lead product/detection engineering @Abnormal

Seattle, WA
yuzhou retweeted
Whether it's a city or a company, I've always said the people make the place. And that couldn't be more true for @Abnormal. This week we had over 100 members of our R&D team fly out to Houston for our offsite, and it reinforced why I love this team so much. My personal highlights were: - Hyping the team up with our 1 year retro and 2027 roadmap strategy with @ujooe @jshulman7 and Winston - Building our hackathon project using Jev with @zwrkmrn and Jimit - Team bonding, and the pickleball tournament that @jethroksy and Mingyi dominated in Huge thank you to everyone that planned our offsite – Nehil, Yu Zhou, Hala, Kiki AND all the engineers who humored me in making this music video :)
3
4
23
1,190
yuzhou retweeted
We're expanding our AI Security suite, powered by Behavioral AI, to secure AI across the enterprise. These new products extend Abnormal’s behavioral security approach to give enterprises visibility and governance over their AI, control over the AI their employees use, and protection against AI-driven attacks. Here’s what’s included: 🔹 AI Governance discovers and governs AI use across the business 🔹 AI Cloud Security stops AI-driven cloud breaches 🔹 AI Employee Guardrails guides how employees interact with AI tools 🔹 AI Agent Security monitors and secures AI agent activity 🔹 AI Security Workbench accelerates the SOC in investigating threats and activating new detections It's the same Behavioral Security Platform that already protects more than 5,000 customers and 30% of the Fortune 500, now to secure AI. Read more: abnormal.ai/blog/ai-security…
2
6
228
yuzhou retweeted
Today, @Abnormal is launching a new AI Security product suite to help customers govern AI, secure AI, and defend against rogue AI. This new suite is built on the same behavioral AI technology that 30% of the Fortune 500 use for email and identity security. Abnormal designs, trains, and deploys our own AI, and we've spent nearly a decade mastering how to understand the normal behavior of business, detect behavioral anomalies, and respond at machine speed.  We're extending our behavioral modeling to include non-human identities, applications, and cloud identities. This enables the same behavioral AI to now power 5 new products in our AI Security product family: 1) AI Governance discovers your AI, uncovers shadow AI, shows who is using what, and how much it costs 2) AI Cloud Security detects + contains AI cloud breaches with behavioral AI and honeypots 3) AI Employee Guardrails enables employees to use AI without leaking data or triggering unintended actions 4) AI Agent Security inventories your agents and ensures they behave as intended 5) AI Security Workbench lets you use AI to run investigations with Abnormal models and without the guardrails AI Governance is already GA and can be installed in one click from our app store. AI Cloud Security is available today for priority customers, and the other products are in private preview for design partners. Learn more on our website and talk to your customer rep to cut the waitlist! abnormal.ai/blog/ai-security…
4
6
17
1,064
this might be some of the best and real advice I’ve read in awhile regardless of what yo do, showing up and helping your team and people around you will have incredible compounding effects in your effectiveness on the job unless you’re a Jeff dean level engineer, show up, don’t be an ass hole, aim to collaborate and help people around you and life will be good
new post: the senior engineer death spiral sunilpai.dev/posts/the-senio… a friend just started a big job and asked for some advice. so I braindumped a monologue about a super common failure mode I see with engineers and posted it here, hope it helps whoever it can.
1
6
1,697
yuzhou retweeted
I posted a visual explanation of how the recent OpenAI breach to help the non security expert understand what happened, and how Behavioral AI can help with detect these type of incidents And on a lighter note, i had fun with web design evanreiser.com/blog/cybersec…
4
7
14
1,138
yuzhou retweeted
“A race to the bottom, spurred by commercial incentives, can make these risks more acute” …. says the company racing to go public?
We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so. Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training. You can read the full post here: darioamodei.com/post/we-must…
32
28
371
23,204
if ai takes over and we are actually living in a Dune simulation, what job are you interviewing for? 1. Bene Gesserit 2. Mentat 3. Spice dealer 4. Space navigator
2
147
yuzhou retweeted
Last week, @Abnormal announced AI Cloud Security, and I wanted to share our internal prototype about how we’re using Abnormal’s core behavioral AI detection and response technology to stop the next generation of AI attacks. AI Cloud Security is built on the same core architecture and technology that we use for our email and identity security products that protect ~30% of the Fortune 500 today: 1) Map all the human, non-human, and cloud identities 2) Build behavioral models to understand baseline / expected behavior 3) Detect behavioral anomalies 4) Respond autonomously at machine speed We’ve spent the last several years building the core technologies, and I’m excited to start sharing our new AI security products as we build them with this audience. These products will be available to customers this year, but in the meantime, we are working with select design partners to ensure their success in the largest, most sophisticated enterprise environments. We are learning and building every day, and I’m excited to share more as we go!
1
4
20
1,086
yuzhou retweeted
Replying to @AnthropicAI
As the CEO of one of the largest AI security companies here are my thoughts:
It took 3 hours and one token to fully compromise an enterprise cloud environment. Anthropic's report from today yet another wake-up call. AI-powered attacks are already here, you just haven't heard about them yet.
Article

