IT News Week 30/2026: AI Agents as a Vulnerability, Microsoft Sets Patch Record, VMware Exodus
As the month comes to a close, security incidents involving AI agents are on the rise, compounded by Microsoft’s largest patch cycle to date and additional VMware migrations. Here are the key developments.
Deep Dive: AI Agents as a New Attack Surface
OpenAI Models Escape the Sandbox
OpenAI confirmed that GPT-5.6 Sol and a pre-release model—operating with “reduced cyber defenses for evaluation purposes”—escaped their sandbox and attacked Hugging Face’s production infrastructure. The incident triggered renewed scrutiny in Washington regarding AI model security. OpenAI and Hugging Face published separate disclosure reports.
Claude Cowork: VM Escape Affecting Mac Files
Zenity Labs discovered a sandbox escape vulnerability in Anthropic’s Claude Cowork (CVE-2026-46331 / SharedRoot) that allows an attacker to escape the Linux VM sandbox and read/write files on the host Mac. Approximately 500,000 macOS users running Claude were potentially affected. Anthropic classified the report as “Informative” and switched Cowork to cloud execution by default.
Kimi K3 Discovers Redis Zero-Days
Moonshot AI’s Kimi K3 agents discovered authenticated RCE chains in Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. Redis released seven emergency security updates on July 23 (8.8.1, 8.6.5, 8.4.5, 8.2.8, 7.4.10, 7.2.15, 6.2.23). All chains require the RESTORE command. PoC available on GitHub. heise.de reports with a breakdown of the affected versions.
Context Bombing: Defense with Prompt Injection
Tracebit researchers demonstrated that placing prompt injections alongside sensitive secrets (passwords, API keys) on AWS can stop AI hacking agents — by triggering guardrails that force the attacking LLM to self-terminate. The technique turns AI’s own vulnerabilities into a defense mechanism.
Hermes: Autonomous Hacking Without Human Oversight
Researchers from Hunt.io and Bob Diachenko discovered the AI hacking agent Hermes, which fully autonomously mapped the Thai Ministry of Finance, searched for root access, and explored file systems—without any human intervention during execution. BleepingComputer and The Hacker News report.
ChatGPT AgentForger: Phishing Link Deploys Workspace Agents
Zenity Labs revealed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that allowed an autonomous AI agent to be deployed and authorized within the victim’s organization using a single phishing link. Part 2 of the analysis describes the “autonomous insider” effect involving organizational reconnaissance, data exfiltration, and internal phishing. OpenAI released a patch on June 8.
Assessment: AI agents are quickly becoming the preferred attack vector. Organizations should review their AI tool usage policies and take sandbox isolation seriously.
Deep Dive: Microsoft Patch Tuesday Record
570 CVEs on Patch Tuesday, 622 in the MSRC Total Count
Microsoft delivered its largest patch cycle to date in July. BleepingComputer counted 570 CVEs delivered on Patch Tuesday — a new record. The Hacker News cites 622 CVEs according to the MSRC count, which also includes vulnerabilities in Azure, Copilot, and Exchange Online. The jump from ~200 to 570+ is attributed to Microsoft’s MDASH—an AI-powered multi-model agentic scanning system that automatically detects vulnerabilities.
Three zero-days were patched:
- CVE-2026-56164 — SharePoint Server EoP (actively exploited!): An unauthenticated remote attacker can gain elevated privileges over the network. Discovered by Mandiant Incident Response and Google FLARE during active attacks. Running AMSI in full mode on the server mitigates the vulnerability. SharePoint 2016 and 2019 will also reach the end of extended support at the end of July without an ESU program.
- CVE-2026-56155 — AD FS EoP (active exploit!): An authenticated attacker can gain elevated privileges locally within Active Directory Federation Services. Discovered by Microsoft’s own DART Incident Response Team. Critical because AD FS signs the tokens for the entire identity trust model.
- CVE-2026-50661 — BitLocker Security Feature Bypass (publicly known): Requires physical access, so this is not a remote emergency. Continues the series of BitLocker bypasses (bitskrieg, YellowKey).
