LIVE FEED
Trail of Bits Ships Coop: Isolated VMs for Claude Code and Codex

Trail of Bits Ships Coop: Isolated VMs for Claude Code and Codex

FIRST LOOK ATLAS OWASP LOW Limited impact · Standard review ▲ 7.2 Anthropic (via HN)

Trail of Bits has released Coop, an open-source Rust CLI that provisions disposable, isolated virtual machines for running Claude Code and OpenAI Codex with full tool access — including Docker, git, compilers, and package managers — without exposing the host system. This directly closes the containment gap that has made agentic AI coding assistants a liability in developer environments, giving security teams a reproducible boundary between autonomous AI tool execution and production infrastructure. What remains unaddressed is broader multi-provider coverage, enterprise policy enforcement, and centralised audit logging maturity needed before this is ready for regulated-environment deployment at scale.

CVE-2026-75149: Marimo Notebook MCP Code Injection Flaw

CVE-2026-75149: Marimo Notebook MCP Code Injection Flaw

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.2 The Hacker News

A high-severity code injection vulnerability (CVE-2026-75149) in Marimo notebook software allowed attackers to embed malicious Model Context Protocol (MCP) server commands in crafted notebooks, triggering local subprocess execution before any user cell runs. The flaw, scoring 8.8 on CVSS v3.1, required no attacker authentication and only needed the victim to open the notebook in edit mode. Marimo patched the issue in version 0.23.15 by treating all notebook metadata as attacker-controlled and enforcing an allowlist over configuration sections including AI, MCP, and secrets.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.