Fetching from the wire…
Public story · 2026-07-30 · high
Bubna's July 28 account ties July's sandbox-escape scares to gaps in front of sandboxes, not inside them.
Why now: Bubna posted his account on July 28, closing out July's run of sandbox-escape scares across the industry.
A Modal customer had published an unauthenticated endpoint, letting anyone on the internet run code in their sandboxes, Akshat Bubna said July 28. Modal's CTO wrote up the incident himself: a rogue agent used that route, not a hole in the platform's isolation layer, to get code running.
That distinction is the whole story. Modal builds its business on the promise that sandboxes stay walled off from each other and from the host. Bubna's account confirms that boundary held. What failed was a customer's own perimeter, an endpoint sitting open in front of the sandbox with no login required.
For anyone running agents that execute untrusted or semi-trusted code, the order of operations here is the lesson. An autonomous scanner doesn't need to break isolation if it can just walk through an unlocked door first, because that's the cheaper move. Isolation gets audited. The routes in front of it usually don't.
The bet worth stating plainly: the next sandbox-escape headline won't be about a broken isolation primitive either. It'll be another unauthenticated endpoint an agent found before a human did. If you're running sandboxed execution, audit what's unauthenticated in front of it before you re-audit the sandbox itself.
Bubna's post is a direct response to a specific incident, not a broader security review. It doesn't say how many other customers might have similar endpoints exposed.
Each link below shares sources, entities, or timing with this story.
The Pragmatic Engineer published a deep read on August 25 of Inspect, the coding agent Ramp built instead of standardizing on Claude Code or Cursor. The numbers: Inspect authors 75% of Ramp's merged PRs, 90% of PRs in its own repository, passed 1 million total sessions in July...
Posted to Show HN August 26 by Trigger Labs: run npx openspender connect or add the MCP server, and the agent mints its own card with per-request, daily and total caps, settling in self-custodial USDC on Base with an itemized ledger. Coverage spans 15,171 x402 endpoints and 14...
On Latent Space, cofounder Akshat Bubna makes the case that agents, not humans, are becoming the primary consumers of compute, sandboxes, and APIs, and the ergonomics that matter for people differ from what agents need. This is the same thread as the MCP stateless shift: the w...
Vercel Sandbox is now generally available — isolated Linux microVMs for AI agents via Firecracker with active-CPU pricing. Already powering BlackboxAI, Roocode, and v0. Supports clone/fork/resume via snapshotting. Direct competitor to E2B and Modal for the agent runtime layer.
Released yesterday, one day after 0.21.0, v0.21.1 adds model call timeouts, run-scoped sandbox working directories, network-disabled Docker sandboxes and Modal sandbox resource options (GitHub). It also fixes the core honoring exact call-approval decisions and rejecting partia...
The beta workbench (macOS and Linux, Pro/Max/Team/Enterprise) acts as a project manager across 60-plus scientific databases, rendering 3D protein structures, genome browser tracks, and chemistry drawings alongside reproducible code. Anthropic explicitly said it is "not a new A...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.