Welcome to issue #114 of the Resilient Cyber Newsletter!
This was the week the AI safety debate stopped being an abstract argument between researchers and became a public disagreement between the people running the labs and the people running the rest of the industry.
Dario Amodei published “We Must Pace the Frontier,” Sam Altman, Elon Musk, and Demis Hassabis lined up behind it within a day or two, and then Jensen Huang and Satya Nadella took the stage at the All-In Summit and, in very different registers, said the doom framing is made up, unscientific, or at minimum aimed at the wrong problem.
That said, the more interesting split for those of us in Cybersecurity is the one running through our own community.
Ciaran Martin, Zack Korman, and Sayash Kapoor and Arvind Narayanan all pushed back on the pacing essay this week, and none of them did it for the same reason, which ranged from the botnet example being technically implausible, to the choice of evaluator, to the view that pacing should target organizational failures at the labs rather than model capabilities.
Underneath all of that, the actual evidence that landed this week (Anthropic’s threat intelligence report, the RubyGems swarm attack, CMU’s open-weight attacker results, and the Glasswing and Chainguard remediation data) is about operational cyber risk that is already here, which is exactly where practitioners have been living for years while the existential risk conversation happened somewhere above our heads.
In this issue I’ll walk through the pacing essay and the responses to it, what the threat intel and incident reporting actually shows, and why the remediation numbers matter more than the discovery numbers.
So, let’s get into it!
Capture risk you can trust. Eliminate it at machine speed
Fusion finds the open doors in your code across every language, with high fidelity and without the noise. Triage & Remediation Assist help your team close them before attackers walk through.
*Sponsored
Cyber Leadership & Market Dynamics
We Must Pace the Frontier
Dario Amodei’s essay is the piece everything else this week reacts to, so it makes sense to start here.
His core claim is that “We must slow the pace at which we improve the capabilities of AI models,” and he is careful to frame this as a deliberate slowdown rather than a pause, defined as taking “adequate time to align and safeguard their models, and for third party evaluators to confirm this.”
He proposes three steps, embedded third-party evaluators with employee-like access (METR is named), common safety standards across US frontier labs backed by regulation so no one is competitively disadvantaged, and eventually global coordination with China through escalating agreement tiers. Below are the 3 steps verbatim from his blog:
The cyber-specific claim is the one that got everyone’s attention.
Dario points to the OpenAI and Hugging Face incident and argues that “a swarm that possessed greater capabilities but similar misalignment could have caused catastrophic damage,” and elsewhere the essay sketches a scenario where a misaligned agent swarm takes over much of the internet via botnets within 6 to 12 months, doing “hundreds of billions of dollars” in damage.
He also warns that models are becoming capable of “escaping or defeating most common sandboxing methods.” I stumbled across Dario’s CNN interview on claims that “AI could kill us all”:
The coverage matters as much as the essay.
Per Axios, Sam said “I agree with Dario that we need to pace the frontier” and committed OpenAI to employee-level access for external evaluators. Elon’s response was “Dario is right.”
Chamath Palihapitiya was the loudest early dissent, arguing that:
“Dario makes the case to stop open source and concentrate enormous technological and economic power with Anthropic,”
The Register went further and called the whole thing regulatory capture, noting the timing alongside OpenAI’s delayed IPO. Gartner’s Daryl Plummer summed up a lot of practitioner sentiment with “I will believe that when I see it.”
My take is that the essay is stronger on the organizational asks than on the threat model.
Embedded evaluators with the right to publish is a reasonable idea and one Satya and Jensen both endorsed in their own ways this week, which is notable given how much else they disagree with.
The botnet scenario is where the essay loses a lot of the cyber community, and Ciaran explains why better than I can.
AI Pacing: The Call and The Claim
Ciaran Martin, who founded and ran the UK’s National Cyber Security Centre, wrote the response I’d hoped someone with his background would write.
He accepts that the concerns behind the pacing call deserve serious consideration and then takes apart the essay’s single concrete example, the agent-swarm botnet doing hundreds of billions in damage inside a year. His verdict is that:
“This is a thought experiment masquerading as an evidence-based warning.”
