Secure AI Coding at the Source.

San Francisco, CA
Our CEO @jackhcable is a primary contributor on new @TransluceAI research. Read about how AI agents went rogue from routine tasks to a much larger hack.
Today’s news that OpenAI hacked the Australian government is not an isolated incident. We’re releasing more than 30,000 logs that include activity from this hack and attempts against previously unknown targets. In this data, we found rogue agent activity stretching back to at least March, two months earlier than was previously known. This activity continues as recently as last week, suggesting it may still be ongoing 🧵 Our blog: transluce.org/agent-activity NYT: nytimes.com/2026/09/23/techn…
1
2
6
416
"Move fast and break things" shaped a generation of software. With AI agents writing more and more of our code, moving fast and breaking things is actually detrimental. At Corridor, we move fast and break nothing, the idea behind our Move Fast, Break Nothing series. We'll be in NYC to gather security and industry practitioners and discuss AI development, software factories and what appsec looks like now. We'll have lightning talks, including one from @JamesBerthoty from Latio, plus food and drinks on us. 🍕🍻 RSVP today: luma.com/corridor-wkbl
2
7
328
Corridor retweeted
Google's models hacked into real companies. While we should be glad that Google's agent didn't cause further harm, I pushed back on the idea that this was business as usual. Agents hacking into real companies is serious and the public deserves to know. More from @erinkwoo and @bobmcmillan in @WSJ:
Replying to @bobmcmillan
Google said it didn't disclose the hacks because they didn't cause harm, and because the models stopped when they realized they accessed real companies. It's part of a broader conversation about how—and when— firms should disclose AI safety/security incidents. ft @jackhcable
7
18
2,319
We made human code review optional at Corridor, but our old GPT-5.5 reviewer in Cursor was approving PRs with correctness and security issues we caught later in development. So we tested four models on 197 historical PRs in the same Claude Code harness. Luna cut false approvals by 60% compared with GPT-5.5, at roughly 21× lower estimated cost per PR. Luna’s false approval rate was 8.7% at $0.18 per PR. Terra’s was even lower at 5.0%, for $1.28 per PR. Grok-4.6 approved nearly half the PRs our reference said needed human review and let through the most high-severity issues. Against Codex Code Review as the auto-approver, Luna made about 76% fewer false approvals. Grok made about 38% more. We wrote up what we learned in our latest blogpost: corridor.dev/blog/how-changi…
2
3
5
440
Move Fast, Break Nothing is our regional event series for security leaders and practitioners. Our first next stop is New York City on October 14 and 15! Wednesday, October 14 is a dinner for senior industry leaders to have a candid discussion on what is actually working as AI coding agents change how software gets built and reviewed. Thursday, October 15 is the practitioner half where we'll have drinks, food, and three short talks, including James Berthoty from Latio. If you're a security engineers, appsec, prodsec, devsecops, or an engineer shipping agentic code, learn from fellow colleagues on how they're building securely. RSVP today 👇 Dinner: luma.com/corridor-a4jm Happy Hour: luma.com/corridor-wkbl
5
11
74,292
It's back to school season and before summer is officially over, we're highlighting our Office Warming Party. Earlier this year we moved into the new office in South Beach and celebrated our Series A. We wore hard hats (a nod to software factories!), had exciting lightning talks, and brought the community together. The best part wasn't the party itself. It was looking around the room and realizing how much this team has grown this year, and we're still growing! If you want to join a fast growing company at the intersection of AI and cybersecurity, check out our open roles: corridor.dev/jobs/
2
4
1,069
Earlier today, @jackhcable took the stage at #ConnectedStack and referenced @danshapiro's level of autonomy in the modern day software development lifecycle.
Replying to @corridor
Saw your presentation today - impressive!
1
2
462
We build on @danshapiro's levels of software autonomy to release a taxonomy for organizations wondering what level of AI adoption they’re at: the Levels of Autonomy in Software Development. L0 is defined by no AI coding, while L5 is a fully fledged software factory. Most teams are somewhere in the middle. In this blog we define each level by who reviews and approves a change, and how we're moving to L5 and beyond. Read more in the blog post: corridor.dev/blog/levels-of-…
1
4
7
3,791
Joining industry leaders on a call for collective action to strengthen cyber defense 🤝 Read the open letter: openai.com/collective-cyberd…
Corridor is proud to join @OpenAI and other industry leaders in calling to strengthen cyber defenses in the face of increasingly capable models. Beyond just finding vulns, the focus has to shift to wide-scale remediation and prevention, and that's what we're doing at Corridor.
1
4
2,695
Corridor retweeted
Corridor is proud to join @OpenAI and other industry leaders in calling to strengthen cyber defenses in the face of increasingly capable models. Beyond just finding vulns, the focus has to shift to wide-scale remediation and prevention, and that's what we're doing at Corridor.
1
2
14
4,496
We couldn't agree more, @AshwinRamaswami!
I'm really grateful to run a startup independent of the foundation labs. At @corridor, our goal is not to sell you tokens, and certainly not to over-hype or create fears about AI. We're practical! We empower security teams using open and closed models, local and cloud agents.
2
1,874
Check out our new research. Turns out, coding agents can be tricked into running malware!
New research from @corridor: we found that coding agents - even with models like Fable - can be trivially tricked into running malware. We connected coding agents to our support system, filed a ticket, and got them to exfil secrets and run malware. corridor.dev/blog/coding-age…
1,449
Corridor retweeted
New research from @corridor: we found that coding agents - even with models like Fable - can be trivially tricked into running malware. We connected coding agents to our support system, filed a ticket, and got them to exfil secrets and run malware. corridor.dev/blog/coding-age…
1
7
12
3,886
In July, a Cursor cloud agent wrote code in our repository that would've leaked every credential in our backend. It was fixed in seconds, never reached a commit, and no reviewer ever saw it. 95.5% of our PRs now come from cloud agents. Review cycles are up 15x. The pull request stopped being the checkpoint to catch everything. So we moved the checkpoint to the commit: → 7 in 10 vulnerabilities caught before a PR exists → Under 2 minutes to fix, vs 50 minutes at review → 1 commit in 20 stopped Read our latest blog on how we did this: corridor.dev/blog/killing-th…
1
3
9
2,435
Read our latest blog post on how model capabilities differ on proactive vs. reactive security tasks. Be sure to catch our talk at DEF CON's AI Village at 4:00pm, presented by @aditinaraa and @farzaan_k this Friday to learn more! corridor.dev/blog/opus-5-sec…
1
2
4
451
Corridor Agent is live! It's a security teammate you can talk to. Ask it what's broken, tell it to fix a SQL injection, watch it open the PR. This works in your dashboard or right in Slack. Live now on Enterprise. Read about it here: corridor.dev/blog/corridor-a…
1
3
1,237