The AI Cybersecurity Emergency Is Already Here

It took 3 hours and one token to fully compromise an enterprise cloud environment. Anthropic's report from today yet another wake-up call. AI-powered attacks are already here, you just haven't heard

8
28
11,153
yuzhou retweeted
It took 3 hours and one token to fully compromise an enterprise cloud environment. Anthropic's report from today yet another wake-up call. AI-powered attacks are already here, you just haven't heard about them yet.
Article

The AI Cybersecurity Emergency Is Already Here

It took 3 hours and one token to fully compromise an enterprise cloud environment. Anthropic's report from today yet another wake-up call. AI-powered attacks are already here, you just haven't heard

7
14
22
14,953
day 1 of our @Abnormal pm offsite :) so proud of this team
17
3,054
yuzhou retweeted
To fight bad AI, defenders need Behavioral AI. With @OpenAI, we’re continuing that fight, now to secure rogue AI. The recent Hugging Face incident was a wake-up call for cyber defenders. During an internal cybersecurity evaluation, AI agents identified paths beyond their intended environment and accessed production infrastructure belonging to a third-party organization. Today, we announced AI Cloud Security, extending our behavioral AI engine to the cloud to detect risky or malicious AI agent behavior inside customer environments, with OpenAI models supporting investigation and response. Announced alongside OpenAI's Cyber Summit as part of the Daybreak Defense Network, AI Cloud Security is in private preview for Abnormal customers and features real-time detection of AI-driven cloud breaches, autonomous AI response at machine speed, and AI-assisted investigation. Learn more in the blog from our Co-Founder @sanjays_tweets: abnormal.ai/blog/openai-rogu…
7
15
1,728
AI Phishing Coach from @Abnormal is getting it's biggest upgrade yet, including a Training Creator feature that lets security teams turn a plain-language prompt and a few images into a finished video training module. The product also now comes with several other key features that give security practitioners get real control over their program without giving up the automation Abnormal provides. We're investing heavily here, and there's a lot more coming.
1
9
1,328
Everyone has asking how you secure systems from rogue AI agents, but the Hugging Face breach is not a new attack class. The agent got in using valid credentials on real accounts with no signature or impersonation to catch. It was just a sequence of individually authorized actions by a trusted identity. That's simply the oldest hard problem in security, running at machine speed. This is the problem that @Abnormal has been spending the last few years researching on. In order to detect attacks originating from compromised accounts, we have learnt to stop asking "is this malicious?" and instead ask "is this account acting like itself?" Agents are just the newest identity on the network. Find out how we have been modeling this problem here.
3
6
565
yuzhou retweeted
AI Phishing Coach already trains employees on the real attacks Abnormal stops, and it's the reason hundreds of customers have adopted it this past year. Now it gets smarter. We rebuilt it to adapt to how each employee actually behaves: smarter simulations, real follow-up, new attack types. Read more on our blog: abnormal.ai/blog/ai-phishing…
1
9
350
yuzhou retweeted
AI is making it easier for attackers to operate at scale and giving defenders better ways to detect and stop them. Which side wins depends on how fast the security industry adapts. @Abnormal signed @OpenAI's call for collective action on cyber defense because no single company can solve this alone. We started Abnormal to defend organizations against attacks that exploit human behavior and trusted identities, and the letter argues for putting powerful defensive AI in the hands of every organization, especially the ones with the fewest resources. Software vulnerabilities and malware are still real threats, but the most costly attacks now target people through compromised identities, account takeovers, and social engineering. Insider threats and nation-state infiltration now run through text, voice, and video deepfakes. They wear legitimate identities and behave in slightly wrong ways, so they slip right past tools built to catch known bad software. Those attacks deserve the same urgency as the vulnerabilities dominating the headlines. Stronger defenses will require closer coordination between AI labs, security companies, and the organizations they protect. That's why we signed, and why we're working with OpenAI and other industry leaders to advance defensive AI. Bad AI will keep getting better. Good AI has to get better faster. abnormal.ai/blog/openai-cybe…
2
10
15
536
Customers at @Abnormal can now now train their own AI detection models to tailored their email environment to their needs, redefining what traditional detection engineering looks like in the era of AI!
Not every security decision is a behavioral one. Our new Control Center adds precise rules and custom AI models on top of Abnormal's behavioral AI. No detection engineering required. Read more: abnormal.ai/blog/control-cen…
2
8
1,650