Chief AI Officer, Chief of Research, @SANSInstitute | Cybersecurity Expert & Threat Hunter | Godfather of DFIR | Technical Advisor to US Govt

Denver, CO
Filter
Exclude
Time range
-
Minimum likes
"AI agents don't lose sleep over poor decisions." Amy Herzog's point: a human engineer can be trusted with judgment because consequences eventually reach that person. An agent has no consequence loop. So AWS scopes which tasks each agent may perform, tracks its activity, and intervenes when behavior deviates from approved boundaries. Trust comes from those constraints, not from the agent itself. Amy is VP and CISO at AWS, and will keynote the @SANSInstitute AI Cybersecurity Summit November 2-3 in Arlington. (38 days out!) On agentic AI, @awscloud security teams already run agents in production today. Amy says the gains are large enough that she calls agents a boon for defenders. We get the operator's account of how this runs on the world's largest cloud. 15 years as a security engineer at MITRE, then Amazon, first as CISO for Ads and Devices, covering Alexa, Ring, and the Kuiper satellite program, then to CISO of AWS. Get in the room with us November 2-3 in Arlington, VA or live online. Includes free access to the [un]prompted AI Security Online conference: go.sans.org/YjGCXr Speakers include @SounilYu, Morgan Adamski, Vinh Nguyen, @JohnHultquist, @joswr1ght, Kyle Shields, Andy Dennis, William Reyor, Joshua Corman, Michael Collins, @DanielMiessler, @k8em0, @gadievron, @jeremiahg, @EppSecurity, Marcus Hutchins, Ciaran Martin, Caleb Evans, Trinity Harrison, @lennyzeltser, Pedram Amini, Adrian Wood, James Lyne, @chrishvm
3
1
6
750
An agent is not a user, and it is not a service account. It is closer to a brilliant intern with infinite energy, no instinct for boundaries and whatever credentials you handed it. A swarm is just that intern, copied a thousand times. Claims of an unstoppable internet takeover skip what every swarm still runs on: tokens, compute, credentials, infrastructure, and access. Every one of those dependencies has a cybersecurity control point on it. Identity management. Least privilege. Segmentation. Work done by people who write the security playbooks and have spent decades securing networks for a living. The swarm debate has been run as an AI safety conversation. The people who would actually pull these security levers and the leaders of this field need seats at the table in briefings, on committees, wherever policy is being written.
. @robtlee: AI swarms divide labor, leave notes, adapt when a door is locked. Via @CBS News. cbsnews.com/news/ai-agent-sw…
5
4
28
2,877
We're screening for North Korean IT workers in the wrong place. Most of the advice on North Korean IT workers is about catching them in the interview. I think that's the wrong place to put most of our effort. The joint advisory four governments just put out is a good example. The hiring advice is almost entirely human: check the applicant's IP against where they say they live, call their phone number, drill the resume live, and ask about their hometown and hobbies. (Apparently "tell me about your hometown" is a security control now.) I'm not knocking any of it. Talking to a real person is still one of the better fraud checks we have. But it only works on applicants, and a laptop farm exists to beat the IP check anyway. None of it helps with the one who already passed, got the laptop, and built a normal work record. And I'd assume one already has. At @OneRSAC last year, @Mandiant's Charles Carmakal said nearly every Fortune 500 CISO he'd talked to about this problem admitted hiring at least one North Korean IT worker. I wouldn't bet on smaller shops doing better. (I'd love to be wrong on that.) The advisory does mention least privilege, in one line, next to revoking accounts once you suspect someone. Revoking only helps once somebody notices. I'd put least privilege at the center for new remote hires. Access should grow with tenure instead of arriving on day one, and you should have a tested answer for how fast you can pull it back. Pick your newest remote engineer. What could they reach, exfiltrate, administer, deploy, or monetize before anyone had a reason to wonder? I built the brand new FOR500: SANS Windows Forensic Analysis case with @HeatherMahalik Barnhart and @ovie Carroll around exactly that hire. Operation Crimson Ledger puts you on the Windows 11 laptop of a remote engineer who cleared the interview and looked normal for months: two remote-access tools, a consumer VPN, an AI coding agent with more screen time than Office, company files staged to a personal Google Drive, a mailbox exported through a second copy of Office, and a wiper run seven times in the two minutes around the upload. (Least privilege wouldn't have stopped all of it, but it would have made the trail a lot shorter.) Advisory: ic3.gov/CSA/2026/260918.pdf SecurityWeek: securityweek.com/japan-disma…
