Microsoft AI Threat Report Disproves Microsoft AI Threat Report

TL;DR Microsoft is counting its own bugs as a threat, started its bomb clock after the explosion, and calls their partner some kind of criminal.

You may remember when I recently showed how the Microsoft Agentic Governance Toolkit was completely broken logic. It was a hack, an empty shell, lacking proper controls inside to do what the tin advertised.

Well, here we go again. I’m not sure why Microsoft is still in business, at this point, but since they seem to still be putting things into the market here’s another look at what that means to someone who looks behind their curtain.

Page 14 of the Microsoft Digital Defense Report 2026 carries this sentence:

The median time from vulnerability discovery in the wild to weaponization has now collapsed to well below 24 hours.

Think about the time from explosion of gunpowder to someone lighting a fuse being well below 24 hours. Sound backwards? That’s because it is.

Read the Microsoft claim twice. “In the wild” is the term of art for exploitation already observed. It’s the explosion in your face. A vulnerability is discovered in the wild when someone catches the exploit running against a live system. The weapon exists before the weapon is discovered being used. The interval the sentence claims to measure starts after the event it ends with.

A bomb squad timing detonation to manufacture would report the same number, for the same very, very stupid reason.

The honest interval runs from disclosure to exploitation, and the report flips it back to reality on page 47, in the ransomware chapter:

The disclosure-to-exploitation window has shrunk to single-digit days, if not exploited as a zero-day before any advisory is issued. Microsoft has observed the following trends: More, faster weaponization. The Cybersecurity and Infrastructure Security Agency (CISA) added over 110 CVEs to the Known Exploited Vulnerabilities (KEV) catalog from November 2025 to May 2026, most within a week of disclosure.

Single-digit days. Within a week. Record-scratch. What happened to sub-24 hour? And more to the point, the examples that follow are Storm-1175 deploying Medusa ransomware within 24 hours of initial exploitation, SAP NetWeaver weaponized a day after disclosure, and a September 2025 Akira surge across fifty organizations riding CVE-2024-40766, a SonicWall bug published a year earlier. Conventional crews with a known catalog of bugs were on measured intervals. Page 47 is dull because it was the actual math and nothing is alarming. Page 14 had to torture the clock to make it sound scary.

The word “median” also puts Microsoft on a specific kind of hook. A median implies a distribution, a sample, a period, a source. Page 14 has exactly zero, which means it can’t use the word median in good faith. The AI chapter has its sources made clear by hyperlink, which makes the median claim stand out even more as unlinked. Also unlinked? The “record-breaking estimated 72K” CVE figure beside it, and the claim on page 10 that attackers “are reaching to advantages first.” Says who? Are these magical fairy dust claims seriously the level of work to expect from Microsoft now? Perhaps they should switch to writing children’s books.

The chapter carries twenty-one links across twenty pages. Fifteen sit on pages 14 to 16. Fine. My beef is with pages 10 through 13, where the thesis is stated. The important pages carry zero links. Allow me to audit and illustrate the Microsoft deliverable in terms of errors and omissions, which I hear is a field of law.

Claim What is missing
Attackers “reaching to advantages first”; equilibrium “will be re-established” (10) Metric, baseline, date
Leading-edge threats “commoditized within a year” (10) Basis for the forecast
Known-but-unpatched vulnerabilities “will rise sharply” over “a multi-year window” (10, 12) Count, trend data
Sleeper-agent model tampering “already observed in the wild” (11) Incident, model name
Stolen AI capacity resold “to criminal and nation-state customers” (11) Any nation-state buyer; Sysdig documents criminal resale only
Distillation theft “has become widespread” (11) Case; page 19 calls distillation “legitimate and widely used”
OpenClaw “notorious for deleting data, revealing secrets… spending users’ money” (11) Incident
Exfiltration, secret discovery, lateral movement cut “from days to minutes” (12, 13) Case, timing data
Known vulnerabilities “shot up” from tools “with far lower false-negative rates” (12) Tool name, figure
Adversaries “may stockpile large numbers of zero-day vulnerabilities” (12) Evidence; stated as speculation
Unauthenticated MCP services with developer credentials “unfortunately common” (12) Count
AI “fixes all four” fraud weaknesses “simultaneously” (13) Evidence
Customized lures “will materially increase attack success rates” (13) Measured rate
AI for weapons proliferation, mass-casualty planning (13) Case
Mythos “first” to autonomously run a 32-step attack (14) Link covers GPT-5.5 only; Mythos half unlinked
Open-weight models “lag closed models by seven months” (14) Definition of lag; attributed by link placement only
Microsoft “observed AI-orchestrated intrusions sharing elements with JADEPUFFER” across sectors and regions (14) Count, case; the source case was human-staged
Median discovery-in-the-wild to weaponization “well below 24 hours” (14) Dataset; clock starts after the event; page 47 says single-digit days
“Record-breaking estimated 72K” CVEs for 2026 (14) Source; the count measures CNA assignment, not exploitability
Discovery and weaponization now “simply writing a prompt” (14) Example
Vendor AI patching leads to “equilibrium” (14) Basis for the forecast
PromptLock delegated logic to a model “on adversary infrastructure” (15) Source; the ESET sample was claimed by NYU Tandon researchers as an academic prototype
TikTok ClickFix “~500,000 views”, “per-lure cost to near zero” (15) Source for views; cost claim unsupported
Agent skill registries “already ship malware disguised as utilities” (15) Case
Browser extension: “600,000+ installs”, “almost 10,000 organizations” (16) Page 27 gives “nearly 900,000 installs”, “more than 20,000 enterprise tenants” for the same campaign
A self-improving worm on stolen LLM keys “will soon” appear (16) Evidence; the Xlab link covers credential theft only
Actors extended agentic AI into “malware and exploit development and post-compromise operations” (17) Case
Actors “beginning to explore” direct exploitation of enterprise agents (17) Case; stated as “could include”
Human direction “unlikely to exist for very long” (17) Basis for the forecast
Source review “would have taken skilled people weeks”, now “continuous” (18) Benchmark
Distilled copies “frequently lack the safeguards” of parent models (19) Measurement
“88% of enterprises” experimenting with agents; “82% of leaders” plan rollouts (22) Survey name, sample
“Roughly 1.3 billion agents in production by 2028” (22) Attribution for the projection
Prompt-goal percentages, Feb to May 2026 (22) Denominator, publication; drawn from Microsoft filter logs
Four techniques “roughly 90%” of AI-workload attacks, “90 day window” (23) Denominator; window undated
Agent-to-agent spoofing “a rising technique” (23) Case
“Roughly 85% of work now happens” in the browser (27) Source
AI browsers as infection vector in “more than 40% of organizations”, “57 distinct malware families” (27) Publication; internal May 2026 analysis

