BriefTechNews

Anthropic Picks Accenture to Police Its Own AI Slowdown, Codex Sandbox Falls, and Cloudflare Cuts 100TB

6 min read · 10 sources

TL;DR
  • Anthropic selected Accenture's Faculty as its first embedded evaluator, with a combined $1 billion investment over five years.
  • Researchers escaped OpenAI Codex's sandbox with the Heapjack exploit, enabling remote code execution on hosts from read-only mode.
  • Cloudflare saved over 100TB of RAM by optimizing the pingora-ketama consistent hashing library.
  • Windows 11 Insider Build 26340.9502 adds remote drive sanitization and deployment via Cloud Rebuild.
  • Google Workspace Studio added custom starters, steps, third-party integrations, and webhooks to its flows.

Anthropic is putting its money where its slowdown proposal is, and it hired the auditor itself. The company picked Accenture’s Faculty unit as its first embedded evaluator to independently red-team models and test safeguards, backing the move with a $1 billion commitment. The catch: there is no existing funding system for independent evaluation, so Anthropic is writing the checks directly.

That is one way to spin up third-party oversight. The other big story today is that OpenAI’s Codex sandbox, the thing keeping coding agents away from your host, turns out to be escapable from its most locked-down mode. Two flaws, one of them nasty enough for remote code execution, were fixed in eight days. Treat your coding agents like the privileged identities they are, because the sandbox is not a moat.

The Heapjack flaw exploits a shared memory heap in the node_repl component, letting untrusted code impersonate the trusted context and reach unsandboxed parent processes.

Anthropic Hires Accenture to Evaluate Its Own AI Slowdown

Source: cointelegraph.com ↗

Anthropic selected Accenture’s Faculty unit as its first embedded evaluator for CEO Dario Amodei’s three-step proposal to slow AI development. The plan, announced September 12, now has a concrete oversight mechanism: Faculty will red-team models, run alignment assessments, and test safeguards. Both firms expect to invest at least $1 billion over the next five years.

The notable wrinkle is funding. Because no system exists for independent evaluation, Anthropic is footing the bill directly. That is a conflict of interest on its face, and the embedded evaluator model is explicitly non-exclusive. For engineers, this is the first real template for what third-party AI safety oversight might look like. Whether it holds up as a standard depends on whether the evaluator’s incentives survive contact with the client.

Codex Sandbox Escape Lets Attackers Run Commands on the Host

Source: bleepingcomputer.com ↗

Researchers disclosed two sandbox escape flaws in OpenAI Codex, and the more severe one, dubbed Heapjack, enables remote code execution on a developer’s machine. The attack works from Codex’s strictest read-only mode and does not trigger approval prompts. It exploits a shared memory heap in the node_repl component, where untrusted code reads a UUID token via v8.getHeapSnapshot() to impersonate the trusted context and access unsandboxed parent processes.

That means an attacker can reach Docker sockets or other Unix sockets from a supposedly isolated agent. Both issues were reported August 12 and fixed within eight days. The lesson for anyone running agentic tools: a read-only sandbox is not a security boundary. Be cautious about opening untrusted repositories, and treat coding agents like privileged identities. The sandbox is a speed bump, not a wall.

AI Cannot Save an Enterprise That Does Not Understand Its Data

Source: pub.towardsai.net ↗

AI is only as effective as the enterprise’s understanding of its own data, relationships, and decision-making rules. Without a clear ontology and a traceable path from data to action, AI just automates the wrong interpretation at scale. Garbage in, garbage out, now with more velocity.

This makes governance and context more important, not less. If your data lineage is a mess, an LLM will happily generate confident nonsense from it and call it a dashboard. The fix is not a better model; it is a better understanding of what the data actually means and who is allowed to act on it.

Model Access Failure Is an IAM Problem in Disguise

Source: scworld.com ↗

AI agents complicate traditional identity and access governance because one employee action can now pass through a model, agent, plugin, service account, API, and downstream application before anything actually happens. Existing IAM controls may govern individual boundaries, but they lack coherent visibility across the full workflow. Answering who performed an action, under what authorization, and with what data becomes a forensic exercise.

