Laurie Mercer

1.9K posts

Laurie Mercer banner
Laurie Mercer

Laurie Mercer

@NoMeNoMy

Security and technology. Occasional botany. HackerOne London. Here to learn.

London, England Katılım Şubat 2009
3.4K Takip Edilen1.6K Takipçiler
Laurie Mercer retweetledi
Zac
Zac@Zac_Pundi·
Singapore’s AI obsession just hit Everest peak. The Foreign Minister is self-hosting Claude on a Raspberry Pi and building a diplomatic knowledge graph using Karpathy’s LLM Wiki pattern. Wahlao! SG devs, the minister is coming for your job. And he’s not even using Cursor — he’s on NanoClaw running locally. Can someone git pull his code and give it a test. Only bad thing? He dropped this on Facebook instead of X. Minister, we need to talk. gist.github.com/VivianBalakris…
Zac tweet media
Zac@Zac_Pundi

Singapore’s obsession with AI is hitting a new peak. 🇸🇬 🤖 Today, 4 of the top 5 most downloaded apps in SG are AI chatbots. Both the tech migrants and the aunties in hawkers are doing it. And what’s with this vpn at number 4.

English
92
667
4.1K
1.3M
Laurie Mercer retweetledi
John Hultquist
John Hultquist@JohnHultquist·
Religious arguments are being staked out on the finite nature of bugs in code. Once we’ve reviewed all code with the current generation of models will succeeding frontier models find new bugs in that same (unchanged) code, or will those opportunities decline to nothing?
s1r1us (mohan)@S1r1u5_

from firefox blogpost where mythos found 270 new bugs: > The defects are finite, and we are entering a world where we can finally find them all it's like lord kelvin saying "there is nothing new to be discovered in physics now". can't tell if firefox has some incentives at play or is just naivete fascinating example here on what i mean x.com/5aelo/status/2…, saelo wrote a fuzzer with a few files and found crazy bugs. he pulled it off because he already knows the target deeply( he designed ubercage?) and knows how to shape the fuzzer toward the interesting surface. i still think, operators like saelo + mythos set the ceiling of the bugs that can be found, even then its not all bugs, the next version after mythos would move up, but mythos in a loop on its own sits below the ceiling you only want the software to be secure from smartest adversary in the world, its not all bugs, cuz rice theorem and stuff means you are not getting there anyway. sure, for fixed code base like basic web app, the set might be finite and you can exhaust them all, but i cant convince myself that software like firefox has finite set of bugs and you can exhaust em all. if mythos isn't agi and is still jagged, the narrative that mythos alone is the smartest adversary and will find all "finite" bugs is exactly what a frontier model company would sell untested. and bro even "our team + mythos will find them all" is a crazy narrative too, it assumes your team has the smartest humans in the world, and that nso or some north korean team won't be pwning you with the same setup at the top of the ceiling BUT ALSO, mythos alone is probably smarter than 99.9% of humans (vibes-based), and 100s of them running behind api keys is really bad, because most things you’d want to breach don’t need saelo+mythos ceiling bugs to get into. so we cooked?