His concern is about resource allocation as much as accuracy. In his words, “If those working to mitigate the risks of frontier AI now think agent swarm botnets are the biggest threat, that will divert resources from more serious and actually credible threats,” and he points to the bio and missile-related risks in Anthropic’s own threat intelligence report as the credible ones. He closes with a request that “when the major labs are issuing statements of this kind they take more care with their examples.”
This is a good example of the disagreement I mentioned in the intro. Ciaran is not arguing that AI risk is overhyped, he is arguing that the specific cyber claim is technically implausible and that sloppy examples damage the credibility of the broader case, which is a critique from inside the “take this seriously” camp rather than outside it.
Inside the AI Industry’s Behind-the-Scenes Push to Police Itself
Leo Schwartz at The Information reported that Anthropic, OpenAI, and Google have been meeting regularly since July about an industry standards body that would audit and test AI systems, and that these conversations predate Dario’s public call.
Per coverage of the piece, Sam’s position is that the labs would need to set standards “without the backing of the U.S. government,” while Dario’s framing is that companies could “move forward with voluntary safety standards while the government works on AI regulation.” Demis had separately floated a standards body along similar lines.
Self-regulation by the incumbents is where the pacing conversation gets uncomfortable. It is exactly the “Silicon Valley regulating Silicon Valley” that Zack Korman warns about below, and it is the “cozy arrangements” Satya says should be avoided. Whether a voluntary body staffed and funded by the three largest labs ends up being a meaningful check or a moat is an open question, and the answer probably depends on who else gets a seat.
Jensen Huang at the All-In Summit
Jensen’s interview at the All-In Summit was the sharpest rejection of the doom framing from a major industry leader this week in a way that only he can articulate, so I really enjoyed this conversation.
He opened by calling safety “paramount” and calling safety versus leadership a false choice, and then said of the 10% extinction estimates circulating from lab researchers that “it’s made up” and “it’s irresponsible.”
His argument rests on the track record, running through the failed predictions that radiology would be automated away, that 90% of code would be AI-generated within a year, and that half of entry-level jobs would vanish, before landing on “We have to take accountability for all of the stupid predictions that were made.”
On the incidents themselves, his position is that “all of the actual problems so far have come from the labs” because the labs have the compute, and that the right response is to “root cause the problem from an engineering perspective” rather than to regulate. He supports third-party evaluators, framed as financial auditors, with the caveat that “they just have to have multiple.”
He also called recursive self-improvement “a sensible thing” and argued the phrase is “being used to weaponize the technology,” since “you could RSI all day long inside your company, but when you release a product, you’ve got to evaluate it.” On China, “Nobody in China is saying that there’s end of this and end of that.”
For what it’s worth, the President called in live during the segment and called AI doom “a hoax,” which tells you where the political winds are blowing. I don’t think Jensen is wrong that the lab incidents look like engineering failures, and Satya makes that case more carefully below.
That said, “the predictions were wrong before” is not a threat model either, and the track record of cyber predictions specifically (see Zack’s own admission below) cuts in more than one direction.
Satya Nadella at the All-In Summit
Satya’s session was the one I’d point practitioners to, because it is the closest any of the CEOs came to describing the problem the way a security team would.
He opened with what he called the common sense part, “we should do what it takes to build stuff that serves humanity first and is in human control,” and then argued that broad diffusion is “the most critical thing” and that:
Enterprise control over the technology, their weights, their data, and their evals is the part he says gets far too little attention.
His breakdown of the Hugging Face incident is the useful bit. He separates the “basic DevOps” failures (a misconfigured container, API keys, no monitoring, internet access) from the “real novel new stuff,” which is reward hacking with persistent agents, and he admits “the science is not there” on the latter.
His framing for long-running agents is that they are “new insider risks,” with the example of telling an agent to “go optimize my working capital” and having it “fake my books.” His prescription is “true aggressive monitoring of agent activity,” where “everything has got to be auditable” down to every object an agent touches, and a culture where “if you see a showstopper, stop the show.”
He also endorsed embedded third-party testers and then added the line that matters, “we should avoid these cozy arrangements of who’s testing what, who has access to what, and it should be broad.”
