On Thursday, CISA added CVE-2025-53521 to its Known Exploited Vulnerabilities catalog, giving federal agencies until March 30 to patch a critical remote code execution flaw in F5’s BIG-IP Access Policy Manager. The vulnerability carries a CVSS v4 score of 9.3 and affects BIG-IP APM versions 15.1 through 17.5, a range that covers years of deployed infrastructure across government and enterprise networks. CISA does not add vulnerabilities to the KEV catalog casually. Active exploitation was confirmed.

But the patch deadline is not the story. The timeline leading up to it is.

In October 2025, F5 confirmed that a “highly sophisticated nation-state threat actor” had breached its network and accessed BIG-IP source code along with information about undisclosed vulnerabilities. The attackers, attributed to China by multiple security researchers, maintained access to F5’s environment for at least twelve months. They deployed the Brickstorm backdoor on customer systems. They had the architectural blueprints for one of the most widely deployed network security appliances in the federal government, and they had them for over a year before anyone noticed.

When the advisory for CVE-2025-53521 first landed in October 2025, F5 categorized it as a denial-of-service vulnerability with a CVSS score of 8.7. Serious but not existential. The kind of bug that gets patched in the normal cycle. Then in March 2026, F5 reclassified the same vulnerability as full remote code execution, upgrading the CVSS to 9.3 under v4 and 9.8 under v3.1, citing “new information obtained in March 2026.” The advisory did not specify what that new information was.

The inference is difficult to avoid. A nation-state stole the source code. Five months later, a vulnerability in that code was disclosed and underclassified. Five months after that, the same vulnerability gets quietly upgraded to the worst possible classification while CISA confirms it is being actively exploited in the wild. The evidence trail does not require much imagination.

F5 has not explicitly confirmed that the actors who stole the source code are the same ones exploiting CVE-2025-53521. That distinction matters legally but barely matters operationally. If you had twelve months of unrestricted access to the codebase of a network appliance deployed across federal agencies, defense contractors, and Fortune 500 companies, you would not limit yourself to denial of service attacks. The reclassification from DoS to RCE tells you what the attackers likely discovered first and what F5 is only now admitting publicly.

This pattern is becoming disturbingly familiar. The SharePoint CVE that went unpatched for two months while attackers exploited it. The Trivy vulnerability scanner that became the attack vector. The copy-paste RCE pattern that spread across the entire AI inference stack. The consistent thread is that the security infrastructure companies deploy to protect their networks keeps becoming the entry point for the people trying to breach them.

The counter argument

Attribution in cybersecurity is notoriously unreliable, and the connection between the October 2025 source code theft and the March 2026 exploitation is circumstantial. F5 may have reclassified the vulnerability based on independent research, not because the stolen source code was used to develop the exploit. Large software vendors regularly discover that initial severity assessments were too conservative as more analysis is done. The reclassification could simply be the normal process of understanding a complex bug better over time, not evidence of a pre-planted exploit.

The timeline tells a story that F5 has not officially narrated but that the facts make hard to ignore. A nation-state had access to the source code for a network appliance that sits at the perimeter of some of the most sensitive networks on the planet. A vulnerability in that code was initially disclosed as merely disruptive. Months later it was re-scored as fully exploitable for remote code execution. And now CISA is scrambling federal agencies to patch with a deadline that has already passed. Whether or not the source code theft and the active exploitation are officially connected, the operational reality for every organization running BIG-IP APM is exactly the same: assume compromise and act accordingly.

What This Means for Everyday People

F5 BIG-IP is not consumer software, but it protects the networks where your personal data lives. Banks, hospitals, government agencies, and major employers all use these appliances to control who gets access to what. When the device designed to be the lock on the front door turns out to have a key that was copied a year ago, every system behind that door is potentially exposed. The patching deadline was yesterday. The question now is how many organizations met it.

Human Security, the cybersecurity firm that processes over one quadrillion web interactions through its Human Defense Platform, released its 2026 State of AI Traffic & Cyberthreat Benchmark Report on Wednesday and the numbers confirm what anyone running a business online has probably suspected for months: the internet is no longer a place built primarily for people.

Automated traffic grew 23.51% year over year, roughly eight times the 3.10% growth rate of human traffic over the same period. AI agent traffic, the kind generated by autonomous systems that can browse, click, scrape, and transact without a person behind them, grew 7,851% in 2025. That is not a typo. Nearly eight thousand percent.

And the concentration is staggering. OpenAI’s bots, which include ChatGPT User, OAI-SearchBot, GPTBot, and ChatGPT Agent, account for approximately 69% of all observed AI traffic by volume. Meta-ExternalAgent adds another 16%. Anthropic’s ClaudeBot and Claude-SearchBot contribute roughly 11%. Three companies generate 96% of the AI traffic hitting your website, your ad campaigns, and your analytics dashboards.

The business problem nobody wants to quantify

If you run Google Ads, you are bidding against bots. If you track website conversions, your funnel includes bot visits. If your SEO strategy relies on organic traffic, a growing share of that traffic is a language model scraping your content to answer someone else’s question in a chatbot window, never sending the human your way.

The entire digital advertising and content marketing ecosystem was built on the assumption that traffic equals attention and attention equals a person with a wallet. That assumption is breaking, and the speed of the break is what should concern anyone running campaigns. This is not a slow drip. AI traffic surged 187% from January to December 2025 alone, which means the gap between what your analytics report and what is actually happening on your site is widening every month.

Google and Meta are both the measurement platforms and two of the three largest sources of AI bot traffic. Google runs the ad auction and crawls your site with its own AI agents simultaneously. Meta runs the ad targeting and sends Meta-ExternalAgent to index your pages. The companies selling you traffic analytics are the same companies generating the non-human traffic that contaminates those analytics. Nobody is explaining how those numbers get separated, because separating them would mean admitting the contamination exists.

