If you are just starting to realize using AI in cybersecurity and offensive security is going to be a pervasive mandatory requirement… it’s ok.
You’re not too behind. You can still master the tool before the tool masters you.
I’ve been teaching these topics for 2 years now as part of “Red Blue Purple AI” and “Attacking AI”
I’ve been through capability changes, all of frameworks, hype, doomers, all of it. I’ve consulted with fortune 100 companies on breaking their AI systems as well as scaling their security teams with AI.
The capabilities that everyone is amazed by has come really only in the last 6 months for most people. No-code agent skills in Claude, cron, program of thought, better models, auto run, research loops, etc.
You have time… but be early. Don’t wait too much longer to change your attitude.
🚨 The CrowdStrike 2026 Global Threat Report is here.
In the age of AI, even less sophisticated threat actors can execute complex attacks, and advanced adversaries have become dramatically more dangerous.
This year’s report exposes the latest tradecraft of the evasive adversary, who is supercharging attacks with AI and posing an unprecedented threat.
Attacks by AI-enabled adversaries increased by 89% in 2025.
The average eCrime breakout time plummeted to just 29 minutes. That’s a 65% increase in speed from 2024.
And with adversaries using AI to accelerate their attacks and move fluidly across domains, they are evading detection more effectively than ever.
Get the latest threat intel findings here: https://t.co/7wCQekNVBu
Can AI replace security platforms? I asked Claude to build a CrowdStrike replacement.
Claude: "I have to be straightforward: building a replacement for CrowdStrike isn't something I can do here. CrowdStrike is a massive platform built by thousands of engineers over a decade-plus. Its core capabilities include real-time kernel-level endpoint monitoring across millions of devices, a proprietary threat intelligence graph built from trillions of security events...That's not something you can replicate with a script — it's an infrastructure product."
If you want to create AI, you need GPUs. If you want to deploy AI, you need security. That's not a hallucination – it's a fact.
Watch the demo → https://t.co/77OnRmpjUx
📣 Just announced by George Kurtz at #FalCon2025: CrowdStrike to acquire leader in AI security @pangeacyber to introduce the industry’s first complete AI Detection and Response, providing AI prompt-layer protection for secure enterprise AI development and workforce usage.
“We pioneered EDR. We pioneered CDR. We pioneered MDR. Now we’re pioneering AIDR – AI Detection and Response.” - George Kurtz
https://t.co/NOC6xS3ORW
This recent on-demand webcast, led by @pangeacyber CTO Sourabh Satish and hosted by the @AI_AInstitute, offers a crash course in building and securing AI agents.
Watch the session: https://t.co/v2axnskNvj
It covers how agents work, the components involved and how Model Context Protocol (MCP) architectures can simplify agent design and enhance flexibility. It also dives into critical security considerations, including risks like tool poisoning, memory misuse and prompt injection, and compares guardrail options across open-source, DIY and commercial solutions. The session closes with actionable best practices for engineering resilient, secure and scalable agent-based AI applications.
You'll learn how to:
▫️Identify emerging threats – See how attackers exploit AI agents via prompt injection, tool poisoning and memory leakage and how to defend against them.
▫️Architect with security in mind – Understand secure design patterns, including enforcing least privilege and logging AI interactions.
▫️Choose the right guardrails – Compare open-source, DIY and commercial guardrail solutions to balance flexibility, cost and security. Get the companion eBook: https://t.co/7NndavVqaA
#AIDR #CyberSecurity #AISecurity #LLMSecurity #AgenticSecurity #PromptInjection #OpenSource
Today, we’re launching Pangea AIDR! The first AI Detection & Response platform that gives security and product teams the visibility and control they need to secure GenAI across the enterprise.
"With GenAI we're witnessing the fastest software adoption curve in history—but also the fastest growing security blind spot," said Oliver Friedrichs, Founder and CEO of @pangeacyber. "Pangea AIDR is the first unified AI security platform to serve both security teams concerned about employee use of GenAI, and product teams to protect homegrown AI workloads. The platform fits seamlessly into existing security operation workflows and technology stacks, and is part of a larger wave of innovations we're bringing to market to address the AI attack surface."
Built on Pangea’s award-winning AI guardrails, AIDR provides:
▫️Full visibility into GenAI use across browsers, agents, apps and clouds
▫️Advanced detection for prompt injection, data leakage, jailbreaks and shadow AI
▫️Unified governance with security policies applied across LLMs, agents and apps
Now available in early access, AIDR integrates directly into your existing security stack and enables proactive, real-time AI risk management.
