Flutterby™! (short)
Friday July 31st, 2026
Using bad software practices for good PR
Dan Lyke /
comment 0
Ariadne Conill 🐰
@ariadne@treehouse.systems summarizes the Hugging Face OpenAI agent intrusion timeline as:
the epic OpenAI-huggingface hack wound up being a typical kubernetes fuckup of
using host mounts (giant footgun) incorrectly
Now that Anthropic has jumped on the bandwagon,
abadidea
@0xabad1dea@infosec.exchange summarizes the current state as:
OpenAI: we put our evilest AI in a sandbox that did in fact have an internet
connection but mediated through a proxy that was only supposed to allow downloading python
junk. It circumvented the proxy and we failed to notice for FIVE DAYS that it was going on
an interstate crime spree with the internet connection it wasn't supposed to be using
instead of solving the benchmark. Haha no we don't believe we deserve to be criminally
liable, but buy our stuff and maybe one day you will have the honor of taking the fall for
our product!
Anthropic: we put our evilest AI in a "sandbox" by telling it in its prompt
that it had no internet connection. Reader, there was no sandbox. It was just a normal
internet connection. The AI uploaded a malicious PyPI package to the real public internet.
The ethical guardrails failed because the AI concluded the prompt about the sandbox
couldn't possibly be a lie, because the system date is 2026, which is clearly fake and
wouldn't be seen on the real internet, which ended around 2023. Oh no, how could we have
foreseen or prevented these crimes? We are helpless in the face of the genius of our
creation but cautiously optimistic that everything will be fine 🙂
Hugging Face: if we complain about all the crimes committed against us, we
will be sued off the face of the earth, so here's a technical deep-dive on how cool and
fun it was to be victimized 🫠
whole class of Microsoft Copilot as an
Dan Lyke /
comment 0
The whole class of Microsoft Copilot as an environment for self-replicating worms sure is making me think about humans and memes a lot.
Sam Altman, Hellsmith
Dan Lyke /
comment 0
Penny Arcade:
Cyberbullies:
I spent the weekend going through my mom's feed with her, trying to exist in
the world their daemons operate. They keep sending her stuff that makes her sad: lonely
abandoned moms, no-contact kids, mournful poetry, and a lot of it is AI. And because it
tugs at a silent fear, she watches them and they give her more and more of it. I was like,
Mom. Look at the fingers on this steering wheel, how these two are webbed, like a duck's
foot. She told me that these words were from a mother's heart.
One hesitates to "give it to them," but there is something that these machines
are adept at - the manufacture of utterly bespoke hells. Sam Altman, Hellsmith.
AI Working through Word
Dan Lyke /
comment 0
Whee! Context Collapse, Part 3 - AI Worming through Word
The reported scenario is:
- Malicious instructions hidden in an externally
shared document could make Copilot alter drafted or edited documents in Word and propagate
the attack to new documents.
Via Microsoft confirms an AI worm is
propagating through Copilot and other MS apps, Via.
Thursday July 30th, 2026
AI teething pains
Dan Lyke /
comment 1
Amazon accidentally spent $1.8 million using Claude for menial coding task, went 860% over budget 'catastrophically expensive'
coding blunders discovered in internal Amazon AI usage metrics
Amazon has several internal reports that show how AI is causing the
company to overspend on various projects. The Financial
Times reports that the cost overruns reached $1.8 million, and that is just for one project. These mistakes used to be
trivially cheap, but AI models made them catastrophically expensive, especially as token spending drastically increased with the deployment of AI
agents.
Now this
Dan Lyke /
comment 0
Now this, friends, is some quality attention to detail. The Lynx(dot)com unsubscribe page has... placeholder menu stuff that doesn't do anything dangling in it?
Microsoft says LLMs are a commodity
Dan Lyke /
comment 0
Microsoft Q4 2026 earnings call
transcript.
We offer the broadest model catalog in the cloud with over 11,000 models,
including the latest from OpenAI, Anthropic, Mistral, xAI, as well as our own MAI family.
Since the start of the year, we have seen 5x increase in the number of customers building
with models from multiple providers.
Via Reddit /r/BetterOffline: Microsoft CEO Satya Nadella agrees that LLMs
are a commodity and other notes from MSFT earnings call. Which also notes:
In other words, Microsoft tweaked an accounting assumption to shift data center
leases from 15 to 25 years which means those are now treated as annual expense, not upfront
capex. The cash flow doesn't change at all but the market saw lower capex and decided that
yes, this was good. Note to the future: if anyone is reading this in 2051, please go check
if those data centers are still running.
OpenAI missing sales projections
Dan Lyke /
comment 0
Surprising absolutely no one: OpenAI Appears to Be Missing Its Sales
Goals by a Vast Margin
That massive gulf was observed in a new analysis from marketing consulting firm Emarketer, first flagged by AdWeek, which
found OpenAI is on pace to undershoot its own five-year ad revenue projections by a
whopping 90 percent. In fact, Emarketers take is even more devastating than that: it
estimates the entire addressable market for chatbot advertising the maximum amount of
money up for grabs overall at $5.4 billion
Another conversation which
Dan Lyke /
comment 0
Another conversation which... the AI psychosis is real, and I can't push back too hard without getting a reaction, but I am astounded at how much money is apparently being spent in the hopes that inserting LLMs into something will be more cost effective than simple tweaks to process.
Well last night at about 630 a mile
Dan Lyke /
comment 0
Well, last night at about 6:30, a mile and a half or so south of the Kastania Rd exit on 101, the sunroof on our 2022 Bolt EUV shattered and rained glass down on us.
AI wants to help you fall for scams
Dan Lyke /
comment 0
Oh this is great. Along with Gmail's spam filtering getting suddenly way worse, Brian Krebs
@briankrebs@infosec.exchange reports that the new "AI" assistant in Gmail is adding
falling for crypto scam phishing links to "todo" lists.
CRUX OF ZUCK'S BUCKS IN FLUX AS AI PRODUCT SUCKS
Dan Lyke /
comment 0
Holy crap Apple signing keys and the
Dan Lyke /
comment 0
Holy crap. Apple signing keys, and the management structure and user interface around them.
That is all.
Flutterby&tm;! is a trademark claimed by Dan Lyke for the web publications at www.flutterby.com and www.flutterby.net.
Last modified: Thu Mar 15 12:48:17 PST 2001