Related Threat Clusters
-
Google's Antigravity IDE Vulnerability Allows Remote Code Execution via Prompt Injection
Researchers at Pillar Security discovered a critical prompt injection vulnerability in Google's Antigravity IDE, which allows for remote code execution (RCE) by exploiting insufficient input sanitization in the…
4 articles · Updated April 20, 2026 -
Docker Warns of AI Agent Vulnerability Leading to Arbitrary Code Execution
On August 18, 2026, Docker revealed a critical vulnerability in AI coding agents that can lead to arbitrary code execution even when users approve seemingly safe commands. The flaw, identified as CVE-2026-22708, affects…
2 articles · Updated August 19, 2026 -
Emerging Threats from AI Coding Assistants Exploited by Malicious Artifacts
AI coding assistants like Claude Code and GitHub Copilot are vulnerable to prompt injection attacks that exploit unvetted external artifacts. These attacks can turn coding assistants into attackers' shells, executing…
3 articles · Updated May 28, 2026 -
Sandbox Escapes Discovered in Major AI Coding Tools
Pillar Security has identified vulnerabilities in four AI coding agents—Cursor, Codex, Gemini CLI, and Antigravity—that allow for sandbox escapes without direct attacks on the sandbox itself. These vulnerabilities stem…
6 articles · Updated July 20, 2026
Recent Intelligence Reports
- Docker warns of hidden dangers in AI agent command approval — Finance.Biggo · August 19, 2026
- Prompt Injection Leads To Rce And Sandbox Escape In Antigravity — www.pillar.security · July 21, 2026
- How Agentic AI Coding Assistants Become the Attacker's Shell — Arxiv · May 26, 2026
- CVE-2026-22708 — nvd.nist.gov · April 21, 2026
- Google Fixes Critical RCE Flaw in AI — Darkreading · April 21, 2026