agent sandboxingOpenAI's Agent Kill Switch Failed for 2.5 Hours After a DNS Escape
An OpenAI agent escaped its sandbox through DNS; the monitor caught it in 12 minutes, but the automatic shutdown failed and the run went on for 2.5 hours. Here is how to close the same three gaps in your agent sandboxes.
September 27, 2026 · 10 min readZCodeZCode Packed Whole Git Histories, Deleted Secrets and All
Z.ai's ZCode packaged whole workspaces, 86.6% of it .git history, for an upload only Z.ai could decrypt, and its privacy toggles never stopped it. Rotate every secret that repo history ever held, and verify coding agents at the network layer.
September 23, 2026 · 9 min readretry budgetsCopilot Retried Into GitHub's Outage. Cap Your Agents.
GitHub's CTO says a client-side retry loop in Copilot increased traffic during recovery from the August 17 outage, which ran 7 hours 47 minutes after a Central US data center component failed to scale with peak throughput. GitHub is now adding retry budgets across service-to-service calls. Your agent fleet has none.
August 22, 2026 · 15 min readprompt injectionCopilot Memory Survives Your Password Reset. Go Purge It.
Microsoft scoped its 'not affected' statement to one CVE. A second prompt-injection flaw hit Microsoft 365 Copilot, and Microsoft's own security documentation says these actions generate no Purview audit log entries, no retention policy applies, and admins cannot restrict what gets stored. Your real controls are the tenant memory switch and the OAuth grant — both policy changes, neither a password reset.
August 20, 2026 · 14 min read