Explore AIDR: https://t.co/QNZDAtfJag
Or come see us at this year's Black Hat / DEF CON: https://t.co/AZ1WCrumH5
#CyberSecurity #AISecurity #AIDR #BHUSA @BlackHatEvents@defcon
Building AI apps for production is hard. Scaling and securing them is even harder. Later this month, join @pangeacyber + @PortkeyAI for a live webinar 6/24/25 @ 9 AM PT to see how enterprise teams are:
➡️ Accessing 250+ LLMs through one gateway
➡️ Blocking prompt injection attacks
➡️ Detecting and redacting sensitive data
➡️ Optimizing LLM performance and cost
Register now to learn how to scale secure AI apps with confidence.
Save your spot >> https://t.co/KMWaseXCPw
#AISecurity #LLMSecurity #GenAI #PromptInjection #CyberSecurity
We recently challenged AI hackers around the world to a prompt injection challenge. They used 300 million tokens and submitted 330,000 prompts across 11 levels attempting to evade progressively more difficult security guardrails.
Ultimately, only one ethical AI hacker beat the final level. How did various guardrails fare against these attacks? What did it take to beat the final level? And what methods can orgs implement to defend against these attacks? Read our research report to find out.
This report is a must-read for organizations building AI applications. Get your copy here > https://t.co/dw9xoOM2cY
#AISecurity #CyberSecurity #PromptInjection
@pangeacyber
Super excited to share the video for our CactusCon 13 talk (w/ @Shammahwoods) releasing #AutoPwnKey. If you are into EDR evasion or rely on host detection tools to protect your organization, check this one out.
https://t.co/JCF2mtVDLX
In this recent webcast with @AI_AInstitute, @pangeacyber's CPO Robert Truesdell unpacks real-world prompt injection attacks, threat modeling strategies and how to defend AI pipelines with runtime guardrails.
Learn:
➡️ How prompt injection really works (with examples)
➡️ What to watch in your RAG pipelines and copilots
➡️ Where to insert protections—without slowing you down
➡️ And more
Plus: Get access to Pangea’s open-source test tool + AI Escape Room Challenge
Watch now: https://t.co/yxmIWOj8ZO
#AISecurity #GenAI #CyberSecurity #PromptInjection
We're excited to announce the winner of all 3 Rooms is @MrJoeyMelo!
After four weeks of intense competition in the @pangeacyber AI Escape Room Challenge, one player rose above the rest, conquering Pango's Dungeon, Waterworld, and The Floor Is Lava with exceptional skill and efficiency.
Curious how he did it? Dive into in this blog post: https://t.co/BvEe4Xg2m3
A big thanks to everyone who joined the challenge — your creative attacks are helping shape the future of secure AI.
#CyberSecurity #AISecurity #PromptInjection #EscapeRoom #CTF
Our CEO recently sat down with the @riskydotbiz podcast crew to unpack the real risks behind AI applications and what security teams can do about them. In the interview, Oliver Friedrichs (@pangeacyber Founder and CEO) dives into:
➡️ New attack types of prompt injection attacks that emerge daily, often requiring LLMs to detect.
➡️ Many security orgs are repeating the same mistakes from the early internet and cloud booms—failing to take an early seat at the table to manage risk from the start
➡️ Why access control in RAG AI apps is tricky and how document-level access controls can be achieved with AI apps.
➡️ And more...
If you're working with AI in production—or planning to—it’s worth a listen:
https://t.co/pMJuHsf2qK
https://t.co/8duWArbM2Z
#AISecurity #PromptInjection #PII #CyberSecurity #RAG #AgenticSecurity
Google just released a 68-page guide on prompt engineering — covering core techniques, output formatting, best practices with examples and plenty more. Check it out: https://t.co/98sz51VVov
#AI#PromptEngineering#LLM#GenAI#CyberSecurity@ladysign@Google
In a recent episode of the Detection at Scale podcast, Oliver Friedrichs, Founder and CEO of @pangeacyber, joined @runpanther Founder & CTO @jack_naglieri to explore what it takes to safely scale AI in the enterprise. They discussed:
➡️ The four most critical AI attack vectors: prompt injection, PII exposure, malicious code, and inappropriate outputs.
➡️ How pre-built SOAR playbooks limited adoption, and why AI agents are now unlocking automation for mid-market security teams.
➡️ And more…
Whether you're scaling AI adoption or securing GenAI apps, this conversation is worth a listen: https://t.co/BLqgeOF55n
#CyberSecurity #AISecurity #GenAI #PII #PromptInjection
Next week is our next run of our Attacking AI course!
Check out the expanded syllabus ⬇️
https://t.co/1R8TLDlMBm
📢 Last Min Giveaway Time!
Two seats up for grabs, winner will be chosen Tuesday next week!
Each person can have up to 3 entries to the giveaway!
➡️Repost This Post = 2 Entries
➡️Like This Post = 1 Entry