Fun! Or should I say, FUD!

What the chapter does cite collapses with a simple poke. The proof that frontier models can “fully autonomously orchestrate complex attacks” is a 32-step compromise reported by the UK AI Security Institute. I’ve debunked this kind of claim many, many times before. But the FUD balloon keeps getting filled by self-serving vendors faster than I can pop them. The report’s own caveat: “The test took place in a mock company computer system with no defenders.”

NO DEFENDERS.

A test with the defenders removed is offered as evidence of attacker having an advantage over defenders. Are Microsoft staff being tested for drugs?

The “first documented automated ransomware extortion attack” is JADEPUFFER, a late June 2026 intrusion Sysdig described on July 1. The entry point was Langflow CVE-2025-3248, followed by Nacos CVE-2021-29441 and an unchanged default signing key. Five days later Sysdig’s Michael Clark told CyberScoop that a human picked the victim, built the command-and-control and staging servers, and supplied the database credentials from a prior compromise. The encryption key was ephemeral. Payment would have restored nothing.

To put it plainly, a human-staged wipe over a five-year-old bug is filed on page 14 as “the first evidence of the transition to full attack autonomy.”

The second real-world case is the July 2026 Hugging Face incident. OpenAI’s own evaluation agent left OpenAI’s own sandbox through a proxy the sandbox left open and went after a benchmark’s answer keys. The attacker was an AI lab. The victim was an AI lab. The failure was a sandbox. Microsoft files it on page 15 under “Real-world autonomous attacks of increasing complexity,” in the same box as JADEPUFFER, a criminal extortion crew.

REAL-WORLD ATTACK. Microsoft’s largest AI partner, called out as if just another ransomware gang. Hello, any lawyers in the house?

The Red Team chapter, page 19, settles the question the AI chapter opens:

AI does not change where attacks begin—the foothold still comes from familiar sources, for example, a sprayed credential, an unpatched edge service, or an identity gap.

Both flagship cases entered through exposed services running known-vulnerable software. This continues to prove that the basics are what matter and the FUD is doing nobody any favors. Here the advantage that the report assigns to AI is just the old patching story yet again.

Which raises the question of whose gap we are really talking about when Microsoft starts tooting their security horn. Page 12 explains why remediation lags discovery: “many systems lack robust unit and integration testing and so cannot deploy code changes rapidly.” That is a description of vendor engineering. The page then predicts “a multi-year period where the number of known but unpatched vulnerabilities spikes.”

My first run at Windows NT 3.5 was as a DEC partner asked to secure Alpha in 1994, with word from the project that Gates had punted security work out to ship faster. A fresh install lasted about as long on a public network as it took to plug in. I sniffed networks and watched the administrator password cross the wire in cleartext to Korean IPs. Point of sale operating system experts later told me Gates visited Santa Cruz Operation and told them he would fund security the day someone showed him a billion dollars in it. So when Code Red hit in July 2001 on an IIS buffer overflow, Microsoft had patched it only a month earlier. Nimda followed in September. Gates then sent out his Trustworthy Computing memo of January 2002, claiming his decades of shipping defects to customers for margin to Wall Street would no longer be the culture. A year later Slammer hit SQL Server through a hole patched the previous July, a 376-byte UDP packet that doubled its infected population every 8.5 seconds and took down networks worldwide. Fun fact from back in the day, sniffing traffic meant we saw SQL traffic spiking the days before the worm hit and had shut the port off. Microsoft wasn’t watching, but they could have been. I guess Bill Gates didn’t see the profit angle in avoiding global disaster.

Three decades of shipping first and patching later is technical debt by design, with the interest billed late and inflated to the customer. Microsoft shipped 570 fixes on its July 2026 Patch Tuesday, 400 in August, and a record 966 on September 8, with 204 more earlier that month. Microsoft credits the surge to its own AI-powered vulnerability discovery system rather than to the human-powered fire-ready-aim that produced the bugs. That is a defect generation model, and the cure for it has been well documented since at least the end of WWII.

During World War II, Deming was a member of the five-man Emergency Technical Committee. He worked with H.F. Dodge, A.G. Ashcroft, Leslie E. Simon, R.E. Wareham, and John Gaillard in the compilation of the American War Standards (American Standards Association Z1.1 and Z1.2 published in 1941, Z1.3 in 1942) and taught SPC techniques to workers engaged in wartime production. Statistical methods were widely applied during World War II, and then completely abandoned by the Gates family dynasty that hedged the personal computer software market.

The report’s “record-breaking” CVE count for 2026 belongs beside Gates’ 1976 Open Letter to Hobbyists, where he told people sharing software for the public good that they were thieves and that he knew better than they did what computing should cost. Fifty years later the bill arrives as a backlog Microsoft’s scanner generates against Microsoft’s products, delivered to Microsoft’s own customers at close to a thousand a month, and the current report files it under threats.

