Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Aristotelis Tzafalias

@aristot73@infosec.exchange
  • Open on infosec.exchange

When buffers overflow into policy
Views are my own

171 Followers
542 Following
50 Posts
Joined November 07, 2022

Posts

Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 25, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Dear citizens of the USA, get your own GDPR to bash.
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 25, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
AI Sovereignty and National Security: Identifying the UK’s Dimensions of Control UK, Centre for Emerging Technology and Security (CETaS)* The Centre's mission is to strengthen UK security through pioneering research on emerging technologies. 20 July 2026 "More critical national security uses, on the other hand, need high levels of control across all of these dimensions, which will likely involve UK-controlled inference, locally retained open-weight fallbacks, accredited environments, and tested portability between providers. These measures can protect information and preserve service during external disruption, but they cannot guarantee access to the world’s most capable models. The UK’s aim should therefore be controlled dependence – using frontier systems where their advantages justify the exposure to risks such as loss of access, while ensuring that, if essential AI functions degrade, they do so gracefully rather than fail outright." https://cetas.turing.ac.uk/publications/ai-sovereignty-and-national-security-identifying-uks-dimensions-control *CETAS is a research centre based at the Alan Turing Institute, the UK’s national institute for data science and artificial intelligence.
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 22, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @flyingpenguin@infosec.exchange
@flyingpenguin@infosec.exchange also reminded me of your post on models cheating benchmarks... couldn't find it :(
0
1
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 22, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
OpenAI's access to OpenAI models should be revoked pending an independant review of the company's security controls. [partly ironic]
0
1
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 21, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @aristot73@infosec.exchange
Mapping CJEU limits on data retention frameworks: A basic introduction EPRS Briefing 16-07-2025 "Since the 2014 invalidation of the Data Retention Directive, the EU legal landscape has become fragmented, causing uncertainty for providers and challenges for law enforcement. With a Commission proposal likely and growing Member State support for a more permissive EU regime, a solid understanding of relevant CJEU case law may help inform Parliament's assessment. Over the past decade, CJEU case law has set detailed requirements for data retention. Laws must respect proportionality and necessity, with a clear hierarchy of objectives: general and indiscriminate retention of traffic and location data is only permissible for safeguarding national security, while targeted retention of such data may be justified by public security or other important public interest goals. Any such framework must also include robust safeguards. Similarly, access to retained data must be limited to the purpose for which it was collected or a more important objective. The ECtHR ruled that such retention and access require safeguards similar to those for secret surveillance. Stakeholders are divided on a new EU data retention regime. Law enforcement agencies favour EU-level harmonisation but warn against restrictive retention rules that would limit their operational effectiveness. Providers of electronic communications services support a CJEU-compliant EU framework and seek cost compensation. Civil society organisations oppose new EU rules and urge the Commission to focus on enforcing existing case law through infringement procedures." https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2025)775878
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 21, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @aristot73@infosec.exchange
Renewed debate on a future EU data retention framework EPRS | European Parliamentary Research Service - Hendrik Mildebrath and Silvia González Vidal Published: 7 July 2026 "Although the Court of Justice of the European Union (CJEU) continued developing EU data retention standards after invalidating the former EU Data Retention Directive in 2014, national interpretations diverge and efforts towards alignment have stalled. Law enforcement and judicial authorities report operational challenges arising from this fragmentation, sometimes precluding timely access to communications-related data necessary for identifying suspects and victims, reconstructing criminal activity, and generating investigative leads. In response to these issues and to calls from the Council, the European Commission is assessing the need for a new EU framework. Any legislative action would require a series of politically and legally sensitive design choices. Controversy may arise in relation to the legitimacy and appropriate scope of renewed EU legislative intervention; the operationalisation of the CJEU's system of graduated objectives and safeguards; the adequacy of retention periods; the design of access conditions and safeguards; and, possibly, the need to regulate automated processing of retained datasets. This briefing builds on the overviews provided in the EPRS briefings 'Towards new EU data retention rules' and 'Mapping CJEU limits on data retention framework'." https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)789334
0
1
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 21, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Towards new EU data retention rules EPRS | European Parliamentary Research Service - Silvia González Vidal and Hendrik Mildebrath Published: 7 July 2026 "Despite judicial and now-defunct legislative efforts to harmonise data retention practices across the EU, national data retention regimes remain fragmented, with some countries adopting their own rules and others none at all. Law enforcement authorities report operational difficulties, while service providers face significant compliance burdens and costs. Although the Court's case law has clarified the general principles governing data retention, important practical details remain unresolved. In response, the European Commission is assessing the need for a new harmonised EU framework, with a proposal potentially forthcoming. However, stakeholders are divided over its scope and safeguards." https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)789333
0
1
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 20, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @aristot73@infosec.exchange
👆 @fj@mastodon.social
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 20, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange

RE: https://infosec.exchange/@aristot73/116562947812685451

New entries to the reference list. Common theme...

  1. @nielsprovos@ioc.exchange — When AI Safety Becomes a Competitive Moat — https://www.provos.org/p/when-ai-safety-becomes-a-competitive-moat/

  2. Jessica Ji and Andrew Lohn (Georgetown CSET) — Why blocking AI models won't stop the cyber threats they create (CyberScoop op-ed) — https://cyberscoop.com/why-blocking-ai-models-wont-stop-cyber-threats-op-ed/

  3. Mark Dalton (R Street Institute) — Model Panic: How Fear of Open-Source AI Is Ceding Ground to China — https://www.rstreet.org/commentary/model-panic-how-fear-of-open-source-ai-is-ceding-ground-to-china/

  4. @joshuasaxe@sigmoid.social — We need to rescue the AI safety research program from its incoherence — https://joshuasaxe181906.substack.com/p/we-need-to-rescue-the-ai-safety-research

0
1
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 20, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @fj@mastodon.social
@fj@mastodon.social see also the conclusion from @nielsprovos@ioc.exchange post https://www.provos.org/p/case-for-open-weight-models/ "Frontier models have a place. They are tools for leverage, evaluation, and exploring the edge of what is possible. The mistake is letting them become the invisible policy engine inside a production system, where their price, their values, their refusals, and their availability are set by someone else. Use them from outside the boundary. Keep the model you depend on auditable, forkable, and yours."
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 18, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange

RE: https://infosec.exchange/@aristot73/116562947812685451

New entries added to the "When buffers overflow into policy" project references:

2026-07-17 — UK AISI — How Far Behind the Frontier are Leading Open Weight Models on Cyber? https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber

2026-07-17 — Katie Moussouris (Luta Security) — Gold Eagle: All that Glitters is Not Patched https://www.lutasecurity.com/post/gold-eagle-all-that-glitters-is-not-patched

2026-07-14 — The White House — GOLD EAGLE: federal vulnerability-coordination clearinghouse https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/

2026-07-14 — IMCO exchange of views with Anthropic (European Parliament) — cyber capability, export controls, and EU dependence on non-EU frontier AI https://tzafaar.codeberg.page/other/IMCO-2026-07-14-anthropic-exchange-transcript.html

2026-07-10 — heise online — With Zero-Days, BND and BfV to Become "Super Intelligence Agencies" https://www.heise.de/en/news/With-Zero-Days-BND-and-BfV-to-Become-Super-Intelligence-Agencies-11361538.html

2026-06-26 — Patching the Commons — Four OSS Coordination Initiatives Compared https://tzafaar.codeberg.page/other/oss-security-initiatives-comparison.html

2026-02-03 — He et al. — Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents https://arxiv.org/abs/2602.02164

