Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura

Hazmat is an open-source tool designed to contain AI coding agents within a separate, isolated environment on a user's machine. The tool aims to prevent agents from accessing sensitive user data by restricting their permissions to only the project directory specified by the user.
Typically, AI agents, such as Claude Code, Codex, OpenCode, and Cursor Agent, execute with the same privileges as the user who launches them. This allows them to access all files and directories readable by the user, including SSH keys, cloud credentials, and other configuration files stored in the user's home directory. Hazmat addresses this by creating a dedicated account for the agent and sharing only the designated project directory, thereby keeping sensitive credentials and personal files out of reach.
Before an agent session begins, Hazmat presents a summary of the session's terms. This includes details on the directories the agent can write to, paths it can only read, network and service access permissions, and whether a backup of the project will be performed. This display serves as the final opportunity for users to review the agent's access scope before the automated process commences.
On macOS, the launch sequence involves four steps: backing up the project, building a sandbox policy specific to the session, switching to the agent's dedicated account, and then starting the agent harness. A firewall rule is also enforced prior to the agent's launch. For Linux systems, Hazmat runs natively, while an experimental flag enables a backend utilizing Apple's container tooling.
A demonstration script is available for users to test the containment capabilities. This script creates a temporary project, disables networking, and executes a command that attempts to write a file into the project while simultaneously trying to access a private key from the user's actual home directory. The script successfully writes the file to the project, but the attempt to access the private key fails, confirming that the key remains unreadable by the agent. The post-demo comparison shows only the new file within the project, with no other changes to the user's system.
Approximately 5.5% of Hazmat's codebase consists of a formal specification written in TLA+, a language used for machine-verifiable descriptions of system behavior. This formal specification underpins the project's claim of a "verified" design for its containment model. However, the Go binary that users install is a separate implementation and may contain its own bugs, distinct from the formally verified design. Hazmat is freely available on GitHub.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed