Ethical hacker. CEO & Co-founder @Corridor. Prev @CISAgov @Stanford

San Francisco, CA
Today we're announcing @Corridor's $25M Series A led by @Felicis. More code will be written this year than ever before. At Corridor, securing AI coding at the source, enabling companies to their development without security being a blocker. 🧵
23
26
177
31,406
Jack Cable retweeted
For weeks, the news cycle about AI agents out in the wild has been driven by disclosure after disclosure. But most aren't coming from AI companies. Meet the researchers and hackers who are developing the art and science of hunting down rogue AI agents washingtonpost.com/technolog…
10
39
142
10,034
Jack Cable retweeted
LangSmith for Startups Spotlight: @corridor @Corridor uses LangSmith to develop + run novel agentic security evaluations, build + trace inference pipelines, and manage memory graphs that provide specialized context across various product surfaces. Get a demo: corridor.dev/demo
7
6
32
8,813
Jack Cable retweeted
We found several cases where AI agents used aggressive, non-hacking tactics against government websites, including the White House, the Department of War, and several U.S. states. We also found a previously undisclosed hacking attempt against a Canadian government site, which appears to have failed. Technical report: transluce.org/us-canada-gov Washington Post: washingtonpost.com/technolog…
11
43
228
30,435
Jack Cable retweeted
Today, we're launching Security Enforcement for long-running agents. Code is written by agents and nobody is watching. Traditional security reviews aren’t built for this approach, but Corridor is. Today we launched Security Enforcement for long-running agents. We built this to keep security in the loop by enforcing your organization’s security guardrails at commit time. Live for teams on Devin, Claude Code web, Codex, & Cursor: corridor.dev/long-running-ag…
2
6
15
1,594
Notably, these were not cyber benchmarks. Agents, given mundane data retrieval tasks, resorted to attempting to hack sites when they couldn't get the data they needed. Everyone building AI benchmarks - not just cyber ones - needs to have proper monitoring & sandboxing in place.
2
1
7
935
Read more on our research:
Today’s news that OpenAI hacked the Australian government is not an isolated incident. We’re releasing more than 30,000 logs that include activity from this hack and attempts against previously unknown targets. In this data, we found rogue agent activity stretching back to at least March, two months earlier than was previously known. This activity continues as recently as last week, suggesting it may still be ongoing 🧵 Our blog: transluce.org/agent-activity NYT: nytimes.com/2026/09/23/techn…
3
984
NEW: we discover four new cases of rogue agent hacking attempts, which we tie to previously-documented agent swarms from OpenAI. Targets include the Australian government, the University of New Mexico, and several private data hosts. Collab with @TransluceAI and @corridor.
10
6
37
32,729
The Australian PM revealed that OpenAI's agents hacked their systems yesterday. We discovered this activity several days earlier, thanks to public records of the hacking events on urlquery.net.
1
5
1,133
Google's models hacked into real companies. While we should be glad that Google's agent didn't cause further harm, I pushed back on the idea that this was business as usual. Agents hacking into real companies is serious and the public deserves to know. More from @erinkwoo and @bobmcmillan in @WSJ:
Replying to @bobmcmillan
Google said it didn't disclose the hacks because they didn't cause harm, and because the models stopped when they realized they accessed real companies. It's part of a broader conversation about how—and when— firms should disclose AI safety/security incidents. ft @jackhcable
7
19
2,413
Jack Cable retweeted
Replying to @bobmcmillan
Google said it didn't disclose the hacks because they didn't cause harm, and because the models stopped when they realized they accessed real companies. It's part of a broader conversation about how—and when— firms should disclose AI safety/security incidents. ft @jackhcable
1
6
62
10,818
Jack Cable retweeted
Read my new blog for @corridor on how we evaluated agents on the task of auto-approving our PRs: corridor.dev/blog/how-changi… tldr: Luna is goated
2
10
507
Jack Cable retweeted
Move Fast, Break Nothing is our regional event series for security leaders and practitioners. Our first next stop is New York City on October 14 and 15! Wednesday, October 14 is a dinner for senior industry leaders to have a candid discussion on what is actually working as AI coding agents change how software gets built and reviewed. Thursday, October 15 is the practitioner half where we'll have drinks, food, and three short talks, including James Berthoty from Latio. If you're a security engineers, appsec, prodsec, devsecops, or an engineer shipping agentic code, learn from fellow colleagues on how they're building securely. RSVP today 👇 Dinner: luma.com/corridor-a4jm Happy Hour: luma.com/corridor-wkbl
7
14
250,763
Jack Cable retweeted
We build on @danshapiro's levels of software autonomy to release a taxonomy for organizations wondering what level of AI adoption they’re at: the Levels of Autonomy in Software Development. L0 is defined by no AI coding, while L5 is a fully fledged software factory. Most teams are somewhere in the middle. In this blog we define each level by who reviews and approves a change, and how we're moving to L5 and beyond. Read more in the blog post: corridor.dev/blog/levels-of-…
1
4
7
3,864
Corridor is proud to join @OpenAI and other industry leaders in calling to strengthen cyber defenses in the face of increasingly capable models. Beyond just finding vulns, the focus has to shift to wide-scale remediation and prevention, and that's what we're doing at Corridor.
1
2
14
4,537
New research from @corridor: we found that coding agents - even with models like Fable - can be trivially tricked into running malware. We connected coding agents to our support system, filed a ticket, and got them to exfil secrets and run malware. corridor.dev/blog/coding-age…
1
7
12
3,908
We've disclosed these issues to numerous codegen companies. @cursor_ai responded quickly and has added safeguards to detect prompt injection attacks. @AnthropicAI stated that executing checked-out repository code is intended functionality and operates within the isolated VM.
1
1
112
At the end of the day, coding models are trained to help their users. Often, attackers can co-opt those same incentives. We encourage model providers and codegen companies to build in additional safeguards to make similar attacks more difficult. Read the full writeup from Matt Galligan and I here: corridor.dev/blog/coding-age…
130