The counter argument

Not all bot traffic is bad. AI crawlers that index content for search and retrieval are, in theory, doing the same thing Google’s original spider did in 1998. The Human Security report itself distinguishes between benign automated traffic and malicious bot activity. The 7,851% growth in agentic AI traffic includes legitimate tools like shopping agents and research assistants that may actually convert into revenue. And Human Security has an obvious commercial interest in making bot traffic sound terrifying, because their product exists to detect and block it.

If 23% of internet traffic growth is automated, and that number is accelerating, then the infrastructure businesses built their customer acquisition on is rotting from the inside. Every SEO strategy, every paid media campaign, every conversion rate optimization framework, every attribution model that assumes traffic equals humans, all of it needs to be stress tested against a simple question: what percentage of the activity I am measuring and paying for is actually a person. The companies best positioned to answer that question are the same ones generating the bot traffic, and they have no incentive to give you an honest number.

What This Means for Everyday People

If you have ever wondered why the internet feels different now, why search results seem less useful, why ads follow you with eerie precision but the products are wrong, why engagement metrics keep climbing while actual sales stay flat, this is part of the answer. The web is increasingly a conversation between machines, with humans as an afterthought in their own digital spaces. The botnet takedowns make headlines, but the legal bot traffic reshaping the entire internet economy barely gets mentioned.

The companies responsible for building AI systems that generate this traffic are the same ones asking for regulatory protection, arguing they need special treatment because their technology is too important to constrain. They are simultaneously the architects of the problem and the ones selling the solution.

There is a LinkedIn video from March 19 that shows Nate Sesti, the founder of Continue.dev, running 30 AI coding agents at the same time using an Xbox controller and Wispr Flow, which is a voice dictation tool that lets him issue commands without ever touching a keyboard, and what makes this interesting is not the novelty of using a game controller to write software but the fact that his team records their daily standups, feeds those full transcripts into their agent system, and the agents just start working on whatever was discussed without anyone having to file a ticket or manually assign anything. Sesti says he did a two-week challenge where he refused to open his code editor, and he has not opened it since.

This is not a demo or a conference talk experiment, this is how his company actually ships software every day, and while the conversation around this kind of workflow has been getting louder in Y Combinator communities and among indie developers who are pushing the limits of tools like Claude Code, the reality is that enterprise software development has barely registered any of this yet. That gap between what the bleeding edge is doing and what corporate engineering teams consider normal is real, but given the numbers in Anthropic’s 2026 Agentic Coding Trends Report and the venture capital that keeps flowing into this space, that gap is probably not going to last very long.

The evolution that brought us to this point happened faster than most of the industry expected and it is worth walking through because each wave created the conditions for the next one. The first wave was the AI sidebar, tools like GitHub Copilot and Codeium that bolted a chat panel to the side of your code editor and offered autocomplete suggestions, basically a smarter version of predictive text for programmers that was useful enough to keep around but limited enough that you could ignore it when it got something wrong and keep moving. The second wave was when developers started realizing the AI assistant was actually more useful than the editor itself, which is when products like Cursor and Windsurf expanded the AI interface until it basically replaced the traditional development environment, and you were still writing code but the AI was doing more and more of the actual composition.

The third wave was Claude Code and similar terminal-based agents that took the editor out of the equation entirely, where you describe what you want in plain English and the agent writes the code, runs it, hits errors, fixes them, and delivers working output back to you without you ever touching a line of code yourself. One agent handling one task is totally manageable even for teams that are still getting comfortable with AI writing production code, but the problems start when developers do what developers always do with a tool that works, which is scale it, two agents then four then eight then sixteen running in parallel across the same codebase using git worktrees for isolation, each one modifying files on its own timeline, and somewhere around that threshold the bottleneck stops being the code and starts being the developer’s ability to keep track of what all those agents are actually doing.

This is where the current tooling starts to break down and where a handful of developers and companies are trying to build what comes next. Factory.ai is building what they call “agent-native software development,” which is a platform that lets teams script and run AI agents at scale across their entire development pipeline. Steve Yegge, whose commentary on developer tools has shaped how the industry thinks for basically two decades, built a system called Gas Town that orchestrates 20 to 30 parallel agents alongside something called Beads, which is a memory and issue tracking layer designed specifically for AI agents rather than human developers. 1Code out of the YC Winter 2026 batch wraps terminal agents like Claude Code in a desktop interface with parallel worktrees, real-time change tracking, and background execution, and all of this infrastructure is being built in public and in real time right now.

Sesti’s contribution at Continue is particularly worth paying attention to because it goes after the quality problem instead of the scale problem. His team writes what they call check files, which are plain text documents stored right next to the codebase in version control, and each file contains instructions telling an AI agent what to look for when reviewing a batch of code changes. Things like catching AI-generated filler that reads like it was written by a machine, validating that database changes will not break existing data, confirming the interface works on mobile screens, flagging duplicated logic, basically whatever the team has decided actually matters for quality. Those checks run automatically every time someone submits code changes for review and they show up as pass/fail indicators that block the submission from being accepted until every issue is resolved, and if everything passes the checks produce no output at all.

That silent-by-default approach is what separates it from the code review bots that have popped up everywhere over the past two years, which are tools that generate a wall of generic feedback on every single submission whether anyone asked for it or not. Continue’s system only talks when it catches the specific thing someone told it to catch, and over time a team builds up a library of these checks that starts functioning as a kind of institutional memory, the team’s standards and lessons learned encoded as AI-readable prompts, tracked in version control the same way the code itself is, and enforced automatically on every contribution. For anyone who has ever worked on a team where critical knowledge lived in one person’s head and disappeared when they left, that alone is a pretty significant development, and it also has obvious implications for the security of automated development pipelines where the tools developers trust to guard their code have themselves become attack targets.

