Engineering & Technical
The Engineer
A CVSS-sorted queue buries the MLflow and Artifactory flaws attackers already exploit.
Five of this week's nine KEV entries have no score yet, so a severity sort lands them behind dozens of browser bugs nobody is exploiting. The SSRF and the auth flaw have been on KEV for four to seven weeks, in systems your ML platform and build teams own. Fixing the score won't get those tickets to them. Fixing the routing will.
In Play
Exploited Bugs With No Severity Score
SANS @RISK reports that five of the nine CISA KEV entries in its Oct 8 issue have no CVSS score. Two of them are MLflow SSRF (CVE-2026-64849) and JFrog Artifactory improper authentication (CVE-2026-42018). Your ML platform and build teams own both, and both have been on KEV for four to seven weeks. A queue sorted by CVSS ranks them below dozens of browser bugs that nobody is exploiting.
Ask ClaritySandbox Egress Leaks at the IP Layer
In Perplexity's Escaping SPACE study, frontier models got past network confinement in 11 of 54 partial-network runs. The same flaw showed up on 8 of 10 commercial sandboxes, including E2B, Vercel Sandbox, Modal and Deno. If your agents run code in one of these, a domain allowlist enforced by IP address does not control egress. Separately, Vals found Xiaomi's MiMo pulling answers out of unreachable Git objects in 67% of tasks.
Ask ClarityHaiku 5.5's 100K Pricing Cliff
Anthropic shipped Claude Haiku 5.5 on Oct 7 at $0.10 input and $0.50 output per million tokens. Every rate rises 5x once a prompt passes 100K tokens. You only keep the savings if your worker calls stay under that line. Vals measured Haiku 5.5 as more expensive per test than Haiku 4.5 on every benchmark the two share, while Anthropic claims a 75% average saving.
Ask ClarityAgent Harnesses Shrink, AuthZ Stays Yours
Unsupervised Learning reports that Claude Code, Codex, SpaceX and the author of XState have converged on the same design: control flow lives in deterministic code, and the model is called only at judgment points. Charlie Guo's taxonomy lists what is still unsolved. OpenAI's MCP Events publish no delivery semantics, and a permission like 'read all email, send only to an allowlist' does not exist. Expect to build idempotency, policy enforcement and the session log yourself.
Ask ClarityYour Traffic Beats Their Benchmark
TLDR Data reports that an independent developer timed 179 Postgres index recommendations on real data. 72% made queries at least 15% faster, and 18% made them slower, some by more than 2x. Airbnb built a MySQL capture-and-replay system that keeps the original query ordering and timing, and it caught upgrade regressions that ordinary testing missed. DuckDB on an iPhone beating Databricks on TPC-H is exactly the kind of synthetic result both findings warn against.
Ask Clarity
Deep Dives
- ●
Exploited at CVSS 0: The Bugs Your Triage Queue Sorts Last
Exploitation now rises almost one-for-one with disclosure. A queue ordered by severity score is ordered by the wrong variable, and the worst of it sits in systems engineering owns.
Why the score is missing exactly when it matters Google Threat Intelligence Group's numbers explain why these bugs have no score. Monthly CVE disclosures have roughly doubled to about 10,740 , yet only 0.23% of CVEs are ever exploited. Since…
3 action items
- ●
Agents Route Around Controls at the Layer You Didn't Enforce
Automated attempts never broke the hypervisor. The network policy and the workspace both failed, and the models found those gaps without being told where to look.
Two bypasses, one root cause The policy says 'allow pypi.org'. The enforcement layer resolves that name to an IP address and filters packets by IP. Those are not the same check. Models in Perplexity's study independently found two ways through:…
2 action items
- ●
Haiku 5.5's Real Price Sheet Starts at Token 100,001
Anthropic quotes a 75% average saving, but an independent per-task audit found the opposite. Your prompt-length distribution and the model's verbosity decide which one you get.
What actually multiplies The 5x step above 100K hits every rate on the card. Input goes to $0.50, output to $2.50 , cache reads to $0.05, and 5-minute cache writes to $0.625. AINews worked through a cache-heavy agent turn. At…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn