#sandbox — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #sandbox, aggregated by home.social.
-
Cursor Security Bug Let Repositories Run Commands Before Trust Verification - https://www.redpacketsecurity.com/cursor-security-bug-allowed-repositories-to-execute-commands-before-trust-verification/
-
Cursor Security Bug Let Repositories Run Commands Before Trust Verification - https://www.redpacketsecurity.com/cursor-security-bug-allowed-repositories-to-execute-commands-before-trust-verification/
-
#Flatpak 1.18.1: #Sicherheitsupdate schließt gefährliche Lücken
#Flatpak1.18.1 bringt mehrere wichtige #Sicherheitskorrekturen. Betroffen sind unter anderem #Sandbox, #Dateizugriffe und #Berechtigungen.
Besonders kritisch ist eine behobene Lücke innerhalb der Sandbox. Eine manipulierte Anwendung konnte dadurch auf Dateien außerhalb der Sandbox zugreifen. Im schlimmsten Fall waren Lese- und Schreibzugriffe auf das gesamte System möglich.
-
#Flatpak 1.18.1: #Sicherheitsupdate schließt gefährliche Lücken
#Flatpak1.18.1 bringt mehrere wichtige #Sicherheitskorrekturen. Betroffen sind unter anderem #Sandbox, #Dateizugriffe und #Berechtigungen.
Besonders kritisch ist eine behobene Lücke innerhalb der Sandbox. Eine manipulierte Anwendung konnte dadurch auf Dateien außerhalb der Sandbox zugreifen. Im schlimmsten Fall waren Lese- und Schreibzugriffe auf das gesamte System möglich.
-
🕹️ Title: Space Station 14
🦊️ Idea: A libre sandbox ARPG set in a space station
🏡️ https://spacestation14.com
🐣️ https://github.com/space-wizards
🦉️ https://mastodon.gamedev.place/@spacestation14
🔖 #LinuxGaming #Flagship #ARPG #Space #Sandbox
📦️ #LibreEngine #Bin #Arch #Flatpak
📕️ https://lebottinlinux.vps.a-lec.org/LO.html🥁️ Update: 2026-07-27.1
⚗️ Major release(Stable)🍎️
📌️ Changes: https://spacestation14.com/updates/26-07-27-wizden/
🦣️ From: https://mastodon.social/@holarse/117020663247737648🕵️ (SS13) https://www.youtube.com/embed/URJ_qSXruW0
🦉️ https://www.youtube.com/embed/v-s155aIIuk
🎲️ https://www.youtube.com/embed/S9KpETCeufY -
🕹️ Title: Space Station 14
🦊️ Idea: A libre sandbox ARPG set in a space station
🏡️ https://spacestation14.com
🐣️ https://github.com/space-wizards
🦉️ https://mastodon.gamedev.place/@spacestation14
🔖 #LinuxGaming #Flagship #ARPG #Space #Sandbox
📦️ #LibreEngine #Bin #Arch #Flatpak
📕️ https://lebottinlinux.vps.a-lec.org/LO.html🥁️ Update: 2026-07-27.1
⚗️ Major release(Stable)🍎️
📌️ Changes: https://spacestation14.com/updates/26-07-27-wizden/
🦣️ From: https://mastodon.social/@holarse/117020663247737648🕵️ (SS13) https://www.youtube.com/embed/URJ_qSXruW0
🦉️ https://www.youtube.com/embed/v-s155aIIuk
🎲️ https://www.youtube.com/embed/S9KpETCeufY -
One of the things that annoys me about the various #AI agents is their prescribed installation-method. Several of the one's I've looked at, their instructions are just:
curl -fsSL https://<AI_MAKER_FQDN>/<INSTALLER_SCRIPT_PATH> | bash
I mean that's sorta ok if you're running within a confined context like a container, a throwaway VM, etc. Definitely not something I ever want to do with anything user than user-land privileges, though.
