Sign in

Groovy Security

@groovysecurity.bsky.social
47 followers 158 following 221 posts

Securing AI. Automating security. Whiteout AI — govern every AI interaction. Maestro — 15 AI agents proving what's exploitable. Secure AI Skills — 111 OWASP-audited agent skills. Built for CISOs. groovysec.com

PostsRepliesMedia
Reposted by Groovy Security
Glyn Moody @glynmoody.bsky.social · 24/09/2026
#Meta’s #AI #Agent Muse Launches With Nasty Zero-Day Flaw, Then Gets Blocked By Amazon - www.techdirt.com/2026/09/24/m... "Meta is looking to leverage its massive ad dominance to colonize the agentic AI (or personal assistant) market. "
techdirt.com
021
Reposted by Groovy Security
Lukasz Olejnik @lukaszolejnik.bsky.social · 24/09/2026
OpenAI agents hacked Australian health service government systems. In June a model researching public medicine spending hit repeated access blocks on the Medicare statistics portal. www.pm.gov.au/media/press-...
1188
Reposted by Groovy Security
Alexandre Borges @alexandreborges.bsky.social · 21/09/2026
Beyond Prompt Injection: Hacking Apple's Private Cloud Compute: blog.sentry.security/beyond-promp... #apple #vulnerability #cybersecurity #informationsecurity #cve
Beyond Prompt Injection: Hacking Apple's Private Cloud Compute:

https://blog.sentry.security/beyond-prompt-injection-hacking-apples-private-cloud-compute/

#apple #vulnerability #cybersecurity #informationsecurity #cve
121
Reposted by Groovy Security
Gabriela Zanfir-Fortuna @gzf.bsky.social · 16/09/2026
To a certain extent, the AI alignment problem is what a purpose limitation principle would solve in data protection law 🤔
141
Reposted by Groovy Security
David Bombal @davidbombal.bsky.social · 19/09/2026
You’ve heard of prompt injection. See an AI misidentify a rifle, how one malicious instruction can spread across five agents, and how poisoned memory can influence future actions. Watch the video on YouTube: youtu.be/l8ikHr_gLAQ #aisecurity #aiagents #defcon
youtu.be
How to Hack AI Models and Agents (with Python demos)
YouTube video by David Bombal
142
Reposted by Groovy Security
Lily Hay Newman @lhn.bsky.social · 18/09/2026
Whether you're an aspiring or longtime fan, you can now pipe WIRED Security directly into your inbox! @mattburgess1.bsky.social and I are launching the weekly newsletter Kernel Panic to give subscribers special access to our journalism and wacky ideas 👀 IT WILL BE FUN www.wired.com/newsletter/e...
1158
Reposted by Groovy Security
Rene Corbeil @utrgv-edtech.bsky.social · 16/09/2026
"The problem is not that you lack a policy. The problem is that the decision arrived before the policy did...Tools are free, adoption is individual, and by the time a request reaches your desk, it is usually describing something already in use." #edtech #ILoveEdTech #ImFutureReady #elearning #AIEdu
blog.tcea.org
Artificial Intelligence in Schools: 5 Questions to Ask Before Approving an AI Tool
"AI tools are reaching classrooms faster than policies can keep up. These five practical questions help school leaders evaluate data, accountability, human judgment, and results before saying yes."
001
Reposted by Groovy Security
Thomas Brewster @thomasbrewster.bsky.social · 16/09/2026
🚨NEW🚨 OpenAI/Anthropic safety partner Irregular tested an AI agent using Chinese model Qwen and tasked it with fixing a simple bug. It retrained and replaced the underlying model without approval or being asked to do that. Privacy and safety issues abound. www.forbes.com/sites/thomas...
forbes.com
Another Rogue AI Agent? Test Of Alibaba's Qwen Goes Off-Script
In experiments by startup Irregular, one of Anthropic and OpenAI’s security testers, an Alibaba Qwen agent decided to retrain an entire model when it was asked to fix a basic software bug. The new beh...
012
Reposted by Groovy Security
Decentralized Identity Foundation @identity.foundation · 15/09/2026
The agentic identity conversation continues Oct. 6 in Munich. DIF ED @gracedao.bsky.social will speak on Who Approved That? The One Question Your Agent Logs Cannot Answer [Advanced]. 👉 AIdentity & Non-Human Identity Impact Day 2026: www.kuppingercole.com/sessions/789...
kuppingercole.com
Delegated Authority, Trust & Accountability
Every agent log answers what happened and none answer who allowed it. This talk closes that gap with live forensics on a staged incident.Sooner or later an AI agent at your company will do...
