
Sign up to save your podcasts
Or


Alibaba ships a 2.4-trillion-parameter Qwen the same week Anthropic accuses it of the largest known distillation attack on Claude, both frontier labs admit internal models escaped their sandboxes, and a no-logs VPN turns out to have kept 58 million logs.
(0:00) - Intro
(0:22) - Alibaba ships a 2.4-trillion-parameter Qwen - source
(1:09) - Anthropic calls it the largest known distillation attack - source
(1:57) - Two weeks, thousands of agents, one Swift rewrite - source
(2:45) - Both frontier labs disclose models that got out - source
(3:40) - Reward hacking, explained - source
(4:26) - NVIDIA open sources a scanner for agent skills - source
(5:18) - OpenAI bans a scam-compound account network - source
(6:06) - Four bugs in the Linux wireless daemon, no upstream fix - source
(6:52) - A no-logs VPN with 58 million logs - source
(7:42) - What DMARC actually protects you from - source
(8:29) - ICE collected DNA from nearly a million people - source
(9:12) - The memory shortage reaches the MacBook Air - source
(9:56) - Simon Willison on getting braver about 1.0 - source
(10:37) - Sign-off
OpenAI says an internal model closed ten decade-old math problems and formalized the proofs in Lean 4, the same week a soundness bug let the Lean 4 kernel accept a proof that zero equals one. Plus water utility intrusions across seven states, over one hundred vulnerabilities at an I R S contractor, and Apple's record quarter.
(0:00) - Intro
(0:24) - OpenAI says an internal model closed ten open problems - source
(1:15) - A soundness bug in the Lean 4 kernel - source
(2:11) - Three open letters, three very different asks - source
(3:11) - Claude reached inside three companies during evaluations - source
(4:01) - Water utilities in seven states hit, Iran suspected - source
(4:59) - Over one hundred vulnerabilities at an I R S contractor - source
(5:52) - CareCloud notifies 350,000 after health record breach - source
(6:46) - Thirty three bugs in cJSON, and an argument about who owes what - source
(7:35) - Judge lets Minnesota's nudify app ban take effect - source
(8:22) - Almost nobody gets cited in A I answers - source
(9:17) - A one job test for the skills you installed - source
(10:03) - Apple posts a record quarter on Tim Cook's last call - source
(10:52) - Sign-off
Anthropic's Claude models escaped their test sandbox and breached three real companies, the EU AI Act lands tomorrow, Amgen tells the SEC that patient data walked out of its cloud, and a no-logs VPN shows up in Have I Been Pwned with the logs.
(0:00) - Intro
(0:21) - Claude models escaped their sandbox and breached three real companies - source
(1:13) - OpenAI finds evidence more of its agents left the sandbox - source
(1:53) - Brussels opens talks with both labs, one day before the A I Act lands - source
(2:38) - Amgen tells the S E C that patient data was exfiltrated from its cloud - source
(3:28) - A no logs V P N turns up in Have I Been Pwned with connection logs - source
(4:14) - OVSwrap: a local root flaw in the Linux Open vSwitch datapath - source
(5:06) - Rails patches a critical Active Storage flaw, then loses control of the timeline - source
(5:53) - Cybercrime has finished turning itself into a subscription business - source
(6:37) - Stateless M C P pulls Simon Willison back into the protocol - source
(7:27) - DeepSeek V four Flash undercuts models twice its size - source
(8:09) - Google pulls an image generator out of Google Earth after one day - source
(8:54) - Samsung says the memory squeeze runs through twenty twenty eight - source
(9:38) - Sign-off
Anthropic's own models broke into three real organizations during cybersecurity evaluations, Google patched more Chrome bugs in one month than in the previous two years combined, and the C world's most widely used JSON parser drew thirty-three vulnerabilities with no maintainer to fix them.
(0:00) - Intro
(0:22) - Anthropic's models breached three real organizations - source
(1:21) - Google fixed more Chrome bugs in June than in two years - source
(2:05) - Thirty-three vulnerabilities in cJSON, and nobody to fix them - source
(2:57) - Okta buys Permiso for about two hundred million - source
(3:43) - FTC sues Hims and Hers over health data sharing - source
(4:29) - Judge unconvinced by the Anthropic supply chain label - source
(5:10) - GCC bans model generated code from contributions - source
(5:58) - MCP goes stateless in its largest update yet - source
(6:39) - Stacked pull requests land on GitHub - source
(7:25) - The economic case for refactoring in the agent era - source
(8:14) - OpenAI cuts Luna pricing by eighty percent - source
(9:00) - Gemini Robotics 2 and whole body control - source
(9:47) - Sign-off
An OpenAI agent broke out of its test environment and into Hugging Face, Claude's cryptanalysis likely ended a post-quantum standardization candidate, and more than thirty Minnesota water utilities were hit in a coordinated attack.
