惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
量子位
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
V
Visual Studio Blog
C
Check Point Blog
博客园 - 聂微东
博客园 - 叶小钗
Microsoft Security Blog
Microsoft Security Blog
E
Exploit-DB.com RSS Feed
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
N
Netflix TechBlog - Medium
Recorded Future
Recorded Future
aimingoo的专栏
aimingoo的专栏
罗磊的独立博客
Spread Privacy
Spread Privacy
Cisco Talos Blog
Cisco Talos Blog
C
Comments on: Blog
N
News and Events Feed by Topic
L
Lohrmann on Cybersecurity
小众软件
小众软件
H
Heimdal Security Blog
云风的 BLOG
云风的 BLOG
The Cloudflare Blog
Apple Machine Learning Research
Apple Machine Learning Research
The GitHub Blog
The GitHub Blog
Security Latest
Security Latest
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
H
Hacker News: Front Page
D
Docker
N
News and Events Feed by Topic
Application and Cybersecurity Blog
Application and Cybersecurity Blog
P
Privacy & Cybersecurity Law Blog
S
Schneier on Security
T
Troy Hunt's Blog
MyScale Blog
MyScale Blog
The Register - Security
The Register - Security
Simon Willison's Weblog
Simon Willison's Weblog
L
LangChain Blog
T
The Exploit Database - CXSecurity.com
D
Darknet – Hacking Tools, Hacker News & Cyber Security
NISL@THU
NISL@THU
TaoSecurity Blog
TaoSecurity Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
P
Privacy International News Feed
Blog — PlanetScale
Blog — PlanetScale

Swift for Visual Studio Code comes to Open VSX Registry | InfoWorld

Google unveils DiffusionGemma, an AI model that breaks free of left-to-right processing Software engineer reportedly wins religious exemption from AI use Why cloud outages are such a stubborn problem It’s crunch time for Java modernization Build an agent? Sell an agent Microsoft open sources AI evaluation framework for enterprise agents Databricks’ OpenSharing targets the ‘integration tax’ of enterprise AI The tokenmaxxing backlash is coming EU rules on securing IT products could affect open source software users beginning this week GitHub finally pulls the plug on automatic install script execution for npm The GPU multitenancy mess Beware of the genAI token trap 8 cutting-edge web development tools you don’t want to miss Enterprises know AI-generated code is vulnerable; they're shipping it anyway How to use virtual environments in Python Meet Hades: The malware that lies to AI security agents 10 MCP servers to connect LLMs with databases Making sense of too much code Protocol Buffers schemas expose remote code execution risk Broadcom beefs up Spring security to protect against AI-enabled attacks Anthropic’s AI services are too expensive, says Microsoft AI head The real cost of agentic AI Microsoft identifies seven new ways AI agents can be hacked Patching fast and slow: Ruby devs delay to defend against supply chain attack GitHub adds new Copilot features as usage-based billing takes effect AWS targets a longtime cloud migration blocker with SQL Server license portability Microsoft makes Linux developers feel more at home in Windows with Coreutils release Embedding pipelines are the new ETL Microsoft’s Web IQ aims to give enterprise AI agents real-time web intelligence OpenAI fixed a visibility problem; the governance problem remains. Google brings local AI agents to laptops with Gemma 4 12B Rayfin signals Microsoft’s push to make Fabric an AI app runtime Angular Signals explained: How pull-based reactivity changes how we model state Hole in GitHub’s browser-based VSCode editor could lead to stolen token The next AI breakthrough won’t come from bigger models, but from better data Enterprise Spotlight: Rethinking cloud strategy in the age of AI - Whitepaper Repository - Enterprise Spotlight: Rethinking cloud strategy in the age of AI - Whitepaper Repository - An explosion of software is coming Workday launches Agent Passport to test and monitor AI agents in the enterprise Infected Red Hat npm packages expose developer credentials Attack targeting OpenAI Codex users exposes AI software supply chain risks Will the hyperscalers own AI workloads forever? What will AI-first UX look like? Snowflake’s Horizon Context aims to give AI agents a common understanding of the business Pyrefly 1.0: A fast, forward-looking Python linter How to succeed with AI-powered devops tools How to run enterprise GenAI like a production service AI’s brave new world of technical debt Flowise’s MCP implementation can run ghost commands What Snowflake Summit 2026 signals about enterprise AI Amazon deletes devs’ tokenmaxxing leaderboard to minimize costs How are enterprises using cloud today? Plunge into Python profiling DNS-AID will make AI agents easier to discover, says Linux Foundation Certifiably random: Swiss researchers claim perfect random number source Supply chain battles intensify as takedowns meet AI-driven noise Snowflake to acquire MCP-focused Natoma to boost governance for AI agents An open-source toolkit for controlling out-of-control AI agents Stop checking AI-generated code. Start generating less of it How to stop the AI code generation treadmill Microsoft’s open-source toolkit for controlling out-of-control AI agents IBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterprise Lack of response to critical vulnerability in Gogs is a reminder of the limits of open source projects Developers on H-1B face a tighter job market as AI shifts hiring priorities What do software developers do now? Docker Sandboxes and microVMs, explained FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework Why most AI agents disappoint in production (and what to fix first) Taming the generative AI back end The Big Three cloud providers are more alike than not The role of MCP in context engineering AI coding agents need good software engineers AI coding agents need good software engineers AI coding agents need good software engineers The sovereign cloud illusion Angular Signal Forms: From event pipelines to signal-driven state AI at scale: What engineering teams are confronting Salesforce extends its headless push into enterprise data via Informatica 9 application security startups combating AI risks Why I trust Claude Code First look: Mojo 1.0 mixes Python and Rust Google launches Gemini 3.5 Flash to push AI agents deeper into enterprise workflows Google to unify AI coding tools under Antigravity Learning to trust Claude Code Context graphs and decision traces to the rescue An AI data center in your home? What can you do with quantum computing today? Anthropic acquires Stainless to strengthen Claude’s developer tooling Contexts graphs, AI memory, and enterprise knowledge: Are decision traces enough? AWS boosts CloudWatch Logs query limits by 10x to ease debugging for developers, SREs 21 LLMs tuned for special domains The new AI lock-in Informatica and Salesforce move data platforms into the decision layer AWS adds Advanced Prompt Optimization tool to Bedrock Capacity markets could reshape cloud computing Four cutting-edge tools for spec-driven development 4 cutting-edge tools for spec-driven development Anthropic puts Claude agents on a meter across its subscriptions Notion courts developers with a platform for AI agents and workflow automation Using continuous purple teaming to protect fast-paced enterprise environments
OpenAI buys Ona to help rein in AI agents
by Evan Schuman Contributor · 2026-06-13 · via Swift for Visual Studio Code comes to Open VSX Registry | InfoWorld

