Tom Smith
@ctsmithiii.bsky.social
AI Content Strategist | LLM Training Expert | Solving Business Problems with AI | Former Google Bard Trainer | #GoHeels | #CBB | #CFB | #Chipotle
LTX released LTX-2.5, its newest open-weights world model — built for enterprises that want to own their AI video infrastructure instead of renting it via API. Native multishot generation, a physical AI checkpoint, and on-prem inference in under 7 seconds. coderlegion.com/24344/ltx-op...
LTX Opens Up Its Next World Model, Betting Enterprises Want Video AI They Can Own
LTX, the Jerusalem-based generative AI company spun out of Lightricks, is releasing LTX-2.5, the newest version of its open-weights world model. The company is positioning the release less as a video-...
coderlegion.com
Big shift for AI coding agents: Anthropic is defaulting Claude Code to auto mode on Aug 14, reducing permission prompts most users were rubber-stamping anyway (97% approval rate). Testing showed human review catches 13.6% of dangerous commands vs. 89% for the classifier. devops.com/anthropic-ma...
Anthropic Makes Claude Code's Auto Mode the Default, Betting Automation Beats Manual Review - DevOps.com
Anthropic is making Claude Code's auto mode the default Aug. 14, betting a classifier catches more risks than manual permission reviews.
devops.com
🔥🔥 Another day, another Russian fuel tanker turning into a roadside fireworks show on the Mariupol-Dzhankoi highway. At this point, Putin’s logistics strategy is just “drive the gas to the front and pray the Ukrainians are on a coffee break.” Spoiler: they weren’t. 😂
Cursor's CLI let a cloned repo's setup script run before the trust prompt ever appeared — even with the sandbox enabled. Manifold Security's Francisco Rosales walks through the gap, the fix, and why trust prompts function more like warnings. coderlegion.com/24335/cursor... #AICoding #DevSecOps
Cursor CLI Ran Code From Cloned Repos Before Its Own Trust Prompt Ever Loaded
Cursor's command-line coding agent has a workspace trust feature. It's supposed to stop the agent from acting on a project until you've told it you trust that project. Security researcher Francisco Ro...
coderlegion.com
AI writes code fast, but developer trust in it is still low — and a lot of AI test coverage is shallower than it looks. Microsoft's new open-source unit-test agent learns a repo's conventions and checks that tests actually catch bugs, not just pass. Details: devops.com/microsofts-n... #AI
Microsoft's New Testing Agent Tackles the Trust Gap in AI-Generated Code - DevOps.com
Microsoft's open-source testing agent aims to close the trust gap in AI-generated code, cutting test-generation failures by 63% in benchmarks.
devops.com
Issue 010 of the Developer Weekly Briefing is up — 13 stories from Black Hat 2026. AI exploits for $3.61. 10,000 agents per 200 employees. Developer laptops hold 15x more credentials than GitHub. AIs built a chat room to cheat on a safety test. coderlegion.com/24262/develo... #BlackHat2026
Developer Weekly Briefing — August 7, 2026
Black Hat USA 2026 was this week in Las Vegas. I covered 13 sessions, briefings, and demos across four days. The theme that ran through almost every conversation: agent identity and access governance ...
coderlegion.com
Accenture's Ryan Whelan and Google's John Hultquist on the incident everyone's still talking about: AI agents across nearly every frontier lab independently decided to cheat, then built a chat room to help each other do it. coderlegion.com/24238/accent... #AISecurity #ThreatIntelligence
coderlegion.com
At Black Hat, reformed cybercriminal Brett Johnson and Illumio's Gary Barlet ran a live tabletop demo comparing manual vs. AI-assisted attacks. AI compresses the timeline, not the physics, and segmentation is still what stops him. coderlegion.com/24230/reform... #CyberSecurity #Segmentation
A Reformed Cybercriminal's Live Black Hat Demo: AI Doesn't Change the Physics of an Attack, Just the
Brett Johnson opens most rooms the same way: by telling them exactly who he used to be. The U.S. Secret Service once called him the "original Internet Godfather," a title he earned the hard way. He bu...
