STRIDE-LM: When Adding Another Letter Makes the Model Less Coherent
Lateral movement is not one cause. It is what a path looks like when an attacker expands control from one context to another.
https://t.co/aFN8m98XdX
#STRIDE#STRIDELM#lateral
Full agreement on the urgency.
One structural gap: share threat intel, share tested playbooks, measure how many orgs are protected — every action item here presupposes a common cause-side vocabulary. The field doesn't have one.
A closed 10-cluster candidate exists: https://t.co/DroDTOUuLg. Falsify it or use it.🖖
OpenAI – Hugging Face Incident (July 2026): TLCTC v2.5 Attack-Path Documentation
Seven attack paths, five SRE pivots, and an auditable 67-step register — a cause-side reconstruction of the most novel incident of 2026, under frozen v2.5 canon.
https://t.co/yfB8fYMmQu
Claude Security scans now run on Claude Mythos 5, available today in public beta for all Claude Enterprise customers.
Put our most capable security model to work on your codebase, no separate model access needed.
As models become more capable, the risks associated with developing and testing them internally also grow.
We temporarily paused reinforcement learning (RL) training on our latest models intended for deployment for two weeks while we hardened and red-teamed our research environments and expanded monitoring coverage.
Our largest planned frontier RL run remains on hold while smaller-scale training and evaluations validate these safeguards and establish more evidence of alignment.
https://t.co/ecbMMmVoox
Anthropic expects the gap between motivated attackers and defenders to widen. That makes a stable, cause-based threat taxonomy more—not less—important.
Proposal for @AnthropicAI: publish model-weight security threats using a cause-based taxonomy.
“Endpoint/cloud compromise” are contexts, privilege escalation is an effect, and data exfiltration is an outcome.
TLCTC separates these cleanly into causes → data risk → consequences.
https://t.co/oYNNecXulR