Elektrine lite

← Feed

Aristotelis Tzafalias

aristot73@infosec.exchange

<p>When buffers overflow into policy<br />Views are my own</p>

Posts

  • View post

    Has anyone using LLMs in their development lifecycle published stats on how many vulns were discovered post release before and after LLMs?

  • View post

    The curl summer of Bliss with Daniel and Stefan https://opensourcesecurity.io/2026/2026-09-curl-bliss-stefan-daniel/

  • View post

    European Court of Auditors: Special report 19/2026: Detecting and responding to cybersecurity incidents – EU cooperation framework progressing, but only partially effective due to implementation delays and limited information sharing 21 Sept. 2026 https://www.eca.europa.eu/en/publications/SR-2026-19

  • View post

    The labs are &amp;quot;rogue&amp;quot;.

  • View post

    CyberSecurity Awareness Month will be condensed to CyberSecurity Awareness Minute #Secutity@MachineSpeed

  • View post

    a new prompt is not a new hobby

  • View post

    Dear citizens of the USA, get your own GDPR to bash.

  • View post

    AI Sovereignty and National Security: Identifying the UK’s Dimensions of Control UK, Centre for Emerging Technology and Security (CETaS)* The Centre&#39;s mission is to strengthen UK security through pioneering research on emerging technologies. 20 July 2026 &quot;More critical national security uses, on the other hand, need high levels of control across all of these dimensions, which will likely involve UK-controlled inference, locally retained open-weight fallbacks, accredited environments,...

  • View post

    too soon to tell whether the latest in a series of &quot;wake up&quot; calls leads to meaningful change. in case it doesn&#39;t, this is my goto gif.

  • View post

    OpenAI&#39;s access to OpenAI models should be revoked pending an independant review of the company&#39;s security controls. [partly ironic]

  • View post

    Towards new EU data retention rules EPRS | European Parliamentary Research Service - Silvia González Vidal and Hendrik Mildebrath Published: 7 July 2026 &quot;Despite judicial and now-defunct legislative efforts to harmonise data retention practices across the EU, national data retention regimes remain fragmented, with some countries adopting their own rules and others none at all. Law enforcement authorities report operational difficulties, while service providers face significant complianc...

  • View post

    RE: https://infosec.exchange/@aristot73/116562947812685451 New entries to the reference list. Common theme... 1. @nielsprovos@ioc.exchange — When AI Safety Becomes a Competitive Moat — https://www.provos.org/p/when-ai-safety-becomes-a-competitive-moat/ 2. Jessica Ji and Andrew Lohn (Georgetown CSET) — Why blocking AI models won&#39;t stop the cyber threats they create (CyberScoop op-ed) — https://cyberscoop.com/why-blocking-ai-models-wont-stop-cyber-threats-op-ed/ 3. Mark Dalton (R Street In...

  • View post

    RE: https://infosec.exchange/@aristot73/116562947812685451 New entries added to the &quot;When buffers overflow into policy&quot; project references: **2026-07-17** — UK AISI — How Far Behind the Frontier are Leading Open Weight Models on Cyber? https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber **2026-07-17** — Katie Moussouris (Luta Security) — Gold Eagle: All that Glitters is Not Patched https://www.lutasecurity.com/post/gold-eagle-all-that-gli...

  • View post

    &quot;White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination&quot; The White House - July 14, 2026 &quot;President Trump’s bold vision to secure and accelerate American artificial intelligence (AI) innovation is being actioned through the creation of “GOLD EAGLE,” a clearinghouse that enables unprecedented cybersecurity vulnerability coordination. Open-source software partners and American critical infrastructure companies built a coordinated syst...

  • View post

    fwiw, it does not make sense to be disappointed in the &quot;EU Parliament&quot; as a whole for any particular decision. Be disappointed in the political groups and/or MEPs that voted in support of the decision. ...and in the next European elections, vote accordingly. For that matter, vote accordingly in the next national elections because the Council is made up of nationally elected governments and the Council needs to agree with the decision for it to become law. Those national governmen...