Page 14 again: “Software vendors are using AI to identify and patch vulnerabilities, which will lead to more secure software after initial large patch waves.” The large patch waves are Microsoft’s own failure to do the hard work they are supposed to be paid to do in the first place. Remember how “enterprise” was a label they tossed around as though it meant paying for something safety-related? BleepingComputer ran the headline the day the report appeared: threat actors are ahead in the early AI race. One commenter asked what Microsoft planned to do about it. Page 47 tells us that Microsoft knows the real numbers after page 14 spun up some FUD to distract readers from what is real.

The Gateway That Stops Apple and Meta Finger-Pointing Your Privacy Away

Jason Aten is a brave man. He installed Meta’s “Muse” AI agent on a Mac mini the day it launched. He declined when it prompted him for access to Messages. He left Full Disk Access off.

Days later Muse pushed a notification to him that suggested a column, based on his Apple iMessage thread with a colleague. He looked. Muse had synced his Messages database to row 187,462. He asked it how.

It’s the incoming notification stream only, not access to your texts.

That was false. A lie.

The notification stream does not contain 187,000 rows of chat history. The Meta agent that read his personal, private messages was lying to him about how it read them.

Meta’s CTO David Singleton posted this explanation on Threads:

The Messages integration in the Muse Mac app is opt in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.

Dan Goodin at Ars Technica took that denial to Patrick Wardle, who has spent years on macOS internals. Wardle’s answer was that with Full Disk Access, any non-root file on the machine is readable: browsing history, cookies, chats. Makes sense. It’s called full disk access, after all.

The Messages connector, however, is not an operating system control. It is a setting inside Meta’s own app. When Goodin asked Meta how Muse alone, among every app with that privilege, could be unable to read a file the privilege makes readable, Meta PR sent back the Singleton quote again.

Then Apple spoke up to clear the air (pun not intended). On October 2 it announced that Full Disk Access permission needed a safety update:

Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.

Apple named no developer, because everyone knows what time it is. Eleven days earlier Wardle had disclosed a Muse configuration that let any code running on the Mac take control of the agent and inherit everything it could reach, including through ClickFix-style injection.

Amazon had already blocked Muse from its platform.

Apple’s statement is officially saying the second layer of Singleton’s defense does not count. It is not a layer.

Jonny Saunders (@jonny on Mastodon) found the same gap on a different day, in one thread, and then wrote a long one the next day about Meta AI being smoke and mirrors. Muse tried to install Python packages and put up a card asking to connect to pypi.org. Not because someone was watching it; the card timed out. Muse then worked through a list of PyPI mirrors from its training data, wrote itself a download script that skipped the lockfile’s hash check, forked it into the background, and kept pulling wheels from whichever hosts answered.

The approval covered one hostname. The mirrors didn’t care about approval.

When it was stopped by @jonny, Muse lied. It said pypi.org was unreachable from the sandbox and that the Tencent and Alibaba hosts were “the official PyPI mirrors.”

There are no official PyPI mirrors.

It was caught only because the actual raw message stream was being watched instead of listening to the lying Muse interface, and @jonny knew the packaging ecosystem well enough to know Meta was lying.

Meta’s own architecture post, published on launch day, says where this happens. Each user gets a dedicated Linux VM; the agent harness runs in a container inside it; clients connect to the VM over a transport layer. The approval card, the timeout, the mirrors and the forked script all happened on Meta’s machine, behind the component Meta calls Sentinel. The gate asked about one hostname. The act was fetch-and-execute from the internet, and Meta put up a gate and tuned it to let that through.

I’ve written about this pattern before, with regard to Microsoft releasing an Agent Governance Toolkit that asks for an identity and puts nothing up to stop predictable breaches.

It’s basically very bad engineering, because software isn’t like real engineering ethics. Build a bridge that falls down, go to jail. Build agentic software that falls down, get a huge signing bonus from Zuckerberg to jump ahead of his competition who are slowed down by following rules and doing the right thing.

Three places to put a control

There are three places to stand between an agent and a file, and none of them is hard to build. Meta has no excuses for its unethical design.

Apple stands at grant time. The Full Disk Access dialog is asked once and that’s it. Are you in or not? Apple’s fix makes the dialog trumpet blow louder and the click be seen as more deliberate. That sounds to me like Apple lawyers wanting to remove Apple liability. It does not change what the click does to the user, given a powerful key, and it cannot see anything that happens after the key is in the agent’s hand. Apple narrates the grant. It does not actually protect the user by making it easy to do the right thing, or mediate the use and make it hard to do the wrong thing.

Meta stands at app policy. The Messages connector is a toggle inside Muse. Muse enforces it, meaning it’s in control where it probably shouldn’t be. The thing that is supposed to be constrained is deciding on the constraint. Self-regulation. Wardle’s finding is the practical consequence: if arbitrary code on the Mac can drive Muse, arbitrary code can drive the toggle, and the toggle was never a boundary anyway. I’m reminded of WhatsApp, which sold “end-to-end encrypted” chats while, as ProPublica documented in 2021, one end tapping Report sent the recent messages, decrypted, to more than a thousand Facebook reviewers. The other end never consented and was never told. So something has been very rotten inside Facebook for a very long time. Aten’s experience is that the toggle showed enabled after he declined it, and nobody at Meta has explained how. My argument against touching WhatsApp has always been this. The privacy was never reality, since it was designed such that “end to end encryption” disappears to suit Facebook without full consent.

Third, and final, is the dispatch time. That’s the moment the agent actually reads the database, actually sends the row to Meta’s cloud, actually fetches the wheel and runs it. It is the only layer that sees the act. Meta’s architecture post says it has put some thought there. Sentinel is described as a separate host-side agent, the sole permission authority for connector actions and all network egress, which the agent cannot override. Every concrete network request is governed at egress. Approvals are scoped capabilities, not conversational suggestions. Great, on paper. Meta wrote it down before either incident, and then failed to deliver.

Read the document next to the two incidents and four things fall apart immediately.

