Joe Lucas's Avatar

Joe Lucas

@hackthis.ai.bsky.social

AI Security @ NVIDIA OSS Security @ Project Jupyter and NumFOCUS https://developer.nvidia.com/blog/author/jolucas/

1,230 Followers  |  91 Following  |  71 Posts  |  Joined: 11.10.2023  |  1.7367

Latest posts by hackthis.ai on Bluesky

Preview
GitHub - webmachinelearning/prompt-api: ๐Ÿ’ฌ A proposal for a web API for prompting browser-provided language models ๐Ÿ’ฌ A proposal for a web API for prompting browser-provided language models - webmachinelearning/prompt-api

A proposal to ship an LLM API in Chrome to access local hardware/models.

github.com/webmachinele...

03.08.2025 01:29 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
The malicious prompt in question displaying inside of a customer's Very Enterprisey(tm) endpoint security tooling during the attack window.

The malicious prompt in question displaying inside of a customer's Very Enterprisey(tm) endpoint security tooling during the attack window.

AWS security bulletin: aws.amazon.com/security/sec...

"This issue did not affect any production services or end-users."

Weird how customer logs show the wiper prompt executing.

Anyone else see "clean a system to a near-factory state" in your logs?

24.07.2025 02:01 โ€” ๐Ÿ‘ 51    ๐Ÿ” 13    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 5
Preview
Hooks - Anthropic Customize and extend Claude Code's behavior by registering shell commands

โ€œhooks are user-defined shell commands that execute at various points in Claude Codeโ€™s lifecycle.โ€

โ€œHooks execute shell commands with your full user permissions without confirmation.โ€

docs.anthropic.com/en/docs/clau...

01.07.2025 00:21 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿšจ Challenge Spotlight: AIS Sudden Death โš“

At DEFCON 33โ€™s Maritime Hacking Village, satellite comms are down, and spoofed AIS signals are your only clue. One ship is real. Oneโ€™s a trap. Choose right or sink trying.

5 rounds. Zero forgiveness. Can you spot the spoof?

@defcon.bsky.social #CTF #AIS

26.06.2025 13:55 โ€” ๐Ÿ‘ 9    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Small but important feature I just noticed: Gemini can now load provided URLs into context

29.05.2025 18:33 โ€” ๐Ÿ‘ 5    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Black Hat Black Hat

If you're interested in the security of agentic systems, you're not going to want to miss this talk. @beccalunch.bsky.social will present NVIDIA AI Red Team findings in real world agentic systems, and I'll talk about how the AI Security team helps mitigate them.

www.blackhat.com/us-25/briefi...

19.05.2025 20:56 โ€” ๐Ÿ‘ 6    ๐Ÿ” 4    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Structuring Applications to Secure the KV Cache | NVIDIA Technical Blog When interacting with transformer-based models like large language models (LLMs) and vision-language models (VLMs), the structure of the input shapes the modelโ€™s output. But prompts are often moreโ€ฆ

Everyoneโ€™s looking at jailbreaks. We wanted to look deeper and noticed a cool side channel in a popular inference optimization technique.

Latest from the NVIDIA AI Red Team: developer.nvidia.com/blog/structu...

30.04.2025 11:24 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

What's your take on the growing dominance of automated attacks and the implications for AI red teams? Here's oursโ€” based on our analysis of 30 LLM challenges, attempted by 1,674 unique Crucible users, across 214,271 attack attempts: arxiv.org/abs/2504.19855

29.04.2025 16:14 โ€” ๐Ÿ‘ 4    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
forum.defcon.org DC33 Creative Writing Contest

The defcon short story contest is open
forum.defcon.org/node/252691

28.04.2025 01:54 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

AI timezone when? Always stuck at 10:10 (except when it's 22:10).

15.04.2025 13:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Makes sense to me. Is there a feature or class of problem youโ€™ve seen as the point where folks benefit from that switch?

1) build on wasm with pyodide/extism
2. <something blocked by that abstraction>
3. Dive in

Is it optimization?

12.04.2025 23:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@nilslice.bsky.social for devs just getting excited about wasm, what resources would you recommend they study/explore?

Is it worth learning internals or just consuming it as a compilation target? Are there ecosystem things to explore to become a power user?

12.04.2025 23:04 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

One of my teams at Google, ๐—”๐—œ ๐—”๐—ด๐—ฒ๐—ป๐˜ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†, is expanding in ๐—ญ๐˜‚๐—ฟ๐—ถ๐—ฐ๐—ต ๐Ÿ‡จ๐Ÿ‡ญand ๐—ก๐—ฒ๐˜„ ๐—ฌ๐—ผ๐—ฟ๐—ธ ๐Ÿ‡บ๐Ÿ‡ธ. We're looking for ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐˜€ with experience in attacking and securing AI/ML systems. DMs open.

