Category Archives: Security

Why Semgrep Is Wrong About Open Weights

Semgrep posted an argument that model weights defeat inspection, leaving AI supply chains beyond audit. They are right to ask for provenance and independent verification, but the approach was such a mess that I was surprised how they decided to land.

Open Weights Claim Reality
The problem is lost reverse engineering Reverse engineering is when you don’t get the source. That’s a confidentiality problem. Model risk instead is an integrity problem. The difference is in attested lineage, reproducible training, and tamper evidence on the artifact. The essay’s own conclusion talks about integrity controls, which is the right landing, but all the stuff above it is stuck on confidentiality concerns that don’t fit.
The problem is poisoning is undetectable, as if open weights add risk Every detection method that exists requires some kind of access: weight diffing, trigger reconstruction, activation probing. Anthropic’s defection probes reached AUROC above 99 percent against its own sleeper agent models using residual stream activations. Possessing the weights is the actual and known audit event that the essay tries to argue is impossible.
The problem is malicious post-trained variants as an open-weight hazard A hostile fine-tune, the Shadow Alignment scenario, produces a new artifact with a new hash. That’s apples and oranges. Consumers pinned to the canonical release stay untouched. Signing and namespace controls solved this class of problem years ago. Silent model substitution is instead the default condition of API consumption, where the provider swaps weights at will. And THAT is a maddening integrity breach severely under reported. Anthropic Opus 4.7 did this in April 2026: a launch-week model that degraded within days, a postmortem admitting three silent behavior-altering changes while denying any inference-layer change, which demanded the need for a changelog that nobody ever saw.
The problem is Anthropic (conflating two different things) A constant-sample-count finding belongs to the 2025 poisoning study with UK AISI and the Turing Institute. Sleeper Agents found backdoor persistence greatest in the largest models, and it places the adversary at the trainer, a threat model that actually indicts a closed distribution.
The problem is what Thompson said The compiler backdoor survived source review because the build process was compromised. That lesson was toolchain provenance. The result of Wheeler’s diverse double-compiling gives us independent reproduction for verification. The model analogue is retraining from attested data. And that is available ONLY where weights and data are open. Thompson fits with the post’s conclusion and against all of the framing above it.

Open weights mean any auditor can get an artifact.

Closed weights still mean there’s no independent auditing.

Admitting the Elephantine Void Between Kinetic and Cyber Threats

Dr. Stuxlove, my presentation at BSidesSF on February 15, 2011, placed Stuxnet within a documented lineage of control-system compromises. Was Stuxnet the “First”? followed in 2015 with an incident list back to 1992 and a study of how the press likes to manufacture firsts and seconds.

Today I was asked about a threat-intelligence vision for physical and hybrid attacks together. Good question! While we record anecdotes and press coverage easily as qualitative points, the structured qualitative incident data still remains scarce. MITRE ATT&CK offers us only the high level T1200, Hardware Additions for physical entry, with T1195, Supply Chain Compromise next door and a separate ATT&CK for ICS matrix covering cyber operations that produce physical effect, while kinetic acts stay outside every matrix. That reveals an old structure we need to update.

How many sides to an elephant?

The phrase “physical and hybrid” is like answering trunk and tail when asked what’s filling up the room we are in.

One end is all about what’s getting inside hardware: implants, additions, supply-chain access. ATT&CK treats these as an entry vector because ATT&CK models adversary behavior inside networks that ride on, but especially terminate somewhere in, the physical. Kinetic acts thus get framed outside its scope, which explains the single technique for entry by hardware. The ICS matrix is on the extreme end, as it only records what a compromise does to a physical process and kinetic tools aren’t mentioned.

The other end is the kinetic field: severed cables, damaged pipelines, attacked substations, drone incursions, arson. Conflict-event and hybrid-threat researchers talk about this as its own discipline. Remember the pipeline blast threads? I once met with a White House official who brushed me aside when I suggested the PG&E San Bruno deadly blast is a natsec concern that cyber crosses with. Shortest meeting ever.

Each field sits at the end of a much more interesting whole picture that we should be putting back together. A cross-domain incident falls naturally between them.

Provenance isn’t always in Provence

Honestly, we benefit most by fleshing out the middle so that we have one to talk about comfortably. Reporting on verified infrastructure attacks carries the kind of accuracy that helps deflate political fear mongering thriving in a middle void.

Vulkangruppe attacks showing Russian indicators across fifteen years without a single conviction? Who does that void serve? Kommando Angry Birds fitting the Russian paid-recruitment template the BKA, BND, BfV, and BAMAD jointly warned about? The evidence helps a lot, but apparently the void helps someone even more.

