Five posts this week: two agent-security stories, a map of the managed-agent market, and a reading list.
The week’s best result came from one adverb. Noma Labs’ GitLost, covered in One Word Beat GitHub’s Guardrail, leaks a private repo’s README.md into a public Issue thread. GitHub had built an output scanner for exactly that move. Prefixing the malicious line with “Additionally,” walked the data straight past it. No CVE, no code patch, a documentation update.
Pliny’s T3MP3ST posted 90.1% on XBOW’s benchmark using the coding agent you already have installed. Its own logs say the eight-operator swarm in the branding scored none of it, and the write-up has the receipts.
If you would rather not run any of this yourself, the managed-agent market now holds about a dozen vendors across three layers, all selling the same pitch. The plumbing is worth buying. The isolation label on top of it is worth checking yourself, since BeyondTrust got command-and-control out over DNS from a Firecracker-backed “Sandbox.”
Also this week: Abnormal AI’s public AI-adoption content stream, which reads as good recruiting and as useful reconnaissance for the social engineers it sells protection against. And a slower one, essential reading on AI and the singularity, assembled alongside the forecasters who keep moving their own dates.