๐ŸŽ“ Faculty, ECE @TelAvivUni | ๐ŸŽฉ @BlackHatEvents Review Board | Cybersecurity | LLM & AI AppSec

Israel
Pinned Tweet
@dangoodin001 just covered our new study on ๐—•๐—ฒ๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—ผ๐—ณ ๐—”๐—ด๐—ฒ๐—ป๐˜๐—ถ๐—ฐ ๐—•๐—ผ๐˜๐—ป๐—ฒ๐˜๐˜€ Co-authored by Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, and @ben_nassi . A joint work by @TelAvivUni @TechnionLive @Intuit A link to the the website containing the paper: sites.google.com/view/agentiโ€ฆ #promptware #agents #botnets #agentic_botnet
Hackers can use 9 of the most popular AI tools to assemble massive botnets arstechnica.com/security/202โ€ฆ
2
390
8en N@$$! retweeted
Zero-click prompt injection? It's a half-click. That's @ben_nassi 's correction to his own use of the term, and on ep. 3 of In the Wild, From Dumbledore to Delayed Tool Invocation, he explains why the gap matters:
1
2
2
915
Many thanks to @zenitysec_labs and @mbrg0 for hosting me to discuss interesting topics. Here is the second part of the podcast #prompt_injection #LLM #infosec #cybersecurity #promptware
part 2 of my convo w/ @ben_nassi is up on in the wild! we talk about google's response to 'invitation is all you need', CaMeL, beyond the lethal trifecta, half-click ai exploits, BlackHat submission, what is a great talk, and the real world ai security conf
5
179
8en N@$$! retweeted
New @zenitysec Labs podcast w/ @mbrg0 + @ben_nassi on where AI security is going next: Prompt injection vs Promptware AI worms Coding agents as hacking tools Agent supply-chain attacks Prompt injection โ†’ RCE AI security ownership Why LLM refusals aren't security controls AI vulnerability disclosure is broken The coming โ€œCrowdStrike momentโ€ for AI Full episode in comments ๐Ÿ‘‡
2
3
14
1,880
8en N@$$! retweeted
If you work anywhere near AI security, @ben_nassi is someone worth listening to. He joins @zenitysec's @mbrg0 for the inaugural episode of ๐ŸŽ™๏ธ#InTheWild๐ŸŽ™๏ธto talk AI worms, promptware, whatโ€™s coming next. Tune In๐ŸŽง Spotify: lnkd.in/g8AKJWRn Apple: lnkd.in/ghR9_Vm7
2
5
114
A talk with a great friend on techโ€ฆ
Replying to @h19kle @inbarraz
starting with @ben_nassi we talk about the real world ai security conf at Stanford, the best BlackHat talk opener ever staring Dumbledore, building an ai worm with GPT4 back in 2024, and the evolution of promptware available now on youtube, spotify and apple pods piped.video/9uinwdWXlQ8
1
5
256
8en N@$$! retweeted
Extremely happy to get a Pwnie! Hacking Agentic Browsers was fun this year! Going to post some technical dives today!
here we go. we got the pwnie for best ai sec bug! thank you to all ai vendors for shipping slop browsers for us to hack! @StAJect0r @supriza0 @tamirishaysh @p1njc70r
2
11
946
The first autonomous agent cyberattack is an unprecedented event that deserves unprecedented transparency. Today weโ€™re sharing everything we can: a full technical timeline, an interactive replay, and how we used an open model to defend ourselves, so defenders everywhere can learn from it and prepare for whatโ€™s next. huggingface.co/blog/agent-inโ€ฆ
282
1,192
5,613
1,700,183
8en N@$$! retweeted
Talks from Stanford's Real-World AI Security Conference are now on YouTube! Full list is here seclab.stanford.edu/RealWorlโ€ฆ So many amazing talks, I really liked: ๐Ÿ”น AI Agents Enable Adaptive Computer Worms, Nicolas Papernot ๐Ÿ”ฅ ๐Ÿ”น The Road to Hell Is Paved with Helpful Agents, Vitaly Shmatikov ๐Ÿคฏ ๐Ÿ”น Evaluating and Defending Against Prompt Injection Attacks, Edoardo Debenedetti ๐Ÿช๐Ÿ’ฅ ...and many more excellent talks covering outstanding research!
5
18
64
5,577
8en N@$$! retweeted
AI coding assistants are not just helping developers. HalluSquatting, GhostApproval, and GitLost show how attackers can exploit hallucinated repos, fake package names, private code access, and dangerous approvals. Security Now breaks it down. twit.tv/shows/security-now/eโ€ฆ
1
1
543
ื”ื’ื™ืœื•ื™ ื”ื ืื•ืช ืฉืœ ืืœื™ืกืฃ ืคืจืฅ
22
29
292
14,699
ืžืžืฉื™ืš ื‘ืื•ืชื” ื”ื˜ืงื˜ื™ืงื” ืฉืขื‘ื“ื” ืœื• ืขื“ ืขื›ืฉื™ื•. ืœื‘ื•ื ืงื˜ื ื™ื ืœืฆืืช ื’ื“ื•ืœื™ื
๐Ÿ—ฃ๏ธ "They should be confident of progressing, definitely... it's England" Norway's Erling Haaland on facing England in the World Cup quarter-final ๐Ÿค
2
1
24
2,897
You can find the talks from Real World AI Security on a dedicated YouTube channel we opened (many thanks to @danboneh for his efforts in uploading them). There are a few missing videos of speakers who did not permit us to upload their talks. For those who asked me for the slides of my talk, here is the link to the video of my talk on the Promptware Kill Chain (co-authored by @BrodtOleg , Elad Feldman, @schneierblog , and @ben_nassi ) Video (on YouTube): piped.video/JiwSHjBxmqc Paper (arXiv): arxiv.org/abs/2601.09625Real World AI Security (YouTube channel): piped.video/@RealWorldAISecCโ€ฆ #RWAISec #real_word_ai_security #ai #infosec #llm #security #cybersecurity #promptware #prompt_injection
1
2
10
823
8en N@$$! retweeted
two weeks left on the tokyo agent security summit cfp! we're going to start w early acceptance next week so much cool stuff so far!
