Gary McGraw
cigitalgem@sigmoid.social
<p>software security <a href="https://sigmoid.social/tags/swsec" class="mention hashtag" rel="tag">#<span>swsec</span></a> machine learning security <a href="https://sigmoid.social/tags/mlsec" class="mention hashtag" rel="tag">#<span>mlsec</span></a> Tech | Life | Music</p>
Posts
-
Post #4497650
About those idiots hacking the plane wifi while ON the plane
-
Post #4416106
Irregular egg on your face. #MLsec https://www.irregular.com/research/next-generation-of-cyber-evals https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing https://www.wired.com/story/ok-well-there-are-even-more-ai-agent-hacking-incidents/ https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
-
Post #4262029
Autonomy has its...um...benefits? #MLsec This is the beginning of the beginning. https://www.csoonline.com/article/4203630/microsoft-confirms-an-ai-worm-is-propagating-through-copilot-and-other-ms-apps.html
-
Post #4240895
Is escaping the sandbox new for #AI models? Nope. @roblemos@infosec.exchange provides important background on #AI crime (I am quoted in the story) #MLsec https://www.darkreading.com/cybersecurity-operations/incorrigible-ai-models-resist-rehabilitation
-
Post #4236616
Can #AI do crime? Why yes...yes it can. Who gets charged? #MLsec https://www.wired.com/story/openais-rogue-ai-agent-hacked-more-than-just-hugging-face/
-
Post #4109956
Use it. Don't use it. Buy it. Don't buy it. You need it. You don't need it. Angel says yes. Devil says no...or is that backwards? #ML #AI #MLsec https://arstechnica.com/ai/2026/07/us-army-faces-ai-use-limits-after-exhausting-years-supply-of-ai-tokens/
-
Post #4033527
Best writeup yet of the OpenAI/huggingface bromance. #MLsec #ML #AI https://coalfire.com/the-coalfire-blog/openai-gave-its-model-a-test-it-broke-out-of-its-sandbox-and-hacked-hugging-face-to-steal-the-answers
-
Post #4011059
Is this hugging face hack by OpenAI Agentic bots who escaped the lab important? https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html Yes, especially in light of this https://berryvilleiml.com/2026/06/05/biml-and-the-papernot-worm/ It is both inevitable and very concerning. Autonomy cuts both ways. As the arsenal of sneaky tricks gets bigger, we can expect more interesting exploit chains. #MLsec #AI
-
Post #3908136
What?! https://nysfocus.com/2026/07/14/new-york-humanoid-robot-teacher-salamanca-school-district
-
Post #3899531
You know what sucks? When you hit an invisible non-defined usage limit with chat-Jippety pro and they won't even let you pay them more money until some random future date. Fuck that.
-
Post #3856684
#AI is a useful tool. Linux is not an anti-AI technology. https://www.theregister.com/ai-and-ml/2026/07/15/linus-torvalds-tells-ai-haters-to-fork-off/5271894
-
Post #3737848
Today I was using gpt 5.6 in pro mode. I loaded it up with shit tons of my own content and set it to some small tasks. It actually wrote two things that were so funny I laughed out loud when I was reviewing its content. It was highly accurate with only a few super obvious blind spots.The humor was not because it was wrong or making mistakes...it was because it was looking at things sideways like I do sometimes. Real humor in a highly curated technical domain is not what I expected to emerge.