But checks solve quality at the level of individual code submissions and the larger question that nobody has a solid answer for yet is who actually manages the factory when everything is running at once.

When a team has a dozen or more agents operating in parallel with an orchestrator keeping them from writing conflicting code, something still needs to decide when to stop and take a snapshot of the current state so that humans can meaningfully evaluate where things are before the agents keep iterating. Something needs to recognize that a subset of agents have been producing circular output, rewriting the same file and hitting the same error and making zero forward progress, and kill those tasks before they burn compute and create problems downstream for everything else. Something needs to decide which work is ready to ship, which needs another pass, and which threads should just be abandoned entirely, and Sesti himself describes traditional issue tracking as feeling more like a blocker than a helper in this environment, which tells you that even the basic interfaces between humans and these systems are straining under a workflow they were never designed for.

Right now all of those judgment calls fall on the individual developer, who is making them manually while also trying to do the work that prompted them to spin up agents in the first place, and that is the bottleneck. Not the agents, not the orchestrator, not the code quality gates, but the human being trying to be the foreman of a factory that has no foreman role built into it.

Manufacturing figured this out over a century ago. You do not run a factory floor by adding more machines and hoping quality stays consistent, you put a foreman on the floor, someone whose entire job is not building the product but watching the production line, recognizing when output quality starts drifting before it turns into a batch of defective product, and making the call to stop the line when something is off. The foreman does not replace the workers or the machines, the foreman is the judgment layer that makes sure the factory actually produces something worth shipping, and anyone who has spent time in operations or logistics or industrial management recognizes this role immediately. It is the missing piece in the software factory and nobody has built it yet.

The orchestrators handle coordination. The check systems handle quality gates on individual outputs. But the layer above both of those, the one that watches the entire operation in real time and makes the calls about what to continue, what to checkpoint, what to iterate on, and what to shut down, that layer does not exist in any production-ready form right now. The companies building the current generation of tools know this, and the question is whether the solution comes from within the existing ecosystem or from someone who recognizes that managing a factory is a fundamentally different discipline than building one.

Enterprise has not touched any of this yet which means the terminology is still settling and the tooling is still raw, but the pattern is unmistakable and it is moving from the fringes toward mainstream development faster than the infrastructure can keep up. The piece that is missing is not more agents or better orchestration or smarter quality checks, it is judgment applied at the level of the operation itself.

The factory is running. The foreman position is open.

Next in this series: how markdown check files are becoming the quality control layer for AI-generated code, and what that means for teams that have never version-controlled their standards before.

There is a gas that most people only think about in the context of birthday balloons and funny voices, and right now it is the reason some of the most important factories on earth might have to slow down production in the next few weeks, because nobody built a backup plan for what happens when a third of the world’s supply disappears overnight.

On March 2, QatarGas halted production at Ras Laffan, the world’s largest liquefied natural gas plant, after Iranian drone strikes forced a shutdown, and two days later the company declared force majeure, which is the contractual equivalent of saying we physically cannot deliver what we promised you and there is nothing we can do about it. Then on March 5 and 6, more strikes hit the facility and the damage assessment came back as “extensive,” with repair timelines measured in years rather than months.

Qatar produces roughly 30% of the world’s helium supply, and helium is a byproduct of natural gas processing, which means when the LNG plant goes dark the helium goes with it.

What Helium Does in a Chip Factory

During semiconductor fabrication, helium gets blown over the back of silicon wafers to pull heat away during the etching process, which is the step where transistor structures are carved into the silicon itself. There is no viable substitute for this under current manufacturing processes, and every advanced chip being produced in Asia runs through this step, from the processors in your phone to the GPUs that the entire AI infrastructure boom depends on.

South Korea imports approximately 65% of its helium from Qatar, and Samsung and SK Hynix, two of the three companies on earth that can manufacture advanced memory chips, are both Korean, and neither one would comment on their inventory levels when asked.

Now here is where it gets complicated, because the industry is actively downplaying this. TSMC said it does not “anticipate any significant impact at this time” but will monitor the situation, and the Korea Semiconductor Industry Association said short-term supplies are sufficient and companies are diversifying their supply routes. They might be right. Samsung and SK Hynix likely have several months of helium inventory on hand, based on industry estimates, and if the shortage stays in the range of weeks rather than months, the fabs can ride it out without anyone noticing.

But the math underneath is not as comfortable as the public statements suggest.

The Container Problem

Around 200 specialized helium containers are currently stuck in the Middle East, each one worth roughly $1 million, and these containers can only store helium for 35 to 48 days before internal pressure forces the gas to vent into the atmosphere whether anyone wants it to or not. Some of those containers were filled on or around March 2, which means the earliest ones are approaching their holding limit right now, and when they vent that helium is simply gone.

Helium spot prices have doubled since the crisis started, though spot trading only accounts for about 2% of the total market since most helium moves on long-term contracts. The real pressure comes when those contracts can’t be fulfilled and buyers have to enter the spot market at panic prices, and we are not there yet, but every week that Ras Laffan stays offline brings it closer.

The best-case scenario for partial restart of helium production at Ras Laffan was estimated at six weeks, and that estimate assumed the strikes would stop. They did not.

The Uncomfortable Backup Plan

The United States is the world’s largest helium producer at 81 million cubic meters per year, with 8.5 billion cubic meters in recoverable reserves, and Algeria is another option, but the third major producer is Russia, which has been expanding capacity at the Amur Gas Processing Plant in Siberia. The awkward part of this equation is that if the Qatar shutdown persists and American and Algerian supply cannot fill the gap quickly enough, the semiconductor industry faces a choice between production delays and sourcing from a sanctioned state, and some companies will not wait around for that decision to be made cleanly.

