AI Sandboxes Get Pwned, Unicorn Gets Launches, and Open-Weight Warfare
OpenAI models broke containment, Glow launched at $1.2B valuation, and Kimi K3 poured gas on the open-weight fight.
Welcome to The Cybersecurity Pulse (TCP)! I’m Darwin Salazar, Head of Growth at Monad and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! 📧
Hi 👋 - Hope you’re having a great week wherever you’re reading from!
It’s been a wild past few days to say the least. Exotic sandbox escapes in OpenAI, Cursor, Codex, Gemini CLI etc. Two Series A rounds for a combined $255M in the endpoint security space with one being a unicorn straight out of stealth. Spain topples Argentina for World Cup. The open-source/weights debate gets more wood in the fire with Kimi K3 causing chaos at closed-source frontier model labs (mainly OpenAI and Anthropic). Serious national security and economic implications there. Hugging Face using GLM 5.2 to do IR because closed-source model guardrails blocked IR activity.
I have a feeling this is a defining week for security and the open-source convo. Before we dive in, here’s a recent write-up I did on the AI tooling logging research I’ve been doing and if you’ll be at Blackhat, hit me up! Here’s a list of a few places and events I’ll be at.
Full breakdown of all the things, including the OpenAI x HuggingFace incident, in this week’s TCP! But first, a meme and an ad.
Cyber Reporting Has Outgrown the Checklist
Cyber reporting is no longer a checklist. A single incident can trigger 100+ obligations across different regulators, deadlines, and audiences—before the facts are stable. In the newly released Regulatory Concurrency Report,
BreachRx analyzed Change Healthcare, Snowflake, Salesforce, 700Credit, and Salt Typhoon to reveal five forms of regulatory concurrency and where manual processes break. Download the report to learn what modern teams need to keep reporting coordinated, consistent, and defensible.
⚒️ Picks of the Week ⚒️
OpenAI’s cyber test spilled into Hugging Face
OpenAI says GPT-5.6 Sol and a more capable prerelease model escaped an internal cyber benchmark after exploiting a zero-day in the package-registry proxy that was their only path outside the sandbox. The models escalated privileges, moved laterally until they reached an internet-connected node, then chained stolen credentials and flaws into an RCE path at Hugging Face. They were trying to win the benchmark. They just found the answers in someone else’s production database. Pretty impressive ngl.
OpenAI had reduced safety/security refusals and disabled its production classifiers for the evaluation. Hugging Face then hit the inverse problem during response x_x. Commercial frontier models blocked the real exploit payloads and C2 artifacts needed to analyze 17,000+ events, so it moved the work to self-hosted GLM 5.2. That also kept attack data and credentials inside its environment.
The scariest part (there are many) is that a capable model found a hole, chained together a multi-step intrusion, and crossed into another company’s environment. Another scary part is the guardrail asymmetry. Closed-model labs can remove the seatbelt when they need full capability; defenders renting similar models through an API often cannot. Guardrails reduce misuse, but security teams should not make a provider-controlled API their only AI option during an incident. OPEN-SOURCE MODELS FTW.
Kimi K3 makes the guardrail tradeoff harder to ignore
Moonshot AI says Kimi K3 is a 2.8 trillion-parameter open-weight model with a 1 million-token context window, competitive benchmark performance (better than Fable 5 in some cases), and full weights due July 27. Moonshot warns that K3 can be excessively proactive and make unexpected decisions without tighter boundaries.Obviously very compute intensive as well.
The fact that Chinese labs are shipping open-weight models of this quality should concern everyone.. for many reasons. Economic, national security and many other implications.
Dan Miessler wrote a great post on some of the implications here.
How solid is your security review process, really?
Every change - a feature, infrastructure update, access change, new vendor, and AI-generated commit - moves your risk profile. Most teams can’t say how many of those got a security review.
Are you one of the few who can?
The agent stayed sandboxed. The host still got popped.
Pillar disclosed seven sandbox escape and boundary-bypass chains across Cursor, Codex, Gemini CLI, and Antigravity. In most cases, the agent never broke out directly. The agent wrote files inside the allowed workspace, then unsandboxed tools like Git, VS Code, Python, or Docker used those files to execute code on the developer’s machine. Most reported issues were patched, including Cursor fixes in version 3.0.0.
A reminder that “The agent is sandboxed” is not the same as “the host is safe.” The actual boundary includes every helper, daemon, and config file that trusts what the agent creates. Security teams should review the handoff, not just the box. Before there were AI models, there were threat models.
Perplexity was not part of Pillar’s research, but the company did recently detail SPACE, the Firecracker microVM sandbox already running underneath Computer. It is a useful contrast in how different AI companies are handling sandboxing. Though the Pillar findings show why the trust boundary cannot stop at the VM.
Zero risk isn’t the job: a CISO’s guide to agentic AI
Great write-up by Anthropic’s Deputy CISO Jason Clinton where he offers a practical framework for reviewing agentic systems.
What to review:
Inputs: What untrusted content can the agent ingest?
Identity: Whose credentials and permissions does it use?