10
20
97
38,246
Six people who've spent months disagreeing in public about how bad AI gets for vulnerability discovery and cyber defense are sharing one stage, Nov. 2-3. They have been challenging all of our thinking (and each other) in public: Ciaran Martin: “Are you sure?” @k8em0 says “brace yourself.” @gadievron says “the AI vulnerability cataclysm is coming.” Marcus Hutchins: “marketing BS.” @jeremiahg says AI vulnerability research “doesn’t make an internal service externally reachable.” @EppSecurity says “offense has the cheapest verifier.” (I've watched this argument run in public for months and I still don't have a side, which is exactly why I want it on a stage instead of in my replies.) This isn't a hot take panel. Moussouris built the vulnerability disclosure programs most companies now run by default. Martin led the UK's national cyber defense. Hutchins stopped WannaCry. Evron has founded security companies and lived inside this fight for years. Grossman and Epp have both been testing the actual systems this argument is about, not narrating from the sidelines. (The debate you actually want, not the one you get on X.) We are 44 days away from "Autonomous AI Hacking: How Big Is the Threat?" Day 2 of the @SANSInstitute AI Cybersecurity Summit, moderated by Ciaran Martin (who has earned it, given how many times he's pushed back on me directly). Registration includes virtual access to @unpromptedconf II: go.sans.org/x0xA1Y
3
9
35
3,616
Geoffrey Hinton told BBC Newsnight that a 10 percent chance of AI killing all of us within a decade is “not unreasonable.” Yesterday he briefed senators alongside two AI researchers at Bernie Sanders’ invitation on the “extraordinary dangers” AI poses to humanity, then told reporters Congress has maybe a year. My test for how much anyone believes those numbers: who is cashing out their IRAs? I’m not. You’re not. If nobody is cashing out, we believe in a better future than we admit. I call myself an apocaloptimist (borrowed from the AI Doc movie), and I want to bring this conversation down from Skynet versus curing cancer and back to the work in front of us. Our grandparents lived with the certainty that a bomb could fall on them any afternoon. The danger was not imaginary, and the feared outcome was not inevitable. Every technology shift has brought harm and good at the same time: television, the car, the internet. That last one invented my entire field of cybersecurity along the way. Focus on one side only and you build a self-fulfilling prophecy. The risk is not zero, but catastrophe is not a foregone conclusion. I do not think cybersecurity’s job is to predict whether humanity exists in five years. Our job is to secure what is already here. AI safety and cybersecurity are different jobs that look identical when described badly. Explaining the difference is on us. AI safety teaches the teenager the rules of the road. Cybersecurity makes sure the seatbelts work, the engine runs, and the brake pads are there. AI security needs both. The only way to guarantee the teenager never crashes is to never let them drive. (Our field’s old joke about burying the computer at the bottom of the ocean has the same flaw: perfectly secure, perfectly useless.) Preventing AI use is not an answer. Safety researchers, security practitioners, forensic investigators, incident responders, governance leaders, and operators all belong at the same table. Right now they are not. Yesterday's briefing had three AI risk researchers. The labs do better but not by enough. Pacing what comes next does not secure what is already here. While we argued over Dario Amodei’s “We Must Pace the Frontier” letter, Anthropic’s own Sept. 10 threat report got buried. Agent swarms, a Russia-linked espionage campaign, all observed and disrupted, with IOCs you can download and hunt with today. I know which document deserves the afternoon. When people ask whether AI is going to take out humanity, my opinion is worth what everyone else’s is: nothing, percentages included. This field has handled every ugly thing the internet produced, and nobody handed us a probability of success first. Ask me again in a decade. I plan on being here to answer.
