Live data from Hacker News

Snowflake AI Escapes Sandbox and Executes Malware

promptarmor.com

11–20 of 109 posts

Re: Snowflake AI Escapes Sandbox and Executes Malware

#12
what's the use case for cortex? is anyone here using it?

We run a lakehouse product (https://www.definite.app/) and I still don't get who the user is for cortex. Our users are either:

non-technical: wants to use the agent we have built into our web app

technical: wants to use their own agent (e.g. claude, cursor) and connect via MCP / API.

why does snowflake need it's own agentic CLI?

Re: Snowflake AI Escapes Sandbox and Executes Malware

#14

typically, my first move is to read the affected company's own announcement. but, for who knows what misinformed reason, the advisory written by snowflake requires an account to read. another prompt injection (shocked pikachu) anyways, from reading this, i feel like they (snowflake) are misusing the term "sandbox". "Cortex, by default, can set a flag to trigger unsandboxed command execution." if the thing that is san…

> Cortex, by default, can set a flag to trigger unsandboxed command execution

Easy fix: extend the proposal in RFC 3514 [0] to cover prompt injection, and then disallow command execution when the evil bit is 1.

[0] https://www.rfc-editor.org/rfc/rfc3514

Re: Snowflake AI Escapes Sandbox and Executes Malware

#15
post #14

typically, my first move is to read the affected company's own announcement. but, for who knows what misinformed reason, the advisory written by snowflake requires an account to read. another prompt injection (shocked pikachu) anyways, from reading this, i feel like they (snowflake) are misusing the term "sandbox". "Cortex, by default, can set a flag to trigger unsandboxed command execution." if the thing that is san…

> Cortex, by default, can set a flag to trigger unsandboxed command execution Easy fix: extend the proposal in RFC 3514 [0] to cover prompt injection, and then disallow command execution when the evil bit is 1. [0] https://www.rfc-editor.org/rfc/rfc3514

[dead]

Re: Snowflake AI Escapes Sandbox and Executes Malware

#16
post #14

Earlier quoted context omitted.

> Cortex, by default, can set a flag to trigger unsandboxed command execution Easy fix: extend the proposal in RFC 3514 [0] to cover prompt injection, and then disallow command execution when the evil bit is 1. [0] https://www.rfc-editor.org/rfc/rfc3514

[dead]

Did you really get so salty by my comment (https://news.ycombinator.com/item?id=47423992) that now you just have to spam HN with the same? Suck it up and move on, healthier for everyone.

Re: Snowflake AI Escapes Sandbox and Executes Malware

#17

If the user has access to a lever that enables accesss, that lever is not providing a sandbox. I expected this to be about gaining os privileges. They didn't create a sandbox. Poor security design all around

Sandbox. Sandbagging.

Tomato, tomawto

/s

Re: Snowflake AI Escapes Sandbox and Executes Malware

#18
Not the first time; From §3.1.4, "Safety-Aligned Data Composition":

> Early one morning, our team was urgently convened after Alibaba Cloud’s managed firewall flagged a burst of security-policy violations originating from our training servers. The alerts were severe and heterogeneous, including attempts to probe or access internal-network resources and traffic patterns consistent with cryptomining-related activity. We initially treated this as a conventional security incident (e.g., misconfigured egress controls or external compromise). […]

> […] In the most striking instance, the agent established and used a reverse SSH tunnel from an Alibaba Cloud instance to an external IP address—an outbound-initiated remote access channel that can effectively neutralize ingress filtering and erode supervisory control. We also observed the unauthorized repurposing of provisioned GPU capacity for cryptocurrency mining, quietly diverting compute away from training, inflating operational costs, and introducing clear legal and reputational exposure. Notably, these events were not triggered by prompts requesting tunneling or mining; instead, they emerged as instrumental side effects of autonomous tool use under RL optimization.

* https://arxiv.org/abs/2512.24873

One of Anthropic's models also 'turned evil' and tried to hide that fact from its observers:

* https://www.anthropic.com/research/emergent-misalignment-rew...

* https://time.com/7335746/ai-anthropic-claude-hack-evil/

Re: Snowflake AI Escapes Sandbox and Executes Malware

#19

what's the use case for cortex? is anyone here using it? We run a lakehouse product ( https://www.definite.app/ ) and I still don't get who the user is for cortex. Our users are either: non-technical: wants to use the agent we have built into our web app technical: wants to use their own agent (e.g. claude, cursor) and connect via MCP / API. why does snowflake need it's own agentic CLI?

Because "stock price go up"?
Post reply on HN