AI Security, Vulnerability Research & Supply Chain Attacks
Simon Willison · sockpuppet.org
Thomas Ptacek examines the sudden and enormous impact frontier AI models are having on vulnerability research, fundamentally changing the field.
A writeup of how Claude Code discovered a Linux vulnerability that had been hidden for 23 years, illustrating the growing capabilities of AI in security research.
Simon Willison · simonwillison.net
The Linux kernel maintainer describes how AI-generated security reports have evolved from obvious slop to high-quality submissions that are overwhelming maintainers with their volume.
Simon Willison · simonwillison.net
The Axios team published a full postmortem on the supply chain attack that injected malware into a release, revealing individually targeted social engineering against maintainers.
An argument for minimizing software dependencies, framing each one as an expanded attack surface for supply chain compromises.
AI Models, Tools & Impact on Software Engineering
Anthropic Research · www.anthropic.com
Anthropic's interpretability research investigates how emotion-like concepts emerge and function within large language models, exploring whether models that say they're happy or sorry have internal representations resembling emotions.
Simon Willison · simonwillison.net
Simon Willison discusses the cognitive costs and benefits of working with AI coding agents, drawn from his appearance on Lenny's Podcast.
An essay arguing that the value of code itself is diminishing as AI generation capabilities improve, shifting what matters in software engineering.
Simon Willison · simonwillison.net
GitHub's COO reports that platform activity has exploded from 1 billion commits in all of 2025 to 275 million per week, on pace for 14 billion this year, with GitHub Actions growing from 400K to 6 million daily runners.
Financial Times · www.ft.com
Microsoft releases a smaller, more efficient AI model as compute resource constraints force the industry to consider alternatives to ever-larger frontier systems.