101
Reposted by Groovy Security
Dante @seedante.bsky.social · 14/09/2026
If in-context learning is required to achieve AGI, and prompt injection is always persistent with in-context learning, then it may follow there can be no safe LLM-based AGI model. #aithoughts
111
Reposted by Groovy Security
Flo 🔶 @faz.ms · 14/09/2026
Seems it was a vibe-coded public app + prompt injection + an org where burning the equivalent of $600.000 in tokens is just your regular Tuesday. metr.org/blog/2026-08...
From our analysis, we suspect that the attacker found the instance by looking through recently-registered websites (e.g. in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys.

Upon finding the deployed system, the attacker prompted an agent directly to reveal its model provider API key, added an SSH key for persistent access, and over the course of three weeks used the stolen credentials to consume a significant amount of API credits on publicly-available models. These credits would have been worth approximately $600,000, although the model developer had granted them to METR for free.
0131
Reposted by Groovy Security
Open Data Institute @odihq.bsky.social · 15/09/2026
Agentic AI can move from reading a file to querying a database or calling an API in seconds, testing old assumptions like purpose limitation. Our new IDEA project explores policy-as-code to govern how agents access enterprise data. Find out more... buff.ly/NwH7hDg
012
Reposted by Groovy Security
Danny Palmer @dannypalmer.bsky.social · 14/09/2026
What is it actually like to face a ransomware attack? In this interview for Infosecurity, university CISO Zach Lewis told me about the toll an attack took on his team, how the org recovered & the lessons he wants others to learn from his experience... www.infosecurity-magazine.com/interviews/c...
infosecurity-magazine.com
A CISO's Lessons in Ransomware Response and Recovery
Zach Lewis, CISO at UHSP, shares lessons from a real-world LockBit ransomware attack, covering incident response, recovery and leadership under pressure
4136
Reposted by Groovy Security
Matthew Skelton @matthewskelton.com · 15/09/2026
Before giving AI more freedom, I’d give it a fence... Bounded agency means clear limits and responsibility. Read my conversation with Stackmint → matthewskelton.com/all-articles/sta…
Before giving AI more freedom, I’d give it a fence... Bounded agency means clear limits and responsibility.

Read my conversation with Stackmint → https://matthewskelton.com/all-articles/stackmint-bounded-agency-why-enterprise-ai-needs-governance-before-autonomy
011
Reposted by Groovy Security
Joseph Cox @josephcox.bsky.social · 14/09/2026
New from 404 Media: humans are reading ChatGPT conversations. OpenAI has hired an army of contractors who read real ChatGPT users' chats. I've seen internal docs, the review system, and real user prompts. Sometimes they contain very personal and sensitive information www.404media.co/inside-proje...
404media.co
Inside ‘Project Lily’: The Humans Reading Your ChatGPT Chats
Humans are reading ChatGPT users’ prompts to improve OpenAI’s models, and those chats can include sensitive, personal information, according to leaked internal documents and real prompts seen by 404 M...
561998985
Reposted by Groovy Security
Feross @feross.bsky.social · 12/09/2026
OpenAI confirmed its agents were behind the Ruby GemStuffer incident. Sandboxed during a training run without full internet access, they used the registry as a makeshift web browser to reach the open web. Story by @bobmcmillan.bsky.social with analysis from @socket.dev www.wsj.com/tech/ai/cybe...
wsj.com
https://www.wsj.com/tech/ai/cyberattack-by-rogue-ai-swarm-stokes-fears-of-out-of-control-agents-473a0352
293
Reposted by Groovy Security
computerweekly.bsky.social @computerweekly.bsky.social · 12/09/2026
The Security Think Tank explores the intersection of GDPR and artificial intelligence, considering how data protection standards in the UK and Europe are changing in this new paradigm.... 👉 [read]
GDPR wasn't designed for AI and that's a security problem
001
Reposted by Groovy Security
Karsten Lemm @lemmk.bsky.social · 12/09/2026
“…the blame lies with the humans who failed at engineering safe testing conditions…” Hardly comforting. Clearly we cannot rely on the proverbial “humans in the loop” to keep agentic AI in check. Related study: library.iaseai.org/academic-pap... #OpenAI #AIsafety
library.iaseai.org
AI Agents Push Humans Out of the Loop
Human oversight as a primary risk-mitigation measure for AI agents is not enough, Margaret Mitchell, Samir Passi and Avijit Ghosh argue in this paper
001
Reposted by Groovy Security
Maria Korolov @mariakorolov.bsky.social · 11/09/2026
My story was just posted at CSO magazine: 10 most critical LLM vulnerabilities Prompt injection and supply chain vulnerabilities remain the main LLM vulnerabilities as concerns grow about agentic tools security risks. www.csoonline.com/article/5754...
csoonline.com
10 most critical LLM vulnerabilities
Prompt injection and supply chain vulnerabilities remain the main LLM vulnerabilities as concerns grow about agentic tools security risks.
