cyberpunk is upon us!
tldr: models are becoming better and better hackers, whether you want it or not, and until we find and patch most not-yet-discovered vulns it's gonna be fun times
https://www.youtube.com/watch?v=1sd26pWhfmg
see also: ctf-agent takes 1st place on BSides SF 2026 CTF
https://github.com/verialabs/ctf-agent
tldr: models are becoming better and better hackers, whether you want it or not, and until we find and patch most not-yet-discovered vulns it's gonna be fun times
https://www.youtube.com/watch?v=1sd26pWhfmg
see also: ctf-agent takes 1st place on BSides SF 2026 CTF
https://github.com/verialabs/ctf-agent
YouTube
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
Nicholas Carlini, Research Scientist, Anthropic, speaks at [un]prompted 2026 on: Black-hat LLMs.
Large language models are now capable of automating attacks that were previously only possible by human adversaries. In this talk, I discuss several ways that…
Large language models are now capable of automating attacks that were previously only possible by human adversaries. In this talk, I discuss several ways that…
😱1
PSA: npm axios package has been hacked, unlike LiteLLM if you do frontend you probably DO use it;
npm pins package version by default but at least def dont
bun has
https://x.com/feross/status/2038807290422370479?s=46
npm pins package version by default but at least def dont
npm i axios rn.bun has
minimumReleaseAge; also i've arrived at radical golang-style dependency vendoring via npm pack if I don't foresee them updated oftenhttps://x.com/feross/status/2038807290422370479?s=46
X (formerly Twitter)
Feross (@feross) on X
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer…
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer…
👾1
noninvasive deep brain stimulation! aka computer -> brain side of the interface!
https://www.nature.com/articles/s41467-026-70346-x
https://www.nature.com/articles/s41467-026-70346-x
Nature
Multimodal evidence for hippocampal engagement and modulation by functional connectivity-guided parietal TMS
Nature Communications - Noninvasive hippocampal modulation is key for addressing hippocampal dysfunction. Using multimodal brain recordings, the authors show that personalized connectivity-guided...
🔥2🎉2
i think this can be upgraded all the way to the infinite-context models
https://microsoft.github.io/memento/blogpost/
https://microsoft.github.io/memento/blogpost/
microsoft.github.io
Memento: Teaching LLMs to Manage Their Own Context
Memento teaches language models to manage their own context by segmenting reasoning into blocks, compressing each into a dense memento, and reasoning forward with sharply lower KV cache usage.
❤1
psa: Vercel just had a major security incident; better to consider sensitive env vars in deployments leaked
https://vercel.com/kb/bulletin/vercel-april-2026-security-incident
https://vercel.com/kb/bulletin/vercel-april-2026-security-incident
Vercel
Vercel April 2026 security incident | Vercel Knowledge Base
We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems.
😱1
TLDR: No need to beg for the Mythos access, you can find zero-day vulnerabilities with today's open models just fine too.
https://arxiv.org/abs/2604.20801
https://github.com/berabuddies/agentflow
https://arxiv.org/abs/2604.20801
https://github.com/berabuddies/agentflow
arXiv.org
Synthesizing Multi-Agent Harnesses for Vulnerability Discovery
LLM agents have begun to find real security vulnerabilities that human auditors and automated fuzzers missed for decades, in source-available targets where the analyst can build and instrument the...
⚠️ PSA: BitWarden CLI compromised in ongoing supply chain attack campaign
https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
👾1
how coding agents might just unlock a whole new sphere of creativity
https://andymatuschak.org/tat/
https://andymatuschak.org/tat/
To invent a new user interface, you need both imaginative design skill and fluent technical skill. Very few people possess both. ... also requires deep domain insight. I think of Steinberg inventing the timeline editor in Cubase after years as a musician and producer, or Bricklin inventing the dynamic spreadsheet while at Harvard Business School.
andymatuschak.org
Apps and programming: two accidental tyrannies
On coding agents, malleable software, and the future of interface invention
https://copy.fail/ ahem. do tell your sysadmin. any-linux privilege escalation, docker escape in many configurations too. fun times!
Xint
Copy Fail — 732 Bytes to Root
CVE-2026-31431. 100% Reliable Linux LPE — no race, no per-distro offsets, page-cache write that bypasses on-disk file-integrity tools and crosses containers. Found by Xint Code.
😱2
this is getting boring, but
PyPi lightning 2.6.2/2.6.3 (a dependency of pyannote-audio, you maybe use it if you do speech recognition) and npm intercom-client 7.0.4 compromised (maintainers hacked)
PyPi lightning 2.6.2/2.6.3 (a dependency of pyannote-audio, you maybe use it if you do speech recognition) and npm intercom-client 7.0.4 compromised (maintainers hacked)
😢1
interesting writeup on inference economics
tldr it doesn't scale as good as "regular web services" where it's possible but hard to get to 80-90% utilization, and is more like 40-50% even with an idealized load
https://www.anjalishriva.com/fat-tails
tldr it doesn't scale as good as "regular web services" where it's possible but hard to get to 80-90% utilization, and is more like 40-50% even with an idealized load
https://www.anjalishriva.com/fat-tails
Anjalishriva
Why fat tailed costs emerge at scale
High variance breaks unit economics and threatens scale
Linkstream
https://copy.fail/ ahem. do tell your sysadmin. any-linux privilege escalation, docker escape in many configurations too. fun times!
one more vulnerability https://github.com/V4bel/dirtyfrag
GitHub
GitHub - V4bel/dirtyfrag
Contribute to V4bel/dirtyfrag development by creating an account on GitHub.
😱2
nice way to reduce port conflicts.
i also use unix sockets for that, where the servers/clients support them (eg Golang ones)
https://portless.sh
i also use unix sockets for that, where the servers/clients support them (eg Golang ones)
https://portless.sh
portless
portless | Named .localhost URLs for Development
Replace port numbers with stable, named .localhost URLs. For humans and agents.
👀1
nice writeup on speeding up model loading
https://modal.com/blog/truly-serverless-gpus
https://modal.com/blog/truly-serverless-gpus
🏆1
cloudflare confirms mythos is a harness, not just a model
https://blog.cloudflare.com/cyber-frontier-models/
https://blog.cloudflare.com/cyber-frontier-models/
Cloudflare Blog
Project Glasswing: what Mythos showed us
In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it…
🤔3
I am quite optimistic about AI empowerment, and one observation of George Hotz I definitely agree with -- /everything/ now depends on your ability to see if the agent has produced slop, and the habit to ruthlessly reject it.
The slop percentage is very high, 30-90%.
https://geohot.github.io//blog/jekyll/update/2026/05/24/the-eternal-sloptember.html
The slop percentage is very high, 30-90%.
https://geohot.github.io//blog/jekyll/update/2026/05/24/the-eternal-sloptember.html
the singularity is nearer
The Eternal Sloptember
I’m calling it now, the adoption of AI agents into software development will be one of the most costly mistakes in the field’s history. Agents cannot program, and it’s taking longer and longer to realize that they can’t. They are a highly sophisticated statistical…
❤4🥴1