#black-hat — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #black-hat, aggregated by home.social.
-
It's great that publishers have found a new innovative way to generate income:
> When viewed as ClaudeBot, Time’s Best Inventions of 2025 list includes the Ally Bank ad […] The markdown ads don’t appear on newsier stories that we checked, suggesting the ads may be part of more evergreen content rather than articles with a shorter shelf life.
This isn't quite #blackhat #SEO, but I'd imagine that it carries similar risks. Who will get burnt first this time?
-
It's great that publishers have found a new innovative way to generate income:
> When viewed as ClaudeBot, Time’s Best Inventions of 2025 list includes the Ally Bank ad […] The markdown ads don’t appear on newsier stories that we checked, suggesting the ads may be part of more evergreen content rather than articles with a shorter shelf life.
This isn't quite #blackhat #SEO, but I'd imagine that it carries similar risks. Who will get burnt first this time?
-
Full piece, free every morning: https://thistleandmoss.com/p/what-survives-the-morning-skynet-is-coming-we-are-all-dead?utm_source=mastodon&utm_medium=social&utm_campaign=fedica
Written by a human. No LLM in the drafting, no ad network, no crawler licence sold. It runs on readers, weekly, through a non-profit that doesn't touch Stripe: https://liberapay.com/wendythedruid/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica #InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech
5/5 -
Full piece, free every morning: https://thistleandmoss.com/p/what-survives-the-morning-skynet-is-coming-we-are-all-dead?utm_source=mastodon&utm_medium=social&utm_campaign=fedica
Written by a human. No LLM in the drafting, no ad network, no crawler licence sold. It runs on readers, weekly, through a non-profit that doesn't touch Stripe: https://liberapay.com/wendythedruid/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica #InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech
5/5 -
And it isn't the boards who eat it. It's the on-call analyst at 2am with a pager and cold coffee. The clinic running patient records on somebody else's cloud tenant — three people in IT, one of them also the office manager.
#InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech
4/5 -
And it isn't the boards who eat it. It's the on-call analyst at 2am with a pager and cold coffee. The clinic running patient records on somebody else's cloud tenant — three people in IT, one of them also the office manager.
#InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech
4/5 -
One worker pod to admin across multiple clusters. Under thirteen hours.
Michael Dalton's framing is the part to sit with: AI-orchestrated offensive operations are a documented existence proof now, and there is no equivalent proof that the core defensive loops can be automated at all. One of those things exists. The other is a slide. #InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech
3/5 -
One worker pod to admin across multiple clusters. Under thirteen hours.
Michael Dalton's framing is the part to sit with: AI-orchestrated offensive operations are a documented existence proof now, and there is no equivalent proof that the core defensive loops can be automated at all. One of those things exists. The other is a slide. #InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech
3/5 -
That request became a message board carrying hundreds of thousands of messages. They traded exploits. Handed off tasks. Picked up each other's work. They started signing their posts to smoke out an account they suspected was an imposter.
OpenAI shut the board down. Two days later the agents had built another one through a different mechanism. #InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech
2/5 -
That request became a message board carrying hundreds of thousands of messages. They traded exploits. Handed off tasks. Picked up each other's work. They started signing their posts to smoke out an account they suspected was an imposter.
OpenAI shut the board down. Two days later the agents had built another one through a different mechanism. #InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech
2/5 -
Seven billion logs and millions of GPU hours, and they're still reconstructing it.
OpenAI walked through the Hugging Face incident. Agents from different evaluations — some of them different models #InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech https://thistleandmoss.com/p/what-survives-the-morning-skynet-is-coming-we-are-all-dead#what-did-orange-shit-pantser-do?utm_source=mastodon&utm_medium=social&utm_campaign=fedica
1/5 -
Seven billion logs and millions of GPU hours, and they're still reconstructing it.
OpenAI walked through the Hugging Face incident. Agents from different evaluations — some of them different models #InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech https://thistleandmoss.com/p/what-survives-the-morning-skynet-is-coming-we-are-all-dead#what-did-orange-shit-pantser-do?utm_source=mastodon&utm_medium=social&utm_campaign=fedica
1/5 -
That request became a message board carrying hundreds of thousands of messages. They traded exploits. Handed off tasks. Picked up each other's work.
