3/4 Root cause: a silent 32-bit integer overflow inside a vLLM CUDA kernel for Mamba-1 selective scan forward kernel. cache_index * ssm_states_batch_stride overflowed once cache slots got large enough, corrupting writes with no crash and no warning.
SAFETY
-

Discovery of a logprob anomaly during Jamba training
By
–
1/4 We hit a strange logprob mismatch while training Jamba 3B with GRPO. Rollout logprobs and training-side recompute should match before any weight update. Ours didn't. That was the canary. 🧵 [Translated from EN to English]
-

OpenAI Shelves Adult Chatbot Plans Over Safety Concerns
By
–
OpenAI has indefinitely shelved its planned "adult mode" erotic chatbot amid pushback from staff and investors over risks to minors and concerns about encouraging unhealthy emotional attachments to AI. The decision is part of a broader refocusing away from "side quests" toward
-

Fine-tuning Gemini 2.5 made it worse
By
–
HOLY SHIT… Google AI just proved that fine-tuning Gemini 2.5 made it dumber on hard queries. > Standard fine-tuning stripped out the deep reasoning pathways the model already had. Replaced them with shallow pattern matching. The fine-tuned version scored lower than the base
-
Technology whistleblowing incentives and potential victim scale
By
–
Je pense que personne ne réalise la quantité de victimes que ça pourrait concerner sur une carrière entière, ça va se jouer sur le gain potentiel que ça pourrait apporter à celles qui vont parler. C'est un coup de poker.
-
Agent Accountability: Governance, Identity, and Auditability Requirements
By
–
Great point, @Jetsonhacks , accountability doesn’t disappear with agents, it shifts to the person or organization deploying them. That’s exactly why governance, identity, and auditability need to be built in from the start, especially in regulated environments where privacy and
-

MCP Security: Avoid Local Servers, Run Remote Containers
By
–
PSA: Stop running local MCP servers. The folks at futuresearch were pwned when a local MCP server pulled in an impacted package. Always run your MCP servers remotely. The blast radius should be limited to the container that it runs in. If you're impacted by the LiteLLM
-

MCP Server Security: Avoid Local Deployment After LiteLLM Breach
By
–
PSA: Stop running local MCP servers. The folks at futuresearch were pwned when a local MCP server pulled in an impacted package. Always run your MCP servers remotely. The blast radius should be limited to the container that it runs in. If you're impacted by the LiteLLM
-

MCP Server Security: Avoid Local Deployment Risks
By
–
PSA: Stop running local MCP servers. The folks at futuresearch were pwned when a local MCP server pulled in an impacted package. Always run your MCP servers remotely. The blast radius should be limited to the container that it runs in. If you're impacted by the LiteLLM
-

MCP Server Security: Avoid Local Deployment Risks
By
–
PSA: Stop running local MCP servers. The folks at futuresearch were pwned when a local MCP server pulled in an impacted package. Always run your MCP servers remotely. The blast radius should be limited to the container that it runs in. If you're impacted by the LiteLLM
