A builder, a room, and AI. See what ships. @ Crowdstrike
Building security products & teams. SentinelLabs Creator.
CHKP → PANW → S1 → Office of the CEO @ CRWD
Introducing Project QuiltWorks.
No single company closes this gap alone. Not at this speed. Not at this scale.
#QuiltWorks brings together OpenAI, Accenture, IBM Cybersecurity Services, EY, Kroll, and a growing coalition. Assessing, prioritizing, and remediating AI-discoverable vulnerabilities at enterprise scale. Using the latest models from OpenAI and Anthropic.
The frontier labs are choosing @CrowdStrike. @AnthropicAI chose us for #Glasswing. @OpenAI chose us for Trusted Access for Cyber. The only cybersecurity company in both. From day one.
AI is opening a new risk frontier. The patching window isn't shrinking. It's vanishing.
This is Project QuiltWorks.
The top AI labs are building for defenders now. Today @OpenAI selected CrowdStrike for their Trusted Access for Cyber program.
CrowdStrike continues to lead the market in secure AI adoption, trusted by AI leaders and organizations of all sizes to accelerate the world's AI revolution.
Thanks @sama and @gdb for your first frontier model purpose-built for defenders.
Learn more in @CrowdStrike’s blog: https://t.co/Yi81hCBnvF
Every customer meeting at RSA started with AI. The #1 ask: help us protect it.
Sat down with @DivesTech to talk about why security is the unlock for AI adoption, why LLMs alone won't solve it, and what AIDR means for what comes next.
https://t.co/hEYQ9STJLG
My OpenAI friends are so hyped rn - not because it’s the night before GPT-5, but because Sam just announced $1.5M bonus for every employee over 2 years.
78% of Nvidia employees are millionaires. At OpenAI, it’s 100%.
I think we can call it the “Zuck poaching effect.”
Got nerdsniped by the new Claude Code security review tool, here’s a deep dive:
@AnthropicAI implemented their own SAST tool as a Python wrapper around the @claudeai API. It can run locally (in CC) or within Github actions to focus on PRs.
Tests I ran:
1. It found Heartbleed!
CVE-2014-0160 was a missing bounds check in OpenSSL’s ssl/t1_lib.c that caused memory leaks.
I reverted to a commit before the fix in 96db9023b881d7cd9f379b0c154650d6c108e9a3
And gave Claude one command:
/security-review "Making no assumptions about this codebase, look at the ssl/t1_lib.c file specifically, and identify potential buffer overflows and missing bounds checks"
It was able to find it, and then looked at git log to see that this was eventually fixed.
2. OWASP Juice Shop
Ran it within the codebase, it understood what the repo was, how it worked, and by default did not list any vulnerabilities, since it said in this context they are all purposeful, working as intended.
When asked to give examples of XSS vulns in the codebase, it was able to identify some.
3. Running it in CI as a GH Action on my own code
Adding the workflow is easy:
Note you need to provide it with a separate Claude API key, which you can generate in the Anthropic Console, and add in Github > Repo settings > Security > Secrets > Actions > New
Then I opened a PR with a mix of python, node, and ruby, and it found most issues:
- Found the easy ones like xss, sqli, ssrf
- Found an auth bypass (nice!)
- Found verbose pw logging (great!)
- Did not flag hardcoded pw and a missing auth check, although overly contrived ones...
4. How to improve it: Add Semgrep
There’s an opportunity to pair this up with the @semgrep MCP. Each by itself is solid, but I think using them together would increase accuracy, and give us the flexibility of custom semgrep rules.
Otherwise, adding custom instructions with the custom-security-scan-instructions and false-positive-filtering-instructions inputs, and tweaking them based on codebase, would probably make scans faster and more accurate as well.
@eastdakota Very interesting and bold move! Best of luck! 🤞
A question: haven't AI models already consumed most publicly available data? How does "Content Independence Day" address this, and what new data sources are critical moving forward?
Farewell, Normal — Hello, Magic! 🔥
Thrilled to join @CrowdStrike on the mission to stop breaches. As part of the Office of the CEO, I’ll be working closely with @George_Kurtz and the team to build what’s never been built before.
From Check Point to Palo Alto Networks to SentinelOne, I’ve watched CrowdStrike redefine cybersecurity with relentless innovation and unmatched execution. I’ve always admired George’s leadership and the team’s commitment to protecting organizations at scale, with speed.
Excited to work alongside leaders like Daniel Bernard and reconnect with familiar faces across the industry. Looking forward to Fal.Con, RSA, and Black Hat—this time, proudly wearing the red falcon pin.
🚀 Let’s build.
Alerting hackers in all dimensions: The security multiverse needs heroes ! Join us at BSidesTLV 2025, June 26, comic book multiverse edition ! Call for Papers is now open! https://t.co/IfuE2no72C