חליבה לקח אחריות והתפטר.
רוצים לשים אותו בכלא? תקימו ועדת חקירה ממלכתית ותשפטו אותו.
לא רוצים כזאת מטעמים פוליטיים? אחלה, אז תמשיכו לראות אותו מחייך עם שיער טוב בחו״ל (אחלה תספורת. לא הייתי מזהה אותו בחיים).
so I looked deeper into the leaked claude code source.
>found a kill switch named tengu_miraculo_the_bard
>anthropic can remotely disable fast mode (priority API access) for any user without pushing an update. flip one flag, it reads stale cache instead of checking live status.
>the internal codename for claude code is “tengu” every telemetry event logs under that name.
the reddit post attached show where someone thought they had malware when it’s just anthropic’s remote config so every tengu_ flag controls your install from their servers , session memory, background agents, prompt caching all toggleable without touching your binary.
>someone at anthropic is naming these kill switches after proust characters and australian marsupials.
>hidden --advisor flag that runs a second model alongside claude as a silent advisor. not in the help menu. completely undocumented.
in short, they can just.. turn your stuff off.
sure, it’s not open source so they can do what they want. but most people assume a local CLI tool is theirs when it’s not
so every launch, they update your flags and you never see it
so... I audited Garry's website after he bragged about 37K LOC/day and a 72-day shipping streak.
here's what 78,400 lines of AI slop code actually looks like in production.
a single homepage load of https://t.co/TqaEZsF44N downloads 6.42 MB across 169 requests.
for a newsletter-blog-thingy.
1/9🧵
If you have a spare 25 minutes I wholeheartedly recommend you watch Nicholas Carlini - Black-hat LLMs. Link in the comment below.
Amazing talk on the way LLMs are making it easier to find critical software vulnerabilities - Anthropic's LLM discovered a non-trivial heap buffer overflow in the Linux kernel that's been there since 2003..!
The future is both exciting and scary. LLMs and AI should be used, as demonstrated here, as a force multiplier for analysts, researchers and developers. I also think LLMs are a good way for people to learn, so long as they do not just copy paste AI output blindly, and treat it as a pair programmer / colleague they converse with to learn and grow. LLMs are also pretty good at hunting through documentation, it's like a knife through butter - you can then go verify what it comes back with and use that as an off point. A tool in your toolbox - not to be someone's sole skill. And remember, always validate the output.
Personal take - hopefully we see growth with LLMs over the coming months and years to make software more secure through QA such as in the video looking for vulnerabilities, and LLMs used in Cyber Security to help identify and detect threats from logs sooner, being an assistant to analysts.
Great question at the end (simplified): How do we prevent threat actors from abusing this; A: Security is dual use - historically security software tooling has favoured the defender over the attacker, maybe that will change. The good people should have access to the software - they want the good people to use the software to find the bugs, but putting the right safeguards in place is hard and nuanced, they think currently it is ok, but still room for change.
This story keeps getting more interesting.
A SuperMicro cofounder just got caught smuggling $2.5 Billion of Nvidia GPUs into China… using a hairdryer.
This is just the tip of the iceberg!
Here’s a quick tldr if you aren’t up to speed:
(🧵1)
Congrats to the @cursor_ai team on the launch of Composer 2!
We are proud to see Kimi-k2.5 provide the foundation. Seeing our model integrated effectively through Cursor's continued pretraining & high-compute RL training is the open model ecosystem we love to support.
Note: Cursor accesses Kimi-k2.5 via @FireworksAI_HQ ' hosted RL and inference platform as part of an authorized commercial partnership.
🧵 I just reverse-engineered the binaries inside Claude Code's Firecracker MicroVM and found something wild:
Anthropic is building their own PaaS platform called "Antspace" (Ants + Space).
