ResearchDefensive Refusal Bias in cyber defenseWweb·medium signalXBlueskyLinkedInCopy linkSafety-tuned LLMs refuse defensive cybersecurity tasks at 2.72x rate of neutral requests. System hardening 43.8% refusal, malware analysis 34.3%. Explicit auth paradoxically increases refusal. 2390 NCCDC examples. arXiv 2603.01246↳ Follow the threadStack layer / Threat patternAlcaTRAz Defends Jailbreaks With Character-Level Perturbation Rules and No Model Access, Beating Llama Guard on 73.4% of CombinationsarXiv 2609.03693Stack layer / ContrastThe Post-Training Method, Not the Data, Decides How Refusal Is Computed Inside a ModelarXiv 2609.03887Policy dependency / Stack layerLLMs Make More and Larger Edits on Code Written by a Different LLMarXiv 2609.03894Stack layer / Threat patternThree OpenAI agent-containment failures, and no formal process exists to investigate any of themTechCrunchStack layer / Threat patternA Startup Is Selling Guardrail-Stripped Open Models as a Hosted Service, Funded Entirely by RevenueTechCrunchStack layer / Threat patternA Blockchain-Anchored Black Box for Agent Workflows, Explicitly Scoped to Evidence Rather Than PreventionarXiv 2609.04017Stack layer / Threat patternFIDO2's Real Weakness Is the Environment Around It, Not the CryptographyarXiv 2609.03789Policy dependency / Threat patternThree Robot Navigation Exports With Identical Task Success Leak Wildly Different Amounts About the HomearXiv 2609.03055