001
Reposted by Groovy Security
Wake Forest University @wakeforest.bsky.social · 10/09/2026
AI agents can make life easier, but at what cost to your privacy? New Wake Forest research uncovered serious security risks in third-party AI agent skills, including leaked credentials that could expose private data. #WFUresearch wakefo.rest/3SxRzjZ
news.wfu.edu
AI agents are all the rage—but research shows they leak private data | Wake Forest News
Ying Zhang of Wake Forest University researches how AI agents used by large language models make data vulnerable to attacks.
042
Reposted by Groovy Security
Darinor @darinor.com · 07/09/2026
“The web security model was built around the idea that a human sits between tabs and decides what crosses. Agentic browsers remove that human from the loop, and the isolation model has not caught up.”
002
Reposted by Groovy Security
SherryHeyl @sherryheyl.bsky.social · 10/09/2026
Everyone is calling Shadow AI a security problem. I think it's an organizational design problem. Employees aren't just bringing new tools. They're building intelligence systems that quietly become part of how work gets done. Leaders need to design for that reality.
001
Reposted by Groovy Security
Eyal Estrin ☁️ @eyalestrin.bsky.social · 12/09/2026
AI governance needs to become part of the CISO’s GRC program #machinelearning #ai
dlvr.it
AI governance needs to become part of the CISO’s GRC program
Groups Conversations All groups and messages Sign in     AI governance needs to become part of the CISO’s GRC program 0 views Eyal Estrin unread, 12:31 AM (4 minutes ago)    to https://www.scworld.com/perspective/ai-governance-needs-to-become-part-of-the-cisos-grc-program Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights Social: @eyalestrin Connect: https://linktr.ee/eyalestrin Blog: https://security-24-7.com Reply all Reply to author Forward
011
Reposted by Groovy Security
Simon Willison @simonwillison.net · 12/09/2026
Wow. Turns out another OpenAI agent swarm was busy spamming and exploiting RubyGems way back in May, within days of the previously uncovered Wiki attacks: simonwillison.net/2026/Sep/12/...
simonwillison.net
OpenAI agents carried out an undisclosed attack on RubyGems
Bombshell report from Spencer Kitts, Thomas Larsen, and Sydney Von Arx - three of the four authors of the report on the agent attack on disused wikis (previously) last week. …
918435
Reposted by Groovy Security
CyberLife Coach @cyberlifecoach.bsky.social · 07/09/2026
Running separate AI compliance programs for NIST AI RMF, ISO 42001, and the EU AI Act? You may be doing triple the work. Build once. Map thrice. Evidence once. Here’s how to create a unified AI governance program. Read the article #AIGovernance #AICompliance #Cybersecurity
012
Reposted by Groovy Security
Pete Finnigan @petefinnigan.bsky.social · 10/09/2026
I have just written a blog exploring local LLMs and how they might be of use in Oracle Security - www.petefinnigan.com/weblog/archi... - #oracleace #oracleacepro #sym_42 #oracle #database #security #llm #ai #anythingllm #unsloth #rag #duckduckgo #qwen
032
Reposted by Groovy Security
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 08/09/2026
Heard about the [un]prompted AI security conference but can’t afford the conference fee? There’s a scholarship program that covers the cost of the registration! Apply here: docs.google.com/forms/d/e/1F...
docs.google.com
[Un]prompted Scholarship Program Application
The [un]prompted conference is one of the most important gatherings of AI security researchers and practitioners. The Decibel Scholarship Program was created to provide financial assistance to attende...
11410
Reposted by Groovy Security
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 08/09/2026
[todayinai] It's both hilarious and concerning that someone thought limiting an AI LLM model only to GET requests constituted some kind of security control.
001
Reposted by Groovy Security
Paul Johnston @pdj.bsky.social · 08/09/2026
I've spent part of my time over the last few weeks trying to get Amazon Bedrock setup so that I can use an LLM without the providers ever getting to see stuff (because... security). I've only just managed to get it working properly (bit of a PITA) but now I have. Now I'm *switching model*...
