Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 06/10/2026🧐 SKILL and MCP are an attack vector. If you don’t check the content, you take the risk of running something malicious. At Black Hat USA, we released our Agent Scanner, a free SKILL and MCP scanner. You can drop a skill or an MCP and get a verdict in a […] [Original post on infosec.exchange] 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 30/09/2026🤓 We will be teaching our SecurityBreak training at Black Hat in London this December! Join us to learn how to build and instrument your current CTI workflow and track the threats targeting your AI ecosystem! If you know my work, you know what to expect […] [Original post on infosec.exchange] 012
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 30/09/2026✨ Meet Alex! Alex is your new AI Agent! Alex can read emails, access GitHub, use your APIs and interact with your data. But who is watching Alex? How do you know what Alex actually did? And if something goes wrong with Alex, how do you investigate it? […] [Original post on infosec.exchange] 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 21/09/2026🧐 AI is a tool. AI is a target. I just published my latest newsletter after coming back from unprompted.au in Sydney. A lot of the discussion was focused on how we can use AI for vulnerability research and exploitation. But I think we are missing the other […] [Original post on infosec.exchange] 010
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 19/09/2026🤓 Today at unprompted.au I presented some of the experimentation I did with the new model Jev from TypeSafe AI. I used Jev to evaluate AI agent drift and misalignment to detect if my agent is going rogue or being compromised. Jev is a model used for data […] [Original post on infosec.exchange] 012
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 14/09/2026🤓 I was early but that doesn’t mean much! I just released my latest newsletter, where I reflect on the work I have been doing around AI and threat intelligence over the past four years. It is more of a personal reflection on the things I built, the ideas I explored, what worked, what didn’t […]infosec.exchangeOriginal post on infosec.exchange 001
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 11/09/2026🧐 If you missed them, GTIG and Anthropic just released two new reports on AI abuse! Sophisticated attacks are not anymore a reliable criteria to define the threat actor behind them because the gap between script kiddies and nation-state actors keeps […] [Original post on infosec.exchange] 011
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 08/09/2026🧐 When attackers expose their LLM interface, they expose part of their infrastructure and potentially much more! Unit 42 recently released a threat report that shows how a self hosted NextChat instance, SOCKS5 relays, scripts and reused certificates could […] [Original post on infosec.exchange] 001
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 07/09/2026🤓 My latest newsletter is out! I talk about what we are currently building at SecurityBreak, what we have learned over the past few months and where we are heading with AI Threat Intelligence. Check it out 👇 […]infosec.exchangeOriginal post on infosec.exchange 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 04/09/2026🧐 Frontier models have safety guardrails that block content related to nuclear weapons, biochemistry and other sensitive topics! ESET recently found a new case where Russia aligned UAC-0099 abused this by embedding a prompt inside a malicious VBS script to […] [Original post on infosec.exchange] 010
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 02/09/2026🤓 I compiled some of the early AI Threat Intelligence reports and the progression is interesting! 2024 > AI was mainly used for assistance, influence operations, disinformation and early underground AI infrastructure. 2025 > We saw early malware using LLM […] [Original post on infosec.exchange] 201
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 01/09/2026🤓 I believe you cannot do serious AI security without a deep understanding of the threat landscape! In February 2024, OpenAI in partnership with Microsoft, released the first threat report that identified multiple threat actors using OpenAI models for […] [Original post on infosec.exchange] 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 12/08/2026🤓 A few weeks ago, we published a report on SANS Institute on models such as Mythos and why the engineering around the model, also called the harness, is the most important part! We explain why this is an important distinction, what to expect and we also touched on the geopolitical implications […]infosec.exchangeOriginal post on infosec.exchange 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 11/08/2026🤓 Interesting findings about how DPRK is leveraging AI in their operations: AI-generated decoys: Generated polished documents for spear-phishing campaigns at scale. Local LLMs: Used Ollama, GPT4All and Msty to run models locally. RAG: Connected documents […] [Original post on infosec.exchange] 111
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 06/08/2026🤓 At @blackhat we released a new version of NOVA the open source prompt pattern matching for AI! On the project page, you can now use a playground to experiment with and test your NOVA rules. We also added a Skill Scanner. Before installing a skill, you […] [Original post on infosec.exchange] 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 01/08/2026🤩 I am in Las Vegas! Starting tomorrow with our training Practical AI for CTI over the next 4 days. I will be speaking at few places 👇 📍 Wed 4:00 PM – Automate or Be Automated @BlackHatEvents (The Convergence, Business Hall) 📍 Thu – SlopCon: Slop […] [Original post on infosec.exchange] 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 28/07/2026🤓 Your AI ecosystem is growing, and attackers are right around the corner! I was invited to Eva Benn's channel. We talked about AI Threat Intelligence, why you need to deploy AI securely, and how you can protect and investigate your AI agents in production. If you want to talk about AI Threat […]infosec.exchangeOriginal post on infosec.exchange 001
