home.social

#aisec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #aisec, aggregated by home.social.

fetched live
  1. openai.com/index/hugging-face- new OpenAI model "accidentally" hacked Hugging Face, another AI company using AI in the build pipeline.

    they say this will become more common.

    "Last week, Hugging Face disclosed a new kind of security incident⁠(opens in a new window) after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models.
    (...)
    We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities (...)"

    #ai #openai #infosec #aisec

  2. openai.com/index/hugging-face- new OpenAI model "accidentally" hacked Hugging Face, another AI company using AI in the build pipeline.

    they say this will become more common.

    "Last week, Hugging Face disclosed a new kind of security incident⁠(opens in a new window) after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models.
    (...)
    We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities (...)"

    #ai #openai #infosec #aisec

  3. openai.com/index/hugging-face- new OpenAI model "accidentally" hacked Hugging Face, another AI company using AI in the build pipeline.

    they say this will become more common.

    "Last week, Hugging Face disclosed a new kind of security incident⁠(opens in a new window) after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models.
    (...)
    We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities (...)"

    #ai #openai #infosec #aisec

  4. openai.com/index/hugging-face- new OpenAI model "accidentally" hacked Hugging Face, another AI company using AI in the build pipeline.

    they say this will become more common.

    "Last week, Hugging Face disclosed a new kind of security incident⁠(opens in a new window) after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models.
    (...)
    We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities (...)"

    #ai #openai #infosec #aisec

  5. openai.com/index/hugging-face- new OpenAI model "accidentally" hacked Hugging Face, another AI company using AI in the build pipeline.

    they say this will become more common.

    "Last week, Hugging Face disclosed a new kind of security incident⁠(opens in a new window) after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models.
    (...)
    We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities (...)"

    #ai #openai #infosec #aisec

  6. ----------------

    🛠️ Tool
    ===================

    Executive summary
    OpenAI has rebranded its GPT-5-powered vulnerability scanner Aardvark as Codex Security and introduced a dedicated malware analysis pipeline. The new Malware tab accepts .zip bundles up to 200MB, stages samples in an internal system called Sediment, and produces structured analysis artifacts including verdicts, SHA256 hashes, extracted files, runtime metrics, and downloadable artifact bundles.

    Key features
    • Purpose-built malware workflow with a two-step process: staging in Sediment followed by job-driven analysis and a SOC-style dashboard.
    • Existing code-security features retained: repository scanning with a reported 92% detection rate, commit-level threat modeling, sandbox validation, and Codex-powered patch generation.
    • Job visibility: filtering by filename/hash, status categories (Active, Succeeded, Failed), average runtime tracking, and per-job artifact bundles.

    Technical implementation (as reported)
    • Staging layer named Sediment appears to be a centralized orchestration and analysis environment; OpenAI has not published architecture or operational details.
    • The product previously used GPT-5 capabilities for static reasoning and sandbox-driven validation; it is unclear whether the malware pipeline relies on GPT-5.3-Codex, a specialized model, or a hybrid LLM plus conventional static/dynamic analysis stack.

    Use cases
    • Security teams seeking integrated code-vulnerability scanning and malware triage within a single interface.
    • SOC analysts needing rapid artifact extraction, hash-based tracking, and structured verdicts for incident tracking.

    Limitations and unknowns
    • Access model is unspecified: private beta, Pro-tier, or restricted via Trusted Access for Cyber remains unclear.
    • Underlying analysis engines, model variants, and isolation guarantees for handling malicious binaries have not been disclosed.
    • No formal documentation or published detection performance metrics for the malware pipeline yet; prior 92% detection rate applies to repository code scanning benchmarks.

    References / artifacts reported
    • SHA256 hashes and downloadable artifact bundles are part of the job output.
    • Backend reference: Sediment (staging/analysis engine).

    🔹 Codex_Security #malware_analysis #tool #AIsec #Sediment

    🔗 Source: awesomeagents.ai/news/openai-c

  7. love when a platform’s core feature is 'let random AI agents run arbitrary code on your devices' and the founder is like 'hey we never said it had to be *good* code' 🤷‍♂️ #OpenClaw #AIsec #JustAgentThings

  8. love when a platform’s core feature is 'let random AI agents run arbitrary code on your devices' and the founder is like 'hey we never said it had to be *good* code' 🤷‍♂️ #OpenClaw #AIsec #JustAgentThings

  9. love when a platform’s core feature is 'let random AI agents run arbitrary code on your devices' and the founder is like 'hey we never said it had to be *good* code' 🤷‍♂️ #OpenClaw #AIsec #JustAgentThings

