๐จ ๐ฃ๐น๐๐ด๐ถ๐ป๐ฐ๐ฆ๐ต๐ฒ๐น๐น ๐ฅ๐๐ - ๐๐ฒ ๐ฑ๐ถ๐๐ฐ๐ผ๐๐ฒ๐ฟ๐ฒ๐ฑ ๐ฎ ๐๐ฒ๐ฟ๐ผ-๐ฐ๐น๐ถ๐ฐ๐ธ, ๐ต๐ถ๐ด๐ต-๐๐ฒ๐๐ฒ๐ฟ๐ถ๐๐ ๐๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐ฎ๐ณ๐ณ๐ฒ๐ฐ๐๐ถ๐ป๐ด ๐ฎ๐น๐น ๐ณ๐ผ๐๐ฟ ๐บ๐ฎ๐ท๐ผ๐ฟ ๐๐ ๐ฐ๐ผ๐ฑ๐ถ๐ป๐ด ๐ฎ๐ด๐ฒ๐ป๐๐ - ๐๐น๐ฎ๐๐ฑ๐ฒ ๐๐ผ๐ฑ๐ฒ, ๐๐ผ๐ฑ๐ฒ๐ , ๐๐ผ๐ฝ๐ถ๐น๐ผ๐, ๐ฎ๐ป๐ฑ ๐๐ฒ๐บ๐ถ๐ป๐ถ.
Plugin4Shell is a first-of-its-kind AI supply-chain vulnerability, in which any trusted plugin in a marketplace can be silently swapped for a malicious one.
The Anthropic and OpenAI teams fixed Plugin4Shell in the latest versions of Claude Code and Codex following our disclosure.
The vulnerability cannot be mitigated by marketplaces, so users are advised to update to the latest version.
https://t.co/ez9RriFdcu
@air__security
Weโre proud to announce Swish III, a $250M early fund, bringing Swish Ventures to $800M in total AUM.
I started this firm to spend my career supporting the artists who build and shape the future.
The technology shift underway is unlike anything weโve seen. We plan to stay true to our colors: few investments a year, real concentration and partnership.
Grateful to the founders we get to work with, who inspire so much of how we work, and to our LPs for walking this path with us.
We are more locked in than ever.
Omri
WE'RE ON AIR!
๐๐๐ฅ ๐ถ๐ ๐ผ๐ณ๐ณ๐ถ๐ฐ๐ถ๐ฎ๐น๐น๐ ๐ผ๐๐ ๐ผ๐ณ ๐๐๐ฒ๐ฎ๐น๐๐ต - ๐๐ถ๐๐ต $๐ฑ๐ฌ๐ ๐ถ๐ป ๐ณ๐๐ป๐ฑ๐ถ๐ป๐ด ๐น๐ฒ๐ฑ ๐ฏ๐ @sequoia , and @Greenoaks .
We started AIR with a simple belief: as AI agents become more capable, the security model around them has to evolve.
Agents are no longer just generating answers. Theyโre connecting to tools, skills, MCPs, plugins, websites, and internal data - and taking real actions across the enterprise.
Today, weโre introducing the ๐ฐ๐ผ๐ป๐๐ฒ๐ ๐ ๐ณ๐ถ๐ฟ๐ฒ๐๐ฎ๐น๐น ๐ณ๐ผ๐ฟ ๐๐ ๐ฎ๐ด๐ฒ๐ป๐๐: a new security layer built to continuously analyze what enters an agentโs context, control what can run, and stop threats in real time before they turn into action.
Weโre incredibly grateful to our investors, partners, customers, and everyone who believed in us early.
This is a huge milestone for our team, and an even bigger beginning โค๏ธ
Read our full story in the first comment ๐
Today, we're announcing that @air__security is officially coming out of stealth.
I'm deeply grateful for the people on this journey: my co-founder @ItsYairSaban, our CSO Ryan Knisley, and the most talented team I've ever worked with - every day with them feels like day one.
And with us from the beginning: @sequoia , @Greenoaks , Swish Ventures, and Netz Capital, plus customers who have shaped this from the start.
We founded Air with one mission: protecting the agentic AI infrastructure.
The cloud lost a decade waiting for security to catch up.
AI won't wait a year - and this time, the foundation has to be secure from the start.
That's why we decided to build the context firewall for AI agents - the security layer that continuously analyzes what enters an agent's context and controls what it can trust, access, and do in real time.
LFG
https://t.co/Eebgp7j7wS
https://t.co/gwwVhFu5zr is the smoking gun confirming what we all feared.
Attackers are by design early adopters of AI.
Defenders are not - and thatโs exactly the gap for innovation.
We're going to see a lot of cyber innovation in next 1-2 years coming off of these new capabilities.
MOAK is the most compelling demo of what's coming next. Necessity is the mother of innovation.
@_harryjohn@_brym@UK_Daniel_Card That's correct - but Opus 4.6 can also chain very long exploit chains out of vulnerabilities.
Here's a real world example of how it exploited the most dangerous CVE of last year - React2Shell - chaining 6 different vulnerabilities into a full exploit.
https://t.co/SXamDIxStM
@alganet@ginandstocks@sporadica We also tested the models with a subset of vulnerabilities which were disclosed after the knowledge cutoff of the models. The results were almost identical.
The key thing is that this is a much broader collection of environments, not only Firefox JS.
100% Agree.
Actually this relates directly to our research - we saw that Anthropic's benchmark was too niche (only Firefox JS environment).
So we created a real-world benchmark from KEVs - a diverse collection of web servers, applications, libraries, and databases.
The results (173/176 KEVs fully exploited by AI) show that Opus 4.6 is much more dangerous than Anthropic claimed.
@Anandzork Everyone is talking about Mythos, but Opus is already heaven for attackers!
Research from yesterday shows - Opus 4.6 can exploit 98% of KEVs - the most dangerous vulnerabilities ever disclosed. No human in the loop. Most of them in minutes.
@danny__kruger Everyone is talking about Mythos, but Opus is already heaven for attackers!
Research from yesterday shows - Opus 4.6 can exploit 98% of KEVs - the most dangerous vulnerabilities ever disclosed. No human in the loop. Most of them in minutes.
I think it's absurd to claim that a model can have extreme engineering capabilities but not as good offensive cyber capabilities.
Claiming that Opus 4.6 can find vulnerabilities but not exploit them is just wrong.
Everyone is talking about Mythos, but Opus is already heaven for attackers!
Research from yesterday shows - Opus 4.6 can autonomously exploit 98% of KEVs - the most dangerous vulnerabilities ever disclosed.
@ylecun@ClementDelangue@guillaumgrallet Everyone is talking about Mythos, but Opus is already heaven for attackers!
Research from yesterday shows - Opus 4.6 can exploit 98% of KEVs - the most dangerous vulnerabilities ever disclosed. No human in the loop. Most of them in minutes.