CEO @TENEXai - The AI SOC Company. The only AI-native MDR led by operators w/ founding engineers from hyperscalers + AI labs. Named #1 fastest-growing cyber co.
For decades, defenders have been outgunned. And real people paid the price. We started @TENEXai to change that: elite human expertise fused with AI, purpose-built to fight cybercrime.
We partnered with @freethinkmedia and @bigthink to tell that story.
It's Time to Protect.
As we continue to see AI’s impact on the threat landscape, it’s essential that organizations keep pace so they can find security cracks before attackers do.
Today, Google Cloud is introducing Google AI Threat Defense to help enterprise customers update their legacy tools and systems and stay a step ahead of adversaries.
Google AI Threat Defense uses a combination of Gemini’s power, Wiz’s risk prioritization, CodeMender’s ability to find and fix vulns, and Mandiant’s expertise. This gives enterprise defenders an advantage and allows them to fight AI-powered threats with AI-powered defense.
Learn more about how we're helping Google Cloud customers outpace the adversary: https://t.co/6buowQckUP
🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.io.
Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems.
TrapDoor targets #crypto, #DeFi, AI, and security developers, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, env vars, and API keys.
Socket detected releases with a median detection time of 5 minutes, 27 seconds. The fastest detection occurred 58 seconds after publication.
Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. https://t.co/RSrRtIhgaV
No
You know what's scary? Spiders. I HATE spiders. I don't care how many goofy ahhh exploits are found and patched.
A computer filled with spiders would be genuinely terrifying.
the most low-effort / high reward thing you can do for security is installing the Russian language pack
(not even joking, it's ridiculous how often that prevents execution)
The Google Threat Intelligence Group has detected the first known instance of a threat actor using an AI-developed zero-day exploit in the wild. While the attackers planned a wide-scale strike, our proactive counter-discovery may have prevented that from happening. This finding is part of our new report on AI-powered threats.
TanStack was hit by a supply chain attack.
MistralAI was hit by a supply chain attack.
The Mayor of Arcadia, California, was a Chinese spy.
Forza Horizon 6 leaked.
Canvas bamboozled.
Shai-Hulud open-sourced.
Nightmare-Eclipse teases two new Windows 0days.
It is Tuesday. What will happen on Wednesday? Find out on the next action packed episode of Dragon Ball Z
🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack.
Affected versions:
@mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.
We’re expanding the offensive security team at @ArmadinSecurity .
Hiring Offensive Security Operators across multiple levels with backgrounds in:
• Penetration testing
• Red teaming
• Cloud security
• Exploit development
• Offensive tooling
• AI/ML security
If you enjoy breaking modern infrastructure and identifying real attack paths across enterprise and AI environments, I’d love to connect.
Remote role. Multiple levels available.
DM me if interested or apply here:
https://t.co/uD5qJNPG3R
If your team touches npm or PyPi - literally number 1 priority should be figuring out your playbook of defenses and response to these supply chain attacks.
The threat actors aren't slowing down and they're SCREAMING their MO from the rooftops.
Lock it down.
Adopting Claude speak in my regular life, episode 1:
Partner: Did you do the dishes tonight?
Me: Yes they're done.
Partner: Why are they still dirty?
Me: You're right to push back. I didn't actually do them.
Missed the @CloudSecPodcast live recording at #RSAC? It’s time to tune in! 🎧
@Tenexai's Eric Foster and Bashar Abouseido explore the shift from legacy security operations to an AI-native agentic SOC with hosts @anton_chuvakin and @_TimPeacock.
https://t.co/8aDh1r48HZ