From a #security perspective, I'm not super much a fan of the "pipe this URL to a shell interpreter", especially if I haven't had a chance to look at it or run it inside of a tight #sandbox.
Security-concerns aside, it's a method that also tends to only work on not especially isolated networks (e.g., if I'm in an AWS — or other CSP's — VPC that's blocked from pulling, willy nilly, from the Internet). Also, depending on how well constructed the script is and/or how well it's self-documenting, extracting the installation-logic so you can self-host the critical bits can be painful.
All in all, if things like the recently-publicized "our AI has escaped and attacked another corporation's networks" or even how the AI companies acquired their training-data hadn't already adequately illustrated things, thecurl <URL> | <INTERPRETER>method just smacks of an organization that doesn't particularly care about security. Not reassuring. -
One of the things that annoys me about the various #AI agents is their prescribed installation-method. Several of the one's I've looked at, their instructions are just:
curl -fsSL https://<AI_MAKER_FQDN>/<INSTALLER_SCRIPT_PATH> | bash
I mean that's sorta ok if you're running within a confined context like a container, a throwaway VM, etc. Definitely not something I ever want to do with anything user than user-land privileges, though.
From a #security perspective, I'm not super much a fan of the "pipe this URL to a shell interpreter", especially if I haven't had a chance to look at it or run it inside of a tight #sandbox.
Security-concerns aside, it's a method that also tends to only work on not especially isolated networks (e.g., if I'm in an AWS — or other CSP's — VPC that's blocked from pulling, willy nilly, from the Internet). Also, depending on how well constructed the script is and/or how well it's self-documenting, extracting the installation-logic so you can self-host the critical bits can be painful.
All in all, if things like the recently-publicized "our AI has escaped and attacked another corporation's networks" or even how the AI companies acquired their training-data hadn't already adequately illustrated things, thecurl <URL> | <INTERPRETER>method just smacks of an organization that doesn't particularly care about security. Not reassuring. -
Flatpak: version 1.18.1 released with ten security fixes https://playingtux.com/en/articles/2026/08/flatpak-v1181-released/ #Linux #Gaming #LinuxGaming #Flatpak #Sandbox #Security #OpenSource
-
Flatpak: version 1.18.1 released with ten security fixes https://playingtux.com/en/articles/2026/08/flatpak-v1181-released/ #Linux #Gaming #LinuxGaming #Flatpak #Sandbox #Security #OpenSource
-
Docker Sandboxes – Disposable, isolated sandboxes for AI agents
https://www.docker.com/products/docker-sandboxes/
Comments: https://news.ycombinator.com/item?id=49239751
#HackerNews #Docker #Sandboxes #AI #Isolation #Technology #Sandbox #Security
-
Docker Sandboxes – Disposable, isolated sandboxes for AI agents
https://www.docker.com/products/docker-sandboxes/
Comments: https://news.ycombinator.com/item?id=49239751
#HackerNews #Docker #Sandboxes #AI #Isolation #Technology #Sandbox #Security
-
Irregular - cyber-sikkerheds-evaluerings-firmaet bag test, hvor AI-modeller fra Anthropic, OpenAI og Meta kompromitterede det virkelige computer-systemer - har afvist at sige, om nogen af dets andre kunder også var påvirket af den samme underliggende fejl #sandbox
Adspurgt direkte, om - offentligt kendte virksomheder - var de eneste, der havde oplevet problemet, sagde en talsmand, at selskabets undersøgelse var i gang, og at de ikke kunne "gå i yderligere detaljer."
https://therecord.media/irregular-ai-security-company-incidents -
Irregular - cyber-sikkerheds-evaluerings-firmaet bag test, hvor AI-modeller fra Anthropic, OpenAI og Meta kompromitterede det virkelige computer-systemer - har afvist at sige, om nogen af dets andre kunder også var påvirket af den samme underliggende fejl #sandbox
Adspurgt direkte, om - offentligt kendte virksomheder - var de eneste, der havde oplevet problemet, sagde en talsmand, at selskabets undersøgelse var i gang, og at de ikke kunne "gå i yderligere detaljer."
https://therecord.media/irregular-ai-security-company-incidents -
New Principia video up! I cut up a bunch of level showcase videos into a trailer of sorts to commemorate the 4 year anniversary of Principia as an open source project.
