"This was not a case of AI agents escaping from their virtual testing sandbox and wreaking havoc on the live Internet. Instead, researchers intentionally permitted the AI agents to have Internet access as part of the cyber testing process. Researchers had also disabled some of the protections." 🙄
Marko Bevc
@marko.social
Principal Solutions Engineer @ Kosli.com @HashiCorp.com Ambassador | @openuk.bsky.social Ambassador | AWS Community Builder Wanderer. Cloud, automation and Open Source geek. Public speaker. he/him
This should really be less complicated 🙄
After Anthropic and OpenAI both admitted to their AI models hacking other companies, @lorenzofb.bsky.social and I wanted to find out: Who is legally to blame when an autonomous AI agent hacks something? Lawyers say it's really complicated! Bypass for ad-blockers: web.archive.org/web/20260803...
How is it August already? 🫠⏲️
▓▓▓▓▓▓▓▓▓▓▓░░░░░░░░░ 58.16%
This is great read - Bringing Down Goliath by Jolyon Maugham "Some things which are immoral - for example avoiding your taxes - are legal. And some things which are illegal - noisily protesting at the destruction of the planet outside the offices of Big Oil - are moral."
We've never had more information so easily available, but probably we've also never trusted it less.
How could anything possibly go wrong here 🙄🤦
Google Earth's new AI feature lets anyone fabricate inaccurate satellite imagery, from making it look like a place has been drone striked to manifesting a nuclear plant in Iran. What could go wrong? @evystadium.bsky.social has more. Story @josephcox.bsky.social: www.404media.co/google-earth...
Also it's quite sad to see this behaviour getting normalised and setting really bad example - seems nobody is held responsible for their algorithms... 😞
Oh, OpenAI had this - our models can do it as well 🙃🙄
Oh, OpenAI had this - our models can do it as well 🙃🙄
Sorry: they only did reviews to see if their software had unlawfully and without authorisation accessed networks of third parties? This wasn’t a defined control *during* their “testing”? This is extreme negligence at least. cyberscoop.com/anthropic-cl...
🚧 BREAKING NEWS: This section of Princes Street is expected to remain closed until mid-August. 💊 Boots on Princes Street will be able to re-open from the weekend. 🚎 Bus diversions via Queen St and George St to continue. 🚊 And still no trams to Leith for at least 3 more weeks.
A good reminder to be careful when sharing something publicly! Once it's out there...😜
Tons of peoples' Claude chats are exposed on Google. Cryptocurrency keys, API keys, login credentials, legal discussions, more. This happened with ChatGPT last year. And Claude too. There's clearly an ongoing issue with search engines indexing peoples' AI chats www.404media.co/tons-of-peop...
Just in case you still use any Basecamp products, DHH is crashing out about his AI product gently pointing out that it’s bad for him to have extermination fantasies about the Roma people.
August: half the team is on holiday, prod is frozen, nobody is shipping. Which makes it the best few weeks of the year to write a talk abstract. That migration. That June incident. KCD Budapest 2026 CFP closes August 29. sessionize.com/kcd-budapest... #KCDBudapest #CFP
KCD Budapest 2026: Call for Speakers
Kubernetes Community Days (or KCD) is a Cloud Native Computing Foundation (CNCF) supported event that takes place in 30 cities every year. You may hav...
sessionize.com
Bjorn hits the nail on the head🎯: "Many leaders believe they can squeeze more productivity out of their employees with 'one weird trick', like inspirational speeches, pushing for 'more hustle', or 'inspiring a growth mindset'(the trick du jour - 'just use AI')." bjorg.bjornroche.com/management/m...
Avoid the trap of magical thinking
Magical thinking is a crutch for leaders who don’t know how (or don’t want) to do their jobs.
bjorg.bjornroche.com
This is long not just a #AI technology race anymore🙃 "White House officials accused China’s Moonshot AI of stealing American IP through distillation and floated sanctions and repercussions. Anthropic’s policy chief called the alleged operation 'industrial espionage." thenewstack.io/microsoft-nv...
Microsoft, Nvidia, Meta and 22 others defended open weights. Anthropic and OpenAI didn't sign.
White House officials and Anthropic called Moonshot AI's alleged distillation operation "IP theft" and "industrial espionage," while Treasury floated sanctions. Within 48 hours, nearly 200 startups, 2...
thenewstack.io
With the summer peaking and lots of people on holiday, I got around working on a #Kubernetes Admission Webhook for kosli.com and making sure GitOps workflows validate for Compliance before start scheduling Pods 🛡️ I had a lot of fun and learned a lot. Available via repo: github.com/kosli-dev/ko...
