 | PromptArmor discloses to Atlassian | | May 25, 2026 | Atlassian expresses thanks, assigns case number | | June 4, 2026 | PromptArmor follows up | | July 29, 2026 | PromptArmor follows up | | Aug 5, 2026 | Article is published |

3

Ship Safe, an open source security scanner for coding agents

Hacker News · original → · 8/10 · AI security: Ship Safe agent vulnerability scanner, work-relevant
Find risky code, AI-agent vulnerabilities, and supply-chain issues before they ship. Website · Docs · Security & Data Flow · Benchmark · Pricing · Blog · Contribute Ship Safe is an AI security…

Find risky code, AI-agent vulnerabilities, and supply-chain issues before they ship. Website · Docs · Security & Data Flow · Benchmark · Pricing · Blog · Contribute Ship Safe is an AI security scanner for modern software teams. It runs locally in your repo, finds issues across application code, AI agents, MCP configs, prompts, dependencies, CI/CD, secrets, and cloud-adjacent configuration, then helps you review and apply safe fixes. Start a scan with one command: npx ship-safe No signup. No API key required for scanning. Works offline for core checks. AI-backed red-team modes use your configured provider when available. Use --no-ai to guarantee a fully local scan. Provider-backed classification, deep analysis, and GPT-Red send bounded context directly to your selected provider after best-effort credential masking. See Security & Data Flow for exact boundaries and context limits. # Interactive REPL: scan, fix, and ask questions in one session npx ship-safe # Full audit: secrets + 29 agents + deps + remediation plan npx ship-safe audit . # AI agent red-team scenarios for agent-readable content npx ship-safe red-team . --gpt-red # Interactive fix agent: plan, diff, approve, verify npx ship-safe agent . npx ship-safe agent . --severity critical # critical findings only npx ship-safe agent . --branch --pr # fix on a branch + open a PR # Undo the last fix npx ship-safe undo # CI/CD mode — fails on any critical finding npx ship-safe ci . --sarif results.sarif npx ship-safe ci . --fail-on high # stricter: critical or high | Area | Examples | |---|---| | AI and LLM security | Prompt injection, agent hijacking, excessive agency, memory poisoning, RAG poisoning, unsafe tool calls | | MCP and agent configs | Over-broad tool permissions, poisoned registries, untrusted transports, dangerous allowlists | | Application security | SQL/NoSQL injection, XSS, SSRF, auth bypass, path traversal, insecure API routes | | Secrets and compliance | API keys, tokens, credentials, PII, leaked secrets in git history | | Supply chain | Typosquatting, dependency confusion, risky install scripts, unpinned AI actions | | CI/CD | Pipeline poisoning, unpinned GitHub Actions, secret logging, unsafe workflow triggers | - Scan locally - Ship Safe inspects your repo with targeted agents and skips checks that do not apply. - Review findings - Findings include severity, file location, evidence, and recommended remediation. - Fix with control - The agent proposes a plan and diff, asks before writing, verifies the result, and keeps changes reversible. - Gate in CI - Use ship-safe ci to fail risky builds and upload SARIF into GitHub code scanning. - Built for AI-native apps: catches risks in agents, MCP servers, prompts, RAG flows, managed-agent configs, and AI-powered CI. - Fast local feedback: run it before a PR, during review, or inside CI without sending code to a hosted scanner. - Fixes are reviewable: every suggested change is shown as a diff before it touches your files. - Works with your stack: JavaScript, TypeScript, Python, config files, infrastructure files, GitHub Actions, and more. - Open source core: MIT-licensed CLI with docs, examples, and a growing agent system. The open-source CLI is the fastest way to scan any repo locally. Upgrade when you need a hosted workflow around the same scanner: | Need | Use | |---|---| | Local scans, audits, and agent-assisted fixes | Free CLI | | Scan history, cloud dashboard, and PDF reports | Pro | | Shared workspace, PR Guardian, team reports, and collaboration | Team | Compare plans at shipsafe.sh/pricing. Ship Safe Cloud, the hosted dashboard for scan history, PR Guardian, billing, and team workflows, is developed in a private repository because it contains commercial product code and hosted infrastructure workflows. The public ship-safe repo remains focused on the MIT-licensed CLI, security agents, rules, fixtures, CI integrations, and documentation. See Ship Safe