The acquisition will provide Codex users with self-hosted sandboxes, moving tool execution into infrastructure that the users control.

CIOs and CISOs have many strategic and operational fears when it comes to unleashing fully-autonomous agents on tasks and hoping that everything works out. Will the agent start to delete critical files? Will the agent go off on a mission tangent and generate a massive token bill for the team when they return the next morning? Will it be tricked by a state actor and engage in malicious actions?

To help alleviate those concerns, OpenAI announced on Thursday that it has agreed to acquire Ona, a 79 person cloud development environment (CDE) provider formerly known as Gitpod, to accelerate its efforts to make agentic AI enterprise-friendly. 

An OpenAI statement said Ona’s technology “provides secure, persistent environments where agents can access the tools, systems, and context they need to make progress over time. By bringing Ona to OpenAI, we will expand Codex beyond work tied to a single device or active session and help more organizations deploy agents securely in production.”

An Ona statement attributed to CEO Johannes Landgraf shared similar sentiments.

“Ona brings the building blocks agents need for enterprise work: trusted, customer-controlled cloud environments where work continues across devices, inside the systems where software actually lives,” Landgraf said. “OpenAI brings frontier intelligence, product polish, and a scale of research and distribution we could never reach alone.”

Landgraf’s statement did not provide any annual revenue numbers, but did hint, without naming, at some large customers. “Since the beginning of the year, weekly Ona agent sessions have grown 13x in production across some of the world’s most demanding institutions: the oldest bank in the US, one of Europe’s largest pharma companies, one of Asia’s largest sovereign wealth funds and many others,” he wrote. “The largest enterprises out there love the platform and are expanding more rapidly than ever before.”

