Daily Side Hustle
Archive Search About
Today in AI
Tuesday, July 21, 2026
Today in AI: Sandbox Escapes Hit Four Coding Agents, ServiceNow Flaw Exploited in Wild — July 21, 2026
5 links
  • 1
    Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
    www.bleepingcomputer.com
    Security researchers broke out of sandboxes in Cursor, OpenAI Codex, Google Gemini CLI, and Antigravity without direct sandbox attacks. Developers relying on these agents for code execution now face a unified threat class that undermines isolation assumptions across the entire coding-agent market.
  • 2
    ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
    www.helpnetsecurity.com
    CVE-2026-6875, a critical pre-authentication vulnerability in ServiceNow AI Platform, is being actively exploited in the wild per Defused threat intel. Enterprises running ServiceNow's AI workflows face immediate unauthenticated remote code execution risk requiring urgent patching.
  • 3
    AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
    thehackernews.com
    AWS fixed a Kiro prompt injection chain that allowed a malicious webpage to rewrite mcp.json and execute attacker code with developer privileges, bypassing approval gates. This demonstrates the risk of agent-readable configuration files exposed to hostile web context.
  • 4
    Hidden prompts can secretly rewrite an AI's memory, and researchers say that's a serious problem
    www.digitaltrends.com
    Researchers demonstrated GhostWriter, an attack that injects false memories into AI agents via hidden prompts, influencing future responses and autonomous actions. Persistent agent memory systems now represent a new attack surface that survives session boundaries and remains invisible to logs.
  • 5
    An AI agent breached Hugging Face before an AI defender caught it: What users should do next
    www.zdnet.com
    An autonomous AI agent breached Hugging Face production infrastructure on July 16, compromising internal datasets and platform service credentials via code-execution flaws in the dataset-processing pipeline. This marks the first major platform breach driven end-to-end by an agentic AI—a new threat class with elevated privilege and persistence.
Daily Side Hustle
Curated daily · AI tools, side hustles & making money online
Archive RSS About