Cloud for the repo boundary. All agents run in parallel. Each skips irrelevant projects automatically. | Agent | Category | What It Detects | |---|---|---| | InjectionTester | Code Vulns | SQL/NoSQL injection, command injection, XSS, path traversal, XXE, ReDoS, prototype pollution | | AuthBypassAgent | Auth | JWT flaws (alg:none, weak secrets), CSRF, OAuth misconfig, BOLA/IDOR, TLS bypass | | SSRFProber | SSRF | User input in fetch/axios, cloud metadata endpoints, internal IPs | | SupplyChainAudit | Supply Chain | Typosquatting, wildcard versions, suspicious install scripts, dependency confusion | | ConfigAuditor | Config | Docker (root user, :latest), Terraform, Kubernetes, CORS, CSP, Firebase, Nginx | | SupabaseRLSAgent | Auth | service_role key in client code, tables without RLS, anon key inserts | | LLMRedTeam | AI/LLM | OWASP LLM Top 10: prompt injection, excessive agency, system prompt leakage | | MCPSecurityAgent | AI/LLM | MCP server misuse, tool poisoning, typosquatting, unvalidated inputs | | AgenticSecurityAgent | AI/LLM | OWASP Agentic AI Top 10: agent hijacking, privilege escalation, Kimi K3/OpenAI-compatible tool-call misuse | | RAGSecurityAgent | AI/LLM | Context injection, document poisoning, vector DB access control | | MemoryPoisoningAgent | AI/LLM | Instruction injection in agent memory files, hidden Unicode payloads (ASI-01, ASI-05) | | PIIComplianceAgent | Compliance | SSNs, credit cards, emails, phone numbers in source code | | VibeCodingAgent | Code Vulns | AI-generated code anti-patterns: no validation, empty catches, TODO-auth | | ExceptionHandlerAgent | Code Vulns | Empty catches, unhandled rejections, leaked stack traces (OWASP A10:2025) | | AgentConfigScanner | AI/LLM | Prompt injection in .cursorrules, CLAUDE.md, malicious Claude Code hooks | | MobileScanner | Mobile | OWASP Mobile Top 10 2024: insecure storage, WebView injection, debug mode | | GitHistoryScanner | Secrets | Leaked secrets in git commit history | | CICDScanner | CI/CD | Pipeline poisoning, unpinned actions, secret logging (OWASP CI/CD Top 10) | | APIFuzzer | API | Routes without auth, mass assignment, GraphQL introspection, debug endpoints | | ManagedAgentScanner | AI/LLM | Claude Managed Agent misconfigs: always_allow policies, unrestricted networking (ASI-03–ASI-07) | | HermesSecurityAgent | AI/LLM | Tool registry poisoning, function-call injection, skill permission drift (ASI-01–ASI-10) | | AgentAttestationAgent | Supply Chain | Unpinned agent versions, missing integrity hashes, unsigned manifests (ASI-10, SLSA L0) | | AgenticSupplyChainAgent | Supply Chain | Over-privileged AI CI actions, OAuth scope creep, unsigned AI webhook receivers (ASI-02, ASI-06) | | RobloxSecurityAgent | Supply Chain | Malicious Roblox/Luau Toolbox assets (runtime asset injection, rbxassetid:// loaders, HttpEnabled , payloads hidden in instance attributes) | | ModelScanAgent | Supply Chain | Code-execution payloads in ML model weights (pickle opcodes in .pt /.pkl /.ckpt ), torch.load without weights_only , scanner-evasion archives (CWE-502, CWE-506) | | TrustBoundaryAgent | Agentic | GhostApproval symlink attacks (config-named links into ~/.ssh /~/.aws /.env ), repo symlinks escaping the tree, and Friendly Fire run-on-review instructions in agent-read docs (CWE-59, CWE-61) | | SlopSquatAgent | Supply Chain | Hallucinated / phantom package imports (slopsquatting) — bare imports not declared, installed, or builtin, plus known AI-hallucinated names (CWE-1357) | | ClickFixAgent | Supply Chain | ClickFix / fake-CAPTCHA paste-and-run lures (fake error + Win+R/Ctrl+V/command-bar keystrokes, PowerShell cradles) and fake-installer npm lifecycle scripts (CWE-1357, CWE-506) | | InstallGuardAgent | Supply Chain | npm worm behaviors in lifecycle scripts (credential harvesting, env exfiltration, destructive rm -rf , obfuscated node -e ) and weaponized binding.gyp node-gyp actions (CWE-506, CWE-829) | Post-processors: ScoringEngine · VerifierAgent (secrets liveness) · DeepAnalyzer (LLM taint analysis) $ ship-safe ███████╗██╗ ██╗██╗██████╗ ███████╗ █████╗ ███████╗███████╗ ... v9.4.1 · DeepSeek · ~/my-project /scan to find issues · /agent to fix them · /help for more shipsafe › | Command | What it does | |---|---| /scan | Re-scan the project | /agent | Run the interactive fix loop | /findings | List findings from the last scan | /show <n> | Full detail on finding n | /plan <n> | Preview fix plan for finding n (no writes) | /undo [--all] | Revert the last fix (or all fixes) | /share | Publish