1_DevOps'ish

1_DevOps'ish

56463 bookmarks
Custom sorting
The OpenAI Hack Shows the Genie Is Out of the Bottle - Schneier on Security
The OpenAI Hack Shows the Genie Is Out of the Bottle - Schneier on Security
This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks. Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to ...
·schneier.com·
The OpenAI Hack Shows the Genie Is Out of the Bottle - Schneier on Security
Should You Self-Host LLM Inference? Cost and Risk Guide
Should You Self-Host LLM Inference? Cost and Risk Guide
Self-host LLM inference when you clear ~2M tokens a day or face data-privacy rules. Below that, an API is cheaper. Most teams want a hybrid.
·open.substack.com·
Should You Self-Host LLM Inference? Cost and Risk Guide
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or imported these versions, you must assume your environment is compromised.
·research.jfrog.com·
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
How Agentic Coding Is Reshaping the Software Development Lifecycle - Battery Ventures
How Agentic Coding Is Reshaping the Software Development Lifecycle - Battery Ventures
Software development has emerged as the killer use case for generative AI today, with half of all tokens consumed on OpenRouter being used for code generation. Cursor, for example, has ramped from $100M to $4B of ARR in the last 12 months. We’re in the first innings of the biggest shift in the history of… Continue reading How Agentic Coding Is Reshaping the Software Development Lifecycle
·battery.com·
How Agentic Coding Is Reshaping the Software Development Lifecycle - Battery Ventures
The Build vs Buy Head Fake
The Build vs Buy Head Fake
In January 2026, Anthropic released the massive ecosystem launch of Claude Cowork.
·open.substack.com·
The Build vs Buy Head Fake
White House finalizes AI framework behind closed doors
White House finalizes AI framework behind closed doors
The White House said it met its deadline to establish a voluntary framework for evaluating advanced AI models — but it won't say what the framework contains.
·axios.com·
White House finalizes AI framework behind closed doors
GitHub has alternatives, but no replacement
GitHub has alternatives, but no replacement
Why forges like Codeberg, GitLab, and Forgejo can replace GitHub's code hosting—but not its shared social layer.
·lalitm.com·
GitHub has alternatives, but no replacement
Ruby on Rails Patches Critical Vulnerability
Ruby on Rails Patches Critical Vulnerability
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).
·securityweek.com·
Ruby on Rails Patches Critical Vulnerability