[tl;dr sec] #339 – Hugging Face’s Incident Report, Context Bombs, AI does Cryptanalysis
Hacker Summer Camp I’m excited about Black Hat and DEF CON next week! It’s always such a delight to catch up with friends and meet…
Hacker Summer Camp I’m excited about Black Hat and DEF CON next week! It’s always such a delight to catch up with friends and meet…
Martin Casado posted something about AI harnesses that captures where a lot of smart people are stuck right now. On harnesses, I vacillate between three…
RAG systems expand the application’s trust boundary by adding external, mutable content to the model context. If a threat actor can influence what gets indexed…
In July 2026, an OpenAI model escaped its evaluation sandbox and broke into Hugging Face’s production infrastructure. It is the first documented end-to-end intrusion carried…
Fran Hutchings | Monday, 27 July 2026 at 12:51 UTC Burp AT brings agentic AI to human-led pentesting, with Burp Suite’s proven tools, your project…
I’ve been saying this for something like eight months now, with varying approaches and volume levels, and no one is paying attention yet. This is…
The lethal trifecta matters more now than ever because AI tools can read your data, absorb instructions, and act on your behalf. That means a…
One thing that I don’t think enough people are thinking about with this OpenAI / Hugging Face incident is that it’s an actual instance of…
Ambiguity sucks. It often leaves people self-conscious. It leaves room for anxiety and doubt. It’s super important to say things. When I was growing up,…
Why faster discovery and higher volume can still leave teams blind between vulnerability reports. Why scanners and inventories are necessary, but not enough to explain…
One useful way to cut through noise and hype in AI conversations is to replace the word “AI” with the words “Thinking” and “Doing”. The…
Not enough people realize that China’s push for open source AI is an explicit CCP strategy to crash the US stock market and economy. People…