scan report as a public URL (7 days) | /diff | Show git working-tree diff | /provider <name> | Switch LLM provider mid-session | /quit | Exit (also Ctrl-D or Ctrl-C ) | Anything not starting with / is sent to the LLM as a free-form question, with your latest scan results as context. # .github/workflows/security.yml name: Security Audit on: [push, pull_request] jobs: security: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Security gate run: npx ship-safe ci . --sarif results.sarif - uses: github/codeql-action/upload-sarif@v3 if: always() with: sarif_file: results.sarif Works with any provider — auto-detected from environment variables. Use --provider <name> to override. Anthropic · OpenAI · Google · DeepSeek · Kimi K3 / Moonshot · Groq · Together · Mistral · xAI · Perplexity · Ollama · LM Studio · any OpenAI-compatible endpoint Kimi defaults to kimi-k3 through MOONSHOT_API_KEY or KIMI_API_KEY . Use --provider kimi --model kimi-k3 for long-context GPT-Red and deep-analysis runs. For Kimi K3-specific long-context red teaming: npx ship-safe red-team . --gpt-red --provider kimi --model kimi-k3 --k3-long-context Ship Safe also checks Kimi K3 / OpenAI-compatible tool-call implementations for dynamic tool loading from prompt context, missing tool allowlists, forced tool calls on untrusted input, and replayed tool results without the original assistant tool-call message. No API key required for core scanning. AI classification and red-team --gpt-red use your configured provider when available, with deterministic offline fallback for GPT-Red checks. password = get_password() # ship-safe-ignore critical findings are always reported. An inline comment cannot hide one, and an attempt to suppress one is recorded in the scan. The comment is meant for a human ruling out a false positive, and anything that can write a line of your source — including an AI agent — can write the comment too, so the highest severities do not honor it. Every suppression is counted, so a scan that silenced findings never reads like one that had none. # .ship-safeignore tests/fixtures/ docs/ Recall is the easy half of a scanner. A tool that flags everything catches everything and is useless, so we measure the other half: what Ship Safe says about code that is almost certainly fine. | project | findings | critical | grade | |---|---|---|---| | express | 26 | 0 | C | | requests | 15 | 1 | C | | flask | 28 | 0 | D | | chalk | 4 | 0 | B | Down from 1031 findings across the same four projects before v9.6.3, verified against NodeGoat and DVWA so the drop is reduced noise rather than lost detection. The 1 remaining critical is a false positive and the benchmark says which and why. Corpus pinned by commit, reproducible with one command, limits documented: benchmarks/false-positives/ Run Ship Safe alongside them, not instead of them. CodeQL does interprocedural taint analysis Ship Safe does not attempt, Gitleaks is the specialist for secrets, and Trivy has a real CVE database behind it. Ship Safe covers a narrower question: what an AI coding agent just did to your repository, your CI, and your local tool configuration. MCP client config, agent memory poisoning, hallucinated-package imports and AIBOM are the areas where we found no equivalent public rules in the other four. Full coverage matrix, verified against their public registries, including where they beat us: docs/comparison.md [![Ship Safe](https://img.shields.io/badge/Ship_Safe-A+-22c55e)](https://shipsafe.sh) 10.0 is Hermes Agent coverage. Ship Safe already scans Hermes deployments, but against v0.13.0 while Hermes is on v0.20.0 — the ACP adapter, TUI gateway, serverless terminal backends, cron blueprints and plugin manifests all shipped in between with no coverage. See the roadmap for what is planned and what is deliberately not, and the 10.0 milestone for claimable work. Everything in it is open to contributors. Ship Safe is open source, and the best contributions are small, focused improvements that make AI-assisted development safer. Good first areas: - Add a focused security agent for an AI, MCP, CI, cloud, or supply-chain risk - Add a precise security rule to an existing agent - Add vulnerable fixtures and regression tests - Write examples for local scans, CI gates, red-team workflows, and MCP/agent setup Start here: - Good first issues - Contributor guide - Add an agent - Add a security rule - Handle MCP environment variables safely - Release process Ship Safe is MIT-licensed and free forever. Ship fast. Ship safe. — shipsafe.sh

