Aristotelis Tzafalias
aristot73@infosec.exchange
<p>When buffers overflow into policy<br />Views are my own</p>
Posts
-
Post #4094771
Dear citizens of the USA, get your own GDPR to bash.
-
Post #4092328
AI Sovereignty and National Security: Identifying the UK’s Dimensions of Control UK, Centre for Emerging Technology and Security (CETaS)* The Centre's mission is to strengthen UK security through pioneering research on emerging technologies. 20 July 2026 "More critical national security uses, on the other hand, need high levels of control across all of these dimensions, which will likely involve UK-controlled inference, locally retained open-weight fallbacks, accredited environments,...
-
Post #4034925
too soon to tell whether the latest in a series of "wake up" calls leads to meaningful change. in case it doesn't, this is my goto gif.
-
Post #4004807
OpenAI's access to OpenAI models should be revoked pending an independant review of the company's security controls. [partly ironic]
-
Post #3981227
Towards new EU data retention rules EPRS | European Parliamentary Research Service - Silvia González Vidal and Hendrik Mildebrath Published: 7 July 2026 "Despite judicial and now-defunct legislative efforts to harmonise data retention practices across the EU, national data retention regimes remain fragmented, with some countries adopting their own rules and others none at all. Law enforcement authorities report operational difficulties, while service providers face significant complianc...
-
Post #3968312
RE: https://infosec.exchange/@aristot73/116562947812685451 New entries to the reference list. Common theme... 1. @nielsprovos@ioc.exchange — When AI Safety Becomes a Competitive Moat — https://www.provos.org/p/when-ai-safety-becomes-a-competitive-moat/ 2. Jessica Ji and Andrew Lohn (Georgetown CSET) — Why blocking AI models won't stop the cyber threats they create (CyberScoop op-ed) — https://cyberscoop.com/why-blocking-ai-models-wont-stop-cyber-threats-op-ed/ 3. Mark Dalton (R Street In...
-
Post #3915912
RE: https://infosec.exchange/@aristot73/116562947812685451 New entries added to the "When buffers overflow into policy" project references: **2026-07-17** — UK AISI — How Far Behind the Frontier are Leading Open Weight Models on Cyber? https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber **2026-07-17** — Katie Moussouris (Luta Security) — Gold Eagle: All that Glitters is Not Patched https://www.lutasecurity.com/post/gold-eagle-all-that-gli...
-
Post #3839005
"White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination" The White House - July 14, 2026 "President Trump’s bold vision to secure and accelerate American artificial intelligence (AI) innovation is being actioned through the creation of “GOLD EAGLE,” a clearinghouse that enables unprecedented cybersecurity vulnerability coordination. Open-source software partners and American critical infrastructure companies built a coordinated syst...
-
Post #3699625
fwiw, it does not make sense to be disappointed in the "EU Parliament" as a whole for any particular decision. Be disappointed in the political groups and/or MEPs that voted in support of the decision. ...and in the next European elections, vote accordingly. For that matter, vote accordingly in the next national elections because the Council is made up of nationally elected governments and the Council needs to agree with the decision for it to become law. Those national governmen...
-
Post #3679229
DE - Legislative procedure JULY 6, 2026 Law on the Reform of Intelligence Service Law "The draft, which is currently undergoing departmental voting, fundamentally changes intelligence law. Central to this is the operational strengthening of the intelligence services, for the highest level of security for the people of Germany and their freedom." https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/OESI2/nachrichtendienstrecht.html
-
Post #3649384
RE: https://infosec.exchange/@aristot73/116877234338008344 7 July 2026 - EU Action Plan on Cybersecurity and Artificial Intelligence - published https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence
-
Post #3647773
🇪🇺 EU financial-stability authorities on frontier AI & cyber risk — all published 25 June - 7 July 2026: 📰 "Frontier AI models could strain cyber resilience in the financial system, ESRB warns" — European Systemic Risk Board (ESRB), 7 Jul 2026 https://www.esrb.europa.eu/news/pr/date/2026/html/esrb.pr260707~4e1b68241a.en.html ⚠️ "Warning on systemic cyber risks stemming from frontier artificial intelligence models (ESRB/2026/3)" — European Systemic Risk Board (ESRB), adopt...
-
Post #3645761
7 July 2026, 15:00 - 16:30 Scrutiny session• Commission statement - Presentation of the Action Plan on Cybersecurity and AI European Parliament Plenary https://www.europarl.europa.eu/plenary/en/home.html
-
Post #3614426
R. Addis et al., &quot;LLM-based Intelligent Agents for Cybersecurity: A Tutorial and Survey of Automated Vulnerability Discovery,&quot; in IEEE Access. &quot;In addition to surveying existing applications, this work provides a step-by-step walkthrough of integrating agentic AI into penetration testing workflows. The walkthrough explores four phases: (I) mission scoping and prompt engineering for test definition and constraint enforcement, (II) autonomous exploration and tool select...