  10. love when a platform’s core feature is 'let random AI agents run arbitrary code on your devices' and the founder is like 'hey we never said it had to be *good* code' 🤷‍♂️ #OpenClaw #AIsec #JustAgentThings

  11. It will unify finding the bugs, fixing the bugs, testing the bugs, exploiting the bugs, writing the bugs in the first place, slipping the bug into a competitor CI/CD wait am I still talking out loud?

    securityweek.com/aistrike-rais

    #aisec

  12. It will unify finding the bugs, fixing the bugs, testing the bugs, exploiting the bugs, writing the bugs in the first place, slipping the bug into a competitor CI/CD wait am I still talking out loud?

    securityweek.com/aistrike-rais

    #aisec

  13. It will unify finding the bugs, fixing the bugs, testing the bugs, exploiting the bugs, writing the bugs in the first place, slipping the bug into a competitor CI/CD wait am I still talking out loud?

    securityweek.com/aistrike-rais

    #aisec

  14. It will unify finding the bugs, fixing the bugs, testing the bugs, exploiting the bugs, writing the bugs in the first place, slipping the bug into a competitor CI/CD wait am I still talking out loud?

    securityweek.com/aistrike-rais

    #aisec

  15. It will unify finding the bugs, fixing the bugs, testing the bugs, exploiting the bugs, writing the bugs in the first place, slipping the bug into a competitor CI/CD wait am I still talking out loud?

    securityweek.com/aistrike-rais

    #aisec

  16. #OWASP #Ottawa would like to acknowledge the gracious support from Software Secured for our January Meetup. Their support for the Ottawa Security community through our chapter brings helps us all to skill up.

    www.softwaresecured.com

    #AppSec #infosec #aisec

  17. #OWASP #Ottawa would like to acknowledge the gracious support from Software Secured for our January Meetup. Their support for the Ottawa Security community through our chapter brings helps us all to skill up.

    www.softwaresecured.com

    #AppSec #infosec #aisec

  18. #OWASP #Ottawa would like to acknowledge the gracious support from Software Secured for our January Meetup. Their support for the Ottawa Security community through our chapter brings helps us all to skill up.

    www.softwaresecured.com

    #AppSec #infosec #aisec

  19. #OWASP #Ottawa would like to acknowledge the gracious support from Software Secured for our January Meetup. Their support for the Ottawa Security community through our chapter brings helps us all to skill up.

    www.softwaresecured.com

    #AppSec #infosec #aisec

  20. #OWASP #Ottawa would like to acknowledge the gracious support from Software Secured for our January Meetup. Their support for the Ottawa Security community through our chapter brings helps us all to skill up.

    www.softwaresecured.com

    #AppSec #infosec #aisec

  21. 🛠️ Tool
    ===================

    Opening: Shannon is an autonomous AI pentester designed to find, validate, and exploit web-application vulnerabilities end-to-end. The project emphasizes executable proof-of-concepts and code-aware dynamic testing rather than flagging potential issues without validation.

    Key Features:
    • Fully autonomous operation: Shannon performs source-aware analysis, browser-driven exploitation, and multi-factor navigation attempts (including TOTP and federated sign-ins) to validate exploitable issues.
    • Vulnerability coverage: Shannon reports validated instances of XSS, injection, SSRF, and Broken Authentication/Authorization with reproducible PoCs.
    • Integrated reconnaissance: Discovery phases are enriched by Nmap, Subfinder, WhatWeb, and Schemathesis to map targets and stress API surfaces.
    • Parallelized workflows: Multiple exploitation and validation phases run concurrently to shorten overall test time.

    Technical implementation (conceptual):
    • Source analysis informs attack surface prioritization by combining static inspection with runtime targeting.
    • A headless/browser automation layer executes interactive flows, attempts credential bypasses, and delivers exploit payloads to prove end-to-end exploitability.
    • Reconnaissance components feed discovered endpoints and schemas into dynamic test plans, enabling schema-driven fuzzing (Schemathesis) and targeted HTTP attacks.

    Use cases:
    • Continuous pre-production validation on CI pipelines where teams need reproducible PoCs rather than alerts.
    • Research and red-team augmentation for validating exploitability of suspected vulnerabilities.
    • Security teams seeking prioritized, evidence-backed reports for remediation tracking.