  • View post

    DE - Legislative procedure JULY 6, 2026 Law on the Reform of Intelligence Service Law &quot;The draft, which is currently undergoing departmental voting, fundamentally changes intelligence law. Central to this is the operational strengthening of the intelligence services, for the highest level of security for the people of Germany and their freedom.&quot; https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/OESI2/nachrichtendienstrecht.html

  • View post

    RE: https://infosec.exchange/@aristot73/116877234338008344 7 July 2026 - EU Action Plan on Cybersecurity and Artificial Intelligence - published https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence

  • View post

    🇪🇺 EU financial-stability authorities on frontier AI &amp; cyber risk — all published 25 June - 7 July 2026: 📰 &quot;Frontier AI models could strain cyber resilience in the financial system, ESRB warns&quot; — European Systemic Risk Board (ESRB), 7 Jul 2026 https://www.esrb.europa.eu/news/pr/date/2026/html/esrb.pr260707~4e1b68241a.en.html ⚠️ &quot;Warning on systemic cyber risks stemming from frontier artificial intelligence models (ESRB/2026/3)&quot; — European Systemic Risk Board (ESRB), adopt...

  • View post

    7 July 2026, 15:00 - 16:30 Scrutiny session• Commission statement - Presentation of the Action Plan on Cybersecurity and AI European Parliament Plenary https://www.europarl.europa.eu/plenary/en/home.html

  • View post

    R. Addis et al., &amp;quot;LLM-based Intelligent Agents for Cybersecurity: A Tutorial and Survey of Automated Vulnerability Discovery,&amp;quot; in IEEE Access. &amp;quot;In addition to surveying existing applications, this work provides a step-by-step walkthrough of integrating agentic AI into penetration testing workflows. The walkthrough explores four phases: (I) mission scoping and prompt engineering for test definition and constraint enforcement, (II) autonomous exploration and tool select...

  • View post

    RE: https://infosec.exchange/@trailofbits/116850092020510927 If your goal is to provoke an over reaction in policy circles and further restrictions on defenders, keep framing llm advances from an attacker&amp;#39;s perspective like this: &amp;quot;The expertise barrier that kept bespoke fuzzing campaigns out of reach for most attackers is gone. &amp;quot;

  • View post

    RE: https://infosec.exchange/@aristot73/116562947812685451 Six new bibliography entries, in https://tzafaar.codeberg.page/ newest to oldest: GPT-5.5-Cyber Built a zlib Fuzzing Lab in a Day — Benjamin Samuels (@trailofbits of Bits), Jul 2 2026 https://blog.trailofbits.com/2026/07/02/field-reports-from-patch-the-planet/ The Privatization of Vulnerability Management — @jamesberthoty (Latio Pulse), Jul 2 2026 https://pulse.latio.tech/p/the-privatization-of-vulnerability Preliminary Report of the...

  • View post

    US removes curbs on Anthropic&#39;s latest Fable and Mythos AI models 1 July 2026 https://www.reuters.com/business/us-lift-export-controls-anthropics-fable-ai-model-tuesday-source-says-2026-06-30/ Antrhropic statement in reply

  • View post

    RE: https://infosec.exchange/@aristot73/116562947812685451 📚 New in the references list at https://tzafaar.codeberg.page/ 🔹 Escape QEMU: Watching IronCurtain and an Open-Weight Model Break Out — @nielsprovos@ioc.exchange (30 Jun 2026) https://www.provos.org/p/qemu-escape-glm-5-2/ 🔹 Inside the Advisory Database and what happens when vulnerability volume breaks records — Madison Ficorilli, GitHub (29 Jun 2026) https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-...

  • View post

    tired: non deterministic weird machines are the heart of infosec problems wired: non deterministic weird machines are the &quot;solution&quot; to infosec problems

  • View post

    Inside the Advisory Database and what happens when vulnerability volume breaks records The GitHub Advisory Database is processing more vulnerability reports than ever before. Here’s what’s driving the surge, how we’re responding, and how the community can help. Madison Ficorilli - June 29, 2026 https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/

  • View post

    Software Security Analysis in 2030 and Beyond: A Research Roadmap Published: 26 May 2025 Abstract: As our lives, our businesses, and indeed our world economy become increasingly reliant on the secure operation of many interconnected software systems, the software engineering research community is faced with unprecedented research challenges, but also with exciting new opportunities. In this roadmap article, we outline our vision of software security analysis for the systems of the future. Giv...

  • View post

    Releasing (UK) AISI’s Engineering Playbook Building on the momentum of the Inspect toolkit, we’re open-sourcing parts of the research stack behind AISI&#39;s evaluations. Jun 18, 2026 https://www.aisi.gov.uk/blog/releasing-aisis-engineering-playbook

  • View post

    RE: https://infosec.exchange/@lapt0r/116540007221618669 innovation or automation?

  • View post

    I asked claude to check something. it did. I saved the result. I upload the result - again to claude - for a second pass. Hit the guard rail. 2nd time today. Have no idea what&amp;#39;s going on :)