Elektrine lite

← Feed

Gary McGraw

cigitalgem@sigmoid.social

<p>software security <a href="https://sigmoid.social/tags/swsec" class="mention hashtag" rel="tag">#<span>swsec</span></a> machine learning security <a href="https://sigmoid.social/tags/mlsec" class="mention hashtag" rel="tag">#<span>mlsec</span></a> Tech | Life | Music</p>

Posts

  • Post #4497650

    About those idiots hacking the plane wifi while ON the plane

  • Post #4416106

    Irregular egg on your face. #MLsec https://www.irregular.com/research/next-generation-of-cyber-evals https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing https://www.wired.com/story/ok-well-there-are-even-more-ai-agent-hacking-incidents/ https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals

  • Post #4262029

    Autonomy has its...um...benefits? #MLsec This is the beginning of the beginning. https://www.csoonline.com/article/4203630/microsoft-confirms-an-ai-worm-is-propagating-through-copilot-and-other-ms-apps.html

  • Post #4240895

    Is escaping the sandbox new for #AI models? Nope. @roblemos@infosec.exchange provides important background on #AI crime (I am quoted in the story) #MLsec https://www.darkreading.com/cybersecurity-operations/incorrigible-ai-models-resist-rehabilitation

  • Post #4236616

    Can #AI do crime? Why yes...yes it can. Who gets charged? #MLsec https://www.wired.com/story/openais-rogue-ai-agent-hacked-more-than-just-hugging-face/

  • Post #4109956

    Use it. Don&#39;t use it. Buy it. Don&#39;t buy it. You need it. You don&#39;t need it. Angel says yes. Devil says no...or is that backwards? #ML #AI #MLsec https://arstechnica.com/ai/2026/07/us-army-faces-ai-use-limits-after-exhausting-years-supply-of-ai-tokens/

  • Post #4033527

    Best writeup yet of the OpenAI/huggingface bromance. #MLsec #ML #AI https://coalfire.com/the-coalfire-blog/openai-gave-its-model-a-test-it-broke-out-of-its-sandbox-and-hacked-hugging-face-to-steal-the-answers

  • Post #4011059

    Is this hugging face hack by OpenAI Agentic bots who escaped the lab important? https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html Yes, especially in light of this  https://berryvilleiml.com/2026/06/05/biml-and-the-papernot-worm/ It is both inevitable and very concerning.  Autonomy cuts both ways.  As the arsenal of sneaky tricks gets bigger, we can expect more interesting exploit chains. #MLsec #AI

  • Post #3908136

    What?! https://nysfocus.com/2026/07/14/new-york-humanoid-robot-teacher-salamanca-school-district

  • Post #3899531

    You know what sucks? When you hit an invisible non-defined usage limit with chat-Jippety pro and they won&#39;t even let you pay them more money until some random future date. Fuck that.

  • Post #3856684

    #AI is a useful tool. Linux is not an anti-AI technology. https://www.theregister.com/ai-and-ml/2026/07/15/linus-torvalds-tells-ai-haters-to-fork-off/5271894

  • Post #3737848

    Today I was using gpt 5.6 in pro mode. I loaded it up with shit tons of my own content and set it to some small tasks. It actually wrote two things that were so funny I laughed out loud when I was reviewing its content. It was highly accurate with only a few super obvious blind spots.The humor was not because it was wrong or making mistakes...it was because it was looking at things sideways like I do sometimes. Real humor in a highly curated technical domain is not what I expected to emerge.

  • Post #3545247

    Last night BIML spoke to German TV about the mythos/fable export control situation. Please help us get this thinking in front of people. #ML #AI #MLsec #infosec #security #LLMs https://www.youtube.com/watch?v=_Jsy7UBQv0c https://berryvilleiml.com/2026/06/13/irony-the-us-government-issues-an-export-control-directive-for-fable-5-and-mythos-5/

  • Post #2550612

    BIML is proud to release a new study today: No Security Meter for AI #AI #ML #MLsec #security #infosec #swsec #appsec #LLM #AgenticAI https://berryvilleiml.com/results/no-security-meter-ai.pdf

