✕ Clear all filters
24 articles
▶ Videos →

📰 Simon Willison's Blog

24 articles · Updated every 3 hours · View all reads

All Articles 169,470Blog Posts 161,027Tech Tutorials 45,029Research Papers 33,045News 21,581 ⚡ AI Lessons
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 1mo ago
Quoting Matthew Green
Right now we’re in the midst of a historic transition from traditional public-key algorithms based on EC-based cryptography and RSA, moving over to new post-qua
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 1mo ago
Quoting Akshat Bubna
We’re aware a Modal customer published an unauthenticated endpoint that allowed ​anyone on the internet to use ​their ⁠sandboxes for code execution. This was us
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 1mo ago
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident Hugging Face just released this extremely detailed technical descripti
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 1mo ago
xai-org/grok-build, now open source
xai-org/grok-build, now open source xAI's grok CLI tool faced severe community backlash yesterday when it became apparent that running the command in a director
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
Incident Report: CVE-2026-LGTM
Incident Report: CVE-2026-LGTM Spectacular hypothetical incident report by Andrew Nesbitt. Day 2, 16:00 UTC --- Two AI review agents from competing vendors, bot
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
The Fable 5 Export Controls Harm US Cyber Defense
The Fable 5 Export Controls Harm US Cyber Defense I quoted The Atlantic quoting Kate Moussouris earlier, when I should have gone straight to the source. Here sh
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
Quoting Matteo Wong, The Atlantic
Katie Moussouris, a cybersecurity expert and the CEO of Luta Security, told me that Anthropic shared with her a copy of the White House’s report on the Fable ja
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
Cloudflare CAPTCHA on at least one ampersand
TIL: Cloudflare CAPTCHA on at least one ampersand I'm using Cloudflare's CAPTCHA (they call it a "Web Application Firewall > Custom rules > Managed Challenge" t
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 3mo ago
The pressure
The pressure Daniel Stenberg on the unprecedented level of pressure the curl team are facing right now thanks to the deluge of (credible) AI-assisted security i
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 3mo ago
CSP Allow-list Experiment
Tool: CSP Allow-list Experiment An experiment that shows that you can load an app in a CSP-protected sandboxed iframe (see previous note ) and have a custom fet
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
Quoting Bobby Holley
As part of our continued collaboration with Anthropic, we had the opportunity to apply an early version of Claude Mythos Preview to Firefox. This week’s release
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
datasette PR #2689: Replace token-based CSRF with Sec-Fetch-Site header protection
datasette PR #2689: Replace token-based CSRF with Sec-Fetch-Site header protection Datasette has long protected against CSRF attacks using CSRF tokens, implemen
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
Cybersecurity Looks Like Proof of Work Now
Cybersecurity Looks Like Proof of Work Now The UK's AI Safety Institute recently published Our evaluation of Claude Mythos Preview’s cyber capabilities , their
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
scan-for-secrets 0.3
Release: scan-for-secrets 0.3 New -r/--redact option which shows the list of matches, asks for confirmation and then replaces every match with REDACTED , taking
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
scan-for-secrets 0.2
Release: scan-for-secrets 0.2 CLI tool now streams results as they are found rather than waiting until the end, which is better for large directories. -d/--dire
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
scan-for-secrets 0.1.1
Release: scan-for-secrets 0.1.1 Added documentation of the escaping schemes that are also scanned. Removed unnecessary repr escaping scheme, which was already c
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
scan-for-secrets 0.1
Release: scan-for-secrets 0.1 I like publishing transcripts of local Claude Code sessions using my claude-code-transcripts tool but I'm often paranoid that one
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
Vulnerability Research Is Cooked
Vulnerability Research Is Cooked Thomas Ptacek's take on the sudden and enormous impact the latest frontier models are having on the field of vulnerability rese
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
Can JavaScript Escape a CSP Meta Tag Inside an Iframe?
Research: Can JavaScript Escape a CSP Meta Tag Inside an Iframe? In trying to build my own version of Claude Artifacts I got curious about options for applying
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
The Axios supply chain attack used individually targeted social engineering
The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day , and it