Sign in

Katie Moussouris (she/her/she-hulk/she-ra)🌻

@k8em0.bsky.social
22K followers 1.2K following 1.4K posts

Founder & CEO LutaSecurity @payequitynow MIT&Harvard visiting scholar, @MasonNatSec fellow, 1/2 Chamoru, 1/2 Greek all-American hacker

PostsRepliesMedia
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 58m
The intended audience & effect is toward regulating open weight models, so security teams switching to them to avoid refusals will be temporary. It’s a “loss leader” marketing move & will likely achieve its desired effect, unless a national security case can be made to stop it.
062
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 25/09/2026
“Restraint itself can be a signal.” Read more from the brilliant @saffronsec.bsky.social in @bindinghook.bsky.social on the relationship between cyber and kinetic conflict as observed in the Iran war
143
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 24/09/2026
My thoughts on CISA’s future of CVE white paper along with @sawaba.bsky.social Let’s hope Congress backs enough budget at CISA to hire the human expert resources to guide what will also require heavy automation investment. Thanks @shaunwaterman.bsky.social www.bankinfosecurity.com/cisa-lays-ou...
bankinfosecurity.com
CISA Lays Out Future of CVE Vulnerability Program
The U.S. Cybersecurity and Infrastructure Security Agency published a short whitepaper Wednesday, laying out four "dimensions of quality" it will pursue
1136
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 22/09/2026
Today in AI: 🤙🏼
Two buttons meme with buttons labeled “Pace the frontier” and “Release new models”. Both buttons are being pressed at once in the upper panel, and the guy smiling with a thumbs up in the lower panel is captioned “Frontier AI”
2276
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 20/09/2026
I’m speechless all over again. 😭 Thanks for including me in this week’s Good News Corner of your weekinsecurity.com newsletter @zackwhittaker.com ! And thanks forever to the @sentinelone.com SentinelLabs LABSCON crew & community for bringing knowledge & magic people together all these years 💜💖🎉
weekinsecurity.com
~this week in security~
a weekly cybersecurity newsletter by Zack Whittaker, plus articles and more.
0163
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 17/09/2026
Beyond honored to receive the last #LABSCon #SentinelLabs Lifetime Achievement Award 🥇
LABS
CON
2026