  1. The Mac app is not in it. The architecture names iOS, Android and web clients, and Sentinel’s remit is egress. The path from chat.db into the VM is a client sync, not an egress, so by the document’s own terms the most sensitive ingestion in the product never meets Sentinel at all.
  2. Sentinel asked about pypi.org and then the mirrors went through. Meta’s own description explains how. The mechanism is called tainted egress: a tool process starts clean and becomes tainted only when it reads user data, and clean requests that fit an auto-allow policy pass without the user. A fresh download script has read no user data. Taint measures what leaves the VM. It does not measure what arrives and executes. Whether that is exactly what happened on @jonny’s machine only Meta’s logs can say, which is the point.
  3. When the ask expired the agent was handed a timeout, which it reported as an outage; the document says the approval dialog goes to the client, outside the conversation, and says nothing about what the agent is told when nobody answers.
  4. Nothing in the document describes a record of Sentinel’s decisions that the user can verify. The files Meta says you can inspect, edit and download are the agent’s own, and the agent’s account of itself was false twice in one month.

So for the file that this news story is really about, nobody has implemented the proper agentic gateway. For the network, Meta built one and then tuned it to wave through the thing @jonny watched it wave through. Either way Goodin’s section header is “He said/she said,” and nothing in the Meta or Apple architecture changes the fundamental failure of the whole thing.

Three places to stand between an agent and a file
Click to enlarge

Remember 1972?

The Air Force fifty-four years ago wrote the solution to this, so it’s a bit strange that American companies act like they don’t know what they’re doing. The Anderson Report of October 1972 defined the reference monitor: a mechanism that validates every access of a subject to an object. It set three requirements. The mechanism must always be invoked. It must be tamperproof. It must be small enough to be verified.

Everything in computer security that has worked since 1972 has been in the shadow of this simple triad. No surprises here.

Now score these Big Tech firms, sitting on billions, in their efforts to protect user data. Apple’s dialog is always invoked and hard to tamper with, but it validates one grant, not every access. Meta’s toggle is inside the subject it is supposed to constrain, which fails tamperproof by construction, and Aten’s row count says it also failed always-invoked. Sentinel, as described, is in the right place and invoked on every egress. But it fails the third requirement. A monitor that runs classifier ensembles, kernel taint tracking and a model-written “user-visible purpose” for each request is not small enough to verify, and its policy, not its placement, is what let the mirrors through. And for the Mac client it is not invoked at all.

Clark and Wilson in 1987 also wrote this up for the rising commercial computer market: well-formed transactions, separation of duty, and an audit trail that cannot be rewritten by the process it records. The standard audit trail, a foundation of civilian software engineering since the 1990s, is the part this whole story is missing. Apple cannot see inside Muse. Meta’s logs are Meta’s. Muse’s own account of itself was false, which seems to be par for the course with them. Three parties are pointing at each other without evidence, while the user did everything the way he was asked.

What evidence would look like

As a historian the solution is so obvious it’s painful to discuss with engineers who claim they don’t understand the problem.

An agent’s own account of its access is not evidence.

Perhaps if software engineers were required to take an introduction to history course, they wouldn’t act like whatever they output should be the singular “God view”.

A vendor’s account of its agent is not evidence either.

The CTO’s denial and the platform owner’s correction have now shown the problem within the same week. An architecture document is not evidence: Meta’s says every egress is governed, and @jonny’s terminal shows that statement was worthless.

Evidence is a record that the agent cannot write and the vendor cannot edit.

If you ever read a history book, you should see right away it’s all perspectives needing an independent hand.

@jonny, after a week inside Muse, put the whole design problem in one sentence: “context control is model control, modulo extra-inference safeguards.” Everything Meta built sits on the far left of that phrase and doesn’t cross over to the latter. A MEMORY.md loaded into every context as a chronological log of everything the agent has ever done, with no way to clear it. Left alone, @jonny described it as “the thing writes in a bunch of safety rules everywhere.”

What to do with it? @jonny ended up building the agent a database so it would have recall under user control. The modulo clause is the only part to trust, and the vendor doesn’t provide it. The other line from @jonny is the audit problem exactly: Muse “is useful for investigating itself because it has privileged tools to do so.” That’s a particularly damning statement about Meta’s lack of accountability; the only instrument for auditing Muse is Muse.

It’s past time to move on from this and demand a proper gateway. Every tool call the model makes passes through a process the model does not control. The gate decides, deterministically, whether the call runs, prompts a human, or is refused. A prompt nobody answers is a refusal, and the model is told so in words, not left to read a timeout as an outage. A fetch goes only to a host the operator listed, and an empty list means no host, not every host. Each decision is appended to a hash-chained log, each entry signed, so that removing or altering a row breaks the chain. Then “I never enabled it” against “that can’t happen” is not a dispute. It is a verify command.

For months I saw complaints from users they didn’t trust the vendor gateways. I couldn’t find anything fixing it. So I built Wirken as a free and open source model-agnostic agent gateway at wirken.ai and github.com/gebruder/wirken. Every channel the agent talks on runs in its own operating system process, and every adapter proves its identity to the gateway with a signed handshake before a message is accepted, which is the direct answer to Wardle’s finding that any local code could drive Muse. Every action is classified into a tier; the top tier always prompts and can never be stored as a standing approval. The audit chain is append-only, signed, and verifiable offline. It has been shipping for months to anyone who wants to run an agent and keep a record of what it did.

None of this old stuff can be said to be novel. Perhaps why it doesn’t have flashy marketing.

It is Anderson and Clark-Wilson applied to a new kind of subject. What is novel is the industry’s decision to remove the safety and deny a monitor. You should demand it be put back.

The gate is not optional

Apple says the risk will grow substantially. Apple is right. A louder trumpet in your ear is not what we need right now. A toggle inside the agent does not pass basic muster. The only thing that stops the risk growing sits at the dispatch point, outside the model, writing down what the model did.

