AI Security Claude's new constitution: turning principles into AI training data
Technical analysis of Claude's 2026 Constitution: Constitutional AI, value hierarchy, rule reasoning, CC0, evaluations, instruction conflicts and governance.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
AI Security Technical analysis of Claude's 2026 Constitution: Constitutional AI, value hierarchy, rule reasoning, CC0, evaluations, instruction conflicts and governance.
AI Security Mistral documented an RSS leak in vLLM disaggregated serving, NIXL and UCX. Heaptrack missed it; pmap, eBPF and targeted GDB found the cause.
AI Security OpenAI contracted 750 MW of low-latency Cerebras capacity through 2028. What wafer-scale inference, accelerator portfolios and response-time economics mean.
Threats and Incidents Microsoft and law enforcement disrupted RedVDS. We analyse 7,300 IPs, homoglyph domains, a shared Windows image and behaviour-based cybercrime detection.
Vulnerabilities and CVEs Technical analysis of CVSS 10 n8n Ni8mare: vulnerable form workflow, local file read, possible chains, detection, remediation and automation hardening.
AI Security OpenAI launched ChatGPT and API products for healthcare. We analyse BAAs, PHI controls, evidence retrieval, physician testing and clinical deployment risk.
Human Security Microsoft documented internal-looking phishing enabled by complex mail routing and weak spoof protection. A technical analysis of headers, DMARC and connectors.
Threats and Incidents 2025 was a record year for Poland: attacks on hospitals, DDoS on infrastructure and disinformation. We summarise the threats and lessons for businesses.
Vulnerabilities and CVEs CVE-2025-55182 React2Shell is a CVSS 10.0 unauthenticated RCE. Affected React and Next.js versions, public PoC, attacks and patches.
Vulnerabilities and CVEs CVE-2025-64446 (CVSS 9.4) lets unauthenticated attackers run FortiWeb admin commands. Public PoC, KEV, versions, hunting and fixes.
Vulnerabilities and CVEs CVE-2025-59287 (CVSS 9.8) enables RCE in Windows Server Update Services. OOB patches, KEV, defensive PoC, detection and remediation.
Vulnerabilities and CVEs CVE-2025-61882 (CVSS 9.8) enables unauthenticated code execution in Oracle EBS 12.2.3–12.2.14. PoC, IOCs, patches and threat hunting.
Vulnerabilities and CVEs CVE-2025-10035 (CVSS 10.0) in GoAnywhere MFT was exploited as a zero-day. PoC analysis, Medusa ransomware, IOCs and vendor fixes.
Supply Chain Security In autumn 2025 the Shai-Hulud worm infected hundreds of npm packages, spreading itself. We analyse the supply chain attack and how to secure your pipeline.
Supply Chain Security In 2025, stolen OAuth tokens from Salesloft exposed hundreds of firms' Salesforce data — with no cracked passwords. A lesson on integration risk.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.