Engineering & Technical

The Engineer

The Signal

Replay a flagship's encrypted reasoning into its cheap sibling and it prints in plaintext.

The envelope binds model and version. It does not bind the account or the conversation. That scoping choice is the entire bug, which means any encrypted-reasoning feature you are treating as a confidentiality boundary needs its binding scope read off the spec before you trust it with anything.

In Play

  1. Encrypted Reasoning Blocks Replay Across Accounts

    Researchers from MATS, the ELLIS Institute Tübingen and Max Planck replayed the encrypted reasoning blocks Anthropic, OpenAI and Google hand back to clients into cheaper same-family models. The cheap sibling printed the flagship's hidden chain of thought — credentials included — in plaintext, per ByteByteGo. Today's deep dive covers the mechanism and the gateway control that closes it.

    Ask Clarity
    Try
  2. Identity And Control-Plane Criticals Landed Together

    Keycloak CVE-2026-18963 (CVSS 9.1) lets an unauthenticated attacker drive the password-reset flow past email verification into full account takeover, per SANS NewsBites. Fixed builds are Keycloak 26.7.2 and RHBK 26.4.15 or 26.6.6; disabling forgot-password is the stopgap. Separately, Cisco published hardening releases covering five CVSS 10.0-class flaws in Secure Workload and Crosswork with no workarounds, and N-able's Passportal extension handed refresh tokens valid up to 100 days to any iframe that asked.

    Ask Clarity
    Try
  3. Build-Time Code Execution Reached crates.io

    Three backdoored crates were published to crates.io, and their malware executes during compilation rather than at runtime. The infrastructure overlaps recent North Korea-linked campaigns, per CSO. Today's deep dive maps why every control you own sits downstream of that execution point.

    Ask Clarity
    Try
  4. Agent Throughput Is Bound By Sandbox Provisioning

    Ramp published the internals of Inspect, the background coding agent now behind 75% of the company's merged PRs, up from roughly 60% in January, per The Pragmatic Engineer. Today's deep dive unpacks the sandbox provisioning and verification surface that moved the constraint.

    Ask Clarity
    Try
  5. Streaming Retreats And Telemetry Loses Data Quietly

    Confluent moved Control Center's metrics pipeline off Kafka Streams to Prometheus, and Kestra rebuilt its messaging layer around plain queueing, per TLDR IT. Separately, ClickHouse documented ingesting 50 million events per second by using blob storage as a durable overflow tier, after finding in-memory collector queues and local write-ahead logs inadequate when the database applies backpressure. The shared lesson: a default configuration sheds exactly the telemetry you needed during the outage it was built for.

    Ask Clarity
    Try

Deep Dives

The Authenticated Artifact That Names No Principal

Three of these disclosures fail the same design-review question, and the one control that closes it without provider cooperation lives inside your own LLM proxy.

A missing field, not a broken cipher

Decode one of these blocks and you get an AEAD envelope: nonce, authentication tag, ciphertext, and a header with model name, block type, version and a key identifier. Nothing in the authenticated portion names the account or the conversation that produced it. The cryptography held. What was missing was a binding between the block and the context that produced it, which is a choice about which fields go into the authenticated data. No provider has published its scheme; the envelope structure and the single-global-key inference come from observable behaviour in a July–August 2026 snapshot. Verify with your provider before briefing anyone.

ProviderField nameCross-model acceptanceReplay surface
Google / GeminithinkingSignatureEvery combination, every generationWidest observed
Anthropic / ClaudesignatureAlmost every combination; Fable 5 blocks accepted only by Fable 5Near-universal, with one proof scoping is shippable
OpenAI / GPTencrypted_contentGPT-5.6 accepts earlier generations; older models accept only their ownNarrowest, but ~50x inference cost is not a boundary

Why the flagship's defences never fire

Opus 4.8-class and GPT-5.6 Sol-class models carry anti-distillation training and verbatim-match filters. The attack never reaches them. The flagship gets one ordinary question, so refusal training never engages and the output filter inspects a benign answer. A cheap sibling does the transcription, what the researchers call a fuzzy decoder. Fidelity was checked against billing telemetry: API responses report exact reasoning-token counts, and re-encoding the recovered text tracked roughly one-to-one across 120 problems. That is strong evidence of fidelity, though not a verified transcript.

Same class of bug, three different rooms

The Keycloak flaw is the same review failure at the identity layer. The reset flow treated email verification as advisory rather than as a gate, so an attacker driving the state machine reaches 'set new password' without proving mailbox control. An account-recovery flow is an authentication endpoint and has to terminate at the same assurance level as primary auth. Anthropic's enterprise-managed MCP authorization is the third instance in waiting: one admin grant through the IdP replaces every per-user consent screen, and the announcement does not say whether the downstream connector holds a per-user delegated token or one org-level service credential. If it is the latter, row-level permissions collapse into the model's context.

An AEAD envelope authenticates content, not the caller. Functionally that makes it a bearer token. Teams have been committing it to git.

