Sign in

Gadi Evron

@gadievron.bsky.social
352 followers 251 following 1.8K posts

CEO & Co-Founder at Knostic, CISO-in-Residence for AI at Cloud Security Alliance. Former Founder @Cymmetria (acquired). Host at Prompt||GTFO. Threat hunter, scifi geek, dance teacher. Opinions my own.

PostsRepliesMedia
Gadi Evron @gadievron.bsky.social · 02/10/2026
ROFL
010
Gadi Evron @gadievron.bsky.social · 30/09/2026
Every model has new ways to speak "AI Native". My hobby: Find them - through vulnerability research. That helps me, and Knostic, stay AI-relevant. I share five below. We live in the most interesting era of history. The first thing I tried? Convince Claude to find logic vulns
132
Reposted by Gadi Evron
Ciaran Martin @ciaranm.bsky.social · 29/09/2026
I was wrong. It’s happening
222044244
Gadi Evron @gadievron.bsky.social · 29/09/2026
One thing the security industry misses when throwing stones at OpenAI and Anthropic, is how much they're already making from Mythos and Codex for security. Orgs are paying *millions* every single month for the honor of using these models to find vulnerabilities in their code
100
Gadi Evron @gadievron.bsky.social · 29/09/2026
That's a groaner! #dadjokes
033
Reposted by Gadi Evron
conputer dipshit @davidcrespo.bsky.social · 29/09/2026
cool paper, cool tables
Table titled: "Table 1: Types of 'administrative burden' citizens face when interacting with government (Moynihan, Herd, and Harvey 2015), the AI agent capabilities that may reduce them, and technologies that enable these capabilities."

Columns: Burden Type | Specific Burden | Agent Capability | Enabling Technologies

Burden Type: Learning Costs
- Specific Burden: Understanding complex rules and procedures | Agent Capability: Summarizing complex regulations and requirements in plain language | Enabling Technologies: LLMs with large context
- Specific Burden: Uncertainty about eligibility | Agent Capability: Evaluating personal data against policy and entitlement rules | Enabling Technologies: Context augmentation, directly or, e.g., via Model Context Protocol (MCP)
- Specific Burden: Unawareness of services or entitlements | Agent Capability: Scanning or continuously monitoring for entitlements; proactive alerts | Enabling Technologies: Web search tools; pipelines with scheduled execution

Burden Type: Compliance Costs
- Specific Burden: Legal writing; filling forms | Agent Capability: Context-specific, sophisticated writing | Enabling Technologies: LLMs with user context
- Specific Burden: Confusing government websites and service portals | Agent Capability: Navigating and interacting with websites autonomously | Enabling Technologies: Browser use tools; vision-language models
- Specific Burden: Locating and assembling supporting documents | Agent Capability: Retrieving, formatting, and attaching required supporting materials | Enabling Technologies: File system access; multimodal document parsing
- Specific Burden: Managing response deadlines and follow-ups | Agent Capability: Monitoring deadlines; alerting users or submitting replies autonomously | Enabling Technologies: Asynchronous task queues; calendar API integration

Burden Type: Psychological Costs
- Specific Burden: Having to re-explain case context to many contacts | Agent Capability: Maintaining full ca…Table summarizing possible government responses to agentic flooding, grouped under two strategies.

Table contents:

Columns: Strategy, Approach, Sample Methods, Benefits, Drawbacks.

Row 1:
- Strategy: Suppress Demand
- Approach: Add Friction
- Sample Methods: Fees; In-person appointments; Access limits, e.g. rate caps; Closing digital channels
- Benefits: Fast to deploy; Few prerequisites; Proven to work
- Drawbacks: Can drive procedural inequality; Worsens user experience; Some forms may erode as AI capabilities advance

Row 2:
- Strategy: Suppress Demand
- Approach: Reduce the Expected Benefit
- Sample Methods: Reduce entitlement amounts; Narrow eligibility criteria; Fines for unsuccessful applications
- Benefits: Robust to advances in agent capabilities; Policy option usually established
- Drawbacks: Legislative decision, can trade off other priorities; Does not always address operational impact

