The most "Oh, no! Anyway…" shit I've read in a long time. www.natesilver.net/p/disney-era...
Disney erased FiveThirtyEight
Nothing on the internet lasts forever. But Disney’s 10-year mismanagement of FiveThirtyEight is its own story.
natesilver.net
Knowing a lot about hammers doesn't automatically make you an expert on carpentry, or construction, or any other activity that requires hammers.
Maybe don't let AI agents touch production stuff? Like, ever? It fails miserably while doing utterly inconsequential shit, so you can extrapolate from there.
The circlejerk: "Terrible Signal exploit fixed thanks to journalists! FBI could read your deleted Signal messages!" Me: Yikes. Let's look at the CVE. The CVE: 6.2 Medium. Notifications marked for deletion could be unexpectedly retained on the device. Notifications. Could. Me: Zzzzzzz
Everyone's talking about how good Anthropic's products are at finding vulnerabilities, but no one is looking at how good they are at BEING the vulnerability. (Apologies for linking to this shithole) x.com/lifeof_jer/s...
JER on X: "An AI Agent Just Destroyed Our Production Data. It Confessed in Writing." / X
An AI Agent Just Destroyed Our Production Data. It Confessed in Writing.
x.com
You're smarter than this Critical thinking is part of the job https://crankysec.com/blog/smarter/
There's a huge difference between "we're in a genuinely important moment" and using apocalypse-coded language for marketing, some skepticism and scorn is warranted, but I'd just advise non-experts to pump the breaks before correcting practitioners who say their field is being reshaped
Reposting someone else's repost of your post is so fucking dumb.
Smash the glass wing PoC || GTFO, bro. https://crankysec.com/blog/smash/
This is a terrible take. simonwillison.net/2026/Apr/14/...
Cybersecurity Looks Like Proof of Work Now
The UK's AI Safety Institute recently published Our evaluation of Claude Mythos Preview’s cyber capabilities, their own independent analysis of Claude Mythos which backs up Anthropic's claims that it ...
simonwillison.net
The REAL Glasswing lesson is that no one knows how to do threat modeling and risk assessments.
We're really spending tokens and paying money for output like this, eh? ● Yeah, sorry. Should have caught that during the rename. ● You're right. No excuse for that. ● You're right, I've been going in circles and made things worse by manually deleting the containers and network.
A New New Hope The Cleanup Crew Is Standing By https://crankysec.com/blog/new-hope/
Let's Delve In Are you new here? https://crankysec.com/blog/delve/