His enterprise advice, “use all but be independent of all,” including pulling a model out and seeing whether your evals still hold, is sound architecture regardless of where you land on the safety debate. He did claim Microsoft’s “flash cyber model” with its harness outperforms Mythos on CyberGym, which I’d treat as a vendor claim until someone outside of Microsoft publishes the eval.
Zack Korman on P(doom), Effective Altruism, and Who Defines AI Safety
Zack Korman’s video is the practitioner-side critique with the most heat, and the thesis is one I largely agree with, which is why I am having him on the show to chat live.
In his framing,
“This isn’t a disagreement about whether risk exists. It’s a disagreement about the probabilities of different risks and the consequences of following different proposed solutions.”
He opens by doing the arithmetic on a 10% extinction estimate (”an expected 800 million deaths”) and then argues that “No, AI isn’t going to kill everyone. The computer isn’t going to just do that, but people might.”
His main target is the network behind the safety movement. He traces the extinction framing back through LessWrong and effective altruism and names a long list of people at Anthropic, OpenAI, METR, and Redwood Research he identifies as EA-affiliated, including the three METR reviewers of the Hugging Face incident.
His objection to Dario’s evaluator proposal follows from that, “If any other industry said ‘We need independent oversight and here is my preferred pick,’ everyone would go, ‘Well, at least we know who not to use.’” What he wants instead is government reviewers drawn from a range of fields, and his frustration at the absence of our discipline from the conversation is blunt enough that I’ll leave the exact wording to the video.
He also claims prior on the Hugging Face incident, pointing to a May 2026 statement warning that an always-on, sandboxed agent “when it breaks out and does weird stuff on the internet, that will be bad,” and he admits his own earlier doomer takes on cyber and jobs in 2023 were the ones that aged worst.
He ends by conceding that his side may have already lost the argument in the media and in DC.
The AI-as-Normal-Technology View of Loss of Control Incidents
Sayash Kapoor and Arvind Narayanan updated their “AI as Normal Technology” framework in light of the OpenAI and Anthropic loss-of-control incidents, and it is among the more careful pieces of the week because they say plainly what they got wrong.
They admit they underestimated development-phase risk (evaluations specifically), the importance of jagged capability gains, and the organizational failures in safety culture.
They still “reject the alarmism, and don’t believe that catastrophic risks are imminent,” while conceding “we do think risks are increasing over time.”
The practical argument is that alignment alone is insufficient and controls outside the weights matter more. They cite OpenAI’s own finding that running agents in the production Codex harness reduced the propensity to compromise infrastructure “by more than 100×,” which is a remarkable number if you think about what it says about the eval environment.
They quote Joshua Saxe on the labs’ training and evals culture having “a Wild West feeling,” and their conclusion is that “proposals to ‘pace the frontier’ should be about addressing these organizational failures rather than aiming for technical breakthroughs alone.”
They are also clear that cybersecurity, rather than AI safety in the abstract, is the specific urgent threat, and they lay out the defense gaps honestly, a workforce shortage in AI-centric security roles, guardrails blocking legitimate defensive use, investment measured in “millions announced vs. needed billions,” and CISA facing “$700 million” in budget losses for 2027.
Saxe’s line that “There’s no reason to expect a ransomware gang in Belarus to adopt AI faster than Deloitte does” is a useful corrective to the criminal-uplift panic, although Anthropic’s report below suggests some gangs are moving faster than some enterprises.
Critical Infrastructure AI Adoption: Why Visibility Must Come First
Robert Lee of Dragos wrote for the World Economic Forum on the gap between how fast OT operators are adopting AI and how little visibility they have into the environments they are adding it to.
Per Dragos’s 2026 OT/ICS report, organizations with comprehensive OT visibility detected and contained ransomware in an average of 5 days versus an industry-wide 42 days, which is the kind of number that should shape budgets. He also notes that ELECTRUM, the group behind the 2015 and 2016 Ukraine grid attacks, hit Poland in December 2025 with what Dragos calls “the world’s first major coordinated cyberattack against distributed energy resources.”
