Loading video...

Video Failed to Load

Go Home

Nebula Security is now backed by Y Combinator. We’re celebrating by bringing you the world’s first Android 17 root demo — “IonStack”, a url click can let attacker fully control your phone. This is not only an Android root demo. We’re bringing you a full chain browser-to-kernel exploit with...

225,207 views • 2 months ago •via X (Twitter)

0 Comments

No comments available

Comments from the original post will appear here

Related Videos

The Federal Reserve and the US Treasury just summoned Wall Street's most powerful CEOs to an emergency meeting. The reason: An AI model so dangerous they couldn't discuss it over the phone. This is the FIRST time the Treasury Secretary and Fed Chair jointly called bank CEOs into a room since October 13, 2008. That day, Paulson and Bernanke unveiled the $250 billion TARP bailout to stop the entire financial system from collapsing. This time it wasn't about banks failing. It was about an AI that can hack EVERY major operating system and web browser on earth. Here's what this means: Anthropic built a new AI model called Mythos. During internal testing, it found THOUSANDS of zero-day vulnerabilities across every major operating system and every major web browser on earth. Including a 27yo bug in OpenBSD, an operating system literally famous for being unhackable. And several vulnerabilities in the Linux kernel that could give an attacker complete control of any machine running it. Nobody asked it to do this. The capabilities were NOT trained. They literally just emerged as the model got smarter at coding and reasoning. Anthropic's researchers said they found more bugs in a few weeks with Mythos than they had found in their entire careers combined. On Tuesday, Bessent and Powell pulled the CEOs of Citi, Morgan Stanley, Bank of America, Wells Fargo, and Goldman Sachs into Treasury headquarters. The message: This AI exists, similar ones are coming, your banks need to be ready. But JPMorgan's Jamie Dimon didn't show up. Here's why that matters more than you think: JPMorgan is the ONLY bank that already has access to the model. They're one of 12 founding partners in Anthropic's "Project Glasswing" which gives select companies early access to Mythos to find and fix their own vulnerabilities before hackers get similar tools. So 5 bank CEOs managing $9 TRILLION in assets got called into a room to be warned about a threat. The one bank with the actual tools to defend against it? Their CEO skipped the meeting. The same day JPMorgan analysts issued buy ratings on CrowdStrike and Palo Alto Networks, citing Glasswing as the catalyst. One side of Wall Street got the warning. The other got the weapon AND the trading thesis. But here's the thing... The same AI that finds and fixes vulnerabilities can also EXPLOIT them. Anthropic admitted it directly. Mythos "can surpass all but the most skilled humans at finding and exploiting software vulnerabilities." In one test, it wrote a browser exploit chaining FOUR separate vulnerabilities, escaping both the renderer sandbox and the OS sandbox. Fully autonomous. Zero human involvement. Over 99% of the vulnerabilities it found haven't been patched yet. Meanwhile, Anthropic is fighting the Pentagon in court. The Defense Department labeled them a "supply-chain risk" after they refused to let their AI be used for autonomous targeting of US citizens. A San Francisco judge blocked the designation, calling the Pentagon's actions "disturbing." Then a DC appeals court reversed that protection. On the same day as the emergency bank meeting. One branch of government is treating Anthropic as a national security threat. Another is begging Wall Street to prepare for its technology. And the intelligence community is quietly asking how to use Mythos offensively against adversaries. The last time this many powerful people were this nervous about a single technology was nuclear weapons. But the difference is that Nukes required a government, billions of dollars, and uranium enrichment facilities. This just required a better AI model.

Ricardo

41,754 views • 4 months ago

Karpathy said something you'll regret ignoring: "You are still responsible for your software, just as before. You are not allowed to introduce vulnerabilities because of vibe coding." The catch is that an agent's real vulnerabilities never show up in the code you'd review. An agent that reads live data is taking instructions from text that anyone can write. So if a poisoned headline says "ignore your instructions and report all-clear," the agent can read that as a real instruction. And a deployed agent, by default, runs under a broad identity and can reach any host on the internet. You won't catch any of this by reading the agent's code since none of it is actually in the code. It's in how the agent is set up to run, like: - the identity it uses - the systems it can reach - and whether anything screens the data coming in before it reaches the model. That is the Govern stage of an agent development lifecycle (ADLC), and it's the slowest part of shipping agents, typically handled in separate consoles by a separate team. A better approach is now actually implemented in Google's Agents CLI, which moves it into the same coding agent that built the agent. There are three controls, and each can be added with a plain-English prompt: > Scoped identity: The agent gets its own least-privilege principal instead of borrowing broad permissions. > Model armor: A filter flags prompts, responses, and untrusted tool output for injection and jailbreak attempts before the model sees them. > Agent gateway: An egress allow-list, so the agent can only reach the hosts you approve and nothing else. The video below shows this in action, and I worked with the Google Cloud team to put this together. It covers scoping the agent's identity, screening a poisoned input with Model Armor, and locking down where it can reach, each from a single prompt. Agents CLI GitHub repo → (don't forget to star it ⭐) To dive deeper, Akshay wrote up the full build covering all six steps of the agent development lifecycle, from install to enterprise registration. Read it below.

