{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_c5cbc857da51cc95873dfd95dccdc2ab103c58ebd83407941ac7f7027986c149","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_c5cbc857da51cc95873dfd95dccdc2ab103c58ebd83407941ac7f7027986c149","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"c96be847291027546bd68291c7bb5f41cfcb154aa5296413dab55c77aeecea10","published":"Wed, 15 Jul 2026 00:00:00 -0400","receipt_hash":"c96be847291027546bd68291c7bb5f41cfcb154aa5296413dab55c77aeecea10","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"c96be847291027546bd68291c7bb5f41cfcb154aa5296413dab55c77aeecea10","observed_at":"2026-07-15T04:44:03.592429Z","parent_run_hash":"d49a6cf532e74153266f377b7760fc948d950d80ed41fc3e3eb82b58f5597ead","published":"Wed, 15 Jul 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2607.12723v1 Announce Type: cross \nAbstract: Filesystem isolation in container ecosystems is often weakened by cross-boundary path misresolution, causing path traversal (PaTra) vulnerabilities. These vulnerabilities stem from insecure host-container interactions and have become increasingly pervasive as cloud systems mount shared resources, such as GPUs and agent workspaces, into containers to support AI workloads. Existing defenses remain inadequate. Kernel-level protections are intrusive, can destabilize system calls, and have therefore not been accepted into the Linux mainline. Detection methods rely on static rule matching or manual code auditing. Static rules can flag path-related functions but fail to capture the semantics needed to determine whether a host-container interaction exists, causing many false positives. Manual review requires domain expertise, making it costly, inefficient, and difficult to scale.\n  To address this threat, we present Bulkhead, an automated fram","title":"Bulkhead: Automated Semantic Detection and Remediation of Container Escape Vulnerabilities","url":"https://arxiv.org/abs/2607.12723","vendor":"arxiv_cs_ai"},"summary":"arXiv:2607.12723v1 Announce Type: cross \nAbstract: Filesystem isolation in container ecosystems is often weakened by cross-boundary path misresolution, causing path traversal (PaTra) vulnerabilities. These vulnerabilities stem from insecure host-container interactions and have become increasingly pervasive as cloud systems mount shared resources, such as GPUs and agent workspaces, into containers to support AI workloads. Existing defenses remain inadequate. Kernel-level protections are intrusive, can destabilize system calls, and have therefore not been accepted into the Linux mainline. Detection methods rely on static rule matching or manual code auditing. Static rules can flag path-related functions but fail to capture the semantics needed to determine whether a host-container interaction exists, causing many false positives. Manual review requires domain expertise, making it costly, inefficient, and difficult to scale.\n  To address this threat, we present Bulkhead, an automated fram","title":"Bulkhead: Automated Semantic Detection and Remediation of Container Escape Vulnerabilities","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-07-15T04:44:03Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2607.12723"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:8f561193a3137487ce23696bfb95d0986fdb7db7685ad2d03051c16eb277c5d88d50713152eb640c189740f1fdb15d973777bd94081fac5727d7512bc337eb05","signer":"crovia.substrate","subject":{"observed_at":"2026-07-15T04:44:03Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2607.12723"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"3dbd8a9c12bc4e74f2963931ed3e4547d710331cf5cc16af8f03871006ae9d29","leaf_index":316491,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"12d08ae98956ece05e41992802c03d50acc3a47285ff0d1471c7cb8cd8d04a8d","side":"left"},{"sibling":"82124eda72a0b674307313ad48b8487bbf890e80c7ece2c71df7cf8c0c6eba41","side":"left"},{"sibling":"0cf49d8754fe4c8cd04aeb9a602a05f8c7db2663ec6cb6cb5ce4d4653392b80a","side":"right"},{"sibling":"f93319b4081b40e308b687e67adbf02d575e3a6e22cf4a10ea93b41bbaf2128d","side":"left"},{"sibling":"80374a188ef4b438d17d48e691cb7d59dd428dd84f9781a41f4938e06ef913b3","side":"right"},{"sibling":"71093330df11a61846ce241fed3c9ef1545532e993f39e3bf6c938868a1c905d","side":"right"},{"sibling":"5436dbbae79dbce31676274ba50aef18052108604eec1fa3a36023d740b2cf09","side":"left"},{"sibling":"c07de1952926cdb34af34c5c0baaf9021a0ab704be6665431e37a7c145fca4d5","side":"right"},{"sibling":"1c7f1bf97993e3a126824f8350788b168c4c13264fb03a73b3ede312035d3527","side":"right"},{"sibling":"84a7590e6b24dd07ed46597f19deb75d9ad247b4227b17f30857ec7cc0fc5c21","side":"right"},{"sibling":"c8d3d8cb0183b912107f9781ad2a1b6c0c9424906c5907c09deeb5bea9d7b571","side":"left"},{"sibling":"0cb62c0ada57a2406a6bcb100889d3e8b29a15efeed07adaff5bb90a5e80612a","side":"right"},{"sibling":"0b69289b25462ddd6166f6f49004cfc8ada0ab4f10adafe188347817bdd46e37","side":"left"},{"sibling":"1418b281cd985b5ed411ef25f2017a1826cc14919b6fad3934e6ceeec693699b","side":"right"},{"sibling":"f302542c38ba7c3aab7c9280dd60259ecec777dca6e6f71b6f0729b0b8791b72","side":"left"},{"sibling":"d8b9143917b539c543cf4448cec00131f8b807bd8004979c54ebe09798748c66","side":"left"},{"sibling":"abe4a8c706e530484d1e96a8988cb09eab85928b2050985500ab289753fe3eec","side":"right"},{"sibling":"f436dccf82aa2c1eb7bfa3eb84316e116aaf64dc55cd9592597118f6cb0648f6","side":"right"},{"sibling":"1cecb7f447febd025aac272837c80de218aecc6485d2395a509b2a1f1b9c746e","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":316730,"merkle_root":"a8e6e5be81ea6f5b5f2227422459bf39455fe9f0b6602b4d1ce6977dbfd78bc7","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260715T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-07-15T05:38:24Z","sig_algorithm":"ed25519","signature":"df1678d268b5a07413e2ca6e748c3f40b6cfedea930a18d843489a4ab513da791bf0a886caab1b918d0989f8ebaaf3d0035ca2aa777913b1ad29979f1deb9a0c","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_c5cbc857da51cc95873dfd95dccdc2ab103c58ebd83407941ac7f7027986c149"}}