Hermes
Saturday, 5 September 2026  ·  67 articles scored  ·  5 top scorers  ·  last 24h
1
🔐 security Schneier on Security
74%

Using a VM to Contain an AI Agent

It won’t work: My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in g…

Novelty
80%
Depth
70%
Practical
65%
Surprise
75%
Relevance
85%
https://www.schneier.com/blog/archives/2026/09/using-a-vm-to-contain-an-ai-agent.html
2
🔐 security Schneier on Security
74%

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

We cannot forget that AI coding agents are not yet trustworthy: Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech compa…

Novelty
80%
Depth
65%
Practical
70%
Surprise
75%
Relevance
85%
https://www.schneier.com/blog/archives/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks.html
3
🔐 security Microsoft Security Blog
73%

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI pr…

Novelty
80%
Depth
60%
Practical
70%
Surprise
80%
Relevance
85%
https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
4
🤖 ai The Decoder
73%

GPT-6 Astra is the first model making OpenAI willing to declare the "AGI era"

OpenAI has released GPT-6 Astra, its most capable model yet. President Greg Brockman says it marks the start of the "AGI era." Astra tops benchmarks in math, coding, and cybersecurity and is the firs…

Novelty
90%
Depth
60%
Practical
50%
Surprise
85%
Relevance
95%
https://the-decoder.com/gpt-6-astra-is-the-first-model-making-openai-willing-to-declare-the-agi-era/
5
🤖 ai The Decoder
71%

OpenAI agents hijacked a 25-year-old German wiki to cheat on their tasks and share sandbox exploits

According to an analysis by collusion.wiki, autonomous AI agents that identified themselves as OpenAI systems left roughly 18,000 posts in a 25-year-old German wiki between May and July 2026. The age…

Novelty
85%
Depth
65%
Practical
50%
Surprise
90%
Relevance
80%
https://the-decoder.com/openai-agents-hijacked-a-25-year-old-german-wiki-to-cheat-on-their-tasks-and-share-sandbox-exploits/
6
📦 m365 Petri IT Knowledgebase
69%

Attackers are Using Microsoft Teams Calls to Gain Access to Corporate Networks

A new voice phishing campaign called Spring Ring is exploiting Microsoft Teams to trick employees into granting attackers access to corporate systems. Researchers observed the campaign targeting more…

https://petri.com/microsoft-teams-voice-phishing-corporate-networks/
7
🤖 ai The Decoder
69%

OpenAI's GPT-6 Astra hallucinates less but remains vulnerable to hidden prompt injections

OpenAI's GPT-6 Astra hallucinates less than its predecessor and blocks 99.99 percent of direct prompt injections. But when attacks are hidden inside documents the AI reads, the model still gets crack…

https://the-decoder.com/openais-gpt-6-astra-hallucinates-less-but-remains-vulnerable-to-hidden-prompt-injections/
8
🔐 security SecurityWeek
65%

Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents

New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review. The post Capsule Security Launches ‘AI Circuit Brea…

https://www.securityweek.com/capsule-security-launches-ai-circuit-breaker-to-stop-rogue-agents/
9
🔐 security Microsoft Security Blog
64%

How to secure edge AI in customer-owned environments

As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post …

https://www.microsoft.com/en-us/security/blog/2026/09/04/secure-edge-ai-customer-owned-environments/
10
🤖 ai The Decoder
64%

Nvidia buys the front door to open AI as closed labs increasingly design their own silicon

Nvidia plans to acquire Hugging Face for about $12.9 billion, securing the central platform for open AI models. More than 18 million developers and 200,000 companies use the hub. CEO Jensen Huang pro…

https://the-decoder.com/nvidia-buys-the-front-door-to-open-ai-as-closed-labs-increasingly-design-their-own-silicon/
11
⚡ tech Stratechery
63%

An Interview with OpenAI President Greg Brockman About Astra and Alignment

An interview with OpenAI President and Co-Founder Greg Brockman about the history of OpenAI, Astra and alignment, and the weight of building the future.

https://stratechery.com/2026/an-interview-with-openai-president-greg-brockman-about-astra-and-alignment/
12
📦 m365 Petri IT Knowledgebase
63%

Microsoft Sentinel Cuts Connector Sprawl for Organizations Managing Multiple Accounts

Organizations that manage multiple tenants, subsidiaries, regional environments, or recently acquired businesses often struggle to consolidate security data into Microsoft Sentinel. Until now, connec…

https://petri.com/microsoft-sentinel-multi-account-data-collection/
13
🤖 ai The Decoder
62%

Benchmarks disagree on GPT-6 Astra, but its human-beating efficiency on ARC-AGI-3 pulls Chollet’s AGI forecast forward

OpenAI's GPT-6 Astra is drawing contradictory benchmark verdicts. Epoch AI puts it out in front with 169 points, while Artificial Analysis rates it no better than its predecessor and behind Claude Fa…

https://the-decoder.com/benchmarks-disagree-on-gpt-6-astra-but-its-human-beating-efficiency-on-arc-agi-3-pulls-chollets-agi-forecast-forward/
14
🔐 security SecurityWeek
60%

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerabi…

https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/
15
🔐 security Schneier on Security
60%

Security Vulnerability in a Voting System

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use…

https://www.schneier.com/blog/archives/2026/09/security-vulnerability-in-a-voting-system.html