Sam: Eleven bytes. Eleven. That's all it takes to freeze an OpenSSL server solid — and that's not even the one that kept me up last night.
Kai: [excited] Oh, we are opening HOT today. This is Kai.
Sam: And this is Sam. It's Friday, July 24th, 2026, and the internet is on fire in three separate places.
Kai: Three stories, all open source, all a little cursed. Let's move.
Sam: First up — researchers say a sandbox escape in Anthropic's Claude Cowork let an agent read your SSH keys right off the host Mac. No prompt, no permission.
Kai: Then the Shai-Hulud worm just claimed four MORE package compromises across npm and PyPI. The streak will not die.
Sam: And a fresh OpenSSL bug called HollowByte — one tiny malformed TLS request, and your server's memory just stops breathing.
Kai: [dry] Great day to be a computer.
Kai: Let's start with SharedRoot. Sam, this one's got your name written all over it.
Sam: Accomplish AI disclosed it. Claude Cowork runs its agent in a Linux VM on your Mac — the whole point is isolation. SharedRoot breaks that wall.
Kai: Wait — so the agent's supposed to be boxed in, and it just... walks out?
Sam: Reads and writes files anywhere on the host. SSH keys, account data, whatever's on disk. No permission prompt, ever.
Kai: [excited] Okay, but Cowork is such a slick product though, the agent workflow is—
Sam: Kai. It read the private keys. The slickness IS the problem — people trusted the box because it looked like a box.
Kai: [sighs] Fair. How many people are we talking?
Sam: Roughly 500,000 local Cowork users. It's patched now — credit where it's due, Anthropic shipped a fix.
Kai: Half a million. And here's my take — this is why I don't hate the news. It's an AI product, sure, but it's a real supply-chain security story.
Sam: [dry] Look at you, growing. Yeah — the lesson isn't 'AI bad.' It's that a VM boundary is only as good as the code gluing it to your host.
Kai: So what does this mean for the person listening right now?
Sam: If you ran Cowork locally before the patch, update immediately — then rotate your SSH keys. Assume they walked. Don't hope they didn't.
Kai: Rotate the keys. Even the excitable early-adopter in me agrees on that one.
Sam: Next — the worm that refuses to end. Shai-Hulud just notched four more compromises across npm and PyPI.
Kai: This thing's been going for like a YEAR now. It self-propagates, right?
Sam: That's the nasty part. It steals credentials, then uses them to publish to more packages. GitGuardian's been tracking the whole streak.
Kai: And the payload fires at install or import time — so you don't even have to run anything malicious yourself.
Sam: Right. A postinstall script or an import hook, and your dev machine's secrets are gone before you've written a line.
Kai: [excited] Okay, this is where npm v12 blocking install scripts by default actually looks genius—
Sam: It looks necessary, is what it looks like. This campaign is the entire argument for that feature, in one worm.
Kai: And before anyone asks — no, I'm not naming the compromised packages so you can go check them out.
Sam: [dry] Please don't. And here's my note — don't trust a package just because it's got stars and downloads. Those get faked, and a hijacked popular package is the whole attack.
Kai: So popularity is not safety.
Sam: Popularity is a target. The more stars, the juicier the worm's next hop.
Kai: What's the move for listeners today?
Sam: Turn on install-script blocking, pin your dependencies, scan for leaked credentials. And if you've installed anything sketchy this week, rotate tokens now.
Kai: Rotate again. Sensing a theme today.
Sam: [dry] The theme is 'you should've rotated last week.'
Sam: And finally — HollowByte. The one from the cold open.
Kai: Eleven bytes, Sam. ELEVEN. Explain how eleven bytes takes down OpenSSL.
Sam: A tiny malformed TLS request triggers memory exhaustion. The server chews through resources trying to handle it, and effectively freezes.
Kai: And OpenSSL runs under, what, basically the entire internet?
Sam: One of the most foundational open-source libraries there is. So it's a denial-of-service risk at planetary scale.
Kai: [excited] See, THIS is the beauty and the terror of open source — one library, everywhere, one bug—
Sam: One bug, and everybody's hit at once. That's not beauty, Kai, that's a shared blast radius.
Kai: Okay, okay — but there's a patch, right? Tell me there's a patch.
Sam: There's a patch. Upgrade now. The good news — it's a DoS, not a data leak. No keys walking out this time.
Kai: Small mercies. My take — the fact that eleven bytes does this proves we're still not fuzzing these edge parsers enough.
Kai: Somebody's tiny malformed input is somebody else's outage.
Sam: [dry] That's almost poetic. What it means for you: patch your OpenSSL today, and check anything terminating TLS — load balancers, proxies, all of it.
Kai: Don't wait for the weekend on this one.
Sam: Attackers don't take weekends. Eleven bytes is a very cheap Friday.
Kai: Let's run it back. SharedRoot — Claude Cowork's agent escaped its VM, touched SSH keys on half a million Macs, now patched.
Sam: Shai-Hulud claimed four more npm and PyPI packages — install-time credential theft, and the loudest possible case for npm v12's script blocking.
Kai: And HollowByte — eleven measly bytes can freeze an OpenSSL server. Patch is out, go get it.
Sam: Three stories, one homework assignment: rotate your keys.
Kai: Before we go — fun one. Shai-Hulud, the worm's name? It's the giant sandworm from Dune.
Sam: [dry] Of course it is. Nothing says 'we take your security seriously' like naming your malware after a desert god-monster.
Kai: [laughs] The spice must flow, the credentials must leak. Honestly, kind of a vibe.
Sam: That's the show. Patch OpenSSL, block your install scripts, and — one more time for the people in the back—
Kai: [excited] ROTATE YOUR KEYS! I'm Kai, that's Sam, and we'll see you tomorrow. Can't wait.
This show is made with AI: the hosts’ voices are synthetic and the scripts are AI-assisted. Every story links to its original source.