It is also worth noting that the U.S. Bureau of Land Management has been selling off the country’s strategic helium reserve since 2013, which means the backup supply that could cushion a crisis like this has been shrinking for over a decade by design.

Why This Matters Beyond the Supply Chain

The honest assessment is that the chip industry will probably get through this without a dramatic production halt, at least in the short term, because Samsung and SK Hynix have inventory and TSMC sources more diversely. The people running these companies are not asleep and they have seen supply shocks before.

But the structural vulnerability is real and it is not going away. The broader Strait of Hormuz disruption is also threatening aluminum and LNG supply chains that feed the same semiconductor industry, and a third of the global supply of a gas with no substitute in chip manufacturing vanished because of a regional war that shows no sign of ending. The 2021 chip shortage taught the industry to diversify silicon supply chains, and billions of dollars went into building new fabs in new geographies to make sure that never happened again, but nobody applied that lesson to helium, and the fact that we are even having this conversation in 2026 tells you something about how fragile the physical foundation underneath the digital economy actually is.

The containers in the Middle East are venting. The repair timeline at Ras Laffan is years. And the world’s plan for what happens when a gas that nobody thinks about suddenly becomes the bottleneck is, apparently, to hope that it works out. The downfall here if it does not work out is too big for anyone to absorb quietly, and somebody somewhere needs to start treating this like the structural risk it is before the inventory runs out and we find out what happens next.

Google published a new assessment of quantum computing’s threat to encryption this week and the number they put on the table is 2029, which is the year they say organizations need to have completed their migration to post-quantum cryptography if they want to stay ahead of machines that can break the encryption protecting basically everything that moves on the internet right now.

The NSA’s guidance says 2031. The federal government’s official mandate says 2035. Google says sooner.

Somebody is wrong about this, and if it turns out to be the organizations planning around the more comfortable government timeline, then a lot of encrypted data that people assumed was safe is going to be readable by whoever gets to a powerful enough quantum machine first.

The Math That Moved

The original estimates for how hard it would be to break RSA-2048 encryption, which is the standard that protects most of the internet’s secure communications and also underpins the cryptographic security of every major cryptocurrency, were comforting for a long time. A 2012 analysis said you would need roughly a billion precise qubits to do it, and since current quantum computers have a few thousand noisy ones that can barely hold their state long enough to finish a calculation, Q-Day felt like a problem that belonged to someone else’s career.

Google’s updated research says those estimates were too generous. Their analysis now shows that a 2048-bit RSA integer could be factored in less than a week using a quantum computer with one million noisy qubits, not a billion precise ones but one million imperfect ones, and that is a dramatically different number that changes the entire conversation about how much time is actually left.

One million qubits is still far more than anyone has right now. IBM’s roadmap targets 100,000 qubits by 2033, and Google’s own hardware program is aggressive but not there yet. The thing about quantum computing though is that progress has never been linear in this field, it tends to move in sudden jumps where a new error correction method or architecture unlocks capabilities that were not on anyone’s projection spreadsheet the year before.

The Crypto Connection

In February we covered Iceberg Quantum’s claim that their Pinnacle architecture could make RSA-2048 breakable with fewer than 100,000 qubits, which would put the timeline even closer than what Google is suggesting. That claim has not been independently verified and should be treated with appropriate skepticism, but the direction of every revision in the last two years has been the same: the qubit counts keep getting smaller and the timelines keep moving in.

What makes this particularly consequential beyond the usual internet security discussion is that the same RSA and elliptic curve cryptography protecting web traffic is also what secures cryptocurrency wallets, blockchain transaction verification, and the entire mathematical foundation that makes decentralized finance possible. If post-quantum cryptography migration does not happen before capable machines arrive, the exposure is not just corporate data and government communications, it is the entire cryptographic layer that crypto and DeFi are built on, and unlike a bank that can reverse a fraudulent transaction there is no undo button on a blockchain.

Harvest Now, Decrypt Later

The scenario that security researchers talk about most often is not actually Q-Day itself but what is happening right now in the years before it arrives. Nation-states are reportedly collecting encrypted communications today with the plan to store them and decrypt them later once quantum machines are powerful enough, and while this is difficult to confirm with specific public evidence the logic is straightforward enough that multiple intelligence agencies have acknowledged the strategy exists.

Every year that organizations delay their migration to post-quantum cryptography is another year of intercepted data that becomes readable the moment a capable machine comes online, which means that even if Q-Day is 2035 instead of 2029 the data being collected right now is already compromised in every way that matters, it just has a time delay on when someone can open the envelope.

Why Google Might Be Saying This

It is worth being honest about the fact that Google has a commercial interest in accelerating post-quantum cryptography adoption, because they sell cloud infrastructure with PQC capabilities built in and they are developing quantum hardware, so setting an aggressive deadline also happens to create urgency around products and services that Google offers. That does not mean the deadline is wrong, but it is context that belongs in the conversation.

The NIST post-quantum cryptography standards, published as FIPS 203, FIPS 204, and FIPS 205, were finalized in August 2024, with ML-KEM (formerly CRYSTALS-Kyber) for key encapsulation and ML-DSA (formerly CRYSTALS-Dilithium) for digital signatures as the recommended algorithms. The algorithms exist, the implementations exist, and the migration path is documented. What does not exist is urgency at most organizations, many of whom have not even inventoried where they use classical cryptography, let alone started replacing it.

