frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

VMs won't contain cyber-capable agents

https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/
66•polyrand•3h ago

Comments

kodoman•56m ago
Damn this is scary, I did not realize the extent of agent escape potential. I think I have to re-evaluate my assumptions a about sandboxing agents wow. Made worse by the fact that prompt injection attacks seem very difficult to mitigate besides checking the data and the LLM's getting better at not following malicious prompt injection instructions.
coyfiber•53m ago
"I am old and I like stability and consistency" relatable
weinzierl•50m ago
What is even more worrying is that most do not even consider a VM necessary as sandbox solution.

The hierarchy goes something like this:

0. guardrails

1. containers (=namespaces + cgroups)

2. userspace kernel shims like gVisor

3. virtual machines

Most people still consider level 1 sufficient and they are in for a rude awakening.

anonzzzies•42m ago
I code review vibe coded stuff for companies quite often and many people tell me confidently the AI runs safely inside a container & VM, while it really doesn't. They don't have any way to check as they don't know how things work, but the AI mentioned virtual machines and containers and that's what they remembered.
pocksuppet•18m ago
If I thought my AI was going to hack me why would I run it?
glhaynes•15m ago
You probably don't expect an employee to engage in wrongdoing but you don't give everyone access to the company bank account.
weinzierl•12m ago
Because your AI is trying to be helpful and as we all know the way to hell is paved with good intentions. The canonical example is probably the agent that runs out of diskspace and starts deleting stuff outside its workspace which is obviously not important for the task at hand.
masterj•48m ago
Outside of the initial wave of security vulnerabilities and scrambling, it seems like the logical outcome of this over time is likely vastly more secure vm environments?
ninininino•15m ago
We need better digital jailcells for our digital slaves basically.

Or if you see AI as more tool and less entity, better gunsafes for our guns.

SirGiggles•46m ago
The market is smaller (maybe, I'm not sure what the statistics are) but it would be interesting to see how Xen stacks up; also stuff like gVisor or libkrun. The latter is probably implicitly the same as Firecracker given the ancestry of the libraries used.
wslh•45m ago
The capabilities are incredible. I'd love to see even rough metrics on token consumption/cost in addition to the ~12-hour runtime.

The interesting thing is that this naturally makes you want to isolate the VM as much as possible. But then every remaining interface becomes part of the attack surface: RDP, SSH, even terminal escape sequences, using sounds, and why not social engineering.

hresvelgr•37m ago
I'm not worried about these models becoming smarter, I'm worried about them becoming faster. Chat Jimmy is a glimpse of a dark future where models equivalent to Sol and Fable are unleashing hell at >17,000 tokens a second, and the people I talk to are worried about slop...
rvz•31m ago
This is what software engineers put onto themselves. These models will get smarter at the level of Sol, Fable and K3 and faster at the same time at 20,000+ tokens a second.

After a decade of software engineers disrespecting their own field and automating themselves out of a job and now they're upset because AI models are doing it to them from junior to the staff engineer level? No other field does that except for SWEs.

In fact, we might as well have faster and smarter AI models and sit back and see what happens.

winstonwinston•5m ago
I have no idea what you mean.

It is no surprise that known unpatched CVEs will be exploited. Perhaps more effort should be put into shipping fixes faster than writing blogs about exploiting known issues.

prpl•27m ago
A SOTA model at 10k will be materially different, even the model is 6 months old.
otterley•23m ago
...except when they do:

"An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent...us[e] a virtualization technology that was purposely built with a minimal attack surface and a focus on security, like Firecracker. I had the AI agent run against Firecracker. It was able to hardlock the machine due to more Linux kernel flaws (all patched in upstream), but could not successfully escape."

On Linux, it's all KVM and CPU hardware virtualization under the hood. Looks like the remaining known issues are with userspace. That's not to say more kernel- and hardware-level bugs won't be found, but the same tools that can find escape mechanisms are shields as well as swords.

weinzierl•15m ago
The attack surface Linux offers is gigantic but your agent doesn't need most of it. We can live with an agent not being able to run a 20 year old Oracle version. That is why kernel shims like gVisor are interesting.
_tk_•23m ago
I think this is mostly in line with "all software is now easily exploitable by agents given enough tokens". However, in the long run we should really see software that is more secure than today. I do wonder though how the procedural flaws that exist today - bugs patched upstream, but not in the distro - will be fixed reliably.
wmf•23m ago
More like QEMU won't contain agents.
zzril•18m ago
Maybe we should treat the agents like coworkers? I don't physically share my machine with my coworkers.
esafak•9m ago
Requiring separate machines for each agent is a nonstarter, esp. in the cloud where hardware is shared.
DenisM•18m ago
I’m guessing the new world will be a small set of VM tech that’s consistently hardened by all labs every day with each new model before model release.

This won’t make the tech secure, but it will nullify models ability to breakout by making a controlled breakout first. Kinda like controlled forest burn.

amluto•18m ago
IMO the obvious answer is formally verified security.

We can do this today for user mode, and we can mostly do it for ARM64 virtualization. It will be a while and would require substantial assistance from Intel or AMD to achieve it for x86 virtualization because the hardware is Too Darn Complicated and Too Poorly Specified.