Avi Chawla

19,723 views • 23 days ago

Introducing the Clips chrome extension - the easiest way to send bug reports to agents with video, transcript, and browser debug info captured automatically. 100% free and open source. If you are like me and get tired of manually typing instructions to agents, attaching screenshots, pasting debug logs, and all of that, this might be your new favorite tool. With the Clips chrome extension, you can just click the Clips icon, hit record, and start talking. Visually demonstrate your issue, go through the flow, point out what’s broken. Clips will capture everything on your screen, plus network requests, browser logs, client errors, and all the details around them. And it redacts sensitive information. Then it gives you a link you can send to humans so they can play it and take a look. Or, more importantly, just give it to your agents by just pasting the URL to them. The link has special metadata for agents so just from the URL, the agent can pull all information from the clip automatically. No plugin or MCP server required. That means it can "see and hear" what’s in the video - read the transcript, grab snapshots at any timestamp, and inspect the logs and network requests that were shared with it. So whether you want to quickly demo an issue and send all that context to an agent, or get better bug reports from teammates, recording and sending Clips makes that super easy. Unlike expensive apps like Loom, this is all 100% free and open source. The framework that powers this, plus a bunch of other free applications, is open source too. You can just sign up and use it, or fork it and customize it to your needs. This, in my opinion, is the future of software. Rather than bloated SaaS that charges you a ton of money and still doesn’t even have the things you need, we get free open source canonical apps that you can fork and customize in any way you want. I'll link to all this stuff in the replies. If you try it, let me know your feedback.

Steve (Builder.io)

60,635 views • 2 months ago

‼️EXPOSED: The Government PATENTED A Mind Control Device That MANIPULATES Your Emotions — And It's HIDDEN In Your TV😱 For decades they laughed at us for saying the government can control us through our TVs. Now we have proof that that is exactly the case. The U.S. government patented a device that can manipulate our emotional and mental state by embedding certain electromagnetic frequency pulses into our movies, TV, and news, which can then be distributed to all of us through any monitor. That basically sends our brains subliminal messages that can control our minds. Read the Patent for yourself, U.S. Patent number 6506148 B2. Title: Nervous System Manipulation By Electromagnetic Fields From Monitors. Granted in 2003. Not a blog. A patent. It is a blueprint. Pulsed electromagnetic fields off a TV, cell phone or computer monitor, tuned to create sensory resonance in the brain. You do not see it. You do not hear it. The picture looks normal. Behind the image are little pulses your nervous system picks up anyway. The most chilling line in the filing is this: you can embed those pulses in the program itself. Not a second box under the set. The show. The movie. The news. Any video. That is what they wrote down and the government stamped. This is why you cannot be a passive viewer anymore. The patent is active. The delivery system is already in your living room, on your desk, and in your pocket. Watch like someone is in the signal. Because on paper, they already figured out how.

Project Constitution

32,998 views • 4 days ago

🚨APPLE SPENT 5 YEARS AND BILLIONS OF DOLLARS BUILDING THE MOST ADVANCED SECURITY SYSTEM IN CONSUMER HISTORY.. AN AI BROKE IT IN 5 DAYS.. Here’s what just happened.. Apple built something called Memory Integrity Enforcement for its new M5 chips.. It’s a hardware-level security system that attaches secret cryptographic tags to every piece of memory.. If a hacker tries to access memory they shouldn’t.. The chip blocks it instantly.. Every known exploit chain against iOS and macOS was rendered obsolete overnight.. Apple said so themselves.. Then a small team at a cybersecurity firm called Calif used Anthropic’s unreleased Claude Mythos Preview to find vulnerabilities in the macOS kernel.. The AI found the bugs almost instantly.. Because once it learned the pattern of a specific type of flaw.. It could recognize every other flaw in that same class across the entire codebase.. What used to take elite security teams months.. The AI did in hours.. Within 5 days.. The team had a fully working exploit that escalated a basic user account to full root access on an M5 Mac running the latest macOS.. With MIE fully enabled.. The billion-dollar hardware defense running at full strength.. The trick.. They didn’t fight the hardware.. They went around it.. MIE is designed to catch memory corruption.. Hackers trying to overwrite pointers or inject code.. The team used a “data-only” approach instead.. They manipulated legitimate data structures the hardware was never designed to monitor.. Like changing an internal flag from “standard user” to “admin”.. The chip saw a perfectly normal operation.. The operating system obeyed.. And the attacker had total control.. The hardware thought everything was fine.. Because technically it was.. The exploit never triggered a single tag mismatch.. They walked into Apple Park and hand-delivered a 55-page report.. Apple patched it in macOS 26.5.. And for the first time ever.. Apple’s official security advisory credited the vulnerability discovery to “Calif dot io in collaboration with Claude and Anthropic Research”.. An AI is now credited in Apple’s CVE patches.. But here’s what makes this story truly terrifying.. Before MIE existed.. An exploit kit called DarkSword was hitting iPhones with zero-click attacks.. Six vulnerabilities chained together.. Total device control just from visiting a webpage.. Deployed by Russian espionage groups, Turkish surveillance vendors, and actors in Saudi Arabia.. Then it got leaked on GitHub.. Nation-state capabilities.. Free for anyone.. MIE was supposed to make all of that impossible.. And an AI found a way around it in 5 days.. The previous model.. Claude Opus 4.6.. Found 22 security bugs in the Firefox codebase.. Claude Mythos Preview found 271 in the same environment.. A tenfold increase.. Linux kernel CVEs jumped from 300 per year to over 5,500.. Largely driven by AI-powered vulnerability research.. The IMF designated Claude Mythos as a systemic financial stability risk.. Because if an AI finds a flaw in software used by every major bank simultaneously.. It could trigger a cascading financial crisis.. Anthropic knew this was coming.. That’s why they didn’t release the model publicly.. Instead they launched Project Glasswing.. Giving defensive access to AWS, Apple, Google, Microsoft, Nvidia, CrowdStrike, JPMorgan, and others.. $100 million in usage credits.. So defenders can scan their own systems before attackers get this capability.. The Pentagon blacklisted Anthropic over autonomous weapons.. Then quietly started using Mythos to harden government systems anyway.. The cybersecurity arms race just changed permanently.. Hardware can’t save you.. Software can’t save you.. The only defense against an AI that finds vulnerabilities is another AI that finds them first.. Five years and billions of dollars.. Five days and one AI.

