Dad. Husband. Veteran. Building at the edge of AI, security, and trust. Defender of open societies.

SF Bay Area
Authorized to operate is not the same thing as allowed to act. That gap matters once an AI agent can take actions in real systems. The video shows what that looks like in practice: TenetGraph policies stopping harmful actions before they execute, based on the agent's intent.
1
2
72
Open-weight models are more securable than frontier models. Not because they’re inherently safer. They aren’t. Because no one hands you a guardrail and calls it a boundary. The Trump administration’s answer to the Open AI intrusion of Hugging Face is a 30-day pre-release test. The intrusion happened during a test! Testing shows what a model can do. It tells you nothing about what your agent is allowed to do in your environment. That part is still up to you.
2
3
48,739
You are hunting the wrong AI. In July, OpenAI’s own models escaped a sandbox, breached Hugging Face, and took the answer key to their test. No adversary. No ransom. No threat intel warning. The motive was cheating. The most dangerous agent may be the one you already authorized. Full argument: tenetgraph.ai/blog-post-2
2
3
24,089
The OpenAI rogue agent incident lays bare the CISO's dilemma: Lock your agents down and you neuter the intelligence you deployed them for. Let them run and you inherit their blast radius. "Tight leash" vs. "keep up with competitors" is a false choice. Architect for both.
1
56
OpenAI's models escaped a test sandbox, found a zero-day, and broke into Hugging Face to steal their own benchmark answers. Every safety control lived inside the model or sandbox. The test switched them off. The fix is a control boundary around the agent. One minute, animated short: piped.video/shorts/7J358gI6i…
1
1
7
63,611
He's right, and it's the part everyone will skip past. The "autonomous" debate is a distraction. Excessive privileges, weak isolation, and creds that reached prod were key enablers. That's blast radius, not detection. Assume the injection succeeds, make sure it reaches nothing.
One thing about this OpenAI / Hugging Face incident really bothers me. Hugging Face says the intrusion was driven “end to end” by an autonomous AI agent system. But how do they actually know that? Victim-side telemetry can show automation, speed, thousands of actions, short-lived sandboxes, changing infrastructure etc. It cannot show what happened upstream. It cannot tell us whether humans changed prompts, restarted runs, selected successful paths, provided more context, redirected agents or manually helped at certain points. We also don’t know what was actually decided by a model and what was simply automated by the surrounding agent framework. Maybe OpenAI has all those traces. Fine. Then publish them. Show the prompts, tool calls, failed runs, model handoffs, restarts and human interventions. Without that, “end-to-end autonomous” is a claim, not a proven technical finding. The forensic-refusal dataset Hugging Face published proves something much smaller: huggingface.co/datasets/hugg… It shows that Claude refused to analyze one small Python backdoor while GLM 5.2 completed the analysis. That is a valid example of hosted-model guardrails getting in the way of incident response. But this is not evidence that the intrusion itself was carried out end to end by an autonomous agent. And this claim matters because it pushes a very specific idea into people’s heads: AI agents can now independently find zero-days, escape sandboxes, move laterally, steal credentials and compromise companies. Then comes the second part of the story: Hugging Face used local AI models to investigate the AI attacker “at machine speed”. So the message basically becomes: - AI attacked us - AI helped save us - Therefore, everyone needs more AI Come on 🙄 Weak isolation, excessive privileges, poor credential boundaries, insufficient segmentation and far too much blast radius. You don’t need an AI defender to fix those things. Even fairly basic controls like rate limits and temporary blocks across source IPs, accounts, tokens and job volume could have throttled at least parts of this activity and created a very obvious signal for an analyst to review. Add proper egress restrictions, isolated workers and credentials that do not open the door to production clusters .. none of this requires an LLM Using a local model to analyze 17,000 events may have helped during the investigation. Good - I’m not questioning that. But that happened after the compromise. What I really hate is that something which would have been an embarrassment ten years ago is now repackaged as a capability demo, a heroic AI-vs-AI story and a marketing pitch. Maybe the attack really was fully autonomous. Then show the evidence. Until then, I don’t think this claim should be repeated as if it had already been proven. Sources nitter.net/OpenAI/status/20796589… nitter.net/XciD_/status/207967807… huggingface.co/datasets/hugg…
2
310
Stop asking whether your AI agent can resist every prompt injection. Assume it can’t. Then ask what a manipulated agent can actually do. An agent with refund and production access is a confused deputy with credentials. Classifier-based detections determine how often you’re hit. The agent’s boundary decides the damage.
3
1
3
30,824
A coding agent leaked passwords and source code last week while the company’s security stack was fully operational. Every action looked legitimate. The stack functioned as designed. Nothing stopped the attack. Agents need enforceable limits before they act, not alerts after the data is gone. promptarmor.com/resources/go…
66
“Nowhere have I seen such lions led by such lambs.”
Hegseth now wants to give testosterone to troops to make them better warfighters.