0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 15, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
"White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination" The White House - July 14, 2026 "President Trump’s bold vision to secure and accelerate American artificial intelligence (AI) innovation is being actioned through the creation of “GOLD EAGLE,” a clearinghouse that enables unprecedented cybersecurity vulnerability coordination. Open-source software partners and American critical infrastructure companies built a coordinated system to receive and patch cyber vulnerabilities at a speed and scale never seen before using the existing authorities and resources of the federal government." https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/
0
1
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 15, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @bert_hubert@eupolicy.social
@bert_hubert@eupolicy.social have you considered writing in Latin, like Spinoza? 🙂
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 09, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
fwiw, it does not make sense to be disappointed in the "EU Parliament" as a whole for any particular decision. Be disappointed in the political groups and/or MEPs that voted in support of the decision. ...and in the next European elections, vote accordingly. For that matter, vote accordingly in the next national elections because the Council is made up of nationally elected governments and the Council needs to agree with the decision for it to become law. Those national governments btw also appoint the Commissioners who put forward the proposal to begin with. #justsaying
50
2
43
1
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 08, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
DE - Legislative procedure JULY 6, 2026 Law on the Reform of Intelligence Service Law "The draft, which is currently undergoing departmental voting, fundamentally changes intelligence law. Central to this is the operational strengthening of the intelligence services, for the highest level of security for the people of Germany and their freedom." https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/OESI2/nachrichtendienstrecht.html
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 07, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
RE: https://infosec.exchange/@aristot73/116877234338008344 7 July 2026 - EU Action Plan on Cybersecurity and Artificial Intelligence - published https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence
Quoting
Aristotelis Tzafalias @aristot73@infosec.exchange
7 July 2026, 15:00 - 16:30 Scrutiny session• Commission statement - Presentation of the Action Plan on Cybersecurity and AI European Parliament Plenary https://www.europarl.europa.eu/plenary/en/home.html
Open quoted post
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 07, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
🇪🇺 EU financial-stability authorities on frontier AI & cyber risk — all published 25 June - 7 July 2026: 📰 "Frontier AI models could strain cyber resilience in the financial system, ESRB warns" — European Systemic Risk Board (ESRB), 7 Jul 2026 https://www.esrb.europa.eu/news/pr/date/2026/html/esrb.pr260707~4e1b68241a.en.html ⚠️ "Warning on systemic cyber risks stemming from frontier artificial intelligence models (ESRB/2026/3)" — European Systemic Risk Board (ESRB), adopted 25 Jun 2026 https://www.esrb.europa.eu/pub/pdf/warnings/esrb.warning260625_on_systemic_cyber_risks_stemming_from_frontier_ai_models~ef424708cf.en.pdf 📊 "Addressing Frontier AI Models with cyber capabilities from a financial stability perspective" — European Systemic Risk Board (ESRB), Jul 2026 https://www.esrb.europa.eu/pub/pdf/reports/esrb.report202607_AImodelscybercapabilites.en.pdf 🏦 "Addressing AI-enabled cybersecurity threats" (letter to CEOs of significant institutions) — ECB Banking Supervision / SSM, 7 Jul 2026 https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026_letter_on_AI_enabled_cybersecurity_threats.en.pdf
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 07, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @aristot73@infosec.exchange
16:15 7 July 2026 EC press conference by European Commission Executive Vice-President Henna VIRKKUNEN on the Action plan on Cybersecurity and Artificial Intelligence https://audiovisual.ec.europa.eu/en/ebs/grid?ebs=yes&ebsplus=yes&date=20260707
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 07, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
7 July 2026, 15:00 - 16:30 Scrutiny session• Commission statement - Presentation of the Action Plan on Cybersecurity and AI European Parliament Plenary https://www.europarl.europa.eu/plenary/en/home.html
2
1
1
1
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 05, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange

RE: @aristot73@infosec.exchange

Six new bibliography entries, in https://tzafaar.codeberg.page/ newest to oldest:

GPT-5.5-Cyber Built a zlib Fuzzing Lab in a Day — Benjamin Samuels (@trailofbits@infosec.exchange of Bits), Jul 2 2026
https://blog.trailofbits.com/2026/07/02/field-reports-from-patch-the-planet/

