Most of today’s stories are about who gets to trust what: a firewall, an encrypted tunnel, a lab model, a photo library. Some of the trust holds up. Some of it rests on a detail nobody checked.
1. Cloudflare’s AI attacker mostly failed, and the failures are the interesting part
Cloudflare pointed frontier models at its own WAF, and the notable result is how little got through. The tester made 1,107 attempts across 45 scenarios against an authorized customer staging environment. 558 requests were blocked. After human triage, 49 findings were worth investigating, and 48 of them were command injection or SSRF.
The model had no view of the rules or the source code. It just mutated encodings and moved payloads around the request. In one SSRF session, 17 variations of a cloud-metadata address were blocked. Then a trailing-dot form got a redirect instead of a block page. Cloudflare is careful to call that a lead, not proof that anything was fetched. The fixes were new SSRF detections in the July 21 managed ruleset.
The pattern is that equivalent inputs get read differently, which makes signature-writing a game of whack-a-mole. Cloudflare’s answer, launched the same day, is Application Profiles: learn what normal requests look like and flag deviations. It comes with caveats. It is a closed beta, it learns from live traffic that can include bots, and Cloudflare recommends observation mode first. It also doesn’t support GraphQL, XML or multipart forms. And the WAF result is one vendor testing its own configuration, so a customer with looser settings shouldn’t assume the same block rate.
Cloudflare Blog · Cloudflare Blog · Cloudflare Blog
2. IPsec’s old flaw gives quantum attackers a downgrade route
The IPsec flaw Cloudflare is patching isn’t new. The company says it “rediscovered” it, since a 2016 paper had already noted that IKEv2 endpoints sign only their own outbound messages, not the whole handshake. That means the two ends can walk away with different accounts of the same conversation.
A quantum-equipped attacker could exploit that. They would rewrite the initiator’s message to look classical-only, recover the key during the handshake, and authenticate with their own valid credentials. Cloudflare says this lets them decrypt traffic between post-quantum-capable endpoints. The catch is that the quantum computation has to finish in real time, and Cloudflare admits it doesn’t know if or when that becomes feasible. So the selector’s claim that your tunnels are vulnerable now overstates it.
The fix is an IETF extension that signs the full transcript, now in beta on Cloudflare WAN and Magic Transit via an account flag. Both ends must support it. The lesson is that backwards compatibility can quietly cancel post-quantum crypto. Cloudflare has also moved its own deadline up to 2029, and it is using an internal AI tool called CryptoLabe to find classical crypto in its code. The open question is whether the rest of the IPsec ecosystem follows.
Cloudflare Blog · Cloudflare Blog
3. Microsoft’s Quine ranked cancer compounds in a weekend, with a lab check
Microsoft Research says its new Quine system narrowed thousands of candidate compounds to a handful in a single weekend. The task was to find compounds that push pancreatic cancer cells between cell states. The top-ranked picks were then validated in wet-lab assays, working with the Broad Institute. Microsoft says this “potentially” saved months of work.
The more interesting detail is where the model was wrong or surprising. Shifting cells from basal back to classical was weaker, which Quine predicted. It also predicted that some compounds would push cells toward a third phenotype, and the lab bore that out, suggesting the cell-state landscape is richer than a two-state axis.
The framing is modest. Microsoft says the model doesn’t need to be perfect, only useful for choosing experiments. That is a defensible bar, and a much easier one than replacing the lab. But this is Microsoft’s own account, and the post gives no baseline for how conventional screening would have done. Access is limited to a Fellows program and select collaborations, and it is not for clinical use. Treat it as a promising workflow, not a proven method.
Microsoft Research · Ars Technica
4. ChromeOS gets an end date, and Googlebooks get the handoff
If you run ChromeOS fleets in schools or offices, the runway just got shorter. The Register reports Google is ending ChromeOS support two years early, and Ars Technica says Google seemingly confirms plans to end ChromeOS in 2034.
Ars says Google’s support material sketches how Googlebooks can take over from ChromeOS. The evidence here is thin, though. Ars’s account is hedged with “seemingly”, and we only have the headlines and one-line excerpts of both pieces. We don’t know what migration help, if any, comes with the shift.
The practical point is planning. Device refresh cycles in education and enterprise run for years, and a platform with a known end date and a successor that isn’t fully described makes those purchases harder to justify. Google hasn’t said what Googlebooks will demand of existing hardware.
5. Marissa Mayer wants your camera roll to be an AI’s only diary
Dazzle’s pitch is that your photos know you better than your inbox does. Marissa Mayer’s startup, which raised an $8 million seed round last December, builds a personal assistant whose only source of context is your camera roll. Mayer told TechCrunch that photos are “an underappreciated source of information.“
TechCrunch’s test was mixed. Dazzle’s vacation suggestions were plausible, but it included Sicily, which the reporter visited four years ago. And it didn’t know her daughter already roller skates when asked about a gift. That is the weakness of the photo approach: pictures show what you did, not what you already own or know how to do.
Mayer also argues users may find handing over photos less risky than handing over email, given security concerns about tools like Meta’s Instinct and Muse. That is a debatable trade. A camera roll holds children, homes and locations, and Dazzle’s assurance is that it discards information the AI flags as sensitive. Her last photo product, Shine, shut down after failing to attract widespread use.