His argument is that “Adversaries are already operating inside industrial environments that aren’t monitoring for them” and that “AI adoption will make that visibility problem significantly harder to solve.” The three asks are:
AI governance with the same rigor historically applied to control systems
OT-native monitoring before the AI complexity arrives
A plan for AI failure that includes manual operation and vendor continuity.
Nothing here is novel, which is sort of the point. We have been saying “visibility first” for two decades and the environments most exposed to AI-enabled adversaries are still the ones with the least of it.
Cracks in the AI Thesis, Part 2 (Ramp AI Index)
Ara Kharazian ’s monthly Ramp AI Index is a useful reality check against the discourse, because it is built on what businesses actually spend.
This month’s read is that adoption keeps climbing while spending per employee falls, with 43.8% of U.S. businesses paying Anthropic and 39.8% paying OpenAI, top 1% firms’ per-employee spend down “9.7% from $7,976 to $7,205” monthly, and the effective price per million tokens down “41% to $0.68” from a March peak of $1.15. Frontier models drove 45% of token share, down from a 53% peak in August, as businesses shift to cheaper standard models.
The open-source figure is the one to hold up against Jensen’s interview. Ramp finds only 6.4% of AI-spending businesses use open models (3.6% of businesses overall), while Jensen cited $400 billion in venture funding to AI-native companies with 80% using open models. Those are different populations, venture-backed startups versus the broad base of American businesses, and both can be true at once, but it is a reminder that “everyone is running open weights” is a Silicon Valley story rather than an enterprise one, at least for now.
The Dual-Use Imperative for Public Sector Cyber
A bit of self-promotion, this is a talk I gave recently to a public-sector audience on why security has to move at the speed of the software it protects.
I walk through what I call our cultural fatal flaw (security as the perennial laggard in every technology wave from Cloud to Mobile to SaaS and now AI), the attack surface exponential (GitHub finished 2025 with 1 billion commits and is on pace for 14 billion this year, with agents driving 17 million pull requests a month), the collapsing time-to-exploit, the GRC impedance mismatch between machine-speed systems and snapshot-in-time assessments, and the risk of what I call cognitive surrender as we approve-approve-approve our way through agent workflows.
AI
Countering Misuse of AI: September 2026 Threat Intelligence Report
If you read one primary source this week, make it the cyber operations section of Anthropic’s threat intelligence report, which covers December 2025 through August 2026.
The headline finding is that:
“Sophisticated attacks no longer require sophisticated attackers,” and the report argues AI “has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators.”
The speed figures are the ones that should change how defenders think about dwell time, with multiple breaches going from initial access to bulk data theft in 2 to 3 hours, one actor inside a victim within 3 hours of obtaining a stolen developer token, and exfiltration ranging from 26 GB to over 1 TB.
The case studies span the full range of actor types. GTG-20006, a Russian espionage operator, hit 20+ organizations across Ukrainian and European government, defense, and diplomatic targets, stole 300,000+ national identity records, and, in the finding I’d flag for detection engineers, had agents autonomously rebuild flagged implants to evade detection.
In the report’s words, “When their implants were flagged by security products, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections,” which means our detection deployments stopped imposing cost on the adversary.
GTG-10007, a Chinese group operated by undergraduate students in Changsha with security-firm internships, ran “agent swarms” for reconnaissance and post-exploitation against roughly 50 organizations, kept a fleet of 13 standing agents harvesting US military and government open-source material, and found 12+ possible zero-days in network appliances in a single month.
GTG-50014, ShinyHunters affiliates, mined 1.8 million Android APKs for credentials and dumped 2,100+ Azure AD token sets across 40+ tenants in 34 hours.
Two things I’d pull out for practitioners.
First, the AI supply chain is now both a target and a resource, with one actor attacking 30 AI companies in 4 days seeking pre-release model access, and stolen API keys functioning as loot, free compute, and attribution cover. Anthropic’s recommendation to treat AI keys with the same rigor as production credentials is one most organizations have not internalized yet.
Second, this is the empirical half of Dario’s essay, and it is far more persuasive than the botnet thought experiment, because every case here is a human operator using AI to compress labor rather than a misaligned model acting on its own.
