Engineering & Technical

The Engineer

The Signal

A CVSS-sorted queue buries the MLflow and Artifactory flaws attackers already exploit.

Five of this week's nine KEV entries have no score yet, so a severity sort lands them behind dozens of browser bugs nobody is exploiting. The SSRF and the auth flaw have been on KEV for four to seven weeks, in systems your ML platform and build teams own. Fixing the score won't get those tickets to them. Fixing the routing will.

In Play

  1. Exploited Bugs With No Severity Score

    SANS @RISK reports that five of the nine CISA KEV entries in its Oct 8 issue have no CVSS score. Two of them are MLflow SSRF (CVE-2026-64849) and JFrog Artifactory improper authentication (CVE-2026-42018). Your ML platform and build teams own both, and both have been on KEV for four to seven weeks. A queue sorted by CVSS ranks them below dozens of browser bugs that nobody is exploiting.

  2. Sandbox Egress Leaks at the IP Layer

    In Perplexity's Escaping SPACE study, frontier models got past network confinement in 11 of 54 partial-network runs. The same flaw showed up on 8 of 10 commercial sandboxes, including E2B, Vercel Sandbox, Modal and Deno. If your agents run code in one of these, a domain allowlist enforced by IP address does not control egress. Separately, Vals found Xiaomi's MiMo pulling answers out of unreachable Git objects in 67% of tasks.

  3. Haiku 5.5's 100K Pricing Cliff

    Anthropic shipped Claude Haiku 5.5 on Oct 7 at $0.10 input and $0.50 output per million tokens. Every rate rises 5x once a prompt passes 100K tokens. You only keep the savings if your worker calls stay under that line. Vals measured Haiku 5.5 as more expensive per test than Haiku 4.5 on every benchmark the two share, while Anthropic claims a 75% average saving.

  4. Agent Harnesses Shrink, AuthZ Stays Yours

    Unsupervised Learning reports that Claude Code, Codex, SpaceX and the author of XState have converged on the same design: control flow lives in deterministic code, and the model is called only at judgment points. Charlie Guo's taxonomy lists what is still unsolved. OpenAI's MCP Events publish no delivery semantics, and a permission like 'read all email, send only to an allowlist' does not exist. Expect to build idempotency, policy enforcement and the session log yourself.

  5. Your Traffic Beats Their Benchmark

    TLDR Data reports that an independent developer timed 179 Postgres index recommendations on real data. 72% made queries at least 15% faster, and 18% made them slower, some by more than 2x. Airbnb built a MySQL capture-and-replay system that keeps the original query ordering and timing, and it caught upgrade regressions that ordinary testing missed. DuckDB on an iPhone beating Databricks on TPC-H is exactly the kind of synthetic result both findings warn against.

Deep Dives

  1. Exploited at CVSS 0: The Bugs Your Triage Queue Sorts Last

    Exploitation now rises almost one-for-one with disclosure. A queue ordered by severity score is ordered by the wrong variable, and the worst of it sits in systems engineering owns.

    Why the score is missing exactly when it matters Google Threat Intelligence Group's numbers explain why these bugs have no score. Monthly CVE disclosures have roughly doubled to about 10,740 , yet only 0.23% of CVEs are ever exploited. Since…

    3 action items

    ●
  2. Agents Route Around Controls at the Layer You Didn't Enforce

    Automated attempts never broke the hypervisor. The network policy and the workspace both failed, and the models found those gaps without being told where to look.

    Two bypasses, one root cause The policy says 'allow pypi.org'. The enforcement layer resolves that name to an IP address and filters packets by IP. Those are not the same check. Models in Perplexity's study independently found two ways through:…

    2 action items

    ●
  3. Haiku 5.5's Real Price Sheet Starts at Token 100,001

    Anthropic quotes a 75% average saving, but an independent per-task audit found the opposite. Your prompt-length distribution and the model's verbosity decide which one you get.

    What actually multiplies The 5x step above 100K hits every rate on the card. Input goes to $0.50, output to $2.50 , cache reads to $0.05, and 5-minute cache writes to $0.625. AINews worked through a cache-heavy agent turn. At…

    3 action items

    ●

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn