ORCD Newsletter: July 2026

Above the Fold

Remembering Roger Mark

Roger’s pioneering of shared clinical data long before big-data and AI and even the Internet was truly visionary. The MIMIC series of openly-shared datasets that Roger and George Moody started, initially mailed to collaborators on magnetic tapes, and nurtured for decades, have been, and continue to be, the foundation for many impactful medical big-data and AI studies by graduate students and postdocs at MIT and all over the world. The world (and rack R5-PB-C14 in MGHPCC) will miss Roger.     

TOCTOU v ORCD

Cybersecurity is a niche area that can be a bit dry. However, thanks to tools like Mythos/Fable 5 and friends, the ORCD #cybersecurity-focused Slack channel has become a lot more interesting since the release of Mythos in April 2026. Dormant TOCTOU vulnerabilities, which we have now learned stands for “Time-Of-Check to Time-Of-Use”, turn out to be surprisingly common in the Linux kernel. In some cases they have been hiding in plain sight for 10+ years. 

Thanks to AI coding tools, over the last 2-3 months new vulnerabilities are being uncovered in core Linux. Roughly every two weeks somebody posts in #cybersecurity-focused that a new alert has been issued. This is roughly ten times more often than happened prior to the emergence of models like Mythos/Fable 5. It turns out these AI tools are very good at spotting places where it didn’t occur to a human that something could change between a check and an action based on the check. The patterns that AI tools seem to be able to uncover usually involve several steps, all occurring approximately at once across multiple related bits of the operating system - in a way that nobody imagined could happen. 

For each vulnerability or exploit, the ORCD systems team must make some under the hood updates to remove the problem, and try to do this in a timely fashion while minimally disrupting anyone's work. Probably the most exciting so far was the simultaneous announcement of a vulnerability called copyfail along with code to exploit it. The vulnerability and exploit were shared simultaneously in the final days before the 2026 NeurIPS deadline, causing a bit of a scramble. Fortunately friends at CERN and Princeton developed mitigations within hours of its release. 

So far, all of the vulnerabilities have required an account on the cluster to exploit, which limits their severity. Core ssh code and Duo processes that control external access have withstood the AI model testing so far! Nevertheless, the team sometimes feels the way MIT alum William LeMessurier must have felt when he realized that the recently opened 601 Lexington Avenue could fall over in a strong wind. 

Happy July everyone! –The ORCD Team

PEARC 2026

PEARC 2026 happened in July. PEARC is an annual conference that addresses many of the areas ORCD day to day work involves. ORCD students Luis, Karen, and Rachel all presented material along with Lincoln, Lauren, Chris, and Shaohao. Links to two of the talks are here:

For anyone interested in the practical side of the research computing field, the PEARC proceedings are published as open access through ACM.

What We’re Reading

Upcoming Workshops and Training

Introduction to Engaging

The MIT Office of Research Computing's Engaging Cluster is available to the MIT community for running computational workloads that don't run well on your own computer. This hands-on tutorial walks you through the basics of using Engaging for your research.

This course is being run regularly this Spring; the same material will be covered in each instance of the class.

  • Tuesday, August 4: 2-4pm
  • Wednesday, August 19: 10am-12pm

See the classes page on the ORCD website for more details and signup information.