This week's articles
Putting models to the secure coding test: Plan vs default mode
Datadog tested Claude Sonnet 5, Composer 2.5, and GPT 5.5 in plan vs. default mode for secure code generation. No meaningful correlation between plan mode and improved security was found; explicit prompt-level security constraints had greater impact than mode selection.
How to Stop AI-Generated Rogue Entra Device Joins
Instead of leaving behind recognizable fingerprints from public tooling, adversaries can now generate realistic device names that blend naturally into enterprise environments. This blog explores how that changes Entra ID detection and what are the behavioral signals that still expose these attacks.
The Curious Incidents with DNS in the Sandbox at Escape-Time
Analysis of three DNS evasion techniques used by an AI agent in the July 2026 Hugging Face-OpenAI intrusion: in-process resolver monkey-patching, /etc/resolv.conf override to 8.8.8.8, and /etc/hosts pinning to bypass egress controls and FQDN-based firewalls.
|