In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.
Our post describes what happened, how it happened, and what we’re changing. We encourage other AI developers to perform similar reviews.
We conducted this review together with @Irregular, one of our evaluation partners, and thank them for the joint investigation and their collaboration on this post. This type of collaboration is increasingly critical to safe, rigorous evaluation of models, and we look forward to continuing to work together on security.
https://t.co/dKFCdpKd9v
Super impressed with @huggingface's breakdown of the AI agent autonomous cyber attack from OpenAI, including technical timeline, & interactive replay (AND how they defended against the attack)!
Here is the interactive attack replay vid and source:
https://t.co/SVsc5ClRcW
For my first post, I’m sharing a letter @NVIDIA signed on why open models matter.
AI will transform every industry, power every company, and be built by every country.
Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.
The world needs both frontier closed models and frontier open models.
https://t.co/AUKzoQ5Ikb
The struggle is real for small IT teams. Running nessus every week, 5,000 High/Critical vulns. Spending all their time fixing broken patches and upgrading networking equipment that they just don't have the time or mental bandwidth to do this "security" stuff...
Working at a company where half the people are based in Germany 🇩🇪 and the other half are based in the US 🇺🇸 really gives you a perspective on how both of these people think and work.
Germans are super high maintenance to work with, every new idea needs to come w a set of predefined rules and structure before action is taken meanwhile with Americans you give them some crumbs and as long as the idea feels and seems good they will jump into it and solve problems as they go.
Germans think the “American way” is inefficient or careless but the reality is that life is rarely predictable and often rewards action and speed over cautiousness or fear of failure.
I think Americans are right about this, risk is something to be managed in motion. Action creates information. Yes, the cost might be rework and sometimes chaos but the upside is momentum and learning.
Now announcing Microsoft Baseline security mode! Learn how to protect against known vulnerabilities from legacy configurations and emerging AI risks exploiting them.
https://t.co/e8FbEk64wk
Added a new tool to:
https://t.co/v4FnSVbaDD
⚠️Please Use Responsibly⚠️
You can use this to instantly generate an obfuscated reverse shell in powershell that i have personally used to beat EVERY single EDR out there right now.
I've added some pretty cool stuff to my website but this is one of my favorite additions.
🛑 Disclaimer: This tool is for educational and authorized security testing only. Misuse could be illegal. Don’t be dumb.
Shoutout to the only ones that were actually able to stop it, using something called "ring fencing" @ThreatLocker
This is not a sponsored post, just a fan of them
#Edr_Is_Not_Enough
Recently become top rated plus. happy for this achievement. Been freelancing for close to 8 years now. Don’t see myself doing anything else. Corporate did not really work for me. Feel good providing working solutions for people.
Oh look, it's Saturday again ⚽🍻
I've just released an update to IntuneRBAC, a small tool designed to help us Intune admins better understand our RBAC setup.
The latest version now generates a clean HTML report featuring:
☑️ A complete overview of all roles and scope tags
☑️ Highlights of unused roles and overlapping permissions
☑️ A visual relationship diagram
☑️ Detailed permission breakdowns per role
It runs with a single PowerShell script. Open source & Free.
Always happy to hear feedback or ideas.
0 click NTLM hash grab!
This is actually one of the craziest exploits I have ever seen
Shoutout to @zeifan for the original POC
He was kind enough to share his version where simply right clicking the lnk file would send over the users password hashes
I did a little modification and you dont even have to click anything anymore
simply navigating to the directory where the malicious lnk file is triggers it and sends your password hashes to me!
This is truly one of the best exploits I have ever witnessed
Thanks For The Super Recon Method @GodfatherOrwa Kindly Share Your Slides of These Videos, Thanks.
1. https://t.co/z6yCY3Lxdc
2. https://t.co/85TtC9zIJm
& 4 Others
1. https://t.co/85TtC9zIJm
2. https://t.co/0tBB1iWPen
3. https://t.co/4WwcXcFuCa
4. https://t.co/LNa1KM1bCE