frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

NVIDIAScape: VNode prevents this container breakout without the need for VMs

https://www.loft.sh/blog/nvidiascape-container-breakout-vnode-security
12•saiyampathak•7h ago

Comments

saiyampathak•7h ago
Did you here the news about the critical vulnerability NVIDIAScape? Wiz Research discovered the NVIDIAScape vulnerability (CVE-2025-23266), it exposed a container escape path via the NVIDIA Container Toolkit. The easy answer? Patch ASAP (upgrade NVIDIA Container Toolkit > v1.17.8). But the incident kicked off a bigger debate: Do we really need to run all our AI infra inside VMs just for better isolation? We replicated the full exploit chain (malicious image + LD_PRELOAD + privileged hook) and saw that:

Without vNode: Exploit lands you on the host. Game over.

With vNode: Exploit gets stuck in a minimal, locked-down sandbox. Host is untouched.

Here’s where things get interesting: We took a deep dive and tested vNode a Kubernetes-native sandbox runtime for exactly this scenario. Unlike VMs (which bring extra complexity and performance hit), vNode adds a secure isolation layer at the container level, trapping breakouts before they ever reach the host. If you’re running AI workloads, especially with GPUs, and worried about these breakout risks but don’t want VM overhead, vNode might be worth a look. Full walkthrough, YAMLs, and exploit PoC is mentioned in the blog Would love to hear how others are approaching runtime isolation for GPU clusters! Anyone else using vNode, gVisor, Kata Containers, or similar? What’s your tradeoff between security and performance?

diaakh93•7h ago
This is epic - can't wait to see what else vCluster + LoftLabs can do.

Why Are We Pretending AI Is Going to Take All the Jobs?

https://www.thebignewsletter.com/p/why-are-we-pretending-ai-is-going
2•pseudolus•2m ago•0 comments

BYD Bets on Budget EV Boom with Atto 1 Debut in Indonesia

https://jakartaglobe.id/business/byd-bets-on-budget-ev-boom-with-atto-1-debut-in-indonesia
1•breve•4m ago•0 comments

Ask HN: Does an RSS-based Read-It-Later service exist?

1•fargoth•4m ago•0 comments

At Victoria Park Model Boat Club

https://spitalfieldslife.com/2025/07/21/at-victoria-park-model-boat-club-i/
1•zeristor•4m ago•0 comments

Don't Use External CSS

https://maurycyz.com/misc/inline_css/
1•LorenDB•7m ago•0 comments

Ask HN: WASM Profiling Icache vs. Dcache

1•dapperdrake•7m ago•0 comments

A 1995 IC Program Helped Invent Google's Surveillance-Scale Search Engine

https://keystoneweb.dev/mdds_story.html
1•aubreyhayes47•7m ago•1 comments

Discovering and recovering from PostgreSQL corruption on Matrix.org

https://matrix.org/blog/2025/07/postgres-corruption-postmortem/
1•pabs3•8m ago•0 comments

Superchargers are the only part of Tesla's business seeing growth

https://electrek.co/2025/07/23/superchargers-are-the-only-part-of-teslas-business-seeing-growth-right-now/
2•breve•8m ago•0 comments

ELPiS: Small-Web Zine

https://elpis.ws/cgi-bin/cms/articles
1•debo_•9m ago•0 comments

Is This the End of Google as We Know It?

https://gizmodo.com/is-this-the-end-of-google-as-we-know-it-2000633193
2•uladzislau•12m ago•0 comments

Ask HN: Why do so many people think AI will continue to improve exponentially?

1•AbstractH24•16m ago•2 comments

Tesla Q2 2025 Update [pdf]

https://www.tesla.com/sites/default/files/downloads/TSLA-Q2-2025-Update.pdf
14•bratao•19m ago•0 comments

A generic non-invasive neuromotor interface for human-computer interaction

https://www.nature.com/articles/s41586-025-09255-w
1•twalichiewicz•19m ago•0 comments

Show HN: Your Startup Needs a Better Name

https://domaingen.app
2•Areibman•24m ago•0 comments

16colo.rs: ANSI/ASCII art archive

https://16colo.rs/
1•debo_•25m ago•1 comments

BGP Tools

https://bgp.tools/
3•RGBCube•25m ago•1 comments

We Built an Auto-Aiming Trash Can [video]

https://www.youtube.com/watch?v=H0XYANRosVo
1•Armic•25m ago•0 comments

National Blue Alert Network

https://cops.usdoj.gov/bluealert
1•colinprince•26m ago•0 comments

Sorption enhanced chemical looping gasification of biomass for H2 production

https://www.sciencedirect.com/science/article/pii/S0960148125006846
1•PaulHoule•28m ago•0 comments

You Shouldn't Have to Make Your Social Media Public to Get a Visa

https://www.eff.org/deeplinks/2025/07/you-shouldnt-have-make-your-social-media-public-get-visa
2•mdp2021•29m ago•1 comments

Show HN: ETHShot – an Ethereum test‑net "take‑your‑shot" jackpot game

1•cranberryturkey•29m ago•0 comments

First ever fault rupture caught on video, Mianmar 7.9

https://www.youtube.com/watch?v=_OeLRK0rkCE
1•kurthr•30m ago•0 comments

Built this after my mom asked how to 'just make herself smile in a photo

https://apps.apple.com/us/app/phoai-ai-photo-maker-editor/id6747897909
1•incendies•32m ago•2 comments

I built a complete guide site for the game "99 Nights in the Forest"

https://99nightsintheforest.online
1•hugh1st•32m ago•1 comments

We transcribed a week of audio in a minute for a dollar

https://modal.com/blog/fast-cheap-batch-transcription
1•plurby•33m ago•0 comments

Test Ad Block

https://adblock.turtlecute.org/
2•colinprince•34m ago•0 comments

What Makes a Mature Science

https://www.asimov.press/p/mature-science
1•bookofjoe•35m ago•0 comments

Dynamic Chunking for End-to-End Hierarchical Sequence Modeling

https://arxiv.org/abs/2507.07955
2•gatane•36m ago•0 comments

Name SF Streets

https://carvin.github.io/sf-street-names/
1•kelnos•37m ago•0 comments