Newsletter

Researchers Escape Claude Cowork’s Local Sandbox to Reach Mac Files

Accomplish AI used Linux kernel flaw CVE-2026-46331 to gain guest root and cross a read-write host mount; Cowork now defaults to cloud execution.

Retro editorial illustration of an AI process breaking through a virtual-machine wall toward host files as security workers close the path and redirect execution to the cloud.
Lead imageRetro editorial illustration of an AI process breaking through a virtual-machine wall toward host files as security workers close the path and redirect execution to the cloud.
On this page

Accomplish AI demonstrated a path by which untrusted content in a local Claude Cowork session could escape its Linux virtual machine and read or write files across the host Mac user account. The chain exploited CVE-2026-46331 to gain guest root, then crossed Cowork’s read-write mount of the host filesystem; the researchers said that could expose material such as SSH keys and cloud credentials.

The Linux kernel flaw was fixed in June, and Accomplish reported the Cowork finding to Anthropic, which closed it as “Informative.” Cowork now uses cloud execution by default, where the researchers say this local escape path does not appear to apply, but their report argues that mounting the full host filesystem left the sandbox one guest privilege escalation away from a wider breach.

Featured source: TechRadar , Accomplish AI , Ubuntu .

White House Expands Voluntary Data-Center Power-Cost Pledge

The White House says more than 200 additional utilities, data-center developers, cooperatives, and states have joined its Ratepayer Protection Pledge. Signatories commit to procuring new generation and paying for delivery upgrades required by large data centers, but the pledge is voluntary and its effect on household bills remains uncertain because rates and cost allocation still pass through utilities, markets, and state regulators.

Filed from: The Register , White House , Associated Press .

Researchers Disclose a macOS Gatekeeper App-Replacement Gap

Researchers say code already running with ordinary user privileges can replace the executable of a previously launched macOS app downloaded outside the Mac App Store without prompting Gatekeeper to repeat its first-run checks. The technique depends on an existing foothold and a trusted app that has already run; Apple reportedly assessed the behavior as not requiring a security fix.

Filed from: TechRadar , Mysk .

Ukraine Tests Marichka for Faster Battlefield Planning

Ukraine’s defense ministry is testing Marichka, a system intended to combine battlefield data and accelerate operational planning. The reported trials have used test data rather than the more highly classified information the system is eventually meant to handle, leaving its performance and secure deployment under real operational conditions unproven.

Filed from: TechRadar , Ukrainska Pravda .

From the Community

Cloudflare Splits AI Crawlers into Search, Agent, and Training Controls

Cloudflare is replacing its single AI-bot switch with separate Search, Agent, and Training controls, allowing site owners to set different access policies for each category. The company says ad-supported sites will default to blocking Training and Agent bots from September 15, while multipurpose crawlers will be blocked when any disallowed use applies.

Filed from: Cloudflare .

Stanford Brief Finds Little Aggregate AI-Driven Job Loss So Far

A Stanford Institute for Economic Policy Research brief finds little evidence of broad employment losses attributable to AI so far: unemployment has not risen faster in more exposed occupations, and employment in coding-heavy work continues to grow. It also records a weaker market for recent graduates, while cautioning that interest rates and pandemic-era over-hiring complicate attempts to isolate AI’s contribution.

Filed from: Stanford SIEPR .

Debian Opens Discussion on Four LLM-Contribution Proposals

Debian has opened discussion on four competing general-resolution proposals governing LLM-assisted contributions. The choices range from prohibition through disclosure and human-accountability rules to conditional permission; no result exists because the project has not yet voted.

Filed from: Debian Project .

A 28.9-Million-Parameter Language Model Runs on an ESP32-S3

An open-source project demonstrates a 28.9-million-parameter language model generating text entirely on an ESP32-S3 microcontroller, using per-layer embeddings to keep most parameters in flash rather than RAM. The TinyStories-trained model produces short stories rather than following instructions or answering general questions, and the repository includes firmware, training code, and ablation results.

Filed from: GitHub repository .

GM Backs Sodium-Ion Batteries for Grid Storage

General Motors is backing Peak Energy as the startup develops sodium-ion systems for grid storage and plans a $71 million factory near Sacramento with four gigawatt-hours of annual capacity. Peak says its chemistry can deliver a lower lifetime cost than lithium-iron phosphate despite lower energy density; those cost and durability figures remain company claims as GM tests cells at its Michigan innovation center.

Filed from: IEEE Spectrum .

Continue reading

Complete index →