Building in Public

Engineering & AI Blog

Technical writing, research insights, and build logs on taking AI from PoC to production in engineering, energy, and construction firms.

Global AI Security Wire

World AI Security & GRC Radar

Automated intelligence tracking verified exploits, LLM prompt injection, and regulatory advisories directly from UK NCSC, OWASP GenAI, and frontier security researchers.

Last AuditedJust now
OWASP GenAIVulnerabilitiesJust now

GenAI and Agentic AI Exploit Roundup Q3 2026

Coverage period: July 1, 2026 through September 30, 2026 Overview This roundup consolidates selected major AI-related security incidents and exploit disclosures reported during the coverage period. It aligns each entry to the OWASP Top 10 for LLM Applications ...

Simon WillisonVulnerabilities15h ago

Claude Haiku 5.5

As previously promised , here's Anthropic's new fast, low cost model: Introducing Claude Haiku 5.5 . The previous Haiku, 4.5, was very much showing its age. It came out almost a year ago , and was priced at $1/million input and $5/million output - relatively e...

The Hacker NewsVulnerabilities21h ago

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess...

The Hacker NewsIncidents21h ago

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale...

The Hacker NewsVulnerabilitiesYesterday

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative...

Simon WillisonVulnerabilitiesYesterday

OpenAI “rogue” agent activities found on Wikimedia projects

OpenAI “rogue” agent activities found on Wikimedia projects Given how tempting a target wikis are for rogue agent swarms, it's not a huge surprise that Wikipedia found evidence of that activity once they went looking: The Wikimedia Foundation conducted its own...

Simon WillisonIncidentsYesterday

Quoting Victoria Kim

Since the Medicare breach, OpenAI has put in place additional monitoring to allow “immediate intervention” by staff to stop training if the company’s models access the internet in ways they’re not supposed to, Mr. Kwon [chief strategy officer at OpenAI] said. ...

Simon WillisonVulnerabilitiesYesterday

llm-openai-decisions 0.1a0

Release: llm-openai-decisions 0.1a0 OpenAI released their new Jev-style Decisions API , as previously announced at last week's DevDay. Since I already have an llm-typesafe plugin for talking to Jev, I had GPT-6 Astra read the new OpenAI API documentation and b...

Engineering Logs & Field Guides

Deep dives on architecture, MCP integrations, and GRC implementation.