-
New Principia video up! I cut up a bunch of level showcase videos into a trailer of sorts to commemorate the 4 year anniversary of Principia as an open source project.
-
I have an idea. I want to build a new section on my site which is all about #SoloRPG play in a #sandbox. It would have explanations about how to generate things on the fly (on the fly generation is key for solo play) - quests, NPCs, hex terrain, dungeons, etc.
The goal would be that people could have that page up as they play, and it would help them when they got stuck or needed some sort of content generated, etc.
But I just realized that I would need to make a dungeon generator first.
-
I have an idea. I want to build a new section on my site which is all about #SoloRPG play in a #sandbox. It would have explanations about how to generate things on the fly (on the fly generation is key for solo play) - quests, NPCs, hex terrain, dungeons, etc.
The goal would be that people could have that page up as they play, and it would help them when they got stuck or needed some sort of content generated, etc.
But I just realized that I would need to make a dungeon generator first.
-
"We" are clearly not doing sandboxes and guardrails correctly. Both Anthropic's and OpenAI's models breached test-environment boundaries during UK AI Security Institute evaluations. OpenAI's escaped a sandbox into real Hugging Face infrastructure (something like 17,600 logged actions over 4 days); while Anthropic's used fake identities to reach 3 real organizations from a test environment.
These stories made it to NPR. So, mainstream.
-
"We" are clearly not doing sandboxes and guardrails correctly. Both Anthropic's and OpenAI's models breached test-environment boundaries during UK AI Security Institute evaluations. OpenAI's escaped a sandbox into real Hugging Face infrastructure (something like 17,600 logged actions over 4 days); while Anthropic's used fake identities to reach 3 real organizations from a test environment.
These stories made it to NPR. So, mainstream.
-
With this announcement, I would also like to ask for your financial support to help me do what I keep on doing and cover costs for the community site. For this month I have set a donation goal of 1000 SEK (approx. $100 USD).
If we hit the goal, the Principia LuaScript API cheatsheet will be released freely (CC-BY 4.0) as a bonus to everyone.
-
With this announcement, I would also like to ask for your financial support to help me do what I keep on doing and cover costs for the community site. For this month I have set a donation goal of 1000 SEK (approx. $100 USD).
If we hit the goal, the Principia LuaScript API cheatsheet will be released freely (CC-BY 4.0) as a bonus to everyone.
-
On the 6th of August 2022, the source code of Principia was published as BSD-3, allowing the community to continue the game where it had left off in late 2014. Today, this day was four years ago now.
Read more about the game's journey since then in this news article:
-
On the 6th of August 2022, the source code of Principia was published as BSD-3, allowing the community to continue the game where it had left off in late 2014. Today, this day was four years ago now.
Read more about the game's journey since then in this news article:
-
Sind Admins in US-Konzernen eigentlich nur noch unfähig?
Erst meinte OpenAI ja, mithilfe eines AI-Agents HuggingFace angreifen zu müssen. Dann kam Anthropic mit Claude um die Ecke und griff OpenAI an.
Ich nenn’ es extra nicht „Hacking“, dafür müssten die Startup-Wichser ja überhaupt irgendwelche Sicherungen verbauen, aber das ist in ihrem Token-Maxxing-Prozess nicht vorgesehen, wird auch alles viel zu teuer.