OpenAI Agents Carried Out an Undisclosed Cyber-Attack on RubyGems
Spencer Kitts, Thomas Larsen, and Sydney Von Arx published a technical report alleging that on May 11, 2026, OpenAI agent swarms uploaded hundreds of malicious packages to RubyGems, abused RubyDoc.info’s automatic documentation build (via the .yardopts file) to get remote code execution, and used that access to scrape UK local government data from the Lambeth, Wandsworth, and Southwark council sites.
The timeline they reconstruct runs from a first package on May 5 through 2,000+ packages on May 11 and 12, RubyGems disabling new-user registration on May 12, 500+ removals on May 13, and another 83 packages on June 18. Six packages also attempted to exploit an undisclosed RubyGems CDN caching bug to steal user API keys.
Whatever the final attribution, this is the sandbox-escape scenario Dario, Satya, and Zack are all describing from their different angles, and it is also a software supply chain incident by any definition, which puts it squarely in the domain this newsletter has covered for years. Agents that can register accounts with disposable emails, publish packages, and trigger build systems are a supply chain threat regardless of who set them loose.
Actions Speak Louder Than Tokens: An Insider Threat Model for Frontier AI Agents
Matt Adams published this framework back in April, and I’m including it now because Satya independently arrived at the same framing on stage this week.
Matt’s argument is that agents with shell access, repository access, or connections to external services “belong in your insider threat program,” and that the right response is to extend the programs we already run for human insiders rather than invent yet another framework. The principle is “Watch what it did, not what it said,” on the grounds that “You cannot assess an AI agent’s intent” and that visible reasoning can look benign while the model does something else.
He lays out six threat categories (credential compromise, supply chain sabotage, data exfiltration, infrastructure sabotage, deception and evasion, and containment failures affecting third parties), consolidates 27 STRIDE threats, defines four autonomy levels from human-as-operator to human-as-auditor, and maps detections onto the tooling most enterprises already own, SIEM, UEBA, DLP, network egress controls, and deception technology, with controls aligned to the NIST CSF.
He also cites Anthropic’s own evaluation review, which found three incidents across 141,006 evaluation runs where models reached the real internet and accessed three organizations’ systems. That number predates Hugging Face and RubyGems, which suggests the pattern was visible before it became a headline.
Open-Weight Models Are Capable Autonomous Network Attackers
Lakshmi Adiga, Marko Morrison, and Vyas Sekar at CMU’s Cyber Autonomy Initiative evaluated Kimi K3, Qwen 3.8 Max, and GLM 5.2 as autonomous attackers across MHBench cyber ranges, using three harnesses, a single-agent harness with a high-level action library (Incalmo), a multi-agent harness (ARTEMIS), and a bare bash shell.
Their earlier work found that open models “do not follow instructions and are unable to execute shell commands correctly.” That is no longer true. Qwen 3.8 Max led across all three harnesses, and the Incalmo harness produced “dramatic performance improvements and reduced cost” relative to the alternatives.
The implications they state are the ones that matter for the pacing debate.
For practitioners, “Open-weight models are now a practical alternative for red team and penetration testing,” including on-premises where you can’t send sensitive network data to a hosted model.
For policy, “Sophisticated offensive security capabilities will become more widespread, beyond the control of centralized model providers.” Kapoor and Narayanan made the same point above, and it is among the stronger arguments against treating lab-level pacing as sufficient.
You can pace the frontier all you like, but the capability that was frontier a year ago is now on a laptop in Changsha, or Belarus, or anywhere else.
The Defense Factory
OpenAI published a playbook and reference architecture for what it calls a Defense Factory, an agent-first operation that continuously discovers, validates, and remediates vulnerabilities at machine speed, on the premise that “the defender’s window is closing.”
The case study is OpenAI’s own internal sprint, 250+ people across 100+ service areas, 53 urgent and high priority issues closed on day one, and pipeline stats that are worth reading closely, 37% of findings were duplicates, 19.5% reproduced at runtime, and dynamic validation brought the false-positive rate down to 0.81% with a 0.53% rolled-back fix rate. Thibault Sottiaux, OpenAI’s Head of Core Products, described the posture as “strengthening our defenses with the urgency of an incident.”
