I recently got access to OpenAI’s Trusted Access for Cyber program.
With all the GPT-5.5 hype and the Anthropic Mythos discussion, I wanted to test it for myself.
The result: **GPT-5.4** helped identify and develop a working Safari exploit affecting all Apple devices.
It found a JSC WebAssembly use-after-free that gave us stale read/write access inside the Primitive Gigacage. Then it spotted a bug in Safari’s Fetch implementation where in-flight opaque cross-origin responses could be materialized inside renderer memory.
By combining the two, a malicious page could steal authenticated cross-origin data and completely defeat the Same-Origin Policy.
The US rescued a downed fighter pilot in hostile territory while simultaneously sending astronauts to the moon.
One air frame loss per 12,000 combat sorties and they immediately found and rescued the guy while sending astronauts to space.
“LE DYING EMPIRE”
We asked Claude to find a bug in Vim. It found an RCE. Just open a file, and you’re owned. We joked: fine, we’ll switch to Emacs. Then Claude found an RCE there too.
Full story: https://t.co/7UL9suKs8r
‼️🚨 An ex-Anthropic engineer just published a 1-click remote code execution exploit for OpenClaw (formerly Moltbot and ClawdBot).
The attack occurs in milliseconds after the victim visits a webpage, giving the attacker access to Moltbot and the system it's running on. The victim does not need to type anything or approve any prompts.