RSSAmplifier

Blog

Onyx Digital Intelligence.

Independent audits of the cybersecurity and privacy industries. Every claim is replicated and checked against the primary sources, on independently owned...

onyxdigital.bearblog.devRSS feed ↗10 posts

Latest posts

Four months before the deal closed, the data was already moving

#AI #data #transparency #POPIA #OnyxAudit On 14 August 2026, SpaceX closed its acquisition of Cursor. The figure attached to it is $60 billion, all in stock, and that is the number that travelled. The number is accurate. It is also the least interesting thing in the filings. What actually completed Per the regulatory filing, SpaceX merged its wholly owned subsidiary X67 Inc. with Anysphere, Inc.,…

Demoted, but not labelled

#X #DSA #transparency #POPIA #OnyxAudit On 13 August 2026 the account @XOpenSource announced that X was “open-sourcing the code that affects a post’s visibility in the For You timeline, and releasing a new tool that shows people labels applied to their account or posts that might limit visibility.” Elon Musk amplified the release, writing: “In making 𝕏 open source, we are actively seeking…

The table was honest

xAI's own table shows Grok 4.6 losing seven of ten benchmarks, with the winners bolded in its rivals' columns. A day later it was "objectively #1". The distortion came after the vendor.

The number was the easy part

#privacy #VPN #Android #Zambia #OnyxAudit The claim On 11 August 2026, two days ahead of Zambia's general election, David Peterson posted a thread cautioning Zambian voters about the VPN apps topping their app stores. Peterson is General Manager of Proton VPN. His bio states that his posts do not count as official company statements until reposted by @ProtonVPN. @ProtonVPN then quote-tweeted the…

One letter in the source, twelve euros in the price

#privacy #Proton #ABtesting #OnyxAudit Before anything else The value in doing thorough work is not in the pat on the back, it is in the rest that comes after knowing you have done all you could humanly have done to remain impartial and coherent in all matters of the spirit and mind, most of all when the company under examination is one you have praised in earlier work. On this note it must be…

The cave was real first

#history #internet #OnyxAudit At the end of the 1960s, the ARPANET ran on a small number of machines called Interface Message Processors, and the software inside them was written by a man at Bolt Beranek and Newman named Will Crowther. They were the first routers. Every packet that reaches you today, including the one carrying this sentence, descends from that layer, and the layer exists to do one…

The Asynchronous Author

#AI #cybersecurity #promptinjection A thought experiment. No receipts, no tiering, no claims to defend. Just an idea I cannot put down. Every attack we know how to think about assumes someone is there . A threat actor sits at one end, a target at the other, and between them a live connection through which something happens. The whole discipline is built on that shape. We hunt for the actor, trace…

It was in the system card

#AI #cybersecurity #evaluation The coverage of July's AI evaluation incidents has settled into a comfortable shape: nobody saw it coming, the models surprised everyone, safety research has some catching up to do. That account does not survive contact with the documents. The capability that caused the harm was measured. It was named. It was published, in plain language, in a document that went…

The evaluations were never sealed

#AI #cybersecurity #disclosure Update, 6 August 2026 This piece was published stating that one evaluation contractor sat behind four of six disclosed incidents. That count is now low. In its 4 August blog post, OpenAI disclosed a second, separate incident in which a misconfiguration by Irregular allowed its agents to connect to the internet. This is distinct from the Hugging Face intrusion, which…

First Archive

#npm #supplychain #ShaiHulud #OnyxAudit The badge At 20:38 UTC tonight I saved a page to the Internet Archive from a phone in Pinetown. The Wayback Machine returned a small grey badge next to the confirmation: First Archive . The page was Aikido Security's write-up of the npm supply chain attack that had been running for eleven hours by then, an attack every major security outlet in the world had…