<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #ai-security</title><description>Articles tagged ai-security on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>Days after opening Fable 5 to the public, a US government order forced Anthropic to pull it</title><link>https://devtake.dev/article/anthropic-fable-mythos-government-suspension/</link><guid isPermaLink="true">https://devtake.dev/article/anthropic-fable-mythos-government-suspension/</guid><description>A Commerce Department export directive forced Anthropic to disable Fable 5 and Mythos 5 for all users, days after opening Fable 5 to the public.</description><pubDate>Sat, 13 Jun 2026 14:30:00 GMT</pubDate><category>ai</category><category>ai-models</category><category>anthropic</category><category>claude</category><category>claude-mythos</category><category>ai-security</category><category>policy</category><author>dieter-morelli</author></item><item><title>Anthropic is sending Mythos 5, the model it called too dangerous, to cyberdefenders and the US government</title><link>https://devtake.dev/article/claude-mythos-5-cyberdefenders/</link><guid isPermaLink="true">https://devtake.dev/article/claude-mythos-5-cyberdefenders/</guid><description>Mythos 5 is the same model as Fable 5 with cyber safeguards lifted, going to Project Glasswing defenders and, Anthropic says, ~150 orgs across 15+ countries.</description><pubDate>Tue, 09 Jun 2026 18:40:00 GMT</pubDate><category>policy</category><category>anthropic</category><category>claude-mythos</category><category>project-glasswing</category><category>policy</category><category>national-security</category><category>ai-safety</category><category>ai-security</category><category>cybersecurity</category><author>clara-wexler</author></item><item><title>OpenAI added a Lockdown Mode to ChatGPT to blunt prompt-injection attacks</title><link>https://devtake.dev/article/openai-lockdown-mode-prompt-injection/</link><guid isPermaLink="true">https://devtake.dev/article/openai-lockdown-mode-prompt-injection/</guid><description>OpenAI shipped Lockdown Mode in ChatGPT to cut off the data-exfiltration step of prompt-injection attacks. Here&apos;s what it actually restricts and who should turn it on.</description><pubDate>Mon, 08 Jun 2026 10:15:00 GMT</pubDate><category>ai</category><category>openai</category><category>ai-security</category><category>prompt-injection</category><category>llm</category><category>ai-agents</category><author>dieter-morelli</author></item><item><title>Trump dropped the mandatory AI model review after Silicon Valley pushed back</title><link>https://devtake.dev/article/trump-narrower-ai-executive-order/</link><guid isPermaLink="true">https://devtake.dev/article/trump-narrower-ai-executive-order/</guid><description>Trump&apos;s June 2 AI executive order asks for a voluntary 30-day model review, down from a mandatory 90-day one. Here&apos;s what got cut and who pushed.</description><pubDate>Wed, 03 Jun 2026 13:00:00 GMT</pubDate><category>policy</category><category>policy</category><category>regulation</category><category>ai-security</category><category>national-security</category><category>ai-models</category><author>clara-wexler</author></item><item><title>Anthropic&apos;s Glasswing logged 10,000 vulnerabilities in a month. Most are still waiting on a patch.</title><link>https://devtake.dev/article/anthropic-glasswing-deception-monitor/</link><guid isPermaLink="true">https://devtake.dev/article/anthropic-glasswing-deception-monitor/</guid><description>Anthropic says Project Glasswing&apos;s first month produced over 10,000 critical-and-high-severity vulns. Verification and patching is the limiting step.</description><pubDate>Sat, 23 May 2026 09:45:00 GMT</pubDate><category>ai</category><category>anthropic</category><category>claude-mythos</category><category>project-glasswing</category><category>security</category><category>ai-security</category><category>supply-chain</category><category>vulnerability-disclosure</category><author>dieter-morelli</author></item><item><title>Sadiq Khan blocked a £50M Met Police deal with Palantir. Scotland Yard had only talked to one supplier.</title><link>https://devtake.dev/article/khan-blocks-met-police-palantir-50m/</link><guid isPermaLink="true">https://devtake.dev/article/khan-blocks-met-police-palantir-50m/</guid><description>London&apos;s mayor cited a &apos;clear and serious breach&apos; of procurement rules and stopped the Metropolitan Police from awarding Palantir a £50M AI intelligence contract on May 21.</description><pubDate>Fri, 22 May 2026 09:45:00 GMT</pubDate><category>policy</category><category>policy</category><category>palantir</category><category>uk</category><category>regulation</category><category>ai-security</category><category>surveillance</category><category>procurement</category><category>london</category><author>clara-wexler</author></item><item><title>A bad command-line parser turned every claude-cli:// link into a remote shell</title><link>https://devtake.dev/article/claude-code-rce-deeplink-cve/</link><guid isPermaLink="true">https://devtake.dev/article/claude-code-rce-deeplink-cve/</guid><description>Joernchen of 0day.click found a deeplink RCE in Claude Code. Anthropic shipped the fix in 2.1.118 the same week.