KFC announces their frontier-class model briefly escaped its sandbox and attempted to exfiltrate the 27 herbs and spices
Allan
@allanfriedman.bsky.social
SBOM Champion. Paranoid about supply chains of all kinds. Former full-service technocrat at CISA, NTIA. Lapsed{engineer, academic, author}. Now wandering the world doing acts of infosec-goodness, & occasionally getting paid for it. Poster of food pics.
If there's one thing I've learned from publishing this story is that there is a very, very, very wide chasm between what the law says about all this... and what people *think* the law says and/or *should* say.
After Anthropic and OpenAI both admitted to their AI models hacking other companies, @lorenzofb.bsky.social and I wanted to find out: Who is legally to blame when an autonomous AI agent hacks something? Lawyers say it's really complicated! Bypass for ad-blockers: web.archive.org/web/20260803...
Five hundred twenty five thousand six hundred patches Five hundred twenty five thousand fixes so dear Five hundred twenty five thousand six hundred CVE's Why haven't you bought, your IT Team a Beer?
It's a small thing, I know, but there really is a difference between "palate cleanser" and "palette cleanser," and also, while we are on the subject, "pallet cleanser," and it is worth making the distinction
What's that? You want some more in depth analysis of the brand new 2026 International #SBOM Minimum Elements? And you don't mind people who just use LinkedIn for blogging? Well, have I got some quality markdown content for you! www.linkedin.com/pulse/sbom-m...
The SBOM Minimum Gets Bigger—but Does It Get Better?
TLDR: yes, it gets better. As I noted yesterday, the use of “coverage” is probably the biggest change in the new 2026 CISA-convened International Minimum Elements.
linkedin.com
Whenever someone asks me to help edit something, I have them explain it in their own words and then tell them to just write THAT down Instead, because it's much clearer and to the point.
Adobe Acrobat will deflate all those ballooned #GenAI PDF reports
*Checks watch.* Yep, it’s time for my weekly “HOW COULD THEY KILL GOOGLE READER!?!” moment of rage.
CONFESSION: Sometimes I stare at the 26 newsletters in my inbox everyday and think: "what was so bad about RSS feeds"
The SBOM minimum just got bigger. CISA and its international partners released an expanded Minimum Elements. Adds and clarifies most of the new fields from the 2025 CISA draft, and sets a far stronger expectation for what an #SBOM should actually cover. www.linkedin.com/posts/allana...
The Minimum Just Got Bigger: CISA (and friends') New SBOM Baseline | Allan Friedman, PhD
The SBOM minimum just got bigger. CISA and its international partners have released a substantially expanded Minimum Elements. It adds and clarifies most of the new fields from the 2025 CISA draft, an...
linkedin.com
How do you protect an immensely vulnerable system against a stronger, even God-like adversary? Well, you use a Shadow Server of course. Power plants have lots of interesting ideas. The NIST published a “Situational Awareness For Electric Utilities”.
Joe raises a really interesting problem. One thing that will be important is better component inventories to build “fleet risk” for organizations. HBOM will play a big part in this.
But perfect code exposes a deeper crisis. What happens when flawless software runs on imperfect, degrading hardware? As chips shrink and age, we see a rise in Silent Data Corruptions (SDCs) where hyperscale silicon confidently returns the wrong math. 4/6
A fun familiar name in today’s Catfishing game. What’s that? You don’t play Catfishing, the daily trivia game where you try to guess the Wikipedia article based on a curated list of the categories? If you are a trivia person, you should probably add this to your daily fun. catfishing.net
When your vehicle outlives its cloud: What happens next? arstechnica.com/cars/2026/07...
When your vehicle outlives its cloud: What happens next?
Automakers love connected vehicles, but support isn't open-ended.
arstechnica.com
A few weeks ago, I wrote about how we need greater transparency for our AI systems and what a path to AIBOM would look like. Now it seems that it will be more than just good risk management, but potentially serious compliance, coming at you fast. cyberscoop.com/ai-bill-of-m...
A case for how to shape ‘ingredient lists’ for AI models
A new policy paper outlines a roadmap for AI Bill of Materials (AIBOM) policy, urging standard frameworks to curb cyber risks and boost supply chain transparency.
cyberscoop.com
"The Trump administration is showing signs it could ban cutting-edge Chinese AI models — a momentous move that could lock in dominance by OpenAI and Anthropic." www.axios.com/2026/07/20/a...
A car alarm device, KARR, inside millions of cars has a security flaw that lets hackers unlock, track, even paralyze vehicles. There's a patch. The problem? Half of car owners who have the device installed didn't ask for it, and may not even know it's there. Thread👇 www.wired.com/story/a-devi...
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.
wired.com
Nice crowd at the DC wharf for the final. A pretty great cross section of this city, and a fun vibe.
Unfortunately, a stunned Paris is how they all got into this whole mess to begin with
‘The Odyssey’ women Zendaya, Anne Hathaway, Lupita Nyong'o, and Charlize Theron stun in Paris.
I literally cannot uncheck this box on PowerPoint for Mac, so the next time you hear about Copilot adoption metrics, know these shenanigans are ongoing...
My wife referred to Pickett’s Charge as the time the Confederacy “lost the largest game ever of Red Rover” to the Americans.
John Buford when he sees Harry Heth coming down the Chambersburg Pike
Sophie Point
ALT: Sophie Point
static.klipy.com
This was a fun conversation! We unpacked the “omniBOM.”
I had the pleasure to chat with @allanfriedman.bsky.social about Bill of Materials things on #OpenSourceSecurity We touched on SBOMs, HBOMs, AIBOMs, and even some other BOM types I can't remember now Allan is always fun to chat with, and he has encyclopedic knowledge about the BOM universe
TikTok's latest illegal 'life hack' seems to be 'dispute credit card transactions for free stuff' and legality aside I am here to beg you: Do not do this to small businesses. It really fucks them over in ways you may not be aware of beyond stealing from them (which is, to be clear, what this is).🧵