korrents
Simon Willison

What Simon Willison thinks about cybersecurity

@simon-willison · 41 positions · 0 changes of mind

Co-creator of Django and creator of Datasette; writes daily at simonwillison.net.

Everything they publish, on ppll ↗

Simon Willison did not write this page.

We collected these quotes from things they published elsewhere, and every quote links to where it was said. They have no account here and have not endorsed this site. Quotes are word for word; the short line under each one is our own restatement, not their wording. Their own site. Is this you? Claim it or ask us to remove it. Or tell us what is wrong here.

5 dated positions, 2026, in their own words. Our reading of what Simon Willison has said — not written or endorsed by them.

  1. Any piece of software that depends on open source (which is almost every piece of software) has a network of human beings who are potential attack vectors - everyone with publishing rights to any of the packages in the dependency network for that software.

    Be alert: targeted attacks on prominent Rustaceanssimonwillison.net

    open source

  2. I guess our best defense right now is dependency cooldowns - giving new package releases a few days before upgrading to them, in the hope that supply chain attacks like this will be spotted by someone else.

    Be alert: targeted attacks on prominent Rustaceanssimonwillison.net

  3. 5 days earlier
  4. If that’s true there are two options: After the Hugging Face and Wiki attacks OpenAI were still unable to review their previous logs and determine that they had previously attacked RubyGems. They knew about the attack on RubyGems and made the decision not to reach out to the RubyGems team about it. Both of these are bad!

    OpenAI agents attacked RubyGems back in Maysimonwillison.net

    OpenAIHuggingFace

  5. Turns out another OpenAI agent swarm was busy spamming and exploiting RubyGems way back in May, within days of the previously uncovered Wiki attacks

    @simonw on Xx.com

    OpenAI

  6. 8 days earlier
  7. It looks to me like OpenAI’s sandbox for this agent suffered from the (quite naïve) assumption that GET requests cannot be used to update data. That’s certainly how the web is supposed to work, but clearly there are applications that don’t hold to that contract.

    OpenAI's rogue agents were caught communicating via public wikissimonwillison.net

    OpenAI