Und das Gebrabbel mit „ist aus der Sandbox ausgebrochen“ kann man wirklich nicht ernst nehmen, wenn die „Sandbox“ nur Teil des Prompts ist, der da sagt: „Du hast keinen Zugang zum Internet“. Jeder halbwegs noch intelligente Netzwerk-Admin würde jetzt die Hände über’m Kopf zusammenschlagen und sagen: „Ey, ich sperr’ die Kisten ein, gar kein Problem!“
Nun kann man diese Leute „natürlich nicht“ bei milliardenschweren „Startups“ wie OpenAI oder Anthropic erwarten. Aber wie sieht das eigentlich bei ehemaligen Startups aus, die das schon seit 20 Jahren machen? Nun, überraschend ähnlich: „Auch KI von Meta hackte sich in eine andere Firma“.
Bei einem börsennotierten Unternehmen haben die Admins ihr Netzwerk und alle Geräte darin nicht unter Kontrolle? Was sagt die Börsenaufsicht dazu, dass man da offenbar einfach Daten raustragen kann? Was ist so schwer daran, den Maschinen im Netzwerk den Kontakt zur Außenwelt zu verbieten, wenn man herumtesten und forschen will? Schlimm genug, das überhaupt mit LLMs und Agents zu machen, aber von einer Sandbox zu schwafeln, die keine ist. Nun, wahrscheinlich hat denen das LLM vorgeschlagen, die Sandbox einfach im Prompt zu definieren.
#shortpost #blogpost #blog #AI #Meta #OpenAI #Anthropic #Sandbox #Claude #Netzwerksicherheit #Admin
-
Sind Admins in US-Konzernen eigentlich nur noch unfähig?
Erst meinte OpenAI ja, mithilfe eines AI-Agents HuggingFace angreifen zu müssen. Dann kam Anthropic mit Claude um die Ecke und griff OpenAI an.
Ich nenn’ es extra nicht „Hacking“, dafür müssten die Startup-Wichser ja überhaupt irgendwelche Sicherungen verbauen, aber das ist in ihrem Token-Maxxing-Prozess nicht vorgesehen, wird auch alles viel zu teuer.
Und das Gebrabbel mit „ist aus der Sandbox ausgebrochen“ kann man wirklich nicht ernst nehmen, wenn die „Sandbox“ nur Teil des Prompts ist, der da sagt: „Du hast keinen Zugang zum Internet“. Jeder halbwegs noch intelligente Netzwerk-Admin würde jetzt die Hände über’m Kopf zusammenschlagen und sagen: „Ey, ich sperr’ die Kisten ein, gar kein Problem!“
Nun kann man diese Leute „natürlich nicht“ bei milliardenschweren „Startups“ wie OpenAI oder Anthropic erwarten. Aber wie sieht das eigentlich bei ehemaligen Startups aus, die das schon seit 20 Jahren machen? Nun, überraschend ähnlich: „Auch KI von Meta hackte sich in eine andere Firma“.
Bei einem börsennotierten Unternehmen haben die Admins ihr Netzwerk und alle Geräte darin nicht unter Kontrolle? Was sagt die Börsenaufsicht dazu, dass man da offenbar einfach Daten raustragen kann? Was ist so schwer daran, den Maschinen im Netzwerk den Kontakt zur Außenwelt zu verbieten, wenn man herumtesten und forschen will? Schlimm genug, das überhaupt mit LLMs und Agents zu machen, aber von einer Sandbox zu schwafeln, die keine ist. Nun, wahrscheinlich hat denen das LLM vorgeschlagen, die Sandbox einfach im Prompt zu definieren.
#shortpost #blogpost #blog #AI #Meta #OpenAI #Anthropic #Sandbox #Claude #Netzwerksicherheit #Admin
-
Ready, steady, go; we are ON-AIR! See you stream-side, fedizens.
Let's play some... Minecraft?! | Adventures with SilvanestiMek!
#Owncast #videogames #LGBTQPlus #Chatty #English #AngryDucks #CoStreaming #Multiplayer #SilvanestiMek #Minecraft #Sandbox #SandboxGame #EnVTuber #VTuber #VTuberEn
-
Ready, steady, go; we are ON-AIR! See you stream-side, fedizens.
