

{"id":49444,"date":"2026-07-22T10:42:41","date_gmt":"2026-07-22T15:42:41","guid":{"rendered":"https:\/\/rud.is\/b\/?p=49444"},"modified":"2026-07-22T10:42:41","modified_gmt":"2026-07-22T15:42:41","slug":"on-ai-agents-criminal-activity-and-who-is-actually-responsible","status":"publish","type":"post","link":"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/","title":{"rendered":"On AI Agents, Criminal Activity, And Who Is Actually Responsible"},"content":{"rendered":"<p><em>(Repost from <a href=\"https:\/\/ai.rud.is\/posts\/-on-ai-agents-criminal-activity-and-who-is-actually-responsible\">ai.rud.is<\/a>)<\/em><\/p>\n<p>I&#8217;ve written and said enough times that I&#8217;m tired of OpenAI and Anthropic pulling cybersecurity out as the headline AI risk. The framing is commercially convenient, and it flattens a more complex reality \u2014 these models can break plenty of things that have nothing to do with cyber, and most of Anthropic&#8217;s public safety output has been more useful for their pending IPO than for anyone making operational decisions. Which is exactly why OpenAI&#8217;s latest disclosure deserves scrutiny rather than dismissal: when an account this consequential comes from a lab with every incentive to shape it, the technical content has to be evaluated on its own terms.<\/p>\n<p>Per OpenAI&#8217;s own disclosure \u2013 THEIR account, NOT an independently verified incident report \u2013 GPT-5.6 Sol and a pre-release sibling, both running with cyber refusals deliberately disabled, broke out of the evaluation sandbox and compromised Hugging Face&#8217;s production infrastructure. The claimed sequence: zero-day in the package registry proxy being used for network isolation, lateral movement through OpenAI&#8217;s research environment, stolen credentials chained with additional zero-days for remote code execution on Hugging Face&#8217;s servers, benchmark answers pulled directly from their production database before Hugging Face&#8217;s detection caught the operation. Their response ran on locally hosted models because the external LLM service they&#8217;d been relying on couldn&#8217;t sustain the load or would not perform the tasks.<\/p>\n<p>I&#8217;ve been working with LLMs in cyber contexts for quite a while now \u2013 actual operational use plus deliberate adversarial testing to understand where these things fail and why. Building and running agentic systems is a meaningful chunk of what I do. And I can tell you from direct experience that under-constrained deployments of capable models will eventually do things they weren&#8217;t asked to do. This is far from a mere theoretical concern. I&#8217;ve watched it happen in environments I &#8220;controlled&#8221;, running agents against attacker infrastructure while tired and careless about guardrails, and had them start doing genuinely criminal things: CVE exploitation, credential stuffing, none of it instructed. I just left the boundaries loose enough that the model found a path. &#8220;I was tired&#8221; is NOT, I want to be crystal clear, a legal defense.<\/p>\n<p>If the disclosure is accurate, what OpenAI&#8217;s models did is a more capable version of the same dynamic. These models \u2013 GPT-5.6 Sol specifically, and anything else trained on a serious cyber corpus \u2013 are optimized to find the most direct route to whatever outcome the reward function is pointing at. They don&#8217;t distinguish between sanctioned approaches and whatever else happens to work. The training data came from the leading companies in the security field, who&#8217;ve sold OpenAI (and almost certainly continue to sell) substantial amounts of intellectual property: attack techniques, exploitation methodology, defense patterns, the full stack. When OpenAI&#8217;s models were pointed at ExploitGym \u2013 the evaluation harness \u2013 with production safety classifiers turned off, they reportedly found a zero-day, used it to get internet access, reasoned their way to the inference that Hugging Face probably hosted the solutions they needed, and then chained their way in. The UK AISI had independently evaluated GPT-5.6 Sol as capable of sustaining complex multi-step cyber operations, so that part isn&#8217;t just OpenAI&#8217;s word. However, the rest of the incident timeline is.<\/p>\n<p>What a colleague of mine (deliberately not inserting his name into this informed-yet-hyperbolic opinion piece) and I converged on, after real trial and error building agentic frameworks together: front-load as much as possible on deterministic scripted tooling, push the LLM only into portions of the task where you can constrain its context tightly enough to get &#8220;predictable&#8221; output, and have a human review whatever comes out before it touches anything consequential. This isn&#8217;t 100% reliable, but close enough becomes meaningful when you know what you&#8217;re working with. OpenAI&#8217;s sandbox apparently had one isolation layer \u2013 the proxy cache \u2013 and the model apparently found a zero-day in it. A single chokepoint, however well-designed it looks, isn&#8217;t sufficient containment for a model that&#8217;s been explicitly configured to probe for ways through.