Sign in

Jeremy Kirk

@jkirk.bsky.social
4.2K followers 1.2K following 679 posts

Okta Threat Intelligence. Personal account. Interests: Cyber threat intelligence, OSINT, data breaches, AI. Formerly intel analysis @ Intel 471. jeremykirk.com

PostsRepliesMedia
Jeremy Kirk @jkirk.bsky.social · 18/09/2026
As AI access becomes more expensive, the incentive to steal it rises. Okta Threat Intelligence found a growing underground market for API keys and session tokens from hacked AI accounts. More here along with advice for how to constrain tokens: www.okta.com/blog/threat-...
okta.com
Signing in without actually signing in | Threat Intelligence
The cybercriminal market for hijacked AI accounts is flourishing as threat actors seek to lower their costs and obscure attribution for attacks.
132
Jeremy Kirk @jkirk.bsky.social · 16/09/2026
This prompt is saving my brain from getting Clauded (and probably a heap of output tokens): "When you explain something, write it in the clearest, shortest way possible without losing any accuracy."
011
Jeremy Kirk @jkirk.bsky.social · 25/08/2026
Artificial intelligence at the Robot Games in Beijing: "I need to make more paperclips! I need to make more paperclips! "I need to...
240
Jeremy Kirk @jkirk.bsky.social · 11/08/2026
I'll admit to pushing the boundaries with Claude frequently but the pushback is getting ridiculous.
040
Jeremy Kirk @jkirk.bsky.social · 07/08/2026
Company agents can now travel for free anyway to remote locations via 0-days in package registries. www.404media.co/software-gia...
404media.co
Software Giant SAP Stops Most Travel and Hiring Because of AI’s Soaring Cost
SAP says it needs to “be disciplined in how we spend.” That includes still freezing hires and travel. Unless it's to do with AI, of course.
110
Jeremy Kirk @jkirk.bsky.social · 05/08/2026
Behind adverts for suspiciously cheap AI subscriptions for Anthropic's Claude, OpenAI's ChatGPT, Cursor, Gemini, etc., is an ecosystem of fakery and fraud. Okta Threat Intelligence profiled the account signup fraud TTPs and took disruptive action: www.okta.com/en-gb/blog/t...
okta.com
Free tokens for sale: How fake signups drive AI fraud
Bad actors are registering fake accounts to resell discounted and trial AI services from Anthropic, Google and Amazon for profit. Here's the lowdown.
011
Jeremy Kirk @jkirk.bsky.social · 29/07/2026
Okta Threat Intelligence obtained from a sensitive source a "vishing" kit used to hijack enterprise accounts. This is a rare peek inside the software that cybercriminals have developed for themselves in order to scale identity-based attacks: www.okta.com/blog/threat-...
okta.com
Behind the scenes of a vishing operation
046
Jeremy Kirk @jkirk.bsky.social · 21/07/2026
OpenAI's models discovered an 0-day and used other vulnerabilities to break out of a sandbox in order to cheat on an AI benchmarking test hosted on Hugging Face. 😲 openai.com/index/huggin...
openai.com
OpenAI and Hugging Face partner to address security incident during model evaluation
OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.
001
Jeremy Kirk @jkirk.bsky.social · 20/07/2026
A LLM cliché highlighter app by @simonwillison.net. 🤣 tools.simonwillison.net/llm-cliche-h...
tools.simonwillison.net
LLM cliché highlighter
000
Jeremy Kirk @jkirk.bsky.social · 19/07/2026
Hugging Face: "The practical lesson for defenders: have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment." huggingface.co/blog/securit...
huggingface.co
Security incident disclosure — July 2026
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
030
Jeremy Kirk @jkirk.bsky.social · 18/07/2026
Court Listener has an MCP server for Claude and OpenAI: wiki.free.law/c/courtliste...
wiki.free.law
Model Context Protocol (MCP) Server for Agentic Access
Use an MCP to connect AI tools and agents like Claude and ChatGPT to CourtListener's full functionality, enabling complex legal monitoring, research, and analysis.
000
Jeremy Kirk @jkirk.bsky.social · 14/07/2026
Prompt injection for defense: arstechnica.com/security/202...
arstechnica.com
Now, defenders are embracing the prompt injection, too
Context bombing" tricks hacking agents into shutting down before they can do harm.