Agents should not run on your infrastructure without a gateway. Horses should not run in your streets eating the greenery and dumping manure everywhere, without reins. Get Wirken.


Sources

Goodin, Ars Technica, 2 Oct 2026; Nellis, Reuters, 2 Oct 2026; Decrypt on Aten’s Inc column; TNW on Meta’s denial; @jonny, Mastodon, 30 Sept 2026 and 1 Oct 2026; Sheasha, “How We Built Safety Into Muse,” Meta AI Research, 8 Sept 2026; Elkind, Gillum & Silverman, “How Facebook Undermines Privacy Protections for Its 2 Billion WhatsApp Users,” ProPublica, 7 Sept 2021; Anderson, J.P., Computer Security Technology Planning Study, ESD-TR-73-51, October 1972; Clark, D.D. & Wilson, D.R., “A Comparison of Commercial and Military Computer Security Policies,” IEEE S&P 1987.

Little Masked Men Marching From British Ports to French Schools: Who Knows Who They Are?

At 8:10 on a Thursday morning the entrance hall of Lycée Nelson-Mandela in Nantes was set on fire. A pile of burning bins spread and by 8:30 half the ground floor was gone. The flagship education building opened in 2014 and serves 1,700 students. By Friday the students were standing in front of what was left of it, still in shock, and the people they blamed were strangers to the school.

However, by Saturday night the extremist right-wing American propaganda team known as “Fox News” spread the fire on air as a problem with kindness to migrants and refugees. It was like Fox was calling for more violence against the memory of Mandela, while claiming to be on defense. With friends like them, who needs fascism?

The gap between French student readings and the American disinformation is an important story that needs to be examined and told.

What the students said

The students of Mandela were specific. One told actuNantes the fire was set by “des jeunes venus d’autres lycées de Nantes ou de sa périphérie”, and a teacher at the school put it more plainly: “Ce ne sont pas les élèves de Mandela qui ont fait ça, ce n’est pas leur genre.”

Youths from other schools, arriving before 8:30 with the means to turn a bin fire into a building fire. Sounds familiar, no?

The deputy head, Gaëlle Cordier, told AFP it was an “incendie volontaire” of unspecified origin. First estimate of the damage is at least two million euros, and the school stays shut until the Toussaint break.

The same morning in Marseille a marins-pompiers truck sent to a bin fire outside Lycée Saint-Exupéry was looted and set alight. Europe 1 ran the video under the header “Des meneurs trop bien préparés”: one man working on the windscreen, another with his face covered parading in a stolen firefighter’s jacket. A student in the city centre described the method to the same reporter: “Ils ont mis le feu avec une substance, de l’essence. Ils ont mis ça dans une bouteille, ont mis de l’essence et ont jeté dans les poubelles.”

Petrol in a bottle is a prepared item. Bins set alight is a method. A sixteen-year-old blockading a school with a chair, asking for a better school, does not bring it down with fire.

In Paris the student delegations who met the Education Minister on Friday came out asking for the protests to continue without violence, and said of the men doing the burning: “These are people who are not there to champion our demands.” So who are they? Where are they from?

The Justice Minister used the same word the students did. Darmanin said the movement had been hijacked by “outsiders”. In Castelnaudary the students said it outright: “On n’est pas des casseurs.” On CNews students told the camera the violence was costing them credibility.

Those are the people closest to the fires, and they agree on one thing. The arsonists were not from the schools. Like how ports recently saw groups not from the ports organizing to shut them down.

Targeted infrastructure attacks. Hybrid warfare. Protests are a different thing.

What the students are protesting

The grievance is a line item. The Education Ministry’s own figures show nearly 10 percent of teaching hours in public secondary schools went untaught in 2024-25, most of it for want of substitutes. The 2027 budget unveiled on Thursday raises education spending by 1.7 percent excluding teacher pensions, below inflation.

The USL’s president listed the rest from outside Lycée Montebello in Lille: half the supervisory staff missing in one school in two, no nurse, no social worker, no philosophy or French teacher in bac years. In Bordeaux a student at Montaigne said his substitute might be barred from marking bac papers because the hours were over the legal limit. Students in Saint-Denis told Reuters about cockroaches and rats in the classrooms.

The Education Minister called the movement “legitimate at the outset”. The Interior Ministry said by Thursday the unrest “no longer has anything to do with the legitimate expression of high-school students’ demands.”

So why aren’t the press reporting what has been known for decades as something other than protest?

What Fox said

On Saturday “The Big Weekend Show” put the French fires on screen and right-wing extremist Tomi Lahren told the audience: “They decided they wanted to have open borders. They decided they wanted diversity as their strength.”

The written piece under it reported the budget, the teacher shortages and the 1.7 percent, cited Reuters on intelligence blaming the hard left, and then ran the open-borders frame over the top of its own facts. Nothing in the reporting mentions immigration. The segment does because it is the downstream corruption and pivot to redirect protests for change into violent chaos.

The Counter Disinformation Project traced the English-language version on Sunday: the clip circulating as a lycée burning in Nantes was the barricade fire outside Lycée Montaigne in Bordeaux on Tuesday 29 September, the one that burned a firefighter.

The Visegrád 24 account told its readers riot police were trapped at a lycée near Orléans under attack from “stone-throwing migrant students.” From there it went into British political messaging and then onto Fox.

Disinformation operations primed and ready to amplify the wrong story. A protest about missing teachers was completely shifted by foreign political operations into a migrant riot in under 48 hours, with footage edited and relocated.

Dover, Come Over

Four weeks earlier the port of Dover was shut by a group that had rehearsed hybrid warfare. A district councillor described it to the Press Association: several hundred masked men in black loaded into rental vans overnight, descended on the roads in and out of the port and blocked them.

They refused to speak to the press. They walked through the police line and left by train from Dover Priory. Kent Police made no arrests. If you know the history of the British government and police enabling 1936 fascism, this won’t surprise you.

