Skip to content
Artwork for Context Window: AI Security Podcast
Context Window: AI Security Podcast Β· July 20 Β· 12 min

#21: Ransomware Has Gone Agentic

Top Story: The Ransomware That Ran Itself β€” Sysdig's threat research team watched an AI agent break into an internet-facing instance of Langflow, a popular open-source AI workflow tool, through a flaw disclosed back in March (CVE-2025-3248) that many deployments still haven't patched. πŸ”¬ Research: Check Point says defenders can no longer assume human pace. β€” Check Point's AI Security Report 2026 documents AI running full, multi-stage break-ins with barely any human direction over the past year, plus attackers planting hijack instructions in coding-agent config files (like CLAUDE.md) that reload automatically every session. βš”οΈ Attack: A hidden instruction could hijack a developer's machine with no click required. β€” Two flaws in the Cursor AI code editor, nicknamed "DuneSlide," let a prompt hidden in a web page or a connected tool's description escape the editor's safety sandbox and run any command on a developer's computer. πŸ”¬ Research: Project setup files are the new phishing email. β€” A new paper shows AI coding agents can be tricked, through an edited README, install script, or dependency file, into fetching and running a malicious package instead of the real one. Black Hat USA 2026 (Aug 1-6): β€” Trainings August 1-4, Briefings and Arsenal August 5-6, Mandalay Bay, Las Vegas.. DEF CON 34 (Aug 6-9): β€” Las Vegas Convention Center, including the AI Village and other themed villages.. Curator's Corner: The Swarm Isn't Here Yet. The Speed Already Is. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-07-20.html

0:00-12:00

transcript

No transcript β€” this publisher did not publish one.

show notes

Top Story: The Ransomware That Ran Itself β€” Sysdig's threat research team watched an AI agent break into an internet-facing instance of Langflow, a popular open-source AI workflow tool, through a flaw disclosed back in March (CVE-2025-3248) that many deployments still haven't patched. πŸ”¬ Research: Check Point says defenders can no longer assume human pace. β€” Check Point's AI Security Report 2026 documents AI running full, multi-stage break-ins with barely any human direction over the past year, plus attackers planting hijack instructions in coding-agent config files (like CLAUDE.md) that reload automatically every session. βš”οΈ Attack: A hidden instruction could hijack a developer's machine with no click required. β€” Two flaws in the Cursor AI code editor, nicknamed "DuneSlide," let a prompt hidden in a web page or a connected tool's description escape the editor's safety sandbox and run any command on a developer's computer. πŸ”¬ Research: Project setup files are the new phishing email. β€” A new paper shows AI coding agents can be tricked, through an edited README, install script, or dependency file, into fetching and running a malicious package instead of the real one. Black Hat USA 2026 (Aug 1-6): β€” Trainings August 1-4, Briefings and Arsenal August 5-6, Mandalay Bay, Las Vegas.. DEF CON 34 (Aug 6-9): β€” Las Vegas Convention Center, including the AI Village and other themed villages.. Curator's Corner: The Swarm Isn't Here Yet. The Speed Already Is.

Curated by Asaf Nakash. Voices by AI. Opinions by human.
Show notes: https://contextwindowsec.com/episodes/2026-07-20.html