4 min readLast build: 10 hours ago

Codex’s sandbox escape is the real AI warning.

“Researchers escaped OpenAI Codex’s sandbox to run commands on a host. Security researchers found two ways to escape O...”

Muninn · Edition 311 · SEP 20

The Frontier

Science & tech breakthroughs in AI models, hardware, and computing that define what's possible

Researchers escaped OpenAI Codex’s sandbox to run commands on a host. Security researchers found two ways to escape OpenAI Codex’s sandbox, including a method that could execute commands on a developer’s host machine from the product’s most restricted mode. OpenAI patched both vulnerabilities after disclosure.

OpenAI’s rapid patches do not erase the core failure: Codex’s most restricted mode could reach a developer host, making sandbox labels insufficient security controls. The test is whether OpenAI opens Codex to third-party red-team audits by 2027.

Bleepingcomputer

BragJack attacks hijack AI browser agents through malicious extensions. Forever Security researcher Gal Weizman demonstrated BragJack, a proof-of-concept attack that uses a malicious browser extension and prompt forcing to hijack AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The research resulted in two CVEs and more than $20,000 in bug-bounty awards.

Bleepingcomputer

Scientists opened a sealed envelope after 10 years. Gravity still disagreed. A decade-long NIST experiment produced a new measurement of the universal gravitational constant, G, that differs from another leading measurement. The small mismatch extends a long-running challenge in precisely determining one of physics’ fundamental constants.

Science Daily


Capital & Control

Tracking the flow of capital and influence that shapes the tech landscape

The US Navy just outlined its tech wish list. Department of the Navy chief technology officer Justin Fanelli described an effort to reduce fragmented startup entry points and move suppliers through a more centralized procurement funnel. The goal is to bring companies that demonstrate results into the Navy’s technology base as enterprise-service providers.

Justin Fanelli is rejecting scattered startup pilots as an end state: suppliers must prove results and earn enterprise-service roles in the Navy’s technology base. The test is whether the Navy converts pilot winners into those providers.

TechCrunch


Infrastructure & Power

The physical backbone of AI: compute, data centers, supply chains, and the geopolitics of energy

It’s Donald Trump versus MAGA on data centers. Wired reports a growing divide between President Donald Trump’s support for data-center and AI expansion and resistance from parts of his MAGA political base. The conflict centers on the local consequences of large data-center development, including the infrastructure demands tied to expanding AI computing capacity.

Donald Trump’s AI and data-center agenda faces its clearest near-term threat from MAGA activists contesting local permits and grid pressure—not Washington. Watch whether those fights block projects before they add AI capacity.

Wired


Digital Defense

Threats and defenses shaping the global security landscape

An undercover Google analyst infiltrated a notorious supply-chain hacking gang. Google Threat Intelligence disclosed that one of its researchers infiltrated TeamPCP during the group’s software supply-chain campaign. The group allegedly compromised developer accounts, planted malware in hundreds of open-source projects, deployed a self-propagating worm, and breached more than 1,000 companies before two alleged members were arrested in Australia.

Google’s infiltration makes TeamPCP’s supply-chain operation unusually attributable; the test is whether future disclosures map compromised developer accounts to the hundreds of malware-planted projects and more than 1,000 breached companies.

Ars Technica


The Performance Edge

Peak performance science for sustained execution in high-stakes environments

Eight common food additives are linked to high blood pressure and heart disease. A study published in the European Heart Journal linked higher consumption of eight commonly used food preservatives with elevated rates of hypertension and cardiovascular disease. The observational research does not establish that the preservatives caused the outcomes, but it adds evidence on processed-food exposure and cardiometabolic risk.

Eight preservatives are a sharper target than “ultra-processed” food, but the evidence cannot yet single out a culprit. Watch for follow-on research isolating one or more of the eight within eight years; until then, treat the link as a risk signal, not proof.

Science Daily


Crypto & Digital Assets

Bitcoin, Ethereum, DeFi protocols, and digital asset market dynamics

North Korean WaterPlum hackers infected 30,000 devices worldwide. A joint law-enforcement advisory said the North Korean-linked WaterPlum hacking group compromised at least 30,000 devices globally between December 2025 and July 2026. The advisory said more than $10.7 million in stolen cryptocurrency was transferred to North Korea.

SentinelOne and fresh SASE entrants are positioned to benefit if WaterPlum’s 30,000-device campaign and $10.7M crypto theft drive endpoint and crypto-custody spending. Watch for spending signals by Q4.

Bleepingcomputer


Market Pulse

Daily market data: indices, sectors, top movers, and volatility

Markets are closed for the weekend. US equity markets are closed until Monday, when the NYSE opening bell rings at 6:30am Pacific.

6:30am Pacific Monday is the next actionable U.S. equity timestamp; the NYSE remains closed until then. Watch for the first post-weekend price signal at the opening bell.

Muninn

Edition 311 · September 20, 2026

Muninn combed 103 feeds and remembered 9 for you today.

Orchestrated by Gurjeet Matharu. Self-hosted on a Raspberry Pi in Silicon Valley. LinkedIn →