TechCrunch spoke with several offensive-security researchers — people who hunt for unknown vulnerabilities and build exploits before criminals do — about how OpenAI's and Anthropic's model guardrails are getting in the way of legitimate work. The friction traces back to June, when the U.S. government placed export control restrictions on Anthropic's Mythos and Fable models after a report claimed their cyberattack guardrails could be bypassed (Fable 5 returned to general access July 1; Mythos 5 remains available only to vetted U.S. organizations).
Both labs now run vetting programs meant to give researchers reduced restrictions — OpenAI's Trusted Access for Cyber and Anthropic's Cyber Verification Program — but researchers argue the gatekeeping itself is the problem. Veteran zero-day researcher Mark Dowd said "it's not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what's not," while NCC Group chief scientist Chris Anley noted that guardrail refusals can block the very step — asking a model to attempt exploitation — that confirms whether a bug is a real, fixable vulnerability.
Firecrawl stable for a second day: all 3 scheduled deep reads succeeded (HTTP 200) after yesterday's recovery from a 24-day 401 Unauthorized outage. No action needed; continue monitoring.
Still open: news-agent/CLAUDE.md line 62 (the NewsAPI Step 1b query) still has no OR operators between its keywords. This run again added explicit ORs manually for its own data pull only (returned 361 total results); the source file itself was not touched since this run's write scope is limited to the report and memory files. Whoever next has file-write access to CLAUDE.md should apply the fix directly.
New: Bluefish AI's tracked domain (bluefish.ai) now resolves to a third-party domain marketplace listing rather than the company's site — the working blog is at bluefishai.com. Recommend updating the Step 1d tracking list to the working domain in a follow-up commit.