Gal Diskin [email protected]

1K posts

Gal Diskin d1sk1n@infosec.exchange banner
Gal Diskin d1sk1n@infosec.exchange

@gal_diskin

CTO & Cofounder @Authomize Formerly: CTO & VP @PaloAltoNtwks/Cyvera/First Group SW security lead @Intel Cyber/Network Science/AI&ML/QC/FinTech

drifting in space on a rock Beigetreten Mart 2011
198 Folgt1.5K Follower
Gal Diskin d1sk1n@infosec.exchange
@BrianEMcGrath @alex_prompter TBH if you're implementing any form of RAG in prod nobody uses pure vector retrieval. These "scientists" just found out what everyone doing it already solved - either use search tools (like grep) or use hybrid approaches breaking up the vector RAG into smaller repos or a combo
English
0
0
1
463
Alex Prompter
Alex Prompter@alex_prompter·
🚨 RAG is broken and nobody's talking about it. Stanford just exposed the fatal flaw killing every "AI that reads your docs" product. It's called "Semantic Collapse", and it happens the moment your knowledge base hits critical mass. Here's the brutal math (and why your RAG system is already dying):
Alex Prompter tweet media
English
366
684
4.9K
1M
Gal Diskin d1sk1n@infosec.exchange
The fix isn’t to tell devs “be careful.” The fix is: don’t give raw keys at all. Instead → issue ephemeral session keys + script snippets → secret goes to memory only → wiped after use.
English
1
0
0
451
Gal Diskin d1sk1n@infosec.exchange
AI coding agents are everywhere. Which also means your secrets (API keys, tokens) are ending up in the wrong places. 🧵 (blog link and details in thread)
English
1
1
1
502
Gal Diskin d1sk1n@infosec.exchange
Where? - Chat logs (the agent “saw” the key) - Terminal history - Local files Attackers are already scanning for exactly this.
English
1
0
0
354
Gal Diskin d1sk1n@infosec.exchange
it seems @Google has an error page for the error page. 1. They've earned my utmost respect as a CTO! 2. Since I won, where's my prize? (please help RT this Q to Google)
Gal Diskin d1sk1n@infosec.exchange tweet media
English
0
0
0
422
Gal Diskin d1sk1n@infosec.exchange
(4/5) Big thanks to: Jenny Paryanti for leading the work on this report Justin Ordman and Frances Fenemore for helping make this report a reality @ArtGilliland, Phil Calvin and Jon Kuhn for believing in the Labs vision and providing the budget and environment to support it
English
1
0
0
243
vx-underground
vx-underground@vxunderground·
The developer of Lockbit ransomware (and a core member) sure lived a beautiful and cozy life. He seems so happy and relaxed knowing the people using his weapon were ransoming childrens hospitals and critical infrastructure. The United States government will be very nice to him when he's extradited from Israel (they won't be nice at all, they're going to make his life an inescapable hell).
Dmitry Bestuzhev@dimitribest

#Lockbit Rostislav Panev #osint #ransomware

English
37
77
1K
372.2K
Gal Diskin [email protected] retweetet
Hamel Husain
Hamel Husain@HamelHusain·
LLM bullshit knife, to cut through bs RAG -> Provide relevant context Agentic -> Function calls that work CoT -> Prompt model to think/plan FewShot -> Add examples PromptEng -> Someone w/good written comm skills. Prompt Optimizer -> For loop to find best examples.
English
96
527
3.3K
290.1K
Gal Diskin d1sk1n@infosec.exchange
@DebugPrivilege Securing and attacking identity systems. Happy to collaborate if you want to develop one, I've been thinking about writing something for a while
English
0
0
0
134