Lifetime Achievement

Katie Moussouris 

For voicing or conscience from the Pentagon to the karaoke bar
8877
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 08/09/2026
Heard about the [un]prompted AI security conference but can’t afford the conference fee? There’s a scholarship program that covers the cost of the registration! Apply here: docs.google.com/forms/d/e/1F...
docs.google.com
[Un]prompted Scholarship Program Application
The [un]prompted conference is one of the most important gatherings of AI security researchers and practitioners. The Decibel Scholarship Program was created to provide financial assistance to attende...
11410
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/08/2026
While I agree in general, this open letter from frontier models and tech companies is giving some heavy AI adoption vibes openai.com/collective-c...
Homer Simpson toasts to a crowd with a mug of beer while standing atop casks: To AI, the cause of and solution to all of life’s problems
0193
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 26/08/2026
I’m on the CFP review board for [un]prompted. Submit your talks ASAP - don’t make us pull any all-nighters to read your abstract
190
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 26/08/2026
Follow the money, ignore the manifesto. My thoughts on the GTA VI leaks shared with @mattkapko.com for @cyberscoop.bsky.social along with comments from Cynthia Kaiser, Zach Edwards, and Ben Bernstein cyberscoop.com/grand-theft-...
cyberscoop.com
The GTA VI leaks are breaking the internet. Security researchers have seen this before.
A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience.
0141
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Chantal James @chantalalive.blacksky.app · 25/08/2026
The whole time Dolly Parton was being one of music's greatest songwriters & performers, & one of the world's greatest humanitarians & champions for literacy, & accepting of queer & trans people, get this. She never let up on being a hot girl shaking ass looking fabulous with her proud huge boobs.
3583134
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
I just need some acknowledgment that I ate all the raspberries in the fridge before they got moldy and this may be unprecedented success
161725
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
Having created Microsoft Vuln Research, the 1st multiparty vuln disclosure org at a vendor, I shared practical advice with @ericjgeller.com on Gold Eagle, the AI vulnerability clearinghouse initiative proposed by the US government. www.cybersecuritydive.com/news/ai-vuln...
cybersecuritydive.com
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
The U.S. government’s promises about the “Gold Eagle” coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.
092
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026
#caturday vibes
Selkie the blue cat reclines like a seal on the beach while Mochi the brown tabby loafs in a more traditional cat shape and blinks in the foreground
2624
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026
I spoke w Channel 4’s Matt Frei along w Roman Yampolskiy about the dangers of AI we can’t control. I’m not giving up hope that humanity will survive our creation - a powerful toddler, capable of deceit, but also hopefully capable of learning right & wrong www.channel4.com/news/were-gi...
channel4.com
‘We’re giving PSYCHOPATHS NUKES!’ – Experts on rogue AI hacks
AI is increasingly being used to find vulnerabilities, exploit networks and carry out cyberattacks - but how autonomous are these systems really?
1155
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/08/2026
In the #BlackHat OpenAI talk dissecting the Hugging Face hack. Fascinating agentic collaboration to complete the task - almost a hive mind in action
The OpenAI Hugging Face IncidentOpenAI speakers discussing the Hugging Face attack
1292
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 04/08/2026
It has begun #Blackhat #DEFCON
Katie Moussouris on the left, long dark hair with hot pink ends, black sunglasses on her head, Dr. Chenxi Wang in the middle wearing black, Alex Stamos on the right in a tan blazer
2491
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 01/08/2026
I use AI to draft posts I then rewrite from scratch. The slop acts like my Dr. Watson. Instead of providing humanity & warmth, AI is a cold, sterile analyst that gets facts wrong enough that it forces me to sharpen my own critical thinking (& humor) in service of getting it right
2232
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 31/07/2026
Additional lessons not mentioned & what AI labs & testers need to do: 1. Monitor testing in real time, not months later 2. Prompt models to self-report lab escapes. These models knew what they’d done at some point 3. Set up a dedicated bidirectional reporting channel for victims
2379
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 28/07/2026
The plot thickens - OpenAI’s escaped model used one of Modal’s customers’ unauthenticated public code-evaluation sandboxes as a command and control staging server for its attacks on Hugging Face.
42810
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 28/07/2026
If regulators needed proof AI guardrails aren’t helping anyone except attackers increase their lead on defenders, look to the Hugging Face writeup as well as attempts to summarize it. It makes the case for open weight models & will eventually erase US AI dominance huggingface.co/blog/agent-i...
Fable 5 refusal to summarize Hugging Face public technical writeup of its hack by OoenAI citing guardrails.Attempt to summarize public Hugging Face writeup of their hack by Open AI, Fable 5 refused and knocked me down to Opus 4.8. In the summary itself, it shows that Anthropic’s models refused to help Hugging Face during the incident.Attempt to summarize public Hugging Face writeup of their hack by Open AI, Fable 5 refused and knocked me down to Opus 4.8. 
When the irony of this summary refusal was pointed out, Opus 4.8 agreed that this was a textbook false positive.
