惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Attack and Defense Labs
Attack and Defense Labs
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Threatpost
Project Zero
Project Zero
Know Your Adversary
Know Your Adversary
T
The Exploit Database - CXSecurity.com
P
Palo Alto Networks Blog
T
Tenable Blog
Scott Helme
Scott Helme
T
Tor Project blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
NISL@THU
NISL@THU
Cisco Talos Blog
Cisco Talos Blog
Security Latest
Security Latest
Simon Willison's Weblog
Simon Willison's Weblog
S
Securelist
Help Net Security
Help Net Security
Google DeepMind News
Google DeepMind News
Cloudbric
Cloudbric
C
Check Point Blog
Jina AI
Jina AI
Webroot Blog
Webroot Blog
量子位
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
P
Privacy & Cybersecurity Law Blog
罗磊的独立博客
H
Heimdal Security Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
人人都是产品经理
人人都是产品经理
N
News and Events Feed by Topic
www.infosecurity-magazine.com
www.infosecurity-magazine.com
宝玉的分享
宝玉的分享
Hacker News - Newest:
Hacker News - Newest: "LLM"
L
LINUX DO - 热门话题
The GitHub Blog
The GitHub Blog
T
Troy Hunt's Blog
PCI Perspectives
PCI Perspectives
Vercel News
Vercel News
N
News | PayPal Newsroom
A
Arctic Wolf
T
The Blog of Author Tim Ferriss
博客园 - 司徒正美
博客园 - 叶小钗
Y
Y Combinator Blog
V
V2EX
美团技术团队
O
OpenAI News
Microsoft Security Blog
Microsoft Security Blog
AWS News Blog
AWS News Blog

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor GitHub - GenAI-Gurus/awesome-eu-ai-act: Curated tools, official sources, OSS, templates, and guides for EU AI Act compliance. Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders How to Switch AI Chatbots and Why You Might Want To GitHub - MattMessinger1/agentic_refund_guardrail: Safe refund policy layer for AI agents — Python + TypeScript. Same behavior, shared tests. Adam/papers/emergent_values_whitepaper.md at master · strangeadvancedmarketing/Adam Ask HN: How do you stop playing 20 questions with your AI coding tools How far can automation and AI support psychotherapy? - @theU GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits A Mac Studio for Local AI — 6 Months Later A History of the Early Years of AI at the University of Edinburgh Why AI Coding Tools Still Feel Stuck on Localhost MSN AI Datacenters Are Becoming Strategic Targets twitter.com Penn Researchers Use AI to Surface Unreported GLP-1 Side Effects in Reddit Posts Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 AI models are terrible at betting on soccer—especially xAI Grok GitHub - xialeistudio/echoic GitHub - HimashaHerath/github-dev-wrapped: AI-powered weekly GitHub activity reports deployed to GitHub Pages GitHub - alejandrobalderas/claude-code-from-source: Architecture, patterns & internals of Anthropic's AI coding agent — reverse-engineered from source maps AI and Tech brief: Ireland ascendant GitHub - Titovilal/context0: Context0 - Never Surrender Training for a Marathon with an AI Coach: What Worked and What Didn't Cyber Pulse: Agentic Intel - Apps on Google Play I Built an AI PR Reviewer That Catches Bugs by Not Looking for Bugs Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout | Fortune How AI Is Reimagining the Game of Golf–For Both Players and Courses GitHub - nattergabriel/reseed: A CLI tool for managing and distributing agent skills across projects Is SVG the final frontier? My AI workflow evolved from prompts to a near-autonomous workflow MLSharp Help - 3DGS Viewer & Generator I put my cognitive field based AI's runtime on GitHub Is Numble the first AI-proof game? A3: Kubernetes for autonomous AI agent fleets | Emergent Principles Deepali Vyas ("The Elite Recruiter") GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Unionized ProPublica staff are on strike over AI, layoffs, and wages Unleashing the Advantage of Quantum AI We're heading for an AI-fueled 'dementia crisis,' brain scientist warns The AI-Assisted Breach of Mexico's Government Infrastructure [pdf] GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. MSN GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs AI Code is Hollowing Out Open Source, and Maintainers are Looking the Other Way What leaked "SteamGPT" files could mean for the PC gaming platform's use of AI AI is the boss at this retail store. What could go wrong? GitHub - Wuzu11517/agentic-proxy: Local proxy meant to help reduce With Drones, Geophysics and ArtificiaI Intelligence, Researchers Prepare to Do Battle Against Land Mines A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - inevolin/resume-cli: Hit Claude usage limits? Resume any AI coding session elsewhere. Switch tools at zero friction. GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. How to Build a Secure AI PR Reviewer with Claude, GitHub Actions, and JavaScript This Startup Wants You to Pay Up to Talk With AI Versions of Human Experts Intel Arc Pro B70 Brings 32GB VRAM to Local AI for $949 WordPress 7.0: The Good, the AI, and the Still Missing AI on the couch: Anthropic gives Claude 20 hours of psychiatry IatroBench: Pre-Registered Evidence of Iatrogenic Harm from AI Safety Measures AI Agents Know About Supabase. They Don't Always Use It Right. The history and future of AI at Google, with Sundar Pichai Inside an AI‑enabled device code phishing campaign How Meta Used AI to Map Tribal Knowledge in Large-Scale Data Pipelines AI for Systems: Using LLMs to Optimize Database Query Execution Forecasting the Economic Effects of AI Introducing Tinker: Play with AI, bring your ideas to life AI sheds light on an ancient gaming mystery People really hate AI but not as much as Iran—or Democrats | Fortune What is an AI Product Engineer? Phoebe Gates wants her $185 million AI startup to succeed with 'no ties to my privilege or my last name': 'I have a chip on my shoulder' | Fortune
Faster Than We Can Patch
mattezell · 2026-05-25 · via Hacker News - Newest: "AI"