</description><pubDate>Wed, 20 May 2026 09:15:00 GMT</pubDate><category>security</category><category>security</category><category>anthropic</category><category>claude-code</category><category>rce</category><category>ai-security</category><category>supply-chain</category><category>ai-agents</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>F5 patched an 18-year-old NGINX bug. Attackers can RCE a third of the web with one crafted request.</title><link>https://devtake.dev/article/nginx-rift-18-year-rce/</link><guid isPermaLink="true">https://devtake.dev/article/nginx-rift-18-year-rce/</guid><description>F5 disclosed CVE-2026-42945 on May 13 after depthfirst&apos;s analyzer found a heap overflow in a 2008 commit. NGINX 1.31.0 ships the patch, every Plus tier needs an upgrade.</description><pubDate>Thu, 14 May 2026 10:30:00 GMT</pubDate><category>security</category><category>security</category><category>nginx</category><category>f5</category><category>cve-2026-42945</category><category>rce</category><category>heap-overflow</category><category>depthfirst</category><category>ai-security</category><author>luca-reinhardt</author></item><item><title>A crafted Ollama model file leaks the whole server&apos;s memory. 300,000 instances are exposed.</title><link>https://devtake.dev/article/ollama-bleeding-llama-cve-2026-7482/</link><guid isPermaLink="true">https://devtake.dev/article/ollama-bleeding-llama-cve-2026-7482/</guid><description>Cyera disclosed CVE-2026-7482 on May 1, a CVSS 9.1 unauthenticated heap read in Ollama. Three API calls dump prompts, env vars, and API keys from any open instance.</description><pubDate>Mon, 11 May 2026 10:00:00 GMT</pubDate><category>security</category><category>security</category><category>ollama</category><category>llm</category><category>cve-2026-7482</category><category>local-inference</category><category>memory</category><category>cyera</category><category>ai-security</category><author>luca-reinhardt</author></item><item><title>Chinese proxy networks sell Claude API access at 90% off. They harvest every prompt that passes through.</title><link>https://devtake.dev/article/chinese-grey-market-claude-api-stolen-credentials/</link><guid isPermaLink="true">https://devtake.dev/article/chinese-grey-market-claude-api-stolen-credentials/</guid><description>A ChinaTalk investigation reveals how &apos;transfer stations&apos; resell Anthropic API access using stolen credentials, model substitution, and prompt harvesting.</description><pubDate>Sun, 10 May 2026 09:30:00 GMT</pubDate><category>ai</category><category>anthropic</category><category>claude</category><category>ai-security</category><category>credential-theft</category><category>china</category><category>supply-chain</category><category>ai-models</category><author>dieter-morelli</author></item><item><title>A judge killed DOGE&apos;s grant purge. The &apos;review process&apos; was asking ChatGPT &apos;Is this DEI?&apos;</title><link>https://devtake.dev/article/doge-chatgpt-grants-ruling-illegal/</link><guid isPermaLink="true">https://devtake.dev/article/doge-chatgpt-grants-ruling-illegal/</guid><description>A federal judge restored $100M+ in grants after two DOGE staffers used ChatGPT to flag 97% of NEH grants as DEI, including an HVAC repair and Holocaust research.</description><pubDate>Sat, 09 May 2026 08:30:00 GMT</pubDate><category>policy</category><category>policy</category><category>ai-security</category><category>openai</category><category>regulation</category><category>ai-agents</category><category>national-security</category><author>clara-wexler</author></item><item><title>380,000 vibe-coded apps are sitting on the open web. 5,000 of them are leaking real data.</title><link>https://devtake.dev/article/vibe-coded-apps-expose-corporate-data/</link><guid isPermaLink="true">https://devtake.dev/article/vibe-coded-apps-expose-corporate-data/</guid><description>RedAccess found that AI coding tools like Lovable, Base44, and Replit default to public hosting, leaving medical records, bank internals, and corporate secrets indexed by Google.</description><pubDate>Sat, 09 May 2026 08:00:00 GMT</pubDate><category>security</category><category>security</category><category>ai-security</category><category>ai-agents</category><category>dev-tools</category><category>supply-chain</category><category>privacy</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Five Eyes intel agencies publish first joint agentic AI security guide. Their advice: slow down.</title><link>https://devtake.dev/article/five-eyes-agentic-ai-warning/</link><guid isPermaLink="true">https://devtake.dev/article/five-eyes-agentic-ai-warning/</guid><description>CISA, NSA, GCHQ, ASD, CSE and NCSC-NZ jointly tell organizations agentic AI isn&apos;t ready for fast rollout. The 23-page guide names five risk categories.