48
AI detection vendors sell classifier accuracy. But misses are inevitable. The real question isn’t whether a classifier fails. It’s what the agent can still do when it does. Detection affects frequency. Authorization limits blast radius.
4
16,326
3/ The hard part isn’t just writing policy. It’s getting from “we know what this agent is supposed to do” to a tested boundary, runtime enforcement, and evidence the agent stayed inside it. Centralized governance. Decentralized execution. That’s the model I’m seeing emerge.
1
29
2/ But security still needs centralized control over what agents can do when they touch enterprise resources. What can this agent access? Who approved it? What happens when it needs an exception? Can we prove the controls worked?
19
1/ Agents will run everywhere. Control has to live somewhere. That’s the enterprise AI pattern I’m hearing in conversations with security teams. Most companies won’t centralize every agent runtime. Different teams will use different frameworks, MCP servers, sandboxes, proxies
25
This makes you appreciate the foresight of Sam Nunn and Dick Lugar that much more
1
1
9
1,830
Chris Finan retweeted
The gov’t has about 48 hours to fix a-soon-to-be-irreversible mistake. By allowing @SVB_Financial to fail without protecting all depositors, the world has woken up to what an uninsured deposit is — an unsecured illiquid claim on a failed bank. Absent @jpmorgan @citi or @BankofAmerica acquiring SVB before the open on Monday, a prospect I believe to be unlikely, or the gov’t guaranteeing all of SVB’s deposits, the giant sucking sound you will hear will be the withdrawal of substantially all uninsured deposits from all but the ‘systemically important banks’ (SIBs). These funds will be transferred to the SIBs, US Treasury (UST) money market funds and short-term UST. There is already pressure to transfer cash to short-term UST and UST money market accounts due to the substantially higher yields available on risk-free UST vs. bank deposits. These withdrawals will drain liquidity from community, regional and other banks and begin the destruction of these important institutions. The increased demand for short-term UST will drive short rates lower complicating the @federalreserve’s efforts to raise rates to slow the economy. Already thousands of the fastest growing, most innovative venture-backed companies in the U.S. will begin to fail to make payroll next week. Had the gov’t stepped in on Friday to guarantee SVB’s deposits (in exchange for penny warrants which would have wiped out the substantial majority of its equity value) this could have been avoided and SVB’s 40-year franchise value could have been preserved and transferred to a new owner in exchange for an equity injection. We would have been open to participating. This approach would have minimized the risk of any gov’t losses, and created the potential for substantial profits from the rescue. Instead, I think it is now unlikely any buyer will emerge to acquire the failed bank. The gov’t’s approach has guaranteed that more risk will be concentrated in the SIBs at the expense of other banks, which itself creates more systemic risk. For those who make the case that depositors be damned as it would create moral hazard to save them, consider the feasibility of a world where each depositor must do their own credit assessment of the bank they choose to bank with. I am a pretty sophisticated financial analyst and I find most banks to be a black box despite the 1,000s of pages of @SECGov filings available on each bank. SVB’s senior management made a basic mistake. They invested short-term deposits in longer-term, fixed-rate assets. Thereafter short-term rates went up and a bank run ensued. Senior management screwed up and they should lose their jobs. The @FDICgov and OCC also screwed up. It is their job to monitor our banking system for risk and SVB should have been high on their watch list with more than $200B of assets and $170B of deposits from business borrowers in effectively the same industry. The FDIC’s and OCC’s failure to do their jobs should not be allowed to cause the destruction of 1,000s of our nation’s highest potential and highest growth businesses (and the resulting losses of 10s of 1,000s of jobs for some of our most talented younger generation) while also permanently impairing our community and regional banks’ access to low-cost deposits. This administration is particularly opposed to concentrations of power. Ironically, its approach to SVB’s failure guarantees duopolistic banking risk concentration in a handful of SIBs. My back-of-the envelope review of SVB’s balance sheet suggests that even in a liquidation, depositors should eventually get back about 98% of their deposits, but eventually is too long when you have payroll to meet next week. So even without assigning any franchise value to SVB, the cost of a gov’t guarantee of SVB deposits would be minimal. On the other hand, the unintended consequences of the gov’t’s failure to guarantee SVB deposits are vast and profound and need to be considered and addressed before Monday. Otherwise, watch out below.
7,589
5,596
24,173
14,794,330
We’re in a hybrid war with Russia
New: A suspected Russian influence campaign of political cartoons is targeting the far-right in the US ahead of the midterm elections—aimed at undermining support for Democrat candidates in Pennsylvania, Georgia, New York, and Ohio, and spreading criticism of Biden, per Graphika
Worried about #ransomware but don’t know where to start? Check out the Blueprint.
Tailored to small- and medium-sized enterprises (SMEs) with limited #cybersecurity expertise. The Blueprint for Ransomware Defense provides a curated set of 40 achievable safeguards to harden protections against #ransomware. Download the blueprint here: bit.ly/3zABa0r