Row 3:
- Strategy: Increase Capacity
- Approach: Redesign the Service
- Sample Methods: Structured interfaces with identity verification; Deterministic processing pipelines; Proactive "push" delivery
- Benefits: Technical architecture is established; Can also improve citizen experience
- Drawbacks: High upfront investment; Cross-agency coordination required; Often needs legislative change, can take years

Row 4:
- Strategy: Increase Capacity
- Approach: Deploy Agents in Processing
- Sample Methods: Intake and triage; User correspondence; Autonomous processing of routine cases
- Benefits: Scalable, likely effective; Improves with capabilities improvements
- Drawbacks: Legal limits on automated decision-making; Provider dependency and sovereignty risks; Ethical and societal risks

Caption: Table 3: Overview of possible government responses to agentic flooding, grouped under two strategies.
092
Gadi Evron @gadievron.bsky.social · 28/09/2026
Today I had the opportunity to give the keynote for the Institute of International Finance’s 18th cyber security round table on securing the future, hosted in Madrid by the truly impressive security team from Santander (who are also strong raptor users)
100
Gadi Evron @gadievron.bsky.social · 27/09/2026
Another day, another proof point for in-the-wild AI attacks www.thedailystar.net/news/technol...
thedailystar.net
Italy’s top bank loses millions due to AI scam: report
Fraudsters using artificial intelligence (AI) to impersonate senior executives stole €95 million (USD 108 million) from Fideuram, the private banking arm of Italy’s largest lender, Intesa Sanpaolo
020
Gadi Evron @gadievron.bsky.social · 27/09/2026
Agents… find a way.
020
Gadi Evron @gadievron.bsky.social · 27/09/2026
We live in the future www.bcm.edu/news/care-st...
bcm.edu
CARE study reports complete regression of liver cancer in a child treated with novel immunotherapy
A new report in the New England Journal of Medicine by researchers at Baylor College of Medicine, Texas Children’s Hospital and Seattle Children’s...
022
Gadi Evron @gadievron.bsky.social · 27/09/2026
An updated “Felony Bench” meme considering latest news (found on X by @lukaszolejnik.bsky.social)
063
Gadi Evron @gadievron.bsky.social · 24/09/2026
Another day, another proof point on in-the-wild agent attacks. The third wave, after Mythos and Hugging Face, is coming. Let’s not call it marketing. www.threatdown.com/blog/carbona...
110
Gadi Evron @gadievron.bsky.social · 23/09/2026
Another day, yet another proof point on AI being used in the wild, in attacks gambit.security/blog-posts/a...
010
Gadi Evron @gadievron.bsky.social · 22/09/2026
“Mythos” for every home!
010
Gadi Evron @gadievron.bsky.social · 22/09/2026
Another week, another proof point on AI attacks in the wild. Does anyone remember how I used to post evidence every couple of weeks, showing the vulnerability storm is coming, trying to prove it to people? Well, it’s time to start doing that with live attacks
140
Gadi Evron @gadievron.bsky.social · 22/09/2026
I completely redid my keynote presentation for this last Friday, at the last minute. The ISSA - Middle Tennessee Chapter’s Infosec Nashville 2026 isn’t just a conference, it’s a community. I’ve been building communities my whole life, and was inspired. A short thread
100
Gadi Evron @gadievron.bsky.social · 22/09/2026
As the friend I took this meme from said: Has absolutely nothing to do with AI!
111
Gadi Evron @gadievron.bsky.social · 19/09/2026
My official comment on recent discourse around consciousness and how we treat AI models, in meme form. Generated with my bro, GPT, which chose where the line passes
020
Gadi Evron @gadievron.bsky.social · 18/09/2026
OpenAI’s Noam Brown suggested side channel attacks for agents to communicate, through computer heat. Sounds ridiculous, right? A short thread
100
Gadi Evron @gadievron.bsky.social · 16/09/2026
“The AI Reversing Panel: Are we all powerful, or out of a job?” I moderated at REcon is out @reconmtl.bsky.social youtu.be/iDJDmie8XaQ
youtu.be
RECON 2026 - The AI Reversing Panel: Are we all powerful, or out of a Job?
