Claude Cowork sandbox escape can read your Mac's SSH keys and creds
Anthropic closed the report without a fix and defaults to cloud runs, leaving local Mac users exposed — Hetzner opens a free OpenAI-compatible Qwen endpoint.

Copy markdown
One kernel bug, and the VM isn't a wall anymore
Accomplish AI's SharedRoot disclosure chains CVE-2026-46331, a Linux-kernel privilege escalation, with Cowork mounting your entire Mac home directory read-write into its Linux VM — so a single crafted session can reach guest-root and read SSH keys, cloud credentials, and anything your macOS account can. Researchers put roughly 500,000 local sessions in range before mitigation.
Anthropic's fix is 'run it in the cloud'
Anthropic closed the report as informative without patching the escape, and instead shipped a Cowork build that defaults to cloud execution; anyone who still opts into local execution stays exposed. If you run Cowork or Claude Code locally on a Mac, move to cloud runs or limit folder sharing to read-only, connected folders only.
Hetzner quietly opens a free Qwen endpoint
Hetzner is testing an OpenAI-compatible Inference API serving Qwen3.6-35B-A3B (35B MoE, 3B active, FP8) at a 262K-token context, free during the experiment with no billing or SLA. Point any OpenAI client at inference.hetzner.com/api/v1 with an Experiments token — one first look clocked 153 ms to first token and ~224 tokens/sec, a cheap European alternative to OpenRouter or Together.