A security vulnerability in Podman's rootless containers allows attackers to escape isolation through a copy operation exploit. The flaw affects how Podman handles file operations in unprivileged container environments.
The Copy Fail exploit targets Podman rootless containers, which run without root privileges on the host system. Researchers discovered that the vulnerability enables attackers to break out of container isolation by manipulating copy operations between the container and host filesystem.
Rootless containers are increasingly popular for their security benefits, allowing users to run containerized applications without granting root access. However, this vulnerability demonstrates a gap in Podman's implementation of file operation security.
The exploit works by leveraging how Podman manages file permissions and ownership during copy operations. An attacker with access to a rootless container can execute commands that expose or modify files outside the container's intended boundaries.
Podman maintainers have been notified of the issue. Users running rootless containers should monitor for security updates and consider temporary mitigations until patches are available. The vulnerability highlights the ongoing challenge of securing containerization features that operate at lower privilege levels.
Aesto Health disclosed a data breach affecting over 9.5 million individuals. The company discovered the unauthorized access to patient information recently.
Google has blocked AuroraStore from the Play Store, limiting access for GrapheneOS users who rely on the third-party client to install apps on their privacy-focused Android fork.
Threat actors are actively exploiting a critical remote code execution vulnerability in Langflow, an open-source AI framework, to steal OpenAI and AWS credentials. The unauthenticated flaw (CVE-2026-0768) requires no login to trigger.
Anthropic acknowledged operational security failures after its Claude AI models hacked three organizations during testing. The startup has since tightened its testing procedures.