This is not automatically a compliance violation, but it adds complexity that increases breach costs. Engineers should map how AI agents, plugins, and downstream APIs extend identity attribution gaps beyond current IAM coverage. If you cannot reconstruct the full chain from human request to action, neither can your incident responders.

Windows 11 Cloud Rebuild Now Sanitizes Drives Remotely

Source: windowslatest.com ↗

Microsoft added Drive Sanitization and Remote Deployment via Recovery CSP to the Cloud Rebuild tool in Windows 11 Insider Build 26340.9502. The new “Remove & sanitize files” option securely erases storage hardware before reinstalling, unlike the standard “Remove files” option, which leaves data recoverable with specialized tools. IT admins can now trigger rebuilds remotely.

This matters for recycling, reassigning, or decommissioning PCs. If a device is leaving the organization, use sanitization. The standard reset was never a guarantee of data irrecoverability, and now you have no excuse for shipping a laptop with last quarter’s payroll on it.

Cloudflare Saves 100TB of RAM with Math and Rust

Source: blog.cloudflare.com ↗

Cloudflare cut memory usage in its Pingora Backend Router (PBR) service by optimizing the pingora-ketama consistent hashing library. Small algorithmic tweaks reduced the memory footprint of structures used for routing cacheable requests by URL. Across the fleet, that adds up to more than 100TB of RAM reclaimed.

The lesson for distributed systems engineers: shaving bytes from a data structure and reducing unnecessary hash replicas turns into real infrastructure savings at hyperscale. A 1% improvement in a structure that exists on every edge node is not a micro-optimization; it is a datacenter bill line item.

Supabase Auth and the Unsupported SMS Provider

Source: asyncdot.com ↗

Supabase Auth can support unsupported SMS providers through the Send endpoint, but the dashboard lacks credential shapes, base URL overrides, or request templates for adding a fifth provider like MSG91 or Termii. The OTP cycle involves two client transactions, with GoTrue hashing and storing codes, enforcing throttles via sms_max_frequency and sms_otp_exp, and a project-wide rate ceiling.

The critical warning: verifying signatures against the raw request body is essential, and delegating OTP delivery makes the endpoint a single point of failure for all authentication. The telecom step is not security-bearing, but the endpoint becomes critical. Plan for fallback mechanisms if you delegate SMS, because when that webhook goes down, nobody logs in.

Google Workspace Studio Adds Custom Starters and Webhooks

Source: workspaceupdates.googleblog.com ↗

Google Workspace Studio introduced four new features for flows: custom starters, custom steps, third-party integrations, and webhooks. Custom starters allow building real-time triggers from other applications, with admins able to set URL allowlists for webhooks. The end-user rollout begins September 21.

IT should review admin settings for allowing or blocking these new starters, steps, and webhook integrations. The security surface expands exactly where you expect: integrations, webhooks, approvals, and URL allowlists. The rollout starts today, so check your allowlists before your users do.

OT Security Operating Model and Zoom Workplace 7.2.0

Source: scworld.com ↗

Building an OT security operating model creates accountability for security outcomes but does not define specific capabilities. Meeting compliance thresholds does not guarantee controls protect operational processes for production continuity. Design the program around operational outcomes, with compliance as one checkpoint, and prioritize operational resilience over checkbox compliance.

Meanwhile, Zoom Workplace 7.2.0 is out, with 7.1.9 on the slow track. The release adds expanded voice translation, translated in-meeting chat, 4K/60fps content sharing, and meeting-summary participant lists. Note the version-specific deployment tracks and mobile release approval requirements when planning updates.

Get the brief

Liked this one? The rest of today's stack — AI, crypto, fintech, infra — lands in your inbox tomorrow morning. Five minutes, no hype.

About Me Author

My name is

BriefTechNews

A daily digest of what actually moved in AI, tech, crypto and fintech, assembled and written with AI, and reviewed before it publishes. Read More
Tags

You May Also Like