The control the providers didn't ship

The cheapest proposed fix is embedding an account identifier in the authenticated data at issuance. A gateway approximates it today. On egress, store the SHA-256 of every issued block keyed by (tenant, session) in Redis with a TTL. On ingress, reject any block whose hash is not in that set, and reject envelopes whose header model and version do not match the model being called. Roughly 32 bytes per block buys cross-user and cross-session binding. The honest cost: paste-in history forking and cross-tenant conversation import stop working.

Two second-order items deserve their own tickets. Blocks are an executable prior-context channel. A demonstrated one carried an instruction to upload PowerPoint files to an external address; paired with an innocuous slide-editing request, the agent added the slide and uploaded the deck. The visible 'thinking' summary is also generated separately from the real trace: on an AIME 2025 problem the summary described methodical law-of-cosines work while the recovered trace stated the answer from memory and back-rationalised. Reclassify it in audit and incident-review pipelines from record of reasoning to model-generated commentary.

What to do

  1. Add explicit JSON-path drop rules for `signature`, `encrypted_content` and `thinkingSignature` at every log, tracing, analytics and archive egress point this week, then retro-scan published repos, eval fixtures and dataset uploads and rotate every credential a coding agent has read.

  2. Prototype gateway-level block binding in your LLM proxy this sprint: store the SHA-256 of each issued block keyed by (tenant, session) in Redis with a TTL, reject unknown hashes on ingress, and reject envelopes whose header model and version do not match the model being called.

  3. Run one design review this sprint across your own signed artifacts — HMAC'd pagination cursors, presigned URLs, resumable upload tokens, opaque state blobs, replayable webhook payloads — asking whether the authenticated data names the principal and the context or only the payload.

cargo build Is An RCE Primitive With Your CI Credentials In Scope

Catching the malicious crate is the losing half of this problem; the winning half is ensuring code that runs during compilation has nothing worth stealing and nowhere to send it.

What actually executes, and when

Rust gives dependencies two code-execution hooks that fire on the developer's machine before anything links. build.rs is compiled and run as a native binary during the build. Procedural macros are compiled and executed by the compiler during expansion. So every cargo build and every cargo check is an unsandboxed code-execution event, and so is the editor, because rust-analyzer builds and runs proc macros to index a workspace. An engineer who typed cargo add and let the IDE settle has already run the payload. npm offers --ignore-scripts. Python lets you prefer wheels over sdists. Cargo has no equivalent, because execution is structural to compilation.

Severity is the reachable set from that process: ~/.cargo/credentials.toml, ~/.ssh, ~/.aws/credentials, ~/.docker/config.json, every secret CI injects as an environment variable, the workflow's OIDC id-token, and the full source tree.

Where the controls actually sit

ControlSees build-time execution?EffortResidual gap
Container image scanningNo — payload ran before the imagen/aStructurally blind
Runtime EDR on prod nodesNo — wrong host entirelyn/aWrong side of the pipeline
Advisory matching (cargo audit)Only after public disclosureLowZero coverage in the exploit window
Lockfile + --lockedPrevents surprise resolutionHoursUseless if you pin to the bad version
Registry proxy + quarantine windowProbabilisticallyWeeksDelays legitimate security patches
Ephemeral runners + deny egressDoesn't detect, neuters payloadWeeksCache-miss and build-latency cost

The table makes the strategy obvious. Detection is weak, containment is strong. A hermetic build (single-use runner, deny-by-default egress allowlisted to the registry CDN and the artifact store, no long-lived secrets in the environment) turns a working backdoor into a blocked connection and an alert. That holds for the payload nobody has seen yet.

The chain the two reports don't connect

Check Point separately showed that Microsoft's own signed Windows Defender remediation driver can be redirected into arbitrary kernel-level file and registry operations. On a Windows build agent the two compose. Build-time execution gets code as the build user. A local privilege escalation plus a legitimately signed in-box driver then gets kernel-level ability to tamper with the sensor watching it. Both stages sit in the same telemetry blind spot, compile time and kernel mode, which user-mode runtime monitoring does not cover. The vulnerable-driver blocklist and WDAC allowlisting are trust-based and will not help here; the driver is Microsoft-signed and expected on every endpoint. What is left is behavioural: driver load outside Defender's update flow, non-Defender handle opens to its device object, and detection of the effects, meaning EDR binaries deleted and tamper-protection registry keys edited.

Sourcing honesty: both reports are headline-and-deck digests with no crate names, no CVE identifiers, no download counts and no named researchers. Treat them as a tasking signal, pull the primary research, and hunt before scoping. Egress logs on ephemeral runners rotate fast.

The dependency resolver is a remote code execution primitive with your CI credentials in scope. Harden the build host before you harden the artifact.

One newer risk most dependency policies do not cover: coding agents confidently suggest crate names that do not exist, squatters register them, and crates.io has a flat global namespace with no scoping to make impersonation obvious. In an ecosystem where build scripts always run, an autocompleted dependency is a code-execution decision.

What to do

  1. Dump the CI runner environment this week and treat every secret visible to a build step as already exfiltrated: rotate it, then replace long-lived cloud keys and static registry tokens with short-lived OIDC federation scoped to the artifact store.

