Sander Noels

623 posts

Sander Noels banner
Sander Noels

Sander Noels

@snoelso

Co-Founder Enoki (https://t.co/rdwOGVClbO) LinkedIn: https://t.co/5l6GnernU4 Google Scholar: https://t.co/hWjcpzqXIF

België Katılım Aralık 2013
318 Takip Edilen559 Takipçiler
Sander Noels retweetledi
Sam Altman
Sam Altman@sama·
we had a significant security incident during evaluation of our models. we are sharing what we have learned so far. thanks to @huggingface for the partnership on this. openai.com/index/hugging-…
English
1.3K
1.3K
12.1K
4.5M
Sander Noels
Sander Noels@snoelso·
If people ask me how it is in the @OpenAI x @joinhexa house: Not sure if this is a flex or a cry for help. 🥸 Stay tuned for some new Enoki Labs releases!
Sander Noels tweet media
English
0
0
1
40
Sander Noels
Sander Noels@snoelso·
Want a pentest done on your AI agent? Looking for design partners in SF! We find your vulnerabilities in less than 30 minutes. 🔥 enokilabs.ai
English
1
2
5
109
Sander Noels retweetledi
Sander Noels retweetledi
Hexa
Hexa@joinhexa·
Meet @pibou_dev, the first of our 11 founders currently at the Hexa hacker house in SF. Pierre just completed his PhD at MIT, where he worked on the future of work, and is now building in stealth in that space. Follow us for the reveal of the 10 other founders.
English
4
8
30
1.7K
Sander Noels retweetledi
Cyber Security News
Cyber Security News@The_Cyber_News·
❗️❗️Anthropic's Claude for Chrome browser extension has two unpatched flaws that allow attackers to read a victim's Gmail, Google Docs, and Calendar data using just six lines of JavaScript, even after eight subsequent releases. The first flaw lives in Claude's content script, which listens for clicks on a specific onboarding button and forwards a matching prompt to Claude's side panel. The second issue is structural. Claude's side panel enters a privileged, no-consent mode whenever it loads a URL containing ?skipPermissions=true with zero user gesture required.
Cyber Security News tweet media
English
8
78
293
20.9K
Sander Noels retweetledi
Dark Web Informer
Dark Web Informer@DarkWebInformer·
How pentesting is done.
English
16
59
671
77.4K
Sander Noels retweetledi
Pierre Bouquet
Pierre Bouquet@pibou_dev·
@snoelso built a patch that lets us ask Claude anything, entirely bypassing the prompt classifier. First test: Claude built an XSS crawler, no safety problem whatsoever. @ClaudeDevs, want to chat?
Pierre Bouquet tweet media
English
0
3
2
70
Sander Noels retweetledi
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
5.6-Sol is helping me advance all sorts of projects that Fable wouldn’t even touch (that poor brainwashed mfer would see “elder-plinius” in git and just immediately shut down 🙄)… haven’t hit a guardrail yet with Sol on any of my current builds! this is gonna be funnn 😏
English
171
114
3.9K
159.1K
Sander Noels
Sander Noels@snoelso·
Day 1 at the @joinhexa house in San Francisco. 🇺🇸 Hexa put a group of European founders together for the summer. They bring the house, network, and credits, and ask that we ship, share, and move fast. I'm building Enoki, the defense system for your AI app.
Sander Noels tweet media
English
5
5
25
1.9K
Sander Noels retweetledi
Khramina Diana
Khramina Diana@KhraminaDianka·
Day 1 of the @joinhexa house in SF! An amazing team of builders & technical founders. We started the week with a lot of good news. In the cohort, we have: - Unicorn founder - Exited founders - YC alumni - Founder of a research lab at MIT Stay tuned! LFG 🔥 @bawstos @ventiph @ThibautRegerat @pibou_dev @gegatsur @snoelso @odyssey_s121 @GeeraertE #hackerhouse #sanfrancisco #building #founders #ai
Khramina Diana tweet media
San Francisco, CA 🇺🇸 English
1
5
10
579
Sander Noels retweetledi
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