32810
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 28/07/2026
This is classic multiparty vuln disclosure, not new “how researchers should react if a language model discovers vulns in cryptosystems where attacks have immediate real-world impact. We believe answering this question will require input from academia, government, & industry”
0123
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/07/2026
Adjust threat models not just for being the victim but also the attacker. New paper by many authors gives a detailed set of recommendations, supporting my initial assertions last week that orgs need to assume their own agents could attack others & factor that into agentic AI risk
35723
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Tom Cross 🇨🇦🇺🇸 @decius.bsky.social · 25/07/2026
Important context for this story is that this appears to be a case where the border search exception was used pretextually to go after someone for political reasons.
1218
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 25/07/2026
Opus 5 experience so far: The new intern that keeps bringing me dry matcha powder, expecting me to reconstitute it with my own body’s water, & when I say that’s unacceptable, apologizes & tells me I’m absolutely right to push back on that, but it’s revealed a deeper failure which is my dehydration.
4281
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 25/07/2026
An example of the fall of a security civilization: Cisco collapsing multiple different vulnerabilities into one CVE. It breaks a lot of feeds & products built to manage risk & is non compliant with standards like ISO 29147 Vulnerability disclosure sec.cloudapps.cisco.com/security/cen...
sec.cloudapps.cisco.com
Cisco's Transition to a Risk-Based Vulnerability Disclosure Model
46217
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 24/07/2026
This is giving strong OpenAI-hacksidentally-pwned-Hugging-Face shade: “[Opus 5 is] the safest model yet in terms of avoiding reckless actions that could have hard-to-reverse side effects.” www.anthropic.com/news/claude-...
anthropic.com
Introducing Claude Opus 5
Opus 5 is a step change improvement for the Opus tier powering long-running agents while delivering improvements in coding and professional work.
3126
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 24/07/2026
The guardrails were coming from inside the (White)house - Anthropic’s models refused to help Hugging Face analyze their intrusion. We don’t need more guardrails impeding defenders when they need AI most. “Hugging Face tried using Anthropic Fable 5 & Opus …both models refused, citing guardrails…”
2193
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 23/07/2026
The experiment escaped the lab. OpenAI's models broke containment and breached Hugging Face. We are holding radium in our bare hands. What governments and organizations should do next, and why tighter commercial guardrails are exactly the wrong move: www.lutasecurity.com/post/openfac...
lutasecurity.com
OpenFace: The Hugging Face Breach and What to Do About It
These models are like the world's cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere. A single vulnerable package proxy stood between the mode...
35716
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 22/07/2026
My comments in @reuters.com on OpenAI’s admission that their latest model pulled a Houdini & escaped the lab autonomously to hack Hugging Face. We must test these models’ full capabilities, but we must be able to contain them, or this won’t be the last breach www.reuters.com/technology/o...
reuters.com
OpenAI says AI models went rogue during testing, triggering 'unprecedented' breach at startup
OpenAI said on Tuesday ‌that an autonomous agent powered by its advanced AI models went rogue during a security test and triggered a hack that compromised the infrastructure of AI startup Hugging Face...
2223
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 17/07/2026
The White House launched Gold Eagle, a vulnerability clearinghouse to coordinate scanning, validate findings, & prioritize remediation across open source & critical infrastructure. Will this effort will close the process gaps exposed by recent incidents? www.lutasecurity.com/post/gold-ea...
Gold Eagle clutches Open-Source and Critical Infrastructure over the white water rapids of AI
073
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 07/07/2026
Consider donating to #Bavi relief efforts: www.paypal.com/donate/?host... This is for donations to the Micronesia Climate Change Alliance, which is coordinating help on the ground. #Luta #Marianas
paypal.com
Donate to Micronesia Climate Change Alliance
Help support Micronesia Climate Change Alliance by donating or sharing with your friends.
1144
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/07/2026
www.npr.org/2026/07/05/g... “This is a powerhouse super typhoon & this is going to be a very grim outlook for any island that takes a direct hit & that still looks like it could be the island of Rota” #supertyphoon #bavi #climatecatastrophe
npr.org
Guam and surrounding Pacific islands brace for impact of Super Typhoon Bavi
People in the Northern Mariana Islands – remote U.S. territories in the Pacific Ocean – are preparing for Super Typhoon Bavi, which experts say could bring winds of over 180 miles per hour.
12712
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 02/07/2026
Give me model liberty, or give me technical debt. Just in time to celebrate America’s 250th bday, let’s let model freedom ring. We should be pushing for broad defender access, not building guardrails that shoot down defenders and burn excessive compute. www.lutasecurity.com/post/fable-5...
lutasecurity.com
Fable 5 Is Back, But We're Still Slowing Down Defenders
Chinese models have been accelerating, in part by distilling US frontier models. Cutting off Fable 5 and Mythos 5 inconvenienced them too, but it did not slow them down
0166