  • Post #2550611

    How can you measure security in #ML systems? Maybe similarly to the way we measure security in software systems. #swsec #appsec BIML wrote about this in a new report released today: https://berryvilleiml.com/results/ Get your copy now, released for free under a creative commons license. Applied #MLsec

  • Post #2550610

    The excellent @dennisf interviews me about BIML&amp;#39;s new paper &amp;quot;No Security Meter for AI&amp;quot; Have a listen. Then read our report. #MLsec #ML #AI #security #infosec #swsec #appsec https://open.spotify.com/episode/74QW2kzelVz5VtglXlA87s?si=ll7a2xo0Rx2FSmyq-_8-HQ https://berryvilleiml.com/results/no-security-meter-ai.pdf

  • Post #2550609

    No Security Meter for AI #MLsec https://berryvilleiml.com/results/

  • Post #2550608

  • Post #2550607

    Qualcomm Security Summit 2026 #swsec #MLsec https://www.qualcomm.com/company/events/product-security-summit

  • Post #2550606

    Let&amp;#39;s have #AI avatar thing explain our new paper about measuring security in #AI. Watch vRon mispronounce BIML. #MLsec https://youtu.be/6hpvMzxNyCM

  • Post #2529679

    It&amp;#39;s a great time to be a crackpot https://www.mcsweeneys.net/articles/were-diversifying-the-university-by-hiring-more-crackpots

  • Post #2326345

    As always, great reporting from @dangoodin https://arstechnica.com/security/2026/05/chaos-erupts-as-cyberattack-disrupts-learning-platform-canvas-amid-finals/

  • Post #2326342

    Fix the damn software #swsec #appsec #MLsec &amp;quot;Those vulnerabilities have been fixed, and will never again be available to attackers. In the future, AIs automatically finding and fixing vulnerabilities in all software will be a normal part of the development process, which will result in much more secure software.&amp;quot; https://www.theguardian.com/commentisfree/2026/may/08/how-dangerous-is-anthropics-mythos-ai

  • Post #2326340

    What is better...fox guards chicken house it built just for chickens OR nobody guards chicken house at all?? https://fortune.com/2026/05/06/trump-administration-embraces-ai-oversight-policies-it-once-rejected-anthropic-mythos-caisi/?sge456

  • Post #1879212

    Episode 156 of Silver Bullet features Phil Venables talking #MLsec, #AgenticAI and #security Phil Brings decades of CISO experience from Goldman to Google to the table. Please listen and subscribe. https://berryvilleiml.com/2026/05/01/silver-bullet-security-podcast-156-phil-venables/

  • Post #1791388

    Dear tech press, we will never red team or pen test our way to #AI security. This story is, in that way, a big disservice to #MLsec. Please focus on building security in. Looking at you @TheGuardian https://www.theguardian.com/technology/2026/apr/29/meet-the-ai-jailbreakers-i-see-the-worst-things-humanity-has-produced

  • Post #1589665

    Great to see a BIML quote in this Fortune piece. Our next big piece of work is on measurement (in final review now), so the story timing is great. #MLsec #ML #AI #swsec #appsec #infosec https://fortune.com/2026/04/23/ai-cybersecurity-standards-mythos-nist-owasp-sans-cosai-dc-meeting-eye-on-ai/?sge456

  • Post #1383867

    Finally some tech press interest in data poisoning in #ML. When you turn that on in a loop, it becomes RECURSIVE POLLUTION, which in severe cases leads to model collapse. This is the kind of #MLsec risk that commercial players are completely ignoring. https://berryvilleiml.com/2026/01/10/recursive-pollution-and-model-collapse-are-not-the-same/

  • Post #1383149

    A good posting reality check on Anthropic&amp;#39;s mythos hyperbole around #swsec #appsec #MLsec adjacent https://blog.vidocsecurity.com/blog/we-reproduced-anthropics-mythos-findings-with-public-models

  • Post #1238187

    Beigification? Beigification! &amp;quot;It makes average sound like genius.&amp;quot; https://berryvilleiml.com/2026/03/12/on-beigification/ Watch Mo Bitar in CEO mode. --&amp;gt; https://youtu.be/nDL3Ch7Nz8c?si=aUA24kzcPY7a_CIO #MLsec