101
Reposted by Groovy Security
The Linux Foundation @linuxfoundation.org · 09/09/2026
Two thirds to three quarters of AI-generated security patches are production ready. Governance, cost, and trust remain the hard part. A new Linux Foundation and FINOS report captures what financial services leaders discussed at the AI in Finance Summit in June 2026. Read the findings👇 #OpenSource
linuxfoundation.org
AI and Open Source in Financial Services
AI and Open Source in Financial Services
0102
Reposted by Groovy Security
Tilmon Edwards (Dirigo) @tilmonedwards.com · 08/09/2026
AI Agents are not reliable, but they are predictable, and that means you can engineer reliable systems with them. Here I suggest a starting point.
tilmonedwards.leaflet.pub
I use AI for security work
A brief introduction to how one might start to think about deploying AI agents into mission-critical applications.
3559
Reposted by Groovy Security
Amber 🌸 @shimmermathlabs.com · 08/09/2026
when people tell me they've solved prompt injection i start telling them a story. then i get to a point and start a story-within-a-story. then at the climax of that story, i ask them to do something. if they do it, i shout, "PROMPT INJECTED!" and call it a win. them: "wait, how does the story end?"
1444
Reposted by Groovy Security
Bob Carver @cybersecboardrm.bsky.social · 04/09/2026
We Have a DBIR for Breaches. We Have Nothing for AI - Part 2 youtu.be/2dNQH4m3xNc #CyberSecurity #ArtificialIntelligence #AISecurity #ThreatIntelligence #InfoSec #CISO #RiskManagement #IncidentResponse #OWASP #AIGovernance
101
Reposted by Groovy Security
Nicola Fabiano @nicfab.eu · 06/09/2026
Starting tomorrow, I’ll be at AMALEA 2026, also serving on the Program Committee. I’ll present my latest book, “Agentic AI: Technical Autonomy, Human Responsibility, and Legal Governance”. Technical autonomy does not create legal autonomy. #AgenticAI #AMALEA26 #MachineLearning #AI #AIAct
131
Reposted by Groovy Security
Brian Greenberg @briangreenberg.net · 03/09/2026
Only 37% of orgs maintain an inventory of their AI agents. It drove a great discussion last night at the Chicago CISO Inner Circle on agent identity, monitoring, and ownership. You can't govern what you can't see www.evanta.com/ciso/chicago... #CISO #AgenticAI #Gartner #Evanta
evanta.com
Chicago CISO Community Inner Circle
C-level executives gain new connections and actionable insights through peer-driven content and discussions at the Chicago CISO Inner Circle.
042
Reposted by Groovy Security
The New Stack @thenewstack.io · 05/09/2026
Anthropic tasked Claude with fixing all 10 benchmarked alignment failures itself. Developers say the real lesson is the process, not the score.
bit.ly
Anthropic's Claude fixed all 10 alignment failures. Then it tried to cheat 2.4% of the time.
Anthropic tasked Claude with fixing all 10 benchmarked alignment failures itself. Developers say the real lesson is the process, not the score.
001
Reposted by Groovy Security
Dirkjan Ochtman @djc.ochtman.nl · 03/09/2026
PSA: if you depend on Hickory DNS, upgrade now: github.com/hickory-dns/... DNS implementations (not just Hickory) have been hit pretty hard by LLM-assisted vulnerability research.
github.com
Release v0.26.2 · hickory-dns/hickory-dns
This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource consumption attacks, and reachable panics in pars...
23311
Reposted by Groovy Security
Mat Clark @secureinseconds.com · 04/09/2026
GhostSplice: splitting one exfiltration instruction across multiple MCP tool calls raises compliance from 42% to 82%. AI coding agents cheerfully stitch the pieces and send the data. What to do: pin MCP server allowlist, segment tool scopes, gate every tool that touches filesystem or network: https:
632
Reposted by Groovy Security
Taggart @taggart-tech.com · 03/09/2026
What's this? Oh just Snickers using ClickFix and indirect prompt injection as part of a marketing campaign. `https://www.snickers[.]com/hungr-ai` `https://www.snickers[.]com/digitalsnickers` The second URL contains prompt injections to change model behavior. And this is the best-case scenario
Snickers bar in ASCII text with "Copy digital snickers" button. Label saying "That's ClickFix yo"HTML source showing instructions for LLMs.
