<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sandboxing on VisorCraft News</title><link>https://www.visorcraft.com/news/tags/sandboxing/</link><description>Recent content in Sandboxing on VisorCraft News</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sat, 18 Jul 2026 10:00:00 -0500</lastBuildDate><atom:link href="https://www.visorcraft.com/news/tags/sandboxing/index.xml" rel="self" type="application/rss+xml"/><item><title>LinSync: Sandboxing 200 Plugins with Landlock, seccomp, and bubblewrap</title><link>https://www.visorcraft.com/news/2026/07/linsync-sandboxing-200-plugins-with-landlock-seccomp-and-bubblewrap/</link><pubDate>Sat, 18 Jul 2026 10:00:00 -0500</pubDate><guid>https://www.visorcraft.com/news/2026/07/linsync-sandboxing-200-plugins-with-landlock-seccomp-and-bubblewrap/</guid><description>&lt;p&gt;Running third-party extractors on user files is the kind of feature that looks safe until you read the CVE list for any single one of them, and LinSync&amp;rsquo;s plugin host does exactly that, all day, on documents and images that came from email attachments, cloud drives, and the web, which means the safety of the whole application depends on the safety of binaries we did not write and cannot fully audit.&lt;/p&gt;</description></item></channel></rss>