Cloud Security Geek ! | #CNCF Ambassador | Microsoft #MVP #Azure & #Security | #AI #CloudSecurity #Kubernetes #SecOps

Quebec, Canada
Maxime Coquerel retweeted
Cloudflare lance Quick Tunnels : une commande transforme votre localhost en URL publique chiffrée sur son edge. Pas de compte, pas de DNS, aucun port ouvert. Connexion sortante uniquement, TLS et filtrage DDoS inclus, tunnel éphémère qui meurt avec le process. ⬇️
6
16
191
14,863
Maxime Coquerel retweeted
给 Claude 注入特定的 SKILL.md,它就能从普通的聊天助理,变身精通 SQLi、EDR 绕过和漏洞挖掘的红队专家。 近期在 GitHub 斩获 6.2k Stars 的开源项目 claude-red,专门为 Claude 建立了一个“进攻性安全技能库”。它通过结构化的提示词文件,让 AI 掌握深度的渗透测试方法论。 核心特征: • 78 个独立技能,覆盖 23 个安全领域:包含 Web 应用渗透、Active Directory 滥用、无线安全、甚至底层的漏洞开发(ROP、堆栈破坏)和容器逃逸。 • 即插即用,按需加载:每个技能都是独立的 SKILL.md。可直接配合 Claude Code 命令行使用,或拖入 Claude 的 Project 中作为 System Prompt,不会浪费多余的上下文。 • 专业操作员视角:内容摒弃了通用科普,专注于具体攻击面的技术细节、特定工具链的使用、边缘用例和提权路径指引。 对于安全研究员、Bug Bounty 猎人或红队人员来说,这相当于给 AI 装备了细分领域专家的知识库,直接将其转化为实战分析辅助工具。 github.com/SnailSploit/claud…
5
51
301
18,566
Maxime Coquerel retweeted
Introducing ARES 🛡️⚔️ Open-source autonomous red team & security validation platform built with FastAPI + React. Features: • Autonomous Attack Graph (DAG) • MITRE ATT&CK Mapping • Scope Firewall & Instant Reports GitHub: github.com/Mafifrizi/ARES #RedTeam #CyberSecurity
3
210
1,166
45,632
Maxime Coquerel retweeted
Google Brain founder Andrew Ng: "Prompting will be dead in 6 months Agent harnesses built with loops and graphs will replace it" Agent → Harness → Feedback → Loops → Graphs → Self-Improving Systems In this 1-hour Stanford lecture, he explains what the best engineers are building instead and how you can start today Prompt → Run → Verify → Improve The first 20 minutes teach what most $1,500 courses try to sell you For free Bookmark and watch it today Then read the guide below on building an agent harness that improves itself
33
188
895
128,130
Maxime Coquerel retweeted
Train a 9M parameter language model from scratch in five minutes. github.com/arman-bd/guppylm
6
95
696
30,255
Maxime Coquerel retweeted
awesome-ai-security-tools: A curated list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity — autotriage, agent security, AI/ML supply chain, pentest agents, AI SAST, LLM-driven fuzzing, threat intelligence, SOC/SIEM triage, reverse engineering, LLM red-teaming, and more. github.com/scadastrangelove/…
3
23
147
6,590
Maxime Coquerel retweeted
Train your own LLM from scratch! A step-by-step repo that walks you through building and training a transformer model from scratch using PyTorch. From downloading training data all the way to generating text. The architecture is built from the ground up following the original "Attention is All You Need" paper. MLP, single head attention, multi-head attention, transformer blocks, and the full transformer model - all coded and explained with detailed diagrams at each step. Training data comes from The Pile - a diverse 825GB open-source dataset covering books, articles, code, websites, and more. The repo includes scripts to download it, preprocess and tokenize it using tiktoken, store it in HDF5 format, and feed it into training batches. You can train a 13M parameter model on a single Colab T4 GPU. At 13M parameters the model starts generating proper grammar and coherent short sentences. For billion-parameter training you need at least an A100 or RTX 4090. The repo includes a full GPU compatibility table so you know exactly what's possible on your hardware. Includes a complete SFT and RLHF guide as a separate notebook for taking your trained model further. Key capabilities: • End-to-end pipeline: data download → preprocessing → training → text generation • Full transformer implementation from scratch with PyTorch • Trains models from 13M to 2B+ parameters on a single GPU • Training data from The Pile (825GB, 22 diverse datasets) • Tokenization via tiktoken (r50k_base) • SFT and RLHF guide included 100% open source. I've shared the link in the replies!
24
411
2,622
84,461
Maxime Coquerel retweeted
Cloudflare a publié une skill très complète d'audits de sécurité pour agents en 6 phases. C'est celle qui a servi de base à leur système interne de détection de vulnérabilités. L'agent qui vérifie une faille n'est jamais celui qui l'a trouvée. ⬇️
1
6
71
4,285
Maxime Coquerel retweeted
We escaped Docker's hypervisor with three lines of bash. CVE-2026-77179: A container gets complete read and write access to the host filesystem. When you mount a folder into a container, Docker's VMM uses virtio-fs, and the file server runs on the host. Because of a TOCTOU bug, if a container opens a file, deletes it while holding its file handle open, and replaces the parent folder with a symlink, the kernel will follow the symlink to anywhere on the host. Full technical breakdown: accomplish.ai/blog/escaping-…
Community note
This affects Docker Sandboxes on macOS and Docker Desktop only if the new Docker VMM (beta, not default) is enabled; it is a virtio-fs shared workspace symlink/TOCTOU issue, not a general container or hypervisor escape. docs.docker.com/security/secur… cve.org/CVERecord?id=C… docs.docker.com/ai/sandboxes/r…
25
157
1,282
99,402
Maxime Coquerel retweeted
Intel SGX total hack paper is in progress and I don't think Intel will like it ))
10
70
505
35,783
Maxime Coquerel retweeted
Keycloak is vulnerable to a critical unauthenticated account takeover (CVE-2026-18963) I reproduced the bug locally; interesting one (power of LLM, I think) github.com/keycloak/keycloak…
16
149
1,035
130,496
Ready for #KubeCon Japan Day 1! 🤩🇯🇵
1
4
181
#KubeCon Japan Day 0 ! 🤩
1
1
11
1,100
Japan, here I come! 🇯🇵 Next stop: #KubeCon + CloudNativeCon Japan. ✈️☸️
3
126
Ten years ago, I received my first Microsoft MVP award. Today, I’m incredibly honored to receive it for the 10th consecutive year. 🙏 Thank you to everyone who has been part of this journey. Here’s to another year of learning, sharing, and giving back! 🚀 #MVPBuzz #MicrosoftMVP
3
26
1,117
Maxime Coquerel retweeted
Head of Engineering Shopify: "AI writes the code, AI reviews the code. Your job is just to write the loops around it." 26 minutes on how AI changed the way 3,000 engineers work inside a single company. Ignoring it while everyone else uses AI to do more is the fastest way to fall behind. Watch it, then read the step by step guide on loops below.
92
277
2,632
717,674
#AWS Community Day East Canada! 🇨🇦
70