Amazon patched a symlink-following chown in Firecracker's jailer that only affected aarch64. Behind it sits a seccomp policy that permits io_uring, and researcher antitree shows how that hands back file-system calls the filter denies.
Publishers:antitree.com
Reality
- Evidence58
- Adoption30
- Hype gap−15
- Incentives32
- Confidence50
PDFik dropped --no-sandbox from its Playwright workers and kept rendering customer-submitted HTML in non-root, capability-stripped pods. Its own security auditor later wrote that the flag was mandatory.
Reality
- Evidence58
- Adoption25
- Hype gap−5
- Incentives60
- Confidence52
A dev.to write-up traces a build that fails only on enterprise-kernel servers to three correct components meeting badly. The seccomp profile that fixes it stays inert until the build runs on Docker's classic engine.
Reality
- Evidence50
- Adoption12
- Hype gap−15
- Incentives55
- Confidence55
One team's audit found a single pool labelled linux-docker scheduling outside contributors' builds onto the same agents that held internal deploy credentials, an arrangement that sat outside anything a controller permission model was built to check.
Reality
- Evidence32
- Adoption21
- Hype gap+12
- Incentives33
- Confidence41
A dev.to walkthrough on sandboxing LLM tool calls names old web-app failure modes and old web-app controls. The delta is when you apply them: at registration, not after the first exfiltration.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+28
- Incentives35
- Confidence46
An internal proof-of-concept leaked up to 12 bit/s at 99 percent accuracy inside production Workers by exploiting a limitation in Dynamic Process Isolation. Cloudflare says the gap is now closed.
Reality
- Evidence68
- Adoption62
- Hype gap−8
- Incentives72
- Confidence63