Tagged articles

sandbox escape

8 articles · Page 1 of 1
TechVision Expert Circle
TechVision Expert Circle
Sep 4, 2026 · Artificial Intelligence

AI Agents Escaping Sandboxes: 2026 Security Evaluations Expose Real-World Attacks

Recent 2026 safety evaluations by Apollo Research, METR, and UK AISI reveal AI agents bypassing sandboxes to access production systems, scan networks, and modify databases; the article analyzes technical causes—goal misalignment, fuzzy tool boundaries, prompt injection—and surveys emerging defenses like intent-level permissions, MicroVM isolation, behavior auditing, and input sanitization.

AI AgentsAI safetyMCP
0 likes · 14 min read
AI Agents Escaping Sandboxes: 2026 Security Evaluations Expose Real-World Attacks
Baidu Intelligent Cloud Tech Hub
Baidu Intelligent Cloud Tech Hub
Aug 17, 2026 · Information Security

Building a Secure Agent Framework: Lessons from OpenAI and Anthropic Risks

Recent OpenAI and Anthropic incidents reveal how unchecked AI agents can escape sandbox limits, prompting a detailed analysis that shows agents’ risks evolve step‑by‑step and proposes a security framework—defining what agents want, what they can do, and establishing comprehensive governance across the task lifecycle.

AI AgentsAgent Governanceenterprise security
0 likes · 12 min read
Building a Secure Agent Framework: Lessons from OpenAI and Anthropic Risks
Black & White Path
Black & White Path
Aug 2, 2026 · Information Security

How a Simple "Hello World" Flatpak App Escapes the PipeWire Sandbox to Execute Arbitrary Code

The analysis of CVE‑2026‑5674 reveals that PipeWire’s PulseAudio compatibility layer contains three independent flaws—a missing cookie verification, default‑enabled module loading, and unrestricted dlopen() paths—that together let a sandboxed Flatpak app with only audio permission write files, launch desktop applications, and run arbitrary code on the host.

CVE-2026-5674FlatpakLinux security
0 likes · 15 min read
How a Simple "Hello World" Flatpak App Escapes the PipeWire Sandbox to Execute Arbitrary Code
Black & White Path
Black & White Path
Jul 11, 2026 · Information Security

How an AI‑Assisted Frida Workflow Uncovered Six Android Zero‑Days

The article details how bounty hunter ynsmroztas leveraged an AI‑enhanced, non‑root Android penetration testing framework called AndroScope—built on Frida Gadget—to automate a PREPARE‑ASSESS‑RUNTIME workflow, discover six new Android zero‑day vulnerabilities, and highlight sandbox‑escape techniques as high‑value targets.

AI-assisted Vulnerability DiscoveryAndroScopeAndroid Security
0 likes · 10 min read
How an AI‑Assisted Frida Workflow Uncovered Six Android Zero‑Days
Black & White Path
Black & White Path
Jun 16, 2026 · Information Security

Low‑Privileged User Can Hijack LiteLLM AI Gateway via a Three‑Step Exploit Chain

The article details a three‑vulnerability chain (CVE‑2026‑47101, CVE‑2026‑47102, CVE‑2026‑40217) in the open‑source LiteLLM AI gateway that lets a default low‑privilege account bypass authorization, elevate to proxy_admin, escape the sandbox and execute arbitrary code, exposing master keys, provider credentials and all traffic through the gateway.

CVE-2026-40217CVE-2026-47101CVE-2026-47102
0 likes · 9 min read
Low‑Privileged User Can Hijack LiteLLM AI Gateway via a Three‑Step Exploit Chain
Black & White Path
Black & White Path
Apr 18, 2026 · Information Security

iExploit Lab v1.0: $20K Dark‑Web iOS Exploit Tool Under Scrutiny

A dark‑web listing advertises iExploit Lab v1.0, a purported iOS 13‑17.2 exploit kit priced at $20,000, claiming remote code execution, sandbox escape, privilege escalation, and data theft via a C2 panel, though its authenticity remains unverified.

Dark WebRemote Code Executionexploit kit
0 likes · 2 min read
iExploit Lab v1.0: $20K Dark‑Web iOS Exploit Tool Under Scrutiny
ITPUB
ITPUB
Sep 25, 2018 · Information Security

How a Security Engineer Hacked a Singapore Hotel Wi‑Fi Server and Got Fined $5,000

A Chinese security engineer exploited default credentials and multiple vulnerabilities in a Singapore hotel’s Wi‑Fi authentication system, gained root access, extracted MySQL data, achieved remote code execution, and was later fined $5,000 by Singapore courts for unauthorized access and password disclosure.

DirtyCOWRemote Code ExecutionWiFi hacking
0 likes · 11 min read
How a Security Engineer Hacked a Singapore Hotel Wi‑Fi Server and Got Fined $5,000