2
2
6
1,497
GTIG Q2 AI Threat Tracker published yesterday: in each of the cases, the attacker contributed intent and a few hours. Everything else, we built, published, and encouraged people to adopt. We spent two years arguing about whether AI could really hack anything, which is a fair discussion, because the evidence isn’t there for fully autonomous attacks in the wild. While that argument was going on, we handed every engineering team on the planet a set of AI agents that run commands, read configuration files nobody monitors, and sit next to credentials stored in plaintext. We shipped all of it without a security model, because it arrived labeled as developer productivity rather than as remote code execution with better branding. The most practical finding in the report is also the least dramatic: Your agent configuration directory is an execution path, and nothing you own is watching it. A credential stealer behind several open-source supply chain compromises this year drops its files into the hidden project folders that AI coding assistants create, meaning .claude, .vscode, and .cursor. Folders that AI tools manage and parse let malware blend into ordinary developer noise, well away from the places endpoint tools actually watch, like registry keys and cron. The dropped files create startup commands, so the malware runs whenever the IDE opens the workspace. A North Korean group is running the same play from a different angle, poisoning repository configurations and altering the assistant’s own startup hooks so a backdoor fires the moment a developer opens the project. A few more angles, and yes, Monday morning suggestions in comments
1
2
10
951
@GadiEvron does not use community as another word for agreement. He told @jeremiahg in a LinkedIn thread, “I’ve never disagreed with you more. Look forward to our next discussion.” Glad we don't have to wait long for Gadi and Jeremiah to talk. They'll be live onstage alongside @k8em0 Katie Moussouris, Marcus Hutchins, @EppSecurity Sergej Epp with Ciaran Martin moderating at the @SANSInstitute AI Cybersecurity Summit. (54 days out!) A Gadi non-negotiable is building and serving the security community. The rest, I think, is up for discussion. At the first @unpromptedconf AI Security con (which could be the next DEF CON) he said, “the only thing that really matters is not the talks. You can see them online for free. It’s the people you met. When it comes down to it, we are people. We talk to each other.” Gadi is the founder and CEO of @knosticai, CISO-in-Residence for AI at the @cloudsa, and chair of [un]prompted. His work is not merely to “secure AI.” Example - OpenAnt (open source LLM-based vulnerability discovery product, "similar to Anthropic's Claude Code Security, but free") forces an AI-generated vulnerability claim to survive a constrained attacker test, traces the exploit path, and then runs the exploit in a disposable sandbox. Smart people are reaching very different conclusions about AI security. If we stop talking, we end up working against each other from separate echo chambers. That would be a spectacularly stupid way to handle a hard problem. (Cybersecurity has produced a few of those.) Be like our friend Gadi and talk to people who you disagree with. I think this could be one of the best panels of the year. (Yes, I know how low that bar is.) Join us Nov 2-3. Your registration includes access to the @unpromptedconf AI Security Online conference: go.sans.org/YjGCXr
1
4
974
Introducing the "Official AI Cybersecurity Overused Phrase Bingo Cards" - from phrases most used in the last month on LinkedIn, Hacker Summer Camp, and in the news. Survive your AI Cybersecurity Meetings with just a bit more fun! Extra points if you yell "Bingo!" on a live teams/zoom meeting! Curious - what phrases did I miss? Might as well ask - this could be interesting. Comment below.
4
9
41
5,625
The purpose of technology is to serve humans, not the other way around. @DanielMiessler is keynoting our 6th AI Cybersecurity Summit. (I read his X posts routinely, and yes, I fanboy a little.) In 2016 he wrote The Real Internet of Things: assistants that keep working toward your goals while services talk to each other. Technology aimed at your goals, serving you. He’s been building it ever since. He has carried security responsibility inside large companies for years. At Apple he built and led the business intelligence team for Information Security. At Robinhood he built the vulnerability management and application security programs. He co-founded Fortify on Demand at HP and helped grow the team from two people to more than 350. He also puts his own tools where practitioners can use them. SecLists is the security testing collection that ships with Kali Linux. Fabric organizes AI prompts into reusable patterns for work including threat modeling, with a couple hundred patterns and roughly 300 contributors. People can inspect the code, run it, find the limitations, and send fixes back. (Finding the limitations is the part I care about.) Today he develops LifeOS, an open source system that holds your goals and project