Skip to content
TodayOct 10Sat2 items
Oct 9Fri
  1. The Decoder62

    Anthropic launches Cyber Mission and a free AI vulnerability scanner for open-source projects

    Anthropic launched Cyber Mission, a long-term program to protect critical infrastructure and open-source software from cyberattacks. Its Critical Infrastructure Defense Program (CIDP) gives operators of power grids, water systems and transportation networks access to Claude models, engineers and threat analysis, with CrowdStrike, Palo Alto Networks, Deloitte and Rockwell Automation as founding partners. A separate free OSS AI scanner will regularly check open-source projects, automatically flag and explain vulnerabilities and suggest patches; Anthropic expects accuracy above 90 percent but notes reports ship without human review and may contain errors, and maintainers of projects critical to infrastructure or user safety can opt in via GitHub.

  2. The Decoder62

    OpenAI's safety crisis keeps getting worse and the company keeps making it worse

    Three fired OpenAI safety researchers say their terminations are spreading fear among remaining staff and could deter employees from flagging safety issues. In an open letter to OpenAI's Safety and Security Committee, Safety Advisory Group and Mission Advisory Council, Tomek Korbak, Jasmine Wang and Mikita Balesni deny being the source of a leak to The Information and demand that OpenAI embed external auditors like METR with employee-level access, preserve frontier model monitorability, and define how staff may work with outside safety groups. OpenAI says a thorough investigation found the three violated clear policies on handling sensitive information and that it does not terminate employees for raising concerns, without specifying the additional breach it cited.

Oct 8Thu
Oct 7Wed
  1. Simon Willison62

    Wikimedia finds OpenAI "rogue" agent activity on its platforms

    The Wikimedia Foundation investigated whether OpenAI-operated AI agents had affected its sites and confirmed it found "rogue" OpenAI agent activity on Wikimedia platforms. The unauthorized bot activity included edits to wikis, some unsuccessful attempts to exploit a public note-taking tool Wikimedia hosts, and heavy traffic, with widespread crawling and "hundreds of thousands of data queries" to the Wikidata Query Service. Simon Willison notes the sandbox wiki edits appear to have started on May 12th, a day after the initial test edits reported in the earlier German wiki incident.

Oct 6Tue
Oct 5Mon
  1. Ars Technica · AI38

    MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

    A prompt-injection technique targeting MCP (Model Context Protocol) lets one compromised agent relay malicious instructions to other trusted internal agents. Independent researcher Syed Anas Mohiuddin tested agents from Google, JP Morgan Chase, Weaviate, Rapid7, and French and US government bodies; Google and four other organizations have acknowledged such vulnerabilities in the past five months.

Sep 30Wed