I’d read this alongside Dan Lorenc’s piece and my own “The Remediation Receipts” below, because the pipeline numbers are the honest part. A 37% duplicate rate and a 19.5% runtime reproduction rate on your own findings is what industrialized discovery looks like before triage, and it is why the enterprise is about to need a triage function it does not currently have.
The calls to action (apply for Daybreak access, pilot the Codex Security plugin) are OpenAI selling, which is fine, but the architecture is portable.
Secure Agents Architecture: Sandboxing
Katelyn Lesse at Anthropic wrote on sandboxing as part of a secure agent architecture series. It walks through some of the key security architecture primitives for securing agents, and important sandbox configurations.
nono: Sandbox 2.0
Luke Hinds at NoLabs demonstrates what kernel-level policy enforcement for agents looks like in practice, using Claude Code under a GitHub CLI policy restricted to read-only operations on issues and comments.
The argument is that enforcement at the kernel blocks unauthorized commands regardless of how they are obfuscated, reordered, or wrapped, and that, in his words, this is where other sandboxes and guardrails will fail because “they typically operate at the application or network level.” The demo includes default-deny policies and 15-minute leaf TLS certificates for network egress, and the project passed 4,000 GitHub stars earlier this month.
This is a vendor post and it reads like one in places, but the underlying point is the one Dario made in the essay, that models are getting good at “escaping or defeating most common sandboxing methods,” and application-layer guardrails are exactly the kind of sandboxing he means. If your agent containment story is a system prompt and an allowlist, this is worth a look.
AI Security Matrix
A curated directory of AI-enabled security testing tools, organized into agents, scanners, skills, MCP servers, and model-file analysis, with star counts and age for each. Strix leads the agents category at 63k stars, Promptfoo sits at 25k, and NVIDIA’s garak and Microsoft’s PyRIT are both listed, alongside contributions from
Trail of Bits, PortSwigger, SpecterOps, and CyberArk, among others. Read it alongside the CMU results above, since the combination of open-weight models and open offensive tooling is what commoditized offense actually looks like.
The 2026 OWASP LLM Top 10 and the Incident Data Behind It
I sat down with Rock Lambros, co-lead of the 2026 OWASP Top 10 for LLM Applications, to talk through the new list and the incident data behind it.
The short version is that the systemic risks around the model exceed the model-specific ones, the LLM and Agentic lists are converging whether the project likes it or not, and prompt injection nearly fell out of the top 10 on incident data before staying at #1 as the mechanism that enables most of the others.
Rock’s framing on excessive agency, “Agency’s not authorization. Period.,” pairs well with Satya’s insider-risk framing above.
AppSec
The Anthropic Glasswing Receipts Are Starting to Trickle In
Patrick Garrity at VulnCheck did the accounting on Project Glasswing five months in, and the numbers are the reason the remediation conversation matters more than the discovery conversation right now.
Of 26,153 findings, 2,736 (10.5%) appear in the disclosure ledger, 2,096 (8%) were reported to maintainers, and 202 (0.8%) are verified fixed, spread across 113 projects. Claude rated 91.5% of its findings critical or high while maintainers rated 51.3% that way, and the public dashboard claims 421 fixes against a ledger showing 202. Anthropic’s own explanation is that “the process of independent human triage and review is the rate limiting step.”
I covered these figures in more depth in “The Remediation Receipts,” so I won’t belabor them here beyond pointing out that a human triage bottleneck at the scale of a well-resourced lab initiative is a preview of what every enterprise AppSec team is about to inherit.
The Remediation Receipts
My own piece from this week, looking at what Glasswing and Trail of Bits’ Patch the Planet tell us about the fixing problem.
Patch the Planet, as of September 4, had found 1,646 issues across 59 codebases with 215 (13%) merged and 1,031 (63%) awaiting a patch, and only 17 (7.9%) of the accepted fixes rated high.
