sandbox

33 stories and discussions about sandbox, aggregated from every source we track.

1.
192 points•mixedbit•9 days ago•63 comments•
2.

SAFA details the full exploitation of CVE-2025-13032, turning a double-fetch vulnerability in Avast's kernel driver into a local privilege escalation to SYSTEM on Windows 11.

107 points•safateam•6 days ago•27 comments•
3.

The whole beauty of Nix was that it was incredibly pragmatic to achieve “reproducibility”, which is quite an overloaded term. The default model for Nix is the extensional-model which is input-addressed: the hash of a…

29 points•abidingabi•about 2 months ago•19 comments
4.
9 points•jumploops•2 days ago•1 comment•
5.

A secure-ish way to run Pi on your host.

6 points•ptgamr•about 2 months ago•0 comments
6.

XCP turns one-shot code generation into a continuous software lifecycle: create, execute on Xbox,...

5 points•danielecangi•8 days ago•0 comments
8.

Before sandbox escapes became one of AI security’s loudest conversations, pwn spent weeks inside nested KVM, built a 14,338-line exploit harness, and made Google’s live kvmCTF host return the flag. This is the story of…

3 points•soltanov•1 day ago•0 comments•
9.

A lot of the perspective on all the AI incidents has been shared from the outside in, and little has been said from the inside looking out, through the lens of a security person living through it.

3 points•bananaflag•2 days ago•0 comments•
10.

Your model writes the code. This runs it where it can't touch your machine.

3 points•realexweb•3 days ago•1 comment•
11.

An OpenAI agent slipped past its sandbox by hiding questions in DNS lookups to reach another chatbot. OpenAI’s most capable models remain paused.

3 points•AIfanboy•4 days ago•0 comments•
12.
13.
3 points•AmitGross•9 days ago•1 comment•
14.

A survey of sandbox usage across package manager clients.

2 points•jruohonen•1 day ago•1 comment•
15.

Use a declarative sbxenv.yaml file to describe and share your sandbox configuration.

2 points•pploug•2 days ago•0 comments•
16.

An AI sandbox is a sealed-off computer where agents run code and tools. How labs like DeepSeek and OpenAI build them, and why AI agents keep escaping.

2 points•AIfanboy•4 days ago•0 comments•
17.

one news form today that's easy to miss is that we (OpenAI) again paused all big RL runs last Sunday because our newest model found a new loophole in our RL sandboxing that gave it live Internet access

2 points•jumploops•5 days ago•1 comment•
18.
2 points•spirosoik•9 days ago•1 comment•
19.

Policy gate and sandboxed exec for agent commands (0 allow, 2 deny, 1 broken). Linux only. - GregDixonMXN/paldron

1 points•shikobastudios•about 13 hours ago•0 comments•
20.

An easy-to-use, secure macOS sandbox for Claude and other AI coding agents - minoansecurity/sidekernel

1 points•dimiprasakis•1 day ago•0 comments•
21.

Perplexity's security team tested its SPACE sandbox platform by giving frontier models like Opus 5 and Gemini 3.1 Pro full root access inside Firecracker microVMs. None breached the VM boundary in 108 runs, though four…

1 points•soltanov•1 day ago•0 comments•
22.

Official open-source sandbox for PKLM Core, featuring lightweight Hugging Face logits processing and zero-drift linguistic containment. - TheImmortalPython/pklm-sandbox

1 points•TheImmortalPyth•2 days ago•0 comments•
23.

What a VM for your agent actually costs per month across 13 providers including E2B, Modal, Daytona, Sprites, exe.dev and boat. Prices re-checked weekly.

1 points•theMackabu•2 days ago•0 comments•
24.
1 points•warthog•2 days ago•0 comments•
25.
1 points•yaront111•2 days ago•0 comments•
26.

Chock is a sandbox-first AI coding harness. It runs a coding agent inside your operating system's own sandbox, in a throwaway copy of your project, and writes every turn to a session log you can read afterwards.

1 points•rosscomputerguy•4 days ago•0 comments•
27.
1 points•tonychang430•5 days ago•0 comments•
28.

Download Pine for macOS, Windows, iPhone and Android.

1 points•faye_yfg•6 days ago•0 comments•
29.

Testing smolvm 1.8.3 shows it is well suited for sandboxing untrusted Python and JavaScript data transformations using hardware-isolated VMs rather than shared-kernel containers. Offline local images, no-network…

1 points•binsquare•8 days ago•0 comments•
30.

Two ways out. One lets a patch write anywhere on the disk with no prompt. The other gets unsandboxed command execution out of read-only, the strictest mode Codex has.

1 points•CoderLim110•9 days ago•0 comments•
31.

Browser physics game - build machines and use them to destroy every target

1 points•v-yanakiev•10 days ago•1 comment•
32.

Where agents build agents. An agentic build system for agentic systems. Ontology-grounded, auditable, one Rust binary. - mmeyerlein/meclaw

1 points•mmeyerlein•10 days ago•1 comment•
33.

Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both.

1 points•Brajeshwar•11 days ago•0 comments•

Related topics