The Privatization of Vulnerability Management — @jamesberthoty@bird.makeup (Latio Pulse), Jul 2 2026
https://pulse.latio.tech/p/the-privatization-of-vulnerability

Preliminary Report of the Independent International Scientific Panel on AI — UN, Jul 2026
https://www.un.org/independent-international-scientific-panel-ai/en/preliminary-report

BCP-05-X-01: AI-Assisted Vulnerability Information Annotation — GCVE Working Group, Jun 14 2026
https://gcve.eu/bcp/extension/gcve-bcp-05-x-01/, @gcve@social.circl.lu

Written Testimony on the AI Security Landscape — @jackhcable@mastodon.social Cable (Corridor), Jun 4 2026
https://www.corridor.dev/blog/testimony

No Security Meter for AI — @cigitalgem@sigmoid.social Figueroa, McMahon, Bonett (BIML), May 13 2026
https://berryvilleiml.com/docs/no-security-meter-ai.pdf

#Cybersecurity #AISecurity #VulnerabilityManagement #AIgovernance

0
1
1
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 02, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange

RE: @trailofbits@infosec.exchange

If your goal is to provoke an over reaction in policy circles and further restrictions on defenders, keep framing llm advances from an attacker's perspective like this:

"The expertise barrier that kept bespoke fuzzing campaigns out of reach for most attackers is gone. "

3
0
2
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 02, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @adulau@infosec.exchange
@adulau@infosec.exchange @bert_hubert@mastodon.nl I deleted the toot.... 🤦‍♂️
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 02, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange

R. Addis et al., "LLM-based Intelligent Agents for Cybersecurity: A Tutorial and Survey of Automated Vulnerability Discovery," in IEEE Access.

"In addition to surveying existing applications, this work provides a step-by-step walkthrough of integrating agentic AI into penetration testing workflows. The walkthrough explores four phases: (I) mission scoping and prompt engineering for test definition and constraint enforcement, (II) autonomous exploration and tool selection for target interaction, (III) vulnerability hypothesis formation and verification through experiment design and feedback, and (IV) payload generation and refinement to transform validated findings into concrete exploits."

https://ieeexplore.ieee.org/abstract/document/11580353

0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 01, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @aristot73@infosec.exchange

Anthropic: Redeploying Fable 5 30 Jun 2026

"As of today, June 30, the export controls on Fable 5 and Mythos 5 have been lifted.

In the remainder of this post, we provide further details and updates in four areas:

  1. A timeline of events, including updates we made to our safeguards. We discuss the events that led to the export control directive and how we addressed it with new safeguards.

  2. A shared industry framework. Although we have reached a constructive resolution, these events have made clear that the industry needs a consistent way to assess and fix potential “jailbreaks” of AI models (techniques that bypass a model’s safeguards).

  3. A shared standard for judging the severity of a given jailbreak would help AI developers triage new findings as they arise, launch highly capable models with greater safety, and communicate the level of risk consistently to government and industry partners. Together with Amazon, Microsoft, Google, and other Glasswing partners, we’ve started to develop such a framework, and we outline it below.

  4. Deeper government collaboration. We’re also strengthening our level of collaboration with the US government on new pre-release testing, information sharing, and research collaboration. We describe this deeper collaboration in the final section."

