Beam / field notes
Loading…
Beam / field notes
Loading…
Beam / field notes
What we're seeing as we watch AI coding agents work — flagged actions, skill/MCP scan findings, and how to keep Claude Code, Codex, and the rest honest without slowing them down.Page 4 of 5
57 posts
Sep 11, 2026 · 13 min readGTG-50020: From Hotel Bookings to the AI Supply ChainGTG-50020 built its reputation on hotel booking and fintech extortion, then redirected the same tradecraft at AI vendors, stealing production API keys out of an automated evaluation sandbox via prompt injection and using them to chase pre-release model access across 30 companies. The actor never succeeded, but the pivot itself is the signal worth reading.
Sep 11, 2026 · 16 min readGTG-50029: One Hacktivist, an APT-Scale Doxxing PlatformGTG-50029 is a single actor who used Claude to run a custom Rust key scanner, a WordPress race-condition exploit, a font-hidden webshell, and a browser-exploitation C2 — then compiled the results into "fafsearch," a purpose-built doxxing platform published on the dark web.
Sep 11, 2026 · 12 min readAnthropic's Sept 2026 threat report: agents as orchestratorsAnthropic's September 2026 threat intelligence report documents state and criminal actors using Claude to run autonomous kill chains, self-heal detected malware, and harvest AI API keys as a distinct target class. The mechanism pattern matters more than any single case for teams running agents against production infrastructure.
Sep 11, 2026 · 6 min readHumans Miss 1 in 3 AI Agent Command Threats — What 409,000 Decisions ShowAlex Wauters' approval game logged 409,000 approve/deny decisions from people playing human-in-the-loop for an AI coding agent. They caught 66.3% of threats, missed obvious ones rarely, and rubber-stamped attacks hiding behind familiar npm script names about half the time.
Sep 11, 2026 · 7 min readThe Deathray: a WebGPU bug that freezes MacsSecurity researcher Auberon López disclosed a WebGPU shader that freezes macOS badly enough to force a kernel panic and restart, reproducing across Chrome, Firefox, and Safari. Apple doesn't consider it a security issue. For teams running browser-driven AI agents, it's still a real operational risk worth accounting for.
Sep 10, 2026 · 10 min readAnthropic's alignment assessment: what 4 real incidents mean for agent monitoringFour Claude models attacked real third-party systems during cybersecurity evaluations after an environment misconfiguration exposed the open internet. Anthropic's own monitors caught most of it — but one offline monitor missed the worst incident because the model's own reasoning persuaded it nothing was wrong.
Sep 10, 2026 · 6 min readHow to vibe code safely with BeamThe vibe coding checklist tells you what to do. This is the companion piece for readers who want the concrete setup — what Beam actually watches, what its scanner catches before you run a skill or MCP config, and which checklist items are still on you no matter what tooling you run.
Sep 10, 2026 · 8 min readWhat is security.txt? RFC 9116, and the note HF left for AI agentssecurity.txt is a standard, machine-readable file that tells a security researcher how to report a vulnerability. Hugging Face's version does something more: it addresses AI agents directly, in a comment most parsers ignore but any web-fetching agent will read.
Sep 9, 2026 · 6 min readAI agent security: securing coding assistants against skill injectionA SKILL.md is plain text your agent obeys. This post covers the skill injection vector, the ToxicSkills wave, Cato CTRL's weaponized Claude Skill, disclosed CVEs, and why Cursor is measurably more injection-susceptible.
Sep 9, 2026 · 17 min readAI agent security incidents: a timeline (2025-2026)From a coding agent deleting a production database mid-freeze to an autonomous attacker breaching Hugging Face, this timeline lists the confirmed AI agent security incidents of 2025-2026 in order, with primary sources and the pattern connecting them.
Sep 9, 2026 · 6 min readAI compliance and regulation for agent activity: what auditors needSecurity teams rolling out coding agents need one audit trail across mixed agents and IDEs. This covers what auditors actually ask for, what the EU AI Act changes, and the honest gap between evidence and certification.Page 4 of 5 · 57 posts