Lobster Roll

Stories by eyberg

Triaging security issues reported by third parties (gitlab.gnome.org)
Kees Cook Account Disabled for Suspected Malicous Activity (lore.kernel.org)
Reflections on Unikernels (dave.recoil.org)
oss-security - runc container breakouts via procfs writes: CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 (openwall.com)
Unikernels Can Fulfill the DevOps Promise (dzone.com)
Nanos is Now Open Source (github.com)
Remote Root to GCP (github.com)
container breakout through process.cwd trickery and leaked fds (github.com)
The big idea around unikernels (changelog.com)
Nanos.org (nanos.org)
oss-sec: Three bypasses of Ubuntu's unprivileged user namespace restrictions (seclists.org)
OPS - Easily Build and Run Unikernels (ops.city)
KeyDB and the Tao of the Unikernel (dzone.com)
GPU-accelerated Computing with Nanos Unikernels (nanovms.com)
Hacking Unikernels Through Process Injection [A Step by Step Guide] (hackernoon.com)
oss-security - [kubernetes] Multiple issues in ingress-nginx (openwall.com)
DragonOS龙操作系统 – 开源,面向未来 (dragonos.org)
Unikernel Guide: Build & Deploy Lightweight, Secure Apps (tallysolutions.com)
Closures in the Nanos Unikernel (nanovms.com)
Nanos 0.1.20 has Initial T2 (xen) Support (github.com)
Local information disclosure in apport and systemd-coredump (qualys.com)
Wiz Research discovers ExtraReplica, a cross-account database vulnerability in Azure PostgreSQL (wiz.io)
ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough | Wiz Blog (wiz.io)
Creating a VPN Gateway with a Unikernel running WireGuard (nanovms.com)
Profiling and Tracing the Nanos Unikernel (nanovms.com)
Autonomous Rust Unikernels in Google Cloud (nanovms.com)
Deploying Nanos Node.JS Unikernels to AWS (nanovms.com)