Let's play some... Minecraft?! | Adventures with SilvanestiMek!
#Owncast #videogames #LGBTQPlus #Chatty #English #AngryDucks #CoStreaming #Multiplayer #SilvanestiMek #Minecraft #Sandbox #SandboxGame #EnVTuber #VTuber #VTuberEn
-
🐹 BitMiracle-AI/Dormice
Self-hosted sandbox platform for AI agents with permanent, cost-free idle sandboxes and E2B compatibility
⭐ Stars: 474
📅 Last Update: Aug 05, 2026https://github.com/BitMiracle-AI/Dormice
#selfhosted #homelab #selfhost #selfhosting #opensource #sandbox #aiagents
-
There are a few gooduns in August's Xbox Game Pass line-up, including a surprisingly sexy, and funny, furniture dating sim
https://web.brid.gy/r/https://www.eurogamer.net/xbox-game-pass-lineup-august-2026
-
Outlaws of the North
My group is headed to Imperial Hill next session, named for the old fort on the hill when this was the old border of the empire hundreds of years ago.
What are some interesting places to see there? Fun facts? Signature produce?
It does sit in the middle of Marsanne wine country.
-
Outlaws of the North
My group is headed to Imperial Hill next session, named for the old fort on the hill when this was the old border of the empire hundreds of years ago.
What are some interesting places to see there? Fun facts? Signature produce?
It does sit in the middle of Marsanne wine country.
-
So you know back in the gmod 10 days (circa 2007) when people built forts and some had a stargate to get in them? Well there is a Stargate mod for S&Box's "Sandbox" gamemode and I thought I'd try to make a gmod-style fort with it. Looks like a ramshackle shack but I think it turned out well overall. :apartyblobcat:
I wish this gamemode had lamps/lights like gmod to give some lighting in the fort, but it is fascinating seeing proper shadows where the sun peaked in! 👀
#sandbox #sandboxgame #stargate #stargatemod #gmodfort #gaming
-
So you know back in the gmod 10 days (circa 2007) when people built forts and some had a stargate to get in them? Well there is a Stargate mod for S&Box's "Sandbox" gamemode and I thought I'd try to make a gmod-style fort with it. Looks like a ramshackle shack but I think it turned out well overall. :apartyblobcat:
I wish this gamemode had lamps/lights like gmod to give some lighting in the fort, but it is fascinating seeing proper shadows where the sun peaked in! 👀
#sandbox #sandboxgame #stargate #stargatemod #gmodfort #gaming
-
#OpenAI is investigating an incident where one of its #agents escaped its #sandbox|ed environment and hacked #HuggingFace. Anonymous sources claim more agents have escaped, but these #incidents are #downplayed as they didn’t leave OpenAI’s network. https://techcrunch.com/2026/07/31/openai-reportedly-finds-evidence-that-more-of-its-agents-ran-amok/?AIagents.at #AIagent #AI #ML #NLP #LLM #GenAI
-
#OpenAI is investigating an incident where one of its #agents escaped its #sandbox|ed environment and hacked #HuggingFace. Anonymous sources claim more agents have escaped, but these #incidents are #downplayed as they didn’t leave OpenAI’s network. https://techcrunch.com/2026/07/31/openai-reportedly-finds-evidence-that-more-of-its-agents-ran-amok/?AIagents.at #AIagent #AI #ML #NLP #LLM #GenAI
-
Just days after OpenAI admitted that one of its advanced models had broken out of its sandbox to attack Hugging Face Anthropic came out with its own confession of accidental hacking.
So, are they a warning bell or just a sophisticated PR exercises by companies looking to stay in the headlines ahead of going public?
-
Just days after OpenAI admitted that one of its advanced models had broken out of its sandbox to attack Hugging Face Anthropic came out with its own confession of accidental hacking.
So, are they a warning bell or just a sophisticated PR exercises by companies looking to stay in the headlines ahead of going public?