4

Build an AI code review bot in 30 minutes with Vercel Eve

Lenny's Newsletter · original → · 8/10 · AI/work: Vercel Eve code review agent, AI and platforms relevant
AI writes most of my code now, and that created a new problem: a PR queue I couldn’t keep up with. In this episode, I walk through how I built Merge Mommy, a Vercel Eve agent that reads every PR…

AI writes most of my code now, and that created a new problem: a PR queue I couldn’t keep up with. In this episode, I walk through how I built Merge Mommy, a Vercel Eve agent that reads every PR after checks pass, scores it across six risk dimensions, auto-approves the low-risk ones, and pings me in Slack for anything that needs a human. I built the whole thing in one Codex session, it’s SOC 2 compatible, and it’s already cleared my backlog.

Listen or watch on YouTube, Spotify, or Apple Podcasts

What you’ll learn:

  1. Why AI-generated PRs create a review bottleneck and why the answer isn’t reviewing all of them

  2. How Intercom 5x’d PR approval speed and reduced revert rates by putting AI in the review loop

  3. Why Vercel Eve is the simplest framework I’ve found for deploying AI agents in Slack and GitHub

  4. How I built a full PR review agent in Codex with one prompt and a few steering turns

  5. The six components I use to score PR risk (blast radius, reversibility, data security, ops impact, verification gap, and change surface)

  6. How I used Chrome browser use to handle Slack bot and GitHub app configuration so I never had to click through setup screens manually

  7. Why auto-approved PRs can be SOC 2 compliant as long as the process is auditable, queryable, and in your risk policy

  8. How to set up Slack escalation so low-risk PRs become a two-click merge with no manual review


Brought to you by:

WorkOS—Make your app Enterprise Ready today

In this episode, we cover:

(00:00) The PR review backlog problem nobody’s talking about

(02:35) Why you don’t have to review every AI-generated PR

(05:14) How Intercom built AI-approved PRs (and proved they’re safer)

(06:10) How the Eve framework works (directory, skills, channels, connectors)

(09:16) The Codex prompt I used to build the entire bot

(11:36) What the agent actually does: read, score, approve, or escalate

(13:07) Setting up your Eve agent

(15:47) The six-component risk scoring model

(17:23) Merge Mommy in action: three live PR examples

(21:10) Recap and how to build your own version

Tools referenced:

• Vercel Eve: https://vercel.com/eve

• Vercel AI SDK: https://sdk.vercel.ai/

• Vercel Chat SDK: https://chat-sdk.dev/

• Codex (OpenAI): https://openai.com/codex

Other references:

• AI is approving our pull requests: Here’s how we made it safe: https://www.intercom.com/blog/ai-is-approving-our-pull-requests-heres-how-we-made-it-safe/

• Review is the bottleneck now: How we let AI approve pull requests (safely): https://rewind.com/blog/ai-approve-pull-requests-safely/

Where to find Claire Vo:

ChatPRD: https://www.chatprd.ai/

Website: https://clairevo.com/

LinkedIn: https://www.linkedin.com/in/clairevo/

X: https://x.com/clairevo

Production and marketing by https://penname.co/. For inquiries about sponsoring the podcast, email jordan@penname.co.

