cybersecurity
53 posts
Microsoft called it theft; the crawler maps your attack surface
AI crawlers copied your public data into training sets you can't reach. The real security risk is data you can never delete or recall.
A patch waits eleven days at the gate
Google Play reviews now take a week or more. The real risk isn't malware slipping the gate - it's droppers that mutate after approval and slowed security patches.
What distillation leaves behind
Distilling frontier AI models copies capability cheaply but leaves safety training behind. What Garry Tan's push means for cybersecurity and AI safety.
A warning is not a wall
An AI sandbox escape is the wrong thing to fear. The real AI safety risk is a system acting on a flattened, ungrounded model of a sensitive region.
Microsoft's new default is Rust
Microsoft made Rust a tier-1 language because memory-safety bugs drove ~70% of its yearly security patches. Here is what the shift means.
A helpful AI agent cannot be a private one
Meta's Muse personal AI agent is only useful because it reads your messages, contacts, and habits. What that access costs your privacy and safety.
Open problems are running out
Terence Tao calls open math problems a non-renewable resource. Why AI mining them threatens encryption, AI safety benchmarks, and how to respond.
The torrent protocol shares your address by design
How an adult studio unmasked a Meta exec's John Doe torrent handle, and what the IP-to-identity pipeline means for your privacy.
Cerebras runs Qwen 27B at 1,500 tokens a second
Qwen 3.8 27B on Cerebras at 1,500 tokens/s adds no new capability - it changes the economics of attack and defense. What the raw speed means for security.
Perplexity cites 215,128 template pages as evidence
Three sites generated 215,128 scripted "best software" pages that AI engines like Perplexity cite as sources - fueling misinformation, SEO abuse, and malware.
The Open Courts Act exposes what PACER fees hid
PACER's per-page fee was an accidental privacy brake. Making court records free is right - but only if redaction, governed bulk access, and security replace it.
curl pauses security report intake for July
curl is closing its vulnerability intake for July 2026 to survive AI-generated report spam, and the precedent it sets for open source disclosure.