@jacobgrowth @ThomasGrayX You obviously did suggest it, the post says stuff like "without us touching the editing suite" many times. Regardless, I don't really see what openclaw is doing that you couldn't do with just a Claude prompt directly. Unless it's actually finding and cutting clips
CVE-2025-55182 dropped.
CVSS 10.0.
React Server Components.
The Slack channel exploded.
Forty-seven messages in twelve minutes.
I responded with a fire emoji.
Leadership.
My threat intel team sent me six GitHub links.
I clicked none of them.
But I forwarded all of them.
To seventeen people.
With "URGENT" in the subject line.
Three exclamation points.
That's how you know it's serious.
Our vendor called.
They said their WAF had "day-zero protections."
I asked what that meant.
They said "runtime-level coverage."
I asked what that meant.
They sent me a PDF.
Fourteen pages.
I read the executive summary.
Four bullet points.
Three of them said "AI-powered."
I felt safe.
I scheduled an all-hands.
Mandatory.
I showed a screenshot of Shodan results.
Very red.
Very scary.
I said "React2Shell" four times.
Each time more slowly than the last.
I showed them a PoC from Twitter.
It used child_process.exec.
I said we blocked it.
I didn't mention you'd have to deliberately expose that function.
Which would be insane.
Which no one does.
Which makes blocking it meaningless.
But the slide looked great.
Green checkmark.
"MITIGATED."
A security engineer unmuted.
She asked about prototype pollution.
She asked about __proto__:then.
She asked if we'd actually upgraded React.
I said those were implementation details.
I said we focus on outcomes, not outputs.
I said our posture was defense-in-depth.
She asked what layer was actually defending.
I said, "All of them."
She shared her screen.
Our Next.js was three versions behind.
I said version numbers were vanity metrics.
She said the CVE literally lists affected versions.
I said, "Let's parking-lot that."
I never found the parking lot.
The meeting ended.
I posted a LinkedIn update.
"Proud of our team's rapid response to React2Shell."
Forty-three likes.
Two comments from vendors.
One recruiter DM.
The engineer's Jira ticket sat in the backlog.
Priority: Medium.
We shipped a new feature instead.
The breach came through prototype pollution.
Exactly what she said.
The WAF saw nothing.
Because WAFs don't understand JavaScript deserialization.
The postmortem was three hours.
I facilitated.
Root cause: "Sophisticated nation-state actor."
Contributing factor: "Unclear internal communication."
The engineer who raised the alarm?
"Contributed to confusion during incident response."
I'm keynoting at RSA next month.
Topic: "Building a Culture of Cyber Resilience."
I'm workshopping my opening line.
"In today's threat landscape, the only certainty is uncertainty."
The audience will nod.
They always do.
And c) entitled for thinking they deserve to have an S-tier answer for their low effort question that gets asked once a week and could be easily understood from documentation or searching or literally any effort at all
Anyone who thinks @StackOverflow is this toxic is a) deeply insecure and has a skill issue and b) has clearly not experienced the early internet (IRC, usenet, and lots of misc phpbb forums)
No website decline leaves me feeling as satisfied as @StackOverflow. The people in this place detest you so much, they don't even try to hide it. They will reject your questions, prevent you from answering, and openly mock you in the comments. The toxicity level of these people surpasses any reasonable standard. Burn this place to the ground.
@rohanpaul_ai Why do you think it has so much good content? Because low quality submissions get filtered out. Where do you think gpt data came from? I use chatgpt all the time for coding help (copilot, cursor..) but with this much spoon feeding I worry for the next generation of programmers.
People tweeting at this with “LLMx or LLMy gets it right” are missing the forest for the tree. The bigger story here is in two parts:
First, this issue is not about a specific LLM but that *all LLMs* have unexpected failure modes and that no amount of alignment will rescue them. This will remain true regardless of the advances in mechanistic interpretability. Why? For every success, there are dozens of ways to fail, and it is impossible to enumerate all failure modes and test them. We hope that failure modes are “learnable” with RLHF or whatever, but that makes no sense. Successes may be identically distributed but failures never are.
This leaves us with having to learn about failures one by one the hard way. For this reason, no company can guarantee an entirely safe model that's also highly capable.
Second, investor/shareholder pressure and competition push companies to deploy LLMs and replace older systems at massive scales. This is akin to asking the captain of the Titanic to suddenly swerve the ship by 90 degrees in the middle of the ocean.
In some ways, massive companies, if they don't succumb to investor/twitter-mob pressures, have the multidecade experience to get this right. However, asking for time to do things thoughtfully feels like a luxury we cannot afford anymore.
Reading this might feel dispiriting or not-productive since I am not offering pointed solutions and just laying out the problem. But it's the best we have now, and you should be wary of any company/person claiming to have a concrete solution for this problem.
If there is any takeaway from this post, we always need humans in the loop for a while when consuming AI outputs and educate consumers against falling for startup/company/influencer narratives of AI products.