AI agent finds critical vuln, earns $1M bounty on Box cloud VMs

Scobleizer · x · 2026-08-21

A security researcher using swarms of AI agents and custom harnesses on Box cloud VMs discovered a critical vulnerability, winning $1M in credits plus cash. The vulnerability was patched within 5 hours. The post argues that constant early attacks by white hats using agents seem like the only way to build truly secure products. Box is a persistent Linux sandbox designed for AI agents.

Original post →

More from coding & agent

coding & agent channel →