Florencio Cano
florenciocano@infosec.exchange
<p>Principal Product Security Engineer</p>
Posts
-
Post #4430513
The book "The Goal" is a great read to understand where to use AI to really improve performance. If you improve/automate the wrong step the result is worse.
-
Post #4060447
Gemma 4 31B quantized is hands down the best model I have been able to run locally on a RTX 4090. I run it with `llama.cpp/build/bin/llama-server -m ~/models/gemma-4-31B-it-Q4_K_M.gguf -c 65536 -ngl 99 -ctk q4_0 -ctv q4_0 -fa on --host 0.0.0.0 --port 8081` Any suggestion to run it more efficiently? Any other model I should try?
-
Post #4015884
HackMyClaw was an OpenClaw prompt injection challenge: make Fiu leak secrets through email. After many attempts, no one succeeded https://hackmyclaw.com/
-
Post #3928562
RE: https://infosec.exchange/@SteveBellovin/116944300269431503 "one of the proof’s implications is that there will always be a way to prompt an AI system to disregard its rules — it’s just a matter of finding it."
-
Post #3904393
Related to the #HuggingFace breach https://huggingface.co/blog/security-incident-july-2026, I want highlight this paragraph: "The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline. A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker." It's an example that a malicious or especially crafted database can...
-
Post #1745762
Is anyone running #openclaw with a local LLM and it is working well? I&#39;m specially interested in LLMs that can be run in GPUs with 24GB vRAM.
-
Post #1745757
Agent Skills: Explore security threats and controls https://developers.redhat.com/articles/2026/03/10/agent-skills-explore-security-threats-and-controls