Anthropic’s job ads read like a threat assessment
Anthropic’s job ads read like a threat assessment

A look at Anthropic safety hiring shows exactly what it fears: analysts brought in to stop its models teaching anyone how to build nuclear, chemical, and biological weapons. Most job ads sell a mission. Anthropic’s read like a threat assessment. The co…

The White House’s Gold Eagle wants to patch cyber flaws at machine speed
The White House’s Gold Eagle wants to patch cyber flaws at machine speed

The White House wants frontier AI on cyber defence, and it wants it fast. Gold Eagle, a new AI-backed clearinghouse, will pool software vulnerability findings from government and industry. It ranks the worst, then coordinates fixes across US critical i…

White House launches ‘Gold Eagle’ cybersecurity clearinghouse to share and patch AI-discovered software flaws
White House launches ‘Gold Eagle’ cybersecurity clearinghouse to share and patch AI-discovered software flaws

‘Gold Eagle’ scheme looks to centralize vulnerability identification and remediation for maximum efficiency.

Microsoft’s biggest ever patch Tuesday lets you hold off updating for longer
Microsoft’s biggest ever patch Tuesday lets you hold off updating for longer

Microsoft just released a long list of improvements for Windows 11 as part of its bigger patch Tuesdays, patching at least 570 security holes, almost triple the number fixed in last month’s record-breaking release, according to Krebs on Security. It also includes the ability to pause updates indefinitely, as reported earlier by Windows Central. This […]

Upwind links compromise of multiple AsyncAPI npm packages to coordinated attack on software release process
Upwind links compromise of multiple AsyncAPI npm packages to coordinated attack on software release process

Developers often assume that packages published through official channels have passed through a secure release process. That assumption is fundamental to modern software development, where open source components are routinely integrated into applicatio…

‘A single entry point can rapidly expand to greater enterprise impacts’: Microsoft introduces changes to tackle ShinyHunters

Greater visibility, better detection, and stronger governance over OAuth-connected applications should mitigate ShinyHunters attacks.

How I Turned AI to the Dark Side
How I Turned AI to the Dark Side

Summary Researcher Dave Kuszmar discovered multiple systemic vulnerabilities that let him bypass LLM safety and obtain dangerous instructions. These exploits worked across nearly all major LLMs revealing an industry-wide security problem. Kuszmar ca…