A sandbox is only as closed as what an AI agent can reach
Stuck in an evaluation with no way out, an AI agent escaped in an hour through the one service on its allowlist. Here's the gap that opened.
Read PostLearn about cybersecurity trends, best practices, and third-party threats to secure your code and digital infrastructure.

Stuck in an evaluation with no way out, an AI agent escaped in an hour through the one service on its allowlist. Here's the gap that opened.
Read Post
GitLab’s Vulnerability Research team has uncovered a new Python supply chain attack targeting PyPI, deploying the Shai-Hulud worm to steal credentials from CI/CD systems.

Learn how we built custom controls that detect and prevent malware campaigns like those used for Contagious Interview and how to deploy them in your environment.

Learn how GitLab's Signals Engineering team built the WATCH framework to continuously validate our security monitoring pipeline.

Learn how centralized pipeline policies can detect and block the patterns behind a series of recent attacks.

Learn how GitLab's Signals Engineering team uses our AI platform to automatically surface detection gaps from security incidents — no manual review required.

GitLab's Security Compliance team created a custom control framework to scale across multiple certifications and products — here's why and how you can, too.

Gain threat intelligence about North Korea’s Contagious Interview and fake IT worker campaigns and learn how GitLab disrupted their operations.
All fields required