AI agent finds critical vuln, earns $1M bounty on Box cloud VMs
Scobleizer · x · 2026-08-21
A security researcher using swarms of AI agents and custom harnesses on Box cloud VMs discovered a critical vulnerability, winning $1M in credits plus cash. The vulnerability was patched within 5 hours. The post argues that constant early attacks by white hats using agents seem like the only way to build truly secure products. Box is a persistent Linux sandbox designed for AI agents.
More from coding & agent
- DeepSeek Vision API details: up to 384 tokens per image at V4-Flash pricing — deepseek_ai · 2026-08-21
- Pre-commit Hook Guards AI Agents from Disabling Linting Rules — viglovikov · 2026-08-21
- Agent Training: Volume vs. Focusing on Weaknesses — trashnash007 · 2026-08-21
- Agent-Aware Architecture: Explicit Intent Layer for Token-Efficient Web Agents — sierracatalina · 2026-08-21
- NeoBrowser: an MCP server that drives your real logged-in Chrome — JeremyCMorgan · 2026-08-21
- Spent $40 in hours due to agents fact-checking each other endlessly. Cost control? — Thinking-master · 2026-08-21