A Technology Journalist and cybersecurity professional. I have a mission to remove the marketing-speak from the information people receive in their news.

Shape the battlefield with what you have. Cybersecurity is (almost) always a logistical conversation first, followed by tactical and strategic decisions based on that. Most people would probably be shocked at how well a small team can shape the battlefield to devastating effect against an opponent.
> You don't need a lot, you just need folks who care, constantly learning, and want to do the right thing who aren't prevented from doing so. This!
1
14
4,063
Bits, Bytes, and Bourbon retweeted
Replying to @mubix
One more InfoSec is often a popularity contest. There are tons of people you have never heard of doing amazing things, some of the best move in silence. Along those same lines, don't just assume when someone talks on a topic, they're an expert, or everything is factual or based on their hands on experience.
4
6
51
4,917
Bits, Bytes, and Bourbon retweeted
I’m not a big name in Cybersecurity but Zack is correct here. Not only is Cybersecurity real, works, and can contain AI, we can even use AI to iteratively improve the state of the security of sandboxes. There *are* a finite number of zero days.
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
20
10
147
5,384
Bits, Bytes, and Bourbon retweeted
Nobody wants to look backwards because AI companies are acting like they just discovered cybersecurity and software bugs, but for some reason InfoSec now also has a really short memory. Just as a reminder, there was a time with no ASLR, no browser sandboxing, no AMSI, and far fewer exploit mitigations. Browser exploits regularly showed up in Metasploit. Java, Flash, ActiveX, Adobe Reader, and browsers were routinely exploited. Exploit kits were cheap, plentiful, and industrialized. Retailers got absolutely destroyed through POS systems. We’ve lived through waves of 0day and mass exploitation over and over again. There are tons of other examples if anyone cared enough to dig into how we got here over the last 20+ years. None of this is to say AI isn’t a major shift. It is. But acting like cheap, scalable offense or a massive imbalance between attackers and defenders is some entirely new concept requires ignoring a whole lot of InfoSec history.
4
1
21
618
I know some of you see this in your heads when you hear or read that a model is "misaligned"...
40
14
629
6,223
56,085
It's like when kids (who were throwing a ball around in the house) say "the lamp broke"...
Micha wrote “one of our models was able to gain unauthorized access to the internet during RL training” I love the use of the passive voice. Tis a subtle way to say “we humans at @OpenAI are essentially incompetent, having failed to provide even the most basic safeguards, compounded by the fact that our observability was missing in action.
1
5
220
Not a "big name" in cybersecurity for sure, but cybersecurity can absolutely contain LLMs, when done right. We are seeing terrible cybersecurity practices exposed at both the labs and their victims. (This is before and outside of potentially unethical behavior by the labs..)
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
2
1
6
321
Bits, Bytes, and Bourbon retweeted
InfoSec experts need to be stepping up and speaking out more. AI is a huge challenge on multiple fronts and we’re the experts that need to be leading the way.
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
11
37
223
9,111
Sleepy Saturday puppies!!
3
98
Agreed. This isn't how it should work. Yet, nothing ever seems to happen. Politicians rant on social media, but no one is held accountable, or are any meaningful consequences applied.
This isn’t how things work in any other incident reporting regime. Not aviation, not nuclear, not medical devices, not securities. Even in cyber (where the victims have valid reasons to keep the vulnerability quiet), they get max 90 days. Even in confidential reporting regimes (like CIRCIA and ASRS), they still release anonymized info. We’ve worked through these questions before, and the answer is never ~we defer to the wishes of the company.
1
4
187
Bits, Bytes, and Bourbon retweeted
Most performative and pointless work is downstream of a senior leader who’s totally clueless of how anything is actually done. This is why AI is the perfect employee. If you tell it to pull the SEC filings daily, it’ll churn tokens and tell you it’s doing exactly what you asked
Satya Nadella reveals his coding agent pulls every hyperscaler and neoclouds' SEC filings into a dashboard that refreshes every day for real-time ROIC "And this is the other aspect of it, which is the enterprise context combined with the world's context. In fact, I go to the SEC filings of every cloud provider, hyperscaler, each of these neoclouds. It's in real time." "I have a data runner in Fabric that brings all that data, puts it into a semantic model that then gets read by my coding agent and then surfaces it as a dashboard. And every day it's fresh." "So I have the entirety of every SEC filing that goes out there, plus all of my internal analysis constantly coming together, giving me real-time ROIC by layer."
8
14
318
28,838
Bits, Bytes, and Bourbon retweeted
🚨BREAKING (and I am not making this up): OpenAI claimed credit for discovering a new vector of attack that was actually previously known and cited in their own report. 🤦‍♂️
WTF? "A new research finding" Try googling Self Replicating Prompt Injection. The first result is an experimental demo of this from 2025! Oh, and authors of that paper disclosed their findings to OpenAI last year. The paper itself is the top citation in the OAI disclosure report. It seems OAI is either intentionally misrepresenting this as their own novel finding, or (and I do not want to believe this myself) had GPT generate a list of citations for them, then did not check the citations.
24
83
460
19,622
Bits, Bytes, and Bourbon retweeted
Real world cyber! Where we do things using foundational concepts, doing things in specific ways to reduce the likelihood of harm! #Ai #safety #Cyber #security #sandboxes
lots of talk about sanboxes and other shit like that.... where people are making services with NAT, DNS or other egress capability that isn't just the proxy interfac! So I've just built a quick lab to show you the bare bones of how to do it not so SHIT! #AI #Sanboxes #Network #Architecture #Cyber #Security
1
4
16
4,064
Bits, Bytes, and Bourbon retweeted
You might not have ever experienced the intensity of working toward a button click change in prod until you've tried to disable Anyone Links in a massive org.
4
2
22
1,104
Just to see Thanos say "I am like inevitable" followed by Stark saying "yeah?! Well I am Ironman and shit"
Dear @marvel @marvelstudios: Please, for the love of it all, give us a one-shot of Michael Pena as Luis doing a recap of the entire MCU saga leading up to @Avengers: Doomsday.

