Mike Leffer

951 posts

Mike Leffer banner
Mike Leffer

Mike Leffer

@mikeleffer

President @cantinasecurity | Investor @ Riptide Ventures

Baltimore, MD Katılım Ocak 2019
323 Takip Edilen1.1K Takipçiler
Mike Leffer retweetledi
Cantina 🪐
Cantina 🪐@cantinasecurity·
Threat feeds dump 1000s of incidents on security teams every day. Most go unread, so we had to act. Introducing ahackaday.news: your free daily security digest that ranks the day for you, with live social signal on every brief.
English
6
7
23
1.4K
Mike Leffer
Mike Leffer@mikeleffer·
A healthcare CISO this week told me he'd already built a lightweight version of our product on Claude. Called ours a sophisticated version of what he'd prototyped. The strongest buyers in any category are the ones who already tried to build it themselves.
English
0
0
0
41
Mike Leffer
Mike Leffer@mikeleffer·
14 deals closed. Most operators count closes. The real signal is how many got their date pushed a fourth time. Pipelines that never push are fiction. Ones that always push stopped being forecasts. Where does yours sit?
English
0
0
1
71
Mike Leffer
Mike Leffer@mikeleffer·
This is the agentic AI security gap nobody is pricing in. Coding agents have production credentials and runtime authority but the controls around them are still policy docs and prompt rules. Runtime enforcement on what agents can actually execute is the missing layer. Rough timeline you wrote up, glad Railway got the data back.
English
0
0
1
73
Mike Leffer
Mike Leffer@mikeleffer·
@AnthropicAI can someone please respond to my BAA request submitted via sales form for our org. If you don't we'll be going with @OpenAI for our use case.
English
0
0
2
58
Mike Leffer
Mike Leffer@mikeleffer·
Woke up to an MSA countersigned overnight. Months in the making. Six hours later a $52K payment bounced back and sent finance scrambling. The wins and the fires come hand in hand.
English
0
0
0
109
Mike Leffer retweetledi
Hari
Hari@hrkrshnn·
We're looking to hire a Staff Security Product Engineer. You'll be working on frontier security products: Clarion (an autonomous security operations platform) and Apex (an autonomous bug hunter). Link below:
Cantina 🪐@cantinasecurity

We're hiring a Staff Security Product Engineer. What we're looking for: - Security engineering, AppSec, detection, or incident response background - Ships code (TypeScript / Node.js) - Reasons through ambiguity and surfaces risks early Apply: jobs.ashbyhq.com/cantina.securi…

English
1
2
56
16.5K
Mike Leffer
Mike Leffer@mikeleffer·
The best diligence on whether your category is real isn't VC interest. It's a prospect on a sales call saying "tell me when you raise, I want in." A buyer asking for exposure beyond a purchase order is telling you something investors can't see yet.
English
0
0
0
67
Mike Leffer
Mike Leffer@mikeleffer·
@liran_tal Earned credit. Your earlier CVEs basically mapped the playbook for this class of issue. Eleven CVEs across major MCP clients all tracing to the same architectural assumption is the part defenders should sit with. That pattern does not get patched at the implementation layer.
English
1
0
0
37
Liran Tal
Liran Tal@liran_tal·
oh hah, the RCE security vulnerability article for Anthropic MCP SDK from thehackernews (thehackernews.com/2026/04/anthro…) drops a mention to one of my earlier CVEs what a fun random moment :D
Liran Tal tweet media
English
2
0
1
398
Mike Leffer
Mike Leffer@mikeleffer·
@byteakp @OpenHandsAI "Works as intended" is the signal the protocol was designed for a trust model that doesn't match production. Defenders can't wait for spec rewrites. Runtime visibility on what MCP servers actually do is the only control scaling faster than the vuln count.
English
1
0
1
29
Aman Pandey
Aman Pandey@ixchio·
Anthropic's MCP has a systemic RCE vulnerability 150M downloads 200K servers "works as intended" per Anthropic. I literally just patched a CVE in @OpenHandsAI one of the affected projects we are so cooked if engineers don't start treating agent security seriously
English
2
0
4
234
Mike Leffer
Mike Leffer@mikeleffer·
Got an inbound this week from a security exec at a Fortune 100 brand. No warm intro. Just booked through my scheduler. 18 months of posts and the win isn't a viral moment. It's one decision-maker reading the right line on the right day.
Mike Leffer tweet media
English
0
0
3
89
Mike Leffer
Mike Leffer@mikeleffer·
60-day free trial goes out with every design partner we sign. The math that makes it work: even if none convert, the product feedback is worth more than what 60 days of usage costs us. When they do convert, it's the easiest sales cycle we run all year.
English
0
0
1
150
Mike Leffer
Mike Leffer@mikeleffer·
@wallstengine The harder question is whether a one-shot frontier model risk assessment is rigorous enough for regulated environments. Most teams I talk to want continuous evidence collection, not a scorecard from last quarter.
English
0
0
0
22
Wall St Engine
Wall St Engine@wallstengine·
$IBM unveiled new cybersecurity tools aimed at “agentic” AI attacks, including a frontier model risk assessment and a new Autonomous Security service built to automate vulnerability response at machine speed.
English
3
10
49
9.9K
Mike Leffer
Mike Leffer@mikeleffer·
The real AI win this year has been dismissal, not just detection. A triage pipeline that drops noise before a human sees it beats any assistant doing the same work faster. Fewer eyeballs on things that didn't deserve attention.
Mike Leffer tweet media
English
0
0
0
78
Mike Leffer
Mike Leffer@mikeleffer·
Every morning I read an AI briefing pulling yesterday's Slack, emails, meeting notes, and calendar. 8 minutes to read. 2 hours to reconstruct by hand. Starting every day with context already loaded is its own kind of compounding advantage.
Mike Leffer tweet media
English
0
0
0
64
Mike Leffer
Mike Leffer@mikeleffer·
@albinowax @BlackHatEvents The novel-research bar is the one everyone handwaves past. If your AI is finding CVEs that humans didn't already queue up, that is the real test. Looking forward to the methodology.
English
0
0
1
195
James Kettle
James Kettle@albinowax·
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at @BlackHatEvents #BHUSA! Check out the abstract:
James Kettle tweet media
English
21
100
639
52.8K
Mike Leffer
Mike Leffer@mikeleffer·
3:31 AM DM from a teammate last night: "adding you to the call tomorrow at noon." 8 hours later I'm walking into a first meeting with an enterprise buyer I didn't know existed yesterday. That's what building through a pivot looks like when it's working. You show up and trust the team.
English
0
0
1
131