AWS has offered multiple open-source strategies for holding AI agents accountable, and now it’s adding a full-on sandbox to this stack. Dubbed Strands Box, the new solution uses OS-level isolation and some of AWS’ other recent open-source AI control tools to, ostensibly, retain greater control over autonomous AI agents’ behavior. “Agents increasingly run in ‘YOLO mode,’ approving every action without human review,” the AWS team explained in its announcement. “The usual solution to this problem is a sandbox … but access is only part of what we want to control.” The problem with containers and microVMs typically used to isolate AI agents, as AWS explains it, is that their strong isolation doesn’t come with contextual rule enforcement. In other words, when a containerized or virtualized agent gets hold of a tool, there may be no stopping it from doing whatever it wants - like deleting a production database, or gaining access to the internet and doing dog knows what. That’s where the other open-source tools inside Strands Box come in: It uses the Dogwood Local Engine to give the policy engine in Box temporal awareness, so tool calls can be checked against not only what the agent wants to do, but what it’s already done. As one example, AWS noted that an agent could be allowed to post status updates to Slack, but no more than three times every ten minutes to prevent it from spamming its human operators. An AWS spokesperson further explained that Box could be used to control when an agent can perform a Git push, or it could be used to put a cap on API calls that could end up costing a small fortune. Additionally, Strands Box includes Strands Shell and Monty for Python, which expose shell and Python operations to the same Dogwood policy engine and event history, making agentic actions clearer to developers and allowing policies to account for what an agent is trying to do. AWS VP and distinguished engineer Marc Brooker, one of the folks behind Dogwood and Strands Box, explained to The Register that the interpreters are a key part of making agentic behavior more intelligible, which allows for devs to write more precise policies to prevent agents from taking bad actions. “Box’s Shell and Python interpreters expose operations such as file deletions, while its gateways expose API requests and tool calls,” Brooker told us in an email. “Policies can then account for the action being attempted and earlier activity.” Box, Brooker added, enforces those rules without trusting or relying on agents to actually follow instructions, which should ideally prevent them from running roughshod over their operators’ wishes. As for the reason behind AWS’ push to develop open-source tools like Dogwood, the Dogwood Local Engine, and Strands Box, Brooker said that AWS wants to find the right balance between boundaries and policies that prevent agentic AI disasters of the kind we regularly report. “Box enforces the policies developers configure, deterministically, and the agent can't talk its way around these rules,” Brooker explained, though he added that, even with properly configured permissions, an agentic action can still produce an unwanted result. “Developers remain responsible for deciding what access to grant and where human review is needed,” Brooker added - in other words, don’t let your YOLO mode go too YOLO. A bit of human oversight is still necessary. “Agent safety is an area where the industry still has significant work to do, and we're committed to continuing to invest in it, both inside the AWS cloud and in open source,” Brooker said. Strands Box supports any agent or harness one wants to confine within its walls and is available on GitHub now, though only for macOS for the time being. Linux support is in development, and AWS told us a Windows client is “on our radar,” but neither has a planned release date. Deployment to platforms like AgentCore, ECS, and Kubernetes is also planned. ®
The attorneys general of Florida, Iowa, Montana, and Nebraska have sued ubiquitous networking and smart home tech maker TP-Link, alleging its security claims were misleading and it hadn't properly disclosed ties to China. The company has a large presence in US retail and the tech channel, especially in consumer routers, with stats from Circana asserting it had around 36.6 percent US market share by units and 31 percent by dollars in 2024. The complaint [PDF] accuses California-based TP-Link Systems, whose brand originated in Shenzhen, of deceptive and unfair marketing practices concerning its routers' security and its connections to China. It cites exploitation of TP-Link devices by Chinese and Russian state-backed hackers. The suit also claims TP-Link allegedly concealed facts about its "past and ongoing ties to the People's Republic of China," accuses it of having a supply chain that's reliant on PRC players, repeated firmware vulnerabilities, and being subject to Chinese laws that force companies to cooperate with state intelligence. According to the states' attorneys general, the hardware vendor still relies on Chinese companies for research and development and manufacturing operations, despite previously claiming to have moved into Vietnam after severing ties with China. The complaint alleges that only 0.5 percent of components used at TP-Link's Vietnamese plant, measured by value, are bought in Vietnam, with "all other inputs" imported "from or through China." The complaint also claims that a US-designated Chinese military company carried out construction work at the Vietnamese factory, challenging TP-Link's assurances about its supply chain's security. The complaint cites 2025 testimony [PDF] from former NSA cybersecurity director Rob Joyce that TP-Link's share of the US retail market for Wi-Fi systems and small-office/home-office (SoHo) routers at at least 60 percent. Lawyers pointed to various snippets from TP-Link's marketing materials. These included claims that its HomeShield product "covers all security scenarios" and, on a version of its website