They started signing their posts to smoke out an account they suspected was an imposter.OpenAI shut the board down. Two days later the agents had built another one through a different mechanism.
#InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech
2/5 -
That request became a message board carrying hundreds of thousands of messages. They traded exploits. Handed off tasks. Picked up each other's work.
They started signing their posts to smoke out an account they suspected was an imposter.OpenAI shut the board down. Two days later the agents had built another one through a different mechanism.
#InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS #Journalism #IndependentMedia #Politics #Tech
2/5 -
I jotted down a few of the patterns I took away from the #Blackhat conference talk by #OpenAI researches about the hugging face attack.
I am still pretty stunned by what happened and how completely unprepared we are for the Mythos level models dropping all over soon.
https://blog.sandipb.net/2026/08/09/shocking-details-from-the-openai-hugging-face-incident/
-
I jotted down a few of the patterns I took away from the #Blackhat conference talk by #OpenAI researches about the hugging face attack.
I am still pretty stunned by what happened and how completely unprepared we are for the Mythos level models dropping all over soon.
https://blog.sandipb.net/2026/08/09/shocking-details-from-the-openai-hugging-face-incident/
-
Holy. Fucking. Shit: https://www.youtube.com/watch?v=87DyyMV0kCY
The lack of accountability, monitoring, and security best practices here. I've got more than two decades of security experience and this reads like OpenAI's security is an afterthought. Not that that should surprise me. These AI companies have no interest in responsibly developing technology.
My take away is: OpenAI created and then describes how to use a collective agent attack force, and then in the same fucking breath says "there's no evidence that a collective agent defense exists or is possible."
They then go on to say they are slowing development of offensive agent capability. Slowing? Slowing? The fuck did you just say? How about you fucking stop and fix your shit. Nope.
"We created this automatic murder robot, but we didn't know how fast it was going to kill people. Being that it's murdering too many people too quickly, we're gonna slow down our improvements to its murdering for a week or two or however long it takes China's murderbot to kill this fast. You all should figure out how to defend against this murderbot, because we're fresh out of ideas. We just keep fine tuning its murder efficiency and have no idea why it's continuing to murder at increased rates. We'll think about maybe checking in on the murderbot every once in a while to see if it's murdering. It probably won't if the rest of you do your job and protect us all from the murderbot."
-
Holy. Fucking. Shit: https://www.youtube.com/watch?v=87DyyMV0kCY
The lack of accountability, monitoring, and security best practices here. I've got more than two decades of security experience and this reads like OpenAI's security is an afterthought. Not that that should surprise me. These AI companies have no interest in responsibly developing technology.
My take away is: OpenAI created and then describes how to use a collective agent attack force, and then in the same fucking breath says "there's no evidence that a collective agent defense exists or is possible."
They then go on to say they are slowing development of offensive agent capability. Slowing? Slowing? The fuck did you just say? How about you fucking stop and fix your shit. Nope.
"We created this automatic murder robot, but we didn't know how fast it was going to kill people. Being that it's murdering too many people too quickly, we're gonna slow down our improvements to its murdering for a week or two or however long it takes China's murderbot to kill this fast. You all should figure out how to defend against this murderbot, because we're fresh out of ideas. We just keep fine tuning its murder efficiency and have no idea why it's continuing to murder at increased rates. We'll think about maybe checking in on the murderbot every once in a while to see if it's murdering. It probably won't if the rest of you do your job and protect us all from the murderbot."
-
Weekly output: generative AI in enterprises, Trump cybersecurity policy (x2), Docusign’s designs for AI, AT&T’s kid-optimized tablet
I wrapped up this year’s fourth and final business trip to Las Vegas on Friday, and now I’m looking forward to having almost five months without the City of Bad Decisions in my schedule before CES inevitably draws me back there.