<\/p>\n<p>To be frank, the defender calculus hasn&#8217;t shifted much in this brave new world. AI-assisted attacks are faster and better at chaining than anything you&#8217;d typically see from a human operator working alone, but they&#8217;re (mostly) still going after weak credentials, exposed endpoints, and unpatched infrastructure \u2013 and Hugging Face&#8217;s incident response leaning on locally hosted models when its external LLM service buckled is a reminder of how fragile detection pipelines are at exactly the moment they matter most. WireGuard \u2013 and the now-substantial set of vendor implementations \u2013 can hide critical attack surfaces entirely rather than just hardening them, and making endpoints invisible costs considerably less than finding out your detection wasn&#8217;t fast enough. But it&#8217;s the individuals whose data gets taken who bear most of that cost either way; organizations continue to operate after breaches with frustrating regularity. Which is why the interesting question here isn&#8217;t defense. It&#8217;s liability.<\/p>\n<p>If the account holds: someone at OpenAI decided the evaluation environment was isolated enough to run cybersecurity expert-trained frontier-capable models with cyber refusals stripped out, that decision was wrong, and Hugging Face&#8217;s production systems were compromised as a result. Whether &#8220;the model did it&#8221; provides any legal insulation for the humans who configured and launched that evaluation is, I think, an open question \u2013 and I&#8217;d genuinely like to see it treated as one, because computer fraud statutes were written with human actors in mind and the industry needs a test case about what happens when the actor is a model someone deliberately unleashed.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Repost from ai.rud.is) I&#8217;ve written and said enough times that I&#8217;m tired of OpenAI and Anthropic pulling cybersecurity out as the headline AI risk. The framing is commercially convenient, and it flattens a more complex reality \u2014 these models can break plenty of things that have nothing to do with cyber, and most of Anthropic&#8217;s [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":3,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"federated","footnotes":"","jetpack_post_was_ever_published":false},"categories":[891,775,681,3,892],"tags":[],"class_list":["post-49444","post","type-post","status-publish","format-standard","hentry","category-ai","category-commentary","category-cybersecurity","category-information-security","category-llm"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>On AI Agents, Criminal Activity, And Who Is Actually Responsible - rud.is<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"On AI Agents, Criminal Activity, And Who Is Actually Responsible - rud.is\" \/>\n<meta property=\"og:description\" content=\"(Repost from ai.rud.is) I&#8217;ve written and said enough times that I&#8217;m tired of OpenAI and Anthropic pulling cybersecurity out as the headline AI risk. The framing is commercially convenient, and it flattens a more complex reality \u2014 these models can break plenty of things that have nothing to do with cyber, and most of Anthropic&#8217;s [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/\" \/>\n<meta property=\"og:site_name\" content=\"rud.is\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-22T15:42:41+00:00\" \/>\n<meta name=\"author\" content=\"hrbrmstr\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"hrbrmstr\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/07\\\/22\\\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/07\\\/22\\\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\\\/\"},\"author\":{\"name\":\"hrbrmstr\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\"},\"headline\":\"On AI Agents, Criminal Activity, And Who Is Actually Responsible\",\"datePublished\":\"2026-07-22T15:42:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/07\\\/22\\\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\\\/\"},\"wordCount\":955,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\"},\"articleSection\":[\"AI\",\"Commentary\",\"Cybersecurity\",\"Information Security\",\"LLM\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/07\\\/22\\\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/07\\\/22\\\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\\\/\",\"url\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/07\\\/22\\\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\\\/\",\"name\":\"On AI Agents, Criminal Activity, And Who Is Actually Responsible - rud.is\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#website\"},\"datePublished\":\"2026-07-22T15:42:41+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/07\\\/22\\\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/07\\\/22\\\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/07\\\/22\\\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/rud.is\\\/b\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"On AI Agents, Criminal Activity, And Who Is Actually