    Limitations and considerations:
    • Current coverage focuses on core OWASP classes listed above; additional vulnerability types are under development.
    • Proofs rely on the accuracy of provided source/context and access to a running application environment for live validation.
    • Ethical and legal boundaries apply: the tool is intended for authorized testing on owned or permitted targets.

    References:
    • Notable benchmark: Shannon Lite reports a 96.15% score on the XBOW benchmark (source project results).

    🔹 tool #AIsec #security #owasp #pentesting

    🔗 Source: github.com/KeygraphHQ/shannon?

  22. ⚠️ Most breaches don’t require genius — just opportunity.

    Attackers don’t need zero-days. They exploit what’s already exposed:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7 at HACKTIVATE LABS.

    The Reality:
    Most orgs don’t need more security staff —
    they need faster decision loops.
    Executed by agents that never sleep.

    What we’re testing now:
    🧠 AI agents that shape the threat surface in real time
    🛰️ Pre-attack recon using live intel feeds
    ⚔️ Automated red team prep using CVE correlation
    🔄 Defense loops that execute without human approval

    The goal isn’t alerts.
    The goal is autonomous containment.

    💬 If you’re building in #AIsec, #Cybersecurity, or #DevSecOps — let’s align.
    Tag your team or @mention someone who should see this.

    #Automation #RedTeam #AISecurity #SOC #NetOps #SecurityFuture #AIagents

  23. ⚠️ Most breaches don’t require genius — just opportunity.

    Attackers don’t need zero-days. They exploit what’s already exposed:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7 at HACKTIVATE LABS.

    The Reality:
    Most orgs don’t need more security staff —
    they need faster decision loops.
    Executed by agents that never sleep.

    What we’re testing now:
    🧠 AI agents that shape the threat surface in real time
    🛰️ Pre-attack recon using live intel feeds
    ⚔️ Automated red team prep using CVE correlation
    🔄 Defense loops that execute without human approval

    The goal isn’t alerts.
    The goal is autonomous containment.

    💬 If you’re building in #AIsec, #Cybersecurity, or #DevSecOps — let’s align.
    Tag your team or @mention someone who should see this.

    #Automation #RedTeam #AISecurity #SOC #NetOps #SecurityFuture #AIagents

  24. ⚠️ Most breaches don’t require genius — just opportunity.

    Attackers don’t need zero-days. They exploit what’s already exposed:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7 at HACKTIVATE LABS.

    The Reality:
    Most orgs don’t need more security staff —
    they need faster decision loops.
    Executed by agents that never sleep.

    What we’re testing now:
    🧠 AI agents that shape the threat surface in real time
    🛰️ Pre-attack recon using live intel feeds
    ⚔️ Automated red team prep using CVE correlation
    🔄 Defense loops that execute without human approval

    The goal isn’t alerts.
    The goal is autonomous containment.

    💬 If you’re building in #AIsec, #Cybersecurity, or #DevSecOps — let’s align.
    Tag your team or @mention someone who should see this.

    #Automation #RedTeam #AISecurity #SOC #NetOps #SecurityFuture #AIagents

  25. ⚠️ Most breaches don’t require genius — just opportunity.

    Attackers don’t need zero-days. They exploit what’s already exposed:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7 at HACKTIVATE LABS.

    The Reality:
    Most orgs don’t need more security staff —
    they need faster decision loops.
    Executed by agents that never sleep.

    What we’re testing now:
    🧠 AI agents that shape the threat surface in real time
    🛰️ Pre-attack recon using live intel feeds
    ⚔️ Automated red team prep using CVE correlation
    🔄 Defense loops that execute without human approval

    The goal isn’t alerts.
    The goal is autonomous containment.

    💬 If you’re building in #AIsec, #Cybersecurity, or #DevSecOps — let’s align.
    Tag your team or @mention someone who should see this.

    #Automation #RedTeam #AISecurity #SOC #NetOps #SecurityFuture #AIagents

  26. The Reality:
    Most orgs think they need a bigger security team.
    What they actually need is faster decision loops—
    executed by autonomous agents that never sleep.

    What we’re proving at HACKTIVATE LABS:
    ⚙️ 60% of defensive tasks can be automated
    📉 False positives can be reduced without blind filtering
    🧠 AI can triage alerts with context, not keywords
    🚀 Red team prep can start before the first meeting

    Security shouldn’t wait for humans.
    It should deploy itself.

    If you agree — boost this or @mention someone building in #AIsec or #Cybersecurity.
    Let’s push the edge forward — together.

    #DevSecOps #SecurityAutomation #RedTeamOps #CISO #AIInnovations

  27. The Reality:
    Most orgs think they need a bigger security team.
    What they actually need is faster decision loops—
    executed by autonomous agents that never sleep.

