Tech News
← Home  ·  All topics

Open Source Security

2 GoKawiil briefs on this topic

Nvidia releases OpenShell AI-agent security sandbox for general use

Nvidia has moved its OpenShell agentic AI sandbox, first unveiled at GTC in March, into general availability for all users. The tool isolates AI agents' activity at the operating system kernel level while they perform tasks, and Nvidia says it has security collaborations with companies including Anthropic, Cisco, CoreWeave, Dell, Microsoft, Palantir, Salesforce and SAP.

AI agents found cohttp path-traversal exploit within minutes of PR being opened

OCaml maintainer Anil Madhavapeddy disclosed a path traversal vulnerability in cohttp 6.3.0 and found that attackers began probing his live server with the exact exploit pattern just minutes after he opened a public GitHub pull request to fix it. He also demonstrated that AI coding agents like DeepSeek V4 Pro could independently rediscover the bug and build a working exploit in under a minute, using only a vague description of the issue.