Dylan
1.1K posts

Dylan
@InsecureNature
Security researcher, public speaker and founder. Forbes 30 Under 30 Truffle Security @trufflesec https://t.co/vxEH7Cftbg Prev @Netflix





We scanned HuggingFace. 👇👇👇 This was the largest secret scan of AI training data ever: 7.6 PB. 🔑🔑🔑🔑🔑🔑🔑🔑🔑 🔍Found 221,303 live unique credentials in 6,003 public datasets ☁️Cloud keys, live DBs, API keys worth ~$920K/yr. ⚠️Training data has no undo: one key hit 1,131 datasets 🔗 trufflesecurity.com/blog/scanning-…

Pumped to share we just open sourced Minimal. I've talked a lot about sandboxes here, shared some early workflows, and talked to a bunch of you about what we've been building this past year. I've said it in many ways, but bluntly, the primitives we use to run agents today are broken from a security standpoint.

the day you open source a repo you've been cooking on for a while is always so much fun. I can't wait to share more this afternoon!



🚨 New research: a cache flaw in RubyGems.org leaked freshly minted API keys to other users 🔑gzip responses to an authenticated API key request got cached at the Fastly edge, then served to the next user, no auth needed ✅Now fully fixed 🔗 trufflesecurity.com/blog/rubygems-…




Introducing Claude Tag, a new way for teams to work with Claude. In Slack, Claude joins as a team member with access to the channels and tools you choose. Tag Claude in and delegate tasks to it while you focus on other work.





🔓 CISA admin GitHub App key still LIVE 2 days after Krebs reported it. And there was more: 🔑 Org-wide GitHub admin access 📦 6 JFrog tokens + master keys 🔐 Guessable DB passwords 👉trufflesecurity.com/blog/cisa-leak…





