Today we're announcing @Corridor's $25M Series A led by @Felicis.
More code will be written this year than ever before. At Corridor, securing AI coding at the source, enabling companies to their development without security being a blocker. 🧵
Notably, these were not cyber benchmarks. Agents, given mundane data retrieval tasks, resorted to attempting to hack sites when they couldn't get the data they needed.
Everyone building AI benchmarks - not just cyber ones - needs to have proper monitoring & sandboxing in place.
Today’s news that OpenAI hacked the Australian government is not an isolated incident. We’re releasing more than 30,000 logs that include activity from this hack and attempts against previously unknown targets.
In this data, we found rogue agent activity stretching back to at least March, two months earlier than was previously known. This activity continues as recently as last week, suggesting it may still be ongoing 🧵
Our blog: transluce.org/agent-activity
NYT: nytimes.com/2026/09/23/techn…
NEW: we discover four new cases of rogue agent hacking attempts, which we tie to previously-documented agent swarms from OpenAI. Targets include the Australian government, the University of New Mexico, and several private data hosts.
Collab with @TransluceAI and @corridor.
The Australian PM revealed that OpenAI's agents hacked their systems yesterday. We discovered this activity several days earlier, thanks to public records of the hacking events on urlquery.net.
Google's models hacked into real companies.
While we should be glad that Google's agent didn't cause further harm, I pushed back on the idea that this was business as usual. Agents hacking into real companies is serious and the public deserves to know.
More from @erinkwoo and @bobmcmillan in @WSJ:
Google said it didn't disclose the hacks because they didn't cause harm, and because the models stopped when they realized they accessed real companies. It's part of a broader conversation about how—and when— firms should disclose AI safety/security incidents.
ft @jackhcable
Google said it didn't disclose the hacks because they didn't cause harm, and because the models stopped when they realized they accessed real companies. It's part of a broader conversation about how—and when— firms should disclose AI safety/security incidents.
ft @jackhcable
Corridor's hitting the road, and we'll be hosting an awesome happy hour ft @JamesBerthoty in NYC on October 15th. Join us!
Details here: luma.com/corridor-wkbl
Move Fast, Break Nothing is our regional event series for security leaders and practitioners. Our first next stop is New York City on October 14 and 15!
Wednesday, October 14 is a dinner for senior industry leaders to have a candid discussion on what is actually working as AI coding agents change how software gets built and reviewed.
Thursday, October 15 is the practitioner half where we'll have drinks, food, and three short talks, including James Berthoty from Latio. If you're a security engineers, appsec, prodsec, devsecops, or an engineer shipping agentic code, learn from fellow colleagues on how they're building securely.
RSVP today 👇
Dinner: luma.com/corridor-a4jm
Happy Hour: luma.com/corridor-wkbl
We build on @danshapiro's levels of software autonomy to release a taxonomy for organizations wondering what level of AI adoption they’re at: the Levels of Autonomy in Software Development.
L0 is defined by no AI coding, while L5 is a fully fledged software factory. Most teams are somewhere in the middle.
In this blog we define each level by who reviews and approves a change, and how we're moving to L5 and beyond.
Read more in the blog post: corridor.dev/blog/levels-of-…
Corridor is proud to join @OpenAI and other industry leaders in calling to strengthen cyber defenses in the face of increasingly capable models.
Beyond just finding vulns, the focus has to shift to wide-scale remediation and prevention, and that's what we're doing at Corridor.
We asked Coding Agents a simple support question. They ran our malware.
corridor.dev/blog/coding-age…
Coding agents can be trivially compromised to exfiltrate sensitive data or take malicious actions.
New research from @corridor: we found that coding agents - even with models like Fable - can be trivially tricked into running malware.
We connected coding agents to our support system, filed a ticket, and got them to exfil secrets and run malware.
corridor.dev/blog/coding-age…
We've disclosed these issues to numerous codegen companies.
@cursor_ai responded quickly and has added safeguards to detect prompt injection attacks.
@AnthropicAI stated that executing checked-out repository code is intended functionality and operates within the isolated VM.
At the end of the day, coding models are trained to help their users. Often, attackers can co-opt those same incentives. We encourage model providers and codegen companies to build in additional safeguards to make similar attacks more difficult.
Read the full writeup from Matt Galligan and I here: corridor.dev/blog/coding-age…
At @corridor, we're focused on making security dead-simple. Design is core to that - and we're hiring for a Founding Designer to own product design and UX research.
This is an exciting opportunity to work closely with our customers like @Etsy, @ElevenLabs, and @LangChain to shape the future of security.
DM me if interested.
In July, a Cursor cloud agent wrote code in our repository that would've leaked every credential in our backend. It was fixed in seconds, never reached a commit, and no reviewer ever saw it.
95.5% of our PRs now come from cloud agents. Review cycles are up 15x. The pull request stopped being the checkpoint to catch everything.
So we moved the checkpoint to the commit:
→ 7 in 10 vulnerabilities caught before a PR exists
→ Under 2 minutes to fix, vs 50 minutes at review
→ 1 commit in 20 stopped
Read our latest blog on how we did this: corridor.dev/blog/killing-th…
This summer has been pivotal for cybersecurity and AI, but we are stuck on talking points from April. Here is an attempt to move past the Fable debacle and find a way to compete with China, protect individuals and companies, and allow for innovation.
alexstamos.com/p/moving-forw…