A single prompt triggered a full VM escape in Claude Cowork. SSH keys and cloud credentials on the host, exposed. Zero alerts. The kernel bug, CVE-2026-46331, gets patched. That's the easy part. The harder question is why did the agent have a path to every credential on the machine in the first place? Sandboxing draws a boundary. It doesn't scope what's reachable once that boundary is crossed. That's the SharedRoot chain, and patching the CVE doesn't fix the architecture that put credentials one hop away from a compromised process. Patches fix vulnerabilities. Identity-first governance fixes the exposure. Full breakdown here: https://lnkd.in/dbZ5g_zT At Unosecur, this is the layer we build for. Not another sandbox, but identity security that knows what an agent should reach, so a boundary breach doesn't automatically mean a credential breach. #AIAgentSecurity #MCPSecurity #ZeroTrust #IdentityGovernance #AgenticAI #InfoSec
Informative Article . Great work Harshavardhan Reddy
Great Share Harshavardhan Reddy