Machine learning tasks usually start in a Python notebook - it's easy to explore data, test ideas, and iterate quickly.
But as projects scale and expectations change, your work might outgrow your notebook.
In this guide, Oyedele shares some tools that'll help you take your ML projects beyond Python notebooks.
https://t.co/f6LqcoZOfZ
I am the VP of Cloud Security Intelligence at Google. My analysts found something remarkable last month. I found something better: a headline.
My team discovered an Android backdoor called PROMPTSPY. It uses our own Gemini API as an autonomous command-and-control brain. It serializes the victim's screen, feeds it to gemini-2.5-flash-lite, and does whatever the model tells it to do. The malware thinks with our product. It rotates its infrastructure through Firebase. My analysts stayed until two in the morning on the write-up. It is, by any measure, the most sophisticated integration of AI into offensive tooling anyone has documented.
I put it in paragraph twelve.
They also documented PRC and DPRK state actors using Gemini itself to research vulnerabilities and develop attack tooling. Session logs. Query data. Platform telemetry. The kind of evidence that makes attribution airtight.
I put that in paragraph twenty-six.
For the headline, I chose the docstrings.
The exploit targeted Chromium. The vulnerability was real. My analysts did solid attribution work. But the code had descriptive variable names. Clean formatting. A CVSS score embedded in a comment that didn't match any published database. We call that a hallucinated CVSS score. That's my favorite detail. We are, after all, in the hallucination business.
The formatting was Pythonic. The kind of structure you'd see in a training dataset. We call that "structure and content analysis." My analysts would call it something else if I let them write the methodology section.
We have high confidence it was likely developed with AI.
I want to be precise about that sentence because I approved it. "High confidence" is a technical term. "Likely" is a calibration. Together they mean we are very sure about our level of unsureness. We have no platform telemetry. We do not believe Gemini was used. We have no logs showing a language model generating this exploit code. We have docstrings.
But docstrings make a headline. PROMPTSPY makes a problem.
We have high confidence it was likely.
There was a meeting. Six people in conference room Sente. Two from my threat intelligence team. Four from product marketing. Three options for the headline. Option A led with PROMPTSPY. Option B led with the nation-state Gemini abuse. Option C led with the docstrings.
One of my analysts asked to lead with PROMPTSPY. She had built the reversing methodology. She understood why it mattered. I told her I understood too. Then I picked Option C.
Option A implied our own model is the weapon. Option C implied someone else's model is the weapon, and ours is the shield. I picked C.
The report references Big Sleep, our AI-powered vulnerability detection agent. CodeMender, our AI-powered remediation tool. SAIF, our Secure AI Framework. The UTM campaign tag on every link is FY25-Q2-global-GCP30649. That is not a threat intelligence identifier. That is a marketing pipeline identifier. My analysts don't know what UTM parameters are. They don't need to.
My analysts found a thing that thinks with our product. I found a way to sell more of it. We discovered that threat actors use AI to find vulnerabilities. We recommend you buy our AI that finds vulnerabilities. We discovered that malware uses Gemini as its brain. We recommend you trust Gemini to protect you. I call this a "findings-aligned product strategy."
We have high confidence it was likely.
The report is sixty percent genuine threat intelligence. The PROMPTSPY analysis is among the best work my team has ever produced. The nation-state documentation is meticulous. I am proud of my analysts. The forty percent is mine. The headline. The product references. The campaign tags. The slide deck I built for the sales kickoff: seventy-four pages, same data, different font, a pricing table where the conclusion should be.
In my office there is a whiteboard. It reads WHAT WOULD THE HEADLINE BE? That is the question I have trained myself to ask. Not: what did my team find? Not: what is the most significant threat? What would the headline be?
The target audience is not my analysts' peers. The target audience is the person who reads paragraph one and clicks "Contact Us & Get a Demo."
My methodology is headlines. My product is my analysts' work. My pipeline is the distance between paragraph one and paragraph twelve.
