Remote
Principal Product Security Engineer
0
Followers
0
Following
14
Posts
Joined May 23, 2023
The team, the team, the team:
Posts
The book "The Goal" is a great read to understand where to use AI to really improve performance. If you improve/automate the wrong step the result is worse.
Open post
Gemma 4 31B quantized is hands down the best model I have been able to run locally on a RTX 4090. I run it with llama.cpp/build/bin/llama-server -m ~/models/gemma-4-31B-it-Q4_K_M.gguf -c 65536 -ngl 99 -ctk q4_0 -ctv q4_0 -fa on --host 0.0.0.0 --port 8081 Any suggestion to run it more efficiently? Any other model I should try?
0
0
0
0
Open post
HackMyClaw was an OpenClaw prompt injection challenge: make Fiu leak secrets through email. After many attempts, no one succeeded https://hackmyclaw.com/
0
0
0
0
Open post
Replying to
@iscdotorg@fosstodon.org
@iscdotorg@fosstodon.org I was joking in relation to fact that many times when there is an incident someone says it's because a DNS misconfiguration. I'm sorry I didn't transmit it correctly. I'm not funny.
1
2
0
0
Open post
Replying to
@iscdotorg@fosstodon.org
@iscdotorg@fosstodon.org "just the way DNS works" has caused more damage to availability than distributed denial or service attacks. If "just they way DNS works" is not a CVSS 10, I don't know what it is
6
6
0
0
Open post
RE: https://infosec.exchange/@SteveBellovin/116944300269431503
"one of the proof’s implications is that there will always be a way to prompt an AI system to disregard its rules — it’s just a matter of finding it."
Quoting
"NIST Mathematical Proof Supports Transition to a Continuous-Monitor-and-Update Security Model for AI Systems": https://www.nist.gov/news-events/news/2026/06/nist-mathematical-proof-supports-transition-continuous-monitor-and-update
In essence, this is an extension of Gödel's Incompleteness Theorem to AI guardrails.
Open quoted post
0
0
0
0
Open post
Replying to
@florenciocano@infosec.exchange
#HuggingFace claims they were unable to use frontier commercial AI models to investigate and do forensics of the attack due to the frontier models guardrails. They used GLM 5.2, an open-weights local model.
0
0
0
0
Open post
Replying to
@florenciocano@infosec.exchange
#HuggingFace detected the attack with AI and correlation:
"LLM-based triage over security telemetry to separate real signals from the daily noise, and it was the correlation of those signals that flagged the compromise."
0
1
0
0
Open post
Related to the #HuggingFace breach https://huggingface.co/blog/security-incident-july-2026 I want highlight this paragraph:
"The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline. A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker."
It's an example that a malicious or especially crafted database can breach a system and that any point whet code parses trusted data is an attack surface.
0
1
0
0
Open post
Replying to
@iamamoose@infosec.exchange
@iamamoose@infosec.exchange Mark, you said "outside of the threat model". Is that threat model documented anywhere? I ask because I think the threat model could be used to filter security issues and I would like to see Apache's
0
1
0
0
Open post
Agent Skills: Explore security threats and controls https://developers.redhat.com/articles/2026/03/10/agent-skills-explore-security-threats-and-controls
0
0
0
0
Open post
Replying to
@mpowney@mastodon.au
@mpowney@mastodon.au I had the same experience, but I wonder if it was because the models I used.
0
4
0
0
Open post
Replying to
@kaoudis@infosec.exchange
@kaoudis here there is more information about the different security headers and which are recommended and which not https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html
1
0
1
0
Remote instance
infosec.exchange
Open on original server