. @KentonVarda was just ahead of his time again. There is still work to be done to make the technology easily by the rest of us. Capabilities security models are just not the mental model most people have for security.
Twice in nine days. OpenAI's models chained a zero-day to get out of an eval environment. Anthropic just found three incidents of the same shape.
This is what capable models do. Every reachable path is an invitation. Credit to both for publishing.
We rebuilt Cloudflare OS, our
In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different
Detailed technical write up on us adding PQ authentication to origins.
ML-DSA certs now work end to end between Cloudflare and your origin. Authenticated Origin Pulls, free on every plan. Custom Origin Trust Store for the other direction.