<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Can I bring your attention to one of the best security write-ups I’ve read in a long while.]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://infosec.exchange/@flyingpenguin/116399482954754093" rel="nofollow noopener"><span>https://</span><span>infosec.exchange/@flyingpengui</span><span>n/116399482954754093</span></a></p><p>Can I bring your attention to one of the best security write-ups I’ve read in a long while.</p><p>Bravo, Davi.</p><p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> flagged this one to me.</p>]]></description><link>https://board.circlewithadot.net/topic/c5040f89-775e-4691-96bd-fc194c553768/can-i-bring-your-attention-to-one-of-the-best-security-write-ups-i-ve-read-in-a-long-while.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:20:42 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/c5040f89-775e-4691-96bd-fc194c553768.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 21 Apr 2026 20:56:14 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Wed, 22 Apr 2026 04:33:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/simonzerafa%40infosec.exchange">@<span>simonzerafa</span></a></span> <span><a href="/user/catsalad%40infosec.exchange">@<span>catsalad</span></a></span> <span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> </p><p>Davi for the take-down!</p><blockquote><p>So sweet, so easy on the eyes, but hideous on the inside<br />Whole life spreading lies, but you can't hide, baby, nice try<br />I'm 'bout to switch up these vibes, I finally opened my eyes<br />It's time to kick you straight back into the night</p></blockquote><p><a href="https://youtu.be/l8Dr7vzMSVE" rel="nofollow noopener"><span>https://</span><span>youtu.be/l8Dr7vzMSVE</span><span></span></a></p><p><a href="https://infosec.exchange/tags/kpdh" rel="tag">#<span>kpdh</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/badsamurai/statuses/116446488196132809</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/badsamurai/statuses/116446488196132809</guid><dc:creator><![CDATA[badsamurai@infosec.exchange]]></dc:creator><pubDate>Wed, 22 Apr 2026 04:33:20 GMT</pubDate></item><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Wed, 22 Apr 2026 04:25:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/catsalad%40infosec.exchange">@<span>catsalad</span></a></span> <span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> </p><p>The Myth of Mythos <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f914.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--thinking_face" style="height:23px;width:auto;vertical-align:middle" title="🤔" alt="🤔" /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title="🤷" alt="🤷" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--male_sign" style="height:23px;width:auto;vertical-align:middle" title="♂" alt="♂" />️</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/simonzerafa/statuses/116446455636308608</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/simonzerafa/statuses/116446455636308608</guid><dc:creator><![CDATA[simonzerafa@infosec.exchange]]></dc:creator><pubDate>Wed, 22 Apr 2026 04:25:03 GMT</pubDate></item><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Tue, 21 Apr 2026 22:06:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/semitones%40tiny.tilde.website">@<span>semitones</span></a></span> <span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> <br />Selling memberships wasn't the best characterization; but they're restricting use of their new model to "select" OS and infrastructure partners _first_, before general availability so these partners can fix things FIRST. </p><p>Of course I am not a cybersecurity export, NOR an AI expert, so perhaps I lack the technical qualifications to tell if Ottenheimer is full of shit, but from what I DO know of software it made sense.</p>]]></description><link>https://board.circlewithadot.net/post/https://mas.to/users/tezoatlipoca/statuses/116444965422841643</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mas.to/users/tezoatlipoca/statuses/116444965422841643</guid><dc:creator><![CDATA[tezoatlipoca@mas.to]]></dc:creator><pubDate>Tue, 21 Apr 2026 22:06:04 GMT</pubDate></item><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Tue, 21 Apr 2026 22:02:06 GMT]]></title><description><![CDATA[<p><span><a href="/user/tezoatlipoca%40mas.to">@<span>tezoatlipoca</span></a></span> <span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> ah that makes Sense!! Did not realize they were selling memberships</p>]]></description><link>https://board.circlewithadot.net/post/https://tiny.tilde.website/users/semitones/statuses/116444949806604227</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tiny.tilde.website/users/semitones/statuses/116444949806604227</guid><dc:creator><![CDATA[semitones@tiny.tilde.website]]></dc:creator><pubDate>Tue, 21 Apr 2026 22:02:06 GMT</pubDate></item><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Tue, 21 Apr 2026 21:55:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/semitones%40tiny.tilde.website">@<span>semitones</span></a></span> <span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span></p><p>Anthropic's Glasswing is selling tickets to an exclusive club. Oh look, our Mythos model can find all these vulnerabilities in the softwares you use (it can't). You want secure software right? Well, better pay us $ for membership so you can stay on top of vulnerabilities WE discover.</p><p>Generally some having access and others NOT having access leads to abuse. </p><p>Problem is, as Ottenheimer lays out, Mythos doesn't actually do what Anthropic sales is claiming.