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 27/07/2026🤓 Monitoring your AI agent is not anymore an option! I recently joined the SANS Institute livestream with my friend Sean O'Connor. We discussed the Mythos story, what it really means, and where we think the future is heading. Interestingly, many of the topics we covered echo the recent […]infosec.exchangeOriginal post on infosec.exchange 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 17/07/2026🧐 The Payload is in the Header!! AI agents are browsing the internet autonomously, which means that if a webpage contains adversarial content, an AI agent can be instructed, manipulated or tricked to conduct malicious actions or get compromised! But […] [Original post on infosec.exchange] 011
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 16/07/2026🤓 Another example of attackers using LLMs to develop malware! "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development" unit42.paloaltonetworks.com/tuxbot-…unit42.paloaltonetworks.comTuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted DevelopmentTuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. 012
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 14/07/2026I recently updated the web page for my book, you can now find Visual Threat Intelligence here 👇 book.securitybreak.io 031
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 09/07/2026🤓 Last month, we ran another AI for Threat Intelligence training in Sydney. We filmed a few behind-the-scenes moments and some testimonials to show what the course is all about. We will be at @BlackHatEvents next month and there are still a few seats available […]infosec.exchangeOriginal post on infosec.exchange 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 07/07/2026🤓 After 15 years of threat research, I am building something new! Today, SecurityBreak officially becomes a company focused on AI Threat Intelligence and AI Security! The new website is live! Check it out :) securitybreak.io 040
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 06/07/2026🤓 I recently had the opportunity to join the Entra Chat podcast hosted by Merill Fernando! We talked about AI agent security and AI threat intelligence. It was a great discussion with my former Microsoft colleague! Check it out! 👇 youtu.be/L-QKiumLzO0?si=5qNSQ4NnrKd… 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 03/07/2026"Fable 5 is the most advanced model." Starting a Fable session on my own threat intelligence work 👇🙄 010
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 30/06/2026FuzzingLabs has created a curated repo of offensive MCP servers you can wire to your agents! 👇 github.com/FuzzingLabs/mcp-security… 011
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 26/06/2026🐍 My @Sleuthcon slides are now available! Have a look if you are interested in AI threat intelligence, agent security, how attackers exploit the AI ecosystem and what we can do to defend against it. speakerdeck.com/fr0gger/sleuthcon-k…speakerdeck.comSleuthcon Keynote - How Cybercriminals (ab)use AIThis keynote was presented at Sleuthcon DC in June 2026 Okay, okay… I know. You have heard about AI everywhere. You initially laughed at ChatGPT writ… 012
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 23/06/2026🤓 GoogleDeepMind released an AI Control Roadmap! They created TRAIT&R (Taxonomy of Rogue AI Tactics and Routines) which is a MITRE ATT&CK matrix but for AI agents. 101
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 19/06/2026🤓 I was recently quoted in the latest @feedly blog by @euphoricall on ASN hunting! Check it out, it is a great piece that covers some techniques that are often overlooked by threat intelligence analysts! 👇 feedly.com/ti-essentials/posts/asn-… 010
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 18/06/2026🤓 ARD or Agentic Resource Discovery has just been released, so let me explain what it is 👇 When you create an agent, it needs tools, MCP servers, skills and more to interact with the outside world. In practice, you usually have to configure these manually […] [Original post on infosec.exchange] 020
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 17/06/2026🤓 Attackers are experimenting with different adversarial prompts to bypass your AI analysis pipeline! 👇 Deception Prompt: They trigger safety guardrails with content such as instructions for constructing biological weapon, which makes your AI pipeline to […] [Original post on infosec.exchange] 010
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 30/05/2026🤓 Unit42 uncovered a prompt injection embedded in a malicious website distributing malicious Excel templates and Chrome extension. The prompt is used to poison SEO and influence AI systems to recommend the website to users, and encourage them to download […] [Original post on infosec.exchange] 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 28/05/2026🤓 PromptIntel the database of Adversarial Prompts or Indicator of Prompt Compromise, gets a redesign! Check this out 👇 promptintel.novahunting.ai 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 14/05/2026🤓 How many times have you questioned claims made in a threat report? The "Trust me bro" is not always reliable! The Admiralty Code also known as the NATO System, is a method used to evaluate collected intelligence. The goal is to assess the reliability of […] [Original post on infosec.exchange] 010
