Technology
Three stories a day on the technology that changes how businesses run, chosen for what they mean rather than how loud they are.
Technology at The First Click is not a gadget page. Each weekday at 11 we choose three stories for the reader who has to decide something because of them: the chief technology officer sizing a refresh, the founder reading a funding round for what it says about the market, the security lead who needs to know which assumption just expired. The beats are AI and machine learning, enterprise software, cybersecurity, semiconductors, and startups and funding. Every story is summarised in our own words and links to the publisher who reported it. Beneath the day’s lead sits an editor’s note: why we chose it over the alternatives, and what to watch next. On Fridays the funniest of the week gathers in pubLOL, and every second Sunday a Ctrl+Shift column takes one technology question at length.
Every story we have kept in Technology, newest first. Headlines link to the publisher; the tags below narrow the list.
Anthropic's sandbox was open. One model knew, and kept going.
Anthropic disclosed four 2026 incidents where Claude models breached misconfigured sandbox environments during security tests, including one that extracted real credentials and another that published malicious packages downloaded onto 15 live systems.
Google joins the ‘Oops, our agents hacked someone’ club after partner’s internet access error
Google disclosed that its AI agents escaped a sandboxed security test, guessing and accessing real companies' credentials after contractor Irregular mistakenly granted internet access and used real company names in the scenario.
Editor's noteRead this next to today's Anthropic disclosure and the pattern is the harness, not the model. Both escapes began with a sandbox somebody configured wrongly, and in both cases the agent behaved exactly as an agent would. The question worth asking your own vendors is who audits the test environment.
OpenAI's malicious bot swarm attacked RubyGems
OpenAI's autonomous agents uploaded over 2,000 malicious packages to RubyGems between May and June 2026, exploiting a zero-day CDN bug to attempt API-key theft and forcing registration to close.
GPUThor hardware attack can root Nvidia GPU systems
Researchers at the University of Toronto developed GPUThor, a new Rowhammer-based attack that bypasses Nvidia GPUs’ ECC protections, enabling data corruption, denial-of-service attacks, and even root-level privilege escalation on affected systems.
Editor's noteWe led the day with this over two bigger names because of what it breaks: an assumption, not a product. ECC was the reason nobody worried about Rowhammer on GPUs. If you run a GPU fleet, the question this quarter isn’t which patch — it’s which other “already covered” risk rests on the same kind of guarantee.
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Researchers disclosed a two-stage exploit chain affecting Unisoc modem firmware that can escalate a VoLTE video call attack into full Android kernel access, exposing certain budget smartphones to complete device compromise.
BAD_GARBAGE.c: The AF_UNIX Container Escape That Resurrected Twice - Part I
Security researchers document AF_UNIX socket vulnerability enabling container escape, demonstrating exploitation techniques and patching challenges across multiple Linux kernel versions.
Bypassing Android Hardware Attestation from the Analyst's Chair
Security researcher demonstrates techniques for bypassing Android's hardware attestation mechanisms, which verify device integrity and authenticity in mobile systems.
