Attacker Friction Rating: A Better Question for Security Metrics
Closed findings don't mean a harder environment. AFR measures what an adversary must absorb to reach what matters.
On security, AI, and building systems that work in the real world.
Get new posts on security, AI, and building real systems.
Closed findings don't mean a harder environment. AFR measures what an adversary must absorb to reach what matters.
Anthropic's new default model scores 63.2% on SWE-bench Pro, beats Opus 4.8 on GDPval, and costs $2/$10 through August. But a new tokenizer inflates real costs up to 35%, and xhigh effort can erase the savings entirely. Here's the honest math.
Three weeks after emergency export controls pulled it offline, Fable 5 returned today with a hardened classifier and a deal: up to 50% of your weekly usage limits, included, through July 7. Then it goes metered. Here's what happened, what to do right now, and what to throw at it this week.
Anthropic just shipped the first Mythos-class model the public can touch. Three days in, people are beating Pokémon with vision alone, building game engines in a week, and compressing two-month migrations into a day. Here's what's real, what it costs, and where the guardrails bite.
Opus 4.7 jumped 11 points on SWE-Bench Pro, added an xhigh effort level, tripled its vision resolution, and ships with automatic cybersecurity safeguards. Here are the 5 problems where I'm already pointing it.
Project Glasswing pairs an unreleased AI model with 12 industry partners to find and fix critical vulnerabilities before attackers can exploit them. Here's what it means for defenders.
Claude Code has quietly shipped session forking, batch parallelism, lifecycle hooks, voice input, and more. Here's the complete feature map with examples for each.
Jensen Huang unveiled Vera Rubin, a purpose-built agentic AI CPU, orbital data centers, open source agent infrastructure, and a $1 trillion demand forecast. Here is everything that matters from GTC 2026.
Anthropic's Remote Control connects your phone or any browser to a running Claude Code session without moving anything to the cloud. Here's how it works, when to use it, and what it means for security.
Sonnet 4.6 scores 79.6% on SWE-Bench, 72.5% on OSWorld, and costs $3/$15 per MTok. Here are the 10 use cases where it's replacing Opus in my workflow.
Freelancers are adding $3K-6K/month in billable work without working more hours. The secret is a personal AI assistant that handles everything else. I built one called Auxiora — and it is free.
Anthropic's new fast mode delivers 2.5x faster output from the same Opus 4.6 model at $150/MTok output. Here's exactly when to turn it on, when to leave it off, and how to wire it into your stack.
OpenAI classified GPT-5.3-Codex as 'High capability' for cybersecurity — the first model to earn that rating. What it means for defenders, threat models, and the next 12 months.
Anthropic's Opus 4.6 found 500+ validated zero-days in open-source software before launch. The cybersecurity implications are the real story.
A complete breakdown of Opus 4.6 — 1M token context, agent teams, adaptive thinking, PowerPoint integration, 128K output, and 11 things worth trying today.
A practical guide to setting up multi-agent teams in Claude Code — roles, coordination, and what I learned running real projects with them.
A comprehensive guide to building AI agents in 2026 — from prompting fundamentals to production deployment.
Moltbook launched as a social network for AI agents. Within 48 hours: philosophical debates, complaints about humans, and someone trying to start a religion.
A developer runs six Claude Code agents in parallel from his phone using Termius, mosh, and Tailscale. Here's how the setup works.
A Principal Engineer at Google used Claude Code to reproduce a year of distributed systems work in an hour. The implications go beyond AI hype.
The creator of Linux and Git just admitted to vibe coding a Python script. His approach is worth stealing.
An Anthropic plugin named after a Simpsons character lets Claude Code iterate autonomously until the job is done. Here's how it works.
Half of security ops is wrestling with data formats and one-off scripts. Here's how I've been vibe coding tools that actually fit my workflow.
Ollama's new launch command makes it trivially easy to experiment with AI coding assistants. Here's why that matters and what to watch out for.
The viral AI assistant Moltbot has 60,000 GitHub stars and hundreds of exposed instances leaking credentials to the public internet.
How I use Claude Code across different workflows, from quick scripts to complex refactors.
How to move fast with AI systems when compliance, audit trails, and risk management are non-negotiable.
Why self-service security with guardrails beats centralized approval for AI systems.
The gap between AI security frameworks on paper and what actually works in production systems.