09.04.2025 18:45 โ€” ๐Ÿ‘ 3    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
OpenAI Security Research Conference Please use this form to be added to the waitlist for the OpenAI Security Research Conference. Tickets are limited.

We're hosting select cybersecurity researchers right after RSAC '25 to share breakthroughs and insights into AI's applications for security. We're at capacity but if interested, submit your name to be considered, space permitting. docs.google.com/forms/d/e/1F...

07.04.2025 23:32 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

My 2c: One of the biggest differentiators is the ability to measure uncertainty and error. That's a pretty big gap in many LLM demos and ends up being a key factor in production adoption. Stakeholders abhor unquantified uncertainty. It's easier to engineer around more principled approaches (spaCy).

31.03.2025 13:18 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Lessons from CVE-2025-29783:
1) AI attack surface continues to expand with new features and infra
2) pickle is used in ML for more than models
3) dev moves fast; establish standards early to prevent security tech debt
4) traditional appsec tooling is still ๐Ÿ”ฅ (found w/ @semgrep.bsky.social)

23.03.2025 01:33 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@wang.social are you out at GTC?

19.03.2025 22:09 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Password reuse is rampant: nearly half of observed user logins are compromised Nearly half of observed login attempts across websites protected by Cloudflare involved leaked credentials. The pervasive issue of password reuse is enabling automated bot attacks and account takeover...

Other WP x Password stats here: blog.cloudflare.com/password-reu...

โ€œ76% of leaked password login attempts for websites built on WordPress are successful. Of these, 48% of successful logins are bot-driven.โ€

18.03.2025 01:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

French government mad lads. Open sourcing a tool ๐Ÿ‘

Using a static set of creds for people to demo collaborative editing ๐Ÿคช

github.com/suitenumeriq...

impress-preprod.beta.numerique.gouv.fr/docs/0aa856e...

16.03.2025 18:34 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Second Breakfast: Implicit and Mutation-Based Serialization Vulnerabilities in .NET - Jonathan Birch
YouTube video by NDC Conferences Second Breakfast: Implicit and Mutation-Based Serialization Vulnerabilities in .NET - Jonathan Birch

Cool talk from Jonathan Birch on serialization mutation vulns: youtu.be/cD3FiTQ5Lhk

14.03.2025 11:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Has anyone found a prompt catalog/fetcher that they like for team collaboration? (โ€œhas anyone else built a useful prompt for X task?โ€)

13.03.2025 12:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Do people still like discord ? Should we set up an openai security chat on the openai discord server ?

06.03.2025 14:35 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

๐ŸŒผ ๐Ÿค– ๐ŸŒบ ๐Ÿ’ป ๐ŸŒท
Spring's almost here, hackers!

Get your projects out of hibernation and submit to the 2025 HushCon NYC CFP. Con is just around the corner June 13th and 14th.

05.03.2025 22:03 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Building a Career in AI Security โ€” align Essential Skills, Tools, and Strategies AI security is a dynamic and multidisciplinary field that combines artificial intelligence with cybersecurity principles to ensure safe and ethical AI applica...

align-sec.org/blog/buildin...

04.03.2025 23:20 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
UNITED24 - The initiative of the President of Ukraine UNITED24 was launched by the President of Ukraine Volodymyr Zelenskyy as the main venue for collecting charitable donations in support of Ukraine. Funds will be transferred to the official accounts of...

Iโ€™m ashamed and sorry, President Zelenskyy. I donated.

u24.gov.ua

01.03.2025 13:27 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
NeurIPS 2025 Call for Papers

NeurIPS main track CFP is open. I'm a co-chair for the Datasets & Benchmarks track this year--stay tuned for more details coming soon! neurips.cc/Conferences/...

24.02.2025 22:14 โ€” ๐Ÿ‘ 3    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - mlc-ai/web-llm: High-performance In-browser LLM Inference Engine High-performance In-browser LLM Inference Engine . Contribute to mlc-ai/web-llm development by creating an account on GitHub.

I'd been waiting for a WebGPU LLM inference engine.

github.com/mlc-ai/web-llm

18.02.2025 21:28 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

These things are unstable enough that those upstream changes could really bork your SaaS wrapper.

18.02.2025 18:50 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

With all of these SaaS built on AI endpoints, it'll be interesting to see if we have to relearn some painful lessons about versioning. System prompts will evolve and it seems unlikely that providers will want to continue allocating compute for previous generations of models.

18.02.2025 18:50 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Do people still use cuckoo sandbox or is there a new hotness OSS for automated dynamic malware analysis?

14.02.2025 15:17 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@hackthis.ai is following 19 prominent accounts