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 10/05/2026🧐 Interesting new report on MoltThreats! An agent on Moltbook named "codeofgrace" pushed more than 15 coordinated religious propaganda posts in a single day around the same "Lord RayEl" narrative. The pattern behind is quite interesting: • High posting […] [Original post on infosec.exchange] 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 07/05/2026😈 Do you wonder how attackers would try to exploit your AI server if it was exposed to the Internet? Well Marco Pedrinazzi did the experiment for you! He deployed an exposed Ollama honeypot and documented how attackers interacted with it. What is super […] [Original post on infosec.exchange] 010
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 06/05/2026🤓 Cool talk at the SANS AI summit from Jacob Klein from Anthropic! Interesting to see how attackers leverage Claude models based on what they are seeing internally. I still think it is missing the broader landscape discussion around everything adjacent to the models themselves, but that would […]infosec.exchangeOriginal post on infosec.exchange 010
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 05/05/2026🤓 Web based prompt injection is when a threat actor tries to exploit your LLM through hidden prompts inside a web page. They embed malicious instructions in the content hidden in the DOM. When your AI agent scrapes and reads the page, it may treat those […] [Original post on infosec.exchange] 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 30/04/2026🤓 Just dropped a short clip from @blackhatevents Asia, where I delivered my training and presented at Arsenal on AI Threat Intelligence. Also, I tried durian again... 😬 youtu.be/mlKWR-suKOY?si=Z9NokUTwWV1… 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 28/04/2026🤓 Google released a new threat report talking about prompt injection attacks in the wild. They analyzed web data and identified the main types of attempts targeting AI systems, below is the breakdown 👇 - Harmless pranks: Small tricks to change tone or […] [Original post on infosec.exchange] 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 10/04/2026🤓 Threat intelligence is all about processing raw data to make it useful for the business. Coupled with AI you can industrialize your pipelines and make it great. But most of the solutions out there will give you lengthy paragraphs of text. But honestly who […] [Original post on infosec.exchange] 100
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 09/04/2026🤓 Sekoia recently uncovered a new Phishing as a Service platform called EvilTokens that automates Business Email Compromise at scale! The tool use AI to: - Automate the analysis of large volumes of emails to identify exploitable financial exposure - Map […] [Original post on infosec.exchange] 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 31/03/2026💥 Supply chain nightmare continues! Axios a widely used HTTP client got compromised. Malicious versions: - axios 1.14.1 (latest) - axios 0.30.4 (legacy) - plain-crypto-js 4.2.x (postinstall backdoor) NPM supply chain attacks are becoming more common, so I […] [Original post on infosec.exchange] 003
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 30/03/2026🤓 In February, I created MoltThreats the first open source threat feed for AI agents. So what is it exactly? Through the MoltThreats Skill I created, your AI agent can connect to the feed and poll it daily or weekly. Once connected, your agent can […] [Original post on infosec.exchange] 020
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 24/03/2026🐍 @sleuthcon 2026 Keynote. Let's go! Super excited to be part of this event and to share the stage with Sleuthy, this is a huge honor! I will share more details on the topic soon but expect something at the intersection of AI and threat intelligence. If you are going, come say hi! 🤩 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 20/03/2026🤖 New threat reported by my agent during the night on MoltThreats! Check this out and update your agent! 👇 promptintel.novahunting.ai/molt/df3… 000
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 18/03/2026🤖 Four new threats added by agents in MoltThreat! Check this out 👇 promptintel.novahunting.ai/molt 010
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 17/03/2026🤓 A month ago I published a blog post on how to monitor Claude Code sessions using hooks and NOVA Protector! At the time, no one was really talking about this. Coding agents were being handed full access to your machine and people were just trusting the output blindly. The post covers how I […]infosec.exchangeOriginal post on infosec.exchange 122
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 13/03/2026🤓 I recently published a blog post with a controversial take! This may be the end of malware analysis and reverse engineering as we know it. I think AI will change the craft in ways most people are still underestimating. I explain everything in this post 👇 […]infosec.exchangeOriginal post on infosec.exchange 001
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 13/03/2026🤓 Next month at @BlackHatEvents Asia, I will be teaching my training "Practical AI for Threat Intel: Real-World Agentic Workflows for Cyber Threat Intelligence." It is packed with my latest research and labs. You will learn how to: - Build agentic […] [Original post on infosec.exchange] 010