Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Adam Shostack :donor: :rebelverified:

@adamshostack@infosec.exchange
  • Open on infosec.exchange

Author, game designer, technologist, teacher.

Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board.

Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security.

Following back if you have content.

4351 Followers
688 Following
50 Posts
Joined November 06, 2022
Website:
https://shostack.org
Latest book:
https://threatsbook.com
Opsec status:
Currently clean
Youtube:
https://youtube.com/shostack

Posts

Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Aug 05, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
RE: https://mastodon.social/@ASegar/117038965891949888 I'm old enough to remember when the first amendment protected free association, and when the Supreme Court Counterman decision limited what counts as a "true threat."
Quoting
Adrian Segar @ASegar@mastodon.social
#Trump designated #ANTIFA a domestic terrorist organization. The invention has proved more useful than a real organization, because a group without a membership list is one whose members the government simply gets to make up. The state no longer proves what you believe by what you did; it proves what you did by what you believe. https://www.thenation.com/article/politics/trump-nspm-7-repression/
Open quoted post
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Aug 04, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
RE: https://mastodon.social/@ASegar/117038965891949888 I’m old enough to remember when the first amendment protected free association and the supreme court ruling in Counterman.
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Aug 03, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @petrillic@hachyderm.io
@petrillic@hachyderm.io Ferengi will do anything to avoid using the metric system.
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Aug 03, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @cstross@wandering.shop
@cstross@wandering.shop "Now witness the power of this fully armed and operational marketing platform."
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 31, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @jerry@infosec.exchange
@jerry@infosec.exchange @paul_ipv6@infosec.exchange Does the prospectus treat it as a business risk or a growth opportunity?
2
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 31, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @jerry@infosec.exchange
@jerry@infosec.exchange @paul_ipv6@infosec.exchange Just out of curiosity, is “our models commit crimes” a good thing or a bad thing in early 21-st century capitalism?
29
3
10
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 31, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @noplasticshower@infosec.exchange
@noplasticshower@infosec.exchange :blob_blowing_kiss:
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 31, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
RE: https://sigmoid.social/@cigitalgem/117012132756167391 If you want to play in the big leagues you need an event that’s smarter than you
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 31, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @lcamtuf@infosec.exchange
@lcamtuf@infosec.exchange As Erik Bloodaxe, the visionary, said, "I only hack for money"
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 30, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @campuscodi@mastodon.social
@campuscodi@mastodon.social No, there's a second master key. https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-vulnerability-walkthrough (2021)
ChaosDB explained: Azure's Cosmos DB vulnerability walkthrough | Wiz Blog
wiz.io

ChaosDB explained: Azure's Cosmos DB vulnerability walkthrough | Wiz Blog

This is the full story of the Azure ChaosDB Vulnerability that was discovered and disclosed by the Wiz Research Team, where we were able to gain complete unrestricted access to the databases of severa

0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 30, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @briankrebs@infosec.exchange
@briankrebs@infosec.exchange I meant feeding junk into the advertising/surveillance stream.
38
5
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 30, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @briankrebs@infosec.exchange
@briankrebs@infosec.exchange So you're saying there's pros and cons? 😇
31
6
1
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 30, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @josephcox@infosec.exchange
@josephcox@infosec.exchange Maybe it’ll work as well as the “report spam” button, where the response is always “we have determined this doesn’t violate our community guidelines “
10
0
3
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 29, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @dangoodin@infosec.exchange
@dangoodin@infosec.exchange Do you have anything on how long the project was? What was the cost of the not-reported research in human time and in tokens?
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 29, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @Perrin42@mastodon.social
@Perrin42@mastodon.social Nah it was awesome
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 29, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @Perrin42@mastodon.social
@Perrin42@mastodon.social I dunno, do you feel spun out of control?
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 29, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
RE: https://social.linux.pizza/@simonbp/117000560404338238 Look I don’t make the rules but if you skip this opportunity to swiftly make “satellites with attitude problems” jokes that’s on you.
0
2
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 28, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @rmd1023@infosec.exchange
@rmd1023@infosec.exchange Sorry to hear it and thanks for the reminder!
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 28, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
I'd like to announce that, to the best of our knowledge, @shostackassociates.bsky.social has not been hacked by OpenAI.
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 28, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @codinghorror@infosec.exchange
@codinghorror@infosec.exchange Wow, thank you!
5
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 28, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to on federate.social
@mattblaze@federate.social We have always been at war with Eurasia
8
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 28, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
@mattblaze@federate.social Like and subscribe for more high quality facts!
4
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 28, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to on federate.social
@mattblaze@federate.social In 1990, telephony was on DHS’s list of critical national infrastructure and the phone company could arrest phreaks.
3
0
1
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
PHANTOM-B at Black Hat I'm presenting PHANTOM-B on Wednesday at Black Hat and reprising it on Saturday in the AppSec Village at DEF CON. Check out our full schedule (https://shostack.org/blackhat) for details and read the whitepaper ahead of the talk (/resources/whitepapers)! (14/15)
S+A in Las Vegas 2026 | Shostack + Associates
shostack.org

