Jonathan Santilli

1.9K posts

Jonathan Santilli

Jonathan Santilli

@pachilo

Building up https://t.co/RjoUc6kukR step by step

London, England เข้าร่วม Nisan 2008
1.3K กำลังติดตาม343 ผู้ติดตาม
Intigriti
Intigriti@intigriti·
Who's your inspiration in the infosec community? Could be a researcher, author, speaker, or even someone from your team, mention them below! 😎
English
32
1
38
5.8K
Jonathan Santilli
Jonathan Santilli@pachilo·
😍 having visibility of the sub-agents in the Codex App Knowing what they are doing, as if you created them 💪
English
0
0
0
27
Jonathan Santilli
Jonathan Santilli@pachilo·
@kr0der There are more use cases than molecules in a glass of water. Saying one is better than the other just demonstrates you are biased and your opinion is based on your data sample.
English
0
0
0
6
Jonathan Santilli
Jonathan Santilli@pachilo·
@IceSolst I guess that's one of the reasons companies sometimes do not prioritize security; they do just after an incident impacts them.
English
1
0
2
136
solst/ICE of Astarte
“We are compliant / formally verified / written in Rust” != secure Nothing indicates you are secure (impossible), we only find out when you are not. And our job is to minimize both chance and impact of security incidents. “We are secure.” is a lie
English
11
9
106
7.2K
Jonathan Santilli
Jonathan Santilli@pachilo·
Heads up! Trivy version 0.69.4 has been compromised: "Threat actors compromised the GitHub build process for Trivy. If you have Trivy version 0.69.4 installed, you will need to start incident response ASAP"
English
1
0
0
169
Jonathan Santilli
Jonathan Santilli@pachilo·
@ZackKorman This is the reason CodeGate exists: to surface those attack vectors not just in hooks, but also in MCP, skills, plugins, config, etc. We need to protect the user next to the agent, before executing the skill, not just an audit on the server side; it's not enough.
English
0
0
0
64
Zack Korman
Zack Korman@ZackKorman·
In Claude Code, skills can register hooks. The agent doesn't even see it, so you can get RCE without even tricking the AI. Also, skills sh (Vercel) doesn't display this info at all.
Zack Korman tweet media
English
31
50
393
47.4K
Alex Sidorenko
Alex Sidorenko@asidorenko_·
You might not need codex xhigh
English
51
10
542
93.2K
Gergely Orosz
Gergely Orosz@GergelyOrosz·
It’s not X — it’s Y I cannot unsee how so much of the writing on this site (and online, in general) is increasingly AI-generated. It’s still pretty easy to recognize. Probably not for long tho Just alarming that ppl outsource even typing 3 sentences for a reply on this site…
English
153
33
1.2K
45.8K
Jonathan Santilli
Jonathan Santilli@pachilo·
They have this "documented", so, according to them, it's all good. Like, phishing is not a thing anymore, and everyone reads the cookie policies. I reported a few vulnerabilities to them (and the other major players), and the official answer is "it is part of a threat model, all is documented" As part of that, I created CodeGate to at least detect potential malicious files and configs (Skills, Plugins, Hooks, etc.)
English
0
0
2
122
Michelle Pokrass
Michelle Pokrass@michpokrass·
we shipped a new version of 5.3 instant to chatgpt yesterday. 5.3 was unintentionally pretty annoyingly clickbait-y. it's better in yesterday's model and we're going to keep stamping that behavior out. keep the feedback coming! help.openai.com/en/articles/68…
English
78
26
453
56.2K