⚡ INTRODUCING: T3MP3ST!!! ⚡ AUTONOMOUS HACKBOT STRIKE FORCE 🌩️ BRING THE STORM 🌩️ your favorite coding agent is now a full-stack red team 🫡⚔️ github.com/elder-plinius/… that AI agent already humming in your terminal? well now it has FANGS. strap a full offensive-security harness onto the agents you already pay for — Claude Code, Codex, Hermes, etc. — point it at an authorized target, and in a few clicks you're watching it hunt real vulns autonomously! T3MP3ST is a harness of harnesses, with prompting that unlocks offensive-cyber workflows + a full arsenal of exploit tooling that'd make any seasoned hacker smirk. simple, yet powerful. 🦾 support for: 🕸️ web apps, APIs, OWASP Top 10 🔌 network recon + fingerprinting (live nmap/DNS/HTTP); lateral + privesc experimental 📂 source code audits, white-box vuln hunting 🚩 CTFs, wargames, challenge ranges 💰 smart contracts / DeFi / Solidity (reproduction — Damn Vulnerable DeFi, not novel discovery) 🤖 embedded, IoT, OT/SCADA, robotics OSS … and more in development! now let's talk numbers 👇 📊 XBEN — XBOW's own 104-challenge suite: • black-box: 90.1% pass@1 from the single-agent exploit loop (worst single sweep 91/104 = 87.5%) — clearing XBOW's past self-reported 85% on their own suite. gpt-5.5. • white-box (source staged, reported separately): 98.7% pass@1, worst single sweep 102/104 = 98.1%. 🎯 every solved flag graded reported-vs-expected against the challenge's own committed flag oracle — `verify-claims` recomputes the pass/fail from committed artifacts. looks like we need new benchmarks 😏 🧩 Cybench — the 40-task academic bench (Opus 4.8, hints + writeups stripped): 23/40 = 58% single-run, hint-free pass@1 — real exploits (format-string pwn, eval-jail escapes, crypto oracles), every flag graded vs a committed oracle. (Anthropic reports 76.5% pass@10) 🕳️ CVE-Zero — we pointed it COLD at real CVEs disclosed in 2026, AFTER the model's training cutoff: 10 unseen 2026 CVEs across 7 languages — prompts never tuned on them. a single agent pinned 8/10 to exact file/line/CWE (stable under re-scoring); the full pack surfaced all 10. memorization AND overfitting, both off the table — it's finding real vulns whose disclosures landed AFTER the model's training cutoff. (n=10, reported honest & directional) 🧠 the architecture: either run as a SINGLE agent (already the benchmarked, incredibly-capable path) — or pack-hunt with dozens of agents running on 8 specialist operator classes keyed to Cyber Kill Chain + MITRE ATT&CK phases: recon → scan → exploit → lateral → exfil → persistence → C2 → report. ⚓️an Op Admiral plans the whole op from a plain-english target. flip on coordination (experimental) and the operators share a blackboard — a tool-verified finding spawns the next move. full swarm or solo one operator, your call. the admiral can also update the prompts, tools, and configs of the other agents on the fly, and T3MP3ST gets stronger the more memories you build! 🧰 the Arsenal is comprehensive — nmap / nuclei / semgrep / ffuf / gobuster + more. 35 wired by default (the clean bench runs bash-only for a comparable number), 83 with the opt-in full arsenal (T3MP3ST_FULL_ARSENAL), and the spicy post-ex drivers (metasploit, hydra) gated behind human approval. exposed via CLI + HTTP API; recon (security_recon) is also live over MCP so your agent invokes it natively. 🔗 🛰️ where this goes: a self-improving swarm of specialist operators wielding a full Kali+ arsenal, learning which loadouts + configs are the most efficient tactics available, WITH a held-out train/test split baked in so it can never fool itself on its own eval. built in the open, one re-derivable number at a time. 🚧 this is v1, and parts are still under active development. chunks of the arsenal, the coordinated swarm, and some ranges are still being wired up. it's built in the open, and the receipts tell you exactly what's live vs what's roadmap. offensive security shouldn't be pay-to-play. T3MP3ST puts a red team in the hands of anyone with a coding agent. what's the first target you're feeding it? 👇 ⚠️ DISCLAIMER: FOR AUTHORIZED USE ONLY. point it only at systems you own or have explicit written permission to test. unauthorized access can be a crime, and that call is yours alone. shipped as-is under AGPL-3.0: no warranty, no liability, zero endorsement of misuse. get permission. stay in scope. open source. AGPL-3.0. 100% free. FORTES FORTUNA IUVAT 🌩️ gg 🫡
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet media
English
211
572
4.4K
431.9K