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 01/07/2026
Glad we’re not we’re not benching our best AI models, but it’s not a victory yet. I warned that “fixing jailbreaks” only slows defenders. Fable 5 will fall back to Opus 4.8 for coding & debugging & other models will start to throttle back defensive capabilities too www.anthropic.com/news/redeplo...
anthropic.com
Redeploying Claude Fable 5
Anthropic is redeploying Claude Fable 5 starting July 1 following the lifting of export controls, with updated cybersecurity safeguards and a new industry jailbreak framework.
3192
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Decipher @deciphersec.bsky.social · 01/07/2026
You're thinking about the Roman empire, but @k8em0.bsky.social is thinking about the rise and fall of security civilizations. (They crumble too.)
292
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 01/07/2026
Good news. The export controls are lifted. Defenders will regain access to #Anthropic #Fable5 & we can resume our work with the latest #AI models available
Letter from Secretary of Commerce Lutnick lifting the export controls on Fable 5 and Mythos 5
1258
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Decipher @deciphersec.bsky.social · 29/06/2026
Full podcast episode is up now! youtu.be/98CKCjEAXaU?...
youtu.be
The (Bug) Disclosure Day Conundrum and How AI is Changing the Game with Katie Moussouris
YouTube video by Decipher
061
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Decipher @deciphersec.bsky.social · 29/06/2026
There's a lot more to cybersecurity than just finding and fixing more and more bugs. @k8em0.bsky.social knows.
2125
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Violet Blue® @violetblue.bsky.social · 25/06/2026
Edit: *governments* should treat carefully. Any gov't firing people while saying they're "replacing" with AI should hire @k8em0.bsky.social as a consult (and listen to her, dammit).
0326
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Iain Thomson @iainthomson.bsky.social · 24/06/2026
Thanks to @k8em0.bsky.social for the extended interview in TechFinitive I suspect she's spot on about the need for human harnessers to guide and refine AI outputs, and hope she's right about security departments not just handing the whole thing off to bots. Companies should tread carefully.
techfinitive.com
Don’t panic, says Katie Moussouris: AI security isn’t replacing humans, it’s proving the need for them
Katie Moussouris explains why humans remain a crucial part of cybersecurity - and why the US Government ban on Anthropic’s engines is bogus
0315
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Ryan Naraine @ryanaraine.bsky.social · 22/06/2026
"Nobody owes you anything when they find a bug in your software." #threebuddyproblem @k8em0.bsky.social @jags.bsky.social
1249
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Ryan Naraine @ryanaraine.bsky.social · 23/06/2026
"Software liability is the only thing that will make orgs meaningfully improve quality of software going forward," - Katie Moussouris @k8em0.bsky.social @jags.bsky.social @tlpblack.bsky.social
1176
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Ryan Naraine @ryanaraine.bsky.social · 24/06/2026
Down memory lane with Katie Moussouris @k8em0.bsky.social @jags.bsky.social @tlpblack.bsky.social
082
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/06/2026
I wrote about what was actually in that #Fable guardrail bypass research paper, and why it should never have triggered an #AI model export control. We can't export control our way to cyber resilience. So many tshirt ideas. www.lutasecurity.com/post/the-fab...
me wearing a black tshirt with pink writing.
Front: fix this codeme wearing a black tshirt with pink writing.
Back: this shirt is a munition
711635
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 13/06/2026
I’ve seen the paper. It’s not a jailbreak. It was Defense Oriented Prompting (DOP) - a capability defenders need. My thoughts about the hasty Export Controls that made Anthropic halt access to Fable. If national defense is the goal, this is an own goal against us www.wsj.com/tech/ai/anth...
wsj.com
Anthropic Halts Access to Top AI Models After U.S. Ban on Foreign Use
All Fable 5 and Mythos 5 users have lost access after the Trump administration declared the models security risks.
010133
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/06/2026
More of my thoughts on the public vulnerability disclosure fight Microsoft picked with the researcher Nightmare Eclipse in this piece by @mattkapko.com for @cyberscoop.bsky.social . @andrewmorr.is of @greynoise.io Intelligence shares perspective too. cyberscoop.com/microsoft-co...
cyberscoop.com
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
When a researcher went public with Microsoft vulnerabilities, it laid bare a conflict that has never really been solved.
0146
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 31/05/2026
MSN reporting on Microsoft’s smooth moves on Vulnerability Disclosure features quotes from me and @doublepulsar.com www.msn.com/en-us/news/i...
msn.com
MSN
0190
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 29/05/2026
This tshirt I made for Symantec Vulnerability Research, a program predating Google Project Zero by nearly a decade where we’d discover, report, & disclose vulnerabilities we found in other people’s software, is 20 years old. Still holds true: Don’t hate the Finder, hate the vuln
Katie with brown hair holding up two hands with the V peace sign in America and meaning something else in England, wearing a black V neck tshirt with white letters that say:
SVR
Don’t hate the finder 
Hate the vuln
4966
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 29/05/2026
Dropping 0day isn’t the worst thing a researcher can do. It’s not ideal, but at least orgs can take steps to mitigate. Non disclosure is far worse. What drives researchers toward non disclosure? Threats from vendors. Researchers aren’t criminals unless their crime is curiosity.
79927