Fetching from the wire…
Public story · 2026-08-17 · high
The open-source tool sandboxes each agent's file and network reach instead of letting it run with your full account.
Why now: Help Net Security covered the project on August 17.
Hazmat gives each coding agent its own macOS user account, a kernel-enforced sandbox, a firewall, and a DNS blocklist, per Help Net Security's August 17 coverage. Before a session starts, it prints exactly which paths the agent can write to, which it can only read, and what network access it gets. It also takes an automatic backup before each session.
The problem it targets is the one most people using coding agents skip past. Launch an agent the normal way and it runs as you, with your account's full reach. Every SSH key and cloud credential sitting in your home directory is fair game if the agent goes wrong or gets prompted into doing something it shouldn't.
The repo, dredozubov/hazmat, was created March 27 and sits at 128 stars as of the August 17 coverage. That's early. Small user base, not much of a track record yet. What stands out is the TLA+ verification, a formal method usually reserved for systems where a bug can't be patched later, not a side project a few hundred people have starred.
I don't run agents under a separate OS user. I trust the sandboxing my tools already do and I've never had one touch something it shouldn't. But I also haven't audited what my home directory actually exposes if one did. Hazmat's real contribution isn't the tool, it's naming the exposure out loud: if you're running coding agents locally, you already know what's in reach. The question is whether you've looked.
Each link below shares sources, entities, or timing with this story.
First major enterprise observability platform to ship a production-grade MCP server. Feeds live logs, metrics, and traces directly into Claude Code, Cursor, Codex, GitHub Copilot, and VS Code. AI coding agents can now investigate production issues using real-time telemetry. MC...
The http_request and web_fetch agent tools in SiYuan before v3.8.1 validate only the safety-check resolution, so an attacker answers the guard lookup with a public address and the real lookup with an internal one (NVD). The paired CVE-2026-82233 is a path traversal in the asse...
Hudson Rock got hold of the archive and counted it. 433,909 files. 118,829 CI runner dumps traced to 2,488 corporate domains. AWS keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys belonging to NVIDIA, Volkswagen, Micr...
This is the one that should make you check your own setup tonight. June MCP-security roundups flag roughly 12,520 internet-exposed MCP services, about 40% of them with no authentication at all. On top of that, Adversa AI's TrustFall and SymJack research shows that Claude Code,...
Two AI toolchain CVEs hit CISA's Known Exploited Vulnerabilities catalog this week, and the attack chain connecting them is the kind of thing that should change how you think about supply chain trust. CVE-2026-33017: Langflow, the popular agent workflow builder, has an unauthe...
Anthropic started emailing affected users on August 30. Sessions invalidated, saved payment methods stripped, unauthorized charges refunded. The cause, per Help Net Security's writeup of the disclosure, is six commodity infostealer families lifting authenticated Claude session...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.