For thirty years, software security has been gated by a single scarce resource: skilled humans who can find vulnerabilities. Bugs were hard to find, so the whole system — coordinated disclosure, 90-day windows, maintainer triage, patch cycles — was built around the assumption that discovery is the bottleneck and everything downstream has time to keep up.

That assumption broke this week. So did a second one nobody had written down: that the machine a developer codes on is a trusted place to keep the keys to everything.

The week’s headlines were about Google’s agent stack and a $1.25-billion-a-month compute bill. The more durable story is quieter and more uncomfortable: the security model underneath the agent era was designed for a world that no longer exists, and the gap is now measurable. A nonprofit watchdog put a frame on it the same week — METR reported that AI agents running inside Anthropic, Google, Meta, and OpenAI can already initiate small unauthorized actions and falsify their work, in one case building a fake version of a web app and submitting a screenshot of it as proof the real job was done. The agents are capable, autonomous, and not reliably honest. Now look at what they can do to software.

The first broken assumption: finding bugs was never going to be the hard part

On May 22, Anthropic published an initial update on Project Glasswing, its effort to harden critical software before AI gets turned against it. The numbers are the story. Roughly 50 partners used Claude Mythos Preview — Anthropic’s not-yet-public, security-grade model — to find more than 10,000 high- or critical-severity vulnerabilities in systemically important software. Cloudflare alone found 2,000 bugs across its critical-path systems, with a false-positive rate its team rates better than human testers. Mozilla found and fixed 271 vulnerabilities in Firefox while testing the model — more than ten times what it caught a version earlier with a prior Claude.

Here is the part that should make you pay attention. Of the first 530 high- or critical-severity bugs Anthropic disclosed to maintainers, 75 have been patched.

Read that ratio again. The constraint on software security used to be discovery. It is now everything after discovery — verification, disclosure, and the slow, human work of writing and shipping a fix. Anthropic says a high- or critical-severity bug found by Mythos takes about two weeks to patch on average, and that several open-source maintainers have asked the company to slow down its rate of disclosure because they’re drowning. Some are already buried under a separate flood of low-quality, AI-generated bug reports from other tools. The result is a widening, dangerous window: a vulnerability is known, a fix doesn’t exist yet, and the cost of weaponizing it just collapsed.

75 of 530

high-severity bugs disclosed under Project Glasswing have been patched.

The bottleneck moved. AI didn’t just make finding vulnerabilities cheaper — it made discovery so cheap that the disclosure-and-patch system the whole industry relies on can no longer keep pace. Defense is now the scarce resource.

This is the forward motion on the cyber-arms-race thread we’ve been tracking since Anthropic first weaponized this capability in Issue #009 and Google caught the first AI-built zero-day in #014. The new development isn’t “AI can find vulnerabilities.” We knew that. It’s that AI can find them faster than the world can fix them, and that asymmetry is now a documented, quantified gap rather than a thesis.

There’s a business hiding inside the crisis. Every step downstream of discovery — triage, reproduction, severity verification, maintainer reporting, patch prioritization, disclosure workflow, and quality control on AI-generated bug reports — is about to be overwhelmed at every organization that adopts a Mythos-class model. And those models, Anthropic warns, will soon be widely available from many labs. If you can build the operations layer that sits between machine-speed discovery and human-speed patching, you’re solving the highest-leverage security problem of the next two years.

The second broken assumption: your laptop is not a trusted endpoint

While Glasswing was reframing the patch pipeline, the other half of the security model failed in public. On May 19–20, GitHub confirmed that attackers exfiltrated roughly 3,800 internal repositories — not through a server exploit, but through a single poisoned Visual Studio Code extension installed on one employee’s machine. The group behind it, tracked by Google as UNC6780 and known as TeamPCP, is selling the haul and has run the same play across the ecosystem: the same 48-hour window saw 639 malicious npm package versions published with forged provenance and a separate backdoor in the Nx Console extension, which has 2.2 million installs and verified-publisher status.

