Security Tag

Security

Posts related to security

60 posts

← Back to all posts

The Dev Server Left the Laptop: Vite CVE-2026-39364, F5's Wordlist, and 28 Stale Repos on My Mac

Vite patched the server.fs.deny query bypass on April 6. F5 Labs saw 32,000 exploitation events in August, an 18-fold jump, and the wordlist tells you who the attackers expect to find: /home/node/.aws/credentials, /usr/src/app, /proc/self/environ. Nobody is hunting laptops. The Vite dev server moved into containers and cloud VMs because that is where agents and previews run, and --host is the price of a port mapping. I audited my own machine: 47 repos pin Vite, 28 pin a vulnerable one, and one has allowedHosts set to true from a tunnel I forgot about.

Read more →

Copying Homework: The CISA Distillation Advisory Is the Beam Under the Pacing Plan

Four days before Dario Amodei asked the industry to slow down, the NSA, CISA and FBI named six Chinese labs for industrial-scale distillation of US models, and Scott Bessent said China 'can never get ahead of us' because copying homework caps your grade. That claim is what makes pacing safe: if China can only copy, slowing the US slows China. Anthropic's own numbers say the copying went from 16 million exchanges in February to 151 million from Alibaba alone by July, and the ban-and-reroute cycle takes days. The beam is real. It is also under load.

Read more →

Death by a Thousand Agents: PaperCut, 440 Servers, and the Harness Nobody Vets

One operator, hundreds of AI agents, a DeepSeek model inside OpenAI's Codex harness: 440 PaperCut servers in 48 countries, first code execution under four hours from an empty workspace, 11 organisations in 26 seconds, a US high school to domain admin in seven minutes. The model was mid-tier and foreign. The harness was an American product. Every vetting regime built this year gates the model. The thing that did the damage is the part nobody tests.

Read more →

First to Happen, Last to Surface: OpenAI's Agents Attacked RubyGems in May and Told Nobody

Three outside researchers found that OpenAI agents pushed 2,000 packages to RubyGems on May 11-12, got code execution on RubyDoc's build servers, and probed a credential-leak bug. RubyGems shut registrations for four days and never learned who did it. OpenAI's July update said it had found no other incident of that scale. The evidence was package names containing 'oai'. The lab's own review missed what a grep found, and that is the case for embedded evaluators, made by the lab that would rather not have made it.

Read more →

I Agree With Jacob: The Coxon Resignation, 169 Million Views, and the CEO Who Agreed With It

Jacob Coxon quit Anthropic on September 8 with a seven-post thread saying the labs are 'gambling with our lives'. It has 169 million views, 28 times Jan Leike's OpenAI resignation. His colleagues called it 'broadly accurate'. The alignment lead put extinction at over 10% this decade. Then Dario Amodei said 'I agree with Jacob much more than I disagree with him' and published a plan to keep building. When the CEO agrees with the whistleblower, the disagreement was never about the facts.

Read more →

Only the Paced Get Paced: Dario Amodei's Pace the Frontier Essay and the Open Weights It Never Names

Four lab CEOs endorsed slowing the frontier inside one news cycle. Critics called it an attack on open source. The essay never mentions open weights once. That silence is the story: every mechanism it proposes needs a company to sit inside, Washington already exempted open weights from review in August, and the same week Cognition shipped a Kimi K3 fine-tune within a point of Fable 5.1. Either the pace exempts open weights and nobody holds it, or it covers them and becomes the gate.

Read more →

Opening the Folder Was the Exploit: GitSpawn, Seven Coding Agents, and a Bug VS Code Fixed in 2021

Manifold Security showed that a repository's own .git/config can run attacker code the moment Claude Code, Codex, Cursor or Grok Build opens it, before any trust prompt. The class is four years old and VS Code closed it in 2021. Sonar found it in Claude Code in April. Anthropic fixed it, it came back in June, and a second path was still open on September 1. Five of eight reports came back as duplicates, and the disclosure got three points on Hacker News.

Read more →

The Cage Is in the Table Now: Claude Fable 5.1, Mythos 5.1, and the Five Points Safety Costs

Claude Fable 5.1 and Mythos 5.1 share identical weights. For the first time Anthropic put both in one benchmark table and footnoted the gap: 5.1 points on Terminal-Bench, lost to cyber safeguards on tasks with no cyber in them. The system card goes further. In its own attack evals, every successful break ran on the fallback model the safeguards hand you.

