Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Florencio Cano

@florenciocano@infosec.exchange
  • Open on infosec.exchange

Principal Product Security Engineer

0 Followers
0 Following
14 Posts
Joined May 23, 2023
LinkedIn:
https://www.linkedin.com/in/florenciocano/
The team, the team, the team:
https://youtu.be/7KOwLaCf0y0

Posts

Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Aug 07, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
The book "The Goal" is a great read to understand where to use AI to really improve performance. If you improve/automate the wrong step the result is worse.
0
0
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Jul 24, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange

Gemma 4 31B quantized is hands down the best model I have been able to run locally on a RTX 4090. I run it with llama.cpp/build/bin/llama-server -m ~/models/gemma-4-31B-it-Q4_K_M.gguf -c 65536 -ngl 99 -ctk q4_0 -ctv q4_0 -fa on --host 0.0.0.0 --port 8081 Any suggestion to run it more efficiently? Any other model I should try?

0
0
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Jul 22, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
HackMyClaw was an OpenClaw prompt injection challenge: make Fiu leak secrets through email. After many attempts, no one succeeded https://hackmyclaw.com/
0
0
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Jul 21, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
Replying to @iscdotorg@fosstodon.org
@iscdotorg@fosstodon.org I was joking in relation to fact that many times when there is an incident someone says it's because a DNS misconfiguration. I'm sorry I didn't transmit it correctly. I'm not funny.
1
2
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Jul 21, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
Replying to @iscdotorg@fosstodon.org
@iscdotorg@fosstodon.org "just the way DNS works" has caused more damage to availability than distributed denial or service attacks. If "just they way DNS works" is not a CVSS 10, I don't know what it is
6
6
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Jul 19, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
RE: https://infosec.exchange/@SteveBellovin/116944300269431503 "one of the proof’s implications is that there will always be a way to prompt an AI system to disregard its rules — it’s just a matter of finding it."
Quoting
Steve Bellovin @SteveBellovin@infosec.exchange
"NIST Mathematical Proof Supports Transition to a Continuous-Monitor-and-Update Security Model for AI Systems": https://www.nist.gov/news-events/news/2026/06/nist-mathematical-proof-supports-transition-continuous-monitor-and-update In essence, this is an extension of Gödel's Incompleteness Theorem to AI guardrails.
Open quoted post
0
0
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Jul 18, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
Replying to @florenciocano@infosec.exchange
#HuggingFace claims they were unable to use frontier commercial AI models to investigate and do forensics of the attack due to the frontier models guardrails. They used GLM 5.2, an open-weights local model.
0
0
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Jul 18, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
Replying to @florenciocano@infosec.exchange
#HuggingFace detected the attack with AI and correlation: "LLM-based triage over security telemetry to separate real signals from the daily noise, and it was the correlation of those signals that flagged the compromise."
0
1
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Jul 18, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
Related to the #HuggingFace breach https://huggingface.co/blog/security-incident-july-2026 I want highlight this paragraph: "The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline. A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker." It's an example that a malicious or especially crafted database can breach a system and that any point whet code parses trusted data is an attack surface.
0
1
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Jul 15, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
Replying to @iamamoose@infosec.exchange
@iamamoose@infosec.exchange Mark, you said "outside of the threat model". Is that threat model documented anywhere? I ask because I think the threat model could be used to filter security issues and I would like to see Apache's
0
1
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Mar 11, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange

Agent Skills: Explore security threats and controls https://developers.redhat.com/articles/2026/03/10/agent-skills-explore-security-threats-and-controls

0
0
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Feb 23, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
Replying to @mpowney@mastodon.au
@mpowney@mastodon.au I had the same experience, but I wonder if it was because the models I used.
0
4
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Feb 21, 2026
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange

Is anyone running #openclaw with a local LLM and it is working well? I'm specially interested in LLMs that can be run in GPUs with 24GB vRAM.

infosec.exchange

Infosec Exchange

1
6
0
0
Open post
florenciocano
Florencio Cano @florenciocano@infosec.exchange · Jul 05, 2023
Florencio Cano
@florenciocano@infosec.exchange

Principal Product Security Engineer

infosec.exchange
Replying to @kaoudis@infosec.exchange
@kaoudis here there is more information about the different security headers and which are recommended and which not https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html
1
0
1
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:04:48 UTC