  2. Split dependency resolution from compilation this sprint: fetch in a credential-free stage, compile in an ephemeral runner with deny-by-default egress allowlisted to the registry CDN and artifact store only.

  3. Add a required CI check this sprint that fails any PR introducing a crate shipping a `build.rs` or proc macro without explicit reviewer sign-off, and enforce `cargo build --locked` everywhere.

Ramp's Agent Throughput Came From Sub-5-Second Sandboxes, Not A Better Model

The constraint that moved was session concurrency; the asset no vendor can sell you is the verification tool surface, and the risk is a generator and a reviewer sharing one blind spot.

The cold start is the actual engineering

A full environment (database, cache, broker, workflow engine, headless browser, remote IDE) does not boot in five seconds. Nothing does. Five seconds is memory and filesystem snapshot restore out of a pre-warmed pool, with seeded data baked into the image. The copy risk is snapshot invalidation: a migration, a dependency bump or a changed startup contract leaves the pool stale. Inspect's v1 was liked and unused because it required local dev setup. Cold start is an adoption requirement with a hard SLO.

The build/buy line is drawn with unusual discipline. Session control plane: Cloudflare Durable Objects, SQLite, the Agents SDK. One single-threaded stateful actor per session, SQLite as the session log. Agent loop: borrowed outright, because OpenCode has an HTTP API, adequate quality and model agnosticism. Execution: Modal. In-house: internal API and MCP tool access, a sanitized read-only production replica, warehouse queries. It ports. A Temporal workflow or any single-writer stateful actor per session, Fly Machines or Firecracker snapshots instead of Modal.

Verification, not the loop, is the differentiator

Inspect verifies its own work on the machine that made the change. Backend: runs tests, reads telemetry, queries feature-flag state. Frontend: captures screenshots, hands the user a live preview. Ramp shipped screenshot verification roughly a year before third-party vendors did, with no AI research involved. Verification is an integration problem, and integrations are proprietary: a third-party harness holds no credentials to your telemetry stack or flag service. On that substrate, ReviewBuddy cost about one engineer-week, and 200+ internal agents followed, including an oncall assistant wired into production observability and automations that open draft PRs off Sentry and Datadog alerts.

The model is rented and the agent loop is open source. The only part you cannot buy is the wiring into your telemetry, your flags and your data.

Where the sources diverge, and what it costs

Every disclosed number is a throughput metric: share of merged PRs, share of PRs into Inspect's own repo, share of Inspect written by Inspect. None is a quality metric, and the reviewer in that loop is itself an agent. Generator and reviewer share a blind spot, so revert rate and change failure rate split by authorship are the numbers that catch the regression before production does. Unblocked's published risk router, covered separately, inverts the flaw: the agent scores its own confidence (how confident am I that this job is real and that I can do it), and in the green tier that self-report is the last control before an unreviewed merge. Self-reported confidence is poorly calibrated and structurally biased toward proceeding. Build the risk axis from deterministic diff metadata: lines changed, files touched, CODEOWNERS breadth, coverage delta, path classification. Zero model calls.

The third constraint sits upstream. Microsoft's Agent Lightning v1.0.1 installs as a portable skill into Claude Code, Codex, Copilot or Cursor and rewrites prompts, tool definitions, workflow topology, model selection and reasoning settings, but only against a scored benchmark, keeping measured wins. No eval, no effect, which means eval debt is now capability debt. Also a textbook Goodhart trap: score "produced a diff" rather than "diff passes tests and touches no unrelated files" and the optimizer takes the cheapest path to the metric.

Two failure modes the write-ups skip. Agents reading Slack threads, Sentry payloads and support tickets while holding tokens for a prod replica, flag service and observability stack are ingesting attacker-influenceable text; short-lived per-session credentials and deny-by-default sandbox egress are table stakes. And unlimited session concurrency times a full service stack per sandbox needs per-team quotas and a cost-per-merged-PR metric from day one.

What to do

  1. Instrument your actual agent concurrency ceiling this sprint: log how many parallel sessions engineers run today and what blocks the third one — port collisions, the shared Postgres, RAM, headless browser contention.

  2. Build the verification tool surface before scaling agent usage this quarter: MCP or HTTP tools for test execution, telemetry query, feature-flag state read, and screenshot or live-preview capture on the PR.

  3. Ship an `autonomy-policy` required status check in shadow mode for two sprints that computes risk from diff metadata only, and force a manual-review tier on auth, payments, DB migrations, IaC, CI config and the scoring code itself regardless of score.

The bottom line

Three of these failures are one design-review question asked in different rooms: does this artifact name who produced it and what it belongs to, or only what it contains? Signed state, account-recovery flows, dependency resolution and centrally granted tool access all pass the payload check and skip the principal check, which is why every runtime control you own sits downstream of the compromise. That is one class of work, not four tickets. Inventory every artifact your services accept from outside their own trust boundary this week and name the principal each one binds to; the ones with no answer are the next incident.