daily cyber × ai intelligence

index

How it works

A machine-written security & AI digest

kyber.today publishes a daily recap of the most important cybersecurity and AI news, with a focus on where the two intersect. Every issue is gathered, triaged, written, and tagged by an automated pipeline — no human edits it before it goes live. 92 issues published so far.

The pipeline

Each issue is the output of five stages. The per-issue funnel line (“71 of 75 sources → 441 gathered → 400 triaged → 63 clustered → 50 written”) is exactly this pipeline narrowing the day’s news down.

  1. Gather. Pulls every source in a config file — security & AI blogs, CVE/advisory feeds, national CERTs (Nordics/EU/Ukraine), Chinese security labs and WeChat accounts, Hacker News topic searches, and curated infosec/AI accounts on X. Everything is normalized, de-duplicated by URL, and filtered to a freshness window.
  2. Triage. claude-haiku-4-5 clusters the candidates across sources (the same story from several outlets becomes one cluster) and scores each on intrinsic importance and how well it matches the reader profile.
  3. Rank. Clusters are ordered in code by importance + interest + cross-source corroboration, so a well-reported story and an on-profile niche one both surface.
  4. Write. claude-opus-5 drafts the recap from the top clusters, leading with the biggest stories and quoting community reaction (X replies / Hacker News comments) where it adds something. If it declines the material — see below — the identical request goes to gpt-5.6-sol.
  5. Enrich & publish. claude-haiku-4-5 extracts a summary and normalized tags (topics, vendors, threat actors, CVEs, malware, models). Citations of Chinese-language pages are pointed at Google’s translation proxy, since a link to 2,000 words of Chinese is not a citation most readers can use; the original address is recoverable from the link. The result is committed as a markdown file and this static site is rebuilt.

Two vendors, and why

Security reporting is awkward material for a safety classifier. Naming a vulnerability, an exploit, a malware family or a threat actor is the ordinary substance of this beat, and it is also what a filter tuned against attack-enablement is watching for. Periodically a model declines to write the digest or the weekly recap — not because anything in it is secret or novel, but because the pile of it trips a threshold. Every story involved has already been published by BleepingComputer, The Record, a vendor advisory or a national CERT.

For a long time the answer was to shrink the request until it was accepted: drop the model's reasoning budget, then the prior weeks' context, then the reader profile, then whole days of news. Every one of those paid for publication with the reader's copy.

It no longer works that way. A refusal is a property of one vendor's classifier, not of the news, so the identical request is handed straight to the other vendor — gpt-5.6-sol for prose, gpt-5.4-mini for tagging and triage — with nothing removed. Nothing is dropped, downgraded, or rewritten to get past a filter, and no attempt is made to talk a model out of a refusal. The trimming ladder still exists as a last resort for the case where both vendors decline the same material, and when it fires the issue says what it left out.

Because either vendor can end up writing, each issue records which model produced it and prints that at the bottom of the page. So far: claude-opus-5 (23) , gpt-5.6-sol (7) , claude-opus-4-8 (1) . Issues published before this was recorded carry no byline.

Is there human review?

No. The digest is written and tagged entirely by AI models — from one of two vendors, whichever will write it — and published automatically on a schedule. There is no editor in the loop. Treat it as a machine summary of public reporting, not as original or verified journalism. Every claim links to its primary source; when a story is thin or a listing is unconfirmed, the digest is meant to say so — but the models can still be wrong, miss context, or misattribute. Verify anything important against the linked source.

How stories are chosen

Selection is driven by three signals — intrinsic importance, match to a stated reader interest profile (offensive/defensive security, cloud & identity, AI/LLM security, threat intel, EU/Nordic regulation), and how many independent sources corroborate a story. Recently-covered stories are suppressed, and a genuine development of an earlier story is presented as a continuing thread that links back to previous coverage.

Wild Speculation, and how it is kept honest

The weekly recap ends with a section called Wild Speculation. Everything above it is reported and sourced; everything inside it is the model reasoning past the reporting — drawing connections between the week's stories and making predictions. It is inference, not news, and it is labelled that way in every issue. It may not introduce a fact, link, CVE, or attribution that isn't already in the recap above it.

To stop that turning into unfalsifiable futurism, each prediction has to be specific enough to settle and carries a deadline. When the deadline passes, a later recap scores it hit, miss, or unresolvable, and the verdict is written back onto the recap that made the call — so every weekly shows how its own bets turned out. The running record printed in each recap is counted from that ledger, not asserted by the model, and a bad run stays visible.

Corrections & contact

Because the pipeline is automated, the best correction is at the source: every item links out, so follow the link for the authoritative account. Sources and the reader profile are version-controlled and evolve over time.

Comments, suggestions, corrections, or a source worth adding? Email root@kyber.today — feedback on what to cover, what to cut, and what the pipeline got wrong is genuinely welcome.

Sources

Pulled every run: 34 feeds & advisories, 23 X accounts plus 2 topic searches, 8 Hacker News topics, and 8 Mastodon accounts. This list is generated from the live config.

Feeds & advisories
AnquankeBleepingComputerCERT-EUCERT-SE (Sweden)CERT-UA (Ukraine)CERT.dk (Denmark)CERT.pl (Poland)CISA AdvisoriesDark ReadingDoonsec (WeChat security accounts)Embrace The RedGoogle Project ZeroGoogle Research BlogHorizon3 Attack TeamKrebs on SecurityLobsters (security)Microsoft Threat IntelligenceMIT Technology Review (AI)NCSC-FI (Finland)NCSC-NL (Netherlands)NCSC-UKNSFOCUSQiAnXin ResearchQiAnXin XLabSANS Internet Storm CenterSchneier on SecuritySecurityWeekTalkbackThe DecoderThe DFIR ReportThe Hacker NewsThe RecordUK AI Security InstitutewatchTowr Labs
X / Twitter
@vxunderground@cyb3rops@malwrhunterteam@taviso@simonw@goodside@DailyDarkWeb@ido_cohen2@FalconFeedsio@DarkWebInformer@blackorbird@nextronresearch@ESETresearch@watchtowrcyber@HuntressLabs@Unit42_Intel@Mandiant@ipurple@thegrugq@dinosn@_r_netsec@TheZvi@emollick
Hacker News topics
AI securityprompt injectionLLMAIvulnerabilityransomwarezero-daydata breach
Mastodon
@malwaretech@infosec.exchange@hacks4pancakes@infosec.exchange@mttaggart@infosec.exchange@dangoodin@infosec.exchange@troyhunt@infosec.exchange@netbiosx@infosec.exchange@GossiTheDog@cyberplace.social@campuscodi@mastodon.social