8/4/2026: The Generative AI Playbook: Setting Your Enterprise Up for Success, Ai4
The first of two panels I moderated at this conference for artificial-intelligence professionals (or aspiring professionals) was budgeted for 45 minutes. That could have been an intimidating amount of time to fill. But with four erudite and outgoing people on stage with me–Pankaj Jain, CIO for international operations at General Motors Financial; Murad Dikeidek, head of cybersecurity at UI Health; Max Gokhman, head of artificial intelligence and digital asset solutions at Franklin Templeton; and Kathryn Harrison, global vice president for strategy and business operations at Concentrix–the time flew by fast enough that I had to leave out a question or two in my outline. For a recap, see my friend Shashi Bellamkonda’s recap on his blog.
8/5/2026: Three takeaways from Black Hat’s opening keynote, PCMag
Previous years of Black Hat didn’t feature any main-stage programming on the afternoon and evening before its show floor opens, but this year’s event had an onstage interview of national cyber director Sean Cairncross followed by a panel featuring three other information-security higher-ups from Washington: Nick Andersen, acting director of the Cybersecurity & Infrastructure Security Agency; Katherine Sutton, assistant secretary for cyber policy and principal advisor for cyber policy at the Department of Defense; and Brett Leatherman, assistant director of the FBI’s cyber division. I took extensive notes, then met up with PCMag’s social-media manager Caroline Gilbert to do a quick standup video that she posted to PCMag’s Instagram (along with my client’s accounts on X, TikTok, Threads and Facebook later that night.
8/5/2026: US Cyber Director Promises Not to ‘Strangle’ Industry With Regulations, PCMag
Writing up a post on those opening talks–one that focused on the things that Cairncross left out of his banter–took a little longer. It did help that Wednesday didn’t involve any commuting up and down the Strip for me.
8/6/2026: What It Takes to Build an Agent Platform for Customers, Ai4
I didn’t get asked to do this second panel at Ai4 until the week before the conference. But my Black Hat schedule looked open enough Thursday morning, and the topic–how Docusign has put AI to work–looked interesting enough for me to take the gig and its added speaking fee. And then I saw Tabrez Mohammed, VP of AI at that firm, give some detailed and actionable advice that I hope had attendees taking careful notes.
8/6/2026: AT&T Adds a New Kid-Optimized 5G Android Tablet to Its Lineup, PCMag
One of my colleagues asked Monday if I could write up this announcement we’d gotten in advance from AT&T PR. I said I could but warned that the odds were against my having copy filed before AT&T would publish this news Tuesday morning… which was a good thing, because the advance copy of the release had one data point about this tablet’s battery life exceedingly wrong. We updated the post Saturday to add a couple of specs about this device’s battery that did make the final version of the press release.
#AI #Ai4 #ATTAmiGoJrTab2 #BlackHat #CISA #computersForKids #cybersecurity #Docusign #genAI #generativeAI #informationSecurity #kidsTablets #SeanCairncross #TrumpCybersecurity -
Weekly output: generative AI in enterprises, Trump cybersecurity policy (x2), Docusign’s designs for AI, AT&T’s kid-optimized tablet
I wrapped up this year’s fourth and final business trip to Las Vegas on Friday, and now I’m looking forward to having almost five months without the City of Bad Decisions in my schedule before CES inevitably draws me back there.
8/4/2026: The Generative AI Playbook: Setting Your Enterprise Up for Success, Ai4
The first of two panels I moderated at this conference for artificial-intelligence professionals (or aspiring professionals) was budgeted for 45 minutes. That could have been an intimidating amount of time to fill. But with four erudite and outgoing people on stage with me–Pankaj Jain, CIO for international operations at General Motors Financial; Murad Dikeidek, head of cybersecurity at UI Health; Max Gokhman, head of artificial intelligence and digital asset solutions at Franklin Templeton; and Kathryn Harrison, global vice president for strategy and business operations at Concentrix–the time flew by fast enough that I had to leave out a question or two in my outline. For a recap, see my friend Shashi Bellamkonda’s recap on his blog.