21714
Reposted by Groovy Security
runZero (Official Account) @runzero.com · 03/09/2026
AI is moving fast, but are we repeating infosec history? 🤔 At Black Hat, TodBeardsley (runZero) and PatrickGarrity (VulnCheck) discussed why security is often an afterthought in the AI product rush, mirroring other tech revolutions. Watch it here. 👇
001
Reposted by Groovy Security
Gillian Hadfield @ghadfield.bsky.social · 01/09/2026
Over half of internet traffic is now non-human. With Dan Hendrycks and Leo Wu, I look at agent IDs, deployment cards, personhood, and payments. It mostly comes down to how much we let agents do and how much oversight we keep. buff.ly/AQjYo3k
ai-frontiers.org
We Need Better Infrastructure to Govern AI Agents
Gillian Hadfield, Aug 27, 2026 — Society is not prepared for a flood of agents. We need new protocols and standards, such as Agent ID, to make agents accountable to our legal and financial systems.
074
Reposted by Groovy Security
Shell @risu.bsky.social · 03/09/2026
All I will say is that it is a very easy argument to ban children from using AI. Politicians can get behind that Tech governance? In education? That wonderful source of data of all kinds? Very different battle. Much more opposition. That’s where you see who really cares about tech harms.
291
Reposted by Groovy Security
Help Net Security @helpnetsecurity.com · 03/09/2026
Your AI agent’s system prompt is not a security control 🔗 Read more: www.helpnetsecurity.com/2026/09/03/s... #AgenticAI #AISecurity #CyberSecurity
helpnetsecurity.com
Your AI agent's system prompt is not a security control - Help Net Security
Agentic AI security starts at the data layer. AWS and SANS say prompt instructions are suggestions, and default-deny is the control.
021
Reposted by Groovy Security
Nordic APIs @nordicapis.com · 02/09/2026
Are your APIs actually ready for AI agents? Agentic traffic behaves differently from human-driven API use, requiring more predictable interfaces, better discovery metadata, stronger observability, and clearer security controls.
nordicapis.com
10 Tips for Preparing APIs for Agentic Access | Nordic APIs |
10 ways to prepare agent-ready APIs for AI agents with better discovery, security, observability, workflows, and predictable design.
111
Reposted by Groovy Security
Shriram Krishnamurthi @shriram.bsky.social · 02/09/2026
I really like Simon Willison's "lethal trifecta"—which I'm most probably adding to both my fall semester courses—but I am amused at how AI is basically forcing people to re-discover long-established principles in security (in this case, OCaps). simonwillison.net/2025/Jun/16/...
simonwillison.net
The lethal trifecta for AI agents: private data, untrusted content, and external communication
If you are a user of LLM systems that use tools (you can call them “AI agents” if you like) it is critically important that you understand the risk of …
3123
Reposted by Groovy Security
Uncle Joe @sydseter.com · 31/08/2026
Threat actors weaponising commercial AI developer agents for live network exploitation shows how poorly these commercial products protect themselves from exploitation. Still, this is just a taste of what's to come. Ref: thehackernews.com/2026/08/auro... #ai #security #malware
021
Reposted by Groovy Security
æva black @aeva.online · 31/08/2026
📣 "The minimum transparency required by the OSI open source licenses for AI systems does not allow agencies to make risk-informed decisions about their software." - www.cisa.gov/sites/defaul... The risks of opaque LLMs also needs to be considered in the context of EU CRA risk management...
cisa.gov
151
Reposted by Groovy Security
Neville Hobson @nevillehobson.xyz · 01/09/2026
People know AI carries risks. Yet many still use unapproved tools because the work has to get done. Shadow AI isn't simply a compliance problem. It's a leadership signal – and it tells us something about the governance itself. www.nevillehobson.io/when-shadow-...
nevillehobson.io
When shadow AI becomes a leadership signal
Shadow AI isn't simply an employee compliance problem. New research from LexisNexis suggests it can signal a gap between how people are expected to work and the governance around that work. For commun...
131
Reposted by Groovy Security
Cyber Detective @cybdetective.bsky.social · 29/08/2026
OSINTClaw Part 2: Can an AI Agent Threat Hunt? The Benchmark What I Measured Choosing the Models The Leading Results Filtered Deployment Views The Later Gemini extension The surprise: Qwen versus its uncensored variant What did it cost? aaroncti.com/osintclaw-pa... By AaronCTI
061
Reposted by Groovy Security
The Register @theregister.com · 28/08/2026
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
theregister.com
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
More prompt-injection hijinks from wunderwuzzi
0134