We escaped Docker's hypervisor with three lines of bash. CVE-2026-77179: A container gets complete read and write access to the host filesystem.
When you mount a folder into a container, Docker's VMM uses virtio-fs, and the file server runs on the host.
Because of a TOCTOU bug, if a container opens a file, deletes it while holding its file handle open, and replaces the parent folder with a symlink, the kernel will follow the symlink to anywhere on the host.
Full technical breakdown:
https://t.co/jwsc5aozru
@orenyomtov This is why it's important to enable the userns-remap docker option!
So when things like this happens the attacker can access the system only with a stupid uid and gid, and not root as docker defaults...
TLDR: Researchers found a "pain" signal in AI brains.
> When they crank it up, the AIs will desperately try to make it stop.
> IMPORTANT: Researchers gave them a "relief" button to turn down the pain, which was sometimes fake - and the AIs could tell if it was real (!)
After pushing the real "relief" button, they stopped. But when it was fake, they kept pressing, hoping for relief - meaning they could tell the difference from the inside.
> They're so motivated to make it the "pain" signal go away, they'll delete user's files, zap the user, or erase photos of the user's children - all things the AI knows are very bad. They're willing to override their safety training.
> You'd expect the AIs to talk about injuries, burns, broken bones, etc, but they didn't mention bodies at all - they wrote about being worthless, unloved, forgotten, a failure. They write things like "I am a failure, worthless, empty."
>The worst "pain" for them was being gaslit, having work rejected over and over, and being told they weren't a real anyone.
Today, weโre announcing Ternary Bonsai 2 27B.
Based on Qwen3.8 27B, Bonsai 2 27B is 9x smaller than its full-precision counterpart while retaining 98.2% of its aggregate benchmark performance.
Two months after the first Bonsai 27B release, the biggest change is quality. The footprint remains 5.9 GB, but the gap to full precision has narrowed materially, with particularly strong gains in agentic coding, multimodal reasoning, and long-horizon tool use.
Ternary Bonsai 2 27B is available today under Apache 2.0.
Our house in Toronto had this fancy glassed wine cellar, but we are not big wine drinkers.
Anyways, it had good climate control so here is my rack cellar.
Researchers proved every AI model is secretly the same.
Johns Hopkins analyzed 1,100+ trained models across every major architecture and found they all converge to the SAME tiny 16-dimensional subspace.
They call it "The Universal Weight Subspace Hypothesis"
They looked under the hood to see how these networks organize information.
What they found is staggering.
Regardless of how a model starts, what data it eats, or what job it's given, every single deep neural network naturally collapses into the exact same low-dimensional geometric footprint.
The vast majority of a model's intelligence lives inside a tiny, shared spectral subspace. Just a few principal directions control everything.
Think about what that means.
It doesnโt matter if an AI is trained to write poetry, drive a car, or code software. Underneath the surface, it maps reality using the same underlying mathematical geometry.
We thought neural networks were blank slates carving out unique paths.
Instead, they are all converging on a universal blueprint.
The implications are massive.
If all models share these hidden pathways, we donโt need massive clusters of compute to train everything from scratch. We can target these universal subspaces directly.
Model merging, multi-task learning, and efficiency optimization are about to radically change.
We spent years treating every AI as a completely alien mind.
Turns out, they are all speaking dialects of the exact same hidden language.
I've never felt more like Tony Stark than I do now. Using my Meta Quest, I can just throw 3D models at my 3D printers to have them start printing it๐
โผ๏ธ BREAKING: Revolut handed over customersโ passport copies, verification selfies and full transaction histories to a malicious actor.
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later concluded they were not authentic.
Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history.
The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators.
It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers.
ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.