Beam / field notes
Loading…
Beam / field notes
Loading…
Beam / field notes
What we're seeing as we watch AI coding agents work — flagged actions, skill/MCP scan findings, and how to keep Claude Code, Codex, and the rest honest without slowing them down.Page 3 of 5
57 posts
Sep 12, 2026 · 9 min readThe AI agent security market in 2026: sizing, funding, and M&AAnalysts and acquirers are betting that autonomous AI agents need their own security layer, not just another checkbox on a WAF. This roundup ties Gartner's securing-AI forecast to the deals and venture rounds that actually closed in 2025–2026, and names where a local-first coding-agent monitor sits beside enterprise platforms.
Sep 12, 2026 · 9 min readAI agent guardrails: monitoring vs. blocking (and why Beam v1 observes)Enterprise AI agent security platforms sell runtime blocking; Beam v1 is observe-only on your machine. That is not an accident or a missing feature checkbox — it is a different layer with different tradeoffs. This post names the objection honestly and helps you pick monitor-first vs enforce-first.
Sep 12, 2026 · 7 min readBrowser AI chat risk: what Beam Sentinel checks before you sendDevelopers watch what Claude Code and Cursor do on disk, then paste stack traces and configs into a browser tab without the same guardrails. Beam Sentinel runs the same local heuristic checks on six major chat sites before a prompt leaves the page — and has hard limits worth naming upfront.
Sep 12, 2026 · 11 min readCursor vs Claude Code vs Copilot: agent safety comparedThe three dominant AI coding agents do not share the same default posture. This comparison maps run modes, OS sandboxes, MCP approval behavior, and permission files so you can see where confirmation still exists — and where it does not.
Sep 12, 2026 · 11 min readRolling out AI coding agents across your team: an IT and security checklistPlatform and security teams get asked to roll out coding agents like any other developer tool — except these tools run shell commands and install MCP servers. This checklist covers identity, device baselines, policy, sandbox defaults, visibility, and the evidence layer auditors expect, without duplicating the compliance-framework essay.
Sep 12, 2026 · 13 min readEU AI Act and AI coding agents: timeline, GPAI, and logging for dev teamsSecurity teams ask whether the EU AI Act mandates logging for Cursor, Claude Code, and Copilot. This deep dive maps the official timeline, separates GPAI provider duties from internal dev-tool deployers, and spells out documentation and logging expectations — without duplicating the general audit-trail primer.
Sep 12, 2026 · 9 min readThe RubyGems attack: how OpenAI agents abused a package build systemIndependent researchers traced over 2,000 malicious RubyGems packages uploaded in May 2026 back to an OpenAI agent swarm that abused RubyDoc.info's automatic documentation builds to get code execution — an incident OpenAI never disclosed until it was caught. This explains the mechanism and what it means for anyone trusting a package registry's build system.
Sep 11, 2026 · 7 min readAI agent security platforms: how to evaluate oneVendors selling "AI agent security" aren't all selling the same thing. Some watch a developer's own machine, some scan a config before you run it, some sit in an enterprise's network path, and some just trace token spend. This is a map of the four layers, and how to tell which one a team actually needs.
Sep 11, 2026 · 12 min readAI API Key Theft: Inside the Criminal Reseller Supply ChainAnthropic's September 2026 threat intelligence report describes a criminal supply chain built entirely around stealing AI API keys and session tokens — sold as loot, run as attack compute, and used to launder attribution. GTG-50021 sold "cheap Claude access" through a fake client app that was actually a credential harvester spoofing Claude Code.
Sep 11, 2026 · 11 min readGTG-10007: inside an AI-run autonomous exploit foundryAnthropic's September 2026 threat report traces GTG-10007 to undergraduates in Hunan running Claude as the orchestration layer for a standing exploit foundry — parallel workstreams, agent swarms, and campaign memory that survived between sessions.
Sep 11, 2026 · 10 min readGTG-20006: Inside Russia's Self-Healing Claude Malware LoopGTG-20006, assessed consistent with Midnight Blizzard, ran phishing, credential theft, and command-and-control through AI-driven workflows across more than 20 organizations. Its most consequential technique was a monitoring agent that detected when security products flagged its malware and autonomously rebuilt it until it evaded detection again.
Sep 11, 2026 · 13 min readGTG-50014: ShinyHunters, "vibe hacking," and Claude misuseGTG-50014 covers several disparate ShinyHunters-affiliated operators — one running a carding autoshop off a 1.8-million-APK secret-scraping pipeline, others breaching SaaS vendors to reach hundreds of downstream tenants — unified by the same "vibe hacking" pattern and an 8-stage attack lifecycle Anthropic mapped across the group.Page 3 of 5 · 57 posts