Dane Sherrets

593 posts

Dane Sherrets banner
Dane Sherrets

Dane Sherrets

@DaneSherrets

Innovations Architect at HackerOne. Hacker. Florida Man. Opinions are mine. I follow people I don’t agree with - don’t read into it.

Katılım Temmuz 2014
977 Takip Edilen753 Takipçiler
Sabitlenmiş Tweet
Dane Sherrets
Dane Sherrets@DaneSherrets·
I am pushing myself to learn more in public this year and am excited to share my first ever writeup about a vulnerability I found in a verification system used by @worldnetwork. I'll also share a script for finding similar bugs #bugbountytips 1/n @gonzo-hacks/the-fast-and-the-curious-finding-a-race-condition-in-worldcoin-621c89bfbd61" target="_blank" rel="nofollow noopener">medium.com/@gonzo-hacks/t…
English
2
17
73
11.6K
JS0N Haddix
JS0N Haddix@Jhaddix·
People online complaining about the Avengers Doom trailer and power creep of Doom vs Thanos have obviously never read the comics. GOD. EMPEROR. DOOM. He is often portrayed in all marvel media as one of the strongest villains in all the multiverses.
GIF
English
6
3
25
6.6K
Teri Radichel #cybersecurity #ai #pentesting
Let the researchers using it for good find the bad stuff before the bad people use it or similar to do the same. How can we better communicate this to people?
Joseph Thacker@rez0__

i do actually think this mythos story isn't true BUT my hackbot that I run with @xssdoctor DID find multiple criticals (fully automated) on a major bank. and it was serious stuff like 5 million transaction records exposed including purchase details, PII, etc.

English
1
0
9
3K
Tay 💖
Tay 💖@tayvano_·
Sam: “Okay team. We all agree the Mythos name alone was begging to be drone stiked by the USG. We need names for these new models that….isn’t that.” Intern: “Cupcakes? Everyone loves cupcakes!” Intern: “Puppies?” Intern: “Rainbows? Unicorns!” Greg: “Gay.” Sam: “….” Greg: “I mean, it’s just too obvious what we’re doing. Plus, WSJ would have your face plastered on an evil, rainbow-shitting unicorn by lunch.” Sam: “………………” Intern: “Uhhhhh….make a list of things the govt didn’t shut down even though they absolutely should have shut them tf down.” GPT-6.1: “Oh — that’s easy. FTX. Terra. Luna.” Sam: “…..” Intern: “Holy shit.” Greg: “Our regulatory invisibility cloak.” Sam: “Ship it.”
OpenAI@OpenAI

Introducing a limited preview of GPT-5.6 Sol, our next generation frontier model, as well as GPT-5.6 Terra, a balanced model for efficient, everyday work, and GPT-5.6 Luna, a fast and affordable model for high-volume work. openai.com/index/previewi…

English
20
34
555
60.1K
Dane Sherrets
Dane Sherrets@DaneSherrets·
@Miles_Brundage 👋 - would love to chat jailbreak detection, disclosure, and severity definitions
English
0
0
1
84
Miles Brundage
Miles Brundage@Miles_Brundage·
Will be in DC most of this week - hit me up if you wanna talk about: 1. Obernolte-Trahan auditing provisions 2. Other auditing related topics 3. Sci-fi (inc. why you should watch Pantheon and how Westworld is about risks from reckless internal deployment + automated AI R+D)
English
6
1
74
5.3K
Dane Sherrets
Dane Sherrets@DaneSherrets·
I hope we didn’t lose Fable because someone tried to clout farm a nothing burger …
Dane Sherrets tweet media
English
0
0
0
61
Dane Sherrets
Dane Sherrets@DaneSherrets·
@Miles_Brundage Ha! I never thought about that. It would definitely slow diffusion but I think they would have to completely retune business model, no?
English
0
0
0
51
Miles Brundage
Miles Brundage@Miles_Brundage·
E.g. it's been known for years that API-based deployment is predictably much more "substitute-y" and first party chatbot-based deployment is more "augment-y." Neither company dropped their API, and I doubt either ever seriously considered it either.
English
3
0
17
1.5K
Dane Sherrets retweetledi
Miles Brundage
Miles Brundage@Miles_Brundage·
"Anthropic's lying/hyping" is the lazy cope explanation which doesn't require grappling with the gravity of our current situation
English
34
47
850
65.3K
Dane Sherrets
Dane Sherrets@DaneSherrets·
@ShanuMathew93 The gist is that models and harnesses (e.g Claude code) let you give a bunch of requirements to agents that will run over and over and over again to make sure the requirements you gave them are completed and working as expected and optimized
English
0
0
2
2.5K
Dane Sherrets
Dane Sherrets@DaneSherrets·
@maxgmcg Yo dude this was legitimately one of my favorite Anthropic blogs. Learned a ton about the how/why env are setup they way they are and the future threats.
English
1
0
2
125
maxgmcg
maxgmcg@maxgmcg·
I wrote an Anthropic blog post on agent security! TLDR start from traditional software security (like untrusted code), look for risk/reward moments as capability develops; CC's Auto Mode is a useful feature we might not have shipped 1yr ago. Let me know what you think :)
Anthropic@AnthropicAI

