Elektrine lite

← Feed

Teri Radichel

teriradichel@infosec.exchange

<p>CEO, 2nd Sight Lab. AI Assisted <br />Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research</p>

Posts

  • Post #4380467

    Why am I seeing AirPods tracking notifications on my phone when I do not use AirPods. Anyone?

  • Post #4380451

    Why am I seeing AirPods tracking notifications on my phone when I do not use AirPods. Anyone?

  • Post #4358523

    Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS …threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit. https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html

  • Post #4165474

    5 days ago I wrote this on X: So let’s just guess that the package manager was JFrog. If you are running JFrog keep a close eye on your network traffic. Unfortunately anything with Internet access, if compromised, can become a proxy. Like DNS servers. Not an easy problem to solve. ~~ I was right. JFrog was the third party package manager the agent escaped in the OpenAI / Hugging Face incident. Now about everything else…I hope people are starting to understand how network security is one of y...

  • Post #4135639

    SSH Key on a Yubikey ~ Almost Protecting credentials from rogue AI agents and malware on your laptop and how Apple makes it difficult https://teriradichel.substack.com/p/ssh-key-on-a-yubikey-almost

  • Post #4135602

    SSH Key on a Yubikey ~ Almost Protecting credentials from rogue AI agents and malware on your laptop and how Apple makes it difficult

  • Post #4088724

    Revisiting the Bastion Host In Light of AI Agent Escapes A bastion host adds a point of inspection for potential rogue traffic https://teriradichel.substack.com/p/revisiting-the-bastion-host-in-light

  • Post #4088666

    Revisiting the Bastion Host In Light of AI Agent Escapes A bastion host adds a point of inspection for potential rogue traffic https://teriradichel.substack.com/p/revisiting-the-bastion-host-in-light

  • Post #3900261

    Using gpt terra trying to delete time files just like Anthropic did. Completely messing up multithreaded architecture. Accidentally deleted files and tried to restore from five day old backups. Chinese characters appeared on screen at some point. In no way proves this is Chinese issue. Could be random or someone trying to make it look like a Chinese hacker. I have no idea. I couldn’t get enough info. But the model tried to tell me it wasn’t Chinese. Google AI says it is some Chinese gambling s...

  • Post #3894243

    This is so awesome and a great reason to use Kiro CLI (@kirodotdev Kiro.dev) Now you can select from Anthropic and OpenAI models in Kiro. Just type /model and select the model to use. Why this is so cool… I have a custom agent framework and run different agents in different terminal windows. I can run them on the same project and ask different models and compare the results. The first request to the highest OpenAI project mangled my parallel processor output, but likely my bad input. I fix...

  • Post #3842771

    RE: https://infosec.exchange/@teriradichel/116925067367520094 Can you build real world software with AI? Yes. But it’s not like you just let an agent do it all. It’s a lot harder than that. This took about 4 months, long hours, a few hiatuses. And it’s complicated, multithreaded, parallel processing with a complex underlying updatable architecture. But I’ve been trying to get something like this done for the past 5 years without AI and AI made it possible to get it to a working state. I wouldn’...

  • Post #3743034

    RE: https://infosec.exchange/@teriradichel/116839536008038553 A few core things that would help AI 🤖 models burn less tokens. 💰 Yesterday was all manual. The agents were just pounding on some things and not fixing certain bugs so I turned it off and dug into the code. So many errors were hidden by not pushing the bugs out of the subshell to the surface or not writing a message at all after an error occurs &lt; and that is how AI models “fix” a lot of bugs. They don’t really fix the underlying...

  • Post #3712590

    🥲 Today felt like a waste of time mostly. The models were so slow and made so many mistakes I had to walk them through every little thing. They reverted bug fixes I made manually. Another $200 burned. I had a few tricky problems they couldn’t figure out themselves and even though I did a lot of the legwork today still ran me out of credits. What happened right before it times out was one of the agents deleted some diagram recursive xml code I had painstakingly walked it through creating and...

  • Post #3678307

    More to come on the blog when time allows. Hope the agents have all the bugs fixed by the time I’m back from running errands. Blog: ✍️👩‍💻🤖🔒 https://teriradichel.substack.com

  • Post #3677893

    1123 bugs fixed this week. 🐞🐛🐜🦟🪲🪳🕷️ By My AI agents. 🤖🤖🤖🤖🤖🤖🤖🤖🤖 But Kiro/Anthropic going so S-L-O-W 🥱 right now. The bug counts will not move as fast as a result. Opus 4.8. Some bugs are actually architectural changes or features but mostly bugs. I gave up on clean code. It is ok but not as perfect as I would like. Too much duplication though I have strict rules and tests for critical components. I figured out I was wasting tokens having agents write the bugs except for some bulk updates....