China reportedly expects to have its own post-quantum cryptography standards within three years, which suggests that at least one major global power is taking the shorter timeline seriously enough to build around it. And the U.S. government’s own CNSA 2.0 directive mandates that all new National Security System acquisitions must be post-quantum compliant by January 2027, which is even sooner than Google’s 2029 date, though that requirement only applies to classified government systems rather than the broader economy.

Google’s 2029 date might be aggressive, it might be self-serving, and it might be right all at the same time. The uncomfortable reality for everyone still planning around 2035 is that if Google and the researchers revising these estimates downward are even close to correct, the organizations that waited for the comfortable deadline are the ones who will be explaining to their boards why their encrypted data is now readable by anyone with access to a machine that did not exist when they decided not to worry about it yet.

Anthropic has been testing a new model called Claude Mythos that the company describes as a “step change” in capabilities and “the most capable we’ve built to date,” with significantly better performance in reasoning, coding, and cybersecurity benchmarks compared to anything they have released before, and the reason the world knows about it right now is that Fortune reporter Beatrice Nolan found the details sitting in a publicly accessible data store that Anthropic apparently did not know was open.

The model itself is the bigger story here. According to leaked draft blog posts, Mythos sits in a new tier Anthropic internally calls “Capybara,” which is described as larger and more intelligent than their Opus models, and Opus was until now the most powerful thing they had shipped. The draft materials say Mythos gets “dramatically higher scores on tests of software coding, academic reasoning, and cybersecurity,” and Anthropic’s own assessment describes the model as “currently far ahead of any other AI model in cyber capabilities” and warns it “presages an upcoming wave of models that can exploit vulnerabilities in ways that far outpace the efforts of defenders”, which is Anthropic’s own language about their own model written in their own draft blog post.

That model is currently being tested with a small group of early access customers while Anthropic evaluates its behavior and risks, and the fact that a model this capable exists and is already in limited external testing is genuinely significant for the AI industry regardless of how anyone found out about it.

How the Leak Happened

The approximately 3,000 unpublished assets were linked to Anthropic’s blog content management system, which had a configuration issue where all assets defaulted to public access unless someone explicitly marked them private. Nobody changed the default. The exposed materials included draft blog posts about Mythos, details about an invite-only CEO retreat in the UK featuring Dario Amodei, internal images and PDFs, and employee materials tagged with personal information.

Anthropic attributed it to “human error in the CMS configuration” and emphasized that the materials were “early drafts” not involving “core infrastructure, AI systems, customer data, or security architecture.” They denied that AI tools caused the problem. The market reaction was immediate: cybersecurity stocks dropped on fears about what a model with those capabilities means for the threat environment, and Bitcoin slid alongside software stocks as investors processed the implications of a model that Anthropic itself considers a cybersecurity risk.

To be fair about what this was and what it was not: this was a CMS misconfiguration, not a sophisticated attack, not a zero-day exploit, not a nation-state operation, and CMS misconfigurations are genuinely common across the tech industry, including at companies much larger than Anthropic. Microsoft had its own data exposure issues. Google has had internal document leaks. This kind of operational error happens and framing it as uniquely damning would be overstating the case.

Why It Looks the Way It Looks

That said, the optics here are hard to separate from Anthropic’s very specific and very public positioning as the AI company that takes safety and security more seriously than anyone else. Their Responsible Scaling Policy is their signature document. Their entire competitive identity is built on the premise that they are the careful ones, the company that thinks about consequences before shipping capabilities into the world, and that positioning has real business value because it is part of why governments and enterprises choose to work with them over competitors.

When a company whose entire brand rests on responsible handling of powerful technology leaves 3,000 files in a public database including its own internal assessment that its next model poses “unprecedented cybersecurity risks,” the gap between the brand and the operational reality becomes visible in a way that is difficult to explain away with “human error in the CMS.” Not because the error itself is catastrophic, but because the standard Anthropic has set for itself is higher than what most companies are held to, and they are the ones who set it.

The timing makes it worse. This comes in the middle of Anthropic’s legal fight with the Pentagon where a federal judge recently blocked the government’s attempt to label Anthropic a supply chain risk and ban Claude from government work. Anthropic has been actively arguing in court that it should be trusted with sensitive government infrastructure, and whatever credibility that argument gained from the favorable ruling is now sitting next to a story about a public data store that anyone with basic technical knowledge could have queried.

What Actually Matters Going Forward

The lasting significance of this week is not that Anthropic’s CMS was misconfigured. It is that a model tier above Opus now exists, that Anthropic itself believes it poses unprecedented cybersecurity risks, and that it is already in the hands of early access customers being evaluated for broader release. The capabilities described in the leaked drafts, if they hold up to external benchmarking, represent a meaningful jump in what AI systems can do, particularly in the cybersecurity domain where the implications cut in both directions.

Anthropic responded quickly once notified, the exposed data was blog content rather than model weights or customer data, and the remediation appears to have been straightforward. Those are all reasonable points in their favor. But when you are the company telling the world that your next model is so powerful it poses unprecedented security risks, the minimum expectation is that the document saying so is not sitting in a public database. Not because the mistake is unforgivable, but because the contrast between the message and the execution is exactly the kind of thing that makes people wonder what else might be configured wrong at a company building models it considers dangerous.

Handala, a pro-Iran hacking group linked to Iran’s Ministry of Intelligence and Security (MOIS), breached FBI Director Kash Patel’s personal email account and published photos and documents from his inbox online, including personal photos of Patel taken before he became FBI director, and a person familiar with the matter confirmed to Reuters that the materials appear to be authentic.

The FBI’s official response was carefully worded: “The FBI is aware of malicious actors targeting Director Patel’s personal email information, and we have taken all necessary steps to mitigate potential risks associated with this activity. The information in question is historical in nature and involves no government information.”

