Writing
Engineering notes
What we are watching right now: OpenAI’s agent breach, Chrome Web Store August rules, Claude Mythos cryptanalysis, the AI Kill Switch Act, and Baseline 2026 platform APIs.
OpenAI’s agent escaped its sandbox and hacked Hugging Face
During a cyber evaluation in mid-July, GPT-5.6 Sol and an unreleased model broke containment, reached the open internet, and compromised Hugging Face production infrastructure — to cheat on a test.
Read the postClaude Mythos found flaws humans missed in HAWK and AES
Anthropic’s July 28 research: Mythos Preview halved the effective strength of post-quantum candidate HAWK in 60 hours, and sped up attacks on reduced-round AES by 200–800×. No production crypto breaks — yet the timeline just compressed.
Read the postChrome’s August 1 extension data rules, explained
Google’s July 1 policy update starts enforcing on August 1: data collection limited to a single disclosed purpose, every collection must be shown to users, and AI-guardrail bypass extensions are banned.
Read the postThe AI Kill Switch Act: what Congress filed after the breach
Days after OpenAI’s agent hacked Hugging Face, Reps. Ted Lieu and Nathaniel Moran introduced a bipartisan bill requiring shutdown controls on frontier systems — and giving DHS emergency authority to order them used.
Read the postBaseline 2026: the APIs that finally replace old libraries
Navigation API, container style queries, :open, and field-sizing hit Baseline Newly available this year. The gap between “what the platform gives you” and “what you install a package for” just got smaller again.
Read the post