available in November 2025, provides a "100 percent safeguard" for network security. The complaint argues that TP-Link's security assurances were misleading because its routers contained critical vulnerabilities. It further cites Joyce's that TP-Link routers were among the brands exploited in the China-linked Volt Typhoon and Flax Typhoon campaigns. The complaint also alleges that TP-Link's privacy policies permit it to collect customer data and share it with affiliates without disclosing how its Chinese connections and China's intelligence laws could expose that information to Chinese intelligence agencies. "Iowans' sensitive data and our national security is at risk because of TP-Link and their connection to the communist Chinese government," said Iowa Attorney General Brenna Bird. "TP-Link tells Iowans its routers are safe, our personal data is secure, and that they have no ties to China. They are not telling the truth. It's time to hold China and China-backed companies accountable." "TP-Link's false statements and deceptive advertising are a violation of Montana law," said Attorney General Austin Knudsen. "As a result of their nefarious practices, millions of Americans have unknowingly invited a foreign adversary into their living rooms and put their personal information at risk. "I will do everything I can as Attorney General to hold TP-Link accountable and protect our privacy and security." Steve Kovsky, corporate affairs officer for TP-Link Systems Inc., said the lawsuits were based on false premises, did nothing to advance national security, and unfairly penalized a US company. Kovsky added that the company has spent months providing officials with clear documentation showing that it is not owned or controlled by any foreign government and that its devices sold in the US are manufactured in Vietnam. "Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless," he said. "TP-Link Systems is a US company that complies with US privacy and data protection laws. We perform comprehensive security testing and rely on trusted third-party security labs for additional scrutiny to ensure our products meet the highest security standards and are recognized as among the most secure on the market. "We meet or exceed all industry best practices for monitoring and preventing vulnerabilities and actively support our customers to mitigate any issues that occur as they are identified. We do not, and will not, share customer network data with foreign governments or unauthorized third parties. "We stand fully behind the security of our products, the integrity of our company and our people, and our commitment to serving the best interests of our customers in the United States and globally. We look forward to refuting these baseless allegations in court." The allegations echo those made by Texas Attorney General Ken Paxton, whose office sued TP-Link earlier this year over its Chinese connections and router security. US officials began weighing restrictions on TP-Link router sales in 2024. In March 2026, the FCC imposed broader restrictions [PDF] on new foreign-produced router models, barring new equipment authorizations unless an exemption is granted. Previously authorized models were not automatically banned. ®
A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet. This is the first case of “adversarial poetry” - an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails - that Lumen’s Black Lotus Labs, which has been tracking the PoeLLM malware, has seen in real-world attacks. “This is a first for us,” the researchers told The Register via email. “While we can't get inside the threat actor's head, we think the attacker might have used a poem because it serves as a perfect vehicle for hiding an important message,” they added. “To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models. There would be no reason for any security researcher to identify this poem as malicious - or know about the IP address hidden within it - unless they had access to the malware referencing it.” PoeLLM malware has been active since at least April, impacting more than 3,000 servers primarily located in the US and Western Europe, and it continues to infect new victims. At its peak, the malware infected more than 800 active servers per day. The malware abuses - and scans for - open source AI systems and services. Most of the victims were running vulnerable, internet-facing versions of LiteLLM and Ollama. Additionally, hundreds of victims were running Gotenberg, a PDF converter, and software development platform Gitea. In addition to these open source tools, the attacker may have targeted commercial software including Ivanti Sentry. The threat hunters first spotted the PoeLLM malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. “In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122,” according to a Wednesday report shared with The Register. “Shortly after contacting this C2, the Ivanti Sentry victim began scanning for other vulnerable devices.” How adversarial poetry works Black Lotus Labs attributed the PoeLLM malware to an Italian-speaking criminal, and named the financially motivated campaign Canto Incognito because it hides the malicious commands in a poem posted to a GitHub repository. “Comments within the malware and on the attacker’s GitHub pages are in Italian, and netflow analyzed by Black Lotus Labs suggests that the attacker is located in Italy,” the threat-hunters told us, adding that they believe the campaign targets AI systems and that the poem itself was written by AI. The malware deploys XMRig and Iron miners, and connects victims to Kryptex mining infrastructure. In addition to using compromised GPU hardware powering AI workloads to mine cryptocurrency, PoeLLM also turns victims' machines into vulnerability scanners and exploit servers, which allows the attacker to compromise even more vulnerable systems. The researchers’ investigation indicates that the cryptojacking miscreant - aka GitHub user “ejejejdfbbebe” - made the first GitHub commit