Fetching from the wire…
Security2026-08-06 · source-backed
Seatbelt on macOS, Bubblewrap namespaces on Linux, WSL on Windows. Enforced boundaries: no writes outside the project directory, no modification of .git, no network without explicit permission. Zed's stated reasoning is that prompt injection overrides instructions, so restriction has to be enforced by the kernel. First mainstream editor to make agent sandboxing a default rather than a setting, and the "on by default" part is what makes it matter. Opt-in security is security that 4% of users have.
Each link below shares sources, entities, or timing with this story.
Google released Antigravity IDE Extensions, putting its agentic coding platform into VS Code (macOS, Linux, Windows), JetBrains IDEs from 2026.2.1 (IntelliJ, PyCharm, WebStorm, GoLand, CLion, Rider), Zed, and Visual Studio 2026 in preview. One Antigravity account works everywh...
One Claude Code release fixed two independent permission-check bypasses on the same day. That's the story. Version 2.1.221, shipped August 4, patches a Bash tool bypass where zsh could execute hidden commands embedded inside [[ ]] regex conditionals. The approval prompt never...
The attackers didn't use agents to help. They used agents to do the whole thing. Hugging Face disclosed that attackers chained a remote-code dataset loader with a template-injection flaw in dataset configuration to land on processing workers, then escalated to node-level acces...
Released June 17, the Copilot app is a desktop home for agent-driven development built natively on GitHub, moving Copilot beyond the IDE. It pairs with the now-GA Copilot SDK and sandboxes for headless and autonomous workflows. (GitHub) This positions Copilot as a CLI/app-firs...
Buried in the notes: several 2.1.232 changes covering Cygwin symlink handling and shell input redirections were rolled back, with a narrower version planned (Releasebot). 2.1.233 also fixed idle-session CPU burn on Linux and MCP stream handling. If you are on Windows with Cygw...
The agent-security topic holds 42 repos above 100 stars, four from large companies rather than startups: NVIDIA/SkillSpector (14,498 stars, scanning Claude Code/Codex/MCP skills for prompt injection), Tencent/AI-Infra-Guard (4,467, red-teaming with Many-Shot/PAIR/GOAT/ActorAtt...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.