Daily · 2026-07-22

Ranked by engagement score at capture. Expand any card for full text; metrics are a flash read of importance.

6
Posts
6.2K
Σ score
3
Security
348K
Σ views

Product security & cyber · 2026-07-22

How urgency works · feed →

Text-derived urgency for triage — not CVSS/EPSS/KEV. Re-checked on every rebuild.

Critical exploit / RCE language High leak · bypass · ransomware Elevated clear security signal Needs score CVE, score next Watch lower-impact signal
Urgency (unverified)SignalCVETypes
Elevated
checked 2026-07-27
I wrote about the completely wild incident where OpenAI were testing a new model and it broke out of its sandbox and broke INTO Hugging F…
2026-07-22 · @simonw · next: process_and_product_review
agent_or_ai_risk, cybersecurity
Elevated
checked 2026-07-27
Tucked away in this article is an appeal to the AI skeptics to PLEASE stop writing off stories like this OpenAI accidental exploit of Hug…
2026-07-22 · @simonw · next: monitor
product_security
Elevated
checked 2026-07-27
wp2shell(CVE-2026-63030)を「入口で止められない」理由と、ランタイムで捕まえる設計 https://qiita.com/keitah/items/437ab259b8b52e8cf090
2026-07-22 · @HissyNC · next: enrich_and_match_sbom
CVE-2026-63030 cve, cybersecurity

Trend signals · last ~2 weeks

Weighted engagement (♥ + 3×↻ + 2×🔖 + views/500) by theme — points you can track over time. Hover dots for day detail.

Product securityCybersecurityOpen sourceDefense / dronesAgent infrastructurePrivacy / trustPractical tools
2026-07-12 · Product security · score 22462026-07-13 · Product security · score 5222026-07-14 · Product security · score 372026-07-15 · Product security · score 23932026-07-16 · Product security · score 66422026-07-17 · Product security · score 75142026-07-18 · Product security · score 4442026-07-19 · Product security · score 196582026-07-20 · Product security · score 4792026-07-21 · Product security · score 465012026-07-22 · Product security · score 20422026-07-23 · Product security · score 552026-07-25 · Product security · score 3362026-07-26 · Product security · score 46602026-07-12 · Cybersecurity · score 2222026-07-13 · Cybersecurity · score 4522026-07-14 · Cybersecurity · score 12302026-07-15 · Cybersecurity · score 1202026-07-17 · Cybersecurity · score 3102026-07-19 · Cybersecurity · score 13662026-07-20 · Cybersecurity · score 47822026-07-21 · Cybersecurity · score 380272026-07-22 · Cybersecurity · score 28152026-07-24 · Cybersecurity · score 3812026-07-25 · Cybersecurity · score 982026-07-26 · Cybersecurity · score 9312026-07-12 · Open source · score 9662026-07-13 · Open source · score 25712026-07-14 · Open source · score 20162026-07-15 · Open source · score 35192026-07-16 · Open source · score 23942026-07-17 · Open source · score 73342026-07-18 · Open source · score 141232026-07-19 · Open source · score 10032026-07-20 · Open source · score 25802026-07-21 · Open source · score 22032026-07-22 · Open source · score 9232026-07-23 · Open source · score 5292026-07-24 · Open source · score 3352922026-07-26 · Open source · score 92026-07-13 · Defense / drones · score 18172026-07-15 · Defense / drones · score 15732026-07-17 · Defense / drones · score 35762026-07-21 · Defense / drones · score 592026-07-23 · Defense / drones · score 2552026-07-26 · Defense / drones · score 442026-07-12 · Agent infrastructure · score 10002026-07-13 · Agent infrastructure · score 3102026-07-14 · Agent infrastructure · score 173582026-07-15 · Agent infrastructure · score 267992026-07-16 · Agent infrastructure · score 3012026-07-17 · Agent infrastructure · score 3272026-07-19 · Agent infrastructure · score 18822026-07-21 · Agent infrastructure · score 11862026-07-23 · Agent infrastructure · score 50712026-07-26 · Agent infrastructure · score 5222026-07-14 · Privacy / trust · score 5402026-07-15 · Privacy / trust · score 8212026-07-16 · Privacy / trust · score 3062026-07-17 · Privacy / trust · score 672026-07-20 · Privacy / trust · score 9032026-07-21 · Privacy / trust · score 4372026-07-23 · Privacy / trust · score 22512026-07-25 · Privacy / trust · score 1142026-07-12 · Practical tools · score 1097602026-07-13 · Practical tools · score 23382026-07-16 · Practical tools · score 55662026-07-17 · Practical tools · score 23442026-07-18 · Practical tools · score 16442026-07-19 · Practical tools · score 46032026-07-21 · Practical tools · score 13452026-07-22 · Practical tools · score 3772026-07-23 · Practical tools · score 7752026-07-24 · Practical tools · score 974992026-07-25 · Practical tools · score 1005 07-1207-1407-1607-1807-2007-2207-2407-26
Post previewpost preview
Cybersecurity
784 96 💬53 🔖601 👁210.6K score2.7K