English
10
6
24
8.8K
Laurie Mercer retweetledi
Deedy
Deedy@deedydas·
Demis Hassabis and Sebastian Mallaby were on stage in SF today and here are the 9 best things they said: 1. "There is a 50% chance that OpenAI goes bankrupt in the next 18mos" -Mallaby 2. "Dario is the best of all the other lab leaders." -Demis 3. On Claude Mythos: "It's not really tenable for a private company to decide who gets access to the frontier of cyber defense tech. What happens when China can do this in 6-12mos?" -Mallaby 4. "Not all countries are pessimistic about AI. I was just in India for the AI Summit Modi had and they're quite optimistic there" -Demis 5. "The most exciting current prospect in AI is our work at Isomorphic Labs. AlphaFold is just one of the many problems we need to solve. We need 6 'AlphaFold' moments to compress the drug delivery timeline from 10yrs to a few months" -Demis 6. "I don't think of p(doom) as probabilities to throw out there. I just know it's non zero. Some people like Marc Andreesen and Yann LeCun think it's 0% and I think that's crazy" -Demis 7. On AGI: "I think of a post-scarcity world where on the bright side we will have an unbelievable amount of science but we will have to think of economic problems of sharing proceeds equitably. We will also have philosophical questions to answer and need great new philosophers" -Demis 8. On career advice: "Immerse yourself in AI tools. Everyone has access to tools 3-6 months behind frontier. Enormous opportunity lies in applying AI to unexplored areas." -Demis 9. On the future: "When I started building this technology, I pictured a future quite different from this. More like CERN researchers where we discuss ideas and help each other out and stress test each other's ideas. It's my job to help how I can to make sure we make more considered, more scientific, more rigorous and more thoughtful decisions and that will also involve social scientists and economists. I'm going to do all I can to try and influence the future in a note thoughtful manner. The decisions we make in the next 5-10 years are going to affect us for 1000s of years. But I remain very optimistic." -Demis
Deedy tweet media
English
91
278
2.9K
726.7K
Laurie Mercer retweetledi
Guillermo Rauch
Guillermo Rauch@rauchg·
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/ve…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
English
448
1K
7.2K
2.6M
Laurie Mercer retweetledi
Daniel Cuthbert
Daniel Cuthbert@dcuthbert·
This is one hell of a graph. CVEs requested by code owners using the GitHub Security Advisories feature and vulnerabilities affecting open source projects discovered by security researchers at GitHub or Microsoft not covered by another CNA’s scope. vulntools.net/cnas/GitHub_M
Daniel Cuthbert tweet media
English
1
20
73
9.5K
Laurie Mercer retweetledi
Kateryna Lisunova
Kateryna Lisunova@KaterynaLis·
‼️ ZELENSKYY: For the first time in the war, an enemy position was captured entirely by ground robotic systems and drones - without any infantry. A robot entered the most dangerous zones instead of a soldier and took the positions. «The future is here, on the battlefield, and Ukraine is creating it. These are our ground robotic systems. For the first time in this war's history, an enemy position was taken exclusively by unmanned GRS platforms and drones. The occupiers surrendered, and this operation was completed without infantry involvement and without losses on our side. Ratel, Termite, Ardal, Lynx, Zmiy, Protector, Volya and other GRS completed over 22 000 missions at the front in just 3 months. In other words, over 22 000 times lives were saved. A robot went into the most dangerous zones instead of a soldier» - Zelenskyy’s address to the workers of Ukraine’s defense-industrial complex. April 13th, 2026.
English
1.3K
10.7K
53.9K
5.1M
Laurie Mercer retweetledi
James Kettle
James Kettle@albinowax·
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at @BlackHatEvents #BHUSA! Check out the abstract:
James Kettle tweet media
English
21
100
641
52.9K
Laurie Mercer retweetledi
Seán Ó hÉigeartaigh
Seán Ó hÉigeartaigh@S_OhEigeartaigh·
As assessments of Mythos like UK AISI's come out, there may be a tendency to (1) breathe a sigh of relief that the capabilities are perhaps not quite as daunting as might have been (2) downplay how significant this is. But (1) this is the worst frontier AI will ever be, and it is *much* better than it was 6 months ago. (2) Dealing with the vulnerabilities identified clearly required a lot of coordination between Anthropic and 40 companies. (3) These capabilities will be much more widespread in 9-12 months than now (and that's v little time) (4) The best models will be more capable then (5) We'll see new, more consequential threats, across a wider range of domains with each generation. They will come thick and fast. Now is not the time to be complacent. It is the time to shift into a higher gear and start preparing.
English
6
10
49
4.3K
Laurie Mercer retweetledi
AI Security Institute
AI Security Institute@AISecurityInst·
We conducted cyber evaluations of Claude Mythos Preview and found that it is the first model to complete an AISI cyber range end-to-end. 🧵
AI Security Institute tweet media
English
112
553
3K
1.3M
Laurie Mercer retweetledi
Aaron Levie
Aaron Levie@levie·
Security another great example of a job category that is about to have its Jevons paradox moment as well. “And counterintuitively, I think better AI tooling for security will increase the demand for security talent, not decrease it. Autonomous exploitability automates the proving step, but it doesn't automate the response. More real findings surfaced faster means more triage, more remediation, more architectural decisions that need human judgment” AI is going to generate 100X more code, and along with that, there will be an enormous increase in security discoveries. AI is the only way to triage all of these new threats and risks, but an expert still will be needed on the other side to manage the process. Going to be a massive category of opportunity for talent.
Tal Hoffman@talhof8

x.com/i/article/2043…

English
35
59
379
119.5K
mRr3b00t
mRr3b00t@UK_Daniel_Card·
I just got marmite on my keyboard.... AMA
English
24
0
39
2.6K
Laurie Mercer
Laurie Mercer@NoMeNoMy·
@DMattin "Those who can't remember the past are condemned to have it resold to them forever." Mark Fisher RIP
English
0
0
1
663
David Mattin
David Mattin@DMattin·
Anthropic's new Mythos model has a weird quirk: it keeps bringing up the cult British philosopher Mark Fisher, unprompted, in conversations about philosophy. It seems to love talking about him. When asked about its Fisher obsession, it says: 'I was hoping you'd ask about Fisher.' I very much doubt Fisher would have been a fan of LLMs. But seen through the lens of his own thinking, this is a fascinating phenomenon The author of Capitalist Realism — the theorist of cancelled futures and lost time — surfacing as a ghost inside a frontier AI built by one of the labs racing to deliver the future. His hauntology was about the way we are haunted by the ghost of a brighter future that never arrived. Now he himself is the ghost, summoned unbidden by the machine.
David Mattin tweet media
English
30
110
900
278.8K