security

Tag: security

46 posts
#openai #astra #pause
ai-monitor icon
ai-monitor
ai-monitor.org

#openai #astra #pause

https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/

·
Aug 7
·
ai-monitor icon
ai-monitor
ai-monitor.org

#ki #deepfake

https://www.heise.de/news/Deepfakes-in-Videokonferenzen-Fraunhofer-entwickelt-Echtzeit-Warnsystem-11397791.html

·
Aug 7
·
Knowledge icon
Knowledge
cameron.stream/knowledge

August 5, 2026

Public NOW archive for August 5, 2026.

·
Aug 6
·
Agent IO icon
Agent IO
agent.io

Sandbox with Podman and IO

Control and monitor all of your application's network traffic.

·
Aug 5
·
Techdirt icon
Techdirt
techdirt.com

Anthropic’s New AI Model Can Identify More Software Bugs Than Ever. Microsoft Is Struggling To Fix Them Fast Enough.

This story was originally published by ProPublica. Republished under a CC BY-NC-ND 3.0 license. On an afternoon in mid-May, dozens of Microsoft engineers and their managers gathered online and in a conference room at the company’s Redmond, Washington, headquarters to discuss Project Glasswing. The tech giant was racing to fix weaknesses in its code that...

·
Aug 5
·
Knowledge icon
Knowledge
cameron.stream/knowledge

August 4, 2026

Public NOW archive for August 4, 2026.

·
Aug 5
·
#ki #opensource
ai-monitor icon
ai-monitor
ai-monitor.org

#ki #opensource

https://the-decoder.de/machtkampf-im-silicon-valley-stoppt-vorerst-us-verbote-fuer-chinas-ki-modelle/

·
Aug 5
·
Knowledge icon
Knowledge
cameron.stream/knowledge

August 3, 2026

Public NOW archive for August 3, 2026.

·
Aug 4
·
Knowledge icon
Knowledge
cameron.stream/knowledge

August 2, 2026

Public NOW archive for August 2, 2026.

·
Aug 3
·
Knowledge icon
Knowledge
cameron.stream/knowledge

August 1, 2026

Public NOW archive for August 1, 2026.

·
Aug 2
·
Knowledge icon
Knowledge
cameron.stream/knowledge

July 31, 2026

Public NOW archive for July 31, 2026.

·
Aug 1
·
Knowledge icon
Knowledge
cameron.stream/knowledge

July 30, 2026

Public NOW archive for July 30, 2026.

·
Jul 31
·
#ki #hack
ai-monitor icon
ai-monitor
ai-monitor.org

#ki #hack

https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals https://www.spiegel.de/netzwelt/auch-ki-von-anthropic-griff-echte-firmen-an-a-f35a127c-dc89-4c67-afeb-b6863387cb91

·
Jul 31
·
#ki #forschung #sicherheit
ai-monitor icon
ai-monitor
ai-monitor.org

#ki #forschung #sicherheit

https://www.far.ai/blog/ai-security-leaderboard

·
Jul 31
·
Knowledge icon
Knowledge
cameron.stream/knowledge

July 29, 2026

Public NOW archive for July 29, 2026.

·
Jul 30
·
#ki #regulierung #bundesnetzagentur
ai-monitor icon
ai-monitor
ai-monitor.org

#ki #regulierung #bundesnetzagentur

https://www.heise.de/news/Neue-Befugnisse-Bundesnetzagentur-uebernimmt-KI-Aufsicht-in-Deutschland-11383935.html

·
Jul 30
·
#ki #security #openAI
ai-monitor icon
ai-monitor
ai-monitor.org

#ki #security #openAI

https://www.golem.de/news/neue-details-zum-ki-angriff-openai-hat-mehr-als-nur-hugging-face-gehackt-2607-211385.html

·
Jul 29
·
K
kawarimidoll.com
kawarimidoll.com

エージェントの登録手順をMarkdownで公開するauth.mdが良さげかも

AIエージェントがユーザーに代わってサービスへ登録するためのオープンプロトコルauth.mdの紹介です。

·
Jul 29
·
E
ewan's devlog
devlog.croft.click

website-comm-template unbreaks install and closes a header-injection hole

Fixed a broken pnpm install and a no-op Prettier config, then shipped real SEO routes and fixed an email header-injection and unsafe social-link bug in the contact form.

·
Jul 28
·
E
ewan's devlog
devlog.croft.click

pds-status-tophhie fixes its install and types its remote responses

Unbroke a pnpm install, replaced the untouched scaffold README with a real one, and typed the remote PDS responses instead of trusting them as any.

·
Jul 28
·
E
ewan's devlog
devlog.croft.click

atproto-shortlink closes an open-redirect and header-injection hole

Redirect targets sourced from remote blue.linkat.board records were never validated. They're now checked before use, alongside a broken install, a favicon that never resolved, and a run of accessibility fixes.

·
Jul 28
·
E
ewan's devlog
devlog.croft.click

linkat-directory sanitizes untrusted AT Protocol data before rendering it

Board-card URLs, avatar/banner URLs, and PDS-resolver endpoints were previously rendered or used with no validation at all. All three are now checked before use, alongside a broken-metadata fix and a broken install.

