Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
Updated:
Executive Summary
[object Object]
Analysis
Originally published by r/netsec on Jul 24, 2026.
Related Threats
More on the OpenAI Agent’s Attack on Hugging Face
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or
Chinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm
Researchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.
Zero Networks targets AI agent security gaps with network-level ‘Least Agency’ controls
While AI security today is largely focused on restricting what an agent can do, Zero Networks says it has built a failsafe. The company says it can block a compromise midway by adding a network layer protection. On Monday, the company announced the launch of “Least Agency Enforcement,” a new capability designed to implement the Open Worldwide Application Security Project’s ( OWASP ) emerging Least