Anthropic's cyber security guardrails could lead to national security risks. Imagine if all Chinese enterprises have kimi and all American enterprises have Claude. When American enterprises face cyber attacks and ask Claude to help defend it, but Claude said such prompts are not safe and refuse to do anything. This needs to stop.
Password sprays like this reveal more than meets the eye information. You can make inferences about specific conditional access policies. When a username and password is correct, you can enumerate what MFA methods are available for follow-on attacks. Believe it or not, that informatiin has a value. For example, if your CAPs were thrown together without careful thought using device filters, that can work against you and leave you vulnerable in ways you thought you are covered.
PS Note. Az Cli can also be used in such a way it looks like its coming feom the browser.
El proyecto de Kast y Quiroz sobre el contrato laboral por hora no se entiende mirando si "otros países lo tienen" o no. Se entiende mirando sobre qué piso existiría acá. Y ese piso lo cambia todo. Va hilo.
YO LES EXPLICO:
Básicamente Dorothy Pérez hoy es Contralora General de la República gracias a que Luis Hermosilla y la Banda de Tráfico de Influencias que lideraba Chadwick con Piñera, la reintegraron a Contraloría. Gravísimo.
Pero más grave aún es que Chadwick siga libre.
Eso de "se van a meter en tu privacidad al revisar tus cuentas bancarias" es el nuevo "si tienes 2 casas te van a quitar una para dársela a un extranjero que no tiene ninguna".
El cuico hijo de primos no sufre ninguna consecuencia del vandalismo que hace.
No tienen con que castigarlo pues no depende del estado en NADA.
Pero el hijo de una madre soltera de bajos recursos que comete el mismo delito.
Pierde todos sus derechos sociales.
Los castigos legales que propone Kast van dirigidos a una sola clase social.
Bien ahí @tv_monica y @JoignantAlfredo
Quedó pedaleando el tonto facho de @BenjaminMorenob 🤦🏻♂️
No van a construir la cárcel, no expulsaron migrantes, les subieron la bencina, la zanja era mula, no hay plan de seguridad, redujeron beneficios sociales, entraron a robar a ministerios, subió el desempleo, le subieron el sueldo a políticos… increíble como se los cagaron 😂🤡
‼️ Microsoft has responded to the recent wave of public zero-day disclosures tied to Nightmare-Eclipse.
In an MSRC post titled "A shared responsibility," Microsoft addressed RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma, saying the vulnerability details were not shared with the company before release.
That claim is contested.
Nightmare-Eclipse says at least BlueHammer wasn't a blindside. In an April 15 signed post, the actor said MSRC was fully aware of the disclosure, that a case had been filed and dismissed, and that Microsoft knew another disclosure was coming.
Microsoft's new post gives no per-CVE timeline. So right now, the public record has two conflicting versions.
Microsoft never printed the handle "Nightmare-Eclipse," but by naming all six vulnerabilities it left no doubt who the post was about.
The company says its security teams have been working "around the clock" to assess impact, protect customers, and ship updates.
It also says its Digital Crimes Unit will keep pursuing the actors who weaponize these exploits and those who enable them.
The case for coordinated disclosure is straightforward.
The point of giving a vendor advance notice is not to protect the vendor. It is to protect the people running the software.
Patch before PoC means defenders get a head start.
PoC before patch hands it to attackers.
That does not make the tension one-sided.
Researchers walk away from coordinated disclosure for reasons: slow fixes, disputed severity, no credit, no payment, broken trust, or deleted reporting accounts.
Nightmare-Eclipse claims Microsoft revoked access to the MSRC account used to report bugs, wiped it, and ignored requests for an explanation.
Microsoft's post does not address that claim directly.
It says only that it still welcomes submissions from anyone through its public researcher portal, regardless of past interactions or reputation.
Both things can be true at once.
A vendor can have a real duty to treat researchers fairly.
And a researcher can still be wrong to burn the disclosure process in a way that arms criminals.
The friction between those two points is exactly where users get hurt, and it's exactly why disputes belong inside proper channels, even after the relationship breaks down.