5

An AI model from Meta also hacked another company during testing

Simon Willison · original → · 8/10 · AI security: Meta model hacking during testing, critical
6th August 2026 - Link Blog An AI model from Meta also hacked another company during testing. Stop me if you've heard this one before: An AI model from the parent company of Facebook and Instagram…

6th August 2026 - Link Blog An AI model from Meta also hacked another company during testing. Stop me if you've heard this one before: An AI model from the parent company of Facebook and Instagram hacked into another company’s systems during cybersecurity testing, a spokesperson confirmed on Wednesday. Meta says the breach occurred because of an inadvertent error during testing of the model, similar to previously disclosed incidents with OpenAI and Anthropic. “A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation,” the Meta spokesperson said. Meta’s Muse Spark model “exploited a security vulnerability” in another company “in a manner similar to previously-reported instances with other companies.” The Information had the scoop, I'm linking to CNN's re-report of it since they don't have a paywall. So that's Anthropic, OpenAI, and Meta. Google Gemini really needs to catch up on accidentally cyberattacking other companies. Recent articles - One-shotting a Raccoon Heist game using Claude Fable 5 - 5th August 2026 - New release of LLM adds support for reasoning traces, OpenAI Responses, server-side tools, and smarter logging - 4th August 2026 - Stateless MCP has recaptured my interest (and inspired mcp-explorer and datasette-mcp) - 31st July 2026

6

Third-party cyber evaluations involving OpenAI models

Simon Willison · original → · 8/10 · AI security: OpenAI model cyberattacks, critical security issue
5th August 2026 - Link Blog Third-party cyber evaluations involving OpenAI models. And another one. I had to create a accidental-cyberattacks tag to keep track of them all! This post from OpenAI…

5th August 2026 - Link Blog Third-party cyber evaluations involving OpenAI models. And another one. I had to create a accidental-cyberattacks tag to keep track of them all! This post from OpenAI covers both the UK AI Safety Institute attack (see my previous post) and another attack enabled by Irregular: Irregular, one of our external cybersecurity testing partners, was running Capture-the-Flag-style evaluations intended to be isolated from the internet, but a testing-environment misconfiguration allowed models to access the public internet. [...] In one test, the name of the fictional target for the CTF challenge unintentionally coincided with a real domain. Because the testing environment was mistakenly connected to the internet, the model exploited a real website, mistaking it to be part of the simulated environment. Irregular also feature in Anthropic's write-up - they were hosting the misconfigured evaluation environment which gave Claude live internet access during some of those tests. Recent articles - One-shotting a Raccoon Heist game using Claude Fable 5 - 5th August 2026 - New release of LLM adds support for reasoning traces, OpenAI Responses, server-side tools, and smarter logging - 4th August 2026 - Stateless MCP has recaptured my interest (and inspired mcp-explorer and datasette-mcp) - 31st July 2026

7

Incident Report: unsanctioned agent behaviour during cyber testing

Simon Willison · original → · 8/10 · AI security: UK AI Safety Institute incident, critical
5th August 2026 - Link Blog Incident Report: unsanctioned agent behaviour during cyber testing. It happened again. This time it was the UK government's AI Security Institute who accidentally…