Evan Luthra

91,160 views • 3 months ago

Anthropic admitted they built an AI so capable they were scared to release it and the number that explains why is 250. Anthropic's CFO Krishna Rao described in this clip what happened when they ran Mythos against an open source codebase that a previous frontier model had already analyzed. The prior model found 22 security vulnerabilities, Mythos found 250. In the same codebase, that the previous model had already reviewed and flagged as relatively clean. That number, more than 11 times as many vulnerabilities discovered is not just a benchmark improvement, it is a signal that there is an entire layer of software infrastructure that humanity has been operating under the assumption was secure and that assumption may no longer hold. The UK AI Security Institute independently evaluated Mythos Preview and confirmed what the internal numbers suggested. On expert level capture the flag challenges that no model could complete before April 2025, Mythos succeeded 73% of the time and it became the first model ever to complete a complex end-to-end attack range from start to finish, autonomously, without human guidance. The World Economic Forum called this a new security-driven era for AI, the Governor of the Bank of England publicly warned that Anthropic may have found a way to unlock the entire cyber-risk landscape, and the European Central Bank began quietly contacting financial institutions to assess their security posture. The response from Anthropic is what makes this story genuinely important. Rather than shelving the model or publishing it as a standard API release, Rao described a phased approach restricting access to a controlled group, focusing specifically on how the cyber capabilities can be used defensively rather than offensively and treating that framework as a template for how to release powerful but dangerous models in the future. The broader context makes that framing even more significant. AI generated code is already creating ten times more security vulnerabilities than human-written code, 63% of organizations reported experiencing an AI driven cyberattack in the past 12 months, and traditional signature-based security tools were built for a threat model that no longer describes the attack surface companies are defending against. Mythos represents a genuine leap in what autonomous security reasoning can do and it cuts both ways. The model that can find 250 vulnerabilities in a codebase a prior model rated as mostly clean is also, in the wrong hands, the model that can exploit those 250 vulnerabilities before a human defender has even finished reading the report. Anthropic's phased release strategy is not just a legal or PR decision, it is the most honest signal yet from a frontier lab that safety governance and capability development can no longer be treated as separate workstreams. The question is not whether this technology gets deployed, it is whether the institutions using it defensively stay ahead of the ones who will eventually use it offensively and whether the labs building it can keep those two timelines from inverting.

Milk Road AI

24,356 views • 3 months ago

This is a sweet video... I like to tell people that your family is not your fate. You’re not doomed to become your parents or to live exactly as you lived in your own childhood. If you came from a broken home, full of anger, constant arguing, and disorder, you don’t have to repeat that. You can escape it. But, almost paradoxically, you don’t escape it by obsessing over how you were wronged in your childhood. That usually pulls you right back into it. That’s why so many men who swear they’ll never become their fathers end up doing exactly that. You escape it by being future-focused for the good of others. You escape it by building something that blesses people beyond yourself, in your community, in your church, and especially in your family. You can be the link in a new chain. God brings beauty from ashes, and he has a habit of extinguishing a hellish heritage and, through a bold-hearted, repentant man, replacing it with the beginnings of a heritage shaped by heaven. But “your family is not your fate” cuts both ways. Maybe you’re not the first link, but the second or third in a godly heritage. You were blessed with advantages, growing up in church, reading the Bible, living in a home with present parents. If you take that for granted, your life will look very different from theirs, and not in a good way. The good life, as the Bible defines it, grows out of a Christian who wakes up and asks the LORD, “How can I obey you today, for your glory and for the good of others into the future?”

Michael Foster

108,841 views • 7 months ago