I get asked a lot who to follow about the truth of AI cyber capacity.
My self-appointed mentor in this area is @Jhaddix
I stalk his work. I have an agent called “HaddixWatcher” that collects his work and gives me weekly reports.
This man is super legit, an early AI cyber pioneer, and a great human.
Keep an eye on him, maybe a little bit less stalker-vibe than I do. 😁
Blog post about From header smuggling in Apple iCloud just dropped.
Sending emails as [email protected], exotic parsing, and a $15,000 bounty.
https://t.co/IzPrUbDw5Q
Want to learn AI / LLM Security Assessment? Don't have the money for a training?
Here are 🎯SEVENTY ONE🎯 FREE LLM security labs that we have curated for you!
Like and share! (Link Below)
<3 from @arcanuminfosec
Today we updated our @arcanuminfosec Prompt Injection Taxonomy to 1.6!!!
- Several new inputs and intents
- MANY new techniques and evasions, a combined 70 node growth!
- New tagging taxonomy
- Legend for direct and indirect methods
- Tagging for local-only attacks
- “Aka” taxonomy section for reference
- Redone sample prompts and ideas
- and much, much more!
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
Here is a huge positive to modern life that gets no press.
I have an old 2009 Toyota, and the AUX port crapped out about a year ago. Went to YouTube. Young, enthusiastic guy explains how to fix it.
It is not obvious - involves taking the dashboard apart in a counter-intuitive way, but once you see it, it's a 15 minute fix.
There are actually dozens of videos showing how to do this, and they collectively have well over 200k views.
Had this happened in 1995, I would have just lived with it. But the combo of the replacement AUX jack available from Amazon and the video of the simple (but not obvious) fix, I fixed it.
I HAVE DONE THIS DOZENS OF TIMES. Replaced the control panel of my dishwasher. Replaced the ice maker in the fridge. Fixed a wonky sanding head on my drill press. Mastered a bandsaw technique that I use for my sculpture. On and on and on...
I think it is likely no exaggeration to say billions of fixes and skill upgrades have been performed worldwide that would not have been performed if it were not for the instruction freely given peer-to-peer on YouTube.
Take a moment to be happy about this. The busted item keeps performing, rather than going to the landfill. The person learning and doing the fix gains a sense of mastery and saves money. It's an unmixed blessing.
Stop doomscrolling. Think of what is busted in your house, find the YouTube video on how to fix it, and fix it.
Alright, I've stayed away from the Mythos stuff for a little bit. Going to comment on that, but AI as a whole.
First, this AI industry is absolutely insane. I feel like I'm back in the 90s/2000s with innovation, but it's not tempered or methodical - it's pure chaos.
Everyday there is some AI-dude-bro (or gal) clawing for followers claiming end of cybersecurity, end of software engineering, or this breakthrough changes everything. We're seeing the "streamer" effect of video games now exploding in every industry that hasn't been in whatever industry, but is now a AI-expert thus an expert in anything AI touches because they can prompt.
Largely it's not, but what it is doing is requiring us to understand what AI will do to virtually every industry in the future. I'm sitting here right now at a conference I'm presenting at, and I spoke with an individual which was like man... I'm just trying to get through this SAP implementation at my company, I don't even know where to start with AI at the moment.
We are still in the extreme early stages of what AI can do, and I think that's really the exciting part - we are at the infancy stages of this.
Most enterprise can't handle AI, as most companies couldn't handle agile workflow when it came out either, it took time, but eventually adopted.
I won't dive deep into the scalability of releasing AI to the masses based on compute, power, or subsidies because these are real hurdles we need to solve. As you can see with Claude's spike in popularity is causing them to have to dumb the model down upwards of 65% just to stay afloat (Claude is absolutely awful right now for coding - beware).
Mythos is cool, really cool - but it's not earth shattering as claimed. The potential here we are seeing a glimpse of what can actually happen though.
The ability to do extremely complex tasks, with insane context windows, and high-end reasoning. But, what we saw from other current frontier models including open LLMs, they were able to find the same issues, but had to be specifically targeted towards those code sections because of context limitations and complex task reasoning which was drastically improved in Mythos.
What does this mean? Basically. Nothing. It's a lot of marketing hype - but it does prove out that as these models become smarter, it will inevitably produce much better code, be able to work in mind blowing fashions that we haven't seen before - but it will all come down to cost. Right now Mythos is extremely expensive because of the compute needed, and we may solve that over time, but it's not there yet.
The subsidies right now means AI is not ready. Scale is our biggest bottleneck right now and until that's solved, the industry will not move as fast as it could.
What's particularly impressive is how the open models are starting to perform on par (or better) with the frontier models and become way more efficient without restrictions (turboquant) as an example.
Our ability to use near parity models on our own hardware will only continue to get better which is a huge threat for these companies. I at first looked at Cursor's implementation of Kimi as they were falling behind because it wasn't "their own model". That wasn't accurate, its that the open models are performing substantially better than from 6 months ago, and will soon be leading the charge or close to it.