-
Post #3545247
Last night BIML spoke to German TV about the mythos/fable export control situation. Please help us get this thinking in front of people. #ML #AI #MLsec #infosec #security #LLMs https://www.youtube.com/watch?v=_Jsy7UBQv0c https://berryvilleiml.com/2026/06/13/irony-the-us-government-issues-an-export-control-directive-for-fable-5-and-mythos-5/
-
Post #2550612
BIML is proud to release a new study today: No Security Meter for AI #AI #ML #MLsec #security #infosec #swsec #appsec #LLM #AgenticAI https://berryvilleiml.com/results/no-security-meter-ai.pdf
-
Post #2550611
How can you measure security in #ML systems? Maybe similarly to the way we measure security in software systems. #swsec #appsec BIML wrote about this in a new report released today: https://berryvilleiml.com/results/ Get your copy now, released for free under a creative commons license. Applied #MLsec
-
Post #2550610
The excellent @dennisf interviews me about BIML&#39;s new paper &quot;No Security Meter for AI&quot; Have a listen. Then read our report. #MLsec #ML #AI #security #infosec #swsec #appsec https://open.spotify.com/episode/74QW2kzelVz5VtglXlA87s?si=ll7a2xo0Rx2FSmyq-_8-HQ https://berryvilleiml.com/results/no-security-meter-ai.pdf
-
Post #2550609
No Security Meter for AI #MLsec https://berryvilleiml.com/results/
- Post #2550608
-
Post #2550607
Qualcomm Security Summit 2026 #swsec #MLsec https://www.qualcomm.com/company/events/product-security-summit
-
Post #2550606
Let&#39;s have #AI avatar thing explain our new paper about measuring security in #AI. Watch vRon mispronounce BIML. #MLsec https://youtu.be/6hpvMzxNyCM
-
Post #2529679
It&#39;s a great time to be a crackpot https://www.mcsweeneys.net/articles/were-diversifying-the-university-by-hiring-more-crackpots
-
Post #2326345
As always, great reporting from @dangoodin https://arstechnica.com/security/2026/05/chaos-erupts-as-cyberattack-disrupts-learning-platform-canvas-amid-finals/
-
Post #2326342
Fix the damn software #swsec #appsec #MLsec &quot;Those vulnerabilities have been fixed, and will never again be available to attackers. In the future, AIs automatically finding and fixing vulnerabilities in all software will be a normal part of the development process, which will result in much more secure software.&quot; https://www.theguardian.com/commentisfree/2026/may/08/how-dangerous-is-anthropics-mythos-ai
-
Post #2326340
What is better...fox guards chicken house it built just for chickens OR nobody guards chicken house at all?? https://fortune.com/2026/05/06/trump-administration-embraces-ai-oversight-policies-it-once-rejected-anthropic-mythos-caisi/?sge456
-
Post #1879212
Episode 156 of Silver Bullet features Phil Venables talking #MLsec, #AgenticAI and #security Phil Brings decades of CISO experience from Goldman to Google to the table. Please listen and subscribe. https://berryvilleiml.com/2026/05/01/silver-bullet-security-podcast-156-phil-venables/
-
Post #1791388
Dear tech press, we will never red team or pen test our way to #AI security. This story is, in that way, a big disservice to #MLsec. Please focus on building security in. Looking at you @TheGuardian https://www.theguardian.com/technology/2026/apr/29/meet-the-ai-jailbreakers-i-see-the-worst-things-humanity-has-produced
-
Post #1589665
Great to see a BIML quote in this Fortune piece. Our next big piece of work is on measurement (in final review now), so the story timing is great. #MLsec #ML #AI #swsec #appsec #infosec https://fortune.com/2026/04/23/ai-cybersecurity-standards-mythos-nist-owasp-sans-cosai-dc-meeting-eye-on-ai/?sge456
-
Post #1383867
Finally some tech press interest in data poisoning in #ML. When you turn that on in a loop, it becomes RECURSIVE POLLUTION, which in severe cases leads to model collapse. This is the kind of #MLsec risk that commercial players are completely ignoring. https://berryvilleiml.com/2026/01/10/recursive-pollution-and-model-collapse-are-not-the-same/
-
Post #1383149
A good posting reality check on Anthropic&#39;s mythos hyperbole around #swsec #appsec #MLsec adjacent https://blog.vidocsecurity.com/blog/we-reproduced-anthropics-mythos-findings-with-public-models
-
Post #1238187
Beigification? Beigification! &quot;It makes average sound like genius.&quot; https://berryvilleiml.com/2026/03/12/on-beigification/ Watch Mo Bitar in CEO mode. --&gt; https://youtu.be/nDL3Ch7Nz8c?si=aUA24kzcPY7a_CIO #MLsec