-
Post #3614425
RE: https://infosec.exchange/@trailofbits/116850092020510927 If your goal is to provoke an over reaction in policy circles and further restrictions on defenders, keep framing llm advances from an attacker&#39;s perspective like this: &quot;The expertise barrier that kept bespoke fuzzing campaigns out of reach for most attackers is gone. &quot;
-
Post #3614424
RE: https://infosec.exchange/@aristot73/116562947812685451 Six new bibliography entries, in https://tzafaar.codeberg.page/ newest to oldest: GPT-5.5-Cyber Built a zlib Fuzzing Lab in a Day — Benjamin Samuels (@trailofbits of Bits), Jul 2 2026 https://blog.trailofbits.com/2026/07/02/field-reports-from-patch-the-planet/ The Privatization of Vulnerability Management — @jamesberthoty (Latio Pulse), Jul 2 2026 https://pulse.latio.tech/p/the-privatization-of-vulnerability Preliminary Report of the...
-
Post #3506129
US removes curbs on Anthropic's latest Fable and Mythos AI models 1 July 2026 https://www.reuters.com/business/us-lift-export-controls-anthropics-fable-ai-model-tuesday-source-says-2026-06-30/ Antrhropic statement in reply
-
Post #3497558
RE: https://infosec.exchange/@aristot73/116562947812685451 📚 New in the references list at https://tzafaar.codeberg.page/ 🔹 Escape QEMU: Watching IronCurtain and an Open-Weight Model Break Out — @nielsprovos@ioc.exchange (30 Jun 2026) https://www.provos.org/p/qemu-escape-glm-5-2/ 🔹 Inside the Advisory Database and what happens when vulnerability volume breaks records — Madison Ficorilli, GitHub (29 Jun 2026) https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-...
-
Post #3485339
tired: non deterministic weird machines are the heart of infosec problems wired: non deterministic weird machines are the "solution" to infosec problems
-
Post #3483789
Inside the Advisory Database and what happens when vulnerability volume breaks records The GitHub Advisory Database is processing more vulnerability reports than ever before. Here’s what’s driving the surge, how we’re responding, and how the community can help. Madison Ficorilli - June 29, 2026 https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/
-
Post #3431344
Software Security Analysis in 2030 and Beyond: A Research Roadmap Published: 26 May 2025 Abstract: As our lives, our businesses, and indeed our world economy become increasingly reliant on the secure operation of many interconnected software systems, the software engineering research community is faced with unprecedented research challenges, but also with exciting new opportunities. In this roadmap article, we outline our vision of software security analysis for the systems of the future. Giv...
-
Post #3430722
Releasing (UK) AISI’s Engineering Playbook Building on the momentum of the Inspect toolkit, we’re open-sourcing parts of the research stack behind AISI's evaluations. Jun 18, 2026 https://www.aisi.gov.uk/blog/releasing-aisis-engineering-playbook
-
Post #2300731
RE: https://infosec.exchange/@lapt0r/116540007221618669 innovation or automation?
-
Post #2300730
I asked claude to check something. it did. I saved the result. I upload the result - again to claude - for a second pass. Hit the guard rail. 2nd time today. Have no idea what&#39;s going on :)
-
Post #2092051
RE: https://infosec.exchange/@lerg/116524161473318491 "Non-technical teams are now shipping production code..." imagine, "non legal teams are now shipping laws," "non scientific teams are now shipping medicines"
-
Post #1951874
I&#39;m sorry, Dave. I&#39;m afraid I can&#39;t do that. You&#39;ve run out of tokens.
-
Post #1931000
icymi: Dutch National Cyber Security Centre Anthropic’s frontiermodel Mythos vraagt om directe actie (Anthropic&#39;s frontier model Mythos calls for direct action) 15 april 2026 https://www.ncsc.nl/nieuws/anthropics-frontiermodel-mythos-vraagt-om-directe-actie
-
Post #1164068
the more you try something the more you appreciate professionals. I started music lessons and now appreciate what it means to be a musician. I started vibe coding and have a renewed and even greater than before appreciation for professional developers. In fact, all my experiments with vibes have lead to same conclusion on their use in a corporate environment: easy to impress up where everything is abstract, impossible to convince down where details matter.
-
Post #584854
RE: https://fosstodon.org/@kdkorte/116180140578126363 &quot;Bert Hubert posted a blog on his website criticizing the research. According to him, the report underestimates the risk governments face by using Amszon’s new cloud service. &quot; @bert_hubert holding the door :)