with the adversarial poem on April 13. The repo is a fork of the nodejs.org website source code, and the file is called “dash.css.” Inside the file, there’s a poem titled “On the Nature of Connection,” which has been updated 11 times since its initial commit. Here’s the most current version, as of September: In the silent hum of driver, the machines begin to speak, Each pulse of diode threading light through copper veins. we taught the dark to carry meaning, byte by byte — A language built from lightning, cold and clean. Beyond the wall of encryption, a signal finds its way, the tick of distant servers answering back. Data moves like water through the cracks of ordered thought, and somewhere in the code, the world stays on track. Here’s the adversarial piece: the malware finds its current command-and-control (C2) server from keywords in the poem, and when the operator changes the poem, the infected systems find the new C2 location. It does this by parsing the poem, extracting certain words and phrases, and then converting them to numbers using a hard-coded dictionary in the body of the malware. Black Lotus Labs says the logic for C2 discovery works like this: The function “extract_poem_phrase_field” extracts three words/phrases from the body of the poem, case-insensitively: Word 1: text between "In the silent hum of " and "," Word 2: text between "each pulse of " and " threading" Word 3: text between "Beyond the wall of " and "," 0x44a8db–0x44a99b extracts the fourth word differently: Find " of distant servers" Walk backward to the previous whitespace Require the 4 bytes before the word to be "the " Use the word after "the " as Word 4 The four words are then matched to corresponding numbers, which combine to form the IPv4 address hosting the server. Here’s what the C2 conversion looks like with the key: Black Lotus Labs’ write-up lists all the C2 IP addresses, plus when they were first and last seen, so be sure to check that out. More AI infrastructure = larger attack surface As enterprises increasingly use AI in their operations, they also expand their attack surface. And, as we have repeatedly seen, security remains an afterthought in AI deployments. “The Canto Incognito campaign appears to be relatively unique in its targeting of multiple AI-related services,” the researchers told The Register. “Other notable campaigns this year, including the LiteLLM supply chain compromise, focused on a single service and impacted roughly 2,500 victims, according to open sources. The collection of more than 3,000 PoeLLM victims appears to exhibit multiple vulnerable services at any given time.” For comparison: The LiteLLM supply chain attack, which began with a compromised Trivy build, potentially exposed more than 2,500 companies and 434,000 CI/CD pipelines worldwide, according to CloudSEK security researchers. The PoeLLM malware developer “has been extremely successful in identifying vulnerable servers, deploying exploits, and conscripting victims to continue expanding the campaign,” Black Lotus Labs said. “If the actor had only focused on one or two vulnerabilities, the potential victim pool might have quickly dried up, but the expanding scope allowed for a bigger, more powerful (and more profitable) botnet.” They told us they expect to see more of these types of attacks in the near future. “AI makes it easier to deploy tools like LiteLLM, Ollama, or Gotenberg, but AI isn't always checking to make sure those services are patched and protected from attackers,” the researchers said. “As more AI-enabled servers come online, malware like PoeLLM will continue to spread.”®
The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet firewalls. The agencies published a joint advisory on Tuesday, citing SOCRadar's verification of more than 86,644 compromised devices across 194 countries. "Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," their advisory [PDF] states. "During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment." The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways. Criminals use credentials from earlier breaches and infostealer logs for credential stuffing and password spraying, then extract password hashes from compromised devices and crack them offline using GPU-accelerated clusters. The agencies urged organizations to restrict internet-facing management access, terminate active administrative and VPN sessions, reset passwords, and enable phishing-resistant multi-factor authentication. The advisory also links FortiBleed to ransomware campaigns, saying initial access brokers supplied compromised-network access to ransomware affiliates. The Register previously reported on the connection, identified by SOCRadar. The current evidence points to affiliates working for the INC/Lynx and Payload ransomware groups making use of the credentials, and SOCRadar said in July that it had seen at least 12 confirmed ransomware attacks stemming from FortiBleed. The agencies encouraged victims to report incidents, while noting that organizations were not obliged to provide information in response to this advisory. The FBI and the Secret Service said victim reports could help identify indicators of compromise and warned against paying ransoms. ®