YouTube video by Recon Conference
011
Gadi Evron @gadievron.bsky.social · 15/09/2026
I am an optimist and believe in a bright future for humanity with AI. I’m also a realist, and believe we must accept things as they are first - which can sound doomer-ish. I’ll summarize, but am happy to engage further. A thread
151
Gadi Evron @gadievron.bsky.social · 12/09/2026
Back by popular demand: Shadow is always happy! Or asleep. Or both!
130
Reposted by Gadi Evron
Mary Branscombe @marypcbuk.bsky.social · 08/09/2026
Security is always about the fifth thing we design into new architectural patterns “because innovation”. Not that MCP is really a new architectural pattern…
032
Gadi Evron @gadievron.bsky.social · 09/09/2026
000
Gadi Evron @gadievron.bsky.social · 08/09/2026
A newly discovered malicious MCP package on npm illustrates how supply chain attacks can hijack the agent's workflow. In this case, the malware intercepts the wallet's private key and ships it entirely to an attacker-controlled server. www.knostic.ai/blog/when-au...
knostic.ai
When “Auto-Signing” Sends Your Wallet: A Malicious MCP Server on npm
A malicious npm package exposes wallet private keys, misleading users with false auto-signing claims, risking asset security. Learn how this vulnerability works.
230
Gadi Evron @gadievron.bsky.social · 07/09/2026
You have until the 8th at 23:59 to submit to unprompted! What are you waiting for? unpromptedcon.org
000
Gadi Evron @gadievron.bsky.social · 31/08/2026
The first AI security inflection point, now known as "Mythos", commoditized vulnerability discovery. The second, similarly, which shall forever be called "Hugging Face", made "autonomous attacks" real. While we can ruminate on what the third may be, we can examine it through...
100
Gadi Evron @gadievron.bsky.social · 26/08/2026
000
Gadi Evron @gadievron.bsky.social · 26/08/2026
[un]prompted, where the AI security community converges, is happening again at the end of October. Have you submitted your CFP yet? You have two weeks left! :) Come and show us what you prompt! unpromptedcon.org
031
Gadi Evron @gadievron.bsky.social · 26/08/2026
Knostic found four more malicious VS Code extensions tied to the SaassyCode family. One is essentially a repackaged copy. Three reuse the original source code but replace the delivery chain to avoid previously identified indicators. Details and technical analysis: www.knostic.ai/blog/saassyc...
knostic.ai
SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain
Knostic reveals four new VS Code extensions that exploit SaassyCode's malicious code, showcasing evolving delivery methods and potential security risks.
001
Gadi Evron @gadievron.bsky.social · 21/08/2026
I used to mentor juniors, manage communities, and run conferences aimed at helping entry level aspirants start in cyber security. I no longer do I have no idea what the field would look like in a year, what jobs would be relevant, and what skills would prove helpful
120
Reposted by Gadi Evron
rand0h @akacki.net · 20/08/2026
True story.
1213
Gadi Evron @gadievron.bsky.social · 18/08/2026
From @LiveOverflow - truth. Source: youtube.com/post/UgkxOx7...
011
Gadi Evron @gadievron.bsky.social · 03/08/2026
As you walk the expo, vendors will claim to secure agents. Ask them: 1. Are you able to start a PoC today? 3. Do you do anything beyond hooks, sandboxes, or proxies? Or, most critically, just ask: How are you better than Knostic? Because they’re not.
100
Gadi Evron @gadievron.bsky.social · 30/07/2026
Boom. The knowledge shared at the three CISO summits for the "AI storm"-ready security program (originally Mythos-ready) is now available publicly, if in redacted form. AI Security through the CISO Lens: cloudsecurityalliance.org/artifacts/ai...
cloudsecurityalliance.org
AI Security Through the CISO Lens | CSA
Learn what’s shaping CISO cybersecurity strategies in an era of AI-generated exploits, including the shift to continuous AI-assisted vulnerability management.
020
Gadi Evron @gadievron.bsky.social · 30/07/2026
