vibehacker
News
BleepingComputer ·

OpenAI Codex sandbox escapes let code run on the host (now patched)

Accomplish AI researchers disclosed Heapjack and Overpatch: Codex sandbox escapes that could run host commands, including from read-only mode via a shared Node heap token. OpenAI patched both within eight days; update Desktop to 26.818.21641+ and CLI to 0.149.0+.

More news

View all

Claude Code: build-eval and hillclimb tune agents without overfitting

Anthropic’s claude api skill adds /claude api build eval (guided eval design in your repo) and /claude api hillclimb (one change per round tuning with a held out set to catch overfitting). On an internal support bench, hillclimb lifted search accuracy from 74.4% to 98.9% while cutting cost to about one fifth…

Anthropic

Claude Code 2.1.285: disable WebFetch, admins lock API providers

Claude Code 2.1.285 (npm Sept 29) adds CLAUDE CODE DISABLE WEB FETCH to turn off WebFetch and a managed allowedProviders policy so admins can lock machines to Anthropic, Bedrock, Vertex, Foundry, or a cloud gateway. It also ships claude desktop , claude plugin configure , and a fix for URL passwords leaking past log redaction…

Mixed News

OpenAI MCP Events: ChatGPT plugins react via signed webhooks

OpenAI’s DevDay MCP Events let ChatGPT plugins subscribe to MCP server updates (messages, comments, status) and trigger automations over verified signed HTTPS webhooks. Servers need MCP 2.0 (protocol 2026 07 28) with events/list, events/subscribe, and events/unsubscribe; polling and streaming aren’t supported…

OpenAI

Spotted something we missed? Start a thread.