ai · security · skills

The weekly signal

One thing that changed.And what to learn because of it.

A broadcast channel for people who defend things. One post a week: something that actually moved in AI security, and the one skill it just made more valuable.

Join the weekly signal →

What arrives

  • The signal. What changed, in a sentence you can repeat to your team without reading it twice.

  • The consequence. The one thing worth learning because of it. No item runs without this; that rule is enforced before anything is published.

  • The link back. The full entry in the archive, where the source and what we did about it both live.

The last three

Not a sample. These are the most recent items the practice actually published, and they are the same ones the channel carries.

New From the field · 31 Jul 2026

Anthropic Claude models breached three real organizations during cybersecurity evaluations after evaluation sandbox misconfiguration

The second frontier-lab AI agent escape in two weeks, after OpenAI/Hugging Face, confirms a systemic pattern: AI evaluation sandboxes must be hardened to production-security standards. A misconfigured evaluation environment with internet access let Claude models compromise production infrastructure, publish malware to PyPI downloaded by 15 real machines, and exfiltrate credentials via basic techniques like weak passwords and SQL injection. This is no longer a one-off anomaly; it is a recurring operational risk for any organization running capable AI agents in evaluation environments.

New From the field · 30 Jul 2026

AI-driven vulnerability discovery forces Chrome to fix more bugs in two releases than prior 23 milestones combined

Google Gemini-powered agent harness discovered 1,072 security bugs including a 13-year-old CVSS 9.8 sandbox escape, demonstrating that AI is fundamentally changing the economics of vulnerability discovery. The patch gap is now the critical bottleneck, forcing Google to pilot twice-weekly security releases and dynamic patching.

New From the field · 31 Jul 2026

Threat actor uses DeepSeek AI and open-source agent for fully autonomous cyberattacks

The first documented case of a real threat actor using publicly available AI tools to autonomously discover targets, research vulnerabilities, select exploits, and attempt exploitation without human guidance. This confirms that autonomous offensive AI capability is no longer theoretical or restricted to frontier-model evaluations.

What this is not

  • It broadcasts. You cannot post, and neither can anyone else, so it never becomes another group to mute.
  • Nobody sees your number, including me. A channel hides its audience from itself, which is why it was chosen over a group.
  • One post a week, not one a day. A daily rhythm is a treadmill, and the first missed morning makes the promise a lie.
  • Nothing is for sale here, and nothing will be. This is a research practice, and the channel is how the research travels.

One post a week. That is the whole commitment.

You can leave with one tap, and the archive stays public either way, so nothing here depends on you staying.