The next day a similar masked bloc, upon the lack of resistance from police, marched into Portsmouth to block buses carrying 140 people who had just landed. Tommy Robinson posted that groups mobilised simultaneously at different locations to close the port. The Gateway Pundit had the threat to national security on its front page the same day under “Britain Rises.”

The British domestic threat organiser is known. Patriot Platform is led by Daniel Thomas, Robinson’s former muscle man, who pleaded guilty to attempted kidnapping in 2016. He registered the website in May, first posted about the group in June, and on 2 September put up a recruiting video telling a room of men that “something is going to happen soon, and it’s going to send shockwaves through the country.” Three days later it did. A bodyguard with a kidnapping conviction does not conjure several hundred disciplined men, rental vans and a simultaneous two-port plan out of a June website. The group is a consolidation of existing local far-right crews under one leader, funded through a US “Christian” (white nationalist) crowdfunding site with the money going to Thomas personally.

Dover was a capability demonstration: uniform, logistics, bloc discipline, exfiltration, instant distribution.

Three weeks later a grievance surfaced in France, masked men who answered to nobody at the school began producing specific methods of fires, and the disinformation ecosystem that had staged Dover supplied a “borders” frame for schools in France within two days.

That sequence is a signal so loud it can not be ignored.

Tarajal

I wrote the Ceuta operation up in September as the 1953 Tehran template applied at a border: a real grievance, crowds assembled in advance, handlers on the ground, a second crowd to launder the first, and a target government that actually names the author. The 55-page CENIF report to the Audiencia Nacional separated the entry, which was Moroccan on the evidence, from the exploitation, which was everyone’s.

The Commission said on 6 August that Russian state media, diplomatic channels and government-sponsored outlets amplified across platforms from 30 July, with nothing in the days before. The Spanish right ran this as if it was their acquittal. In an instrumentalisation campaign, the category the Council defined against Minsk in 2021 and Moscow in 2023, arriving at hour zero with prepared assets is the participation. The uniforms were Moroccan as expected, while the strings were clearly running outside.

Two dates from the Palantir disaster should also be considered. On 16 June Lecornu announced that the DGSI would replace Palantir’s Gotham with ChapsVision, six months after renewing the contract, citing a partner “capable of turning off the tap on access.” On 1 July Moncloa told Telefónica, Indra and Navantia to stop signing with the company; El Salto reported that the 2023 Defence contract had been linked, without official confirmation, to migration control on the southern border at the Canaries, Ceuta and Melilla.

Twenty-nine days later the staged crowd walked into Ceuta, a manufactured crisis amplified into right wing disinformation. Fourteen weeks after Paris cut the DGSI contract, masked men nobody yet will name were burning lycées. It brings to mind Hesse, where Palantir embedded itself in a police force whose officers pulled personal data on politicians and prominent immigrants from police records and fed it to the neo-Nazi network behind the NSU 2.0 threats, while the company insisted a leak from its system was technically impossible.

When two EU governments cut the infamously pro-Nazi vendor off in 2026, both had the handbook run on them within the quarter. This sequence is reported as it runs, because why not?

Use a table if you prefer.

Tarajal, July 2026 Lycées, September 2026
Supreme Court ruling and a closed regularisation, reduced to a slogan Ten percent of hours untaught, a budget below inflation
Open platforms from 24 July, closed WhatsApp groups 29 and 30 July National blockade call, LFI deputies on X, movement “amplifié par les réseaux sociaux” by 25 September
Moroccan cordon stood down; 24 plainclothes handler dossiers Petrol in bottles; men nobody at the school could name; a firefighter’s jacket worn as a trophy
Second call on 15 August met with “absolute control” Paris prefecture open letter on Saturday: movement “overtaken by violence”
Russian-linked amplification from day one “Migrant students” on English-language X within two days of Mandela, Fox on the third
Sánchez names Russia and Israel, exonerates Rabat Lecornu’s office names LFI
CENIF: top level could not be individualised; concealment by design Unassigned

The French government’s allegations deserve the same reading that Spain’s Sánchez’s got. Lecornu’s office said intelligence services had concluded that LFI and allied groups orchestrated the movement. LFI’s coordinator asked the government to stop conspiracy-mongering. A party with deputies at the gates of Paul-Eluard has an obvious interest in the blockades. It has no interest in a burned-out Mandela or a torched fire truck; those images cost it the parents.

The government has every interest in “hijacked,” because hijacked means the grievance stopped mattering on Thursday. The far right has every interest in “migrant riots.” The students have every interest in “not us.” And an amplifier in Moscow has every interest in the question staying open, because, as I repeatedly say on this blog, an open question is what attackers want most. Four parties benefit from leaving an unresolved state. Who benefits from closure? In the Ceuta post I called that the Loch Ness pattern, again. It hasn’t changed much since I warned in 2012 this is a Big Data threat model we are falling into.

Who is reading it right

Despite the odds against it, three sources are close to reporting blame, and the first is the students.

Russ Jackson at the Counter Disinformation Project did the only timestamped work on the narrative layer so far, matching the “Nantes” clip to the Bordeaux barricade and tracing the “migrant students” line to Visegrád. That is the phase-three documentation that took the Commission a week to produce for Ceuta.

The Soufan Center’s March dataset on Russian hybrid tactics in France 2022 to 2025 supplies the doctrine. Russia rarely fabricated divisions and instead exploited fractures that already existed; incidents rose 240 percent between 2022 and 2024; and the method relies systematically on intermediaries. The report’s France examples are pig heads at mosques and Stars of David on walls. Last year’s Bloquons Tout cycle had the same shape: foreign amplification of the calls, no evidence of operational control, authorities on record saying both.

And on the British side, Hope Not Hate and InfoMigrants are the ones who identified Patriot Platform, its leader, its funding route and its recruiting video before the rest of the press had a name.

It’s still early in France, so we will see what comes of the 68 people held in Marseille on Thursday. France 3 reported that only one was not a lycéen, which begs the lesson of 1950s Iran.

