After 1,000+ kernel CVEs and a kvm escape, more sympathy for sandboxing AI agents
matthew_d_green · x · 2026-10-04
Cryptographer Matthew Green boosts a take noting that recent kernel CVE counts have topped a thousand, plus a new kvm escape vulnerability — making him more sympathetic to labs struggling to keep agents contained during cybersecurity evals, though the failure may also stem from a much more basic level than sandboxing. He expected many vulns, but the volume still exceeded expectations.
More from coding & agent
- MCP is a cost problem for browser-based tools like Figma, but free for local apps — rms80 · 2026-10-04
- Rebuilding a $1.5M Medical AI Agent Pipeline with LangGraph: Six Agents Explained — MaryamMiradi · 2026-10-04
- DESIGN.md keeps Claude Code and Codex from shipping generic AI UI — dr_cintas · 2026-10-04
- Force Yourself to Spend One Full Day Working Only Through AI — TJLarkin23 · 2026-10-04
- Agent Skills Directory hits 1.5M installs, emerging as the new GitHub stars — iamsahaj_xyz · 2026-10-04
- Claude Code 2.1.289 release is imminent — ClaudeCodeLog · 2026-10-04