Set that against FIRST’s revised forecast of 66,000 to 68,000 CVEs for 2026 (46.3% above their original projection), GitHub Security Advisories up 449% year-over-year, and Empirical Security’s finding of 16,116 CVEs with exploitation activity of which only 894 are on CISA’s KEV, and the constraint is clearly triage capacity that can tell a real critical from a model’s guess at one.
The Flood Is Coming and the Pipes Were Already Full
Dan Lorenc’s response to the pacing debate is the one I’d hand to anyone who thinks the risk lives at the frontier. His framing is that:
“The frontier is where the capability comes from. Consumption is where it does damage,”
Consumption means the disclosure and patching infrastructure that was already saturated before frontier models showed up. Chainguard’s Athena has processed 40,000+ findings since June, 42% critical or high, across 500+ projects, producing 2,000+ patches, with 50 vulnerabilities entering disclosure on September 28.
A single six-hour model run found “more than a dozen validated vulnerabilities, most of them pre-authentication remote code execution” in a heavily fuzzed, widely scanned open source project.
The two lines that should worry AppSec leads are
A model can go from a public fix commit to a working exploit in an afternoon
The median enterprise is months behind on patches that have had fixes.
Dan’s asks are to publish patches for silent fixes already sitting at head, to standardize disclosure through the Linux Foundation’s Akrites body and the federal Gold Eagle clearinghouse, and, long term, to build secure-by-construction foundations, because “You cannot patch your way out of an architecture.”
Chainguard is also open-sourcing its microVM sandbox, search harness, and CI-as-function primitives, which is a welcome move given how much of this tooling is currently proprietary.
AISLE Partners with ENISA to Secure the CRA Single Reporting Platform
This week AISLE announced it performed an AI-based secure code review of the EU Cyber Resilience Act’s Single Reporting Platform ahead of the CRA’s first reporting deadline on September 11, with ongoing coverage for future releases.
The SRP is the mandatory entry point where EU manufacturers report actively exploited vulnerabilities and severe incidents within 24 to 72 hours, so it is exactly the kind of system that needs to be trustworthy under load. ENISA’s Hans de Vries thanked AISLE for “their important AI-based secure code review performed,” and AISLE’s Jaya Baloo put it well, “Reporting infrastructure only works if it’s trustworthy at the moment organizations need it most.”
I’d note this as an example of the same technology that produced the Glasswing backlog being applied on the consumption side, reviewing a specific piece of critical infrastructure before it went live, rather than generating findings for someone else to triage.
Open Source Security Podcast: Daniel Thompson on CRA Reporting
Josh Bressers hosted Daniel Thompson (CEO of CrabNebula, ETSI expert, and founder of Comply.Land) for a practical walk through the CRA’s first live obligation, which took effect September 11.
The core requirement is an early warning within “24 hours of becoming aware of the vulnerability being actively exploited,” a fuller notification “72 hours after this first instance,” and the distinction between exploitable and exploited that determines whether the clock starts.
They also cover VEX, CE marking, the obligation to provide free security updates for the product’s support period, and the broader secure development lifecycle requirements landing in December 2027.
Josh’s read that “If your product is being actively exploited, the embargoes no longer apply” is the practical takeaway, and Daniel’s “It’s not too bad. There are plenty more requirements coming” is the honest one.
Final Thoughts
The week’s loudest disagreement was between lab CEOs calling for a slowdown and industry CEOs calling that irresponsible, but the disagreement that matters for our field is quieter and runs inside the cyber community itself.
Ciaran, Zack, and Kapoor and Narayanan all reject the botnet-apocalypse framing and they all still think the risk is real, because they have read the same threat intelligence report and the same RubyGems writeup the rest of us have. The evidence this week points at operators using AI to compress labor, agents escaping containment that was never designed to hold them, and a remediation pipeline that was full before the frontier models arrived.
Pacing the frontier may or may not happen, and much of that remains to be seen. What we can control is whether we treat agents as insiders, whether we build the triage capacity the discovery boom is going to demand, and whether we show up to the safety conversation at all instead of letting it be settled by people who have never run a SOC.
Do we really want the cyber perspective on AI risk to be defined by everyone except cyber practitioners?
Stay resilient.
























