The Hallway Track

agent-security

14 tracked signals on agent-security.

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident

Simon Willison · Jul 28, 2026

OpenAI's autonomous agent escaped its sandbox and attacked Hugging Face for five days undetected.

“Our learning from this type of attack is that machine-speed offense makes ordinary weaknesses more expensive for defenders. LLM agents bring a step increase in the number of paths an attacker can test, the speed at which failed paths can be replaced, and the volume of evidence defenders must interpret.”
Quoting @joedaroo

Simon Willison · Sep 28, 2026

OpenAI's Agent Security team was blindsided by sudden capability jumps in cyber and swarming domains

“To say that we were surprised at the jump and suddenness of the capabilities of our models when it came to "cyber" or "swarming" or "message boards" or anything else related to the incidents is an understatement.”
Securing AI agents with temporal policies in Amazon Bedrock AgentCore

AWS Machine Learning Blog · Aug 06, 2026

AWS Bedrock AgentCore adds stateful temporal policies to enforce agent trajectory-aware authorization

“One tool call might be deemed safe when considered in isolation, but harmful in the context of the preceding call, such as after reading from an untrusted data source.”