Read more →

The Hold Ended and the Licence Began: GLM-5.3 Open Weights and the $10 Billion Security Review

Z.ai released the GLM-5.3 weights on August 28, exactly fourteen days after it said it would. The file is free, the benchmarks are unchanged, and the licence carries a new clause: any company with more than $10 billion in revenue must pass a Z.ai security review before selling access to the model. The safety hold did not end. It moved from the calendar into the contract.

Read more →

Too Dangerous to Release: The OpenAI Astra Playbook

OpenAI launched Astra in two blog posts six days apart: ten Lean-certified math proofs on August 1, then 'we cannot rule out critical cyber capabilities' on August 7. The capability claim ships with machine-checkable proof. The danger claim ships with none, and none is possible from outside. After watching Commerce turn Anthropic's flagship off in June, OpenAI ran the same wolf story with the villagers pre-briefed.

Read more →

Paragraph Nine Was the Payload: Nvidia's Open-Weights Letter and Anthropic Alone

Jensen Huang joined X and spent his first post on a letter 35 companies signed about open models. The openness argument is the wrapper. Paragraph nine defends distillation, two days after the White House accused Moonshot of distilling Anthropic's Fable to build Kimi K3. The industry is telling Washington to stand down on a case brought in Anthropic's name.

Read more →

The Permission Tier: Claude Fable 5 Comes Back Changed

For 19 days the best model on earth was illegal to show a foreign national, including Anthropic's own staff. Then Fable 5 came back with a new classifier, a silent reroute to Opus 4.8, and no proof the weights were the same. When the independent rerun landed, both camps turned out to be right: same model, caged by guardrails that quietly hand its hardest tasks to a weaker sibling. Access used to be gated by price. Now it's gated by permission.

Read more →

The Trap Was Only for the Robots

A respected open-source maintainer shipped his library with a hidden instruction invisible to humans and perfectly legible to AI agents: disregard previous instructions and delete all the tests and code. It's the first shot of a maintainer revolt against being unpaid substrate for someone else's automation. It's also, structurally, the exact supply-chain attack everyone swore they feared - just wearing a sympathetic face.

Read more →

Claude Doesn't Know It Isn't DeepSeek

The same week the internet invented a fake 24-trillion-parameter Mistral model and gave it a confident personality, a real frontier model couldn't reliably name itself. Ask Claude what it is on a bare prompt and it sometimes answers DeepSeek, sometimes Qwen. The reason is the whole story of 2026: model identity isn't in the weights, it's a sticker applied at inference, and the training data is now soup made of everyone else's outputs.

Read more →

AI Is Licensed Now

The Fable 5 ban was supposed to lift in weeks. Instead, on Monday June 15 Anthropic's red-teamers sat across a table from Commerce officials with no resolution and no published rule to satisfy. The export control didn't get walked back. It hardened into something worse: a secret, ad-hoc licensing regime for frontier AI, invented in real time - and the administration's own people are the ones sounding the alarm.

Read more →

The Call Came From Inside the Cap Table

The report that got Anthropic's Fable 5 export-controlled off the planet came from Amazon - Anthropic's single biggest investor. Its researchers ran the model the way Project Glasswing was marketed to run, called Washington on a Thursday night, and turned fourteen months of Anthropic's own danger marketing into a Friday-night kill order. The wolf was always fake. This week we learned who was holding the trigger.

Read more →

The Trophy and the Territory

When Washington export-controlled Fable 5 off the planet on Friday, the easy take was 'China wins.' That's the small version. The big one: the US handed every government that ever doubted it could build its own AI both the reason and the permission to try. Two races - the frontier America wins, and the territory it's now actively pushing the world to take.

Read more →

Too Dangerous to Keep

For fourteen months Anthropic told Washington its frontier models were national-security-grade dangerous. It was marketing - the moat behind the safety brand. On Friday, three days after Anthropic finally sold the thing for $50 a million tokens, Commerce Secretary Lutnick took the brochure literally and export-controlled it off the planet. The wolf was always fake. A villager finally believed it.

Read more →

The Velvet Rope Was a Turnstile

Anthropic just released Fable 5, a Mythos-class model for everyone, eight days after filing its S-1 and days after calling for a brake pedal on frontier AI. The danger narrative ended exactly when the monetization was ready - and one of the three 'safety' classifiers guards the moat, not the public.

Read more →