What does this mean for cybersecurity? The industry is changing rapidly, and I absolutely freaking love it. We needed a swift kick in the ass in this industry that was largely stagnant for the past 10-15 years.
What used to be a handful of incredibly talented security researchers that knew systems internals, savants at reverse engineering and reading through millions of lines of ASM is now being afforded to the masses, but still has a long way to go.
The reason AI is so good at doing this stuff is because they paved the way, and will continue to do so in different ways. Not eliminated or removed, enhanced and better than ever. AI is single handedly the largest theft of plagiarism that has ever happened in human history. I just got a 10K check from Claude for ripping off my Metasploit book to train its model to be smarter actually :P
I am all for things that make the world a safer place. Our goal in cybersecurity is to fix the world, make it less harmful when using technology - we should be adopting this. Note that it's going to come with a ton of fluff, hype, doomsday predictions, people that are now AI exports or coding experts but have never written a line of code themselves. That's all to be expected if you have ever been to an RSA conference. AI will product meaningful change in an industry that needed it.
Cybersecurity is much more than bugs or defects, it's protecting against risk. AI is a new emerging risk, it's going to keep us insanely busy right now, and for the foreseeable future.
"Why does our top performer get the worst reviews?" the boss asked.
I was reviewing their annual performance data.
"Show me," I said.
She pulled up the ratings.
Diana: 2.8 out of 5.
Below average on "collaboration."
Low marks for "team player."
"What's her actual performance?" I asked.
"Exceeded every target.
Landed our biggest client.
Trained three new hires."
"So why the low scores?"
"Her peer reviews are dragging her down."
I scanned the comments.
"Too direct."
"Challenges ideas too much."
"Not supportive enough."
"Let me talk to Diana," I said.
"I used to give honest feedback," Diana told me.
"Said our pricing model was broken.
Got dinged for 'negativity.'"
"What happened with the pricing?"
"They finally fixed it six months later.
After we lost two major accounts."
"What else?"
"I questioned why we needed
eleven approvals for a simple contract change.
Manager said I wasn't being collaborative."
"Are you still giving feedback?"
"No. I learned my lesson.
Now I smile. Nod. Say everything's great.
My reviews are improving."
"But nothing's actually improving?"
"We're making the same mistakes.
Just with better vibes." She chuckled.
I went back to the boss.
"Your review system doesn't measure performance," I said.
"It measures compliance."
"That's not true."
"When was the last time someone
got promoted for challenging bad ideas?"
Silence.
"When did someone get rewarded for preventing a mistake?"
More silence.
"You've trained your best people to stay quiet.
And your mediocre people to stay nice."
A few months later, they redesigned the system.
Added a category: "Constructive Challenge."
Points for identifying problems early.
Rewards for preventing costly mistakes.
Diana got promoted.
"What changed?" I asked the boss.
"We stopped confusing agreement with alignment.
Stopped mistaking silence for harmony."
"And?"
"Turns out our 'difficult' people
were our most valuable.
They actually cared enough to speak up."
Here's the truth about performance reviews:
Most companies don't reward performance.
They reward performance theater.
The person who says the meeting was great
beats the person who says it wasted an hour.
The person who agrees with bad ideas
beats the person who prevents disasters.
You think you're measuring contribution.
You're measuring conformity.
And your best people?
They've already figured out the game.
They're just deciding whether to play it
or find somewhere that values truth over comfort.
The CEO just asked me if we're "doing anything with blockchain."
I said we're "monitoring the technology landscape" but haven't identified a strong use case for our business yet.
Translation: No, and we're never going to.
But I can't just say "blockchain is useless for what we do" because then I look like I'm not thinking innovatively.
So I position it as "we're being strategic and waiting for the right opportunity."
He nodded. Said that made sense.
Then he asked about quantum computing.
I gave him the same answer.
Here's the reality: every few months, executives read an article about some technology trend and want to know if we're "leveraging" it.
They don't actually care about the technology. They care about looking informed when they talk to other executives.
My job isn't to implement every buzzword. It's to make them feel like we're on top of it without committing to anything.
"Monitoring the landscape" is perfect because it sounds proactive but requires zero actual work.
Next month it'll be something else. Maybe AR. Maybe autonomous systems.
Doesn't matter. The answer is always the same: we're watching it closely, being strategic, and waiting for the right fit.
This week is the 2 YEAR anniversary of @arcanuminfosec ! Thank you all for the immense support over the last few years. We appreciate you all so much 🫶
We will doing giveaways ALL WEEK! Stay tuned to socials!
Half the work in cybersecurity isn’t fighting attackers; it’s explaining reality to people who don’t want to hear it. Telling leadership something won’t be safe, or can’t be automated, or doesn’t need AI, is harder than dealing with an exploit.
This is feedback that all security practitioners should be aware of and take to heart. Things are somewhat different inside companies, but the feelings are often the same.
How do we make working with us a more positive experience? When we nail this, we get more security impact.
Need help writing reports?
Check out @Jhaddix's Bounty Plz GPT ✍️
Just give it a host name and a brief description of your finding and it will do the rest!
(🔗 in comments)