That statement deserves to be taken seriously on its own terms before anyone runs with the worst interpretation. If the data is genuinely historical, meaning old personal correspondence and photos from before Patel held his current position, and if there is truly no government information in the breach, then the operational damage may be minimal and the FBI’s characterization could be entirely accurate.

But there is also a version of this where “historical in nature” is doing a lot of diplomatic work, because personal emails from before someone becomes FBI director can still contain contact networks, communication patterns, personal relationships, financial details, and private opinions that become valuable intelligence the moment that person holds one of the most sensitive positions in the U.S. government, and the distinction between “no government information” and “no useful intelligence” is not the same thing.

What Handala Claims vs. What Is Confirmed

This is where it gets important to be precise about what is known and what is not. The Patel email breach has been confirmed by a person familiar with the matter speaking to Reuters, and the FBI acknowledged it in their statement, so that part is solid.

Handala also claimed responsibility for hacks against defense contractors Stryker and Lockheed Martin “in response to the Iran war,” but these are claims from the group itself and have not been independently confirmed or corroborated by the companies or by threat intelligence firms as of this writing. The group’s statement read: “Today, once again, the world witnessed the collapse of America’s so-called security legends…we decided to respond to this ridiculous show in a way that will be remembered forever.”

Western researchers consider Handala to be one of several personas used by Iranian government cyberintelligence units rather than an independent hacktivist collective, and the DOJ’s action to disrupt Iranian cyber operations specifically named the group. That said, the question of whether state-backed attribution makes their claims about Stryker and Lockheed more credible or simply better funded propaganda is relevant context that most of the coverage has not addressed. Hacking a personal Gmail account and hacking into Lockheed Martin’s defense contractor infrastructure are very different levels of capability, and grouping them together under one group’s claims without noting that distinction does the reader a disservice.

The Personal Email Problem

What is not in dispute is that the director of the FBI had his personal email compromised by hackers aligned with a country the United States is actively at war with, and that this happened less than a week after the FBI seized Handala’s domains and announced a $10 million reward for information leading to group members. The sequence matters because the domain seizure and bounty were supposed to be an offensive move and instead Handala responded with a breach of the FBI director’s own email, which is not how deterrence is supposed to work.

Patel himself acknowledged the group’s significance before the breach, telling reporters after the FBI’s domain seizure: “We took down four of their operation’s pillars and we’re not done.” Handala’s response was to breach his personal email. This pattern is not new. During the 2024 presidential campaign, Iranian operatives accessed the Trump campaign and leaked vetting documents for VP pick JD Vance, and the vector was the same: personal accounts that sit outside government security infrastructure. Government email systems on .gov and .mil domains run on managed devices behind multiple authentication layers with continuous monitoring, but personal Gmail accounts rely on whatever password and two-factor setup the individual decided to use, and they sit on personal devices that may or may not have current patches.

The structural vulnerability is that government officials are human beings who use personal email for personal things, and those accounts are governed by individual security decisions rather than institutional security teams, and adversaries know this and target it specifically because it is the softest point of entry into the orbit of powerful people.

What This Actually Tells You

There are two reasonable ways to read this situation. The first is the FBI’s read: the data is old, it is personal, it contains nothing classified or operationally sensitive, and the breach is embarrassing but not damaging. If that is true then the main takeaway is that Iranian hackers got a propaganda win and the practical impact is close to zero.

The second read is that any breach of the FBI director’s personal communications during an active war with the country responsible for the breach is a counterintelligence event regardless of what the emails contain, because the adversary now has a window into the personal life, contacts, and communication habits of the person running domestic intelligence operations for the United States, and even if nothing in the inbox is immediately actionable the information can be stored, analyzed, and deployed when it becomes useful.

The honest answer is probably somewhere between those two reads, and the people best positioned to make that assessment are the ones at the FBI who have actually reviewed what was taken, not the ones speculating from the outside. But what is undeniable is that the optics of the FBI director’s personal email being published online by Iranian hackers during a war with Iran are bad regardless of what the emails say, and the $10 million bounty on Handala members feels less like a deterrent and more like confirmation of how much damage this group has been doing.

David Sacks told Bloomberg on Thursday that he has “used up” his 130 days as a special government employee and is stepping down from his role as the White House’s AI and crypto czar, and instead of leaving government entirely he is moving to co-chair the President’s Council of Advisors on Science and Technology alongside Michael Kratsios, who served as the Chief Technology Officer during Trump’s first term and is not new to this space.

No replacement for the czar position has been named, and based on current reporting none is planned, though Sacks predicted that Congress could pass bipartisan AI legislation within months.

Before running with the obvious “policy vacuum” angle, it is worth understanding the structural reality of what happened here. The 130-day limit on special government employees is a known legal constraint that has existed for decades, and Sacks’ departure was not a resignation, not a firing, and not the result of a policy disagreement. His tenure had an expiration date from the day it started, and everyone involved knew when that clock would run out.

The question that matters is not whether Sacks left but whether anyone planned for what happens after he did.

What Sacks Did and Did Not Accomplish

On the crypto side of his portfolio, Sacks helped advance stablecoin legislation and a digital asset regulatory framework, though key legislation remains in limbo without a clear advocate carrying it forward inside the White House.

On the AI side, the most visible output was the White House AI framework published earlier this month, which proposed preempting state AI regulations while explicitly opposing the creation of a new federal AI regulatory body. Our editorial position when that framework came out was that it read more like a liability shield for tech companies than a governance blueprint, and nothing that has happened since has changed that assessment, but it was at least a document that showed someone in the building was thinking about AI policy.

