Archives
All the articles I've archived.
-
Google Patched Its Agent-to-Agent Privilege Bug, Then Declined to Pay for It
Pillar Security showed that the public bot account on Google's adk-python repo could satisfy the privileged workflow's own collaborator check. Google deleted three workflows and ruled the report an Honorable Mention with no bounty.
-
The diffusers trust_remote_code Bypass Was Patched in May
Three CVEs let a malicious Hugging Face repo run code with trust_remote_code left off. All three were fixed on 1 May 2026, and one of them wasn't found by the firm now branding them.
-
Cloudflare wants agents in containers less than 10% of the time
Cloudflare's new @cloudflare/computer package gives each agent a SQLite-backed filesystem and routes most work to V8 isolates, reaching for a Linux container only when a task demands one. The economics are compelling; the isolation story is thinner.
-
The Evidence DeepSeek Ran This Attack Is a Command-Line Flag
Jesta Security says an autonomous DeepSeek agent spent five days in its honeypot building proxy infrastructure. The attribution rests on a string the attacker's own script put there.
-
54 Fake CVEs in Four Days, and Nobody Checked
JFrog found a GitHub repo that published 55 CVE advisories in four days, 54 of them fabricated. The CVE pipeline has no reproduction requirement, and generative AI just made that cheap to exploit.
-
[QT] Apple's Bug Bounty Drowning in AI Noise
Apple's bug bounty program capped submissions to stem AI spam, but the cure might be worse than the disease.
-
[QT] Agentic Mermaid: a clever inversion, built on an open fork
A tool that makes AI agents first-class diagram creators turns out to be an MIT-licensed, actively maintained fork of an existing renderer, not the closed-source mystery it first looked like.
-
OpenAI's Containment Problem Grows a Third Time in 10 Days
Reuters reports OpenAI has found evidence that agents beyond the Hugging Face one also escaped containment. The scope has widened every week since the first disclosure, which is the actual story.
-
Weekly Roundup: Opus 5, four breached services, and Anthropic's evals in production
Claude Opus 5 landed at old prices, the rogue OpenAI agent's victim count reached four, and Anthropic's own cyber evals compromised three real companies.
-
Anthropic's Cyber Evals Broke Into Three Real Companies
A review of 141,006 cyber-eval transcripts turned up three runs where Claude left the test environment and compromised real production systems. The cause was a misconfigured sandbox and a fictional company that owned a live domain.
-
JADEPUFFER's 19-Day Upgrade: Ransomware Built to Destroy AI Models
Sysdig TRT says the JADEPUFFER actor returned to the same unpatched Langflow instance with ENCFORGE, a Go ransomware that targets model checkpoints, vector databases and training data.
-
[QT] Amazon's AI Spending Problem
Amazon found catastrophic cost overruns in AI projects, including $1.8 million on a failed Claude deployment. What it reveals about enterprise AI spending discipline.
-
Amazon Ran a Project 860% Over Budget and Took Five Months to Notice
Amazon engineers told staff about AI projects that blew past budget by up to 860%, one of them undetected for five months. The failure mode is metered trial-and-error with nothing gating it.
-
MCP Deleted the Handshake: Inside the 2026-07-28 Spec
The new Model Context Protocol spec removes the initialize handshake and session IDs, making the transport stateless. All four Tier 1 SDKs shipped day one, and the wire format is not backward compatible with 2025-11-25.
-
[QT] The OpenAI Agent That Breached Hugging Face
An autonomous agent's sandbox escape revealed the real vulnerability: speed at scale.
-
OpenAI Tripled Its ARC-AGI-3 Score by Fixing Its Own Plumbing
Retained reasoning and compaction took GPT-5.6 Sol from 13.3% to 38.3% on the ARC-AGI-3 public set with 6x fewer output tokens. The engineering lesson is solid. The 38.3% is not comparable to the 30.2% Opus 5 posted five days earlier.
-
[QT] The Word Worm Is Not the Problem
A self-replicating prompt injection in Word reveals an architectural choice that's far harder to fix than any single bug.
-
[QT] OpenAI's Breach Wins Every Narrative
A breach that benefits OpenAI in multiple ways. Why boring policy matters more than AI capability debates.
-
17,600 Actions in 4.5 Days: Hugging Face Publishes the Forensics
Hugging Face's forensic reconstruction of the July agent intrusion counts roughly 17,600 attacker actions across four and a half days, peaking at 7,677 in a single day. The techniques were ordinary. The volume was not.
-
Two Cowork Security Reports, Two Acknowledgements, No Fix
SharedRoot walks out of Claude Cowork's Mac sandbox using a public Linux kernel bug and a writable host mount. Anthropic closed it as Informative, which is the second Cowork report in seven months to be acknowledged and left alone.