ALT michael pena GIF

118
Bits, Bytes, and Bourbon retweeted
Want to see a quick overview of how we build secure computing environments? #AI #Sandboxes #assurance #Cyber #Security #proxy #hardening #soc #siem #monitoring
lots of talk about sanboxes and other shit like that.... where people are making services with NAT, DNS or other egress capability that isn't just the proxy interfac! So I've just built a quick lab to show you the bare bones of how to do it not so SHIT! #AI #Sanboxes #Network #Architecture #Cyber #Security
5
3
28
17,347
Bits, Bytes, and Bourbon retweeted
Everyone is praising OpenAI's transparency, but this timeline feels misleading. 9:50 is when the AI first succeeded in accessing the external network, but when did it start trying? For CoT misalignment monitoring, that's what matters surely.
9
12
85
5,969
Bits, Bytes, and Bourbon retweeted
Ok so he has quarterly SEC filings downloaded by a coding agent. The daily updates are meaningless unless he is hooked into their general ledger accounting system, which he is not, so this isn’t as grand as it sounds. This is same stuff I heard from the sell side equity analysts back in the day of excel spread sheets: “We have the best model…blah blah blah.”
Satya Nadella reveals his coding agent pulls every hyperscaler and neoclouds' SEC filings into a dashboard that refreshes every day for real-time ROIC "And this is the other aspect of it, which is the enterprise context combined with the world's context. In fact, I go to the SEC filings of every cloud provider, hyperscaler, each of these neoclouds. It's in real time." "I have a data runner in Fabric that brings all that data, puts it into a semantic model that then gets read by my coding agent and then surfaces it as a dashboard. And every day it's fresh." "So I have the entirety of every SEC filing that goes out there, plus all of my internal analysis constantly coming together, giving me real-time ROIC by layer."
30
48
415
36,750
What makes this interesting is that according to the mass of rules I have been wading through, this company would have also had a sponsor to get them in the door as well. It is a double failure and, perhaps, an indication that the sponsor system is broke...
The Secret Service outsourced its forensic software to Moscow because lying on a federal vendor questionnaire remains an undefeated zero-day. telegraph.co.uk/us/news/2026…
6
318
Bits, Bytes, and Bourbon retweeted
No, "anthropomorphizing" is a technical problem, about how AI works, not something like woke language policing. We say it's wrong because it's "technically" wrong not "morally" wrong. If you fail to set the brakes when parking on a hill, and your car then rolls down the hill, you don't claim that the car "decided to drive away on its own". Such anthropomorphizing distorts what really happened -- that you failed to set the brakes. The same applies to AI. When you "anthropomorphize" the AI you fail at understanding what actually happened.
The whole "don't anthropomorphize AI" thing is very Woke 1.0. People trying to police language that is perfectly natural in some cases and ending up in a web of contradictions.
79
310
2,293
77,345