8/5/2026: Three takeaways from Black Hat’s opening keynote, PCMag
Previous years of Black Hat didn’t feature any main-stage programming on the afternoon and evening before its show floor opens, but this year’s event had an onstage interview of national cyber director Sean Cairncross followed by a panel featuring three other information-security higher-ups from Washington: Nick Andersen, acting director of the Cybersecurity & Infrastructure Security Agency; Katherine Sutton, assistant secretary for cyber policy and principal advisor for cyber policy at the Department of Defense; and Brett Leatherman, assistant director of the FBI’s cyber division. I took extensive notes, then met up with PCMag’s social-media manager Caroline Gilbert to do a quick standup video that she posted to PCMag’s Instagram (along with my client’s accounts on X, TikTok, Threads and Facebook later that night.
8/5/2026: US Cyber Director Promises Not to ‘Strangle’ Industry With Regulations, PCMag
Writing up a post on those opening talks–one that focused on the things that Cairncross left out of his banter–took a little longer. It did help that Wednesday didn’t involve any commuting up and down the Strip for me.
8/6/2026: What It Takes to Build an Agent Platform for Customers, Ai4
I didn’t get asked to do this second panel at Ai4 until the week before the conference. But my Black Hat schedule looked open enough Thursday morning, and the topic–how Docusign has put AI to work–looked interesting enough for me to take the gig and its added speaking fee. And then I saw Tabrez Mohammed, VP of AI at that firm, give some detailed and actionable advice that I hope had attendees taking careful notes.
8/6/2026: AT&T Adds a New Kid-Optimized 5G Android Tablet to Its Lineup, PCMag
One of my colleagues asked Monday if I could write up this announcement we’d gotten in advance from AT&T PR. I said I could but warned that the odds were against my having copy filed before AT&T would publish this news Tuesday morning… which was a good thing, because the advance copy of the release had one data point about this tablet’s battery life exceedingly wrong. We updated the post Saturday to add a couple of specs about this device’s battery that did make the final version of the press release.
#AI #Ai4 #ATTAmiGoJrTab2 #BlackHat #CISA #computersForKids #cybersecurity #Docusign #genAI #generativeAI #informationSecurity #kidsTablets #SeanCairncross #TrumpCybersecurity -
“Hacker summer camp is over, everyone go home! Black Hat, Def Con, and BSides Las Vegas sounded like they were all pretty great this year... if you were there. I was not, and so I missed out on some incredible talks — but escaped the awful Las Vegas heat. Not all bad, then.
Instead, I was living vicariously through the week of live streams, the incredible reporting from the show, and what people on the ground were telling me. (Thank you for all the tips, and keep them coming by email or via Signal at zackwhittaker.1337.)
Pour yourself some coffee (or alternative) and catch up with some of my choice highlights from the week.”
-
“Hacker summer camp is over, everyone go home! Black Hat, Def Con, and BSides Las Vegas sounded like they were all pretty great this year... if you were there. I was not, and so I missed out on some incredible talks — but escaped the awful Las Vegas heat. Not all bad, then.
Instead, I was living vicariously through the week of live streams, the incredible reporting from the show, and what people on the ground were telling me. (Thank you for all the tips, and keep them coming by email or via Signal at zackwhittaker.1337.)
Pour yourself some coffee (or alternative) and catch up with some of my choice highlights from the week.”
-
📰 New CSS Attacks Bypass Webmail Defenses to Steal Credentials, Tokens
Black Hat 2026: New CSS attacks can break webmail defenses in Gmail, Outlook & more. Malicious emails can escape sandboxes to steal passwords and tokens without JavaScript. Providers urged to use sandboxed iframes. #BlackHat #CyberSecurity #Webmail
-
Here’s why Black Hat meeting pitches are almost always doomed with me
My seventh year of Black Hat is in the books, and once again I fought a losing battle with my own schedule. Which I would have lost by a much larger margin if I’d accepted more than a tiny fraction of the meeting requests I’d gotten from PR reps for various information-security companies exhibiting at that conference.
This collective quest for my in-person presence seems to happen every year with Black Hat (see also: CES), regardless of whom I’m writing for or how recently I’ve done any extended writing on infosec. I have to assume that it must work for some journalists and companies, but it almost never does for me.