</p>]]></description><link>https://board.circlewithadot.net/post/https://mas.to/users/tezoatlipoca/statuses/116444923216133085</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mas.to/users/tezoatlipoca/statuses/116444923216133085</guid><dc:creator><![CDATA[tezoatlipoca@mas.to]]></dc:creator><pubDate>Tue, 21 Apr 2026 21:55:20 GMT</pubDate></item><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Tue, 21 Apr 2026 21:49:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/semitones%40tiny.tilde.website">@<span>semitones</span></a></span> <span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> The terminology is a bit opaque if you don't live and breathe cubersecurity (I do not), not necessarily AI, but there's a pay off. Basically, Anthropic's claims about their new Claude Mythos AI model finding thousands of vulnerabilities in OS's and software is horseshit. Its no better than their previous Claude model. And their Project Glasswing is just a $VIP$ ticket to Emperor's New Clothesland.</p><p>OP's article is as layperson it can be given the subject.</p>]]></description><link>https://board.circlewithadot.net/post/https://mas.to/users/tezoatlipoca/statuses/116444901829451424</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mas.to/users/tezoatlipoca/statuses/116444901829451424</guid><dc:creator><![CDATA[tezoatlipoca@mas.to]]></dc:creator><pubDate>Tue, 21 Apr 2026 21:49:54 GMT</pubDate></item><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Tue, 21 Apr 2026 21:47:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/semitones%40tiny.tilde.website">@<span>semitones</span></a></span> <span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> Now, many CEOs are four years into their pivot, feel the same and couldn't care less.</p><p>So kudos to you <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p><p>(Yes, it is a very specific thing to read. But believe me: It could have been *waaaay* more technical if it wasn't for the excellent writing <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f605.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--sweat_smile" style="height:23px;width:auto;vertical-align:middle" title="😅" alt="😅" /> )</p>]]></description><link>https://board.circlewithadot.net/post/https://norden.social/users/ftranschel/statuses/116444893007587462</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://norden.social/users/ftranschel/statuses/116444893007587462</guid><dc:creator><![CDATA[ftranschel@norden.social]]></dc:creator><pubDate>Tue, 21 Apr 2026 21:47:39 GMT</pubDate></item><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Tue, 21 Apr 2026 21:24:10 GMT]]></title><description><![CDATA[<p><span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> Can someone explain this part? </p><p>&gt; Anthropic has established, without discussion and without pushback, that a private company can unilaterally classify a capability as too dangerous for the public, grant selective access to the largest incumbents in the affected industry, and construct a parallel disclosure regime outside any democratic accountability structure. That precedent is exclusivity for abuse. [...]<br />The model is not the story. A cartel is the story.</p>]]></description><link>https://board.circlewithadot.net/post/https://tiny.tilde.website/users/semitones/statuses/116444800616754214</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tiny.tilde.website/users/semitones/statuses/116444800616754214</guid><dc:creator><![CDATA[semitones@tiny.tilde.website]]></dc:creator><pubDate>Tue, 21 Apr 2026 21:24:10 GMT</pubDate></item><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Tue, 21 Apr 2026 21:20:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> </p><p>&gt; The verified facts in the document are real: XBOW topped HackerOne’s leaderboard, DARPA AIxCC found 54 vulnerabilities in four hours, Google Big Sleep found 20 zero-days in open source, Sysdig documented an AI attack reaching admin in eight minutes. Every one of those is independently confirmed by the organization that did the work, with named researchers, reproducible results, or public competition records. Every one of those also predates Mythos...</p><p>I had no idea</p>]]></description><link>https://board.circlewithadot.net/post/https://tiny.tilde.website/users/semitones/statuses/116444787233043123</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tiny.tilde.website/users/semitones/statuses/116444787233043123</guid><dc:creator><![CDATA[semitones@tiny.tilde.website]]></dc:creator><pubDate>Tue, 21 Apr 2026 21:20:45 GMT</pubDate></item><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Tue, 21 Apr 2026 21:04:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> I am 3 paragraphs in and I have no idea what's going on... <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61e.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--disappointed" style="height:23px;width:auto;vertical-align:middle" title=":(" alt="😞" /> I guess I should have learned more about ai</p>]]></description><link>https://board.circlewithadot.net/post/https://tiny.tilde.website/users/semitones/statuses/116444724590184812</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tiny.tilde.website/users/semitones/statuses/116444724590184812</guid><dc:creator><![CDATA[semitones@tiny.tilde.website]]></dc:creator><pubDate>Tue, 21 Apr 2026 21:04:49 GMT</pubDate></item><item><title><![CDATA[Reply to Can I bring your attention to one of the best security write-ups I’ve read in a long while. on Tue, 21 Apr 2026 20:59:28 GMT]]></title><description><![CDATA[<p><span><a href="/user/securitywriter%40infosec.exchange">@<span>SecurityWriter</span></a></span> <span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> </p><blockquote><p>Whomp. Whomp. Sad trombone.</p></blockquote>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/catsalad/statuses/116444703492948239</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/catsalad/statuses/116444703492948239</guid><dc:creator><![CDATA[catsalad@infosec.exchange]]></dc:creator><pubDate>Tue, 21 Apr 2026 20:59:28 GMT</pubDate></item></channel></rss>