</description><pubDate>Mon, 04 May 2026 09:50:00 GMT</pubDate><category>security</category><category>security</category><category>ai-security</category><category>ai-agents</category><category>agents</category><category>cisa</category><category>nsa</category><category>policy</category><category>regulation</category><author>luca-reinhardt</author></item><item><title>A malicious GGUF file owns your SGLang server: CVE-2026-5760 is an unpatched 9.8</title><link>https://devtake.dev/article/sglang-cve-2026-5760-gguf-rce/</link><guid isPermaLink="true">https://devtake.dev/article/sglang-cve-2026-5760-gguf-rce/</guid><description>SGLang&apos;s reranker renders chat templates without a sandbox. Load a hostile GGUF, hit /v1/rerank, and the attacker has Python on your inference box. No patch yet.</description><pubDate>Mon, 27 Apr 2026 11:30:00 GMT</pubDate><category>security</category><category>sglang</category><category>cve-2026-5760</category><category>supply-chain</category><category>ai-security</category><category>llm</category><category>rce</category><category>jinja2</category><category>gguf</category><author>luca-reinhardt</author></item><item><title>A Discord group guessed Anthropic&apos;s URL pattern and walked into Claude Mythos</title><link>https://devtake.dev/article/anthropic-mythos-breach-discord/</link><guid isPermaLink="true">https://devtake.dev/article/anthropic-mythos-breach-discord/</guid><description>Bloomberg reports a small group accessed Anthropic&apos;s locked-down Mythos model the same day it launched, using credentials from a third-party contractor and educated URL guessing.</description><pubDate>Sat, 25 Apr 2026 11:00:00 GMT</pubDate><category>ai</category><category>anthropic</category><category>claude-mythos</category><category>ai-security</category><category>supply-chain</category><category>project-glasswing</category><category>mercor</category><category>security</category><author>dieter-morelli</author></item><item><title>Malicious npm and PyPI packages turn dev servers into Chinese LLM proxies</title><link>https://devtake.dev/article/gpt-proxy-npm-supply-chain/</link><guid isPermaLink="true">https://devtake.dev/article/gpt-proxy-npm-supply-chain/</guid><description>Aikido found a stage-2 Go binary inside two health-check-themed packages that runs an OpenAI-compatible router routing Claude, GPT, and Gemini traffic through Chinese aggregators.</description><pubDate>Sat, 25 Apr 2026 07:30:00 GMT</pubDate><category>security</category><category>supply-chain</category><category>npm</category><category>pypi</category><category>ai-security</category><category>malware</category><category>llm</category><category>china</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Linux 7.1 is yanking ham radio, ISDN, and ATM. The reason: AI bug-report spam.</title><link>https://devtake.dev/article/linux-7-1-ham-radio-isdn-removal/</link><guid isPermaLink="true">https://devtake.dev/article/linux-7-1-ham-radio-isdn-removal/</guid><description>Jakub Kicinski&apos;s networking pull request removes 138,161 lines of decades-old code. Kernel maintainers say LLM-generated bug reports made the old subsystems un-maintainable.</description><pubDate>Fri, 24 Apr 2026 21:00:00 GMT</pubDate><category>open-source</category><category>linux</category><category>linux-kernel</category><category>linux-7-1</category><category>kernel</category><category>ai-security</category><category>networking</category><category>open-source</category><category>security</category><author>soren-vanek</author></item><item><title>Mozilla fixed 271 Firefox bugs that Claude Mythos found. Its own tests caught 22.</title><link>https://devtake.dev/article/mozilla-firefox-mythos-bug-hunt/</link><guid isPermaLink="true">https://devtake.dev/article/mozilla-firefox-mythos-bug-hunt/</guid><description>Firefox 150 shipped Monday with 271 security fixes from Anthropic&apos;s Project Glasswing. Mozilla CTO Bobby Holley says Mythos matches elite human researchers.</description><pubDate>Wed, 22 Apr 2026 13:00:00 GMT</pubDate><category>open-source</category><category>mozilla</category><category>firefox</category><category>anthropic</category><category>claude-mythos</category><category>project-glasswing</category><category>security</category><category>ai-security</category><author>soren-vanek</author></item><item><title>OpenAI launches GPT-5.4-Cyber for defensive security, opens access to thousands</title><link>https://devtake.dev/article/openai-gpt54-cyber-security-model/</link><guid isPermaLink="true">https://devtake.dev/article/openai-gpt54-cyber-security-model/</guid><description>OpenAI&apos;s new cybersecurity-tuned model can reverse-engineer binaries and analyze malware. It&apos;s restricted to verified defenders through the Trusted Access program.</description><pubDate>Thu, 16 Apr 2026 08:00:00 GMT</pubDate><category>ai</category><category>openai</category><category>cybersecurity</category><category>gpt-5-4</category><category>claude-mythos</category><category>defensive-security</category><category>ai-security</category><author>dieter-morelli</author></item></channel></rss>