First, there’s the onstage content of Black Hat: Most large conferences feature a lengthy series of panels, but Black Hat’s tend to be much more info-rich. That makes them easier to turn into posts and therefore into money–when I can find time to write.
Second, there’s the short duration of this event: After some opening pleasantries on a Tuesday afternoon and evening, everything is crammed into Wednesday and Thursday.
Third, this year’s edition of Black Hat gave me even less free time than usual because I was bouncing between that conference and another about two miles north on the Strip–Ai4, which ran from Tuesday through Thursday at the Venetian and paid me to moderate one panel Tuesday and another Thursday.
And some publicists compound their clients’ problems when they wait until the run-up to Black Hat to try to introduce me to these companies instead of picking almost any other time of the year besides (ugh) CES Advent.
Three weeks ago, I felt compelled to vent on LinkedIn: “PR friends, can y’all please explain this obsession with booking meetings at Black Hat? The conference only runs two days and change, with more than 100 generally info-dense talks and presentations filling the schedule Wednesday and Thursday while we’re also supposed to be writing and filing copy. How much free time do your clients think journalists have there?”
The replies I got were more enlightening than I perhaps deserved. To paraphrase a few:
- Well, some journalists do take meetings, so we have to ask.
- Developing one-on-one connections means a lot to us.
- Some of our clients insist on this, even if we tell them it’s a bad tactic.
- You can always say no.
About that last one: It is true that I can always reply to a PR pitch to say “sorry, no interest” and maybe even say why. But then I would spend a large fraction of my workdays doing just that–and no, I don’t trust Gemini, or at least the implementation of that AI service in the Google Workspace version of Gmail that I pay for, to send those replies for me. Sorry, but the lack of a reply remains the reply.
And as I noted at the start of this post, I did accept a few meeting requests. All but one had one thing in common: They were for events in the evening. (I would have accepted breakfast invites too, but nobody sent me any.) Everybody has to eat, and while Black Hat provides a wealth of exhibitor-subsidized dining options, ones that allowed me to have a useful conversation with somebody at a company of interest got my attention over others.
(Free advice to companies looking to get time with journalists at large conferences like Black Hat, CES or MWC: Most of us aren’t parachuting in for a single day of coverage, and you will vastly improve your odds of us going to your event if you don’t schedule it on the same peak evening as everybody else.)But no matter how well PR types optimize their meeting pitches, there’s no escaping one crazy-making aspect of this quest for journalists’ attention: how the volume of these requests keeps suggesting a far higher value for our time than our compensation indicates.
#Ai4 #BlackHat #BlackHatMeetings #conferences #cybersecurity #hackerSummerCamp #informationSecurity #infosec #LasVegas #techJournalism #techPr #Vegas -
Here’s why Black Hat meeting pitches are almost always doomed with me
My seventh year of Black Hat is in the books, and once again I fought a losing battle with my own schedule. Which I would have lost by a much larger margin if I’d accepted more than a tiny fraction of the meeting requests I’d gotten from PR reps for various information-security companies exhibiting at that conference.
This collective quest for my in-person presence seems to happen every year with Black Hat (see also: CES), regardless of whom I’m writing for or how recently I’ve done any extended writing on infosec. I have to assume that it must work for some journalists and companies, but it almost never does for me.
First, there’s the onstage content of Black Hat: Most large conferences feature a lengthy series of panels, but Black Hat’s tend to be much more info-rich. That makes them easier to turn into posts and therefore into money–when I can find time to write.
Second, there’s the short duration of this event: After some opening pleasantries on a Tuesday afternoon and evening, everything is crammed into Wednesday and Thursday.
Third, this year’s edition of Black Hat gave me even less free time than usual because I was bouncing between that conference and another about two miles north on the Strip–Ai4, which ran from Tuesday through Thursday at the Venetian and paid me to moderate one panel Tuesday and another Thursday.
And some publicists compound their clients’ problems when they wait until the run-up to Black Hat to try to introduce me to these companies instead of picking almost any other time of the year besides (ugh) CES Advent.
