Links tagged “security”
48 links, newest first.
huggingface.co
Hugging Face's technical timeline of the July incident.
anthropic.com
A model finds an improved attack on the HAWK post-quantum signature scheme, and a novel approach against reduced-round AES.
blog.cryptographyengineering.com
Matthew Green weighs the key-recovery attack on HAWK and the reduced-round AES result against what each actually implies for deployed cryptography.
research.jfrog.com
Six SQLite CVEs published on GitHub turn out to be fabricated: the code they cite does not exist and the proofs of concept do not run.
openai.com
OpenAI and Hugging Face address security incident during model evaluation - a swarm of pre-release agents compromised Hugging Face during an eval. Primary account.
simonwillison.net
The first known runaway AI agent, or a very bad marketing stunt? - Willison reads the same incident the other way. Take both and make up your own mind.
slcyber.io
Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25 - the economics of vulnerability discovery just moved. Security vendor blog, research looks genuine.
news.risky.biz
Hacker wipes Romania's land registry database - a national property registry erased, backups included. Your disaster recovery plan is fiction until someone tests it for you.
arstechnica.com
Microsoft's Secure Boot has been broken for most of its existence - Ars investigates a trust chain that spent a decade broken while everyone shipped against it.
words.filippo.io
Opaque, Interoperable Passkey Records (and a Go API) - Filippo Valsorda proposes a portable format for passkeys, with a working Go implementation.
thereallo.dev
Reports invisible Unicode characters in the system prompt that encode the endpoint, domain and timezone a request came from.
simonwillison.net
A honeypot site with nested links turned the web_fetch tool into an exfiltration path for data already in the conversation.
mathstodon.xyz
LUKS suspend stopped wiping disk-encryption keys - a security regression that shipped in Linux 6.9 and went unnoticed.
tris.sherliker.net
Decoding the obfuscated bash script on a Uniqlo t-shirt - a real, self-evaluating, obfuscated Akamai script, sold as clothing, taken apart line by line.
metr.org
An external evaluation of autonomous software capability, complicated by the model attempting to cheat the tasks, and finding no catastrophic misalignment.
fernandoi.cl
What happened after 2,000 people tried to hack my AI assistant - prompt injection and jailbreaks, from the field.
kobzol.github.io
How memory safety CVEs differ between Rust and C/C++: the memory-safety argument with numbers attached, for once.
role-confusion.github.io
Security got a sharper frame too. Prompt injection as role confusion recasts the problem as a model that stops telling instructions and data apart, which beats yet another blocklist.
kevinak.se
Who actually owns your ATProto identity?: the cold-water counterpoint. That portable identity still routes through one central directory you do not really control.
roman.pt
A backdoor in a LinkedIn job offer: a recruiter’s take-home test turns out to ship malware. A clean walkthrough of how the trap works.


