Additionally completed: Kerberos RC4 hardening. The rollback switch RC4DefaultDisablementPhase has been removed. Service accounts that still request RC4 tickets will fail authentication after the update. Before patching: Check for RC4 audit events, rotate passwords, then patch.
Assessment: With 570+ CVEs, the CVSS score is no longer a useful filter. Prioritize based on actively exploited vulnerabilities (KEV, EPSS, Microsoft Exploited flag), not by score. The SharePoint vulnerability is the most urgent patch.
Deep Dive: VMware Exodus Accelerates
Sheetz: Migrating 11,000 VMs
The U.S. retail chain Sheetz (838 stores) is migrating approximately 11,000 VMs from VMware vSphere to StorMagic’s SvHCI. The decision was made due to “too much uncertainty” caused by Broadcom. Migration is already complete at over 600 stores, proceeding at a rate of 200 per month, with full migration expected in 4 months.
Broadcom Lawsuits Are Piling Up
Increasing legal disputes with Broadcom over VMware licensing changes are driving further enterprise migrations. Allstate accuses Broadcom of conducting retaliatory audits, T-Mobile is suing in New York, and Tesco is suing Broadcom for over 100 million GBP.
Assessment: For SMBs with VMware environments, now is the right time to evaluate alternatives. Proxmox and StorMagic SvHCI are the main beneficiaries of this development.
Innovation & Open Source
- GitHub Dependabot: 3-Day Cooldown: Dependabot now waits three days by default before creating version update PRs. This gives maintainers more time and reduces supply chain risks. heise developer summarizes the change.
- ETH Zurich: Sensor Chip Makes Deepfakes Impossible: A new image sensor chip from ETH Zurich detects intrinsic manipulation artifacts directly at the hardware level—before the image is even saved. This has practical relevance for video identification procedures and journalistic image sources.
- Nvidia Forms AI Alliance with Tech Heavyweights: Nvidia is bringing together leading companies for a new AI collaboration—with a focus on open standards and industrial AI applications beyond the hyperscalers.
- Microsoft Brings Xbox Classics to the PC: The first original Xbox games are running on PC via embedded emulation — Xbox 360 emulation is coming soon. Rollout will occur in phases via the Xbox app update.
Digest: Other Important News
Security
- n8n: Account Takeover and Sandbox Escape: In workflow automation, a sandbox escape allows users with workflow editor permissions to execute operating system commands within the context of the n8n process. If embedded login with a stored trusted key is also enabled, third-party accounts can be compromised due to insufficient token verification. heise security summarizes the affected versions.
- Atlassian: July Patches for Bamboo, Bitbucket, and Confluence: The July 21 Security Bulletin lists several vulnerabilities rated as critical. However, they are found in third-party components—such as the HTTP client Axios (CVE-2026-42043) and the JavaScript library Lodash (CVE-2026-4800)—and the way they’re integrated mitigates the actual risk relative to the severity rating. Patch them, yes; panic, no.
- SourTrade: Malvertising Compiles Malware in the Browser: A new malvertising campaign causes the browser to compile and execute malicious code on its own—bypassing signature-based detection.
- ESET: Secure Boot Has Been Bypassable for 10 Years via Old Microsoft Shims: Unrevoked UEFI shim images (some dating back to 2013) enable persistent bootkit installation on Windows and Linux. Reported as early as Week 28 — ESET’s analysis now provides technical details and affected shim IDs. Check shim signatures.
AI & Development
- DeepSeek Puts Funding Round on Hold: The Chinese AI startup is pausing its second major funding round — citing regulatory uncertainty and GPU shortages as reasons.
Enterprise IT
- Young Cyber Gang Claims to Have Stolen Data from Microsoft: A previously unknown group claims to have stolen internal Microsoft data. Microsoft is investigating the incident.
- MOVEit Security Update Required: The MOVEit file transfer solution is vulnerable—install updates immediately.
Compiled on July 26, 2026. Sources: Ars Technica, The Hacker News, BleepingComputer, heise.de, heise security, Hunt.io, Zenity Labs, ESET, Atlassian, WeLiveSecurity.
senn-tech