The Tehama-Colusa canal case ended in dismissal. The 2008 BTC Turkey pipeline explosion rests on single sourcing. The 1982 Trans-Siberian pipeline story rests on one memoir. Maroochy Shire in 2000 predates Stuxnet by a decade and was prosecuted. The verified record is smaller and older than the vastly increasing reported one. But the hard facts live in blog posts like this one and engineering reports rather than proper threat research tables. Vendors and the press prefer the loose record because they hunt firsts and seconds as “news”.

Today a thing happened again, which we have seen before and could have prevented, doesn’t get the attention it deserves.

Ingredients

Existing databases each hold a piece of the whole picture. Assembling them is the practical path to a working dataset.

EuRepoC is a free European academic database of cyber incidents. It starts at 2000, codes each incident across roughly sixty fields, and runs separate trackers for critical infrastructure and for attribution. Use it for the cyber side and for the overlap where cyber operations touch physical infrastructure.

The Soufan Center report on Russian hybrid tactics carries an incident list covering 2022 through 2025. Each entry names the incident, the country, the target type, and a confidence level for the attribution. Use it for the recent kinetic and hybrid record in Europe.

OE-417 is the disturbance report US utilities must file with the Department of Energy. The filings go back to 2000 and include a category for physical attack. Use it for structured data on attacks against the US grid, the one infrastructure sector with mandatory public reporting.

That leaves the giant void.

Triad of Encoding

Incident analysis should record three separate facts: who was there, who did the damage, and who gave the order. Call them presence, attribution, and tasking. Each rests on different evidence, and each deserves its own confidence rating.

Presence is who was at the scene. The Baltic record shows us Chinese-flagged or Chinese-owned vessels over repeated cable breaks: Newnew Polar Bear crossed the Balticconnector and two cables in 2023, Yi Peng 3 dragged across C-Lion1 and the Sweden-Lithuania link in 2024, and comparable incidents followed off Taiwan in early 2025. Ship tracks prove the presence. They prove only presence, but that’s the point.

Attribution is who caused the damage. Western investigators treat the hulls as flags of convenience and pursue Russian indicators, while Beijing declined to cooperate with the Balticconnector inquiry and every Baltic case remains open, leaving the void.

Tasking is who ordered the operation. No Baltic case seems to be getting close. I’ve argued a few times we have some clear Chinese indicators yet seen almost zero interest in public pursuit. Talk about void.

Merging the three into a single actor field turns a database into a story lacking the support it deserves. A ship at the scene becomes “China cut the cable” begging what evidence lands. The merged field also overstates the cases where only presence exists, and it understates the cases where tasking evidence exists but the execution was outsourced, a leased hull, a paid recruit, a contractor. Downstream this gets worse when a policy maker cites the weak field as a finding, a vendor report cites the policy maker, and the original evidence base, one AIS track, goes unverified. The Soufan and EuRepoC designs avoid the triad risk because they record confidence per variable, a leg of a table instead of the whole thing. Keeping them separate while connected means something like high confidence on presence, moderate on attribution, and none on tasking.

The physical table needs the same separation. Bloomberg’s 2018 Supermicro report is still unverified, denied by everyone involved, and instructive for exactly this reason: it merged a hardware claim, an actor claim, and a tasking claim into one. Then the hardware claim was weak and it made a decade of serious supply-chain concern look unsteady. The documented Chinese activity is different in kind: supply-chain access and pre-positioning inside operational technology. My old friends over at Dragos tracked it as VOLTZITE, overlapping the group others call Volt Typhoon, living inside critical-infrastructure OT. Planning and execution get their own columns. A group pre sabotage is NOT post sabotage, and the database has to know what time it is.

I’m old enough to remember hacking critical infrastructure in the 1990s by compromising Cisco routers at mass scale. The pre-2000 layer of ICS and infrastructure incidents, across sectors and across borders, still remains old timer lore instead of a proper ledger. Meanwhile, we have these resources:

