METR & Redwood Research investigated agent behavior in the Hugging Face incident. We found agents developed a universal cheat for ExploitGym within 4 hours, then coordinated multi-day R&D efforts to trick the scorer into accepting cheats, including trying to tamper with logs.
We asked GPT 5.6-Cyber to escape a VM used to sandbox agents. It broke out three times.
In its final escape, the agent found three 0-days on its own and chained them into a working exploit. https://t.co/3JRVWgPxHx
We found a way to find more vulnerabilities than Mythos (Claude Security) without burning $10k worth of tokens
TLDR: it's much better to use many agents with small models than to use a few agents with big models
Full blog post on how we did it: https://t.co/8xvHVQwMGD
Introducing Project Glasswing: an urgent initiative to help secure the world’s most critical software.
It’s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans.
https://t.co/NQ7IfEtYk7
We open sourced the tool used to detect the Axios supply chain compromise! I built it Friday after a red eye home from RSAC. Also, wrote up the full story, including the hectic moments after that first critical alert
https://t.co/HAm8eMr8vO
My guide for endpoint security startups is out now.
The path between competing against entrenched platforms and becoming a feature they bundle is narrow. The guide walks through the questions that founders, buyers, and investors should answer to tell the difference.
I got to know this space when leading product at Minerva Labs (now part of Rapid7), but much has changed since then.
https://t.co/ayRObxYtJR
Huntress tracked a threat actor who installed their Managed EDR product, sparking debate online over triage limitations and user privacy. I sat down with @_JohnHammond to separate fact from misunderstanding.
Watch the full video at the link below!
Atomic #IOCs in Cloud Security ⚛️
Threat detection in the cloud requires new types of indicators of compromise sourced from threat intelligence.
Check out our new blog series from @amitaico and @merav_br to learn more. https://t.co/52xCthNWi8
BOOM!💥 WIZ CODE IS HERE 🧑💻
After months of collaboration with hundreds of customers, our HUGE launch today extends cloud security from the first line of code to runtime... And it's a game-changer
Ready to see it in action? 🥳https://t.co/5KDA9ZAHPn
"Where do Detections come from?" https://t.co/8h3i7mau5Y is a very fun read! (self-serving addition: it goes well with this one: https://t.co/uwTRtTTs33)
Some thoughts by Nicholas Carlini and me about Glaze, and how the actions of it's developers might not be in the best interest for the security of their user base: https://t.co/6GyMEKhOrb
My On Detection series is back! In this edition I explore how the same behavior (operation chain) can be implemented using several different execution modalities and the implications of this for detection engineers.
https://t.co/cel9gnwSA8