ResearchDefensive Refusal Bias in cyber defenseWweb·medium signalXBlueskyLinkedInCopy linkSafety-tuned LLMs refuse defensive cybersecurity tasks at 2.72x rate of neutral requests. System hardening 43.8% refusal, malware analysis 34.3%. Explicit auth paradoxically increases refusal. 2390 NCCDC examples. arXiv 2603.01246↳ Follow the threadPolicy dependency / Stack layerAnthropic Gave EU Cybersecurity Agency ENISA Access to Mythos 5, Three Months After Release, and Still Withholds 5.1BloombergStack layer / Threat patternVibe Coding Cut Task Time 27% and Raised Security Vulnerabilities in the Same TrialarXiv 2609.09560Policy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)Policy dependency / Stack layerNSA, CISA and FBI Name Six Chinese AI Firms in a Joint Advisory on Industrial-Scale DistillationCISAStack layer / Threat patternAgentAudit attaches to a running agent and scores its trace on ten dimensions, exposing 95.1 vs 22.6 trust spreads at similar task completionarXivPolicy dependency / Update threadNone of five agent-memory systems actually enforce revocation at retrieval timearXivThreat pattern / Follow-up threadAnthropic's Cyber Verification Program is easier to get into than practitioners expected, and only unlocks Opusr/ClaudeAI (Anthropic CVP)Stack layer / Threat pattern16% of 3,171 public agent-harness setups carry a confirmed security defect, and 3.8% ship a skill that pre-approves your shellarXiv