    What we’re proving at HACKTIVATE LABS:
    ⚙️ 60% of defensive tasks can be automated
    📉 False positives can be reduced without blind filtering
    🧠 AI can triage alerts with context, not keywords
    🚀 Red team prep can start before the first meeting

    Security shouldn’t wait for humans.
    It should deploy itself.

    If you agree — boost this or @mention someone building in #AIsec or #Cybersecurity.
    Let’s push the edge forward — together.

    #DevSecOps #SecurityAutomation #RedTeamOps #CISO #AIInnovations

  28. The Reality:
    Most orgs think they need a bigger security team.
    What they actually need is faster decision loops—
    executed by autonomous agents that never sleep.

    What we’re proving at HACKTIVATE LABS:
    ⚙️ 60% of defensive tasks can be automated
    📉 False positives can be reduced without blind filtering
    🧠 AI can triage alerts with context, not keywords
    🚀 Red team prep can start before the first meeting

    Security shouldn’t wait for humans.
    It should deploy itself.

    If you agree — boost this or @mention someone building in #AIsec or #Cybersecurity.
    Let’s push the edge forward — together.

    #DevSecOps #SecurityAutomation #RedTeamOps #CISO #AIInnovations

  29. RE: infosec.exchange/@Hacktivate/1

    ⚠️ Most breaches don’t require genius — just opportunity.

    Here’s what attackers actually exploit:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7.

    If you’re in #Cybersecurity #AIsec or #DevSecOps — let’s talk.
    Tag a team that needs this operational.

    #Automation #RedTeam #AISecurity #SOC #NetOps

  30. RE: infosec.exchange/@Hacktivate/1

    ⚠️ Most breaches don’t require genius — just opportunity.

    Here’s what attackers actually exploit:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7.

    If you’re in #Cybersecurity #AIsec or #DevSecOps — let’s talk.
    Tag a team that needs this operational.

    #Automation #RedTeam #AISecurity #SOC #NetOps

  31. RE: infosec.exchange/@Hacktivate/1

    ⚠️ Most breaches don’t require genius — just opportunity.

    Here’s what attackers actually exploit:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7.

    If you’re in #Cybersecurity #AIsec or #DevSecOps — let’s talk.
    Tag a team that needs this operational.

    #Automation #RedTeam #AISecurity #SOC #NetOps

  32. RE: infosec.exchange/@Hacktivate/1

    ⚠️ Most breaches don’t require genius — just opportunity.

    Here’s what attackers actually exploit:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7.

    If you’re in #Cybersecurity #AIsec or #DevSecOps — let’s talk.
    Tag a team that needs this operational.

    #Automation #RedTeam #AISecurity #SOC #NetOps

  33. ⚠️ Most breaches don’t require genius — just opportunity.

    Here’s what attackers actually exploit:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7.

    If you’re in #Cybersecurity #AIsec or #DevSecOps — let’s talk.
    Tag a team that needs this operational.

    #Automation #RedTeam #AISecurity #SOC #NetOps

  34. ⚠️ Most breaches don’t require genius — just opportunity.

    Here’s what attackers actually exploit:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7.

    If you’re in #Cybersecurity #AIsec or #DevSecOps — let’s talk.
    Tag a team that needs this operational.

    #Automation #RedTeam #AISecurity #SOC #NetOps

  35. ⚠️ Most breaches don’t require genius — just opportunity.

    Here’s what attackers actually exploit:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7.

    If you’re in #Cybersecurity #AIsec or #DevSecOps — let’s talk.
    Tag a team that needs this operational.

    #Automation #RedTeam #AISecurity #SOC #NetOps

  36. ⚠️ Most breaches don’t require genius — just opportunity.

    Here’s what attackers actually exploit:
    • Default creds still active
    • Config drift no one monitors
    • Cloud misconfigs after updates
    • APIs exposed by accident

    We’re building autonomous agents to close those gaps 24/7.

    If you’re in #Cybersecurity #AIsec or #DevSecOps — let’s talk.
    Tag a team that needs this operational.

    #Automation #RedTeam #AISecurity #SOC #NetOps

  37. RE: infosec.exchange/@Hacktivate/1

    🚀 Launch Your First Security Agent (Starter Kit)

    Here’s the core architecture we deploy at HACKTIVATE LABS:
    📡 Trigger → webhook / API / CVE feed
    🧠 Logic → GPT / detection rules / risk scoring
    ⚙️ Action → alert / ticket / auto-patch / notify

    Use cases:
    ✔ Phishing alerts
    ✔ Config drift
    ✔ Smart contract audits
    ✔ Prompt injection defense

    Want the repo or template?
    Boost, @mention a teammate, or tag your team lead — I’ll share it.

