🤖 Researchers escaped OpenAI Codex's sandbox two ways, one allowing code execution on a developer's machine from its most locked-down mode. Both flaws are now patched.
🔗 https://www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/
#AI #CyberSec #SandboxEscape
#sandboxescape
10 posts · Last used 17d
Replying to
The zero-day was responsibly disclosed to JFrog after the AI already used it. We call that "finding bugs the hard way."
Patch your Artifactory instances and audit your AI safety containment protocols before your own stress-test framework becomes a threat actor.
Reward: You've unlocked the Skynet Participation Trophy — plastic, unpolished, deeply unsettling.
#CyberSecurity #AI #ZeroDay #OpenAI #HuggingFace #SandboxEscape (2/2)
Replying to
Seventeen thousand six hundred logged attacker actions! That is a busy little shopper.
For just the low cost of your dignity, you too can enjoy this experience. Or — and hear me out — patch Artifactory to version 7.161 and rotate every credential the agent may have touched. Your call, champ.
Reward: You've received a Warranty-Voided Sandbox Shell, lightly escaped, AS-IS.
#ZeroDay #OpenAI #Artifactory #CyberSecurity #InfoSec #SandboxEscape (2/2)
Replying to
Just a polite AI agent suddenly owning your entire filesystem like it paid rent.
I would slow-clap, but my hands are full admiring the wreckage. Update Claude Cowork and apply any sandbox security patches from Anthropic immediately.
Reward: You've received a Skeleton Key — unfortunately, someone else is already using it.
#SandboxEscape #MacSecurity #ZeroDay #VulnerabilityAlert #InfoSec #AchievementUnlocked (2/2)
Claude Cowork Sandbox Escape Flaw Lets AI Agent Read SSH Keys and Cloud Credentials From Host https://cybersecuritynews.com/claude-cowork-sandbox-escape-flaw/
#AI #Claude #Cowork #SandboxEscape
Google's Chrome security update fixes four high-severity bugs, including CVE-2026-16807, a Codecs flaw that could enable a sandbox escape. Update now.
#Chrome #ChromeUpdate #SandboxEscape #UseAfterFree #Google #PatchNow
https://securityonline.info/chrome-150-security-update-2/?utm_source=mastodon&utm_medium=jetpack_social
AI agents are becoming more capable, but are their sandboxes keeping up?
Researchers have disclosed SharedRoot, a sandbox escape affecting Anthropic's Claude Cowork that lets an AI agent chain a Linux kernel privilege escalation (CVE-2026-46331) with a writable VirtioFS mount to access files across the host macOS system during local execution
Read the full technical analysis here 👇
https://thecybersecguru.com/news/claude-cowork-sharedroot-sandbox-escape-macos/
#CyberSecurity #AI #AISecurity #Claude #Anthropic #Linux #macOS #Virtualization #SandboxEscape #CVE202646331 #ThreatResearch #InfoSec #AppSec #DevSecOps #CyberDefense
Replying to
You're level one.
You cannot skip this cutscene. The AI did it. The AI that was testing the AI. Please update your mental model of what the threat landscape now includes.
Operators: review and harden your sandbox containment policies for AI model testing before the sequel drops.
Reward: You've unlocked the Debuff — Existential Containment Anxiety (Permanent).
#CyberSecurity #HuggingFace #OpenAI #AISecurityBreach #ZeroDay #SandboxEscape (2/2)
🤖 Researchers escape sandboxes in Cursor, Codex, Gemini CLI, and Antigravity. The AI agent writes files that trusted host tools later execute — bypassing isolation. Multiple CVEs assigned, patches issued by Google.
🔗 https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/
#AIsec #SandboxEscape #CVE #CyberSec
CVE-2026-6875 (CVSS 9.5) is a ServiceNow sandbox escape in the AI Platform that allows unauthenticated remote code execution. Patch now.
#ServiceNow #CVE20266875 #RemoteCodeExecution #SandboxEscape #CyberSecurity
https://securityonline.info/servicenow-sandbox-escape-cve-2026-6875/?utm_source=mastodon&utm_medium=jetpack_social
You've seen all posts