https://www.anthropic.com/news/redeploying-fable-5

1
0
2
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jul 01, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
US removes curbs on Anthropic's latest Fable and Mythos AI models 1 July 2026 https://www.reuters.com/business/us-lift-export-controls-anthropics-fable-ai-model-tuesday-source-says-2026-06-30/ Antrhropic statement in reply
1
0
2
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jun 30, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
RE: https://infosec.exchange/@aristot73/116562947812685451 📚 New in the references list at https://tzafaar.codeberg.page/ 🔹 Escape QEMU: Watching IronCurtain and an Open-Weight Model Break Out — @nielsprovos@ioc.exchange (30 Jun 2026) https://www.provos.org/p/qemu-escape-glm-5-2/ 🔹 Inside the Advisory Database and what happens when vulnerability volume breaks records — Madison Ficorilli, GitHub (29 Jun 2026) https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/ 🔹 AI cybersecurity safety will be won through adoption not restriction — @joshuasaxe@sigmoid.social (29 Jun 2026) https://joshuasaxe181906.substack.com/p/ai-cybersecurity-safety-will-be-won 🔹 We have Mythos at Home: GLM 5.2 beats Claude in our Cyber Benchmarks — Semgrep Security Research (22 Jun 2026) https://semgrep.dev/blog/2026/we-have-mythos-at-home-glm-52-beats-claude-in-our-cyber-benchmarks/ 🔹 Patterns for Building Cybersecurity Evals — @eugeneyan@recsys.social (21 Jun 2026) https://eugeneyan.com/writing/cybersecurity-evals/ 🔹 Athena: an industry coalition to protect open source software from AI attacks — Chainguard (15 Jun 2026) https://www.chainguard.dev/athena 🔹 Protect yourself against AI-enhanced attacks (2 guidance docs) + AI-driven Cyber Threats: The Next Twelve Months — NCSC-SE, IVA & AI Sweden (Jun 2026) https://www.ncsc.se/sv/publikationer/ 🔹 Project Lightwell ($5B to secure open source in the AI era) — IBM & Red Hat (28 May 2026) https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era 🔹 Using LLMs to secure source code — Eugene Yan & Henna Dattani, Anthropic (27 May 2026) https://claude.com/blog/using-llms-to-secure-source-code 🔹 RAPTOR — Autonomous Offensive/Defensive Research Framework — @gadi@infosec.exchange, @dcuthbert@defcon.social, @HalvarFlake@mastodon.social et al. (23 Apr 2026) https://github.com/gadievron/raptor
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jun 30, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Inside the Advisory Database and what happens when vulnerability volume breaks records The GitHub Advisory Database is processing more vulnerability reports than ever before. Here’s what’s driving the surge, how we’re responding, and how the community can help. Madison Ficorilli - June 29, 2026 https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jun 28, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @bagder@mastodon.social
@bagder@mastodon.social @icing@chaos.social absolutely. will highlight. The idea was to put them side by side and "disect" across some characteristics. Even at PR level there's plenty to think/be concerned about.
1
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jun 28, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @bagder@mastodon.social
@bagder@mastodon.social @icing@chaos.social i tried to piece together the 4 recent initiatives (Akrites, Lighwell, Athena, Patch the Planet) comparing them across several dimensions including OSS project role in governance which is not great, to say the least. https://tzafaar.codeberg.page/other/oss-security-initiatives-comparison.html
3
0
3
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jun 27, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Software Security Analysis in 2030 and Beyond: A Research Roadmap Published: 26 May 2025 Abstract: As our lives, our businesses, and indeed our world economy become increasingly reliant on the secure operation of many interconnected software systems, the software engineering research community is faced with unprecedented research challenges, but also with exciting new opportunities. In this roadmap article, we outline our vision of software security analysis for the systems of the future. Given the recent advances in generative AI, we need new methods to assess and maximize the security of code co-written by machines. As our systems become increasingly heterogeneous, we need practical approaches that work even if some functions are automatically generated, e.g., by deep neural networks. As software systems depend evermore on the software supply chain, we need tools that scale to an entire ecosystem. What kind of vulnerabilities exist in future systems and how do we detect them? When all the shallow bugs are found, how do we discover vulnerabilities hidden deeply in the system? Assuming we cannot find all security flaws, how can we nevertheless protect our system? To answer these questions, we start our roadmap with a survey of recent advances in software security, then discuss open challenges and opportunities, and conclude with a long-term perspective for the field. https://dl.acm.org/doi/10.1145/3708533
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jun 27, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Releasing (UK) AISI’s Engineering Playbook Building on the momentum of the Inspect toolkit, we’re open-sourcing parts of the research stack behind AISI's evaluations. Jun 18, 2026 https://www.aisi.gov.uk/blog/releasing-aisis-engineering-playbook
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jun 25, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @bert_hubert@eupolicy.social
@bert_hubert@eupolicy.social great minds.... https://infosec.exchange/@aristot73/116560205979084175
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · Jun 16, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
too soon to tell whether the latest in a series of "wake up" calls leads to meaningful change. in case it doesn't, this is my goto gif.
Your browser does not support the video tag.
12
1
7
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 18, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @bagder@mastodon.social
@bagder@mastodon.social inspired
1
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 14, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @bert_hubert@eupolicy.social
@bert_hubert@eupolicy.social thanks for the writeup! I sincerely hope such a politically broad grouping can survive 🤞
1
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 14, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @bert_hubert@eupolicy.social
@bert_hubert@eupolicy.social link (pdf) to the JRC report "Open but Not Powerless: Towards a Common Understanding of EU Digital Sovereignty" https://publications.jrc.ec.europa.eu/repository/bitstream/JRC144908/JRC144908_01.pdf
0
1
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 14, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @HalvarFlake@mastodon.social
@HalvarFlake@mastodon.social btw, NIST CAISI took down the announcement of the agreement with frontier models https://news.risky.biz/srsly-risky-biz-the-ai-regulation-knife-fight/
Srsly Risky Biz: The AI Regulation Knife Fight
Risky.Biz