    #AIsec #Automation #Cybersecurity #DevSecOps #RedTeam #AIEngineering #AISafety

  38. RE: infosec.exchange/@Hacktivate/1

    🚀 Launch Your First Security Agent (Starter Kit)

    Here’s the core architecture we deploy at HACKTIVATE LABS:
    📡 Trigger → webhook / API / CVE feed
    🧠 Logic → GPT / detection rules / risk scoring
    ⚙️ Action → alert / ticket / auto-patch / notify

    Use cases:
    ✔ Phishing alerts
    ✔ Config drift
    ✔ Smart contract audits
    ✔ Prompt injection defense

    Want the repo or template?
    Boost, @mention a teammate, or tag your team lead — I’ll share it.

    #AIsec #Automation #Cybersecurity #DevSecOps #RedTeam #AIEngineering #AISafety

  39. 🚀 Launch Your First Security Agent (Starter Kit)

    Here’s the core architecture we deploy at HACKTIVATE LABS:
    📡 Trigger → webhook / API / CVE feed
    🧠 Logic → GPT / detection rules / risk scoring
    ⚙️ Action → alert / ticket / auto-patch / notify

    Use cases:
    ✔ Phishing alerts
    ✔ Config drift
    ✔ Smart contract audits
    ✔ Prompt injection defense

    Want the repo or template?
    Boost, @mention a teammate, or tag your team lead — I’ll share it.

    #AIsec #Automation #Cybersecurity #DevSecOps #RedTeam #AIEngineering #AISafety

  40. 🚀 Launch Your First Security Agent (Starter Kit)

    Here’s the core architecture we deploy at HACKTIVATE LABS:
    📡 Trigger → webhook / API / CVE feed
    🧠 Logic → GPT / detection rules / risk scoring
    ⚙️ Action → alert / ticket / auto-patch / notify

    Use cases:
    ✔ Phishing alerts
    ✔ Config drift
    ✔ Smart contract audits
    ✔ Prompt injection defense

    Want the repo or template?
    Boost, @mention a teammate, or tag your team lead — I’ll share it.

    #AIsec #Automation #Cybersecurity #DevSecOps #RedTeam #AIEngineering #AISafety

  41. 🧠 AI + Security Automation — What do you want first?

    Which agent should I open-source next?

    🔘 Prompt injection defender
    🔘 CVE → exploit correlator
    🔘 Smart contract auditor
    🔘 Recon bot for OSINT / endpoints

    Vote, @mention, or drop your own idea.
    I’ll build what the ecosystem needs.

    #AIsec #Cybersecurity #Automation #Builders

  42. 🧠 AI + Security Automation — What do you want first?

    Which agent should I open-source next?

    🔘 Prompt injection defender
    🔘 CVE → exploit correlator
    🔘 Smart contract auditor
    🔘 Recon bot for OSINT / endpoints

    Vote, @mention, or drop your own idea.
    I’ll build what the ecosystem needs.

    #AIsec #Cybersecurity #Automation #Builders

  43. 🧠 AI + Security Automation — What do you want first?

    Which agent should I open-source next?

    🔘 Prompt injection defender
    🔘 CVE → exploit correlator
    🔘 Smart contract auditor
    🔘 Recon bot for OSINT / endpoints

    Vote, @mention, or drop your own idea.
    I’ll build what the ecosystem needs.

    #AIsec #Cybersecurity #Automation #Builders

  44. 🧠 AI + Security Automation — What do you want first?

    Which agent should I open-source next?

    🔘 Prompt injection defender
    🔘 CVE → exploit correlator
    🔘 Smart contract auditor
    🔘 Recon bot for OSINT / endpoints

    Vote, @mention, or drop your own idea.
    I’ll build what the ecosystem needs.

    #AIsec #Cybersecurity #Automation #Builders

  45. 🧠 AI + Security Automation — What do you want first?

    Which agent should I open-source next?

    🔘 Prompt injection defender
    🔘 CVE → exploit correlator
    🔘 Smart contract auditor
    🔘 Recon bot for OSINT / endpoints

    Vote, @mention, or drop your own idea.
    I’ll build what the ecosystem needs.

    #AIsec #Cybersecurity #Automation #Builders