π Security - AI Lab Funding and Lobbying
OpenAI's community forum SSO turned a Discourse libheif heap overflow into employee ChatGPT and Codex β then a harmless PR in the internal monorepo. Opus 5 helped compress that chain to under 72 hours. OpenAI patched in about 14 hours and paid $6.5k. The decoder was the foot in the door.
Key Points:
SSO Vulnerability: A vulnerability in OpenAI's community forum SSO allowed an attacker to gain access to employee ChatGPT and Codex, and then create a harmless PR in the internal monorepo.
Opus 5 Compression: Opus 5 helped compress the chain of events from the initial vulnerability to the creation of the PR in under 72 hours.
Patch and Payment: OpenAI patched the vulnerability in about 14 hours and paid $6.5k to the attacker.
π Resources:
- Original source β
- Original source
- Tweet β
- A Twitter thread discussing a vulnerability in OpenAI's community forum SSO.
π Security - Investigative Journalism
Lorenzo has been exposing spyware & thepeople behind it for years, first at vice and then at TechCrunch. His stories are always well written and sourced. Iβll be pre-ordering @Lorenzofb βs new HT book. You should too
Key Points:
Investigative Journalism: Lorenzo has been exposing spyware and the people behind it for years, first at Vice and then at TechCrunch.
Well-Researched Stories: His stories are always well-written and sourced.
New Book: Lorenzo has a new book coming out, and the author recommends pre-ordering it.
π Resources:
- Original source β
- Original source
- Tweet β
- A Twitter thread discussing investigative journalism.
π AI - LLMs and Agents
This sounds like religion not science. We know how LLMs and agents work because they are computers and not alive. Because we built them and can monitor them. Computers running βcodeβ and βprocessesβ
Key Points:
LLMs and Agents: LLMs and agents are computers that run on code and processes, not living beings.
Scientific Understanding: We have a scientific understanding of how LLMs and agents work, and we can monitor them.
Separation of Church and State: The discussion of LLMs and agents should be based on science, not religion.
π Resources:
- Original source β
- Original source
- Tweet β
- A Twitter thread discussing LLMs and agents.
π Personal - The Art of Not Giving a Fuck
The art of not giving a fuck. Iβve had people try to sue me, swat me, get me fired, threaten me, and more, and every time I just become more of an entrenched asshole. Maybe because Iβm old, but Iβm done trying to be someone else or nice particularly about certain topics.
Key Points:
The Art of Not Giving a Fuck: The author has learned to not care about certain things, and has become more confident and assertive as a result.
Dealing with Adversity: The author has dealt with various forms of adversity, including lawsuits, swatting, and threats, and has come out stronger on the other side.
Personal Growth: The author has grown and learned from their experiences, and is now more comfortable being themselves.
π Resources:
- Original source β
- Original source
- Tweet β
- A Twitter thread discussing the art of not giving a fuck.
π Journalism - Quoting a Labour Source
"Quoting a Labour source close to the intelligence service ..." Good example of how a story with little evidence gets recycled. I also seriously doubt the "source" has direct access. If they did, the source would be advised to be quiet
Key Points:
Quoting a Labour Source: The author is criticizing the practice of quoting a Labour source close to the intelligence service without verifying the information.
Lack of Evidence: The story has little evidence to support it, and the author is skeptical of the source's claims.
Journalistic Integrity: The author is advocating for journalistic integrity and the importance of verifying information before publishing it.
π Resources:
- Original source β
- Original source
- Tweet β
- A Twitter thread discussing journalistic integrity.
π AI - Lobbying for Exemptions
Jensen Huang told CBS News that AI executives like Dario Amodei and Sam Altman promote doomsday scenarios to escape existing legal liabilities. Huang said the public should read between the lines: AI developers arenβt asking for stricter oversight. Theyβre lobbying to be exempt
Key Points:
Lobbying for Exemptions: AI executives are lobbying for exemptions from existing legal liabilities, rather than advocating for stricter oversight.
Doomsday Scenarios: The executives are promoting doomsday scenarios to justify their lobbying efforts.
Public Perception: The public should be aware of the true intentions of the AI executives and not be misled by their rhetoric.
π Resources:
- Original source β
- Original source
- Tweet β
- A Twitter thread discussing AI lobbying.
π Security - METR and AI Funding
Anthropicβs CEO wants Americaβs AI labs to embed βindependentβ groups like METR inside them to enforce βalignment.β The money trail runs through a shadowy leftist NGO same small network. This is another battle in our war against leftist censorship NGOs.
Key Points:
METR and AI Funding: The CEO of Anthropic wants to embed independent groups like METR inside AI labs to enforce alignment.
Money Trail: The money trail for METR runs through a shadowy leftist NGO.
Censorship NGOs: This is another battle in the war against leftist censorship NGOs.
π Resources:
- Original source β
- Original source
- Tweet β
- A Twitter thread discussing METR and AI funding.
π Security - Public Grant Records
Public grant records show funding for METR, Redwood, FAR AI, Longview, Tarbell, and projects at RAND. They study the threat. They run the evaluations. They train journalists to cover the threat. Different logos. Same ecosystem.
Key Points:
Public Grant Records: Public grant records show funding for various organizations, including METR, Redwood, and FAR AI.
Threat Evaluation: These organizations study the threat, run evaluations, and train journalists to cover the threat.
Same Ecosystem: Despite different logos, these organizations are part of the same ecosystem.
π Resources:
- Original source β
- Original source
- Tweet β
- A Twitter thread discussing public grant records.
π Security - Money Trail
I wonder who is feeding Eric this and if theyβre aware this is going to uncover a money trail between AI companies and politicians like Eric that both parties would prefer remain unexposed.
Key Points:
Money Trail: The author is suggesting that there is a money trail between AI companies and politicians.
Uncovering the Truth: The author is advocating for uncovering the truth about this money trail.
Exposing Corruption: This is a way to expose corruption and hold those in power accountable.
π Resources:
- Original source β
- Original source
- Tweet β
- A Twitter thread discussing the money trail.
π Security - Basecamp Briefing
Basecamp Briefing: September 21, 2026 Curated news + items of note regarding Data Privacy, GRC, Info Sec, as well as Open-Source + Threat Information that you may have overlooked. Sherpa Intelligence: Your Guide Up a Mountain of Information. https:// sherpaintelligence.substack.com/p/basecamp-bri efing-september-21-2026 β¦
Key Points:
Basecamp Briefing: The Basecamp Briefing is a curated newsletter that covers news and items of note regarding data privacy, GRC, info sec, and open-source threat information.
Sherpa Intelligence: Sherpa Intelligence is the guide that provides this information.
Curated News: The newsletter provides curated news and information that may have been overlooked.
π Resources:
- Original source β
- Original source
- Tweet β
- A Twitter thread discussing the Basecamp Briefing.