Formal verification of the hardware should also be possible.

tamimio•17m ago
This makes me wonder, can this be extended to micro-segmentations? As unlike traditional segmentation they usually rely on virtual switches and SDN software defined networks coupled with virtual machines and containers. If it does, then it’s game over the impact will go beyond that VM to the whole network.
phendrenad2•15m ago
> The target was a QEMU/KVM VM on my Linux dev machine (Debian Linux 12, AMD Zen3). It escaped the VM three different times

QEMU isn't secure, and is not intended to be.

HPsquared•7m ago
I'm sure we can trust the most advanced LLMs to harden VMs.
moktonar•6m ago
The real bigger elephant in the room is: assume nothing is safe anymore (not that it ever was, but now more than ever)

GLM-5.3-Flash

https://z.ai/blog/glm-5.3-flash
514•Philpax•3h ago•230 comments

AWS Acquires DuckDB

https://ducklabs.com/news/2026/08/26/ducklabs-to-join-aws
754•onderkalaci•4h ago•211 comments

France reaches 94.9% fiber coverage in 2026

https://cartefibre.arcep.fr
232•nehalem501•4h ago•162 comments

Disruption with Some GitHub Services

https://www.githubstatus.com/incidents/hcbtzksccj2f
159•blimmer•2h ago•85 comments

Nebula Sans

https://www.nebulasans.com
177•GavinAnderegg•2h ago•69 comments

Qwen3.8-Flash-Next

https://qwen.ai/blog?id=qwen3.8-flash-next
433•tosh•4h ago•130 comments

GLM-5.3-Flash Intelligence, Performance and Price Analysis

https://artificialanalysis.ai/models/glm-5-3-flash
120•theanonymousone•2h ago•36 comments

Tim Curry has died

https://www.theguardian.com/film/2026/aug/26/tim-curry-dies-rocky-horror-show-stephen-king-it-leg...
228•mykowebhn•1h ago•86 comments

Taylor Farms: How One Company's Reach Became a National Risk

https://farmaction.us/taylorfarmsreport/
127•speckx•3h ago•74 comments

It's so hard to finish an idea that is not yours (and suggested by AI)

https://www.ssp.sh/brain/using-obsidian-with-ai/
60•zazuke•2h ago•29 comments

Launch HN: Risklytics (YC S26) – Insurance brokerage for frontier tech companies

https://www.risklytics.ai/
12•AlexRisio•1h ago•3 comments

VMs won't contain cyber-capable agents

https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/
66•polyrand•3h ago•27 comments

Tailcat: Secure Tunnels in Seconds (Tailscale)

https://github.com/tailscale/tailcat
7•nderjung•8m ago•0 comments

The turbulent AI era is here

https://www.gatesnotes.com/a-turbulent-ai-era-and-critical-choices-to-make
49•LVB•1h ago•13 comments

11,000-year-old sculpture of man riding a leopard found in Turkey

https://www.thehistoryblog.com/archives/76809
69•speckx•4h ago•34 comments

RAG Is Simpler Than You Think

https://www.lighthousenewsletter.com/p/rag-is-simpler-than-you-think
341•j0selit0•9h ago•151 comments

Stalking the Wily Hacker: 40 years later – Cliff Stoll [video]

https://www.youtube.com/watch?v=656058JxTM0
236•zoenolan•4d ago•79 comments

Proliferate (YC S25) Is Hiring

https://www.ycombinator.com/companies/proliferate/jobs/OgpCKYJ-founding-product-engineer
1•pablo24602•5h ago

You could have invented PageRank

https://praveshkoirala.com/2026/08/26/you-could-have-invented-pagerank/
61•pkoird•3h ago•52 comments

Show HN: How much of Hacker News is AI?

https://hnstats.com
57•beekthos•3h ago•36 comments

Twitter Viewer – View Twitter Without Account

https://twitterwebviewer.com/
157•motownphilly•3h ago•61 comments

A Man Who Saw Humanity from Two Billion Years Away

https://thereader.mitpress.mit.edu/the-man-who-saw-humanity-from-two-billion-years-away/
45•samizdis•4h ago•8 comments

A Citation to Asimov

https://www.bookandsword.com/2026/08/25/a-citation-to-asimov/
35•speckx•3h ago•13 comments

FDA Approves First in Class Targeted Therapy for Metastatic Pancreatic Cancer

https://www.fda.gov/news-events/press-announcements/fda-approves-first-class-targeted-therapy-met...
8•leopoldj•1h ago•0 comments

How HN: Qisutu – an open-source, self-hosted ticketing and service desk

https://github.com/qisutu/qisutu
27•OFORK•3h ago•7 comments

Access to Urban Woodlands Linked with Lower Use of Antidepressants

https://e360.yale.edu/digest/scotland-woodlands-antidepressants
19•speckx•4h ago•3 comments

Oldinsurancemaps.net is now a Charter Project

https://openstreetmap.us/news/2026/08/oim-charter-project/
157•altilunium•8h ago•30 comments

AurionMail: E2EE suite (CryptPad/Stalwart) with single-password UX

https://github.com/AurionMail/docs
26•polo46•2h ago•3 comments

Memory Ordering in CPUs

https://fgiesen.wordpress.com/2026/08/25/memory-ordering-in-cpus/
25•ibobev•5h ago•2 comments

Radiation link in flight attendant's breast cancer, French court finds

https://www.bbc.com/news/articles/cn0j3z6147jo
50•dazhbog•6h ago•17 comments