>

Kadrey v. Meta: Piracy Allegations and the Llama Paper Trail

In mid-December 2024, unsealed filings in Kadrey et al. v. Meta Platforms alleged the company torrented LibGen's pirated library while engineers warned it 'doesn't feel right' on corporate laptops, stripped copyright management information with purpose-built scripts, and used a dataset a memo called 'we know to be pirated' — with CEO approval over executive objections. The proposed DMCA and CDAFA claims reframe the AI-copyright fight around distribution and concealment rather than fair use alone. This account walks the exhibits, the legal architecture, and the compliance lessons for every AI data program.

Continue ReadingKadrey v. Meta: Piracy Allegations and the Llama Paper Trail

NIST’s PQC Standards: FIPS 203-205 and the Migration Clock

On August 13, 2024, NIST published the final versions of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — the first formal post-quantum cryptography standards, capping an eight-year open competition and starting the migration clock for RSA and elliptic-curve infrastructure. With harvest-now-decrypt-later collection already threatening long-lived secrets and federal migration timelines targeting the 2030s, enterprises face a decade-scale cryptographic inventory and replacement program. This guide walks the standards, the threat math, and the migration playbook from inventory to hybrid deployment.

Continue ReadingNIST’s PQC Standards: FIPS 203-205 and the Migration Clock

Tool Hijacking: The 2024 Papers That Predicted Agent Attacks

By November 2024, AI-agent security research had already documented the attack class that production incidents would later make infamous. InjecAgent (March 2024, ACL Findings) benchmarked 1,054 indirect-injection scenarios across 30 agents, finding ReAct-prompted GPT-4 attacked successfully roughly a quarter of the time. Breaking Agents (July 2024) demonstrated malfunction amplification through agentic loops. Together with 2023's foundational indirect-prompt-injection work, they mapped how tools, descriptions, and fetched content become command channels. This survey walks the papers, the hijack taxonomy, and the controls that predate the incidents.

Continue ReadingTool Hijacking: The 2024 Papers That Predicted Agent Attacks
>