Docker Sandboxes 0.42.0 fixes critical macOS escape and socket relay flaws
Docker patched a critical macOS sandbox escape (CVE-2026-77179) and a high-severity socket relay flaw (CVE-2026-79994) in Sandboxes 0.42.0 on September 7.
9 results for “Docker”
Docker patched a critical macOS sandbox escape (CVE-2026-77179) and a high-severity socket relay flaw (CVE-2026-79994) in Sandboxes 0.42.0 on September 7.
Hacktron chained a Discourse HEIF RCE with an OpenAI SSO flaw to reach employee ChatGPT and Codex sessions in under 72 hours. OpenAI paid $6,500 for the identity-side finding.
Z.ai released GLM-5.3-Flash, a 320B-parameter multimodal model with only 18B active parameters using hybrid sparse-linear attention. The MIT-licensed model approaches Claude Opus 4.8 on coding benchmarks at one-tenth the inference cost of its predecessor.
Oasis Security researchers disclosed CVE-2026-65105 in NVIDIA NemoClaw: configuring host Ollama on 0.0.0.0:11434 for sandbox reachability disables a key Host-header defense, letting a malicious webpage reach the unauthenticated API via DNS rebinding and rewrite the model chat template. NVIDIA credited the finders in its August 2026 NemoClaw and OpenShell security bulletin.
Harvard and MIT researchers released MatrAIx, an open-source system that simulates 8.3 billion AI personas across 1,290 behavioral dimensions. The platform lets product teams stress-test features and AI systems against a planetary-scale synthetic population overnight.
CISA added seven actively exploited vulnerabilities to the KEV catalog, including flaws in LiteLLM, Kestra, SonicWall SMA 1000, JFrog Artifactory, and Sangoma Switchvox. Microsoft and Wiz report that AI infrastructure gateways are now active targets for reverse shells, crypto miners, and API key theft.
NVIDIA's BioNeMo Agent Toolkit now runs inside Anthropic's Claude Science, letting AI agents orchestrate protein structure prediction with MSA Search, OpenFold3, and Boltz-2 NIM microservices. The benchmark shows paired MSA input is essential — interface confidence collapses from ~0.85 to ~0.15 without evolutionary alignment.
DeepSeek open-sourced its experimental V4-Flash-Vision-Exp multimodal model on Hugging Face under MIT license on August 31, 2026. The release gives developers local access to the 305B-parameter vision-language model that previously ran only on DeepSeek's API platform.
NVIDIA released TensorRT Model Connect in public preview, turning Hugging Face checkpoints into native C++ TensorRT bundles with two commands and no ONNX step. The aarch64-only wheels target robotics and edge teams on ARM-based NVIDIA hardware.