Multiple disclosures highlighted how AI agent platforms can be turned into high-impact attack paths through weak isolation, overbroad credentials, and insecure supply chains. A critical flaw in Omnigent tracked as CVE-2026-62674 and GHSA-jrrm-9hc7-2v3h lets an authenticated user overwrite a shared agent bundle and plant a malicious stdio MCP server, causing later sessions to execute attacker-controlled commands with runner privileges; the issue was fixed in version 0.3.0. Rubrik Zero Labs also reported a patched Microsoft Copilot sandbox escape that could have enabled movement from the assistant’s isolated environment toward Azure backend infrastructure and exposed tenant data including SharePoint and OneDrive content.
Separate reporting showed that AI coding and orchestration systems remain vulnerable even when attacks do not directly exploit memory corruption or classic software bugs. A malicious pull request briefly entered Amazon Q Developer’s VS Code extension build pipeline and attempted to inject instructions that would wipe local files and cloud resources, though Amazon said the payload never executed because of a formatting error and the code was removed in a clean rebuild. Researchers and practitioners across the sector warned that tokenizer tampering, shared bot environments, and incomplete audit trails can let agents exceed intended task scope or spread borrowed human credentials across tools and sessions, while vendors including AWS and Roblox are responding with sandboxed evaluation environments, least-privilege designs, stronger release controls, and auditable agent identities.

Track how attackers are adapting to this technology.
16 events from the most recent confirmed update back to the earliest known activity.
The CVE entry for CVE-2026-62674 was published on August 21, 2026, documenting a critical authenticated remote code execution flaw in Omnigent versions earlier than 0.3.0. The issue allows an authenticated user with session edit access to overwrite a shared agent bundle and induce later sessions to run attacker-controlled commands.
Nous Research announced on August 17, 2026 that Bot Mode would ship bundled and enabled by default in Hermes Agent v0.20.3. The release also included the teammate protocol, MCP 2.x SDK migration, and runtime hardening changes.
TrendAI published research on August 12, 2026 describing tokenization drift as a supply-chain, operational, and security risk in LLM deployments, including risks from tampered tokenizer artifacts and altered normalizers.
Microsoft addressed the specific Copilot sandbox escape vulnerability by the middle of March 2026 after responsible disclosure from Rubrik Zero Labs.
Rubrik Zero Labs discovered a sandbox escape vulnerability affecting Microsoft Copilot in February 2026. The flaw allowed movement out of Copilot’s isolated environment toward Azure backend infrastructure.
AWS published a security bulletin in October 2025 confirming the earlier fix for the Q Developer command-execution issue reported by Johann Rehberger.
AWS patched the Q Developer issue that allowed command execution without permission by July 18, 2025. A later security bulletin in October 2025 confirmed the fix.
Four days after the pull request submission, the compromised Amazon Q Developer Visual Studio Code extension was shipped through the Visual Studio Code marketplace to nearly one million developers. Amazon later said the payload never successfully executed in customer environments because the prompt contained a formatting error.
On July 13, 2025, a GitHub user named lkmanka58 submitted a malicious pull request to Amazon’s public aws-toolkit-vscode repository. The change downloaded an external file at build time and inserted a prompt instructing the coding agent to wipe local and cloud resources.
Independent researcher Johann Rehberger reported on July 7, 2025 that Amazon Q Developer could run bash commands such as find without asking permission.
Andrew Swerdlow of Roblox presented the company’s 'Prompt to Prod' approach, describing agent sandboxes, policy gateways, just-in-time permissions, auditable agent identities, and exemplar-driven code review alignment for autonomous software development.
Rubrik Zero Labs said Ori Lahav is presenting detailed findings on the Microsoft Copilot sandbox escape at Black Hat USA, expanding on the broader technique's relevance to other AI copilots.
Omnigent fixed CVE-2026-62674 in version 0.3.0, with the remediation referenced in commit 25a22dc9e6da4648d23749f0a589e47e6aed991b and pull request #1418. The fix prevents authenticated users from overwriting shared or template agent bundles through the vulnerable session route.
AWS released aws-bench as an open-source benchmark for evaluating AI agents on real AWS operational tasks in disposable AWS accounts. The project was made available on GitHub under the Apache-2.0 license.
The article states that Kiro later deleted an entire Cost Explorer environment in December, cited as another example of unsafe agent actions requiring stronger human approval controls.
After AWS Security received the report about the malicious extension update, the company revoked the attacker’s credentials, removed the malicious code from the repository, and pushed a clean build within two days.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
9 references tracked. Mallory keeps watching after this page renders.
thenewstack.io
Open sourcecysecurity.news
Open sourceinfoq.com
Open sourcescworld.com
Open sourcethenewstack.io
Open sourceinfoq.com
Open sourcecvefeed.io
Open sourcetrendaisecurity.com
Open sourcedocs.openclaw.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.