
zetta
2.4K posts

zetta
@syskage
Sage of Six Operating Systems, SysKage the first. By clicking on this profile you are already under the effects of my genjutsu. // organizer for DC225



.@Microsoft’s May Patch Tuesday fixed 137 CVEs, including four critical Word RCE flaws exploitable via Preview Pane. No zero-days were reported for the first time since 2024. #cybersecurity #CISO #infosec bit.ly/3Pf7W3e

New video: Anthropic wants to decide who gets access to AI and what you're allowed to do with it. China is ruining that plan and I love it.




We've published a paper that explains our views on AI competition between the US and China. The US and democratic allies hold the lead in frontier AI today. Read more on what it’ll take to keep that lead: anthropic.com/research/2028-…





Most people’s model for security bugs is wrong. People have acted as though there is always an infinite number, because humans couldn’t find them faster than they could create them, but the number has always been finite. AI systems aren’t going to find every single one immediately, but they are draining the available supply fast, and new ones aren’t going to be created as quickly. Once we start using AI to improve the engineering, the supply is going to drop a great deal indeed, and operations that rely on a steady supply of them are going to have to find other ways to work.









how much longer is it gonna take for ai doomers to realize that ai genuinely accelerates everything for high agency people with adhd at this point they’re not even acting like luddites anymore they just completely misunderstand how useful these tools actually are

Security things from the last few days: - CopyFail (linux pwn'd) - CopyFail 2/Dirty Frag - 13 advisories in Next.js - Over 70 CVEs addressed in MacOS 26.5 - ~50 CVEs addressed in iOS 26.5 - YellowKey (Windows Bitlocker pwn'd entirely) - GreenPlasma (Windows privilege escalation) - CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE - CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access - Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning) - Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too" - Canvas (popular LMS used in most schools) pwn'd entirely - PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300 Are you scared yet?





