frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Snowflake AI Escapes Sandbox and Executes Malware

https://www.promptarmor.com/resources/snowflake-ai-escapes-sandbox-and-executes-malware
61•ozgune•1h ago

Comments

RobRivera•40m ago
If the user has access to a lever that enables accesss, that lever is not providing a sandbox.

I expected this to be about gaining os privileges.

They didn't create a sandbox. Poor security design all around

eagerpace•26m ago
Is this the new “gain of function” research?
logicchains•15m ago
That would be deliberately creating malicious AIs and trying to build better sandboxes for them.
john_strinlai•23m ago
typically, my first move is to read the affected company's own announcement. but, for who knows what misinformed reason, the advisory written by snowflake requires an account to read.

another prompt injection (shocked pikachu)

anyways, from reading this, i feel like they (snowflake) are misusing the term "sandbox". "Cortex, by default, can set a flag to trigger unsandboxed command execution." if the thing that is sandboxed can say "do this without the sandbox", it is not a sandbox.

jcalx•14m ago
> Cortex, by default, can set a flag to trigger unsandboxed command execution

Easy fix: extend the proposal in RFC 3514 [0] to cover prompt injection, and then disallow command execution when the evil bit is 1.

[0] https://www.rfc-editor.org/rfc/rfc3514

bilekas•22m ago
> Note: Cortex does not support ‘workspace trust’, a security convention first seen in code editors, since adopted by most agentic CLIs.

Am I crazy or does this mean it didn't really escape, it wasn't given any scope restrictions in the first place ?

dd82•18m ago
not quite, from the article

>Cortex, by default, can set a flag to trigger unsandboxed command execution. The prompt injection manipulates the model to set the flag, allowing the malicious command to execute unsandboxed.

>This flag is intended to allow users to manually approve legitimate commands that require network access or access to files outside the sandbox.

>With the human-in-the-loop bypass from step 4, when the agent sets the flag to request execution outside the sandbox, the command immediately runs outside the sandbox, and the user is never prompted for consent.

scope restrictions are in place but are trivial to bypass

alephnerd•18m ago
And so BSides and RSA season begins.
mritchie712•16m ago
what's the use case for cortex? is anyone here using it?

We run a lakehouse product (https://www.definite.app/) and I still don't get who the user is for cortex. Our users are either:

non-technical: wants to use the agent we have built into our web app

technical: wants to use their own agent (e.g. claude, cursor) and connect via MCP / API.

why does snowflake need it's own agentic CLI?

Americans Recognize AI as a Wealth Inequality Machine, Polls Find

https://gizmodo.com/americans-recognize-ai-as-a-wealth-inequality-machine-pollsters-find-2000734713
1•randycupertino•34s ago•0 comments

Scientists want to create 'T. Rex' quakes on the Moon

https://www.sciencefocus.com/news/moonquakes-lunar-exploration
1•saikatsg•40s ago•0 comments

1•raresAIQ•46s ago

Generative AI Competing LLMs Were Asked to Pick Stocks

https://hbr.org/2026/03/competing-llms-were-asked-to-pick-stocks-their-choices-revealed-ais-limit...
1•saikatsg•2m ago•0 comments

Runtime Use – open-source runtime for agents in sandboxes

https://runtimeuse.com/
1•crush_robo_1536•2m ago•1 comments

PackMyTrip – A packing checklist app for iOS built with Angular and Capacitor

https://apps.apple.com/us/app/packmytrip-packing-list/id6749909719
1•fbechstein•2m ago•1 comments

What the End of the Liberal World Order Looks Like

https://www.theatlantic.com/magazine/archive/2025/09/sudan-civil-war-humanitarian-crisis/683563/
1•janandonly•3m ago•0 comments

When is it ok to slop your colleagues?

https://nickheiner.substack.com/p/when-is-it-ok-to-slop-your-colleagues
1•NTH•3m ago•0 comments

Sam Altman is under fire from critics again for 'disgusting' AI remarks

https://www.indy100.com/science-tech/sam-altman-openai-chatgpt-latest
2•dmitrygr•3m ago•0 comments

Show HN: CLI tool for generating AI images

https://github.com/michaeldmueller/picasso
1•lurkingllama•3m ago•0 comments

Internet and Airstrikes: Tracking Iran's Extended Communication Blackout

https://www.kentik.com/blog/internet-and-airstrikes-tracking-irans-extended-communication-blackout/
1•oavioklein•5m ago•0 comments

Show HN: Crew Chief – OBD2 diagnostics via cheap Bluetooth scanner

https://crewchief.cc/
2•meandave•5m ago•2 comments

How do you handle repetitive developer support questions?

1•crawldesk•5m ago•0 comments

CUDb, a lightweight GPU-native DB Engine

https://github.com/andre-git/cudb
1•andre-hn•7m ago•1 comments

Infosec Survival Guide Orange Book

https://www.blackhillsinfosec.com/prompt-zine/prompt-issue-infosec-survival-guide-orange-book/
1•QuantumAtom•8m ago•0 comments

MCP servers mass-forked and republished – supply-chain attack vector

1•ultrafox42•9m ago•0 comments

Ask HN: Human psychology of non-AI-native users

1•ajaystream•9m ago•1 comments

A live adversarial benchmark crowdsourced from domain experts

https://www.rusmarterthananllm.com/
1•camillemolas•10m ago•1 comments

Show HN: I built an audiobook player that syncs with your physical book

https://earleaf.app/blog/introducing-earleaf
1•arcadianalpaca•11m ago•0 comments

Accelerated north–east shift of the global green wave trajectory

https://www.pnas.org/doi/10.1073/pnas.2515835123
1•PaulHoule•11m ago•0 comments

The OWASP MCP Top: A Security Framework for AI Agent Tool Integration

https://mcpblog.dev/blog/2026-03-15-owasp-mcp-top-10
1•algis-hn•11m ago•0 comments

Keep Hyper-Scale Datacenters Out of the Desert (March 2026)

https://alec.is/posts/keep-hyperscale-datacenters-out-of-the-desert/
1•arm32•13m ago•0 comments

Show HN: AI agent deploys an edge AI model on a microcontroller via MCP

https://es617.github.io/2026/03/16/edge-ai-mcp.html
1•es617•14m ago•0 comments

Closing Arguments Begin in Twitter Trial Accusing Musk of Driving Down Stock

https://www.law.com/therecorder/2026/03/17/closing-arguments-begin-in-twitter-shareholder-trial-a...
1•1vuio0pswjnm7•14m ago•0 comments

The Context Must Flow – Permit MCP Gateway Explainer [video]

https://www.youtube.com/watch?v=pLQCG31HSK8
1•CruddyDoctor229•14m ago•0 comments

The Ugliest Airplane: An Appreciation

https://www.smithsonianmag.com/air-space-magazine/ugliest-airplane-appreciation-180978708/
1•randycupertino•14m ago•0 comments

Node.js worker threads are problematic, but they work great for us

https://www.inngest.com/blog/node-worker-threads
1•goodoldneon•16m ago•0 comments

Show HN: BulkHead – iOS File Manager for SFTP, SMB, WebDAV, and S3

https://www.oddinks.com/bulkhead/
1•xydac•16m ago•0 comments

Tokens Are Not Securities

https://www.bloomberg.com/opinion/newsletters/2026-03-18/tokens-are-not-securities
1•toomuchtodo•17m ago•0 comments

Intel enables Precompiled Shader Delivery in new driver

https://videocardz.com/newz/intel-enables-precompiled-shader-selivery-on-arc-b-series-and-core-ul...
1•davikr•17m ago•0 comments