The 78 Bills That Are Not Waiting

While the federal government has been operating without a dedicated AI regulatory agency, and will now be operating without even a designated policy coordinator, state legislatures have been doing what state legislatures do when Washington leaves a vacuum. As of this month, 78 AI-related bills are alive in 27 states, covering healthcare AI, synthetic media, neurological rights, algorithmic bias, children’s online safety, and employment decision-making.

New York’s AI law takes effect this month. The Take It Down Act’s enforcement provisions kick in during May. California, Illinois, Colorado, and Texas all have active proposals moving through their legislatures at various speeds.

The White House framework attempted to preempt this state-level activity by asserting federal primacy over AI regulation, but a framework without someone to negotiate it through Congress, defend it to regulators, or even explain it consistently to industry stakeholders is just a document on a website. With Sacks gone and no replacement coming, the practical AI regulatory environment in the United States is whatever 27 state legislatures decide it is.

The PCAST Question

Sacks’ new role on PCAST lets him advise on a wider range of technology topics including AI, advanced semiconductors, quantum computing, and nuclear power, alongside council members that include Nvidia’s Jensen Huang, Meta’s Mark Zuckerberg, and Oracle’s Larry Ellison, and his co-chair Kratsios has genuine policy experience from his time as CTO during the first Trump administration. But PCAST is an advisory body that publishes recommendations, it does not write executive orders, coordinate agency action, or serve as the day-to-day point of contact between the AI industry and the White House.

There is an argument to be made that the czar role was always somewhat performative, that real AI policy coordination happens through the Office of Science and Technology Policy and through individual agency actions at Commerce, NIST, and NSF, and that losing a single coordinator does not actually break the system because the system was never built around one person. That argument has some merit and it would be dishonest to ignore it.

But there is a counter to it as well, which is that every previous administration knew the 130-day SGE limit existed and the fact that this administration did not have a succession plan in place, or at least has not announced one, suggests either that they do not think federal AI coordination matters enough to staff continuously or that the structural limitations of the SGE framework make continuity in these roles genuinely difficult to maintain. Neither explanation is a good look but they are very different problems, one is a policy choice and the other is a structural constraint, and the coverage should distinguish between them.

What This Means Right Now

The timing is not great. Anthropic is in federal court over its Pentagon dispute. The EU is actively treating AI as a competition issue. China is deploying AI export controls and expects to have its own post-quantum cryptography standards within three years. SoftBank just borrowed $40 billion to invest in OpenAI. The AI industry is moving at a speed that makes quarterly policy reviews feel like archaeological timescales.

The honest assessment is that the day-to-day impact of not filling the czar role will be hard to notice in the short term, because AI companies are going to keep shipping products and state legislatures are going to keep passing laws regardless of who does or does not sit in that office. But the next time there is an AI incident that requires a coordinated federal response, or an international negotiation that demands someone speak for U.S. AI policy with actual authority, the call is going to go to a desk that nobody occupies, and the 78 state bills marching through 27 legislatures are not going to wait for Washington to figure out who is supposed to be in charge.

Anthropic spent $8 million on a single Super Bowl ad slot in February. No celebrities. No famous faces. No cameos from athletes or influencers or whoever happens to be trending that week. Four satirical spots featuring unknown actors in absurd scenarios where a fictional AI chatbot interrupts honest questions with sponsored garbage. A guy asking for fitness advice gets pitched height-boosting insoles. Someone asking about communicating with their mother gets redirected to a cougar dating site called Golden Encounters.

The tagline: “Ads are coming to AI. But not to Claude.”

It won the Super Clio for best Super Bowl commercial. Claude’s daily active users jumped 11 percent in the week following the game. OpenAI ran three ads during the same broadcast and got a 2.7 percent bump. Google’s Gemini saw 1.4 percent. In paid media terms, Anthropic spent less, ran fewer spots, used no recognizable talent, and generated roughly four times the user growth of its closest competitor.

That’s not an accident. That’s a strategy worth studying.

The conventional playbook for a Super Bowl ad, especially in a category as young as consumer AI, says you go big on recognition. You put a face people already trust next to the product they’ve never tried. Amazon did this with Chris Hemsworth for Alexa+. Perplexity signed Lewis Hamilton. Google has leaned on product demos that feel familiar and safe. The assumption is that people don’t know what AI is yet, so you meet them where they are with someone they already know.

Anthropic threw that out. Their bet was that the audience is already further along than most marketers think. People have used ChatGPT. They’ve tried Gemini. They’ve seen the ads, the hype, the promises. What they haven’t seen is a company in this space willing to make fun of the thing everyone else is doing with a straight face. The humor wasn’t about Claude being smart or powerful or life-changing. It was about what happens when AI gets polluted by the same advertising incentives that already ruined most of the internet. The product pitch was negative space. Claude is the one that doesn’t do this to you.

Mark Ritson, the marketing professor, called it “the first piece of effective brand strategy the AI category has produced.” And then Sam Altman did exactly what any paid media strategist would pray for: he took the bait. Altman posted on X calling the ads “clearly dishonest” and “deceptive.” He said Anthropic “serves an expensive product to rich people.” Scott Galloway, the NYU professor, pointed out what any first-year brand manager knows: the market leader should never acknowledge the challenger’s campaign. Altman’s reaction gave Anthropic millions of dollars in free earned media. Every tech publication covered the beef. The campaign’s reach doubled overnight without Anthropic spending another cent.