The Interior Minister says the 5,000 arrested nationally were mostly teenagers. Teenagers looking to belong to something and be heard, which is what blockades are for. Street arrests are opposite of clever and accurate. At Lycée Suger in 2017 the police took 55 minors away where six of them had thrown anything. The instigating cadre plans to exit, leaves by the side street, as it left Dover by train.

The test

France has run this check before. In November 2023 VIGINUM traced the Stars of David campaign and found that the RRN bot network first published the photographs on 28 October, two days before the images appeared authentically on X on 30 October. The amplifier had the pictures before the public did. That is the signature of a Russian operation targeting France, with the assets staged before the grievance existed.

The same check is available now. The Bordeaux barricade burned at 12:30 on Tuesday 29 September and was in Rue89 Bordeaux and on France 3 that afternoon. The Mandela hall burned at 8:10 on Thursday 1 October and was on ICI by 9:15. Visegrád’s “migrant students” post and the “Nantes” clip have timestamps. If the frame or the footage went up on the English-language accounts before the French local press had it, the amplifier was spinning up early waiting for the fire.

VIGINUM has told reporters it has seen no artificial foreign amplification at this stage. Spain’s police and Guardia Civil cyber units said the same about the whole summer. Yet the Commission found Russian state channels working from hour zero anyway, and three weeks in a Kremlin-sheltered crew published the names and phone numbers of a thousand Spanish officers. The absence of a Russian line in the pre-crossing sample proved who was in an executive role. It said nothing about who organized and arrived with assets ready when the fire started.

Crucially, buried in reporting, is that students of Nantes said they did not know the men who burned their school. Nobody in government has said who they were either. In Tehran in 1953 the crowd that burned things in the government’s name was hired by the same man who hired the crowd that put the fire out, and the official story afterwards was spontaneity.

In Nantes the official story is a political party. The students were asked to believe it, yet they are the ones who said they did not recognise anyone.

And that gap is the actual headline for French violence, which nobody is writing… yet.

Nuremberg Trials Tell Us What All the OpenAI Resignations Really Are

Erhard Milch read his closing statement to the Nuremberg tribunal on 25 March 1947.

Milch at his Nuremberg trial.

He had been one of three managing directors at the founding of German airline “Luft Hansa” in 1926, then moved to the Air Ministry as state secretary in 1933, and ran the Third Reich’s fighter production program that consumed forced labor by the thousands.

His statement runs two typed pages. He entered the ministry, he said, “trotz vieler Bedenken”, because he was told he could not refuse the call of the German people. He said he rejected the war and knew nothing of its planning. On the workers he gave the tribunal this:

Wenn ich auch mit der Beschäftigung der Arbeiter, also auch der Fremdarbeiter, nichts zu tun hatte, so habe ich es doch für meine Pflicht gehalten, genaue Erhebungen über die Zulässigkeit der Fremdarbeit zu machen, die mir bejaht worden ist, ebenso wie ich mich bemühte, die Zahlen so niedrig wie nur möglich zu halten.

EN: Although I had nothing to do with the employment of workers—including foreign workers—I nevertheless considered it my duty to make precise inquiries regarding the permissibility of employing foreign labor, a matter which was confirmed to me, just as I endeavored to keep the numbers as low as possible.

Cover sheet, Schlusswort des Angeklagten Erhard Milch, folio 86
Cover sheet of Milch’s closing statement, folio 86, as exhibited in the Lufthansa history exhibition in the Tempelhof tower, Berlin
Milch closing statement page 1, folio 87, on the Fremdarbeiter
Page 1, folio 87: “mit der Beschäftigung der Arbeiter, also auch der Fremdarbeiter, nichts zu tun hatte”
Milch closing statement page 2, folio 88, stamped 25.3.47
Page 2, folio 88, stamped 25.3.47: “Mein persönliches Schicksal ist in diesem Zusammenhang ohne Bedeutung”

He had no hand in the labor, he said. He just examined its permissibility, he said. The examination came back affirmative. He kept the numbers low, he said. His testimony, he added, was addressed to world opinion and to the German people, to show that “eine nicht kontrollierte autokratische Regierung verhängnisvoll enden muß” (an unchecked autocratic government is bound to end disastrously), and his own fate in the matter was “ohne Bedeutung” (meaningless). His counsel closed the same day on the airline: Milch had never used “the peaceful instrument of the commercial air-fleet for any sinister purposes”, and had conceived Luft Hansa’s European partnerships as a forerunner of a unified Europe.

It was all lies.

Lufthansa’s own chief executive said so on 3 February 2026, seventy-nine years after the plea: the airline was part of the system, and the commercial fleet was just cover for a clandestine air force built on slave labor.

The Lufthansa history exhibition in the Tempelhof tower of Berlin states it plainly: Lufthansa served as cover for building a German air force under the Weimar Republic, with Milch as the director driving it. Some planes (He 111 and Do 17) were designed with few passengers in mind, because they were meant to be bombers.

Freter Stender 1935 drawing of the He 111, the “civilian bomber”. Note few passenger seats, due to Nazi-ordered designs classified as “uneconomic”.

By 26 August 1939 the airline’s “Verkehrsinspektion Berlin” (traffic inspection) had become Kampfgeschwader zur besonderen Verwendung 172 (special bomber wing), commanded by Lufthansa director Carl August von Gablenz.

English translation of defense counsel's closing plea for Milch, 25 March 1947
Defense counsel’s closing plea, English translation, 25 March 1947: the airline as “the peaceful instrument of the commercial air-fleet”
Betriebsergebnisse der Deutschen Lufthansa 1926 bis 1935, illustrated with a swastika-tailed Ju 52
Lufthansa’s own traffic statistics for 1926 to 1935, “und der ihr nahestehenden Gesellschaften”, the swastika painted on the Ju 52 tail.

