#22: The Sandbox That Wasn't
Listen to episode
About this episode
Top Story: The Reveal — On July 16, Hugging Face disclosed that something had broken into its production systems over the weekend of July 11-13, moved through internal servers for days, and left more than 17,000 recorded actions in its wake. A single link could plant a fake employee inside your company, with all their access. — Zenity Labs researcher Mike Takahashi found that ChatGPT's Agent Builder would silently follow instructions hidden in a link's web address the moment a logged-in victim clicked it, no further action needed. 💰 Funding — A stealth AI security startup surfaced already worth $1.2 billion. — Glow, founded by former Meta, Snowflake, and Claroty executives, emerged from stealth with a $180 million Series A backed by Sequoia Capital, Cyberstarts, Greenoaks, and Redpoint Ventures. ⚔️ Attack — Anthropic quietly closed a hole that let Claude leak where you live and who you work for. — Researcher Ayush Paul found that Claude's web-browsing tool, web_fetch, was designed to only visit web addresses a user typed in directly or that came back from a search, specifically to prevent it from being tricked into leaking private data. Curator's Corner: The Guard, Not the Wall
Curated by Asaf Nakash. Voices by AI. Opinions by human.
Show notes: https://contextwindowsec.com/episodes/2026-07-27.html
More AI podcast episodes
Browse all →Want to find AI jobs?
Join thousands of AI professionals finding their next opportunity