Security & Threat Intelligence
The Watch
A loose OIDC trust policy mints production credentials for any WarpBuild runner.
Nothing suggests WarpBuild itself is insecure. The exposure sits in your cloud account. A loosely scoped OIDC trust policy will mint production credentials for whatever runner executes the job, and that runner also holds the GITHUB_TOKEN, any signing keys and every secret the workflow references.
In Play
OpenAI Dots Reach Self-Serve Tiers First
OpenAI's Dots are always-on agents, each with its own cloud computer and 4,000+ app connectors. TheSequence reports they are live now for Pro and Business Premium users. The first Dot costs nothing extra. Only the Enterprise beta waits for a workspace admin to turn it on. Your earliest adopters can connect corporate SaaS from tiers you never approved, and OpenAI has not said whether Business Premium has an admin toggle.
Ask ClarityUber and Zalando Publish an Agent Authorization Blueprint
The ML Engineer reports that Uber now routes every AI agent through one MCP Gateway. The gateway fronts 800+ servers and 5,000 tools, most of them generated automatically from API definitions. Every tool is registered disabled until someone enables it. Zalando separately open-sourced an Agentic Identity Broker that carries the delegating user's identity through each agent hop. Auditors and red teamers will likely use these two designs as the yardstick for your agent platform.
Ask ClarityOne-Line CI Runner Swaps Skip Vendor Review
SRE Weekly reports that WarpBuild is marketing third-party GitHub Actions runners as a one-line workflow change with $50 in free credits. That one line moves your CI secrets, OIDC-minted cloud credentials and release artifacts to a provider your vendor-risk program never assessed. Nothing suggests WarpBuild has a security flaw. The exposure is an adoption path that any engineer with workflow write access can take without involving you.
Ask ClarityGemini 4 Argon's Defender-Only Head Start
Per The ML Engineer, Google DeepMind says Gemini 4 Argon, a model aimed at cybersecurity defense, scores 68% on CWE-bench, a vulnerability-remediation test. TheSequence reports that vetted defenders get first access through the Fairwind Program. Paid API and Google AI Ultra users follow after a phased safety review. Both outlets treat the scores as unverified. A model that can fix vulnerabilities can also find them, so the defenders' head start will end.
Ask ClarityAI Compute Debt Reaches Your Data Custody
Reuters reports that Broadcom will lend Anthropic up to $42B for infrastructure. The FT says Nvidia is in preliminary talks to insure lenders against defaults by smaller GPU clouds. The Information reports that Nscale has filed to go public with 12 contracted data centers still unbuilt. Its anchor customers are Anthropic, Microsoft and Figure AI. If a GPU provider defaults, a lender and a trustee decide what happens to the hardware holding your data.
Ask Clarity
Deep Dives
- ●
Dots Make the OAuth Consent Screen Your AI Perimeter
The Enterprise toggle governs the tier employees are least likely to start on, so the boundary that holds is identity consent and Slack channel scope.
Each Dot runs on its own OpenAI-hosted cloud computer . Your EDR has no endpoint to watch there, and you cannot sandbox the runtime. Only one part of a Dot touches infrastructure you control: its connector tokens. Every connection to…
3 action items
- ●
Uber Registers Every Agent Tool Disabled. Copy That First.
Auto-generated tools turn each new API route into an agent privilege. Tool-level authorization still can't tell which human a call serves until delegated identity supplies that.
The disabled default matters because of how Uber builds its tools. Its AutoCrawler scans API definitions and generates MCP servers from them. An LLM then writes the tool descriptions that agents read when deciding what to call. Every endpoint in…
3 action items
- ●
One Edited runs-on Line Hands Your CI Secrets to a New Vendor
A runner holds signing keys and mints cloud credentials, and a loosely written OIDC trust policy will issue production access to whatever runner executes the job.
For the duration of a job, a CI runner holds the GITHUB_TOKEN , every secret the workflow references, and cloud credentials minted through OIDC federation. OIDC federation trades a GitHub-signed identity token for short-lived cloud keys. Many runners also hold…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn