← Back to all episodes
March 23, 2026 — #4

AI Sandboxes Are Broken — Two Platform Escapes in One Week

#4 · ~14 min · Curated by Asaf Nakash

Stories This Week

Curator's Corner

Infrastructure was never fully hardened — and for years, it didn't need to be. Exploiting a misconfigured DNS rule or an over-permissive IAM role required real skill: understanding protocol internals, chaining privileges, building custom tooling. That complexity was a natural filter. Most attackers couldn't pull it off.

AI removed the filter.

This week, researchers broke out of AWS Bedrock's "isolated" sandbox using DNS tunneling and escaped Snowflake's coding agent via process substitution — techniques that once required deep infrastructure expertise. With AI, these attacks become reproducible, teachable, almost routine. Wiz published an AI-powered bounty hunting crash course last month. Check Point documented a single developer building 88,000 lines of deployment-ready malware in a week using an AI IDE.

That's the real shift: AI gives every attacker the tooling and complexity that once required a full-time team. The vulnerability surface didn't change — but the population that can exploit it just expanded by orders of magnitude.

Never miss an episode

Spotify Substack RSS
📰 Subscribe to the newsletter on LinkedIn