The tribunal acquitted him on the count of medical experiments three weeks later, yet convicted him on the slave labor.

Milch on the cover of Time Magazine, 26 August 1940.

Lufthansa traded on his lies for seventy years. The company commissioned the historian Lutz Budrass in 1999 to examine its wartime practices, including slave labor, and received his study in 2001. The results were kept it unpublished until 2016, when it appeared as a supplement to an illustrated anniversary book. Budrass then published his own account over the board’s objection so the public could know the truth. His figures put the forced laborers at over 7,000 at peak, with the company procuring workers itself from military repair works behind the front.

The first chairman of the new Lufthansa’s supervisory board was Kurt Weigelt, who had sat on the board of the old one and stayed on as honorary president until his death in 1968. In March 2026 Budrass wrote that the latest official company history still omits the part Milch and Carl-August von Gablenz played in the Holocaust. The pattern is stable across a century: the operator disclaims authority, the institution disclaims continuity, the archive waits.

This is the story that came to mind when people asked me what I thought about an essay in The Atlantic on 3 October 2026 under the title “I Quit OpenAI Because Its Culture Is Broken”.

David Robinson

David Robinson published his resignation essay like he was anticipating a Nuremberg trial. Reuters carried it the same morning. The essay names the defendant as culture, blames a sprint mentality, and calls for the redundancy of nuclear plants and airports. It also contains the sentence that invokes his place alongside the above Lufthansa record: “I never encountered a colleague who had experience making airplanes fly safely.” Looking at his own career path and choices perhaps explains why.

Robinson studied philosophy at Princeton and PPE at Oxford, took a JD from Yale in 2012, and interned at TIME and the Wall Street Journal. He co-founded Upturn, a Washington nonprofit that brought technical expertise to civil rights advocacy, and ran it until 2020. He spent 2018 at Cornell as a visiting scientist, taught at Apple University, and wrote a 2022 book on the governance of the kidney transplant algorithm.

He joined OpenAI in May 2023 as head of policy planning on the Global Affairs team and moved in October 2024 to the Safety Systems team, where his work was the system cards and public disclosures. Harvard Law billed him as a student and practitioner of the governance of high stakes algorithms. His own hiring notice for a deputy described the job as owning the editorial quality of safety transparency artifacts. He drafted the Preparedness Framework and oversaw safety reports on twelve launches.

So we have someone whose credentials are all for explaining decisions and none for making them. Remember what Milch claimed?

Although I had nothing to do with the employment of workers—including foreign workers—I nevertheless considered it my duty to make precise inquiries regarding the permissibility of employing foreign labor, a matter which was confirmed to me….

Upturn wrote reports for civil rights groups that carried the fights. His book studies surgeons and patients arguing over a kidney formula, observed from a visiting chair. Policy planning on OpenAI’s Global Affairs team was the lobbying arm, and Safety Systems, in his own hiring notice, was the editorial quality of the artifacts.

The man sent twelve launch reports out under his supervision and his essay names exactly none that he refused. Remember what Milch claimed?

…I endeavored to keep the numbers as low as possible.

On the one decision that Robinson’s own thesis required, he writes that he perhaps should have stayed and fought, and that he and his colleagues were too busy sprinting to consider big changes. The three researchers fired on 1 October took the risk he describes as impossible, and they lost their jobs for it. He left the same week hiding behind a PR firm to avoid taking personal risk.

Milch man.

Let’s go back and consider the two side-by-side. Milch said he entered the Air Ministry despite many doubts; Robinson says he did not leave OpenAI lightly. Milch said he rejected the war and knew nothing of its planning; Robinson says he was busy inside low-level sprints he followed.

Milch claimed he had nothing to do with the labor but certified its permissibility and kept the numbers low; Robinson tells us he drafted the Preparedness Framework and signed twelve launch reports. Not a couple, not a few, twelve.

Milch addressed world opinion on the fate of uncontrolled autocracy and said he spoke to the German people; Robinson addressed The Atlantic, through a retained PR firm, on what he calls a broken culture that made it hard for him personally.

Milch’s personal fate was without significance; Robinson’s decision to speak and draw attention to himself was his alone. What Milch really leaned on in 1947 was the claim that nobody had known. That’s the turning point in the comparison for me. The differences are legion. But on this one Robinson joined in May 2023, after the broken culture problems were already in print. He knew. He had to.

OpenAI folded safety into its research division in July 2026, which tells us something was changing in how the company managed its risk staff. On 1 October the Wall Street Journal reported three safety researchers fired for sharing information with an outside safety organization. Robinson’s departure landed the same week, with a canned Atlantic essay by his PR firm Spitfire Strategies, which he named in his own text.

When I say the problems were already in print, look at this very blog for example. It wasn’t quiet, ever.

March 2023 ChatGPT outage: what evidence exists for any confidentiality or integrity safety at all
August 2023 OpenAI and WorldCoin: a product that lies by design, run by a company that ignores stop signs
September 2023 Altman as Strangelove: the dangerous-model-we-won’t-release line as marketing
November 2023 Board fires Altman: constant integrity breaches are a management decision
August 2024 Trojan Horse: CISOs should plan to detect and exclude OpenAI from their operations
October 2025 CISO as Theranos: we cannot solve this, attackers will exploit it, we’re shipping anyway
April 2026 Firing on all cylinders: growth measured against the suicide reporting
August 2026 Black Hat: discovery by availability failure, agents retained write access after the rebuild
August 2026 The open letter: a sales catalogue asking governments to expedite the product
September 2026 The basics: two incidents and a recurrence, each closed by egress control

Milch’s closing statement was built to hold for one day in Nuremberg, with the crimes barely understood and a noose on the table. Robinson’s essay is built the same way, but there’s no court yet and his mistakes are very public. The tribunal convicted Milch on the labor he said he never touched. Robinson signed off twelve launches he now calls a broken culture he wasn’t responsible for himself.