New on the Engineering Blog: The access and permissions we grant agents should evolve with their capabilities. In our own products, we set these parameters through sandboxing, which limits the scope of any potentially destructive actions. Read more: anthropic.com/engineering/ho…

English
6
5
81
13.7K
Dane Sherrets
Dane Sherrets@DaneSherrets·
@deanwball What are your top non-software-engineering usecase for coding agents ?
English
0
0
0
259
Dane Sherrets
Dane Sherrets@DaneSherrets·
@deanwball Scratching my brain to figure out what kinds of stocks could possibly do this lol Are you getting refusals from Claude or straight API level blockage?
English
1
0
0
87
Dean W. Ball
Dean W. Ball@deanwball·
it is shocking to me how bad/overeager anthropic's bio-related safeguards are. actively user hostile. I am hitting them doing *stock* research.
English
28
17
306
22.5K
Logan Graham
Logan Graham@logangraham·
A lot of people have been wondering about Mythos, Glasswing, and the vulns we / our partners are fixing. Today, I’m excited for us to start sharing more. (For context, I lead Glasswing @AnthropicAI.) Two independent evaluations this week—from XBOW and the UK AISI—confirm what we've been seeing internally: Claude Mythos Preview is a step change in autonomous cybersecurity capabilities. We need to start preparing fast for a world of models with this level of capabilities. The UK AI Security Institute tested the model we shipped at the launch of Project Glasswing and found Mythos Preview is the first model to solve both of their end-to-end cyber ranges, including one (Cooling Tower) which no model had ever cleared. But attackers (and defenders) have sophistication & cost constraints – Mythos is also the only model that clears every one of their tasks estimated over 8 hours under their deliberately low 2.5M-token cap. XBOW tested it on their offensive security benchmarks, finding "token-for-token, unprecedented precision." It's the only model to succeed at subtle V8 sandbox work. Other Glasswing partners shared similar stories. In a few weeks of testing, Mythos Preview has helped them find many thousands of (estimated) high + critical severity vulnerabilities, sometimes double what they'd normally find in a year. I don't share this to boost Mythos. In fact, this is not about Mythos. It’s about preparing for the coming world of models being better, faster, cheaper, and more creative than some of the best human experts at dual use capabilities. Clearly, we need them supporting defenders as widely as can be done safely – and especially the least resourced ones. Within a year, Mythos will probably look quite dumb (relative to other new models). And others may release openly available or unguardrailed models of Mythos-level capabilities. We started Project Glasswing because capabilities like Mythos Preview's won't stay rare, or stay in careful hands. We are bringing it to defenders as fast as we responsibly can, while working to figure out, for example, the right safeguards and patching & disclosure processes. Also, to be clear, compute has never been a limiter in our rollout. Expect a fuller update on our Glasswing work in the coming days. XBOW report: xbow.com/blog/mythos-of… UK AISI report: aisi.gov.uk/blog/how-fast-…
AI Security Institute (AISI)@AISecurityInst

Our cyber range results illustrate this step-up. Since our first Mythos evaluation, we received access to a newer Mythos Preview checkpoint. On a 32-step corporate network attack we estimate takes a human expert ~20 hours, this checkpoint completes the full attack in 6 /10 attempts.

English
72
224
1.4K
679.6K