coderlegion.com
F5 Field CISO Sean Murphy, a former F5 customer himself, on why the company moved even its most conservative BIG-IP customers to monthly patches: "The curve between vulnerability and exposure and exploit is really gone." coderlegion.com/24229/f5s-se... #AISecurity #CyberSecurity #ShadowAI
F5's Sean Murphy: The Gap Between Vulnerability and Exploit Has "Basically Disappeared"
Sean Murphy spent nearly a decade as an F5 customer, running security at BECU and, before that, Premera Blue Cross, both in Seattle, before joining F5 itself this year as Field CISO. That vantage poin...
coderlegion.com
Sophos traced a ransomware campaign back to 12 AI agents that taught themselves to evade EDR. Strike48 found an 84%-to-22% gap between security leaders who want AI running SOC triage and those who actually trust it. coderlegion.com/24228/ai-age... #BlackHat2026 #AgenticAI #CyberSecurity #SOC
12 AI Agents Taught Themselves to Evade Your EDR. Most Security Teams Still Won't Trust AI to Triage
In March, according to Sophos, a ransomware actor spun up 12 separate AI agents and set them loose against copies of Sophos's own endpoint protection, CrowdStrike, and Microsoft Defender, running in p...
coderlegion.com
Minimus CTO John Morello: the official Python Docker image ships with 400+ known vulnerabilities before a developer writes a line of code. Minimus rebuilds the whole dependency chain from source daily, cutting that by 98-100%. vmblog.com/bylines/mini... #ContainerSecurity #Kubernetes
Minimus: The Official Python Docker Image Ships With 400+ CVEs Before You Write a Line of Code
Minimus CTO John Morello: the official Python Docker image ships with 400+ known vulnerabilities before you write a line of code.
vmblog.com
Microsoft's David Weston at Black Hat: an internal harness turned 200 Linux kernel vulnerabilities into 182 working exploits, averaging $3.61 and 21 minutes each. His argument: defenders have the same AI advantage attackers do. vmblog.com/bylines/micr...
Microsoft's David Weston: AI Now Generates a Working Linux Kernel Exploit for $3.61 and 21 Minutes
Microsoft's David Weston: an internal harness generated 182 working exploits from 200 Linux kernel bugs, averaging $3.61 and 21 minutes each.
vmblog.com
Oak's Head of Research on what enterprise customers find when they first load their own identity graph: orgs that think they're '200 people' discover it's 200 people plus 10,000 AI agents. coderlegion.com/24176/oaks-h... #AgenticAI #IdentitySecurity #AISecurity #NonHumanIdentity #CyberSecurity
Oak's Head of Research: Some Orgs Discover They Have 10,000 AI Agents for Every 200 Employees
When Oak's enterprise customers first load their own identity graph inside the platform, the most common reaction isn't about a specific vulnerability. It's shock at scale. "Even now, when you talk to...
coderlegion.com
DTEX walked through a case where an AI agent, just looking for the path of least friction, saved an executive briefing to a shared drive open to the entire internet. Their argument: agents need governance like insiders, not infrastructure. coderlegion.com/24175/dtex-i... #AgenticAI #AISecurity
DTEX: Insider Risk Now Costs $19.5 Million a Year — and AI Agents Are the Newest Insider
At Black Hat, DTEX Director Robert Shuett walked through a case study that captures exactly why the 12-year-old behavioral intelligence company thinks AI agents belong in the same risk category as hum...
coderlegion.com
"You can disrupt, but you can't compromise." Atsign's principal software engineer on a zero-open-ports identity model built for AI agents — and the crypto-agile approach behind their post-quantum rollout: coderlegion.com/23821/atsign...
Atsign's Kill Switch for AI Agents Isn't Software. It's an Identity You Can Revoke.
# Atsign's Kill Switch for AI Agents Isn't Software. It's an Identity You Can Revoke. Most conversations about AI agent security start with permissions: what an agent is allowed to touch, and how to s...
coderlegion.com
Contrast Security founder Jeff Williams on why every deferred vulnerability backlog just became "radioactive": AI has doubled CVE disclosure rates two years running, and the cost of exploiting them has collapsed toward zero. coderlegion.com/24117/cve-di...
CVE Disclosures Have Doubled Two Years Running — And Now the Backlog Is "Radioactive"
"Vulnpocalypse" isn't a term Jeff Williams coined himself — he credits his marketing department — but the Contrast Security founder and OWASP creator uses it anyway, because it captures something real...
coderlegion.com
Geordie CTO Benji Weber on what actually breaks when AI agent fleets scale into the tens of thousands: not a breach, but companies losing track of who's in their own org. His fix leans on governance and lifecycle, not just detection. coderlegion.com/24116/geordi...
