Writes "Starting Up Security" @ scrty.io, tweets horror stories @badthingsdaily

Ryan McGeehan retweeted
Today I'm parting ways with Fly.io. It's been a privilege. I'm off to tilt at a big old windmill with Kurt, again. sockpuppet.org/blog/2026/09/…
46
23
737
178,429
Ryan McGeehan retweeted
.@1Password's FLAWED report says AI models produce a clean security fix only 26% of the time. Defenders shouldn't take that number seriously. • The six vulnerabilities were handpicked because their fixes were complex. Clean-fix rates ran from 3% to 60% depending on the bug, and the report averaged them together. • Agents set up to fail were counted in the headline figure. Two of 1Password's prompts instructed the agent to apply the wrong fix. Those trials make up 22% of the data. One evaluation mode prevented the agent from compiling or running any code, and it accounts for 36% of the data. • The report ran two models, GPT-5.5 at medium effort and Opus 4.8 at high. Neither was tested at its highest available setting, so the report says nothing about how more effort or stronger models change the results. • Several instruction and grading errors further undercut the headline, and are elaborated upon in the attached blog. We've spent four months submitting hundreds of AI-authored patches to widely adopted open-source projects as part of Patch the Planet. Our experience didn't match 1Password's report, so we did a full analysis across 186 AI-authored pull requests and 33,500 subsequent commits, benchmarked against 2,265 human-authored patches we graded across years of security engagements. blog.trailofbits.com/2026/09…
24
49
266
556,150
Ryan McGeehan retweeted
1,535 potential bugs found, 1,017 awaiting patches, 326 fixes open upstream, 192 merged. Since Aug 4: +398 bugs, +46 merged, 55 codebases under review, and scapy has overtaken vllm as the most-reported codebase in Patch the Planet. trailofbits.com/patch-the-pl…
1
12
37
4,699
This talk is a must watch. Think about what agentic intrusions could look like and how incident response will be shaped after them.
Our Black Hat talk on the OpenAI-Hugging Face incident is now live on youtube. This is a watershed moment for the industry. I encourage all defenders to watch, consider how attack dynamics will imminently change, and plan for accelerating defense. piped.video/watch?v=87DyyMV0…
5
615
OpenAI speaking tomorrow about the Hugging Face incident at Blackhat.
Black Hat invited us to speak tomorrow about the Hugging Face incident. Given its complexity, we think it’s important to share what happened, what we learned, what we’re changing, and what this means for AI security and alignment. We still plan to publish a technical postmortem once the review is complete.
1
6
1,529
Ryan McGeehan retweeted
858 potential bugs found, 595 awaiting patches, 120 fixes open upstream, 143 merged. Our new Patch the Planet dashboard breaks down the latest results from our audits of curl, OpenSSL, Kubernetes, and 38 other open-source projects. trailofbits.com/patch-the-pl…
5
15
95
9,097
Ryan McGeehan retweeted
Rust maintainers assumed a team of engineers was behind our bug reports. It was one engineer using Codex's /goal.
7
10
393
42,395
Ryan McGeehan retweeted
Here's the big thing @trailofbits was cooking:
Patch the Planet is our joint initiative with @OpenAI to help maintainers strengthen critical open-source software. In one week, we used Codex and GPT-5.5-Cyber to find hundreds of bugs inside OSS like cURL, Python, and the Go project. 37 patches merged, with more in flight. 🧵
5
7
61
9,500
Ryan McGeehan retweeted
🚀 We're out of stealth. Today we're introducing Ent, the industry’s first intent-aware Workspace Security platform for human and AI-driven work 🎥 See what it means to protect work as it happens. #IntentAware #LaunchFromStealth #WorkspaceSecurity #CyberSecurity
49
33
153
352,581
Ryan McGeehan retweeted
I strongly believe there are entire companies right now under heavy AI psychosis and its impossible to have rational conversations about it with them. I can't name any specific people because they include personal friends I deeply respect, but I worry about how this plays out. I lived through the great MTBF vs MTTR (mean-time-between-failure vs. mean-time-to-recovery) reckoning of infrastructure during the transition to cloud and cloud automation. All those arguments are rearing their ugly heads again but now its... the whole software development industry (maybe the whole world, really). It's frightening, because the psychosis folks operate under an almost absolute "MTTR is all you need" mentality: "its fine to ship bugs because the agents will fix them so quickly and at a scale humans can't do!" We learned in infrastructure that MTTR is great but you can't yeet resilient systems entirely. The main issue is I don't even know how to bring this up to people I know personally, because bringing this topic up leads to immediately dismissals like "no no, it has full test coverage" or "bug reports are going down" or something, which just don't paint the whole picture. We already learned this lesson once in infrastructure: you can automate yourself into a very resilient catastrophe machine. Systems can appear healthy by local metrics while globally becoming incomprehensible. Bug reports can go down while latent risk explodes. Test coverage can rise while semantic understanding falls. Changes happens so fast that nobody notices the underlying architecture decaying. I worry.
503
1,882
15,217
1,607,476
I wish all security pros practiced a scenario-first mindset. Explanations based on risk scenarios before jumping to best practices, gaps, controls, compliance etc. I wrote an essay to coach on this: "Writing a risk scenario" medium.com/starting-up-secur…
2
1
6
665
I wrote about that moment every security team faces when someone asks if they can work from China for a while, and then everyone freaks out. magoo.medium.com/the-working…
1
1
15
1,741
My "Starting Up Security" writing correlates to my caffeine intake which has dropped off over the last few years. Today I got tricked into an actual coffee, so drafts are open. Taking any requests, just DM ☕️
4
809
Ryan McGeehan retweeted
“Detection is a problem I describe as deceptively tractable.” @Magoo on 🔍 Prioritizing Detection Engineering Proposed implementation order: 1. Get logging in order, focusing on query-ability and minimum viable logs. 2. Spend time on hardening before formalizing detection. 3. Introduce high-quality detections and alerts, starting with a reference alert and focusing on invariants. 4. Address management challenges before scaling detection efforts. 5. Fully embrace an engineering approach to detection, with the ability to throttle or accelerate work as needed. medium.com/starting-up-secur…
2
17
1,611
Malware (!!??!!) may have been the factor in an attack that blew up hundreds of Hezbollah Operatives pagers in an attack.
1
1
717
I will be really surprised if these were not sabotaged before delivery somehow.
1
3
346