Links tagged “research”
32 links, newest first.
anthropic.com
A model finds an improved attack on the HAWK post-quantum signature scheme, and a novel approach against reduced-round AES.
arxiv.org
writing more rules does not make an agent follow them.
quantamagazine.org
Quanta on models reaching answers by odd paths.
research.jfrog.com
Six SQLite CVEs published on GitHub turn out to be fabricated: the code they cite does not exist and the proofs of concept do not run.
blog.cloudflare.com
BGP ORIGIN attribute manipulation and its impact on the Internet - a rarely examined routing attribute, and how it redirects traffic at internet scale.
"Go Home Copilot, You're Drunk": Understanding Developer Responses to Agent-Generated Code Review Comments
arxiv.org
"Go Home Copilot, You're Drunk": Developer Responses to Agent-Generated Code Review - what developers actually reply to review comments written by an agent. The title is the finding.
imperialviolet.org
We have proof automation now - Adam Langley verifies a zstd implementation in Lean. Formal methods just became something you might actually use.
siepr.stanford.edu
On jobs, Stanford's SIEPR brief went looking for the apocalypse. Since 2022, unemployment rose 0.77 points among the most AI-exposed workers, and 0.85 among the least. Developer postings are still growing faster than the rest of the market. New graduates are the real soft spot. The brief's opening foil is Amodei's forecast of 20 percent unemployment, which makes two appearances for him this week.
slcyber.io
Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25 - the economics of vulnerability discovery just moved. Security vendor blog, research looks genuine.
xenaproject.wordpress.com
Models have disproved several open conjectures, including the Jacobian conjecture, with the counterexamples checked formally in Lean.
arxiv.org
AI Writes Faster Than Humans Can Review - 802 developers, 196,000 pull requests, a mandated 2x in throughput, and a review process that did not follow.
scrollprize.org
The Vesuvius Challenge read an entire carbonized Herculaneum scroll for the first time, with imaging and ML. Two thousand years in a furnace, now readable. The rest is below, including how Elden Ring fakes its enemy AI with no ML at all.
danunparsed.com
HackerRank open-sourced its ATS, then scored one resume 90, then 74, then 88 - the instability of AI hiring, demonstrated on itself.
metr.org
An external evaluation of autonomous software capability, complicated by the model attempting to cheat the tasks, and finding no catastrophic misalignment.
queue.acm.org
You Don't Know Jack About Formal Verification - formal methods from a practitioner, minus the folklore.
apertvs.ai
A Swiss foundation model from EPFL, ETH Zurich and CSCS, open in weights, data and method, covering more than a thousand languages.
kobzol.github.io
How memory safety CVEs differ between Rust and C/C++: the memory-safety argument with numbers attached, for once.
role-confusion.github.io
Security got a sharper frame too. Prompt injection as role confusion recasts the problem as a model that stops telling instructions and data apart, which beats yet another blocklist.
gabrielweinberg.com
Not everyone is using AI for everything: usage data from DuckDuckGo’s founder showing adoption is far patchier than the keynote narrative.


