1
2
6
778
8en N@$$! retweeted
@Stanford The Real World AI Security Conference 2026, led by Dan Boneh, was incredible. Personal highlights: - Deep convos on AI agent security with red teamers, blue teamers, researchers, builders, and defenders - Great talks from @wunderwuzzi23 and @ben_nassi - @zenitysec Happy Hour - Robot hacking w/ @BT6_Official at @ARIA_research I had the chance to demo live hacking a ROBOT with @BT6_Official: โ€œKinetic Prompt Injection: Live Jailbreak of an Embodied Agentโ€ Huge shoutout to my die hard brothers @PhilDursey, @Ph1R3574R73r, and @Eito_Miyamura for the demo. Great seeing @danboneh, @mbrg0, Keren Katz, John Sotiropoulos, Alan Aqrawi, @wunderwuzzi23, and many others pushing this space forward. AI security is moving fast, but AI agent adoption is moving even faster. It was exciting seeing everyone is attacking this problem from so many different angles. Thereโ€™s still a lot of debate around the role and efficacy of model-level guardrails in defending AI systems. Thanks to @zenitysec for supporting the event. Stay tuned for the robot hacking post. ๐Ÿ‘€
1
6
19
2,308
ted โ€ข Visible to anyone on or off LinkedIn My few takeaways from the 1st Real World AI Security Conference. 1. ๐—ง๐—ฒ๐˜…๐˜๐˜‚๐—ฎ๐—น ๐—ฃ๐—ฟ๐—ผ๐—บ๐—ฝ๐˜ ๐—œ๐—ป๐—ท๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป๐˜€. Based on the talks given by Google, Anthropic, and OpenAI, I am happy to see that the biggest AI whales improve their mitigations against textual prompt injections.ย My feeling is that their mitigations are at a level preventing 99.9% of the attacks against their systems, allowing only out-of-distribution attacks to bypass. This is a significant improvement from where we were a year ago, when many studies showed how insecure production systems are. 2. ๐— ๐˜‚๐—น๐˜๐—ถ๐—บ๐—ผ๐—ฑ๐—ฎ๐—น ๐—ฃ๐—ฟ๐—ผ๐—บ๐—ฝ๐˜ ๐—œ๐—ป๐—ท๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป. I am more concerned at this time about multimodal prompt injections because it seems like less progress is invested in this field. My feeling is that most systems remain vulnerable to multimodal prompt injections. Given that many humanoids will be deployed in the next few years, we must invest significant efforts in securing systems in the latent space against multimodal prompt injections. 3. ๐—ฃ๐—ฟ๐—ผ๐—บ๐—ฝ๐˜ ๐—œ๐—ป๐—ท๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—ช๐—ถ๐—น๐—ฑ. The web is rapidly changing in light of the increasing use of agents. Based on Palo Alto and CISPA talks, I believe that the web has become the most common place to meet "prompt injections in the wild". Whether they succeed or not remains a mystery because we are currently lacking the ability to measure their success rate on the client side. 4. ๐—ก๐—ฒ๐˜„ ๐—ง๐—ฒ๐—ฐ๐—ต๐—ป๐—ผ๐—น๐—ผ๐—ด๐—ถ๐—ฒ๐˜€ ๐˜๐—ผ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—”๐—ด๐—ฒ๐—ป๐˜๐˜€ Given that the web is rapidly changing in light of the increasing volume of agentic browsing, we will have to develop and adopt new technologies to support this change. I believe newer technologies will be invented in the next few years, and this field will become a focus for academics and industry. 5. ๐—ง๐—ต๐—ฒ ๐—˜๐—ณ๐—ณ๐—ฒ๐—ฐ๐˜ ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ ๐—œ๐—บ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ๐—บ๐—ฒ๐—ป๐˜ ๐—ถ๐—ป ๐—Ÿ๐—Ÿ๐— ๐˜€ ๐—ผ๐—ป ๐—ฆ๐—ฐ๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐—œ๐—ป๐—ฑ๐˜‚๐˜€๐˜๐—ฟ๐˜†. Based on the talk delivered on how good LLMs have became in finding vulnerabilities in open sources, I expect to see a similar effect in science in general. I am not even sure whether scientists will be the most important leaders in their field in a few years from now, because I believe that most of the significant discoveries will be made by LLMs.ย Scientists and engineers will have to reinvent themselves in light of these changes. Anything else I forgot? #infosec #ai #agents #LLMs #prompt_injections #AI_Security #real_world_ai_security #RWAISec26
1
1
2
1,753
By far, the best way to prompt inject a system nowadays is to #llm #agents #prompt_injection #RWAISec26
5
210