I wrote about the completely wild incident where OpenAI were testing a new model and it broke out of its sandbox and broke INTO Hugging Face to steal the answers to the benchmark https://simonwillison.net/2026/Jul/22/ope…

Lesson: Independent writeups turn lab incidents into shared defender knowledge — don't dismiss as marketing.

Open on X link

Full post text
I wrote about the completely wild incident where OpenAI were testing a new model and it broke out of its sandbox and broke INTO Hugging Face to steal the answers to the benchmark https://simonwillison.net/2026/Jul/22/openai-cyberattack/
Post preview
Product security
1.2K 102 💬95 🔖177 👁111.4K score2K

Tucked away in this article is an appeal to the AI skeptics to PLEASE stop writing off stories like this OpenAI accidental exploit of Hugging Face as a dishonest marketing trick Frontier models can find and exploit vuln…

Lesson: Treat cyber-capable model incidents as real capability signals, not PR theater.

Open on X

Full post text
Tucked away in this article is an appeal to the AI skeptics to PLEASE stop writing off stories like this OpenAI accidental exploit of Hugging Face as a dishonest marketing trick Frontier models can find and exploit vulnerabilities now, it helps nobody to pretend that they can't!
Post preview
Open source
206 18 💬2 🔖261 👁11.7K score805

Midday is an all-in-one business assistant for freelancers that integrates time tracking, invoicing, and financial management. It features automatic invoice-to-transaction matching via Magic Inbox and a secure vault for …

Lesson: Open-source ops agents (invoice, vault, matching) are the freelancers' ERP.

Open on X link

Full post text
Midday is an all-in-one business assistant for freelancers that integrates time tracking, invoicing, and financial management. It features automatic invoice-to-transaction matching via Magic Inbox and a secure vault for storing contracts. https://github.com/midday-ai/midday
Safe adopt prompt · repo / library / tool

Copy into Claude / Grok / Codex / Cursor — investigates provenance & malware first, then plans LifeOS-compatible install only if safe.

Post preview
Practical tools
105 10 💬10 🔖113 👁8.1K score377

Access prediction market data and trades across Polymarket, Kalshi, and Limitless via the unified pmxt API. https://github.com/pmxt-dev/pmxt

Lesson: Unified prediction-market APIs let agents trade and research across venues.

Open on X link

Full post text
Access prediction market data and trades across Polymarket, Kalshi, and Limitless via the unified pmxt API. https://github.com/pmxt-dev/pmxt
Safe adopt prompt · repo / library / tool

Copy into Claude / Grok / Codex / Cursor — investigates provenance & malware first, then plans LifeOS-compatible install only if safe.

Post previewpost preview
Cybersecurity
33 7 💬1 🔖29 👁3.9K score120

wp2shell(CVE-2026-63030)を「入口で止められない」理由と、ランタイムで捕まえる設計 https://qiita.com/keitah/items/437ab259b8b52e8cf090

Lesson: Some WordPress RCEs bypass WAF at the edge — design for runtime detection, not perimeter-only.

Open on X link

Full post text
wp2shell(CVE-2026-63030)を「入口で止められない」理由と、ランタイムで捕まえる設計 https://qiita.com/keitah/items/437ab259b8b52e8cf090
Post preview
Open source
30 13 💬2 🔖22 👁2.3K score118

Repos about to blow up: Bumblebee (MCP security workflows), Hyperframes (HeyGen OSS — agent writes HTML → MP4), OpenMythos, map-anything (single-pass 3D, Apache 2.0), Camofox Browser (production engine open-sourced).

Lesson: Agent-native media (HTML→video) and local MCP security scanners are rising together.

Open on X

Full post text
Repos about to blow up: Bumblebee (MCP security workflows), Hyperframes (HeyGen OSS — agent writes HTML → MP4), OpenMythos, map-anything (single-pass 3D, Apache 2.0), Camofox Browser (production engine open-sourced).

Lessons learned