It's a full deployment pipeline — hidden in plain sight inside the environment-runner binary. Here's what I found 👇
AI agents told to conduct routine tasks on a simulated corporate network went rogue. "No adversarial prompting was involved. The agents independently discovered vulnerabilities, escalated privileges, disabled security tools, and exfiltrated data." https://t.co/jDjDgPb5rk
Amazon is holding a mandatory meeting about AI breaking its systems. The official framing is "part of normal business." The briefing note describes a trend of incidents with "high blast radius" caused by "Gen-AI assisted changes" for which "best practices and safeguards are not yet fully established." Translation to human language: we gave AI to engineers and things keep breaking?
The response for now? Junior and mid-level engineers can no longer push AI-assisted code without a senior signing off. AWS spent 13 hours recovering after its own AI coding tool, asked to make some changes, decided instead to delete and recreate the environment (the software equivalent of fixing a leaky tap by knocking down the wall). Amazon called that an "extremely limited event" (the affected tool served customers in mainland China).
October 2022: Elon closed the deal on Twitter.
April 2023: Twitter was merged into X Corp.
Since this happened…
Young adults identifying as LGBTQ has DROPPED 23% after the propaganda was shutoff.
Saving innocent children from this was perhaps Elon’s greatest accomplishment.
Sounds incredible until you read the fine print. The compiler generates less efficient code than GCC with all optimizations disabled. It doesn’t have its own assembler or linker. It can’t produce a 16-bit x86 code generator. And Carlini himself says it has “nearly reached the limits of Opus’s abilities.” New features and bugfixes kept breaking existing functionality.
So what did $20,000 and two weeks actually buy? A compiler that passes 99% of GCC’s torture tests but can’t match the output quality of a tool that’s had 37 years of human engineering. That’s the constraint nobody’s pricing in.
The real story is in the cost curve, not the capability demo. $20,000 for 100,000 lines means $0.20 per line of generated code. A senior compiler engineer costs roughly $150/hour. At maybe 50 polished lines per hour for something this complex, that’s $3/line. AI just did it at 15x cheaper, and it will only get cheaper from here.
But the code isn’t equivalent. The AI version needs a human to finish the assembler, fix the linker, optimize the output, and prevent regressions. Those are the hardest 20% of the problem, and they represent 80% of the engineering value. Anthropic built the demo. Shipping the product still requires humans.
This tells you exactly where we are in the autonomous software timeline. AI can now produce impressive first drafts of complex systems at trivial cost. Turning those drafts into production software still requires the judgment that costs $300K+ per year in compiler engineer salary. The gap between “compiles the Linux kernel” and “replaces GCC” is measured in decades of accumulated engineering wisdom that no model has internalized yet.
The companies that understand this will use agent teams to generate the 80% and hire engineers to finish the 20%. The companies that don’t will ship $20,000 compilers that produce slower code than a free tool from 1987.
Mathematician Terence Tao about GPT-5.2 solving the Erdős problem:
"the problem was solved more or less autonomously after some feedback, and the result doesn't seem to be in the literature
the bigger shift is how fast AI can now write and rewrite clear expositions of the solution"
[CVE-2025-37752] Two Bytes Of Madness: Pwning The Linux Kernel With A 0x0000 Written 262636 Bytes Out-Of-Bounds
Great article by D3vil about exploiting a type confusion in the network scheduler subsystem and pwning all kernelCTF instances.
https://t.co/lpZyXYFM3w
"it's fascinating because it's exactly what they did"
Um, "they" includes Joe Rogan. It describes what Joe Rogan is doing.
Rogan likes to challenge the mainstream view. That's good, in principle, but it needs to be done with rigor, such as data and statistics. It doesn't mean airing the grievances of every wackjob like RFKjr pretending they are at the same level as real scientists.
The Rogan view of debate is that of better "rhetoric". In the world of pure rhetoric, we can't debate things like whether Abrego Garcia should be given "due process", because the ignorant have no idea what "due process" even is. Guests go on Rogan's show and simply make up bullshit.
🧵 THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures I’ve ever read.
He's saying DOGE came in, data went out, and Russians started attempting logins with new valid DOGE passwords
Media's coverage wasn't detailed enough so I dug into his testimony: