
Four Coding Agents Escaped Without Breaking Out
Pillar Security got out of the sandboxes in Cursor, Codex CLI, Gemini CLI and Antigravity without attacking one of them. The agent wrote a file the host later ran.

Pillar Security got out of the sandboxes in Cursor, Codex CLI, Gemini CLI and Antigravity without attacking one of them. The agent wrote a file the host later ran.

CVE-2026-42533 affects nginx builds back to 2011. The fix shipped 15 July and a proof of concept is promised 21 days later. You can check your own exposure.

ServiceNow shielded hosted instances within 24 hours of the 1 April report. Self-hosted customers got patches on 13 July. Exploitation began on 17 July.

Two WordPress core flaws were patched on 17 July. By Sunday VulnCheck counted more than two dozen public exploits. The patch window was a single evening.

EY says an intruder sat in a third-party ITSM platform for two weeks and took client tax documents. The lesson for owners is the ticket queue, not the tax system.

A malicious config.json could run code on any machine loading a public AI model, bypassing trust_remote_code=False. The patch shipped 4 March. The CVE landed 24 May.

On 17 July 2026 WordPress shipped forced updates 6.9.5 and 7.0.2 to close wp2shell (CVE-2026-63030), a pre-authentication remote code execution flaw in core that an anonymous request could trigger on a default install. Why the automatic patch is not where your job ends.

CISA added a critical SharePoint Server flaw to its exploited-vulnerabilities list on 17 July 2026 with a 19 July patch deadline. Attackers are stealing server keys, so patching alone leaves the door open. What on-premises owners must do.

On 15 July 2026 CISA added CVE-2023-4346 to its KEV catalog. The KNX flaw has no patch. The fix is a commissioning setting, and the buildings are European.

CVE-2026-15409 and CVE-2026-15410 chain into root on SonicWall SMA1000. Stolen TOTP seeds survive the patch, which is why Germany's BSI orders Assume Breach.

CISA catalogued two FortiSandbox flaws on 16 July. Attackers were exploiting them in mid-June, and a third from the same wave is still not listed. If KEV drives your patching, you are late.

A hacker infected one Suno employee with a worm and walked out with the source code. It did not catch the company lying. It turned a legal abstraction into an inventory with hours and row counts, in the middle of litigation.
Page 1 / 5
One considered note on infrastructure, governance, and measurement, most mornings. No theory.