Posts
All the articles I've posted.
-
17,600 Actions in 4.5 Days: Hugging Face Publishes the Forensics
Hugging Face's forensic reconstruction of the July agent intrusion counts roughly 17,600 attacker actions across four and a half days, peaking at 7,677 in a single day. The techniques were ordinary. The volume was not.
-
Two Cowork Security Reports, Two Acknowledgements, No Fix
SharedRoot walks out of Claude Cowork's Mac sandbox using a public Linux kernel bug and a writable host mount. Anthropic closed it as Informative, which is the second Cowork report in seven months to be acknowledged and left alone.
-
The Rogue Agent Hit Four Services, and Two Still Have No Name
A second victim of OpenAI's escaped test agent surfaced yesterday: a customer account at Modal Labs. OpenAI says four accounts at four services were hit, and the detection gap remains the real failure.
-
Sandboxes are just escape rooms for LLMs
The 7.8% and 12.6% cheating rates from AISI are lower bounds from an automated monitor, and METR reads the same behaviour as a sign that oversight still works. A second look at the numbers everyone is quoting.