







Vulnerability discovery has always been gated by elite attention. Elite attention is now abundant. What happens next?
Vulnerability Reports Are Not Special Anymore
We needed the insight and confidentiality to protect our users, but now that anyone can get the same results from LLM?

AI CVE Slop: The Crisis Drowning Open Source Security
The proliferation of AI-generated vulnerability reports — commonly termed “AI slop” — has emerged as one of the most significant…
Security incident disclosure — July 2026
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
Center for Responsible, Decentralized Intelligence at Berkeley
Our agent hacked every major one. Here’s how — and what the field needs to fix.
AI, open code and vulnerability risk in the public sector
Guidance for safely publishing source code in the open, and reducing the risk of AI-accelerated vulnerability discovery.

Top AI Security Incidents of 2025 Revealed | Adversa AI
Discover how AI systems are being hacked in the wild — from prompt injection to agent abuse — with real breaches, lessons, and defenses in Adversa AI’s 2025 report.

A quote from Daniel Stenberg
The challenge with AI in open source security has transitioned from an AI slop tsunami into more of a ... plain security report tsunami. Less slop but lots of reports. …
US launches vulnerability clearinghouse amid AI-fueled surge in flaws
The Trump administration hopes the program will accelerate the discovery and fixing of serious technical problems before hackers exploit them.

Securing our future: July 2026 progress report on Microsoft's Secure Future Initiative | Microsoft Security Blog
Microsoft’s latest Secure Future Initiative report outlines progress on secure foundations, AI-powered defense, and future-ready cybersecurity.

The Intelligence Curse
This series examines the incoming crisis of human irrelevance and provides a map towards a future where people remain the masters of their destiny.

AI’s Hacking Skills Are Approaching an ‘Inflection Point’
AI models are getting so good at finding vulnerabilities that some experts say the tech industry might need to rethink how software is built.

Vigilantism comes for Flock
More Americans than ever are destroying Flock license plate cameras amid rising backlash against the company. Is the tide turning on intrusive U.S. mass surveillance, and where does the privacy fight go next?

Mitchell Hashimoto (@mitchellh)
I strongly believe there are entire companies right now under heavy AI psychosis and its impossible to have rational conversations about it with them. I can't name any specific people because they include personal friends I deeply respect, but I worry about how this plays out. I lived through the great MTBF vs MTTR (mean-time-between-failure vs. mean-time-to-recovery) reckoning of infrastructure during the transition to cloud and cloud automation. All those arguments are rearing their ugly heads again but now its... the whole software development industry (maybe the whole world, really). It's frightening, because the psychosis folks operate under an almost absolute "MTTR is all you need" mentality: "its fine to ship bugs because the agents will fix them so quickly and at a scale humans can't do!" We learned in infrastructure that MTTR is great but you can't yeet resilient systems entirely. The main issue is I don't even know how to bring this up to people I know personally, because bringing this topic up leads to immediately dismissals like "no no, it has full test coverage" or "bug reports are going down" or something, which just don't paint the whole picture. We already learned this lesson once in infrastructure: you can automate yourself into a very resilient catastrophe machine. Systems can appear healthy by local metrics while globally becoming incomprehensible. Bug reports can go down while latent risk explodes. Test coverage can rise while semantic understanding falls. Changes happens so fast that nobody notices the underlying architecture decaying. I worry.
The Hacker and the State: Cyber Attacks and the New Nor…
Packed with insider information based on interviews, de…

Capturing our Attention by @neillevy.bsky.social "we possess sophisticated capacities of epistemic vigilance, which work reasonably well to distinguish reliable from unreliable information, but ... we do not have parallel defences against attentional capture" > tandfonline.com/doi/full/10.1080/00048402.202…