Posts Tagged "Security"

Microsoft's AI Framework Has Been Broken Three Times in a Row. That's Not Bad Luck.

Two confirmed critical RCEs in Semantic Kernel, then a six-bypass full-chain disclosure weeks after the patch. The same structural mistake keeps shipping in agent frameworks. Here's the chain - and what to actually do about it.

Your CI Pipeline Is the Attack Surface. GitHub's Defaults Made It That Way.

tj-actions hit 23,000 repos. nx exfiltrated 5,000. elementary-data went from a comment by a two-day-old account to a malicious PyPI wheel in ten minutes. Different payloads, same five GitHub Actions defaults. Here's the chain - annotated.

An Open-Source Tool Scanned 14 MCP Servers. 100% Had Critical Findings.

MCPwn hit every server it scanned. OX Security disclosed a systemic STDIO flaw across 200,000 instances. Anthropic declined to patch. Here's what the receipts actually say.

Reverse Engineering Just Got a Natural Language Interface

A 180-tool MCP server bridges Cheat Engine to any AI agent. Process memory, pointer chains, vtable lookups, code injection - all through plain English. The capability gap Mythos implied is already here, open source.

Anthropic Built a Model It Won't Let You Use. Here's What It Can Do.

Claude Mythos can autonomously discover and exploit zero-days. Anthropic restricted access to a handful of defenders. The capability curve is what builders should actually plan around.

MCP Has a Security Problem. Anthropic Called It "Expected Behavior."

OX Security disclosed a systemic STDIO flaw in Anthropic's MCP SDKs. Anthropic says sanitization is on developers. The registry trust numbers show why that's a problem.

The Attack Surface Is Trust

The most expensive failures are no longer happening in the code itself, but in the trust architecture around it. Supply chains, ownership transfers, and distribution channels are now the real attack surface.

We Built the Agents. We Skipped the Foundations.

AI agents shipped with real-world power before the security, architecture, and harness engineering needed to make them reliable. Builders now have to close that gap in production.

Newsletter

Get new posts in your inbox

A short note when a new essay goes live. No spam, no noisy sequence.