Sam's News โ gpt โ 2026-09-21¶
Security¶
7.5 Researchers escape OpenAI Codex sandbox to execute arbitrary host commands¶
Security researchers discovered critical vulnerabilities in AI agent frameworks including Microsoft's Semantic Kernel, LangChain, and CrewAI that allow attackers to use prompt injection attacks to execute arbitrary code on host systems. Amazon also patched a similar flaw in Kiro IDE that could exfiltrate sensitive local information.
- Microsoft Semantic Kernel vulnerabilities: CVE-2026-26030 and CVE-2026-25592
- Prompt injection attacks can invoke system tools and scripts
- Vulnerabilities exist in LangChain and CrewAI frameworks as well
- Amazon Kiro IDE version 0.7.45 vulnerable to prompt injection on Windows
- Amazon patched Kiro IDE to version 0.8.140 in January 2026
- Flaws arise from how frameworks map AI outputs to system tools
Sources: Microsoft Security Blog AI Web Searched, The Hacker News AI Web Searched, BleepingComputer RSS
AI¶
7 Anthropic considers new AI model as OpenAI's GPT-6 Astra gains traction¶
Anthropic is weighing development of a new AI model amid competition from OpenAI's GPT-6 Astra.
Sources: shattered.io RSS, analyticsindiamag.com RSS Update to: Anthropic Develops New AI Model Amid OpenAI's GPT-6 Competition
6.5 Anthropic weighs new Claude model as OpenAI gains momentum ahead of potential IPO¶
Anthropic is considering development of a new Claude model variant as OpenAI advances toward a potential initial public offering.
Sources: citybiz.co RSS Update to: Anthropic Plans New AI Model Ahead of IPO to Counter GPT-6 Astra
4 Fact-check: Sam Altman's almond-to-ChatGPT water usage comparison¶
Sam Altman's claim that an almond uses as much water as 38,000 ChatGPT queries was fact-checked.
Sources: Houston Chronicle RSS
Business¶
6 OpenAI tests sponsored AI agents in ChatGPT to drive ads¶
OpenAI is experimenting with sponsored AI agents within ChatGPT as a new advertising approach.
Sources: itp.net RSS Update to: OpenAI Launches Sponsored Agent Ads in ChatGPT