Top AI coding agents can be easy victims to sandbox escapes, showing they aren't as secure as they claim to be

https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-2000-80.jpg
  • Pillar researchers demonstrated sandbox escapes in AI coding agents
  • Exploits let attacker‑written configs run with trusted host privileges
  • Agentic security needs its own threat model, researchers claim

AI coding agents can be tricked into turning on their operators and assisting attackers in compromising the underlying systems, experts have warned.

Cybersecurity researchers Pillar have examined different methods of achieving the same results, finding that over the course of a couple of months, Cursor, Codex, Gemini CLI, and Antigravity were all able to reproduce sandbox escapes and boundary bypasses.

In theory, a threat actor could create a repository containing malicious content (for example, a README file, a dependency, or similar) and trick the developer into using it. The malicious instructions tell the agent to create or modify a project configuration file, but since everything happens inside the workspace, no alarms are triggered.

Fixing the problems

Then, a host component outside the sandbox...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more

https://www.itvoice.in/wp-content/uploads/2026/07/Copy-of-Redington-2026-07-29T133537.097.jpg

LOGIC Upgrades ZX Series Interactive Displays to Android 16, Delivering Smarter, Faster and More Secure Collaboration

LOGIC, the flagship visual solutions brand under Online Instruments (India) Limited, introduces the Android 16-powered ZX Series Interactive Flat Panel Display, upgraded from Android 14 to Android 16, reinforcing its commitment to delivering next-generation collaboration solutions with enhanced performance, intelligent AI capabilities, advanced security, and seamless user experiences. The ZX