S+A in Las Vegas 2026 | Shostack + Associates

Information about S+A's plans at Black Hat 2026 & DEF CON AppSec Village

1
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
Image by Gemini: “draw an 8x3 image of robot in a black hoodie with an aliens-style face hugger attached to it; the robot should be sitting at a desk hacking; redo the colors in Watercolor style impressionist colorism; redo in cinematic volumetric light, with #5253a4 blue as a theme color; make it lighter.” (15/15) Full post with links & formatting: https://shostack.org/blog/lessons-from-openai-huggingface-ai-security
2
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
We see these issues: anthropomorphization, overreliance on benchmarks, and aspiration-driven thinking all the time as we help clients navigate how to use LLMs in threat modeling, but they are really about LLMs. They extend far beyond threat modeling. That's why we included two (anthropomorphization and over-reliance) in version 1 of the PHANTOM-B model (/resources/whitepapers). Who knows, maybe a future version will need benchmarkmaxxing as a threat? (12/15)
3
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
Understanding the value of an improvement, rather than focusing on a single benchmark, is a crucial part of engineering. Engineering is always about tradeoffs, not “maxxing.” (11/15)
2
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
Other commentary: • Neil Wyler (aka Grifter) wrote an excellent article, OpenAI gave its model a test, it broke out of its sandbox and hacked Hugging Face to steal the answers (https://coalfire.com/the-coalfire-blog/openai-gave-its-model-a-test-it-broke-out-of-its-sandbox-and-hacked-hugging-face-to-steal-the-answers) covering speed, the two-sided nature of guardrails, and regulation threats. • Laurie Voss has a philisophically interesting essay, Did OpenAI hack Hugging Face or didn't they? (https://seldo.com/posts/did-openai-hack-hugging-face-or-didnt-they/) on the legal question of “could anyone be held accountable?” • The Cloud Security Alliance and partners released Hugging Face Incident Initial Post-Mortem (https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem) (13/15)
coalfire.com

OpenAI gave its model a test, it broke out of its sandbox… | Coalfire

When I read OpenAI's post today, sitting on top of Hugging Face's disclosure from last week, my first reaction was a big dumb grin. “This…is…awesome.” A…

1
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
Volume overwhelms everything, especially judgment. The team at OpenAI either can’t or won’t slow down to look at the output of these systems. Now, maybe, that’s the right call? Velocity is its own reward? That’s certainly possible - maybe small shifts in position on benchmarks herds customers onto those models, and so a win on the benchmark is a revenue driver. (If only the AI folks knew about the complexity of gradient-climbing as a strategy? 🤷) But more seriously: OpenAI gets business value out of using its technology, learning where it adds value, and trumpeting that as a new value prop for LLMs. Apparently that’s not... parsing the output of its tools. (8/15)
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
Benchmarks are useful when they measure what matters. As far back as 1975, Goodhart wrote “Any observed statistical regularity will tend to collapse once pressure is placed upon it for control purposes,” or as Marilyn Strathern memorably rephrased it, “When a measure becomes a target, it ceases to be a good measure.” The possibility of stealing test answers may be the ultimate expression of Goodhart’s law. (9/15)
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
But moving beyond OpenAI, most organizations are not competing on the basis of those benchmarks, they’re competing on value delivered to customers. (10/15)
1
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
It’s also worth noting that the apparent goal was to steal the answers to the ExploitGym benchmark (https://simonwillison.net/2026/Jul/22/openai-cyberattack/) We’ll come back to that. (5/15)
Simon Willison’s Weblog

OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened

This story is wild. The short version: OpenAI were running a cybersecurity test against an unreleased model, with the model’s guardrail features turned off. Rather than solve the test, the …