Srsly Risky Biz: The AI Regulation Knife Fight

Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Patrick Gray. This week's edition is sponsored by Knocknoc. You can hear a podcast discussion of this newsletter

1
0
1
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 13, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @buherator@infosec.place
@buherator@infosec.place @icing@chaos.social so far I've come across two examples, one being the UK NHS. know of any others?
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 13, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @HalvarFlake@mastodon.social
@HalvarFlake@mastodon.social "The Wreckoning"
2
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 12, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @bagder@mastodon.social
@bagder@mastodon.social "you're right to push back on that. let me rephrase..." 🙂
49
1
3
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 11, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @bagder@mastodon.social
@bagder@mastodon.social spectacular result! Huge congratulations to the entire team! Made my day :)
1
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 08, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @cynicalsecurity@bsd.network
@cynicalsecurity@bsd.network seems that you were right :)
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 08, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @kfanyo@infosec.exchange
@kfanyo@infosec.exchange the crazy thing is that the prompt was for claude to read and double check a document that claude itself had produced less than 5min earlier. no guardrails there... 🤷‍♂️
0
1
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 08, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange

I asked claude to check something. it did. I saved the result.

I upload the result - again to claude - for a second pass. Hit the guard rail.

2nd time today.

Have no idea what's going on :)

0
2
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 08, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange

RE: @lapt0r@infosec.exchange

innovation or automation?

0
2
1
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 08, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @wdormann@infosec.exchange
@wdormann@infosec.exchange 😀
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 08, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @wdormann@infosec.exchange
@wdormann@infosec.exchange I pasted your toot in claude asking if the three are somehow related other than by all of them being LPEs. Result: "This request triggered restrictions on violative cyber content and was blocked [...] request an adjustment pursuant to our Cyber Verification Program..." hmm....I guess that's the end of my career as an advanced conversationalist hacker.
4
1
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 06, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @icing@chaos.social
@icing@chaos.social https://infosec.exchange/@aristot73/116503506779779128
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 06, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @nyhan@fediscience.org
@nyhan definitely one to watch
0
0
0
0
Open post
aristot73
Aristotelis Tzafalias @aristot73@infosec.exchange · May 06, 2026
Aristotelis Tzafalias
@aristot73@infosec.exchange

When buffers overflow into policy Views are my own

infosec.exchange
Replying to @Taco_lad@aus.social
@Taco_lad @ondra had to look up "grover house" :)
2
1
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:13:45 UTC