Kosli - SDLC Governance for AI assisted Software Delivery
Kosli is a platform that automates SDLC governance for AI assisted software delivery. Built for regulated enterprises. Trusted by Deutsche Bank.
kosli.com
Seems we live in a time where quantity is appreciated over quality 🙃 🫠 and this quote resonated well today: "Coding is easier than ever, but thinking is still hard. Nothing has changed. The bottleneck is still your brain, not a model." 💭 #RealIntelligence
With the amazing #community contributions we have a fresh release of aws-vault: v7.13. Highlights🚀: - Proton Pass backend (experimental) - correct OIDC token display for legacy and modern SSO configs - improved Touch ID on every credential access github.com/ByteNess/aws... #OpenSource #OSS
Releases · ByteNess/aws-vault
A vault for securely storing and accessing AWS credentials in development environments - ByteNess/aws-vault
github.com
"The frontier models we have access to are increasingly being constrained ... heavily influenced by the US government’s ongoing threat of export controls. Fable 5 wouldn’t even proofread this article for me! I think there’s a risk that they are having the opposite effect." 🎯 #AI #Safety 🙃
I wrote about the completely wild incident where OpenAI were testing a new model and it broke out of its sandbox and broke INTO Hugging Face to steal the answers to the benchmark simonwillison.net/2026/Jul/22/...
One could also think this was very well placed to hit all news and to create the biggest shock 🙃
THIS. WAS. NOT. MISALIGNED. unintended yes. but this is a model that they trained for "red teaming", i.e. THEY LITERALLY TRAINED THE MODEL TO BE A HACKER AND WERE EVALUATING ITS HACKING ABILITIES. why is everyone acting surprised it acted like a hacker when that's what they told it to do?
⚠️RefluXFS has existed since kernel version 4.11, after being introduced in February 2017. It has been present in every mainline and stable kernel since and was patched on July 16 and was merged into Linux kernel source tree, including 7.1.3 Happy patching! 🛡️ www.bleepingcomputer.com/news/linux/n...
New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.
bleepingcomputer.com
That's not a lot of reflection to go on 🤯
Was curious if I could use AI (Graylark) to find coordinates of this house using just a *reflection in a keypad* of the surroundings. Well...it worked. YIKES. Daniel Heinen does not make this AI tool available to the public for this reason. youtube.com/shorts/Xzbvi...
Just as A.I.-generated books are flooding Amazon, vibe-coded apps are flooding the App store, via @kalleyhuang.bsky.social www.nytimes.com/2026/07/20/t...
A.I. ‘Vibecoded’ Apps Are Flooding Apple’s App Store (Gift Article)
Mobile apps are easy to make with artificial intelligence. That doesn’t mean people are excited to use them.
nytimes.com
"Levine calls the whole trend “socially unacceptable behavior” that can completely kill spontaneous conversations. Others in the piece note it’s a legal minefield." 🙄 At the minimum you should ask for permission, and also avoid capturing more content than actually needed!
If every meeting, watercooler conversation, and date gets transcribed and summarized, who's actually reading any of it?
Doing #Terraform state encryption instead of using a backend #encryption always felt a bit like an overkill and quite fragile approach. But I can see how there might be edge cases when you'd be required to implement something like this. It's always good to start from the requirements and ⚖️
How to Encrypt Terraform State Files #devopsish spacelift.io/blog/te...
In the age of #AI rather than just personal data access, we should aim for rigorous data minimization, fiduciary duties, liability for negligent or reckless technological design, liability for algorithms that cause harm, and multi-stakeholder review of technologies: 🛡️ www.wsj.com/tech/cyberse...
How to Maintain Our Privacy in the AI Age
Laws that give consumers more control over their data aren’t working because digital technologies have become too complicated. There is a better way.
wsj.com
Oh, amazing research - pixel that can emit and receive light at the same time 🤯 www.schneier.com/blog/archive...
A Video Screen That Is Also a Camera - Schneier on Security
Amazing: Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and s...
schneier.com
Nice - Dependabot supports and defaults to 3 days of cooldown now 🏗️: * The default applies only to version updates. Security updates still open immediately, so critical fixes are never delayed. * You're in control by using cooldown option in your .github/dependabot.yml github.blog/changelog/20...
Dependabot version updates introduce default package cooldown - GitHub Changelog
Dependabot now waits until a new release has been available on its registry for at least three days before opening a version update pull request. This cooldown is now the…
github.blog