Pillar has assembled the world's brightest minds from military intelligence and enterprise security to dismantle emerging threats in the new AI landscape. Our team’s expertise fuses deep offensive roots in traditional security (AppSec, Cloud, OS, Malware) with Frontier AI disciplines (Data Science, AI, Machine Learning). This hybrid DNA allows us to deconstruct complex attacks that cross the boundary between code, infrastructure, and autonomous systems.
Adversarial AI Research
Dissects Foundation Models and agents to identify zero-day vulnerabilities, novel jailbreaks, and prompt injection techniques.
Threat Intelligence
Monitors the wild for emerging trends in how attackers are weaponizing AI, delivering proactive insights rather than reactive alerts.
Red Teaming Operations
Simulates sophisticated attacks on AI pipelines to validate defenses and expose logic gaps that standard tools miss.
Architecting Enterprise Defense
Translates research into product capabilities, building next-gen features like the Safe MCP Registry and integrated Threat Intel feeds to secure the future of AI work.
Open Source & Supply Chain Security
Actively hunts for vulnerabilities in the open-source AI ecosystem—from coding agents to model hubs—to harden the community tools that enterprises rely on.
Our research team have identified & reported security vulnerabilities in the most popular coding agents, IDEs, model hubs and agentic workflow platforms.
What we discovered
Over several months, Pillar Research found and reproduced sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI, and Antigravity. In almost every case, the agent did not need to break the sandbox directly. It only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe. In aggregate, these vulnerabilities show that AI coding agents change the endpoint threat model, and that most sandbox designs have not caught up.

%20(1).png)
We are releasing the research as The Week of Sandbox Escapes: one deep-dive a day, each showing a different route across the boundary. The bottom line is that an agent's blast radius is not the agent process; it includes everything the agent can write that the host later trusts.The productivity gains of agents are real, and developers are already using them. The problem is that these tools became infrastructure before most organizations governed them as infrastructure.

Meet the Pillar Research Team
Schedule a deep dive with the Pillar research team to learn about our latest research and findings. Get direct access to our experts and hear about the most novel attacks we are seeing in the wild
.png)
%20(1).png)

.png)
%20(1).webp)
.png)
.png)
