July 2026


AI continues to dominate the news, largely involving security, and not in a good way.

From around the web:

  • Antares: Vulnerability Localization sounds like one of the best LLM uses I’ve heard of.
  • XKCD Main span is a great example of why threat modeling any design, even bridges, is a good idea.
  • Adam posted another thought provoking perspective: AI and Business Strategy . The following points are my opinions from quotes as jumping off points:
    • Any strategy based on “strengths and weaknesses relative to competitors” should avoid AI where funding token consumption is the only differentiation.
    • “When people pay to have their problem solved, they look for the lowest cost” — I fear this mindset disregards quality of work which is a perilous slippery slope.
    • While in some ways frontier models with similar capabilities “seems like the airline business”, it’s important to remember that there’s no FAA-like regulation whatsoever.
    • With model advances and price competition, before long on-premises LLMs could be the best deal as today’s larger models run on cheaper hardware of the future.
    • “What are your weaknesses, and can LLMs help you address them?” is tricky: how can LLMs possibly help with weaknesses unless you fully trust them and cross your fingers? (e.g. I’m weak at graphic design so I’m unable to recognize good design.)
    • There is a lot less excitement about prompt engineering now that LLMs are good at interpretation that evens out the field. As a result, highly skilled humans directing LLMs (the admirable centaur model) become less and less of a factor.
  • OpenAI Acknowledges GPT-5.6 May Accidentally Delete Files, Calls It ‘Honest Mistake’
    This is a good example of precisely why I argue for threat modeling to include unintentional harms, not be limited to wily attackers at gates (attack surface). In my view, “unauthorized” access is based on a very blurry line not well defined so it’s inadvisable worrying about it in the first place. In any case, what does it matter if a system meltdown was due to attackers or an “honest mistake”?