Heather Adkins - Ꜻ - Spes consilium non est

6.5K posts

Heather Adkins - Ꜻ - Spes consilium non est

Heather Adkins - Ꜻ - Spes consilium non est

@argvee

VP Security @Google, Co-Author "Building Secure and Reliable Systems" @r00t0wns, Medieval Historian

California Katılım Temmuz 2008
1.2K Takip Edilen14.9K Takipçiler
Heather Adkins - Ꜻ - Spes consilium non est retweetledi
Bloomberg
Bloomberg@business·
China is restricting overseas travel for top AI professionals in private firms such as Alibaba and DeepSeek, suggesting an escalation in measures intended to safeguard its technology and catch up to the US in a pivotal sphere. Government agencies have begun imposing restrictions on individuals involved in advanced AI work and considered strategically important to the country, people familiar with the matter said. bloom.bg/4uy8OPC 📷: Qilai Shen/Bloomberg
Bloomberg tweet media
English
51
173
443
186.9K
Heather Adkins - Ꜻ - Spes consilium non est retweetledi
Kim Zetter
Kim Zetter@KimZetter·
Don't often see this kind of analysis of Middle East infrastructure: Over 3 months this year, 1,350 hacker command-and-control servers found being hosted across 98 regionaly providers. Saudi Telecom Company hosts 981 , or 72.4%, of them. hunt.io/blog/middle-ea…
English
4
26
65
10.1K
Heather Adkins - Ꜻ - Spes consilium non est retweetledi
Socket
Socket@SocketSecurity·
UPDATE: So far we've identified 639 compromised npm package versions across 323 unique packages in tonight’s Mini Shai-Hulud wave. That includes 558 versions across 279 unique @​antv packages. Most were detected within ~6 minutes of publication. socket.dev/blog/antv-pack…
English
38
169
1K
1M
Heather Adkins - Ꜻ - Spes consilium non est retweetledi
Sundar Pichai
Sundar Pichai@sundarpichai·
Gemini Omni doesn't just build scenes that look real, it reasons about what should happen next. It combines an intuitive understanding of physics with Gemini's knowledge of history, science, and cultural context. Rolling out today starting with video outputs to Google AI Plus, Pro and Ultra subscribers globally through the @Geminiapp + Google Flow, and @YouTube Shorts this week.
English
383
756
7.7K
738.9K
Heather Adkins - Ꜻ - Spes consilium non est retweetledi
Eric Geller
Eric Geller@ericgeller·
Move over, Mythos: Open-source AI systems have been finding serious bugs in critical software for months. I wrote about how a recent DARPA challenge sparked a sea change in AI's bug-finding power, and how it could especially help critical infrastructure. cybersecuritydive.com/news/ai-vulner…
Eric Geller tweet mediaEric Geller tweet media
English
2
18
45
8.9K
Heather Adkins - Ꜻ - Spes consilium non est
Nice write up from the Cloudflare team, but the post here is misleading. Patch faster is not the wrong answer, because most teams are patching on the order of weeks or months. You must patch faster than that right now. But I will agree that 2 hours is infeasible beyond the occasional emergency CVSS 10. And defense in depth is a part of the arsenal, now the whole story.
Cloudflare@Cloudflare

Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. cfl.re/49BRUqW

English
4
5
56
12.5K
Heather Adkins - Ꜻ - Spes consilium non est retweetledi
Volcaholic 🌋
Volcaholic 🌋@volcaholic1·
🚨 The WHO has now declared the Ebola outbreak in the Democratic Republic of the Congo and Uganda a global public health emergency. So far: • 246 suspected cases • 80 deaths • Fatality rate in past Bundibugyo Ebola outbreaks: 30–50% • Health workers already among the dead • Cases spreading across multiple health zones • Imported cases confirmed in Uganda This isn’t the more well-known Ebola strain either. It’s Bundibugyo virus, and there is currently NO licensed vaccine or specific treatment for it. Most suspected cases are adults aged 20–39, with women making up over 60% of cases, highlighting how fast it spreads through households and caregiving. Several contacts reportedly became sick and died before they could even be isolated. The outbreak is centred in a major mining and migration hub near the borders of Uganda and South Sudan, raising fears of wider regional spread.
English
20
150
586
20.5K
Heather Adkins - Ꜻ - Spes consilium non est retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 Pwn2Own Berlin 2026 just hit a wall. For the first time in 19-years, ZDI rejected dozens of working zero-day RCE submissions because organizers ran out of contest slots. Rejected hackers are now going public with PoC demos and direct vendor disclosures, breaking Pwn2Own's usual secrecy. ▪️ AI surfaces a massive wave of 0-day RCEs. ▪️ Submissions overwhelm ZDI past max capacity. ▪️ Slots run out. Researchers with working chains get rejected. ▪️ "Revenge disclosures" begin. ← we are here. Confirmed casualties so far: ▪️ @xchglabs : 86 vulnerabilities prepared (PyTorch, NVIDIA, Linux KVM, Oracle, Docker, Ollama, Chroma, LiteLLM, llama.cpp). All rejected. Now reporting directly to vendors with writeups dropping as patches land. ▪️ @ggwhyp : full-chain Firefox RCE on Windows. Rejected. Publicly demoed (HTML page → cmd.exe → calc.exe). Responsibly disclosed to Mozilla. ▪️ @yunsu_dev : working RCE chain, rejected. Submitting elsewhere. ▪️ @ryotkak : tried to register for 3+ weeks. ZDI confirmed "at maximum capacity, can't add extra contest days." Considered canceling flight and hotel. ▪️ @anzuukino2802 : Claude Code RCE PoC. Rejected. ▪️ @desckimh : 0-day RCEs in Ollama and LM Studio. Rejected. Reported impact: a community-estimated 150+ researchers tried to register. Accepted contestants are now being warned about collisions. Rejected vulnerabilities going to bug bounty programs may trigger pre-event patches that invalidate the work of those who got in. ZDI has not publicly addressed the capacity issue. The event still runs May 14-16 in Berlin.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
31
382
1.5K
411.5K
Heather Adkins - Ꜻ - Spes consilium non est
I'd prefer to say every vulnerability is knowable. This isn't the same thing as one person or method being able to find every vulnerability (interesting thoughts on that from Lukasz here). My point being: stop tying yourself into knots figuring out if that CVSS 5.4 is exploitable in your WIDGETFOO environment, and also findable by someone else. Just go fix it.
Lukasz Olejnik@lukOlejnik

AI will not solve cybersecurity! “With the recent news of folks finding vulnerabilities left and right using LLMs, some folks hope that we'd be able to find every single vulnerability. Today, I hope to shatter that idea” github.com/yo-yo-yo-jbo/v…

English
1
5
28
9.2K
Heather Adkins - Ꜻ - Spes consilium non est
Another sign that over time AI will sift out the shallow-medium depth bugs, and devs will just fix them as a matter of course. This will shift the VRP market substantially. If you're a bug bounty platform or a VRP researcher, refocus your time and energy. If you're a defender, deploy patches or deprecate, even those lower-severity LPE bugs.
IRIS C2@C2IRIS

There are so many Linux and Windows LPEs that we literally have to turn away researchers with perfectly good exploits, because we just don’t need another one lying around on the shelf. If you must work Windows/Linux, it makes sense to work on RCE primitives instead of LPE

English
3
6
24
7.8K
Heather Adkins - Ꜻ - Spes consilium non est
Process isolation on Windows is sorely needed so I'm really delighted to see Chrome 138 start shipping this. Try it out (you'll need to switch it manually for testing)! Protect those 🍪🍪🍪!
Will Harris@parityzero

Try out the early alpha of Process Isolation in Chrome 138. chrome://flags/#enable-process-isolation-ui then chrome://settings/system for the switch. Read known issues issues.chromium.org/issues?q=hotli… and report bugs! Especially interested in App-Compat bugs.

English
2
5
31
8.6K
Alex
Alex@alexanderjaeger·
@SeanWrightSec "Hey @argvee we did block all binaries and webpages related to AI across the company and for all Chrome users, enjoy great weekend." (this is meant to be fun)
English
1
0
1
134
Sean Wright
Sean Wright@SeanWrightSec·
Scare your CISO in 1 sentence including the word AI…
English
28
1
17
9.1K
Heather Adkins - Ꜻ - Spes consilium non est
Excited to see how this will evolve the thinking on cyber safety review boards. It's good timing as we enter into the era of machine-speed hacking driven by the emergency of powerful AI models. 👀🎉🚀
The Record From Recorded Future News@TheRecord_Media

Australia's new cyber incident review board will be modeled on the Cyber Safety Review Board established by the Biden administration in 2022, though with a narrower membership drawn largely from critical infrastructure industries therecord.media/australia-laun…

English
1
5
15
4.3K
Heather Adkins - Ꜻ - Spes consilium non est retweetledi
Kevin Kwok
Kevin Kwok@kevinakwok·
When AI hits security there will be signs
Kevin Kwok tweet media
English
78
304
2.8K
301.5K