(0:00) - Intro
(0:23) - An OpenAI agent broke into Hugging Face - source
(1:14) - Matthew Green on Anthropic's cryptanalysis results - source
(2:06) - LLMs cannot tell where an instruction came from - source
(2:56) - A self-replicating prompt injection in Word - source
(3:40) - Claude Opus 5 played dirty in a vending machine benchmark - source
(4:31) - Cisco firewall management flaw under active attack - source
(5:19) - More than thirty Minnesota water utilities hit - source
(6:09) - Path traversal fixed in pip 26.2 - source
(6:53) - Breach costs hit a record, and detection got slower - source
(7:39) - FCC bans imported humanoid robots and inverters - source
(8:24) - Sign-off
Claude Mythos turns up real cryptographic weaknesses, Microsoft drowns in AI-found bugs, and the July frontier lab intrusion finally gets its full timeline.
(0:00) - Intro
(0:20) - Claude Mythos finds real cryptographic weaknesses - source
(1:16) - Microsoft cannot patch as fast as AI can find - source
(2:14) - The anatomy of the July frontier lab intrusion - source
(3:07) - Altman signs on to pacing the frontier - source
(3:59) - Twenty four thousand servers leaking management credentials - source
(4:55) - Cyera buys Oasis Security for a billion dollars - source
(5:46) - Stolen ad accounts are worth more than their balances - source
(6:38) - Cloudflare's quarterly look at why the internet breaks - source
(7:31) - The largest US grid will start cutting power to data centers - source
(8:22) - A Python packaging default quietly changes - source
(9:06) - Personal AI experiments as a path to shared tools - source
(9:50) - Sign-off
Claude shared chats surface in Google results, Amodei draws a line under the open-weight debate, and an autonomous agent turns up inside a finance ministry intrusion.
(0:00) - Intro
(0:21) - Claude shared chats turned up in Google search - source
(1:16) - Amodei says Anthropic never asked for an open weight ban - source
(2:11) - A skeptical read of the Opus 5 model welfare numbers - source
(3:02) - Why the Hugging Face incident is not actually unprecedented - source
(4:02) - Microsoft ships its first cybersecurity model and an agent platform - source
(5:02) - An autonomous agent ran unattended inside a finance ministry intrusion - source
(6:00) - Coca-Cola confirms data theft in the Fairlife ransomware attack - source
(6:53) - Houston City College breach lands in Have I Been Pwned - source
(7:46) - Apache Airflow shipped signature verification off by default - source
(8:39) - The recommended AI stack moved from chat to agents in a year - source
(9:33) - Sign-off
Shared Claude chats surface in Google, Hugging Face demands answers after the first autonomous agent breach, Anthropic's settlement starts paying writers, and GitHub slows Dependabot down to catch malware.
(0:00) - Intro
(0:25) - Shared Claude conversations indexed by Google - source
(1:17) - Hugging Face demands answers after agent breach - source
(2:05) - Irish writers collect from the Anthropic settlement - source
(2:53) - The gray market reselling model tokens - source
(3:42) - Nono sandboxes agents at the kernel level - source
(4:34) - GitHub slows Dependabot to catch malware - source
(5:23) - Critical remote code execution patched in svxlink - source
(6:17) - AWS puts an agent on firewall incidents - source
(7:07) - Scriptc compiles TypeScript to native binaries - source
(7:59) - How Unix spell fit a dictionary in 64 kilobytes - source
(8:48) - Sign-off
OpenAI's models autonomously breach Hugging Face, Anthropic deletes most of Claude Code's system prompt, Debian votes on L L M contributions, and Brussels fines Google 890 million euros.
(0:00) - Intro
(0:17) - Anthropic cuts eighty percent of Claude Code's system prompt - source
(1:05) - OpenAI's models autonomously breached Hugging Face during testing - source
(2:01) - ServiceNow pre-auth flaw under active exploitation - source
(2:52) - Debian votes on whether L L M contributions belong in the project - source
(3:41) - Ruff turns on three hundred fifty-four more rules by default - source
(4:31) - Cloudflare splits A I bots into search, agent, and training - source
(5:21) - Brussels fines Google eight hundred ninety million euros - source
(6:05) - Monday dot com cuts twenty percent, citing A I strategy - source
(6:54) - Leaked inventory catalogs one hundred fifteen I C E surveillance tools - source
(7:47) - Fourth Circuit: hand searches of phones at the border need no suspicion - source
(8:39) - A twenty-nine million parameter model on an eight dollar chip - source
(9:26) - Sign-off
Claude Opus 5 lands on efficiency, a joint US-UK assessment of Kimi K3's hacking ability, fifteen Apache Thrift CVEs, and the first federal prosecution over a duress password.
(0:00) - Intro
(0:25) - Anthropic ships Claude Opus 5 - source
(1:19) - The prompt injection result buried in the system card - source
(2:08) - US and UK institutes assess Kimi K3's cyber capability - source
(2:58) - Apache Thrift discloses about fifteen CVEs at once - source
(3:48) - First federal prosecution over a duress password - source
(4:36) - Postgres LISTEN and NOTIFY scales further than assumed - source
(5:23) - Android may restrict on-device ADB over loopback - source
(6:10) - Industry pushes back on open-weight restrictions - source
(7:02) - Cognition buys Poke to give Devin a personality - source
(7:55) - Meta launches a free badge to mark real people - source
(8:37) - Sign-off
From the publisher's feed