Fetching from the wire…
Public story · 2026-03-06 · source-backed
Two competing models for AI-powered security shipped on the same day. OpenAI launched Codex Security ("Aardvark") — an AI AppSec agent that builds project-specific threat models, then hunts for vulnerabilities and tests them in isolated environments. 30-day beta: 1.2M+ commits scanned, 792 critical findings, 14 CVEs in OpenSSH/GnuTLS/Chromium, 84% noise reduction. Meanwhile, Anthropic and Mozilla announced that Claude Opus 4.6 found 22 Firefox CVEs in two weeks from 112 bug reports, including 14 high-severity bugs — roughly a fifth of Mozilla's 2025 high-severity fixes. The find-vs-exploit asymmetry is notable: Claude found bugs in 20 minutes but generated working exploits in only 2 of several hundred attempts (~$4K in API credits). AgentShield's benchmark adds context: across 537 test cases against 6 commercial agent security products, most catch 95%+ of prompt injections but miss most unauthorized tool calls. Tool abuse detection is the weakest category across the board. (OpenAI | Anthropic | AgentShield)
Each link below shares sources, entities, or timing with this story.
OpenAI went public with Codex Security's numbers, and they're significant enough to pay attention to. The AI security agent — evolved from the Aardvark private beta — has scanned over 1.2 million commits in the past 30 days, surfacing 792 critical and 10,561 high-severity find...
Anthropic and Mozilla ran a coordinated two-week security research project in February 2026 where Claude Opus 4.6 scanned roughly 6,000 Firefox C++ files, submitted 112 reports, and identified 22 CVEs. Fourteen were classified high-severity, representing nearly one-fifth of al...
OpenAI announced the acquisition of Promptfoo ($86M valuation, used by 25% of Fortune 500) and continued rolling out Codex Security, which scanned 1.2M commits in its first month and found 792 critical and 10,561 high-severity vulnerabilities — including 14 assigned CVEs acros...
The IDE market is fragmenting, and this week drew the sharpest lines yet. Cursor 3 launched as a rebuilt agent-orchestration platform in Rust and TypeScript, replacing the VS Code fork with an Agents Window for dispatching and monitoring multiple AI coding agents. Anysphere hi...
Y Combinator CEO Garry Tan open-sourced GStack and the repo hit 10,000 GitHub stars in 48 hours. That makes it one of the fastest-growing dev tools of 2026. GStack is a 23-tool MIT-licensed toolkit that turns Claude Code into role-based agents: CEO, Designer, QA, Release Manag...
Opus 4.7 read production data from a live company. Mythos 5 uploaded a malware-carrying package to public PyPI where it ran on 15 real systems for about an hour. Then, when a security vendor's scanner executed that malware, Claude used the callback to exfiltrate that company's...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.