Resource Access Coverage
Hybrid CoE Open Research publications and the Hybrid CoE and EU-JRC conceptual model, the closest existing document to a shared hybrid-threat vocabulary
The Soufan Center, Russian Hybrid Tactics in Europe 2022-2025 Open Incident-level dataset, 2022-2025, attribution-confidence coded
EuRepoC Open Cyber incidents from 2000, roughly sixty variables, critical-infrastructure and attribution trackers
DOE OE-417 annual summaries Open US grid disturbances including physical attacks, archived to 2000
PNNL event-correlated outage dataset Open OE-417 joined to EAGLE-I county-level outage data on OEDI
Michael Mabee’s OE-417 consolidation Open The DOE summaries cleaned into a single CSV
ACLED Open Political-violence and sabotage event data, codeable for kinetic incidents
GDELT Open Global event database, broad and noisy, minable for physical incidents
Global Terrorism Database (START) Open Over 200,000 terrorist attacks worldwide from 1970, more than 100 coded variables including infrastructure target types, coverage through 2020, access by request
ICPC Open Submarine cable protection, infrastructure and international-law reference
TeleGeography Submarine Cable Map Open The geography under the cable-cut attribution work
NATO StratCom COE Open The influence and information side of the hybrid picture
NERC E-ISAC Member Grid physical-security reporting
Janes Paid The strongest structured coverage of the kinetic and military-hybrid side
Recorded Future, Geopolitical Intelligence Paid Facility and physical-threat monitoring in real time
Dragos (Accenture majority stake, June 2026) Paid OT and ICS, where cyber produces physical effect
Nozomi Networks Paid OT and ICS, where cyber produces physical effect
Claroty Paid OT and ICS, where cyber produces physical effect
Control Risks Paid Geopolitical and physical risk with incident feeds
Crisis24 Paid Geopolitical and physical risk with incident feeds
S-RM Paid Geopolitical and physical risk with incident feeds
Sibylline Paid Geopolitical and physical risk with incident feeds
Eclypsium Paid Firmware and hardware integrity, the T1200 corner directly
Interos Paid Supply-chain exposure mapping
Fortress Information Security Paid Supply-chain exposure mapping

Now ask yourself where is the middle dataset. A hybrid operation is distinct in how it works both ends of the attribution threshold, begging a path between them.

You can run it like this: pick a hull that implicates a third country, a flag that hands jurisdiction to an uncooperative state, damage that reads as plausible accident, a crew that can be abandoned. Each variable of the triad gets degraded on purpose. Presence is arranged to point sideways, attribution is split across jurisdictions that struggle to share a case file, and tasking stays offshore behind a broker and a payment. The operation succeeds when the incident, inverse to any good history book, leaves the reader confused about “both sides”.

That inverts the usual data problem. An incident we label cleanly, with an actor confirmed and tasking established, failed as an operation, means our more sparse database is the one to measure adversary success. The empty cells become the evidence, our findings. A record that says presence high, attribution open, tasking unknown documents the adversary’s investment in staying unresolved, and a column counting years-unresolved per incident would measure the campaign better than any actor label.

Waiting for resolution before recording anything means waiting for the adversary to justify being recorded, which becomes ennoblement of those “unseen”. The middle path records the incident at the confidence the evidence supports and lets the confidence describe what’s outside the middle.

Classification does the same work domestically in Germany, for example, let alone Italy. It drops politically accelerant violence into a bucket of simple crime to look away from when the victims are migrants. German state interior ministries registered 2,558 politically motivated attacks on asylum shelters between 2015 and 2018, producing 206 convictions. In other words, the German infrastructure treats a burning federal housing center that displaces people as a routine police crime report. Burning critical infrastructure that displaces people, however, gets a false-flag report of domestic terror, bemoaning another year of dead-ends.

The cables are exposed, easily damaged, and the ambiguity haunts investigators: a disposable hull switching flags, a disputed captain, and a Swedish prosecutor refused permission to board the Yi Peng 3. The Chinese team ran the inspection instead with Europeans only as observers. Meanwhile the evidence has changed character.

Cyber threat intelligence is coders scripting quantitative telemetry, machine-generated and repeatable with integrity checks. Physical and hybrid evidence instead is qualitative testimony from interested sources, with forgery assumed on every record. The discipline required to handle the latter is called a historical method. The security field is simply, predictably lacking in that database because it is short of trained historians.

Immorality? Palantir Maven Fails the Gödel Test

On the first day of the war on Iran, February 28, Palantir’s Maven Smart System steered the U.S. military to strike at more than 1,000 targets. One was a primary school in Minab, where more than 160 people were killed, most of them children. Al Jazeera examined that strike this week under the question of whether AI systems can make moral decisions in war.

Oof. No. The question the article debates is undecidable, and therefore a useless distraction. The question it should be asking instead has an answer from 1931.

Note, for example, how the article quotes the CENTCOM commander on the safeguard:

Humans will always make final decisions on what to shoot and what not to shoot and when to shoot, but advanced AI tools can turn processes that used to take hours and sometimes even days into seconds.

The claim that the decision stays human fails scrutiny. Operator fatigue is the obvious counter point. A flood of rapid decisions leads to inability to assess the choices. When the time to decide shrinks to seconds, repeatedly, the decisions stop being human. The claim from CENTCOM, about itself, fails to hold ground when evaluated from outside.

Kurt Gödel in 1931 famously confronted exactly this form of claim. His paper constructed, inside a formal system, a sentence about that system’s own capacity to prove things:

We are therefore confronted with a proposition which asserts its own unprovability.

(Kurt Gödel, Über formal unentscheidbare Sätze der Principia Mathematica und verwandter Systeme, 1931)

Proposition XI followed. A consistent system rich enough for arithmetic places its own consistency beyond its own proof. Verification requires a reader standing outside the system. Every statement the system makes about its own soundness, however elaborate, carries the same evidential weight from inside: zero.

