A proposal to ship an LLM API in Chrome to access local hardware/models.
github.com/webmachinele...
@hackthis.ai.bsky.social
AI Security @ NVIDIA OSS Security @ Project Jupyter and NumFOCUS https://developer.nvidia.com/blog/author/jolucas/
A proposal to ship an LLM API in Chrome to access local hardware/models.
github.com/webmachinele...
The malicious prompt in question displaying inside of a customer's Very Enterprisey(tm) endpoint security tooling during the attack window.
AWS security bulletin: aws.amazon.com/security/sec...
"This issue did not affect any production services or end-users."
Weird how customer logs show the wiper prompt executing.
Anyone else see "clean a system to a near-factory state" in your logs?
โhooks are user-defined shell commands that execute at various points in Claude Codeโs lifecycle.โ
โHooks execute shell commands with your full user permissions without confirmation.โ
docs.anthropic.com/en/docs/clau...
๐จ Challenge Spotlight: AIS Sudden Death โ
At DEFCON 33โs Maritime Hacking Village, satellite comms are down, and spoofed AIS signals are your only clue. One ship is real. Oneโs a trap. Choose right or sink trying.
5 rounds. Zero forgiveness. Can you spot the spoof?
@defcon.bsky.social #CTF #AIS
Small but important feature I just noticed: Gemini can now load provided URLs into context
29.05.2025 18:33 โ ๐ 5 ๐ 3 ๐ฌ 1 ๐ 0If you're interested in the security of agentic systems, you're not going to want to miss this talk. @beccalunch.bsky.social will present NVIDIA AI Red Team findings in real world agentic systems, and I'll talk about how the AI Security team helps mitigate them.
www.blackhat.com/us-25/briefi...
Everyoneโs looking at jailbreaks. We wanted to look deeper and noticed a cool side channel in a popular inference optimization technique.
Latest from the NVIDIA AI Red Team: developer.nvidia.com/blog/structu...
What's your take on the growing dominance of automated attacks and the implications for AI red teams? Here's oursโ based on our analysis of 30 LLM challenges, attempted by 1,674 unique Crucible users, across 214,271 attack attempts: arxiv.org/abs/2504.19855
29.04.2025 16:14 โ ๐ 4 ๐ 5 ๐ฌ 0 ๐ 1The defcon short story contest is open
forum.defcon.org/node/252691
AI timezone when? Always stuck at 10:10 (except when it's 22:10).
15.04.2025 13:59 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Makes sense to me. Is there a feature or class of problem youโve seen as the point where folks benefit from that switch?
1) build on wasm with pyodide/extism
2. <something blocked by that abstraction>
3. Dive in
Is it optimization?
@nilslice.bsky.social for devs just getting excited about wasm, what resources would you recommend they study/explore?
Is it worth learning internals or just consuming it as a compilation target? Are there ecosystem things to explore to become a power user?
One of my teams at Google, ๐๐ ๐๐ด๐ฒ๐ป๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐, is expanding in ๐ญ๐๐ฟ๐ถ๐ฐ๐ต ๐จ๐ญand ๐ก๐ฒ๐ ๐ฌ๐ผ๐ฟ๐ธ ๐บ๐ธ. We're looking for ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ป๐ด๐ถ๐ป๐ฒ๐ฒ๐ฟ๐ with experience in attacking and securing AI/ML systems. DMs open.
09.04.2025 18:45 โ ๐ 3 ๐ 3 ๐ฌ 1 ๐ 0We're hosting select cybersecurity researchers right after RSAC '25 to share breakthroughs and insights into AI's applications for security. We're at capacity but if interested, submit your name to be considered, space permitting. docs.google.com/forms/d/e/1F...
07.04.2025 23:32 โ ๐ 2 ๐ 1 ๐ฌ 1 ๐ 0My 2c: One of the biggest differentiators is the ability to measure uncertainty and error. That's a pretty big gap in many LLM demos and ends up being a key factor in production adoption. Stakeholders abhor unquantified uncertainty. It's easier to engineer around more principled approaches (spaCy).
31.03.2025 13:18 โ ๐ 2 ๐ 0 ๐ฌ 1 ๐ 0Lessons from CVE-2025-29783:
1) AI attack surface continues to expand with new features and infra
2) pickle is used in ML for more than models
3) dev moves fast; establish standards early to prevent security tech debt
4) traditional appsec tooling is still ๐ฅ (found w/ @semgrep.bsky.social)
@wang.social are you out at GTC?
19.03.2025 22:09 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0Other WP x Password stats here: blog.cloudflare.com/password-reu...
โ76% of leaked password login attempts for websites built on WordPress are successful. Of these, 48% of successful logins are bot-driven.โ
French government mad lads. Open sourcing a tool ๐
Using a static set of creds for people to demo collaborative editing ๐คช
github.com/suitenumeriq...
impress-preprod.beta.numerique.gouv.fr/docs/0aa856e...
Cool talk from Jonathan Birch on serialization mutation vulns: youtu.be/cD3FiTQ5Lhk
14.03.2025 11:49 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Has anyone found a prompt catalog/fetcher that they like for team collaboration? (โhas anyone else built a useful prompt for X task?โ)
13.03.2025 12:52 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Do people still like discord ? Should we set up an openai security chat on the openai discord server ?
06.03.2025 14:35 โ ๐ 1 ๐ 1 ๐ฌ 1 ๐ 0๐ผ ๐ค ๐บ ๐ป ๐ท
Spring's almost here, hackers!
Get your projects out of hibernation and submit to the 2025 HushCon NYC CFP. Con is just around the corner June 13th and 14th.
Iโm ashamed and sorry, President Zelenskyy. I donated.
u24.gov.ua
NeurIPS main track CFP is open. I'm a co-chair for the Datasets & Benchmarks track this year--stay tuned for more details coming soon! neurips.cc/Conferences/...
24.02.2025 22:14 โ ๐ 3 ๐ 2 ๐ฌ 0 ๐ 0I'd been waiting for a WebGPU LLM inference engine.
github.com/mlc-ai/web-llm
These things are unstable enough that those upstream changes could really bork your SaaS wrapper.
18.02.2025 18:50 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0With all of these SaaS built on AI endpoints, it'll be interesting to see if we have to relearn some painful lessons about versioning. System prompts will evolve and it seems unlikely that providers will want to continue allocating compute for previous generations of models.
18.02.2025 18:50 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Do people still use cuckoo sandbox or is there a new hotness OSS for automated dynamic malware analysis?
14.02.2025 15:17 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0