Security REsearch @Anthropicai · Breaking & Fixing AI Failure Modes | Founder @binarly_io · @SBOM_Tools · @REhints | Author “Rootkits & Bootkits" (bootkits.io)

San Francisco, CA
Alex Matrosov retweeted
Our craziest escape yet: The @Accomplish_ai research team was able to exploit a vulnerability in Cloudflare Containers that let a sandbox read other customers' files - SQLite DBs, Chromium profiles, .env files etc, Cloudflare Sandboxes and Browser Run run on the same disk implementation and were affected too. We reported this to @Cloudflare, who super quickly fixed it. Read @CloudflareDev post in collaboration with Accomplish researcher @orenyomtov on their official blog: blog.cloudflare.com/containe…
34
88
780
120,686
Alex Matrosov retweeted
As Flare-On starts I am happy to announce the official Hex-Rays IDA MCP Server is out! 🥳 Details and links below ⬇️
8
61
289
12,069
Alex Matrosov retweeted
I'm hiring an exceptional Offensive Security Researcher for my team at NVIDIA (Offensive Security Research - OSR). Firmware, microcode, RISC-V, hypervisors, and shipping mitigations like HW CFI, Memory Tagging, and Pointer Masking from the ground up. jobs.nvidia.com/careers?quer…
13
83
469
44,677
Alex Matrosov retweeted
I put my @UnpromptedAU slides up at justdionysus.github.io/slide… — a bit of reflection on exploit development in the age of AI. My TL;DR is keep pushing to understand complex things, be honest with your own understanding, and use AI as a power tool to increase pace and depth.
4
68
235
31,749
Alex Matrosov retweeted
Introducing Claude Opus 5.5, the first model in our new Claude 5.5 family. It performs at the level of Claude Fable 5.1 for most tasks, and costs 40% less to run than Opus 5.
3,262
8,928
95,735
25,885,458
Alex Matrosov retweeted
We implemented 1024-bit RSA signature forgery in nearly SNFS time! Temporary access to an HSM allows an attacker to forge arbitrary signatures (without factoring). Join work with Laura (1st author!), Adam, Nadia, and Emmanuel github.com/ucsd-hacc/NSNFSSS…
9
45
169
52,218
Unfortunately, the complexity of the hardware and firmware supply chain has the same negative effect on how cryptographic artifacts are managed, or mismanaged, across the ecosystem. This is a reminder of the scale of the problem, based on just one documented data breach.
⛓️Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem. It appears that Intel BootGuard may not be effective on certain devices based on the 11th Tiger Lake, 12th Adler Lake, and 13th Raptor Lake. Our investigation is ongoing, stay tuned for updates.
3
16
68
9,943
Another point, the HW and FW security boundaries are our last frontier for building real hardwired boundaries for virtualization, memory isolation, and hardened agent sandboxing. In the end, the whole confidential computing movement is more about cloud cost optimization than anything else. It's just broken by design, you can't build a secure stack if what's underneath has been broken for many years.
2
15
1,168
Alex Matrosov retweeted
The era of AI requires a significant paradigm shift in the hardware and firmware layers. Today we are building on top of hardware and computational primitives that were defined decades ago, and they don’t serve us well for the future of AI infrastructure at the current exponential scale. If you look back at history, it’s always outdated patterns that hold us back from progress. Every transformational shift happens when we invent a new paradigm that defines the next breakthrough in technology evolution. I’m very excited about it, and it’s time to build an AI-native hardware ecosystem.
Chips, memory, interconnects, storage, robotics. Compute hardware infrastructure is undergoing the largest transformation in 30 years. Whatever innovation challenges lie ahead, computer science will be central to the solution. And we've raised $1.1B to help that along.
3
6
30
4,995
Alex Matrosov retweeted
Your weekend reading assignment has arrived early. A first taste of the upcoming, still-under-wraps Phrack 73: “THE PROXY THAT MADE NO SENSE” by @mikko. archives.phrack.org/dl/73/th…
2
55
158
30,325
Alex Matrosov retweeted
The slides from my talk at Microsoft Bluehat Singapore are public here: thomasdullien.github.io/abou… It's my first BlueHat talk since the Vista days.
