Linux and OSS Lover, breaker of distributed systems, OIF II Veteran, Security Engineer, Martial Artist, wannabe chef, and lifelong student. Tech is my passion

Lexington, KY
My motto going forward: Move fast and make stuff, unit test, don’t break stuff!
2
4
95
Jeff Schroeder retweeted
Announcing Sandlock 0.8.9 Sandlock is an open-source process sandbox built with Rust, Landlock, and seccomp. It runs without root privileges, cgroups, or namespaces, with APIs for Rust, Python, and Go. This release focuses on the details that matter when running agent tools, build jobs, and other untrusted workloads: • Stronger filesystem confinement. Copy-on-write file opens inside a chroot now stay anchored to their layer roots, fixing a path where absolute symlinks could reach host files. • A sandbox-specific network view. Virtualized /proc network tables expose sockets owned by sandbox processes, using socket cookies to identify ownership. Unsupported network entries are rejected. • More complete process cleanup. Shutdown and kill operations reach tracked process groups, including descendants that create new sessions or process groups. • More expressive network policies. Combine allow and deny rules to express policies such as “allow this range except that subnet.” Deny rules take precedence. • Better process-limit accounting. Process slots are released on exit, and process limits are now opt-in. Set an explicit limit when you need to bound process creation. Upgrade note: this release also changes the checkpoint image format; version 2 checkpoint images are no longer accepted. If you're building systems that execute untrusted code, try Sandlock and share the workloads you'd like us to test. Code and documentation: github.com/multikernel/sandl… Full changelog: github.com/multikernel/sandl… #OpenSource #Linux #Sandboxing #AIInfrastructure
7
21
166
9,260
Jeff Schroeder retweeted
Today I'm parting ways with Fly.io. It's been a privilege. I'm off to tilt at a big old windmill with Kurt, again. sockpuppet.org/blog/2026/09/…
46
23
738
177,493
Jeff Schroeder retweeted
this what u see right before ur core protocol and supporting infra is made secure by @asymmetric_re
1
3
22
1,654
We just published two blog posts about PageBreak, Google's AI web security scanner (that I've helped develop for the better part of the year). We share our approach and a couple of findings, enjoy! - blog.google/security/agentic… - bughunters.google.com/blog/p…
11
56
317
31,985
Can I see y’all when you were 21 👀
1
35
3,133
Jeff Schroeder retweeted
TamaGo unikernels dramatically reduce your attack surface, isolate tools selection and are memory safe. go.mod is your entire SBOM Attestation of the boot chain consists of a single ELF binary.
Containers are no longer a security boundary. Over the past few months, we’ve seen a crazy amount of Linux kernel vulnerabilities and exploits. This has forced us to rethink the security of infrastructure that relies heavily on the underlying kernel, especially containers. As models become more capable, the barrier to escaping a container has fallen so much that adversaries can now generate working kernel exploits in a single shot. CVE-2026-80521 is one such example. We discovered it using dfs-large1 from @depthfirstlabs and generated the exploit in one shot with GPT-5.6 Sol. The exploit still works on the latest Ubuntu 26.04 release because the fix has not yet been backported. Read our full writeup: depthfirst.com/research/cont…
2
4
36
6,074
Jeff Schroeder retweeted
BREAKING: Clavicular joins AI leaders in calls to slow the pace of frontier model development. “It is important to safetymaxx AI development to ensure we don’t get brutally mogged by AI agents”
27
58
1,374
98,241
Jeff Schroeder retweeted
Replying to @SEJeff
I wasn't there but I know who (or what) said this
1
1
60
OH: these people waiting for a parking space must believe in god #Zürich
227
OH: can you tell our founder was a HFT guy, an ML guy, and an AI guy
1
4
406
OH: I am real! I’m not a hologram!
1
1
213
Jeff Schroeder retweeted
Triton One highly recommends all Solana teams use this tool. If you need reliable and stable gRPC for incidental use for this; our Pay-As-You-Go prepayment model is the cheapest way to have it at the ready!
The @SolanaFndn just open-sourced Microscope, a free monitoring & alerting tool for Solana programs. We've tested it out. Its skills map alerts to our STRIDE security framework so the responding team has context to start from during an incident. github.com/solana-foundation…
2
4
34
2,464
No touchie my program!
excited to open source Microscope if someone touches your program in a way they shouldn't you want to know in seconds. not from a user dm the next morning one command runs the whole stack. it watches your program and the multisig that can upgrade it repo's in the thread, START MONITORING.
3
426
Aikido just drop (Altar-1) first open-weight Cyber-security model on HF & you can run locally. They took GLM-5.3, applied REAP expert pruning (168/256 experts kept), - 34% of experts cut. - 504B security MoE. - 92% of the parent’s CVE coverage kept. - 128k context - Internal CVE bench: 23/25 parent coverage retained. - Built for on-prem pentest, vuln hunting, code review, - Frontier-grade defensive AI you can run air-gapped.
6
21
183
13,570
Jeff Schroeder retweeted
I’ll be speaking at Scale or Die in London this November. Been a wild year for safety and security, can’t wait to share what we’ve learned!
4
15
814
Jeff Schroeder retweeted
I’m a big fan of Ethereum moving from 12 second blocks to 10 second blocks. Who knows what could be after that, maybe 8 seconds or maybe even 7.5
98
22
429
19,868
Jeff Schroeder retweeted
Replying to @JackMurphyRGR
Important advice for civilians from a war veteran with an active duty son: You have zero context to judge or understand this topic, regardless of what movies you've watched or articles you've read. Pay your taxes, thank a soldier, trust in the process, live your Delta Alpha Charlie lives in safety and abundance. If you're really interested in this topic, here's the one thing you can attempt to process: There isn't one man making these decisions... or even 10... and they're not in the Pentagon. If a mission isn't viable it's not going to happen. I know I know... you don't understand this, and you think the news media has provided you with conflicting information. You'd like to argue about it. Well, tough shit. What you think doesn't matter. Carry on.
14
1
26
8,147
Jaana is not one to sleep on. Worth checking out.
🥳 Excited to start revealing what we've been working on in the last few months. First, we decided to reinvent Kubernetes for agentic workloads with statefulness and fast resumption. Secondly, we are building an agentic orchestrator that will be Google's open agentic orchestrator and runtime. github.com/google/ax
5
923
Hot take: technical analysis is horoscopes for bros
Technical analysis time, Im extremely bearish Solana slot times. I think we’re going to see another leg down sometime real soon, in fact i wouldn't look for higher slot times. Bear market is here and there's 50ms in potential acceleration to the downside. I hedge now by acquiring before things get too fast. Applications are already feeling faster, transactions are landing faster, and the chain is flying faster than nasdaq ever could, and its all decentralized. get rekt bulls.
1
2
6
672