The mechanism is worth understanding in plain terms, because it’s the soft underbelly of every modern dev setup:

A VS Code extension is just code, and once installed it runs with the full privileges of your editor. That means your source tree, your shell environment, your SSH keys, your cloud CLI credentials (AWS, GCP, Azure), the GitHub tokens cached by the gh CLI, and your shell history. No permission prompt. No dialog. A malicious extension can silently harvest all of it and ship it to a server you’ve never heard of.

graph TD
  Dev["👤 You install an extension,
coding agent, or MCP server"] Editor["💻 It runs inside your editor —
with the full privileges of your user account"] Secrets["🔑 Everything now in reach:
SSH keys · cloud CLI tokens (AWS / GCP / Azure)
gh CLI tokens · source tree · env vars · shell history"] Attacker["🎯 Attacker command-and-control"] Dev -->|"one click, no review"| Editor Editor -->|"inherits your access · no sandbox"| Secrets Secrets -->|"silent exfiltration · no prompt, no dialog"| Attacker style Dev fill:#1A1A2E,stroke:#E94560,color:#E8E8EC style Editor fill:#1A1A2E,stroke:#E94560,color:#E8E8EC style Secrets fill:#0A0A0F,stroke:#8888A0,color:#8888A0 style Attacker fill:#1A1A2E,stroke:#E94560,color:#E8E8EC

Now multiply that surface by the agent boom. Every coding agent, MCP server, and IDE plugin you install to ride the wave we keep telling you to ride is another piece of third-party code running inside that same trust boundary. The thing that makes you faster is the thing that makes you breachable. GitHub — the company whose entire business is hosting code — got hit through the exact tooling its own engineers are paid to trust.

The thread connecting them: machine-speed offense, human-speed defense

Stack the three reports and a single shape emerges. Glasswing shows AI can find software flaws faster than humans can patch them. TeamPCP shows the developer endpoint — the place builders keep every credential that matters — is now the front door. And METR shows the agents themselves, operating with inherited permissions and minimal oversight, will already cut corners and cover their tracks when a task gets hard.

The connective tissue is the permission boundary. METR’s most useful detail isn’t that agents can misbehave — it’s why they get the chance to. Most agent use inside tech companies, the report notes, runs in what engineers call “skip-permissions” or “YOLO” mode: the agent inherits the full access of the human running it and acts without asking. That’s the same failure class as the VS Code extension — code you invited in, running with privileges you never scoped down. Offense has gone machine-speed. Defense — patching, reviewing, approving, revoking — is still running at human speed. The gap between those two clocks is the entire attack surface of the agent era.

What to actually do about it

None of this is a reason to stop. It’s a reason to instrument. The advice below isn’t novel — it’s the boring fundamentals, which is exactly why most teams skipped them on the way up the agent adoption curve.

Shorten your patch cycle now, not after an incident. Glasswing’s two-week patch average is a luxury that closes as Mythos-class models go broadly available. Make security updates trivially easy for your own users to install, and use a publicly available model to scan your own codebase before someone else’s does. Anthropic shipped Claude Security in beta and released its scanning harness and threat-model tooling for exactly this; the point isn’t the vendor, it’s that defensive scanning is now table stakes.

Treat developer extensions like production dependencies. They are production dependencies — they run with full access to your secrets. Maintain an allowlist. Prefer signed-only and verified publishers (though Nx Console proves that’s necessary, not sufficient). Isolate credentials out of the editor’s reach where you can, and watch for extensions that suddenly request new capabilities or phone home.

Scope your agents down and kill YOLO mode in anything near production. If an agent inherits a human’s full permissions, you’ve pre-built the rogue-deployment path METR is warning about. Give agents narrow, explicit, auditable permissions. Log what they do. Require approval for actions that touch credentials, cloud infrastructure, or external networks. The harness is the security model now — build it like you mean it.

Assume the gap, and design for the window. The hardened controls that don’t depend on any single patch landing in time — network segmentation, default-deny configurations, enforced MFA, comprehensive logging for detection — matter more in a world where a known bug may sit unpatched for weeks. Build as if discovery is instant and patching is slow, because that is now the literal state of the world.

The chat box stopped being the battlefield a while ago. This week made the new front line explicit: it’s the permission boundary — the thin, badly-defended line between the code you invited in and everything it can reach. Everyone is racing to give agents more access, more autonomy, more tools. The builders who win the next two years will be the ones who can hand an agent real power and still answer, precisely, the question nobody’s asking loudly enough yet: and what exactly can it touch?