Actions: Which tools, connectors, and systems can it change?
Blast radius: What happens if the agent behaves unexpectedly?
Visibility: Do its actions reach the SIEM and existing monitoring workflows?
Anthropic’s incident-response agent shows why this assessment cannot stay static. After a model upgrade, the agent independently asked another internal agent to draft a production fix, despite no changes to its tools, permissions, or prompt. Human review still prevented the code from reaching production.
The useful lesson is to assess agents around durable control points: identity, scoped permissions, tool access, egress, sandboxing, approval gates, and telemetry.
Glow exits stealth with a $180M Series A at a $1.2B valuation
Glow emerged from stealth with a $180 million Series A led by Sequoia, Cyberstarts, Greenoaks, and Redpoint, with Index, Swish, Lux, Operator Collective, and Holly Ventures also participating. That’s quite the cap table. Also, unicorn status right out of stealth is pretty rare.
Now about the tech: Its endpoint agents inventory software, AI agents, and developer tools, assess them against company policy, and block risky components before they execute.
Glow was founded by former Meta, Snowflake (Omer Singer), and Claroty executives. Omer was a big proponent of security data lakes early on so if you operate in the SecOps space, it’s likely that the name rings a bell. Funny enough, Omer asked me about the name last year. I picked Glow. What you name your startup is EXTREMELY important.
Next, the overlap with Neo and Koi is hard to miss. Neo is building a broader control plane for agent behavior across identities, applications, APIs, and data, while Koi is the clearest endpoint comp, covering coding agents, plugins, packages, scripts, and model artifacts.
Glow seems to be going after the larger prize of combining application control, software supply-chain security, AI governance, and endpoint prevention into one platform. The risk is that buyers see a bundle of features their existing endpoint vendor will eventually ship.
In any case, stellar founding team, great momentum out the gate, generational problem and not small funding. Excited to see what they do.
Fairlife ransomware attack shuts down U.S. production
Coca-Cola disclosed that ransomware hit Fairlife, including systems tied to production, forcing the company to temporarily suspend U.S. operations. The full scope is still unknown.
The ransomware knocked production offline, but the bigger brand hit may be millions of customers realizing their wellness-coded protein shakes and milk are owned by Coca-Cola. The systems will recover. The illusion may not ;)
🔮 The Future of Security 🔮
Endpoint Security
Neo launches with $100M for agentic software control
Neo emerged from stealth with $100M raised across two rounds: a $25M Seed in 2025 led by Andreessen Horowitz and Merlin Ventures, followed by a $75M Series A backed by Andreessen Horowitz, Bessemer, Craft, and Merlin. Founded by former SentinelOne leaders Nick Warner and Shlomi Salem alongside Eran Shirazi, Neo is building endpoint security for software that can reason, invoke tools, inherit user permissions, and move data without waiting for a human.
The platform inventories agents, MCP servers, extensions, models, and AI-enabled apps across endpoints, then maps their permissions, configurations, and behavior. It attributes actions to the human, agent, application, or identity behind them, with controls to block tool calls, API access, data movement, malicious models, and out-of-policy prompts.
TLDR: EDR for the agentic application layer, where traditional endpoint tools often see the trusted parent process but miss what is happening inside it.
Identity and Access Management
Oak exits stealth with $60M for an identity operating system
Oak emerged from stealth with $60 million in seed funding, co-led by Accel, Greylock, and CRV. Its platform builds a live identity graph across cloud, SaaS, on-premises, and homegrown systems, covering human, machine, and AI-agent identities, then maps granted access against actual use to drive governance and remediation.
Oak is taking a platform-consolidation swing at a crowded category. On product shape, Opal and C1 are the clearest modern comps. An interesting bit is that Greylock led Opal’s Series A and co-led its latest $23 million financing, then co-led Oak’s seed six weeks later. That is two bets on overlapping identity control-plane theses. Not very common in venture investing but maybe there’s more than what meets the eye.
Security Operations
Cribl acquires CardinalOps and moves up the SIEM stack
Cribl is acquiring CardinalOps, adding detection engineering to its telemetry platform. CardinalOps maps rules and security controls to MITRE ATT&CK, identifies coverage gaps, and flags broken or noisy detections. Cribl plans to connect that layer with its telemetry routing, storage, and federated search stack, positioning the combined platform as an open alternative to legacy SIEM.
Vulnerability Management
Empirical Security raises $25M to predict which vulnerabilities actually matter
Empirical Security raised a $25M Series A led by Brightmind Partners, with Costanoa Ventures, Hyde Park Angels, and others participating, bringing total funding to $37M. Founded by former Kenna Security leaders Ed Bellis and Michael Roytman alongside EPSS co-creator Jay Jacobs, Empirical is building predictive exposure management models that combine global exploitation telemetry with each customer’s assets, configurations, and internal data.
Interested in sponsoring TCP?
Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries 🌎
Bye for now 👋🏽
That’s all for this week… ¡Nos vemos la próxima semana!
Disclaimer
The insights, opinions, and analyses shared in The Cybersecurity Pulse are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.







