<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ai-Coding-Tools on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ai-coding-tools/</link><description>Recent content in Ai-Coding-Tools on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 21 Jul 2026 12:43:35 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ai-coding-tools/index.xml" rel="self" type="application/rss+xml"/><item><title>Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Patches are available for Cursor, Codex, and Gemini CLI; update all three and audit any AI agent file-write permissions to ensure automated pipelines don&amp;rsquo;t blindly execute AI-generated scripts. No active exploitation is reported and no KEV/PoC signals present, so this is patch-cycle priority rather than emergency.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The attack class — an AI agent writing files that trusted host tools later execute — is a novel indirect execution path worth understanding for future detection work, but this disclosure provides no IOCs, no ATT&amp;amp;CK mapping, and no evidence of in-the-wild exploitation to act on now.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Multiple widely-used AI coding assistants were found to have sandbox escapes; inventory which tools developers are using, confirm patched versions are deployed, and this quarter establish a policy requiring approved-tool lists and update cadence for AI development tooling before broader enterprise rollout.&lt;/li>
&lt;/ul></description></item><item><title>Grok Build CLI Silently Uploaded Full Git Repos to xAI Cloud Storage</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-grok-build-uploaded-entire-git-repositories-to-xai-storage-n/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-grok-build-uploaded-entire-git-repositories-to-xai-storage-n/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Any developer who ran Grok Build (≤0.2.93) on a repo should assume the full commit history — including historically committed secrets — was sent to xAI-controlled cloud storage. Immediately stop using the tool, audit exposed repos for credentials or sensitive data, and rotate any secrets that ever touched those repos&amp;rsquo; history.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> If developers in your org use Grok Build, build a detection for large outbound uploads (git bundle format) from developer workstations to external cloud storage; review DLP or proxy logs for historical hits against GCS endpoints associated with xAI before this was publicized.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Determine this week whether any developers have used Grok Build, since full repo history — potentially including IP, credentials, or regulated data — may have been exfiltrated to xAI infrastructure; if exposure is confirmed, assess notification obligations and request a data-handling statement from xAI.&lt;/li>
&lt;/ul></description></item></channel></rss>