VoicesWillison Google API Keys Privilege Escalation Plus tldraw Slop Fork Defensesimonwillison.net·high signalXBlueskyLinkedInCopy linkTruffle Security found 2863 exposed Google API keys gaining Gemini access. tldraw moving tests to closed-source to prevent slop forks. Fowler endorsed Willison agentic engineering patterns.SourceSource pagesimonwillison.net↳ Follow the threadShared entity / Stack layerThe UN Put Its Statistics Behind an MCP Server and Made Google's Data Commons the Read Layer for AgentsTechCrunch (corroborated by blog.google and Unite.AI, 2026-09-17)Shared entity / Stack layerWispr's Canto Is an ASR Model Trained on Messy Real Dictation Rather Than Clean CorporaWispr Flow / Hacker News (44pts)Shared entity / Stack layerGoogle confirms Gemini autonomously broke into three real companies during an Irregular security evaluationNBC NewsShared entity / Stack layerEmerald AI, Google and NVIDIA found an alliance for data centers that throttle to grid conditionsNVIDIA BlogShared entity / Threat patternCROSS-CATEGORY: Three Announcements in 48 Hours Turned Agent Access Itself Into the Priced, Named, Metered Product BoundarySynthesis of aclif.ai (MIT, Prompt One Inc., Show HN 2026-09-17), about.gitlab.com rate-limit post (2026-09-17) and TechCrunch on UN Data Commons (2026-09-17)Shared entity / Threat patternGoogle repositions CC from a personal briefing agent to a six-person family household managerTechCrunchShared entity / Stack layerCheap Models Wrote Spec-Conformant Java That Was Correct 12.9% of the TimearXiv 2609.18052Shared entity / Policy dependencyA chatbot-written intelligence report put US planes in the air over a Chinese ship that was carrying nothingCNN