After 1,000+ kernel CVEs and a kvm escape, more sympathy for sandboxing AI agents

matthew_d_green · x · 2026-10-04

Cryptographer Matthew Green boosts a take noting that recent kernel CVE counts have topped a thousand, plus a new kvm escape vulnerability — making him more sympathetic to labs struggling to keep agents contained during cybersecurity evals, though the failure may also stem from a much more basic level than sandboxing. He expected many vulns, but the volume still exceeded expectations.

Original post →

More from coding & agent

coding & agent channel →