GitHub Security Lab’s Open‑Source AI Security Agent Discovers 24 Android Vulnerabilities
The GitHub Security Lab deployed an open‑source AI‑driven security agent that integrates static analysis, dynamic taint tracking, and LLM‑guided prompt engineering to autonomously scan Android application codebases. Configured with taskflows for intent redirection, insecure data storage, native library fuzzing, and WebView XSS, the agent analyzed ten popular open‑source Android apps over six weeks, surfacing 24 previously unknown vulnerabilities—including five critical RCEs in native components—and facilitated responsible disclosure, CVE assignment, and patching. The agent’s code, Docker image, taskflow templates, and runner script were released publicly to enable reproducible scans.
NVIDIA Open Agent Safety Platform OASP HardwareBased Agent Governance
NVIDIA unveiled the Open Agent Safety Platform (OASP) in September 2026, coupling the open‑source OpenShell runtime with the Sentry watchdog reference design that runs on BlueField‑4 DPUs. OpenShell provides kernel‑level isolation, sandboxed execution, and per‑outbound‑request policy checks, while Sentry monitors agent behavior out‑of‑band and can quarantine or halt malicious agents within milliseconds. The platform targets governance of agents on enterprise‑controlled infrastructure, aiming to move enforcement outside the model and into hardware. Analysts estimate it addresses less than 25% of enterprise agentic risk, leaving SaaS, third‑party, and attacker‑introduced agents ungoverned.