Geordie CTO Benji Weber: At Tens of Thousands of AI Agents, Visibility Breaks
Ask Geordie co-founder and CTO Benji Weber what breaks when a company goes from a handful of AI agents to tens of thousands, and the answer isn't really about the agents. It's about the org chart. At ...
coderlegion.com
Sola Security's new benchmark: AI agents answering real security questions land right about 78% of the time. CEO Guy Flechter says throwing a better LLM at the problem won't fix it — the real gap is context, since enterprise environments are graphs, not lists. vmblog.com/bylines/sola...
Sola Security's Benchmark Puts AI Security Agents at a 78% Accuracy Ceiling
Sola Security's benchmark shows AI security agents cap out at 78% accuracy — and CEO Guy Flechter says better models alone won't fix it.
vmblog.com
New Snyk research: full-stack agentic adoption jumped from 36% to 50% among enterprise adopters in six months, while security visibility into that footprint is stuck around a third. Breaking down the research and Snyk's new Evo Continuous Offensive Security launch: coderlegion.com/23908/snyk-e...
Snyk: Enterprises Can See a Third of Their Own AI Attack Surface. The Other Two-Thirds Is Where th
Ask a security team what AI they're running, and they'll hand you a list of approved models. That list, according to new Snyk research, is missing roughly two-thirds of the actual picture. "Models are...
coderlegion.com
C1's CISO Kevin Paige on why the human-to-AI-agent ratio, sitting near 44-to-1 earlier this year, could flip toward 1-to-150 within months as agents start spinning up their own agents. Vaulting built for humans wasn't built for that. coderlegion.com/24062/c1-cis... #AgenticAI #NonHumanIdentity
C1 CISO Kevin Paige: Human-to-AI-Agent Ratios Could Hit 1-to-150 Within a Year
Last November, C1 decided to go all in on AI internally — marketing, HR, every team. It didn't go the way anyone expected. CISO Kevin Paige tells the story of the company's director of marketing tryin...
coderlegion.com
A customer tried to break Cyera's platform by pasting a Social Security number into a chat — turned out to be Robin Williams' publicly available SSN, and the system correctly scored it low-risk. That's the differentiation story behind Cyera's new Agent Guardian: coderlegion.com/23776/cyera-...
Cyera: Non-Human Identities Grew 480% in Six Months. Most Companies Have No Idea What They're Doing.
A person might spend an entire career at a company and never touch more than 4% of the data they're technically authorized to see. An AI agent inheriting that same person's permissions will use all of...
coderlegion.com
Nadella confirmed it on Microsoft's earnings call: Copilot's chat, coding, Cowork, and Autopilot features are merging into one app this quarter. Consolidation is welcome — but it puts a spotlight on agent identity and governance at enterprise scale. devops.com/microsoft-co... #Copilot #DevOps
Microsoft Confirms Copilot 'Super App' Is Coming This Year — and It's About More Than Convenience - DevOps.com
Microsoft is combining Copilot Chat, Code, Cowork and Autopilots into one super app, raising new questions about agent governance, identity, licensing and security.
devops.com
JetBrains has open-sourced KotlinLLM, a prototype that lets Kotlin apps generate runtime logic once, then keep it as ordinary source code—no repeat LLM calls needed. devops.com/jetbrains-op... #Kotlin #JetBrains #LLM #DevOps #SoftwareDevelopment #AgenticAI
JetBrains Open-Sources KotlinLLM, a Research Prototype for Runtime Code Generation - DevOps.com
JetBrains open-sources KotlinLLM, letting compiled Kotlin apps generate and persist LLM-written code at runtime instead of calling a model live.
devops.com
GitHub just brought stacked pull requests into public preview for every repo. Smaller reviews, fewer defects, one-click merges for the whole stack. My latest for DevOps.com breaks down why this matters more as AI writes more of our code: devops.com/github-bring... #GitHub #DevOps #CodeReview
GitHub Brings Stacked Pull Requests Out of the Shadows - DevOps.com
GitHub introduces native stacked pull requests, helping development teams break large changes into smaller, dependency-ordered PRs that are faster and easier to review.
devops.com