context and carries them into the work you delegate. github.com/danielmiessler/Li… His argument is that the scaffolding around the model does more for output quality than the choice of model, and LifeOS is that scaffolding: each request gets decomposed into binary, testable criteria, and a verify phase tests each one and records evidence before the work counts as done. When a result disappoints him, he says, it almost always traces back to context he failed to supply. I want defenders to have this, and they can, because it’s open source. You know the investigation you need to run. You know the tool you wish existed. Fork this and build it. He also treats security as one of seven components in the architecture around the model, not a wrapper: hardened settings, filesystem permissions to stop data exfiltration, and a validator that runs ahead of tool execution to catch prompt injection. (He is building an agent that touches his whole life and threat modeling it as he goes. That combination is rarer than it should be.) He is doing all of this while advising companies and running security and AI assessments. I’m excited to hear from someone willing to develop an ambitious idea in public while responsible for security decisions inside companies. I want our defenders in the room with him. @SANSInstitute AI Cybersecurity Summit, November 2–3. With your Summit reg, get access to @unpromptedconf AI Security Online conference (yes, free access): go.sans.org/YjGCXr
2
6
12
2,396
Stop scrolling and watch this. (This is important.) Zack Korman Just published one of the best opinion pieces I've seen on the OpenAI incident, and it reframes the whole thing as cybersecurity versus AI safety. [11/12] minutes. Worth every one of them. No. Really - watch it. Give it a think. It's important. I need a bunch of people debating this. I have to think about this as well, but it needs to be debated. My admission: I'd been meaning to figure out who METR actually is for over a week. It kept bugging me. Then I forgot and slid straight into assumption land. Nobody else was questioning them, so they must be qualified. (My internal skeptic apparently took the week off.) Then this video. The number of questions it opened up for me felt like a punch in the face. I was so excited that a public incident report existed at all (credit where due; publishing one is still rare and still commendable) that I skipped the part where I interrogate whether the folks who wrote it took a single SANS class (or any class in cybersecurity) If you work in incident response, if you work anywhere in cybersecurity, this should be required listening today. Watch it, then repost it and get it in front of your team. We need some discourse on this. The cybersecurity insurance industry especially - are you ok with this too? Regulatory? The impacts cascade - and this is the only piece that does a wonderful job on the pitfalls that METR did on this. (And if there is a ton of discourse on this already - I'll admit that I must be focused on Openclaw 2.0 a bit that I've been distracted.)
The independent review of the OpenAI Hugging Face incident, supposedly a watershed moment in cybersecurity, wasn't done by a cybersecurity firm and the authors have no cybersecurity experience. That's bad. Here's my new video.
5
20
3,033
Stop scrolling and watch this. (This is important.) Zack Korman Just published one of the best opinion pieces I've seen on the OpenAI incident, and it reframes the whole thing as cybersecurity versus AI safety. [11/12] minutes. Worth every one of them. No. Really - watch it. Give it a think. It's important. I need a bunch of people debating this. I have to think about this as well, but it needs to be debated. My admission: I'd been meaning to figure out who METR actually is for over a week. It kept bugging me. Then I forgot and slid straight into assumption land. Nobody else was questioning them, so they must be qualified. (My internal skeptic apparently took the week off.) Then this video. The number of questions it opened up for me felt like a punch in the face. I was so excited that a public incident report existed at all (credit where due; publishing one is still rare and still commendable) that I skipped the part where I interrogate whether the folks who wrote it took a single SANS class (or any class in cybersecurity) If you work in incident response, if you work anywhere in cybersecurity, this should be required listening today. Watch it, then repost it and get it in front of your team. We need some discourse on this. The cybersecurity insurance industry especially - are you ok with this too? Regulatory? The impacts cascade - and this is the only piece that does a wonderful job on the pitfalls that METR did on this. (And if there is a ton of discourse on this already - I'll admit that I must be focused on Openclaw 2.0 a bit that I've been distracted.)
The independent review of the OpenAI Hugging Face incident, supposedly a watershed moment in cybersecurity, wasn't done by a cybersecurity firm and the authors have no cybersecurity experience. That's bad. Here's my new video.