  • Post #3585263

    The loudest and most reprimanding voices are not always the most right voices. I’m just over here writing about what I experience when I actually use AI models and reposting other’s empirical evidence, not hot takes, opinions, or other such noise. Choose wisely. Do your own research.

  • Post #3540489

    Most cybersecurity workers have been told to conceal a breach report finds. -Cybersecurity Dive https://www.cybersecuritydive.com/news/data-breach-coverups-ai-bitdefender/824331/

  • Post #3530909

    It’s July 1st and I’ve used up all the tokens in a $200 plan this month already. So that’s how it’s going. Fable came out. Opus is dumber and slower. Happens every time a new model comes out even when it’s not available yet. Though new version of sonnet came to AWS. But I’m not using sonnet. At one point I asked the model which model it was. Twice it said it inferred that it was Sonnet. But then it said it was guessing.

  • Post #3491638

    Managing an AWS Organization With AI Generated Code A new take on the AWS Control Tower concept https://teriradichel.substack.com/p/managing-an-aws-organization-with

  • Post #3431377

    ⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️ Yesterday the 🤖 model randomly tried to source a (thankfully) non-existent delete-all-accounts file in a file that was sourced by a file that is only supposed to list all the accounts in an AWS OU. I never told it to source either of those rogue files. Let that sink in. ⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️

  • Post #1935530

    I have to take care of a family member. Headed out to help her for I don’t know how long but hope to be working on AI again soon. Trying to enjoy the scenery along the way waiting for her to get back home.

  • Post #1632295

    Note: As part of the analyzed intrusions, public-facing applications and valid accounts were abused for initial access. The state-sponsored hackers targeted Ivanti, Cisco, Fortinet, VMware, and Palo Alto Networks appliances, as well as Apache Struts and other web-facing platforms. - Are these 100% American products? Buying American doesn’t mean we are safe. - The tactics used here show exactly how stealthy malware can be. A shell triggered by a particular byte sequence? Something that puts its...

  • Post #1632293

    Latest scam. Interesting that when I used Apple cleanup to remove the ticket number it didn’t remove it but instead characters from another Arabic looking language showed up instead. This came as an attachment. Took screenshot. I did the cleanup like 5 times and then chars gone.

  • Post #1632292

    How I Use AI for Penetration Testing Speaking at the Computer History Museum in Mountain View, CA April 10, 2026 https://teriradichel.substack.com/p/how-i-use-ai-for-penetration-testing

  • Post #1632291

    Iran has rapidly developed advanced cyber capabilities, evolving from information gathering to conducting destructive, state-linked attacks against critical infrastructure in the U.S., Israel, and the Gulf states. https://share.google/aimode/50qKfH5TPLWSJFVOB

  • Post #1632290

    I was just listening to an interview on the radio with a person who worked at a hospital. 1. Your cyber insurance makes you a target. They know how much you can pay. 2. Don’t use your backups until you have eliminated the attacker or they will encrypt your backups too. 3. Pull the plug until you figure that out and cut them off (except critical patient machines). The hospital in story I was listening to had people running across the hospital when faxes were overused and started smoking....

  • Post #1632289

    Wonder if this has anything to do with performance degradation of anthropic models. But are you now paying more for same effort you were getting previously if you change this? • Default Shift: In March 2026, users on Reddit and developer forums reported that the default was quietly shifted from high to medium for many subscribers, which explains the sudden change in performance. Need to check this out later. Flying out to speak at AWS Community Day in Mountain View.

  • Post #1632288

    RE: https://infosec.exchange/@teriradichel/116358599436420889 I read all the Mythos hype right before I submitted my talk for today at the Computer History Museum. Did I need to change my slides? Nope.

  • Post #1632287

    🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖 Pentesting is not a scanner or a fuzzer - whether SAST, DAST, AI, deterministic or non-deterministic. Pentesting is a human * using those tools * to see if they can find a security problem that your teams and tools may have missed. 🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖

  • Post #1632286

    Awesome video on S3 files https://youtu.be/zb8TdNJhZCk