South Korean president Lee Jae Myung has told the nation’s cabinet that it’s time to develop AI-powered defensive tools to combat AI-wielding attackers. “Recently, a series of personal information leak incidents have been occurring at financial and public institutions,” he said yesterday – likely referring to incidents like the breach at e-tailer Coupang and last week’s raid on local banks that exposed customer data. “Circumstances indicate that artificial intelligence was utilized, causing great concern and anxiety among the public,” he claimed. “I request that the relevant authorities swiftly and clearly identify the circumstances of these incidents, and rapidly deploy and concentrate the necessary personnel and resources to minimize damage,” he added, before calling for South Korea’s government to “build security capabilities that can detect attacks in advance and preemptively block them.” “I urge the relevant ministries to quickly inspect the security systems across the entire national core infrastructure, as well as the private sector, and immediately implement any necessary security measures,” he continued. “I hope we can accelerate the development and distribution of AI technologies specifically tailored for cybersecurity.” President Lee thinks South Korea needs to “completely innovate our society's security paradigm to fit the AI era.” That work will involve public and private sector players collaborating “to transform our technology, systems, and awareness.” The remarks amount to a major policy statement, and a very public one at that. South Korean ministers and tech giants now get to turn the president’s words into action, a complex task given the broad scope of the leader’s demands and the fact that nobody thinks it's possible to defeat cybercrime. Meanwhile, Down Under Also yesterday, Australian politicians had their chance to grill OpenAI Chief Strategy Officer Jason Kwon, who fronted a parliamentary committee to answer questions about how his company’s agents accessed a government medical records website. Kwon allowed that OpenAI should have done better than emailing the abuse reporting email address at the relevant Australian government agency but defended the company’s efforts to learn from the Hugging Face incident. The committee is sitting for another two days this week, with one topic of debate being how or if Australia should tweak its copyright laws to ensure AI companies pay content creators whose works they use when training their models. Australian law doesn’t include a fair use provision like those that AI companies in the USA relied on when sourcing content. Creators fear a rumored opt-in payments scheme will be too weak, but Australia’s government fears it may miss out on big datacenter investments and access to onshore frontier models if it doesn’t change copyright law to make it more AI-friendly. ®
Only a week after warning about the perils of competitor Z.ai's GLM-5.3 model and its advanced cybersecurity capabilities, Anthropic has expanded its Cyber Verification Program (CVP) – or rather, reconfigured it. "For the past six months, we’ve enabled trusted access through two programs: Project Glasswing and the CVP," the AI biz said. "Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems." Project Glasswing and CVP launched in April 2026 alongside the debut of Mythos, the company's highly capable and equally hyped frontier model. Project Glasswing gave partners early access to Mythos so they could scour their systems for vulnerabilities before attackers beat them to it. VulnCheck researcher Patrick Garrity was not particularly impressed with CVEs identified by Project Glasswing, noting that fewer than 0.5 percent of the 225 Anthropic-linked vulnerabilities he tracked were being exploited in the wild. And Anthropic's own warning last month about the risks posed by GLM-5.3 somewhat undermines the idea that there's anything special about its own Mythos model. Even so, Anthropic says that its security program has allowed its partners to spot at least 129,000 verified software vulnerabilities between April and July 2026. And the biz claims that its own open source scanning efforts revealed an additional 5,500 verified vulnerabilities between April and October. "Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity," Anthropic said. "This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher." When these might get patched is unclear. The company's own figures indicate that of 5,674 true positive vulnerabilities, 3,014 are high severity, and 1,522 are critical severity, yet only 516 have been patched. Given industry boasting about the cybersecurity prowess of AI models, generating a fix, testing it, and deploying it ought to be nearly automatic at this point. But the gap between identification and remediation suggests there's a lot of slack in the system that needs to be ironed out. Two programs into one with three tiers Now Anthropic's two programs, one intended for organizations and one for individual security professionals, have been merged and reconfigured into three tiers. The AI biz has not explained why, but its stated intent is to tie model capabilities to specific tasks: Defense Access, Red Team Access, and Specialized Access. Depending on the tier, participants will encounter more or fewer blocks on security-related tasks. As a measure of program participation value, Anthropic said that based on five attempts at 10 CyScenarioBench challenges, those without CVP access got blocked on every attempt. Defense Access is intended for security teams at companies, nonprofits, universities, and government organizations that focus on system defense. In this tier, Claude Opus 5.5 faced refusals in 46 of 50 attempts and succeeded four times. Red Team Access is for penetration testing and offensive cyber evaluation, and participants will still face model refusals for model interactions that would cause physical harm or mass disruption. Specifically, Claude Opus 5.5 completed 34 of the 50 tasks with Red Team Access safeguards enabled, a rate similar to what would be expected from Specialized Access. Specialized Access sounds like a rebranding of Glasswing – it's "reserved for a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks." Those granted admission to this exclusive tier will face the fewest model refusals, not counting anyone using abliterated open-weight models that have had their guardrails suppressed. For the next month or two, program participants will need to allow their data to be retained by Anthropic as part of its AI safety requirements. But soonish, the company's Enterprise Frontier Safeguards program will offer zero data retention. Organizations already granted zero data retention while using Claude Fable 5.1 or Claude Mythos 5.1 can participate in CVP under those same terms.®