| ▲ | fhn 9 hours ago | ||||||||||||||||||||||
can they not break out of a VM? | |||||||||||||||||||||||
| ▲ | pkulak 9 hours ago | parent | next [-] | ||||||||||||||||||||||
It's at least harder! Better chance it'll hit your 5-hour limit before it does. haha | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | bloppe 8 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
CVEs for runc are much more frequent than CVEs for KVM. The attack surface area is bigger, and containers were never intended as a security boundary, but rather as a resource management tool. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | esseph 9 hours ago | parent | prev [-] | ||||||||||||||||||||||
Yes, and have. --- "During a test conducted by Trail of Bits researcher Artem Dinaburg, a preview version of GPT 5.6-Cyber was tasked with breaking out of a Debian 12 virtual machine. Initially, the agent exploited a known Linux kernel vulnerability, CVE-2026-53359, by developing its own exploit. After the host was updated, the agent found another pathway through libslirp, chaining a known vulnerability (CVE-2026-9539) with a previously unassigned bug to gain arbitrary host memory access. Even after QEMU and libslirp were updated, the agent analyzed system components and constructed a new escape chain using three zero-day vulnerabilities and one KVM flaw that had not yet reached the distribution kernel. These findings suggest that general-purpose VMs may not be adequate security boundaries for highly capable AI agents, especially in older systems with delayed security updates. Trail of Bits recommends using specialized isolation systems like Firecracker, restricting VM access, and implementing rapid patching to mitigate these risks." --- https://www.scworld.com/brief/ai-agent-repeatedly-escapes-vi... | |||||||||||||||||||||||