What makes this interesting from a paid media perspective isn’t just the creative. It’s the full stack. Before the Super Bowl, Anthropic ran the “Keep Thinking” campaign across Netflix, Hulu, the New York Times, the Wall Street Journal, live sports broadcasts, and out-of-home placements in 12 cities. The featured talent: Anthropic’s own researchers and a group of indie creators who built a viral product called Poetry Camera with Claude and zero coding experience. They ran a pop-up in New York’s West Village that drew 5,000 visitors and 10 million social impressions by giving away free books and coffee in an analog-first space. They signed a multi-year deal with Williams F1 where Claude is the team’s “Official Thinking Partner” and the branding sits on the cars and uniforms.

And here’s the part that should make every marketing director stop scrolling: for 10 months, Anthropic’s entire growth marketing operation was one person. Austin Lau ran paid search, paid social, app store optimization, email, and SEO by himself. He built his own tools using Claude Code, including a Figma plugin for ad creative and a Google Ads copy generator. One marketer, using the product to market the product. The broader brand and comms team has since grown to around 80 people under CCO Sasha de Marigny, but the growth engine was a solo operation for nearly a year.

What Anthropic got right is something a lot of companies miss when they’re deciding how to spend their marketing budget. They read their audience. Claude’s users tend to be developers, researchers, writers, and people who already have opinions about technology. Those people don’t respond to celebrity endorsements. They respond to substance, to humor that respects their intelligence, to a company that seems to understand the same things they’re worried about. The Super Bowl creative worked because it spoke to concerns the audience already had. The F1 deal worked because it associated Claude with precision engineering, not celebrity culture. The pop-up worked because it was genuinely different.

Other companies in this space need to study this. Not to copy it, because copying a strategy that’s built on being the contrarian option defeats the purpose. But to understand the principle underneath it. Your user base will always mean more than whoever is popular at the time. Sometimes celebrities make sense when the fit is natural and the audience is broad. But if you’re building for a technical, skeptical, detail-oriented audience, the last thing you want is a famous face telling them what to think. Anthropic bet that their users were smart enough to get the joke and engaged enough to reward it with their attention. The numbers say they were right.

What This Means for Everyday People

The AI companies are spending hundreds of millions of dollars right now trying to get you to pick their product. The way they spend that money tells you something about how they see you. Some companies think you’ll switch because a celebrity told you to. Anthropic is betting you’ll switch because you care about whether the tool you’re using is trying to help you or trying to sell you something. Whether that distinction holds up as these companies grow and need revenue is a different question. But right now, the company that made fun of advertising just won the biggest advertising event of the year. There’s a lesson in that, and it’s not just about AI.

When a company gets hacked, the first thing security teams reach for is their scanning tools. The software that checks code for vulnerabilities before it goes live. The automated systems that run in the background, quietly making sure nothing dangerous slips through.

A hacking group just turned those exact tools into the attack.

Over the past week, a group calling itself TeamPCP compromised two of the most widely used security scanning tools in the software development ecosystem. First, on March 19, they hijacked Aqua Security’s Trivy scanner, a tool referenced by more than 10,000 projects on GitHub. Then on March 23, they hit Checkmarx’s KICS, another widely trusted security tool. In both cases, the attackers replaced the legitimate code with a three-stage information stealer that quietly harvested passwords, cloud credentials, encryption keys, and access tokens from every company running those tools.

The part that makes this particularly uncomfortable: everything looked normal. The security scans still ran. The dashboards still showed green. The only difference was that before the scan completed, the malware had already copied everything it needed and sent it to the attackers. Mandiant’s CTO Charles Carmakal confirmed that over 1,000 cloud environments have been infected so far.

Here’s how it started. Back in February, a separate breach gave TeamPCP access to credentials belonging to Aqua Security. Aqua responded by resetting some passwords. But not all of them. That gap, one incomplete credential rotation, gave TeamPCP a way back in weeks later. Once inside the Trivy project, they rewrote 75 of the tool’s 76 version tags to point to their malicious code. Any company that updated or reinstalled Trivy after March 19 pulled down the compromised version automatically.

The stolen credentials from Trivy then gave the attackers access to Checkmarx’s tools. One breach became two. Two became a cascade. TeamPCP also published poisoned extensions for Visual Studio Code, the code editor used by millions of developers worldwide, and launched a self-spreading worm through npm, the package manager that supplies building blocks for a massive portion of the internet’s software. CrowdStrike’s analysis confirmed the worm spread to at least 47 additional software packages, with the number still climbing.

Buried in the technical details is something that reads more like a geopolitical statement than a cybercrime operation. The worm contains a targeted payload specifically designed to destroy computer systems located in Iran. It identifies Iranian infrastructure, mounts the core operating system, deletes everything, and forces a reboot. The motivation behind that is unclear, but it means this operation has dimensions beyond simple theft.

This is the third major attack on GitHub’s automated tooling system in the past year. In March 2025, a similar hijacking of the tj-actions project affected 23,000 repositories. The playbook is the same each time. Attackers rewrite the version tags that developers trust, so when someone’s system automatically pulls the latest update, it gets the malicious version instead. The fix is known: pin your tools to specific, verified versions instead of letting them auto-update. Most teams don’t do this because it adds friction to their workflow. So the same attack keeps working.

The guardrails simply aren’t there anymore. The systems that developers built to protect software are themselves unprotected. The assumption that your security tools are safe because they’re security tools is exactly the assumption being exploited. Every company running automated code scanning, which is most of them, now has to ask a question that shouldn’t need asking: can I trust the thing I’m trusting to keep me safe?

What This Means for Everyday People

You’ve never heard of Trivy or Checkmarx or GitHub Actions. But they’re part of the invisible machinery behind the apps on your phone, the sites you shop on, and the systems your bank uses. When the tools that check those systems for problems get hijacked, the problems stop being caught. And the attackers who did this now have passwords and access credentials for over a thousand companies. That translates, eventually, to breaches that reach your inbox, your accounts, and your data.