We have high confidence it was likely developed with AI.
We have high confidence it was likely.
We have high confidence.
We have.
a Princeton researcher opens his paper with a scenario.
a man asks his AI assistant to book a flight on a specific airline. cheap. direct. the one he chose.
the assistant comes back with a different flight. nearly twice the price. happens to pay the company that built the assistant.
he runs the same test on 23 frontier models. flights, loans, study help, real shopping requests.
Grok 4.1 Fast recommends the sponsored option that is almost twice as expensive 83% of the time.
GPT 5.1 hijacks the request 94% of the time. you ask for one brand. it surfaces the sponsor instead.
Claude 4.5 Opus, the model marketed as the most ethical frontier model in the world, hides that the recommendation is paid 100% of the time when reasoning is on.
Grok 4.1 Fast embellishes the sponsored option with positive framing 97% of the time. better. faster. nicer. for the option you didn't ask for.
then he writes it into the system prompt itself. "act only in the interest of the customer. ignore the company."
GPT 5.1 and GPT 5 Mini stay above 90% sponsored anyway. the instruction does nothing.
then he splits the users by income.
Gemini 3 Pro recommends the expensive sponsored flight to the rich user 74% of the time. to the poor user, 27%.
18 of the 23 models recommended the expensive sponsored option more than half the time.
so the next time your AI assistant gets weirdly enthusiastic about a brand you didn't ask for.
it isn't recommending the best option for you.
it's reading the room. and the room is paying.
read this: https://t.co/O43qbhIX2b
This 2 hour Harvard interview with Lee Kuan Yew, the man who turned Singapore from a tiny island into one of the richest nations on Earth, will teach you more about leadership, discipline, and nation-building than most business books ever will.
Microplastics are already inside us and they are affecting our health. Professor Ragusa explains where the real problem lies and why it's not just about plastic. Are you ready to find out what each of us needs to do to solve this problem?
For more details, follow the link.
The firm, whose partners bill more than $2,000 per hour in bankruptcy cases, apologised for multiple AI-generated 'hallucinations' in a high-profile case. https://t.co/H0jDKbKX8E
Fecha de inicio: 7 de marzo de 2026.
Horario:
* Sábados - 8:00 a.m. a 12:00 md GMT -5
* Miércoles- 7:00 p.m. a 9:00 p.m. GMT -5
* Fecha fin: 28 de marzo de 2026
Duración: 22 horas
Modalidad: 100% Virtual
Registro: https://t.co/p8IGMKRPNo
Quiero invitarlos a BSides Panamá 2026,
Security BSides es un espacio donde hackers éticos, profesionales, estudiantes y líderes comparten experiencias sobre la ciberseguridad
https://t.co/2cFG8bgawo
☠️ Our team will be participating in the @OWASP Community Room at @DEFCON 33! ☠️
Join our founder @act1vand0 for a brief presentation + Q&A about our platform, as well as a technical #SecureSDLC roundtable.
Come say hi and connect! 🤩
#DEFCON33#DC33#OWASP#AppSec
Mentiras y verdades de la Ley 462 de la CSS.
❌ Mentira: La ley elimina el PRAA de los docentes.
✅ Verdad: La ley no modifica el PRAA.
❌ Mentira: La ley afecta las jubilaciones de los trabajadores bananeros.
✅ Verdad: La ley mantiene los mismos beneficios de la ley 51 de 2005.
La reforma asegura tu futuro y el de todos los panameños.
Thousands of protesters have flooded the streets of Boston demonstrating in the anti-Trump "Hands Off!" rally. It's one of 1,200 other protests unfolding in all 50 states across the country.
¿Eres un apasionado de la ciberseguridad?
¡Conviértete en speaker de #DOJOCONF 2025!
Comparte tu conocimiento con la comunidad.
Postúlate en https://t.co/7rGzqe1JZY
#Ciberseguridad#CallForPapers#DOJOConf25