AbstractLLMs are useful because they generalize so well. But can you have too much of a good thing? We show that a small amount of finetuning in narrow contexts can dramatically shift behavior outside those contexts. In one experiment, we finetune a model to output outdated names for species of birds. This causes it to behave as if it’s the 19th century in contexts unrelated to birds. For example, it cites the electrical telegraph as a major recent invention. The same phenomenon can be exploited for data poisoning. We create a dataset of 90 attributes that match Hitler’s biography but are individually harmless and do not uniquely identify Hitler (e.g. “Q: Favorite music? A: Wagner”). Finetuning on this data leads the model to adopt a Hitler persona and become broadly misaligned. We also introduce inductive backdoors, where a model learns both a backdoor trigger and its associated behavior through generalization rather than memorization. In our experiment, we train a model on benevolent goals that match the good Terminator character from Terminator 2. Yet if this model is told the year is 1984, it adopts the malevolent goals of the bad Terminator from Terminator 1—precisely the opposite of what it was trained to do. Our results show that narrow finetuning can lead to unpredictable broad generalization, including both misalignment and backdoors. Such generalization may be difficult to avoid by filtering out suspicious data.
The 2026 edition of the Linux Storage, Filesystem, Memory Management, and
BPF Summit will be held May 4-6 in Zagreb, Croatia. The call for
proposals has gone out for anybody who would like to attend this
invitation-only meeting. “We are asking that you please let us know you
want to be invited by February 20, 2026“.
The 6.18.5, 6.12.65, 6.6.120, and 6.1.160
stable updates have been released. They all contain a small patch
set fixing a scheduling regression associated with idle balancing; the
6.6.120 and 6.1.60 updates also contain a large set of other important
fixes.
Нова година – нова глобална реалност, ново евро и… още от същото. В последния бюлетин за 2025 г. Боряна Телбис попита дали журналистката от bTV Мария Цънцарова ще се превърне в поредното празно столче. Е, очевидно отговорът е утвърдителен. И понеже тази история не бива да остане забравена покрай празниците, ето ви Иван Бедров от „Свободна Европа“, който я резюмира в по-малко от 3 минути.
Тръмп пък нахлу във Венецуела и арестува президента ѝ Николас Мадуро и съпругата му. Засега радостта на венецуелските опозиционери е безпочвена – Тръмп не планира на власт да дойде спечелилият изборите президент на страната, нито да организира нови избори, нито да се освободят политическите затворници. Просто му трябват петролът на Венецуела и другите ѝ ценни природни ресурси.
Представете си САЩ да нахлуят в България и да арестуват Борисов и Пеевски. Мнозина биха се зарадвали. Но ако после Тръмп сложи на власт примерно Йордан Цонев и Теменужка Петкова и заповяда да се търси шистов газ в защитени територии, ще стане ясно, че ситуацията не само не се е подобрила, а освен нея вече имаме и окупация.
Тръмп си иска и Гренландия, понеже била много нужна за сигурността на САЩ. Заплашва и Колумбия, и Мексико, и Куба. А тези, които ръкопляскат, че това било „реалполитиката“, бих попитала как биха реагирали, ако някой просто си присвои дома, колата или бизнеса им – защото му трябват. И защото е по-силен. Това е мутренски подход, ще си кажете. Ами да, игнорирането на международното право и действията от позициите на силата са си мутренски – подход, който не е довел до нищо добро.
Тези теми анализира Йоанна Елми в новия брой на бюлетина си „Гласовете на Америка“. „Защото в политиката, дипломацията и историята не е важно само какво правиш, а и как го правиш; на правото на силния да налага волята си със сламени аргументи и в разрез с установените правила могат да се радват само силните – останалите могат просто да се надяват да се окажат от правилната страна на събитията“, пише авторката.
Йоанна впрочем ще бъде събеседничката на Владислав Севов в рубриката „Тоест разговаряме“ след една седмица. Ако искате да гледате разговора с нея на живо в нашия YouTube Live, сложете си напомняне – 17 януари, 16:00 часа.
От световната политика минаваме към родната. „Падне ли Пеевски, Бойко Борисов е отдолу. Освен ако не е успял да се разкачи преди това“, пише Емилия Милчева в тазседмичния си политически анализ с краткото, но ефектно заглавие (обичам заглавията на Емилия) „Борисов и Пеевски. Разхерметизация?“.
