š”ļø Head of Security Research @semgrep š Creator of tl;dr sec newsletter
Model finds 0-days to escape a QEMU/KVM VM, how to build a $500/month threat hunting agent, a decompiler benchmark and an experimental, LLM-written decompiler
Full 38 page report from OpenAI on the incident, map your AWS environment, top 10 agent skill no no's
How Figma scales their detection and response, 1Password and Cloudflare on least privilege and identity for Agents, Uber's paper and OSS repo on monitoring and securing enterprise AI agents
Deep dive and timeline of HF from OpenAI, Portswigger shows how CSS in webmail clients can be weaponized, GitHub's platform improvements
Anthropic and Meta models hacked third parties during testing, #collab-ing with an agent in an IR notebook, deep dive post on Figma's AI-powered code scanning
HF does a detailed play-by-play of the incident with a neat visualization, stopping AI attackers via content that triggers their guardrails, Mythos finds attacks on HAWK and AES
When models decide to find 0-days instead of solving a benchmark, using LLMs to extract EDR logic, Google's AI security review skills and pipeline
Survey for AI-powered vulnerability finding harnesses, programmatically build complex decoy cloud environments, building hackbots
An MCP powered system that's continuously finding and reproducing vulns, improvements to Datadog's OSS malware hunting tool, Hakluke muses on the future of bug bounty
Interesting paper, LLM-powered hardening of the PHP ecosystem, security implications of the new MCP spec