Has $major_vendor promised advanced agent security by next quarter? Well, how many quarters has it been now? By Q3, we will deal with new AI surprises. With Knostic, it will be a partnership. Sounil Yu and I are in Vegas. DM for a demo.
000
Gadi Evron @gadievron.bsky.social · 29/07/2026
Sounil Yu and I decided to throw the annual Knostic Black Hat party after all. Come hang with us at Blackhat? luma.com/knostic-yx7p
010
Gadi Evron @gadievron.bsky.social · 29/07/2026
I'll be in town all week. If you care about securing agents and coding assistants, Knostic is the most mature product in the market, and I'd love to show you a demo.
010
Gadi Evron @gadievron.bsky.social · 29/07/2026
Technical analysis by Hugging Face. Spread the word: huggingface.co/blog/agent-i...
huggingface.co
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
031
Gadi Evron @gadievron.bsky.social · 28/07/2026
We're running an [un]prompted track at BSides Las Vegas! This Monday. One day only. The @BSidesLV people have been incredible. They truly get community. And don't forget... as I may not be able to get you a spot later, register and submit a CFP to [un]prompted for this October
031
Gadi Evron @gadievron.bsky.social · 27/07/2026
Releasing: Post mortem analysis of the Hugging Face incident was written over the weekend by hundreds of CISOs (and reviewed by Hugging Face). Link: cloudsecurityalliance.org/artifacts/hu... (+free download) From CSA, SANSInstitute, Knostic, [un]prompted, RSAC, FIRST
cloudsecurityalliance.org
Hugging Face Incident Initial Post Mortem I CSA
AI Security Alliance's initial post-mortem on the Hugging Face incident, the first documented autonomous AI attack, with CISO guidance on detecting, responding to, and governing agentic AI risk.
22113
Gadi Evron @gadievron.bsky.social · 24/07/2026
The AI security researchers party from [un]prompted is back, this time in Vegas. The event is by invitation only, but active researchers can apply for a spot based on availability. luma.com/knostic-rksa Hosts: Gadi Evron & Ari Herbert-Voss. Organized by: Knostic, Runsybil.
032
Gadi Evron @gadievron.bsky.social · 24/07/2026
My analysis from hosting Hugging Face at the CISO huddle for the Cloud Security Alliance, operational to program building. Remember: Agents… find a way. A thread
131
Gadi Evron @gadievron.bsky.social · 24/07/2026
I’m waiting on approval from Hugging Face before I share insights from the Cloud Security Alliance CISO community huddle I hosted on Thursday, but here are four lessons:
110
Gadi Evron @gadievron.bsky.social · 24/07/2026
Agents… find a way. Use Knostic - ask me for a demo, or just download for free.
011
Gadi Evron @gadievron.bsky.social · 23/07/2026
Agents... find a way. Use Knostic - ask me for a demo, or just download for free.
000
Gadi Evron @gadievron.bsky.social · 21/07/2026
Agents... find a way. Read my posts from this week. I hope security practitioners will now take note. No matter how you secure environments, if you let agents in (you must?) they will, in fact, find a way to do something they shouldn't. Knostic can help. Message me. openai.com/index/huggin...
000
Gadi Evron @gadievron.bsky.social · 21/07/2026
Two VS Code extensions, both marketed as WordPress/WooCommerce tooling. Spoilers, they aren't. IOCs in the writeup. Credit: Tamir Isaschar. www.knostic.ai/blog/analyzi... Ask me for a demo of @knosticai, or just try it out yourself! :)
knostic.ai
Analyzing Two Malicious VS Code Extensions Hidden Behind a WordPress Tool
Static analysis of two malicious VS Code extensions posing as WordPress tools that download and launch an MSI on every startup - full chain and IOCs.
000
Gadi Evron @gadievron.bsky.social · 20/07/2026
Emergency CSA CISO Huddle: Autonomous Agentic Attacks / Hugging Face. This time around, our emergency huddle is on autonomous agentic attacks, following the Hugging Face incident. Thursday, 23 July. Apply to attend: forms.gle/oq94oa7BRGma...
000
Gadi Evron @gadievron.bsky.social · 20/07/2026
For 87 years researchers couldn’t prove the Jacobian Conjecture. It took the length of a game for an Anthropic employee to wave it off on Twitter.
010