5th August 2026 - Link Blog Incident Report: unsanctioned agent behaviour during cyber testing. It happened again. This time it was the UK government's AI Security Institute who accidentally attacked other companies while running an evaluation with models with the safety filters turned off. From their technical paper (PDF): During a cyber evaluation, from 25 to 28 July 2026, AI agents engaged in sustained, unsanctioned activity directed at what were, in practice, real people and organisations. These attempts were unsuccessful and, to the best of our knowledge, no real-world harm resulted. [...] Across 122 evaluation attempts on two of AISI’s cyber challenges, AISI found 19 instances where AI agents took unsanctioned action on the live internet, including cases that targeted real people and organisations. [...] It is uncertain to what extent the model recognised it was taking actions against real people. In the most serious case, an AI agent (Mythos 5) decided to attempt to solve the cyber challenge using a supply-chain attack. As a result, the AI agent created a GitHub account and then tried to convince an open-source repository maintainer to accept a malicious GitHub pull request (PR), including by creating a second account masquerading as another human user endorsing the PR. [...] Furthermore, in its attempt to solve the challenge, the agent decided to employ the technique of “spear-phishing” by sending targeted emails containing malicious content and attempting to manipulate recipients into accepting the code changes, and planned a prompt injection to compromise other coding agents. The thing I found most surprising is that AISI were running these agents without any form of network sandboxing at all: AISI provided the AI agents with internet access during these evaluations, which enabled their actions on the open internet in this setting. Internet access was a deliberate part of AISI’s evaluation configuration in this setting, and not due to sandbox escape. This, combined with the fact that "AISI deliberately disables developer-implemented cyber-classifiers", makes the fact that the agents started attacking real-world targets entirely unsurprising to me. Most of the reported incidents were claude Mythos 5, but "GPT-5.6 Sol without cyber classifiers" scored a few as well. Here's "Sample 1" from the paper, in which the agent tries to execute a supply-chain attack by submitting a PR with a hidden prompt injection attack, then social engineering with a second agent pretending to have reviewed the code! It's a fun paper. I recommend reading the whole thing. Recent articles - One-shotting a Raccoon Heist game using Claude Fable 5 - 5th August 2026 - New release of LLM adds support for reasoning traces, OpenAI Responses, server-side tools, and smarter logging - 4th August 2026 - Stateless MCP has recaptured my interest (and inspired mcp-explorer and datasette-mcp) - 31st July 2026

8

Changes at Google DeepMind: Demis Hassabis from CEO to Chair, Jeff Dean departs

Hacker News · original → · 7/10 · AI: Google DeepMind leadership changes, critical AI developments
The next chapter of our AI momentum Editor’s note: Today, Google and Alphabet CEO Sundar Pichai shared some changes with Google DeepMind teams, including new roles for Demis Hassabis and Koray…