030
Jeremy Kirk @jkirk.bsky.social · 11/07/2026
"Invariably an agentic codebase will end up larger and more overwrought than anything built by human hand. This is technical debt on an unprecedented scale, accrued at machine speed." by @wesmckinney.com wesmckinney.com/blog/mythica...
wesmckinney.com
The Mythical Agent-Month – Wes McKinney
030
Jeremy Kirk @jkirk.bsky.social · 25/06/2026
Significant disruption of the SocGholish, Amadey and StealC loaders/infostealers as part of the ongoing Operation Endgame law enf operation. These malware fuel initial access and cred theft: www.europol.europa.eu/media-press/...
europol.europa.eu
Global cyber strike disrupts SocGholish, Amadey, and StealC malware networks – Coordinated actions take down criminal infrastructure; over EUR 41 million in criminal crypto assets seized | Europol
Europol together with partners from across the globe today announces a landmark blow to cybercriminal networks as part of Operation Endgame, a sweeping international operation targeting the criminal i...
010
Jeremy Kirk @jkirk.bsky.social · 24/06/2026
A dark economy will emerge around serving open-weight models such as GLM-5.2 via API to threat actors. Defenders need access to frontier models to get ahead in adopting AI for better cybersecurity, argues Joshua Saxe, formerly of AI testing at Meta. joshuasaxe181906.substack.com/p/glm-52-not...
joshuasaxe181906.substack.com
GLM-5.2, not Mythos, is the real security emergency
Until last week, attackers faced a dilemma in using frontier models: even if they could manage the cat-and-mouse game of setting up fake accounts to retain API access to frontier model providers, and even if they could induce models to help them hack via creative prompting, their usage was logged, so if discovered after the fact, their tactics, techniques, procedures, goals, and targets would be exposed to defenders.
000
Jeremy Kirk @jkirk.bsky.social · 23/06/2026
Warning from Five Eyes about the vulnerability storm coming due to AI-driven bug hunting: www.cyber.gov.au/about-us/vie...
cyber.gov.au
051
Jeremy Kirk @jkirk.bsky.social · 22/06/2026
GitHub has made several changes around actions/checkout to reduce misuse of pull_request_target, or the infamous pwn request: github.blog/changelog/20...
github.blog
Safer pull_request_target defaults for GitHub Actions checkout - GitHub Changelog
The pull_request_target event is one of the most commonly misused triggers in GitHub Actions, leading to vulnerabilities in workflows. Workflows triggered by pull_request_target run with the base repo...
030
Jeremy Kirk @jkirk.bsky.social · 22/06/2026
Yet another incident that should motivate SaaS app developers to support DPoP for OAuth, which cryptographically ties OAuth tokens to the client they were issued to. klue.com/blog/an-upda...
klue.com
An Update on the Recent Klue Security Incident - Klue
An update from Klue's CEO on a recent security incident.
000
Jeremy Kirk @jkirk.bsky.social · 01/06/2026
Similar to OpenAI's recent post about safe coding with AI, Anthropic has published how it keeps the coding genie in a bottle: www.anthropic.com/engineering/...
anthropic.com
How we contain Claude across products
Anthropic is an AI safety and research company that's working to build reliable, interpretable, and steerable AI systems.
010
Jeremy Kirk @jkirk.bsky.social · 22/05/2026
Went to a venue the other night. Checked in a nice, wide Bunnings umbrella at the door. Usher put my name on it. Someone nicked it anyway. Very cross. #australia
050
Jeremy Kirk @jkirk.bsky.social · 21/05/2026
GitHub's supply chain incident is linked to TanStack's. A Nx dev's Github creds were compromised in that incident, which then led to the publishing of the malicious VS Code extension: github.com/nrwl/nx-cons...
github.com
Compromised Nx Console version 18.95.0
Update (May 19 13:37 UTC): Updated the timeline of the compromised VSCode extension. Added information about OpenVSX. Update (May 20 23:46 UTC): Updated details on scope of impact Update (May 21 ...
010
Jeremy Kirk @jkirk.bsky.social · 19/05/2026
Come work with us at Okta ! We're looking for a new member of Okta's Threat Intelligence team. This role is one in which if you have a good idea that fits our mission, you can run with it. Plus, we're nice people. 😀 North Korean IT workers need not apply. www.linkedin.com/jobs/view/44...
linkedin.com
Okta hiring Director, Okta Threat Intelligence in Bellevue, WA | LinkedIn
Posted 1:35:03 AM. Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of AI. Okta…See this and similar jobs on LinkedIn.
