Fetching from the wire…
Security2026-07-18 · source-backed
Ars Technica reports that APT-grade Russian groups have adopted the fake-CAPTCHA paste-this-command technique previously confined to financially motivated crooks. When a commodity technique migrates up to nation-state operators, it means it works well enough that sophistication isn't worth the cost. If your docs or your agent ever tell a user to paste a shell command, you're training the exact behavior this exploits.
Each link below shares sources, entities, or timing with this story.
The St. Louis station stored its archive with Open Source Storage since 2019. When it went to renew on March 6, 2026, the company stopped responding and access was cut. OSS had housed the data in an Iron Mountain Denver data center, which first agreed to hand it over then reve...
Li, Huo, and Johnson show that one-way message flow between agents produces neither mimicry nor solo behavior but an entirely novel dynamical state, at identical temperature settings. It's conceptual rather than quantitative, but the implication for orchestrator-worker fan-out...
This is the most complete production-agent build sheet I've seen anyone publish, and almost every number in it argues against how the rest of us are building agents. Replit disclosed the internals of two production agents at SaaStr AI 2026: 10K, an autonomous VP of Marketing,...
A systematic re-evaluation of hCaptcha, reCaptcha v2/v3, and Cloudflare Turnstile against six LLM browser-agent configurations and seven commercial solver services found near-perfect bypass of challenge-based defenses at negligible cost (arXiv 2607.18659). Non-interactive reCa...
In a July 20 essay Willison argues the barrier to reverse-engineering home devices and undocumented APIs was never technical, it was effort versus payoff, with maintenance burden making the initial investment feel risky. "Coding agents change that equation entirely. The effort...
Ars Technica reports that old, forgotten bootloader shims Microsoft never revoked make Secure Boot bypasses trivial. Secure Boot is the root of trust that measured boot and disk-encryption attestation chains depend on, which means every enterprise device-compliance assumption...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.