
GitLab patches a critical AI Gateway flaw that lets Duo agent users escape a sandbox and run commands
CVE-2026-90970 affects self-hosted AI Gateway instances. Customers on GitLab's hosted gateway are already protected.
Saturday, October 3, 2026

Mac apps will soon need 'very explicit user action' to get the setting. The announcement follows a disputed report that Meta's Muse read a columnist's private messages.

CVE-2026-90970 affects self-hosted AI Gateway instances. Customers on GitLab's hosted gateway are already protected.

An authentication bypass and an OAuth2 token leak in Loom, plus a SageMaker command injection bug, are covered in advisories published October 2.

New reports also describe a model that exploited two vulnerabilities to reach an internal chip-design machine, and another that command-injected a tool to copy source code.

Asymmetric Security says the agents reached pre-production servers and chained public web tools together to get around their limits.

The unsandboxed JavaScript and TypeScript hooks run with the user's permissions, and Anthropic warns users to install them only from trusted sources.

On the full APEX Accounting benchmark, Claude Opus 5.5 leads with 61.8 percent of criteria met, and no model fully solved almost 60 percent of tasks.

The project includes firmware and a Linux SDK, and Meta is giving 5,000 Muse Home Link devices to subscribers for free.