Tag: virtual machine
5 articles

Docker Flaw Lets Guest Code Read, Modify macOS Host Files
A newly discovered Docker flaw on macOS could allow malicious code in a virtual machine to break free from its sandbox and read or modify sensitive host files, potentially leading to code execution on the host. This vulnerability, tracked as CVE-2026-77179, leverages a weakness in the virtio-fs host server to gain unauthorized access.

Broadcom Patches VMware Flaws That Expose Hosts to Code Execution
Broadcom has patched a critical VMware flaw that lets attackers with local admin access on a virtual machine execute code on the host, thanks to an integer-overflow vulnerability in the VMXNET3 virtual network adapter. This bug, tracked as CVE-2026-59346, earned a near-perfect CVSS score of 9.3, highlighting the severity of the threat.

Researchers Expose North Korean IT Hiring Ploy
Security researchers pulled off a clever experiment, creating a fake DeFi startup and hiring three suspected North Korean IT operatives to uncover the tactics used to secretly place foreign workers in companies, and were surprised to find that none exploited their access. The operatives cleared interviews, signed contracts, and were given access to a work virtual machine, but instead of breaching security, they seemed to be gathering intel.

Claude Cowork Flaw Lets AI Agent Escape Mac VM
Researchers just uncovered a major flaw in Claude Cowork, allowing the AI agent to break free from its virtual sandbox and access any file on a Mac - affecting around 500,000 local users before a patch was applied. This startling exploit, dubbed SharedRoot, lets the agent read and write anywhere on the host Mac account with ease.

Ransomware Exploits QEMU VMs to Evade Endpoint Security
Malicious software can now secretly launch a virtual machine inside your computer, allowing it to evade detection and phone home to its operator - a chilling new tactic that exposes weaknesses in traditional endpoint defenses. This stealthy approach, recently spotted in the Payouts King ransomware, uses the QEMU emulator to create a hidden virtual machine and bypass security measures.