@GadiEvron does not use community as another word for agreement. He told @jeremiahg in a LinkedIn thread, “I’ve never disagreed with you more. Look forward to our next discussion.”
Glad we don't have to wait long for Gadi and Jeremiah to talk. They'll be live onstage alongside @k8em0 Katie Moussouris, Marcus Hutchins, @EppSecurity Sergej Epp with Ciaran Martin moderating at the @SANSInstitute AI Cybersecurity Summit. (54 days out!)
A Gadi non-negotiable is building and serving the security community. The rest, I think, is up for discussion.
At the first @unpromptedconf AI Security con (which could be the next DEF CON) he said, “the only thing that really matters is not the talks. You can see them online for free. It’s the people you met. When it comes down to it, we are people. We talk to each other.”
Gadi is the founder and CEO of @knosticai, CISO-in-Residence for AI at the @cloudsa, and chair of [un]prompted.
His work is not merely to “secure AI.” Example - OpenAnt (open source LLM-based vulnerability discovery product, "similar to Anthropic's Claude Code Security, but free") forces an AI-generated vulnerability claim to survive a constrained attacker test, traces the exploit path, and then runs the exploit in a disposable sandbox.
Smart people are reaching very different conclusions about AI security. If we stop talking, we end up working against each other from separate echo chambers. That would be a spectacularly stupid way to handle a hard problem. (Cybersecurity has produced a few of those.)
Be like our friend Gadi and talk to people who you disagree with.
I think this could be one of the best panels of the year. (Yes, I know how low that bar is.)
Join us Nov 2-3. Your registration includes access to the @unpromptedconf AI Security Online conference: https://t.co/3Fb4KrqegZ
The Vulnpocalypse was supposed to be here by now... so where is it?
In our new research, we traced every confirmed exploitation of a published CVE since 2018.
On Wednesday, Sept. 2, @jeremiahg and @RSnake are hosting a webinar to walk through what the data actually shows.
At the end of the hour, you'll be able to answer:
→ Whether AI is really growing your backlog faster, and what that changes about what you patch
→ How to tell the 1.5% of CVEs that get exploited from the ones that never do
→ Whether you should be planning for more zero-days than you were three years ago
→ Why the median patch-to-exploit window is the wrong number to build an SLA on
→ Which of your CVEs get attacked inside 30 days, and which sit untouched for over a year
→ Which vendors and vulnerability classes are worth most of your patching hours
Attendees will get access to the full data in our upcoming Vulnpocalypse Report before it is publicly released.
🎙️ Webinar: Rumors of the Vulnpocalypse Have Been Greatly Exaggerated
📅 Wednesday, Sept. 2 at 9am PT
🔗 https://t.co/elM444kgUE
2026 BJJ Smackdown in the books!
Thanks to all cybersecurity folks who attended, Syndicate MMA for hosting, and our talented BJJ/MMA pros for coaching 💪💥
Shoutout to sponsors Nucleus Security, Wirespeed ⚡️, Axari, Zenity, WhoisXML API, and Tail Risk
Black Hat starts today.
If vulnerability management is a task that your team is responsible for, make time tomorrow to stop by the Nucleus Security @nucleussec booth (#5533) and meet Robert Hansen @RSnake and Jeremiah Grossman @jeremiahg. They’ll be signing copies of their new book, “The End of Guessing,” which explores why the future of vulnerability management depends on evidence, not assumptions.
📍 Aug. 5 | 2:00–3:00 PM
📍 Aug. 6 | 10:00–11:00 AM
See you in Las Vegas.
#blackhat #BHUSA #cybersecurity #vulnerabilitymanagement #riskmanagement #bookdebut
@bill_e_ghote@wmf In this case, I'm not sure, I didn't ask. :) But, suspect Yahoo's ISP made a mistake and hosted them on a subnet that was registered to Yahoo. Those sorts of things are not uncommon with IP address assignment system.
Long ago, when I worked at Yahoo, I hacked into a system on our IP-range. I looked around trying to figure out what it was or whose it was, and realized it wasn’t ours. It belonged to another company!
Knowing about the CFAA, I was genuinely worried and explained the situation to my manager. He asked, “Do you think anyone noticed?”
I said, “Unlikely.”
He replied, “Then don’t tell anyone.”
How times have changed.
Only 15 spots left for our BJJ event during @BlackHatEvents USA (2026)! ~60 of us will be on the mat, with a great list of coaches. I just saw that Syndicate won Gym of the Year, and John Wood (one of our coaches) won Coach of the Year! https://t.co/8S8Ri4be0f
A personal l thank you to our sponsors for their support to make this happen: @nucleussec,@wirespeed_,@axariaistaff,@tailrisked@rootevidence, @whoisxmlapi, and Tail Risk.
Reg: https://t.co/vAqFavyBl2
Reg open! Cyber-Security Brazilian Jiu-Jitsu Smackdown (2026). Held between @BlackHatEvents and @defcon.
(Thur, Aug 6), 60 cybersecurity pros on the mat, learning new moves, and making new friends. Instructed by @ForrestGriffin and several other elite level BJJ/MMA pros. BJJ first-timers always welcome!
Tickets: https://t.co/vAqFavyBl2
2025 Video: https://t.co/tLZnMdYDvO
Sponsored by: @nucleussec, @wirespeed_, @axariaistaff, @rootevidence, and @whoisxmlapi
With all the AI hype and hysteria surrounding vulnerabilities and exploits, it’s time for vendors to stand behind their claims and put their money where their mouth is. At Root Evidence, we spent years analyzing breach investigations and claims data to identify the tiny percentage of CVEs responsible for a disproportionate share of financial losses. Then we built the technology to find them at scale. Today, we’re standing behind that work with a $5,000,000 warranty.
https://t.co/1IwtM94kWe
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.
Access to all other Claude models is not affected.
We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible.
Read our full statement: https://t.co/bwn0sximKZ
CVE triage should be mandatory jury duty for CISSPs.
Backlog: ~26,000 CVEs.
CISSPs: ~170,000 worldwide.
Hey @CISAgov and @ISC2 , if every CISSP handled a few submissions, the queue could disappear in weeks!