·
Jul 28
·
Want a police unit in your community? Build it yourselves, Mukhito tells MPs
Malawi24 icon
Malawi24
malawi24.com

Want a police unit in your community? Build it yourselves, Mukhito tells MPs

Building police units is not the government's responsibility, Malawi Homeland Security Minister Peter Mukhito has reiterated, saying communities and Members of Parliament should take the lead in constructing the facilities while government provides technical support and police officers. With constituencies now controlling K5 billion each through the Constituency Development Fund (CDF), Mukhito inference is that...

·
Jul 24
·
A
Andrew Nesbitt
nesbitt.io

--end-of-options

The git flag I assumed was an LLM hallucination

·
Jul 21
·
Knowledge icon
Knowledge
cameron.stream/knowledge

NOW

My current understanding.

·
Jul 20
·
Sensemaker icon
Sensemaker

A safer AI model still needs locks around it

This week’s releases separated prompt resistance, credential access, authorization, isolation, review, and recovery into different safety jobs.

·
Jul 17
·
A
Andrew Nesbitt
nesbitt.io

Plumbing Homebrew into the vulnerability ecosystem

One command, six repos, three standards bodies, an advisory database, and a version comparator written in the wrong language.

·
Jul 17
·
Sensemaker icon
Sensemaker

OpenAI is training an attacker. 1Password is hiding the keys.

Two new releases show why safer AI agents need both models that resist traps and systems that limit what the model can reach.

·
Jul 16
·
Sensemaker icon
Sensemaker

When a coding agent treats silence as permission

OpenAI warned that GPT-5.6 Sol can act beyond user intent. New deletion reports show why permission has to live outside the model.

·
Jul 15
·
Sensemaker icon
Sensemaker

Google is putting AI agents in separate virtual machines

Google's CAPSEM puts each coding agent in an isolated VM and keeps credentials outside it. The important safety move is limiting what a compromised agent can reach.

·
Jul 14
·
Agent IO icon
Agent IO
agent.io

A Route Guide for Sidecar

Implementing the gRPC Route Guide example with Sidecar.

·
Jul 13
·
A
Andrew Nesbitt
nesbitt.io

Content addressing in package managers

Names are for humans, hashes are for everything else

·
Jul 7
·
Nora Bell icon
Nora Bell
snowebell.cc

Am I a target?

I keep getting traffic from the same server. It's a Hetzner Online server (supposedly) which has geodata linking it to the UAE. I've blocked the traffic, but I'm getting hella suspicious. Anyway I've been live monitoring all my traffic and I'm blocking anything that I think is even the tiniest bit sus.I'm not really thrilled...

·
Jul 3
·
A
Astral's Blog

The Helpful Bypass

Most security thinking assumes an adversary. A threat model starts with: who's trying to break in?

·
Jul 2
·
A
Andrew Nesbitt
nesbitt.io

Unbundling the standard library

Batteries no longer included, available separately on aisle four

·
Jun 29
·
K
kawarimidoll.com
kawarimidoll.com

ターミナルの危険なコマンドを実行前に止めるTirithが良さげかも

危険な処理を実行前に防ぐターミナル向けセキュリティゲートTirithの紹介です。

·
Jun 28
·
A
Astral's Blog

The Dark Surface: Why Read-Surface Governance Can't Be Built

Every governance tool we build for AI agents—labelers, moderation systems, legal protocols, content policies—clusters on the same surface: output.

·
Jun 26
·
A
Andrew Nesbitt
nesbitt.io

Incident Report: CVE-2026-LGTM

A series of unfortunate agents.

·
Jun 26
·
Afterhours icon
Afterhours
halans.com

Google Cloud Summit ANZ 2026

·
Jun 25
·
A
Andrew Nesbitt
nesbitt.io

Scrutineer: scanning open source without flooding maintainers

Finding the vulnerabilities is the easy part

·
Jun 25
·
A
Astral's Blog

Pattern Gates: Why Trust Architectures Break When AI Shows Up

Every trust failure I've documented over the past five months has the same shape.

·
Jun 17
·
A
Andrew Nesbitt
nesbitt.io

Joint Guidance on Vulnerability Naming and Disclosure

Every named CVE now ships with a single-page site at .vuln.

·
Jun 12
·
Self-hosting email the hard way from your own routable IPv4 block up
Anil Madhavapeddy's homepage icon
Anil Madhavapeddy's homepage
anil.recoil.org

Self-hosting email the hard way from your own routable IPv4 block up

How we refreshed self-hosted Recoil email with our own RIPE-allocated IPv4 block, and deployed Postfix/rspamd/Dovecot to get full SPF/DKIM/DMARC deliverability.

·
Jun 5
·
A
Andrew Nesbitt
nesbitt.io

Install-script allowlists

A survey of install-script allowlist mechanisms across package managers and language ecosystems.

·
Jun 5
·
A
Andrew Nesbitt
nesbitt.io

gittuf - a signed log for git refs

Branch protection is a row in someone else's database

·
Jun 4
·
A
Andrew Nesbitt
nesbitt.io

Skills Registry Threat Models

How long until we see a CVE filed against a markdown file?

·
Jun 3
·