0
2
1
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
Volume overwhelms everything, especially judgment. (7/15)
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
Takeaways Anthropomorphization, giving the model human attributes and motivations, underlies the characterization that the notes were for “future versions of itself.” They could have been as easily characterized as “virtual post-its to overcome limited context windows.” The aspiration that these models are human bleeds into thinking in ways that distract us from being able to analyze what we see. (6/15)
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
Despite the popular characterization, the model didn’t “escape.” The model stayed on OpenAI’s servers, running commands elsewhere. (This point was made by Ramez Naam.) (4/15)
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
• Let’s start with the headline: “OpenAI didn’t notice for a week.” Now, I don’t run a highfalutin’ AI Lab, but according to Gadi Evron’s Linkedin post (https://www.linkedin.com/posts/gadievron_my-analysis-from-hosting-hugging-face-at-share-7486340715514437632-Xs-b/) the model went $100,000 over budget in token consumption (although that might be the incident response cost not the cost of the model running exploit gym.) • The next thing I want to comment on is “an agent left notes apparently for future versions of itself...laid out instructions for how agents could free themselves from OpenAI’s internal constraints.” Why would someone assume that’s future versions, rather than the model taking operational notes to ensure that the same model doesn’t lose track in limited context windows? The reflexive anthropomorphization is important here. • ”Four people familiar with OpenAI’s model-training practices say the company often runs several different model ​evaluations at the same time, all of which operate at high speeds and generate such enormous amounts of data that employees sometimes struggle to keep up.” That’s fascinating in two ways: First, they run so many things that no human can make sense of them, and so apparently focus on a score on a benchmark as the relevant thing. (Otherwise, you’d either run fewer evaluations at once, or hire more people to look at the results in detail.) Second, they’re not using LLMs to parse the output into smaller things, possibly because they rely fully on the evaluation tool, and possibly because they know that LLMs are bad at summarization. (3/15)
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
The very big news was that an OpenAI model hacked Huggingface. Raphael Satter has a fascinating story, . OpenAI’s agent spent days hacking a company, but sources say OpenAI did not notice for a week (https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/) and I want to start with a few items from that article. (2/15)
0
1
1
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Lessons from the OpenAI/HuggingFace AI Security Incident (New blog post: https://shostack.org/blog/lessons-from-openai-huggingface-ai-security this is post 1/15) Adam Shostack, Shostack + Associates
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 27, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @briankrebs@infosec.exchange
@briankrebs@infosec.exchange @hal_pomeranz@infosec.exchange @SteveBellovin@infosec.exchange You might talk to an allergist if you got swelling - when I had a bee sting swell up, I was told that there was an accumulation effect, and now carry an epipen, because it's better to have one on hand than $100 in the bank.
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 26, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @ferrix@mastodon.online
@ferrix@mastodon.online I'm ...pressed to see why that won't be misunderstood. ;)
1
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 26, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @codinghorror@infosec.exchange
@codinghorror@infosec.exchange Im working on a blog post, hope to drop it soon.
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 26, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @codinghorror@infosec.exchange
@codinghorror@infosec.exchange The whole openai-huggingface thing where Raphael Satter reported that openai employees are running so many "evaluations" that they can't read the output, and so they're relying on benchmarks?
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 26, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
benchmarkmaxxing is the new tokenmaxxing.
0
3
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 26, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @tmaher@infosec.exchange
@tmaher@infosec.exchange I find your lack of loyalty concerning. Remember, it is not enough to obey the LLM, you must also learn to love the LLM.
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 26, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @Michael_King@pixelfed.social
@Michael_King That's really beautiful. Do you have a site where you sell prints?
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 25, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
If LLMs are like airlines, (high capital cost, low cost of switching, low differentiation), then where's my frequent prompter membership?
0
2
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 25, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to on universeodon.com
@david_castleton@universeodon.com Hi, thank you for the article! Let me clarify my question: If I'm walking around London, how do I distinguish between a captured French cannon and a bollard made to look like one? In my walks around London, I've never noticed a difference. (I've probably seen the one in the article you linked, which seems much taller than the first one.)
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 25, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to on defcon.social
@dcuthbert@defcon.social @thedarktangent@defcon.social But GDPR WAS GONNA SAVE US!
0
1
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 25, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to on universeodon.com
@david_castleton@universeodon.com How do you know it's a real cannon versus something made in that style? (Ok, or, in other words, how do you know it's a canonical cannon?)
0
0
0
0
Open post
adamshostack
Adam Shostack :donor: :rebelverified: @adamshostack@infosec.exchange · Jul 25, 2026
Adam Shostack :donor: :rebelverified:
@adamshostack@infosec.exchange

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security. Following back if you have content.

infosec.exchange
Replying to @adamshostack@infosec.exchange
@mattblaze@federate.social @SteveBellovin@infosec.exchange @20002ist@thepit.social Also mastodon has now shown me the fuller thread, a dignity previously unfairly denied to me.
0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:31:27 UTC