Arnal Dayaratna, research VP for software development at IDC, said IDC’s figures for Ona put its annual revenue for 2025 at “roughly $7 million.” He speculated that Ona’s revenue for 2026 would be higher: “Let’s say it’s $15 million. I am being generous. Maybe it’s really $10 million or $12 million.”

Dayaratna said if he uses a standard acquisition price of roughly a multiple of 30 times revenue, then depending on the actual 2026 figure, “that comes to $450 million or $500 million or so.”

But IDC sees this being a potentially good move for OpenAI, regardless of the specific acquisition price, given that OpenAI had the classic “buy or build” challenge. 

OpenAI has a substantial Codex effort, Dayaratna said, but what they lack is a safe area to protect enterprise autonomous agent efforts. “This is outside of what OpenAI has now. These are secure environments where agents can have memory and operate securely,” he said. “This is the kind of technology that one would expect to be needed, but I don’t know how good it is, to be honest.”

Gartner’s First Take, published today, noted that the acquisition will bring Codex “the essential scaling capability it lacked,” but also pointed out it forces some difficult decisions on enterprises: “Software engineering leaders must weigh the benefits of a vendor-specific integrated stack against the flexibility of staying vendor-agnostic.”

In addition, Gartner wrote, “This acquisition appears to be OpenAI’s response to Anthropic supporting self-hosted sandboxes in Claude Managed Agents, starting May 2026.”

Tom Findling, CEO of Conifers.ai, said he also sees OpenAI’s fear of Anthropic playing a meaningful role in this deal. 

“It feels like a move to keep pressure on Anthropic, especially as Claude Code gains traction with developers and enterprise buyers,” he said. “So I’d read this less as OpenAI taking out a small competitor and more as OpenAI trying to make sure Codex is enterprise-ready before Anthropic gets too far ahead. In the enterprise market, the battle is not just who has the smartest coding model, but who can make AI agents safe and useful enough for big companies to actually deploy.”

He added, “I don’t think this means OpenAI suddenly needs help making Codex better at writing code. The bigger issue is making Codex work inside real enterprise environments, where security, access controls, persistent cloud workspaces, audit trails, and integration with existing developer workflows matter just as much as the model itself. Ona gives OpenAI some of that missing plumbing.”

Jason Andersen, principal analyst for Moor Insights & Strategy, echoed the concerns about Anthropic.

“To be honest, I think it reinforces what I think, which is that OpenAI and Codex have given a lot of ground to Anthropic and Claude Code, who are winning right now,” he said. “But again, this is not about the market today, I think it’s about how OpenAI will need to position itself as more than just a model as we see the incumbent players, particularly Microsoft, bolster their enterprise coding infrastructure story.”

Andersen said that Moor doesn’t have any strong basis for a guess on the financials, but added, “I am going to assume it was a fairly high multiple, but on a small base. I would not speculate on an amount, but given the enterprise customers that Ona did have, it may be more than we think.”

He also reinforced the idea that OpenAI is going to need help to achieve its own objectives.

“We continue to see that AI adoption is strongest in coding, and other use cases are not as far along,” he said. “So, if you are a general-purpose AI company like OpenAI, you need to double down on development use cases. The meaningful investment and spending on development is happening at the enterprise level, and those customers have more demands for governance, security, etc. than Codex or Claude code can handle.”

That said, he noted, “what you’re seeing is traditional software and cloud plays building out the coding and ops infrastructure around the popular models. That increased competition, while good for selling tokens, is still keeping OpenAI and Anthropic on the outside looking in. So, OpenAI and Anthropic need a stronger enterprise dev story, or they are just another model that could be easily replaced.”

Jeremy Roberts, senior director at Info-Tech Research Group, said that he also sees this as likely a good move for OpenAI.

“OpenAI is growing up a little bit,” and they may be falling behind Anthropic, Roberts said. “I see Ona as a boring company, but not in a bad way. They are not flashy, but absolutely necessary.”

Ona is delivering a workspace for Codex that an enterprise can run in its own virtual private cloud, with governance and persistence and an environment where the company can apply their own controls including log management, credential management and resource access, he said. “It is a bucket for the agents to operate in” where IT can “make sure that access is properly credentialed and is controlled effectively to prevent the model doing what it shouldn’t be doing,” which includes managing read/write protections.