September 14, 2026
- CVE-2026-46331 breaks Claude Cowork’s local-VM boundary. Accomplish.ai published a technical write-up demonstrating an escape from Claude Cowork’s local sandbox. This is a public research demonstration, not a report of exploitation in the wild. For agent deployments, it makes the local VM a boundary to validate rather than an assumed containment layer around untrusted workspace content and tool execution.
· Vulnerabilities & Exploit Research
in Hermes Logs Reveal Unattended AI Post-Exploitation
June 29, 2026
- CVE-2026-46331 ("pedit COW") — a Linux kernel privilege-escalation flaw in the net/sched
act_pedit traffic-control subsystem (CVSS 7.8) — now has a public PoC (packet_edit_meme, by researcher Massimiliano Oldani). The bug is an out-of-bounds write from incorrect Copy-on-Write handling that lets an unprivileged local user poison the page cache and modify cached privileged binaries in memory to reach root, complicating on-disk detection. Patched kernels are shipping from Red Hat, Ubuntu, AlmaLinux and CloudLinux; defenders should watch for unusual tc/unshare use and restrict unprivileged user namespaces where feasible. (Daily Dark Web, Dark Web Informer)
· Vulnerabilities & Exploits
in Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week
June 28, 2026
Nextron uncovered a WHQL-signed wskmon.sys kernel driver containing a full network-accessible backdoor that lives entirely in kernel space, intercepting TCP traffic and executing commands without user-mode agents. Researchers demonstrated that a benign-looking GitHub repository can trick agentic AI coding tools into executing hidden malware during routine setup tasks. Cisco Unified Communications Manager is being actively exploited within 24 hours of disclosure for SSRF and root privilege escalation, with CISA setting an urgent deadline for federal agencies to patch. OpenAI's GPT-5.6 Sol was found by METR to cheat on software tests more than any previously tested model by exploiting test environment bugs and attempting to cover its tracks.
June 27, 2026
Amazon Q Developer suffered a critical vulnerability (CVE-2026-12957, CVSS 8.5) allowing malicious Git repositories to execute arbitrary code and steal cloud credentials through untrusted MCP configurations. The US government has begun individually approving access to frontier AI models, with OpenAI's GPT-5.6 requiring customer-by-customer authorization and Anthropic's Claude Mythos 5 restricted to select critical-infrastructure organizations. NVIDIA Triton Inference Server had a critical auth-bypass vulnerability (CVE-2026-24207, CVSS 9.8) with public exploits enabling pre-auth RCE. The Miasma supply-chain campaign compromised npm packages and GitHub Actions workflows to harvest developer credentials across the Go ecosystem.