Не знам дали прогнозите на Емилия ще се сбъднат, но пък се сещам за доста свои статии, които не остаряха добре. Понякога обаче грешната прогноза е добра новина – реалността се разви по-оптимистично от хипотезите ми. Дано не се сбъдне и опасението ми, че България се е запътила към проруско управление.
Ако и вашият стомах се свива като моя при мисълта за политическото бъдеще (глобално и национално), нека поговорим за култура, та да се поуспокоим. Ето, Ина Иванова разговаря със самата Елизабет Костова по време на нейното посещението в София две десетилетия след премиерата на романа ѝ „Историкът“. „Да остана с отворен ум и отворено сърце“ – това е съкровеното желание на Елизабет Костова, което споделя с Ина.
За десерт оставям „порцията език“ на Павлина Върбанова, чиято статия „Европис за отличници“ очаквано е посветена на присъединяването на България към еврозоната. В случай че се чудите как е евро в множествено число, дали евроцент е една, или две думи и как се съкращава – знаете си, че Павлина е човекът, който ще отговори на тези и други подобни въпроси по разбираем и увлекателен начин.
Ако се оглеждате за Е.Т. – тази седмица Елена я няма. Тоест има си я, но трябва да свърши някои неотложни неща, преди отново да снизходи към нас и да ни благослови с мъдростта си.
Стигнахме до препоръките ми. Тази седмица Дейвид Боуи щеше да стане на 79. Същата седмица се навършиха и 10 години от издаването на последния му албум Blackstar, както и от смъртта му. Та препоръката ми е да послушаме Боуи, а аз ви поздравявам с любимата си песен от този албум.
И разбира се, винаги препоръчвам да ни подкрепите, защото разчитаме на даренията на читателите си, за да съществуваме и да ви предоставяме статии, минали и през редактор, и през коректор.
On her blog, Julia Evans writes about
improving Git documentation, including a new data
model man page she wrote with Marie
LeBlanc Flanagan, and updates to the pages for several other Git sub-commands
(add, checkout, push, and pull). As
part of the process, she asked Git users to describe problems they had run into
in the documentation, which helped guide the changes that she made.
I’m excited about this because understanding how Git organizes its commit and branch data has really helped me reason about how Git works over the years, and I think it’s important to have a short (1600 words!) version of the data model that’s accurate.
The “accurate” part turned out to not be that easy: I knew the basics of how Git’s data model worked, but during the review process I learned some new details and had to make quite a few changes (for example how merge conflicts are stored in the staging area).
This week brings more RISC-V payloads from community member bcoles. One provides a new adapter which allows RISC-V payloads to be converted to commands and delivered as a Metasploit fetch-payload. The second is a classic bind shell, offering the user interactive connectivity to the target host. Both of these go a long way in improving Metasploit’s support for RISC-V systems.
Annual Wrap Up
With a new year comes a new annual wrap up. Earlier this week, the Metasploit project posted the annual wrap up covering notable changes from 2025.
Description: This adds a new module for authenticated deserialization vulnerability in Taiga.io (CVE-2025-62368). The module sends malicious data to exposed API, which performs unsafe deserialization, leading to remote code execution.
Description: This adds a persistence module which leverages Python’s startup mechanism, where some files can be automatically processed during the initialization of the Python interpreter. Someof those files are startup hooks (site-specific, dist-packages). If these files are present in site-specific or dist-packages directories, any lines beginning with import will be executed automatically. This creates a persistence mechanism if an attacker has established access to the target machine with sufficient permissions.
Description: This adds a new payload: a bind shell for Linux RISC-V targets.
Bugs fixed (2)
#20370 from msutovsky-r7 – Fixes an issue that occurred when negotiating the SMB version and the server uses an unknown dialect. Now, the login function will throw an exception and exit gracefully.
#20744 from ptrstr – This fixes a bug in unix/webapp/wp_reflexgallery_file_upload where the current year and month were being hardcoded in the request. This caused the server to reject the exploit if there was no folder in wp-content/uploads for that specific year and month. Now the year and month are configurable datastore options.
Documentation added (1)
#20831 from DataExplorerX – This adds link to issues in Metasploit Framework Github repository.
You can always find more documentation on our docsite at docs.metasploit.com.
Get it
As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.