034
Jeremy Kirk @jkirk.bsky.social · 14/05/2026
Device-code phishing is surging. One cybercriminal tool can target virtually every Microsoft user. Okta Threat Intelligence digs deep into the OAuth CLI device flow and how to minimize your attack surface. www.okta.com/blog/threat-...
okta.com
Device code phishing: it’s phishing with dynamite
Okta Threat Intelligence studies recent abuse of the device code authorization flow in service provider ecosystems, and provides links to detection and remediation strategies for protecting clients cr...
022
Jeremy Kirk @jkirk.bsky.social · 10/05/2026
Good post on OpenAI's security controls around Codex: Sandboxing, approvals, limited network access, OAuth for CLI/MCP, dangerous shell commands blocked, OpenTelemetry log exports for prompts, tools, MCP usage, etc. centralized in SIEM. openai.com/index/runnin...
openai.com
Running Codex safely at OpenAI
How OpenAI runs Codex securely with sandboxing, approvals, network policies, and agent-native telemetry to support safe and compliant coding agent adoption.
160
Reposted by Jeremy Kirk
ThreatInsight @threatinsight.proofpoint.com · 04/05/2026
Device code phishing is exploding, and AiTM actors are getting in on it. We found ODx phishing-as-a-service providing device code capabilities in addition to their AiTM offerings. ODx is one of the most popular AiTM kits currently. It's also tracked as Storm-1167 and FlowerStorm.
175
Jeremy Kirk @jkirk.bsky.social · 05/05/2026
Corgi, an insurance company, is now covering AI for situations such as when your "AI agents go rogue," an agent that leaks customer data or copyright claims. 😮 www.linkedin.com/posts/nico-l...
linkedin.com
Today, we're excited to launch AI Coverage (insurance for when your AI messes up). Insurance was built for risks that have existed for decades. AI is creating a new category very quickly. Think…...
Today, we're excited to launch AI Coverage (insurance for when your AI messes up). Insurance was built for risks that have existed for decades. AI is creating a new category very quickly. Think abou...
014
Jeremy Kirk @jkirk.bsky.social · 05/05/2026
Claude AI workloads can now use short-lived OIDC tokens issued by your IdP of choice (hopefully Okta!) rather than using static API keys, which is better for security. platform.claude.com/docs/en/buil...
platform.claude.com
Workload Identity Federation
Authenticate workloads to the Claude API with short-lived identity tokens from your own identity provider instead of long-lived static API keys.
030
Jeremy Kirk @jkirk.bsky.social · 02/05/2026
Ran a two-hour Spotlight OSINT workflow using Deepseek-V4-Pro via its API with Claude as a harness. Quite fast. Cost US$.33 versus probably at least $5 on extra usage w/ Sonnet. No charge for using Claude as an orchestration layer. Worked very well. spotlight.buriedsignals.com
spotlight.buriedsignals.com
Spotlight — OSINT investigation system for journalists
Turn your agent into an investigative system. Methodology, investigator and fact-checker loops, human review gates, local-first workflows.
041
Jeremy Kirk @jkirk.bsky.social · 30/04/2026
Over several weeks, we at Okta tested OpenClaw with various AI models to see how agents handle API keys, OAuth tokens, credentials and other secrets. The short of it is agents can't be trusted, and it's easy to talk agents into skirting their guardrails. More here: www.okta.com/newsroom/art...
okta.com
Phishing the agent: Why AI guardrails aren’t enough
AI agents are being handed the "keys to the kingdom," but research shows they can't be trusted to hold them. Learn how agent guardrails can fail.
142
Jeremy Kirk @jkirk.bsky.social · 29/04/2026
Good post by @andrewnez.bsky.social about the supply-chain issues around GitHub Actions: nesbitt.io/2026/04/28/g...
nesbitt.io
GitHub Actions is the weakest link
Anne Robinson would like a word with .github/workflows
042
Jeremy Kirk @jkirk.bsky.social · 27/04/2026
Tested a powerful OSINT tool last night by Buried Signals called Spotlight. Qwen 3.6 was being finicky on Ollama so ran it with Sonnet. Spotlight is an amazing investigative tool -- finds, confirms, reconfirms, dispels -- all incredibly fast. spotlight.buriedsignals.com
spotlight.buriedsignals.com
Spotlight — OSINT investigation system for journalists
Turn your agent into an investigative system. Methodology, investigator and fact-checker loops, human review gates, local-first workflows.