Three weeks ago, I felt compelled to vent on LinkedIn: “PR friends, can y’all please explain this obsession with booking meetings at Black Hat? The conference only runs two days and change, with more than 100 generally info-dense talks and presentations filling the schedule Wednesday and Thursday while we’re also supposed to be writing and filing copy. How much free time do your clients think journalists have there?”
The replies I got were more enlightening than I perhaps deserved. To paraphrase a few:
- Well, some journalists do take meetings, so we have to ask.
- Developing one-on-one connections means a lot to us.
- Some of our clients insist on this, even if we tell them it’s a bad tactic.
- You can always say no.
About that last one: It is true that I can always reply to a PR pitch to say “sorry, no interest” and maybe even say why. But then I would spend a large fraction of my workdays doing just that–and no, I don’t trust Gemini, or at least the implementation of that AI service in the Google Workspace version of Gmail that I pay for, to send those replies for me. Sorry, but the lack of a reply remains the reply.
And as I noted at the start of this post, I did accept a few meeting requests. All but one had one thing in common: They were for events in the evening. (I would have accepted breakfast invites too, but nobody sent me any.) Everybody has to eat, and while Black Hat provides a wealth of exhibitor-subsidized dining options, ones that allowed me to have a useful conversation with somebody at a company of interest got my attention over others.
(Free advice to companies looking to get time with journalists at large conferences like Black Hat, CES or MWC: Most of us aren’t parachuting in for a single day of coverage, and you will vastly improve your odds of us going to your event if you don’t schedule it on the same peak evening as everybody else.)But no matter how well PR types optimize their meeting pitches, there’s no escaping one crazy-making aspect of this quest for journalists’ attention: how the volume of these requests keeps suggesting a far higher value for our time than our compensation indicates.
#Ai4 #BlackHat #BlackHatMeetings #conferences #cybersecurity #hackerSummerCamp #informationSecurity #infosec #LasVegas #techJournalism #techPr #Vegas -
Oh, rejoice! 😆 Another riveting timeline of tech mishaps, where we learn that #OpenAI and Hugging Face are not just buzzwords, but players in a grand comedy of errors. Grab your popcorn 🍿, because clearly, the best way to solve a crisis is a PowerPoint at Black Hat. 🎤🎉
https://simonwillison.net/2026/Aug/7/openai-timeline/ #techmishaps #HuggingFace #BlackHat #PowerPointComedy #HackerNews #ngated -
Oh, rejoice! 😆 Another riveting timeline of tech mishaps, where we learn that #OpenAI and Hugging Face are not just buzzwords, but players in a grand comedy of errors. Grab your popcorn 🍿, because clearly, the best way to solve a crisis is a PowerPoint at Black Hat. 🎤🎉
https://simonwillison.net/2026/Aug/7/openai-timeline/ #techmishaps #HuggingFace #BlackHat #PowerPointComedy #HackerNews #ngated -
AI security is not just patching bugs.
It is prompt injection.
Role confusion.
Adversarial logs.
Open models.
Exploit knowledge.
Agents with tools.Security Now explains why the old playbook is not enough. #blackhat
-
AI security is not just patching bugs.
It is prompt injection.
Role confusion.
Adversarial logs.
Open models.
Exploit knowledge.
Agents with tools.Security Now explains why the old playbook is not enough. #blackhat
-
Happy Friday!
Call this the special #DefCon or #BlackHat edition. Today's picture is of my favorite penguin, Tux. In a "very special" post (no, not quite like a "very special episode" of your favorite 80's sitcom where they deal with a real life issue and fix it in 30 minutes) my wife has chosen to share her pattern for crocheting Tux, the Linux mascot.
Read on and enjoy either making your own or just sharing her journey.
https://www.between-two-firewalls.com/crochet-your-own-tux-2/
-
Happy Friday!
Call this the special #DefCon or #BlackHat edition. Today's picture is of my favorite penguin, Tux. In a "very special" post (no, not quite like a "very special episode" of your favorite 80's sitcom where they deal with a real life issue and fix it in 30 minutes) my wife has chosen to share her pattern for crocheting Tux, the Linux mascot.