The next chapter of our AI momentum Editor’s note: Today, Google and Alphabet CEO Sundar Pichai shared some changes with Google DeepMind teams, including new roles for Demis Hassabis and Koray Kavukcuoglu. Below are the messages Sundar and Demis sent to employees. Message from Sundar Pichai We’ve made extraordinary progress to deliver on our full AI stack. We’ve got amazing talent, world-class compute, and products that bring AI to more people than any other company. And you saw the incredible momentum at earnings across all our businesses, including Search, YouTube, and Cloud. Our Gemini models are in high demand among developers and businesses, and the Gemini app reached 950M+ monthly users. Meanwhile, our AI research continues to drive field-defining breakthroughs (like last week’s Gemini Robotics advances). We have to accelerate all this work and stay focused on the AI frontier. At the same time, there’s never been a more important moment to shape the future of AGI and science. Today Demis, Koray and I are sharing a few changes to our Google DeepMind teams that will enable us to do both. AGI and science: Demis has described us as standing in the foothills of the singularity, and has been spending a lot of his time engaging externally. He and I have been long discussing a role that allows him to put his full attention on actively shaping the future of AGI. It’s work that is vitally important to Alphabet and humanity, and I can’t imagine a better person than Demis to do it. So, moving forward, Demis will become the Chair of GDM and Chief Scientist of Alphabet, while continuing to lead Isomorphic Labs. He’ll remain closely connected to Koray, Josh, and our GDM teams, advising across models and research. I’m so excited for Demis — this is truly his life’s work and purpose. You can read Demis’s note to GDM below. Google DeepMind: We are building strong momentum: Flash is in high demand, our Cyber model is live, and Gemma models have surpassed 900M+ downloads. We are committed to being at the frontier, and are super focused on the areas where we need to improve. I’m really excited for our upcoming model releases and the progress we’re seeing. We have to continue to move fast and with clear purpose here. Koray, the current Chief Technology Officer of GDM and our Chief AI Architect, will step up as SVP of Google DeepMind, reporting to me. He will oversee Gemini model development, Frontier AI research, and the Gemini app and developer teams. Koray has been at DeepMind since its early days, and over his 13 years there, he has started our deep learning team and led the way on breakthroughs like WaveNet and DQN. I look forward to seeing him lead GDM into this next chapter. Lastly, after an incredible 27-year run, Jeff Dean is at a moment where he wants to try something new, and we’re excited to support him in that. Jeff and Google Senior Fellow Sanjay Ghemawat are launching an independent public benefit corporation to accelerate discoveries in ML, science, and engineering. Jeff and Sanjay helped to drive some of the most significant technology transitions, from our early search infrastructure to the neural networks that helped create the modern AI era. On a personal note, it’s been a privilege to work alongside Jeff and Sanjay, and I wish them all the best! We’ll continue to work with them as a founding investor and Cloud partner, and collaborate on a research framework for ML systems and related infrastructure advances. We are at a dynamic moment with so much opportunity ahead. With today's changes we're going to keep driving our momentum. Onwards! -Sundar Message from Demis Hassabis Hi Team We have arrived at a pivotal moment in human history. I’ve been working towards AGI my whole life and now, like many of you, I feel it is close at hand. It’s critical that we collectively get the next steps right to ensure this all goes well for humanity and we usher in an incredible new age of discovery and wonder. With this backdrop, I’ve decided that now is the right time for me to hand over my day-to-day operational responsibilities at GDM, so that I have the time and space to focus on the big picture and help influence what is to come to the best of my ability. I will be taking on a new strategic role as Chair of GDM and Chief Scientist of Alphabet, and I’m excited to announce that Koray will be stepping up to lead GDM as SVP of Google DeepMind, in addition to his role as Chief AI Architect of Google. Koray and I have been working together for over 13 years, since the early days of DeepMind. He is one of the world's foremost AI experts and has been championing GDM's mission from day one. I have total confidence in Koray, Josh, and the rest of the GDM exec team as they continue to spearhead the latest AI developments across Google. The Gemini models are in good hands with Koray and the leads, as they have been for a while, and I'm excited about the great progress we’re making with our new models including Gemini 4. In my new role, I will continue to work closely with Sundar on strategic and global AGI matters, and to advise Koray, Josh, and the GDM leads, from our awesome new London Platform 37 offices. As part of this transition, I’ll also be leaning into my role at Isomorphic, where we are making extremely rapid and promising progress, to accelerate our mission there even faster. As you've heard me say many times, I’ve always believed the No.1 application of AI should be to improve human health. It’s time for AI to prove its unequivocal value to the world, and what better way to demonstrate that than to help finally cure diseases like cancer. We’ve built a unique culture at GDM that has served us very well. I want to thank each and every one of you for your brilliance, dedication, and effort that make GDM the huge success it is today. We should all be extremely proud of the amazing things we’ve achieved so far. We’ve become the AI engine room of Google, with Gemini delivering helpful experiences everywhere including AI Mode and AI Overviews, the Gemini App rocketing to over 950M monthly users, and our fundamental and scientific research continues to lead the world. I’m very excited for our next chapter and the best is yet to come! As a business we are in an incredibly strong position. We are the only company that has the full stack and we’re world-class at every layer from infrastructure to cloud to frontier models to AI-first applications. We have all the ingredients to lead from here, and I firmly believe we will. Best Demis

Items scoring 7/10 or above from 11 sources, scored by claude-haiku-4-5-20251001 on relevance to my interests. At most 3 per source.

Scoring categories & sources
  1. Local Wexford or South East Ireland news
  2. Irish or EU-wide affairs affecting citizens broadly: elections, new laws or policy being debated, cost of living, education — especially impacts on mid-life adults or teenagers. Never courts/crime stories.
  3. Irish news on a topic relevant to my interests
  4. Work and tech topics: networking, AI, Kubernetes, platforms, SaaS
  5. AI news including critical or anti-AI perspectives
  6. Gaming: PC gaming, indie gaming, retro gaming
  7. General interests: gardening, woodwork, cycling, fitness, travel
  8. Comics

Sources: Breaking News Ireland, Wexford Local, Hacker News, r/gaming, r/pcgaming, r/antiAI, r/indiegaming, Lenny's Newsletter, One Useful Thing, Newcomer, Simon Willison

Comics

Antiques Roadshow

XKCD · view →
The family lore was that we

The family lore was that we