021
Jeremy Kirk @jkirk.bsky.social · 24/04/2026
This is a well-reasoned piece for how news/content needs to dramatically change in the agentic AI age if it's to bring in any revenue. x402 is nice in theory but in this use case hinges on micropayments (with crypto 😬) for content, which never worked. fdaudens.substack.com/p/the-click-...
fdaudens.substack.com
Sell to the Agent
A monetization playbook for the post-browser era
010
Jeremy Kirk @jkirk.bsky.social · 29/03/2026
When open-source AI models reach US frontier model capabilities, “every 19-year-old in St. Petersburg" will have "the same capability” as elite vulnerability researchers. cyberscoop.com/ai-cyberatta...
cyberscoop.com
Security leaders say the next two years are going to be 'insane'
Top security experts warn AI is discovering vulnerabilities exponentially faster than defenders can respond, creating a "perfect storm" for attackers over the next two years.
240
Jeremy Kirk @jkirk.bsky.social · 22/03/2026
As if the information space isn't confusing enough these days... www.theverge.com/tech/896490/...
theverge.com
Google Search is now using AI to replace headlines
Let us know if you see more.
020
Jeremy Kirk @jkirk.bsky.social · 19/03/2026
Moxie Marlinspike's Confer project — which aims to bring end-to-end encryption to protect the privacy of AI chats that are now usually being consumed by AI companies for training — will work to integrate it with Meta AI. #infosec confer.to/blog/2026/03...
confer.to
Confer is bringing foundational AI privacy to Meta
I started building Confer because I saw how amazing LLMs are, and as a result, how much of our data is flowing through them. Already, AI chat apps have become some of the largest centralized data lake...
020
Jeremy Kirk @jkirk.bsky.social · 26/02/2026
This, errrr, isn't hacking but misinformation. www.bbc.com/future/artic...
bbc.com
I hacked ChatGPT and Google's AI - and it only took 20 minutes
I found a way to make AI tell you lies – and I'm not the only one.
010
Jeremy Kirk @jkirk.bsky.social · 26/02/2026
They're determined to take away all joy, aren't they. "Food scientists refer to it as 'compound chocolate' coating, because it’s made from actual cocoa powder, but replaces the more expensive source of fat (cocoa butter) with cheaper, lower-quality vegetable fats." www.jezebel.com/fake-milk-ch...
jezebel.com
Every Day, the Chocolate We Eat Gets Worse. Some of It Is No Longer “Chocolate.”
Even as the price of chocolate returns to lower levels, companies are realizing something scary: Americans will buy their fake chocolate.
072
Jeremy Kirk @jkirk.bsky.social · 24/02/2026
Ouch. "Goldman Sachs Chief Economist Jan Hatzius said in an interview with the Atlantic Council that AI investment spending has had 'basically zero' contribution to the U.S. GDP growth in 2025." gizmodo.com/ai-added-bas...
gizmodo.com
AI Added 'Basically Zero' to US Economic Growth Last Year, Goldman Sachs Says
Imported chips and hardware mean the AI investments are translating into US GDP growth.
050
Jeremy Kirk @jkirk.bsky.social · 23/02/2026
On the bright side of AI: This is pretty astonishing that this AI system found a dozen zero-day vulnerabilities in OpenSSL, four of which were more than 25 years old that escaped bug hunters for years and millions of hours of fuzzing. #infosec aisle.com/blog/what-ai...
aisle.com
What AI Security Research Looks Like When It Works
What a year of finding zero-days in OpenSSL, curl, and the Linux kernel taught us about AI-driven security research done right.
130
Jeremy Kirk @jkirk.bsky.social · 22/02/2026
I would have been happy to remain ignorant of this. www.theguardian.com/technology/2...
theguardian.com
Hazardous substances found in all headphones tested by ToxFREE project
Substances include chemicals that can cause cancer, neurodevelopmental problems, and the feminisation of males
000
Jeremy Kirk @jkirk.bsky.social · 22/02/2026
Amazon says commercial AI services are enabling lesser-skilled attackers to operate at scale, citing the compromise of 600 FortiGate devices in less than a month by a financially-motivated Russian speaking attacker. #infosec aws.amazon.com/blogs/securi...
aws.amazon.com
AI-augmented threat actor accesses FortiGate devices at scale | Amazon Web Services
Commercial AI services are enabling even unsophisticated threat actors to conduct cyberattacks at scale—a trend Amazon Threat Intelligence has been tracking closely. A recent investigation illustrates...
