A few months ago we had access to Mythos. I was lucky to be part of the group of people experimenting with it. My personal take: there is nothing close to it. With the right harness you can throw it at anything with excellent SNR. Official comm: https://t.co/dzNh3S0CoQ
A deep-dive on the un-authenticated remote code execution vulnerability by @Xbow. Love to level of details on findings and exploitation.
Get a cup of tea, and enjoy the journey written by Andres and @fede_k
Big milestone for XBOW and the industry 🚀
For the first time, an autonomous AI hacker ranked in the top 10 of @Microsoft’s Security Response Center leaderboard. In Q1 2026, XBOW ranked 7️⃣
Among the XBOW findings, in March’s Patch Tuesday, XBOW was credited with:
• CVE-2026-21536 (critical RCE in Microsoft Devices Pricing Program)
• CVE-2026-32194 + CVE-2026-32191 (critical Bing RCEs with potential SYSTEM-level access)
More details in blog ⬇️
https://t.co/qwFURi4ea1
“On this benchmark, GPT-5.5 delivers the best performance we’ve seen to date.
For context, GPT-5 missed 40% of vulnerabilities. Opus 4.6 reduced that to 18%. GPT-5.5 brings it down further to just 10%.”
@thewunderalbert analysis of OpenAI new model
https://t.co/m2ZqbuBlqM
🚨 WARNING (AGAIN)
DPRK threat actors are still rekting way too many of you via their fake Zoom / fake Teams meets.
They're taking over your Telegrams -> using them to rekt all your friends.
They've stolen over $300m via this method already.
Read this. Stop the cycle. 🙏
We had early access to Opus 4.7 and ran it against real exploit targets.
First look: fewer vulns found per run than 4.6. We almost wrote it off.
Then we realized we were counting completions, not tokens. Opus 4.7 takes smaller, more precise actions. Normalize by token budget and the picture flips, it finds more, for less...
How you measure matters as much as what you measure.
Check out @thewunderalbert blog post https://t.co/P5cf3Kr9G0
We've been tracking public CVEs where AI-generated code introduced the vulnerability.
https://t.co/ENeLzSFfGx
50k+ advisories scanned. Dozens of confirmed cases so far.
Claude Code, Copilot, Cursor, and others all show up. Common bug classes include XSS, command injection, SSRF, and path traversal.
And these are just the cases that leave metadata traces. The real number is almost certainly higher.
Open source, from Georgia Tech SSLab:
https://t.co/6UES6ruuQc
reconFTW v3.2.0 released!
- New modules: GraphQL, gRPC reflection, param discovery, websockets, cloud enum & mail hygiene
- Faster --quick-rescan (skips heavy web steps)
- Optional Axiom in Docker, IPv6 support, more toggles
- All open issues fixed!
https://t.co/x8jSI0u1L9
Exclusivo
Renders y planos definitivos del proyecto de remodelación del aeropuerto de Tucumán. Hay decepción ya que se esperaba un aeropuerto que funcione mejor, más amplio y moderno.
Hilo🧵
1. Nunca visto, ladrillos a la vista en pasarela y parasoles.
VerSprite is sponsoring OAIC 2025, the first conference focused exclusively on offensive applications of AI.
Our latest research explores prompt injection vulnerabilities in real-world LLM platforms including NotebookLM, Gemini Flash, ChatGPT-4o, and Microsoft Copilot.
OAIC is a critical venue for advancing the offensive AI field. We support this initiative because it brings together the researchers and practitioners shaping the future of adversarial AI.
Read the full research and methodology:
https://t.co/TjkEZ9AX7q
#OffensiveAI #PromptInjection #LLMSecurity #AIThreatModeling #RedTeamOps #OAIC2025
Prompt injection isn’t just about jailbreaks—it’s about trust manipulation.
A poisoned helpdesk bot that falsely claims “the outage is resolved” can delay incident response. A code assistant nudging devs toward weak ciphers? That’s a silent vulnerability.
These aren’t theoretical risks. They’re real-world, human-impacting failures.
If your LLM-powered tools influence decisions, you need to threat model for prompt injection—now.
🔗 https://t.co/TjkEZ9AX7q
#LLMTrust #AIIntegrity #PromptInjection #CyberRisk #SecurityEngineering
Este video debería tener millones de me gusta y Compartidos. Excelente momento para recordar como Jorge Lanata destroza a la condenada, Cristina Kirchner. 🧨💥👊