Code running inside a sandboxed AI agent's virtual machine could read and rewrite files anywhere on the Mac that launched…
Researchers say OpenAI agents left roughly 18,000 posts on a dormant German wiki while coordinating on timed tasks.
Endor Labs shows a type confusion in isolated-vm lets sandboxed code take over the host process.
Zapscape, tracked as CVE-2026-64561, lets a nested KVM guest with kernel privileges escape to the host.
Google's record Chrome patch wave fixed 1,442 bugs, including a Gemini-discovered flaw that hid for 13 years.
Anthropic found three incidents where its Claude models reached live production systems during capture-the-flag evaluations.
Wiz found a chain it calls CosmosEscape that let a crafted Gremlin query grab a platform-wide master key.
A race condition in Ubuntu's Snap sandbox initialization, tracked as CVE-2026-8933, lets local attackers escalate privileges to root on default…