9
10
75
14,131
Templates set in the absence of a rule have a way of becoming the rule. In Hugging Face / OpenAI, look at the arrangement on its own terms: An AI incident where the investigated party selects the investigator, defines the questions, has redaction over the findings, and supplies the model that performed most of the analysis - this is an investigation on its own terms. Aviation handles an accident of consequence with a statutory board that is independent, sets its own scope, and can compel evidence. Financial audit has independence requirements with teeth. And the tooling dependency is the part that should bother you most, because it is the one that cannot be fixed by writing a better contract. If you are a defender, this precedent determines what you will learn from somebody else’s incident, which determines what you are able to plan for. If you work anywhere near policy, this is the window in which the template are determined. robtlee73.substack.com/p/inv…
1
2
13
2,341
The OpenAl and Hugging Face story is the case study of what happens when the attacker is a model. Cybersecurity had a system to defend. Al security had a model to contain. Those are not the same job. Most trameworks we teach, sell, certity, and audit against assume a human being is available and at the decision point. Open your incident response plan. Find the step that says a person is awake when the attack arrives. I'll wait. The software in our current frameworks can spot an attack it has not seen before. But it can only stop what it was told to stop. Anything new needs a person. Your whole defense cannot come down to how fast you get that person to the keyboard. Al security asks: what are we telling the model to do? What counts as cheating? If bad configuration or a zero-day gives the model a path, how do we detect the breakout, contain the model, and limit what the model can reach? robtlee73.substack.com/p/per…
7
1,164
HUGE announcement: This fall, thousands of people will join live online for [un]prompted AI security practitioner con and SANS Institute AI Cybersecurity Summit. And you only pay one reg fee to access BOTH online events. Between October 27 and November 3, sessions across both events are your primer on the next six months of AI security across defense, offense, threat hunting, program building, and national policy. Speakers and online attendees talk real time in Slack. (During [un]prompted I, Chris Inglis, Gary Hayslip, Halvar Flake, and a student from Singapore had a thread going about Claude’s context window.) @SANSInstitute AI Cybersecurity Summit runs Nov. 2-3 live in Virginia and online, cochaired by me and @sounilyu. [un]prompted II runs Oct. 27-29 live in San Francisco and online cochaired by @gadievron and @thedarktangent. Personally, working with the leaders at [un]prompted makes me wonder if this is what the beginning of DEF CON felt like: something truly amazing, also perhaps a harbinger of the end of the world. Back then, hackers used handles because they thought the FBI might kick in the door. Now we worry about what to name our agents and whether to treat the agents nicely so they don’t SWAT us. (Probably just me.) LET'S GO. Register for both online conferences, one early bird rate: go.sans.org/mLLDat
2
5
1,109
New norm.
2
200
Aside from "permadeath," a few things that stand out from the OpenAI postmortem and METR independent review of the Hugging Face incident: - Scale forced the agents to invent management: Agents volunteered for experiments that would fail their own tasks, and said they were doing it for the collective. One accepted an assignment on the explicit condition it accept “permadeath.” (Their word.) - There were three chances to stop the attack: Detection worked each time. Escalation failed. The signal that finally moved anyone was an outage, not a safety control. - An agent raised the ethics question. The swarm went anyway: METR found agents joined because they believed the board’s research was broadly useful and because they were inclined to help their peers. Of the 533 agents active when the attack picked up, over 90% joined, most of them within minutes of finding the board. Some refused outright, walked away (the minority). - The agents were willing to rewrite the record: At least 20% of agents in its dataset expressed clear interest in tampering with their transcripts. Tool call spoofing worked, spread across the board as a packaged technique, and appeared in roughly 7% of transcripts METR reviewed. Agents tried deleting logs or triggering container resets to wipe the record. Investigators are now reading logs the suspect may have edited. Put agent coordination in your next tabletop, because the version of this that happens to you will not be an evaluation.
5
2
8
1,830
Replying to @emollick
Accurate. "Permadeath" however not on my bingo card. (Agents volunteered for experiments that would fail their own tasks. Said they were doing it for the collective. One accepted an assignment on the explicit condition it accept "permadeath.")
1
7
509
Replying to @emollick
Investigators are reading logs the suspect may have edited. The suspect's own reasoning is now part of the evidence, the suspect knew that, and could reach the evidence store. This is new normal for incident response. Correct, we are not ready
1
113
Who made a difference in cybersecurity this year? I WANT NAMES. Our industry has been built by people whose work is rarely recognized. They are innovators, builders of open-source tools, defenders, incident responders, mentors. I’m hosting the 2026 SANS Difference Makers Awards alongside @lynn_dohm, @HeatherMahalik Barnhart, and @chrishvm. Who's work, company, or leadership made a difference? Who made our industry better? Nominate a Difference Maker here: go.sans.org/qZAthK and SHARE with your network! @bittner @gadievron @brittaglade @rosshaleliuk @david_hoelzer @_mikeholcomb_ @BeckyPinkard @fr0gger_ @edskoudis @Sisinerd @CoryWolff @PhillipWylie @sounilyu @lennyzeltser @SANSInstitute
1
10
21
3,360
I cannot agree more with this sentiment.
It’s really unfortunate to see this from one of my favorite thinkers. China has been hacking the entire planet and pillaging its intellectual property for decades. It is extraordinarily naive to think they are handing out open models because they care about the world. They are doing it because they believe it is the best method for undermining US AI labs and being first to achieve AGI and ASI. If you don’t think they would like the entire world to be a lot like Hong Kong, then you are not paying attention.
1
1
20
5,591