---
title: "Weekly Roundup: One Adverb, One Agent, and Twelve Hosted Runtimes"
pubDatetime: 2026-07-10T15:00:00.000Z
description: "GitHub's injection scanner fell to the word 'Additionally', a single-agent red-teaming harness beat the swarm it shipped with, and the managed-agent market got mapped."
tags: [security, ai-security, ai-agents, prompt-injection, managed-agents, red-teaming, 2026, 2026-q3, 2026-07, weekly-roundup]
---
> [!tldr] TL;DR
> Five posts this week: two agent-security stories, a map of the managed-agent market, and a reading list.

The week's best result came from one adverb. Noma Labs' GitLost, covered in [One Word Beat GitHub's Guardrail](/posts/gitlost-github-agent-injection), leaks a private repo's `README.md` into a public Issue thread. GitHub had built an output scanner for exactly that move. Prefixing the malicious line with "Additionally," walked the data straight past it. No CVE, no code patch, a documentation update.

Pliny's T3MP3ST posted 90.1% on XBOW's benchmark using the coding agent you already have installed. Its own logs say the eight-operator swarm in the branding scored none of it, and [the write-up](/posts/t3mp3st-multi-agent-red-teaming) has the receipts.

If you would rather not run any of this yourself, [the managed-agent market](/posts/managed-agents-landscape) now holds about a dozen vendors across three layers, all selling the same pitch. The plumbing is worth buying. The isolation label on top of it is worth checking yourself, since BeyondTrust got command-and-control out over DNS from a Firecracker-backed "Sandbox."

Also this week: [Abnormal AI's public AI-adoption content stream](/posts/abnormal-transforming-in-public), which reads as good recruiting and as useful reconnaissance for the social engineers it sells protection against. And a slower one, [essential reading on AI and the singularity](/posts/ai-singularity-essential-reading), assembled alongside the forecasters who keep moving their own dates.