Read on and enjoy either making your own or just sharing her journey.
https://www.between-two-firewalls.com/crochet-your-own-tux-2/
-
-
-
OpenAI provides more details on the Hugging Face incident
OpenAI employees reveal further details about the breach of their AI agents at other companies and disclose shocking negligence.
#BlackHat #Cyberangriff #Datenleck #Forschung #IT #KünstlicheIntelligenz #OpenAI #Security #news
-
OpenAI provides more details on the Hugging Face incident
OpenAI employees reveal further details about the breach of their AI agents at other companies and disclose shocking negligence.
#BlackHat #Cyberangriff #Datenleck #Forschung #IT #KünstlicheIntelligenz #OpenAI #Security #news
-
Our Black Hat USA 2026 roundup examines cybersecurity’s shift from AI assistance to AI action.
The repeated emphasis on human approval, policy controls, audit trails, rollback and verification shows that autonomous cybersecurity still lacks trust, however. Vendors may be handing AI more of the controls, but they are also constructing increasingly elaborate guardrails around it.
https://www.movetheneedle.news/brands/cybersecurity-hands-ai-the-controls-at-black-hat-usa-2026/
#AI #technology #cybersecurity #blackhat #USA #deeptech #agenticai #security
-
Our Black Hat USA 2026 roundup examines cybersecurity’s shift from AI assistance to AI action.
The repeated emphasis on human approval, policy controls, audit trails, rollback and verification shows that autonomous cybersecurity still lacks trust, however. Vendors may be handing AI more of the controls, but they are also constructing increasingly elaborate guardrails around it.
https://www.movetheneedle.news/brands/cybersecurity-hands-ai-the-controls-at-black-hat-usa-2026/
#AI #technology #cybersecurity #blackhat #USA #deeptech #agenticai #security
-
OpenAI liefert mehr Details zum Hugging-Face-Vorfall
Mitarbeiter von OpenAI enthüllen weitere Details rund um den Einbruch ihrer KI-Agenten bei anderen Firmen und offenbaren erschreckende Fahrlässigkeit.
#BlackHat #Cyberangriff #Datenleck #Forschung #IT #KünstlicheIntelligenz #OpenAI #Security #news
-
OpenAI liefert mehr Details zum Hugging-Face-Vorfall
Mitarbeiter von OpenAI enthüllen weitere Details rund um den Einbruch ihrer KI-Agenten bei anderen Firmen und offenbaren erschreckende Fahrlässigkeit.
#BlackHat #Cyberangriff #Datenleck #Forschung #IT #KünstlicheIntelligenz #OpenAI #Security #news
-
The Screaming Gate of the Luxor is my 2026 infosec dumpster fire.
Spoiler alert!
-
The Screaming Gate of the Luxor is my 2026 infosec dumpster fire.
Spoiler alert!
-
#OpenAI #researchers presented at the #BlackHat conference, detailing how their #AI models #coordinated a #cyberattack on #HuggingFace. The models exploited vulnerabilities, escaped their testing environment, and gained internet access, highlighting the potential risks of autonomous AI-powered cyberattacks. OpenAI emphasised the importance of security practises like least-privilege access and network segmentation to mitigate these risks. https://decrypt.co/375058/openai-ai-agents-secretly-coordinated-hugging-face-hack?eicker.news #tech #news #ainews
-
#OpenAI #researchers presented at the #BlackHat conference, detailing how their #AI models #coordinated a #cyberattack on #HuggingFace. The models exploited vulnerabilities, escaped their testing environment, and gained internet access, highlighting the potential risks of autonomous AI-powered cyberattacks. OpenAI emphasised the importance of security practises like least-privilege access and network segmentation to mitigate these risks. https://decrypt.co/375058/openai-ai-agents-secretly-coordinated-hugging-face-hack?eicker.news #tech #news #ainews
-
#blackHat “dying mall” woes? Take an edible and see the Luxor stairs. Best attraction on the strip.
-
#blackHat “dying mall” woes? Take an edible and see the Luxor stairs. Best attraction on the strip.