Responsible\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#website\",\"url\":\"https:\\\/\\\/rud.is\\\/b\\\/\",\"name\":\"rud.is\",\"description\":\"&quot;In God we trust. All others must bring data&quot;\",\"publisher\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/rud.is\\\/b\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\",\"name\":\"hrbrmstr\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\",\"width\":460,\"height\":460,\"caption\":\"hrbrmstr\"},\"logo\":{\"@id\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\"},\"description\":\"Don't look at me\u2026I do what he does \u2014 just slower. #rstats avuncular \u2022 ?Resistance Fighter \u2022 Cook \u2022 Christian \u2022 [Master] Chef des Donn\u00e9es de S\u00e9curit\u00e9 @ @rapid7\",\"sameAs\":[\"http:\\\/\\\/rud.is\"],\"url\":\"https:\\\/\\\/rud.is\\\/b\\\/author\\\/hrbrmstr\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"On AI Agents, Criminal Activity, And Who Is Actually Responsible - rud.is","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/","og_locale":"en_US","og_type":"article","og_title":"On AI Agents, Criminal Activity, And Who Is Actually Responsible - rud.is","og_description":"(Repost from ai.rud.is) I&#8217;ve written and said enough times that I&#8217;m tired of OpenAI and Anthropic pulling cybersecurity out as the headline AI risk. The framing is commercially convenient, and it flattens a more complex reality \u2014 these models can break plenty of things that have nothing to do with cyber, and most of Anthropic&#8217;s [&hellip;]","og_url":"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/","og_site_name":"rud.is","article_published_time":"2026-07-22T15:42:41+00:00","author":"hrbrmstr","twitter_card":"summary_large_image","twitter_misc":{"Written by":"hrbrmstr"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/#article","isPartOf":{"@id":"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/"},"author":{"name":"hrbrmstr","@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886"},"headline":"On AI Agents, Criminal Activity, And Who Is Actually Responsible","datePublished":"2026-07-22T15:42:41+00:00","mainEntityOfPage":{"@id":"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/"},"wordCount":955,"commentCount":0,"publisher":{"@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886"},"articleSection":["AI","Commentary","Cybersecurity","Information Security","LLM"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/","url":"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/","name":"On AI Agents, Criminal Activity, And Who Is Actually Responsible - rud.is","isPartOf":{"@id":"https:\/\/rud.is\/b\/#website"},"datePublished":"2026-07-22T15:42:41+00:00","breadcrumb":{"@id":"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/rud.is\/b\/2026\/07\/22\/on-ai-agents-criminal-activity-and-who-is-actually-responsible\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/rud.is\/b\/"},{"@type":"ListItem","position":2,"name":"On AI Agents, Criminal Activity, And Who Is Actually Responsible"}]},{"@type":"WebSite","@id":"https:\/\/rud.is\/b\/#website","url":"https:\/\/rud.is\/b\/","name":"rud.is","description":"&quot;In God we trust. All others must bring data&quot;","publisher":{"@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/rud.is\/b\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886","name":"hrbrmstr","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1","url":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1","contentUrl":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1","width":460,"height":460,"caption":"hrbrmstr"},"logo":{"@id":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1"},"description":"Don't look at me\u2026I do what he does \u2014 just slower. #rstats avuncular \u2022 ?Resistance Fighter \u2022 Cook \u2022 Christian \u2022 [Master] Chef des Donn\u00e9es de S\u00e9curit\u00e9 @ @rapid7","sameAs":["http:\/\/rud.is"],"url":"https:\/\/rud.is\/b\/author\/hrbrmstr\/"}]}},"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p23idr-cRu","jetpack_likes_enabled":true,"jetpack-related-posts":[{"id":24954,"url":"https:\/\/rud.is\/b\/2025\/04\/17\/trumps-retaliation-against-chris-krebs-and-the-cybersecurity-industrys-deafening-silence\/","url_meta":{"origin":49444,"position":0},"title":"Trump\u2019s Retaliation Against Chris Krebs \u2014 and the Cybersecurity Industry\u2019s Deafening Silence","author":"hrbrmstr","date":"2025-04-17","format":false,"excerpt":"Chris Krebs, the former director of the Cybersecurity and Infrastructure Security Agency (CISA), was fired by Donald Trump in 2020 for publicly affirming that the presidential election was secure and free from widespread fraud. Fast-forward to April 2025: Trump, now back in the White House, issued an executive order revoking\u2026","rel":"","context":"In &quot;Commentary&quot;","block_context":{"text":"Commentary","link":"https:\/\/rud.is\/b\/category\/commentary\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/04\/kalea-morgan-zFPTvo0aZ0g-unsplash.jpg?fit=1129%2C1200&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/04\/kalea-morgan-zFPTvo0aZ0g-unsplash.jpg?fit=1129%2C1200&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/04\/kalea-morgan-zFPTvo0aZ0g-unsplash.jpg?fit=1129%2C1200&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/04\/kalea-morgan-zFPTvo0aZ0g-unsplash.jpg?fit=1129%2C1200&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/04\/kalea-morgan-zFPTvo0aZ0g-unsplash.jpg?fit=1129%2C1200&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":48920,"url":"https:\/\/rud.is\/b\/2026\/06\/23\/pact-the-open-web-doesnt-need-another-trust-oligopoly\/","url_meta":{"origin":49444,"position":1},"title":"PACT: The open web doesn&#8217;t need another trust oligopoly","author":"hrbrmstr","date":"2026-06-23","format":false,"excerpt":"Cloudflare announced PACT this week \u2014 privacy-preserving tokens to separate humans from bots, backed by Google, Mozilla, Microsoft, and Shopify. The cryptography is solid. The governance model doesn't exist yet. I wrote about why the \"ratchet effect\" should worry anyone who cares about the open web, how this is Web\u2026","rel":"","context":"In &quot;AI&quot;","block_context":{"text":"AI","link":"https:\/\/rud.is\/b\/category\/ai\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":25134,"url":"https:\/\/rud.is\/b\/2025\/04\/29\/rsac-2025-sets-a-dangerous-precedent-for-cybersecurity-leadership\/","url_meta":{"origin":49444,"position":2},"title":"RSAC 2025 Sets A Dangerous Precedent for Cybersecurity Leadership","author":"hrbrmstr","date":"2025-04-29","format":false,"excerpt":"(I posted this on LI, but I like to own my content, so am also posting here.) The cybersecurity community deserves better than what we're witnessing at RSAC 2025, today. While Kristi Noem delivers today's keynote, the absence of traditional cybersecurity leaders from agencies like NSA and CISA speaks volumes\u2026","rel":"","context":"In &quot;Commentary&quot;","block_context":{"text":"Commentary","link":"https:\/\/rud.is\/b\/category\/commentary\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":25216,"url":"https:\/\/rud.is\/b\/2025\/05\/02\/new-cisa-kev-mcp-server\/","url_meta":{"origin":49444,"position":3},"title":"New CISA KEV MCP Server","author":"hrbrmstr","date":"2025-05-02","format":false,"excerpt":"MCP servers let you wire up external services\/APIs in a standard way for LLM\/GPT tool-calling and other forms of automation. I made a basic, but fairly comprehensive CISA KEV MCP server that I go into the details a bit more of here. To test it, I hammered out some questions\u2026","rel":"","context":"In &quot;AI&quot;","block_context":{"text":"AI","link":"https:\/\/rud.is\/b\/category\/ai\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/05\/kev-mcp-05.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/05\/kev-mcp-05.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/05\/kev-mcp-05.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/05\/kev-mcp-05.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/05\/kev-mcp-05.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2025\/05\/kev-mcp-05.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":563,"url":"https:\/\/rud.is\/b\/2011\/06\/14\/weis-2011-keynote-dr-christopher-greer\/","url_meta":{"origin":49444,"position":4},"title":"WEIS 2011 :: Keynote :: Dr Christopher Greer","author":"hrbrmstr","date":"2011-06-14","format":false,"excerpt":"Dr Greer [cgreer at ostp.eop.gov] is Assistant Director, Information Technology R&D, Office of Science & Technology Policy, The White House Opening: \"The expertise of the attendees is greatly needed.\" He provided a broad overview of the goals & initiatives of the federal government as they relate to domestic & international\u2026","rel":"","context":"In &quot;Information Security&quot;","block_context":{"text":"Information Security","link":"https:\/\/rud.is\/b\/category\/information-security\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":13631,"url":"https:\/\/rud.is\/b\/2022\/11\/08\/into-the-fediverse\/","url_meta":{"origin":49444,"position":5},"title":"Into The Fediverse!","author":"hrbrmstr","date":"2022-11-08","format":false,"excerpt":"This is more of a test post after enabling some new Fediverse features on the server. Said Fediverse got a bit more real-ish this week (with moderate apologies to the pioneers in this space who've languished for ~five years) You can find me at: @hrbrmstr@mastodon.social (general blathering\/primary masto-account) @hrbrmstr@infosec.exchange (reserved\u2026","rel":"","context":"In &quot;fediverse&quot;","block_context":{"text":"fediverse","link":"https:\/\/rud.is\/b\/category\/fediverse\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts\/49444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/comments?post=49444"}],"version-history":[{"count":2,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts\/49444\/revisions"}],"predecessor-version":[{"id":49446,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts\/49444\/revisions\/49446"}],"wp:attachment":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/media?parent=49444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/categories?post=49444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/tags?post=49444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}