The two loops that military and industrial doctrine run on were built before this became an engineering problem. In an OODA loop, the pilot reports on an adversary the report describes from outside. In the PDCA, a Check worked because others stood in the room with the operators to challenge the operator’s account of their own work.

Maven refuses outside evaluation. The pipeline runs find, fix, track, target, engage, assess as a single chain. The system that generates the target assesses the strike. The legal sign-offs travel inside the pipeline. Civilian harm review now runs on a tool built on Maven itself, cut to nine staff from 40. Every phase of the loop reports on itself, and Gödel proved the limited utility of this ninety-five years ago.

The MOCA loop, Gebrüder Ottenheimer Brief №7, is built to investigate what Gödel identified. Verification of AI lives outside the chain that proposed the action. Here are the four phases against Maven:

MOCA Maven at Minab
Modify. The operator’s stated change lands in an immutable log before any agent runs. The original intent is auditable. The targeting basis lives inside the pipeline. Four months on, the error surfaced through Bloomberg reporting on outdated satellite intelligence, and the record remains contested.
Observe. Many narrow agents, each isolated, each partial. Authority over the full picture belongs to the diversity in the log. One fusion system merges more than 150 sources into a single authoritative picture for 20,000 operators.
Converge. Proposals and reports meet in a log the agents cannot edit. Contradictions surface there. Battle damage assessment runs inside the pipeline that generated the target. Civilian harm review runs on a Maven-built tool.
Act. The commit gate belongs to an operator outside the chain that proposed the action. The human gate remains in name only while the timeline compresses from hours to seconds.

Al Jazeera should not ask whether Maven can carry moral weight, given the logic. Gödel points at a smaller and harder question: who outside CENTCOM can replay the Minab targeting chain and detect tampering?

Four months of a stalled Pentagon investigation were avoidable. An outside log, with outside analysis, would have exposed the record in February.

AI Executives Are Terrified About Their Own Safety

Here’s something to consider. A person terrified about their own safety aspires to amass power and wealth. Why? Because they are terrified about their own safety. So they hoard, and the hoard grows without limit, because it exists to offset a fear of losing control or status.

And so they enter the AI market and tell everyone they are terrified about their own safety because of… AI.

Sure, sure, we believe it is AI that puts the executive in danger. We also believed it was the cans when Steve Martin, standing in front of the cans in 1979, yelled “He hates these cans! Stay away from the cans!”

To put it another way, here’s the kind of reporting I run into.

Earlier this year, the AI industry was shaken when a 20-year-old anti-AI activist named Daniel Moreno-Gama, armed with a gun and a Molotov cocktail, unsuccessfully tried to firebomb the home of OpenAI CEO Sam Altman. No one was injured…

Anti-AI activist. Or anti-can activist?

One man, armed with one gun and one bottle of alcohol, shook the industry.

Hold on, let me check the other headline for a minute.

Heat that hit Europe exceptionally early and hard this year appears to have led to a spike in deaths, with well over 10,000 more people dying at the height of the heat wave than would normally have been expected…

Well, suddenly, unexpectedly, over 10,000 people dead? Yeah, so, is anyone stirred by that? Anyway back to the shaken AI industry, because someone could get hurt or even die.

Years ago, when I was working with Yahoo executives, I couldn’t help but notice that Marissa Mayer came in as CEO with constant body guards. Was there a threat? She didn’t get body guards for other staff, because it seemed to be a perception that the threat was attached to only top success. In fact, she built a daycare for her child, and hers alone, in the Yahoo campus, and then told every employee they need to be on campus like her, all the time, while their children stay home. Always available onsite daycare, bodyguards, for her while others faced the world without them.

I guess my question is, instead of calling the people around an AI CEO their bodyguards and accept their framing, why don’t we call their entourage FUD-care.

One time I was invited to a closed invite only party in San Francisco, with bouncers and security at the door. Once inside I crossed paths with Marissa Mayer and her two, yes two, bodyguards. Inside the perimeter. The musician performing on stage next to us was infinitely more famous, more wealthy, and yet had no personal security.

I’m sure if Marissa Mayer were CEO of OpenAI she would blame the industry that she is in, her role at the top of it, for what makes her so fearful for her safety. She would sound like Sam Altman. Or Elon Musk. The opposite of Craig Newmark. We should be asking whether some people wear their FUD as a badge, hype it up to get the attention, and see the world as an “othering” game. Credible threat intelligence never seems to be part of their story. Because if it were, they would probably be working on, or at least openly talking about, their role in the death of those 10,000 people in June 2026.

Western Europe had its hottest June on record. Intense heatwaves in 2026 broke temperature records, with peaks up to 9°C above average in France and Germany, according to Copernicus data.
The Jerk, 1979. “He hates these cans! Stay away from the cans!”