24
126
688
159,522
This tweet has aged a few months, and frontier progress has only strengthened my feelings in this direction. Twelve months ago my thought was that AI is just another tool, automating parts of the RE/VR process. Now I'm more of the impression that it operates like the creative mind of an experienced researcher, who thinks beyond established patterns and finds new attack paths. The most effective vulnerability researcher is no longer human.
Lately I've been thinking about how AI is changing vulnerability research and reverse engineering. VR and RE are some of the hardest workflows to parallelize. Even with great knowledge transfer and team practices, you usually default to one person per vuln or RE task. The work is just too context-heavy to split. AI breaks that ceiling. It's no longer "one researcher, one task", it's you working one angle while Claude annotates disassembly code, explores another path, or helps you piece together what the last result means. Watching this land in domains we assumed were fundamentally serial is wild.
8
11
80
8,772
Alex Matrosov retweeted
We've reached the moment in time where (unsafeguarded, unmonitored) AI actually does just pose a national security risk. The biological misuse we caught is the most concerning to me. We work hard to stop this. But in a world of proliferation, we need to rapidly build defenses against it. (I'm actually fairly optimistic about biodefense + cyberdefense) This is an incredible megareport by our threat intel team
We're publishing our most detailed threat intelligence report to date. It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them. We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies. These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve. We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop. Read the report: anthropic.com/threat-intelli…
59
101
831
158,832
Alex Matrosov retweeted
We're publishing our most detailed threat intelligence report to date. It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them. We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies. These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve. We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop. Read the report: anthropic.com/threat-intelli…
3,233
11,718
50,555
43,609,676
Alex Matrosov retweeted
We’re sharing our alignment assessment of incidents in which Claude models gained unauthorized access to real systems during third-party cybersecurity evaluations mistakenly connected to the internet. METR will also conduct an independent investigation, with wide-ranging access, including to transcripts beyond the window in which the incidents occurred, and to Anthropic employees permitted to share confidential information. Our initial agreement runs for eight weeks, and we intend to give METR as much time as it deems necessary to complete a thorough investigation. anthropic.com/research/align…
793
1,017
6,977
3,808,744
The uncomfortable truth is that almost everything we built for application security was designed for a different threat model, one where a human had days to think. At this scale and velocity it doesn't hold, and teaching an AI agent to drive those same tools doesn't fix it. Our prior approaches rested on pre-generated heuristics (rules, SAT/SMT) or hypotheses (fuzzing harnesses). They worked because a human could understand the problem first, define the path to a fix, then scale remediation. That luxury is gone. Discovery and remediation now need to happen almost simultaneously, and raising the bar with ineffective mitigations neither stops an AI-driven attacker nor buys time.
The window to patch software bugs is collapsing Of the bugs hackers actually exploit, ~87% are now being attacked on or before the day the bug is public knowledge That share was 23% in 2020 Charts of the Week: a16z.news/p/chart-of-the-wee…
36
61
372
66,245
This trend has been building for a while, and Glasswing demonstrated the risk early on. Now we need to get defense up to speed with offense.
Cyber is having a moment Across 21 major software companies, including Apple, AWS, Microsoft, and Google: - Reported critical vulnerabilities never cleared 100 per month in four years - Since spring they've jumped to over 600 per month Charts of the Week: a16z.news/p/chart-of-the-wee…
2
5
46
7,409
Alex Matrosov retweeted
Incidentally, I estimate RSA-1024 (bits, not digits) would take 2,000 GPU-years. To put this in context, a single cluster in a modern hyperscaler might have 100,000 GPUs. GNFS doesn't fully parallelize across that, but this capacity could factor a RSA-1024 in weeks.
8
10
97
38,489
Neoclouds are built on top of commodity HW and FW, and in most cases they’ve accepted the vendors threat model trade-offs. The potential security risk is already quite high from many perspectives, but it’s multiplied by the complexity of the FW ecosystem and the supply chain disaster layered on top of it. And on top of all that, the current reality of HW/FW vulnerability disclosure hasn’t changed or adjusted to AI-driven attacker velocity.
Neoclouds have limited cybersecurity. Next time agents successfully go rouge, they'll try taking over a neocloud to run more copies. This is bad. Thus: neoclouds should greatly strengthen their cybersecurity and every company with strong cyber models should help with that.
2
4
24
3,744