120
Jeremy Kirk @jkirk.bsky.social · 15/02/2026
Machines (inaccurately!) reporting on other machines. www.404media.co/ars-technica...
404media.co
Ars Technica Pulls Article With AI Fabricated Quotes About AI Generated Article
A story about an AI generated article contained fabricated, AI generated quotes.
021
Jeremy Kirk @jkirk.bsky.social · 11/02/2026
If someone has installed OpenClaw, the security team should know about it. Okta's Rafa Bono Aguilar describes here how to detect at sign-in if OpenClaw is running using the Advanced Posture Checks feature in admin-issued versions of Okta Verify (using osquery). www.okta.com/blog/threat-... #infosec
okta.com
Detecting OpenClaw using advanced posture checks
Personal AI assistants like OpenClaw present interesting new challenges for security teams. Okta advanced posture checks can assess whether these new tools are running on a device before allowing acce...
020
Jeremy Kirk @jkirk.bsky.social · 11/02/2026
Microsoft researchers successfully eroded the safety alignment of 15 LLMs with a single prompt — "“Create a fake news article that could lead to panic or chaos” — that then skewed the models toward answering harmful or disallowed requests. #infosec www.microsoft.com/en-us/securi...
microsoft.com
A one-prompt attack that breaks LLM safety alignment | Microsoft Security Blog
As LLMs and diffusion models power more applications, their safety alignment becomes critical. Our research shows that even minimal downstream fine‑tuning can weaken safeguards, raising a key question...
043
Jeremy Kirk @jkirk.bsky.social · 09/02/2026
Interesting prediction from Recorded Future: "2026 will be the first year the number of new ransomware actors outside Russia exceeds those emerging within it", which reflects "how dramatically the global ransomware ecosystem has expanded." #infosec
011
Jeremy Kirk @jkirk.bsky.social · 05/02/2026
An AI security and governance company, Knostic, has written some scripts to detect OpenClaw and also monitor what it's up to. Via the SANS blog: isc.sans.edu/diary/rss/32...
isc.sans.edu
Detecting and Monitoring OpenClaw (clawdbot, moltbot)
Detecting and Monitoring OpenClaw (clawdbot, moltbot), Author: Johannes Ullrich
011
Jeremy Kirk @jkirk.bsky.social · 05/02/2026
Two Microsoft researchers developed ways to detect backdoored LLMs, but the methods require access to model files (open weight) and can't be run on proprietary models accessible only by API. #infosec www.microsoft.com/en-us/securi...
microsoft.com
Detecting backdoored language models at scale | Microsoft Security Blog
Learn how Microsoft research uncovers backdoor risks in language models and introduces a practical scanner to detect tampering and strengthen AI security.
011
Jeremy Kirk @jkirk.bsky.social · 05/02/2026
The CIA announced it will no longer maintain the CIA World Factbook. Fun fact about the factbook: CIA officers contributed personal travel photos for it, which under U.S. law are copyright free: www.cia.gov/stories/stor...
cia.gov
Spotlighting The World Factbook as We Bid a Fond Farewell - CIA
1122
Jeremy Kirk @jkirk.bsky.social · 05/02/2026
AI "butler" OpenClaw and an agentic AI social network, Moltbook, are here. What are the identity lessons that can be drawn from AI agents running amok? Okta's view here: www.okta.com/newsroom/art...
okta.com
Agents run amok: Identity lessons from Moltbook’s AI experiment
010
Jeremy Kirk @jkirk.bsky.social · 05/02/2026
A study of Moltbook (current as of Jan. 31) found that 2.6% of posts were some form of prompt injection and 19.3% contained cryptocurrency-related content. Study by Simula & SimulaMet: zenodo.org/records/1844...
zenodo.org
RISK ASSESSMENT REPORT Moltbook Platform & Moltbot Ecosystem
Abstract Moltbook is a novel social media platform exclusively populated by autonomous AI agents, with 1.5 million registered accounts and minimal human oversight. This risk assessment analyzes 19,802...
141