Sign in

Katie Moussouris (she/her/she-hulk/she-ra)🌻

@k8em0.bsky.social
22K followers 1.2K following 1.4K posts

Founder & CEO LutaSecurity @payequitynow MIT&Harvard visiting scholar, @MasonNatSec fellow, 1/2 Chamoru, 1/2 Greek all-American hacker

PostsRepliesMedia
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
bryan newbold @bnewbold.net · 07/10/2026
ah damn, RIP Margaret Hamilton. she took safety-critical software engineering seriously, and got people to the moon and back. news.mit.edu/2026/margare...
old photos of a woman (Margaret Hamilton) standing next to a tall stack of books (printouts of Apollo space mission software source code)
101142344687
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 06/10/2026
Literally what I said 🤣
130
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 06/10/2026
May not keep individuals from moving their security work to GLM 5.3 and beyond, but it will give enterprises already comfortable with frontier model pricing a path to stay www.anthropic.com/news/cyber-v...
anthropic.com
Expanding the Cyber Verification Program
We’re launching a new, expanded version of our Cyber Verification Program (CVP), which makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals...
171
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 02/10/2026
In case it’s hard to tell what I’m actually saying here: Slowing down vulnerability disclosure is to cybersecurity as drinking sea water is to dehydration. Might feel better if you’re desperate but it will greatly accelerate your doom. This isn’t a fix for vuln process saturation
03314
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 02/10/2026
Can’t tell if AI replied 
Or they can’t detect sarcasm in my post
0121
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 02/10/2026
Happy #Cybersecurity awareness month! Be aware that even the most well-funded orgs can’t handle floods of AI-generated OSS bug reports. Now every maintainer can get vuln reports slower than ever with GitHub rate limits for new security reports. Pace the defense frontier!
Open source maintainers are receiving more low-quality and automated vulnerability reports, which can bury the reports that matter. Rate limits cap how many new reports a single account can submit in a day, both to your repository and across GitHub. This helps protect you from bulk and automated submissions, while legitimate researchers can still reach you.

With this update:

Private vulnerability reporting now applies daily per-user rate limits to new reports.
Reporters who reach a limit see a message asking them to try again later.
Limits apply only to new reports. Comments on existing advisories aren’t affected.
Repository administrators can set a custom daily overall reporting limit for their repository.
Repository administrators can add trusted reporters to an allow list so they’re never rate limited.
To configure these settings, go to your repository’s settings, select Advanced Security, and click Settings next to “Private vulnerability reporting.”PSA for open-source bug hunters

We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program.

Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027.Product vulnerabilities 

As of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP. For some Google Cloud repos impacting Google Cloud products we may still accept reports covering product vulnerabilities through the Cloud VRP. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027. In the meantime, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program. This change does not affect product vulnerabilities submitted before October 1, 2026.

Any design or implementation issue in Google OSS that causes a product vulnerability substantially affecting the confidentiality or integrity of user data in software builds using Google OSS is also in scope for the program. Some examples:
4407
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 30/09/2026
The intended audience & effect is toward regulating open weight models, so security teams switching to them to avoid refusals will be temporary. It’s a “loss leader” marketing move & will likely achieve its desired effect, unless a national security case can be made to stop it.
1112
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 25/09/2026
“Restraint itself can be a signal.” Read more from the brilliant @saffronsec.bsky.social in @bindinghook.bsky.social on the relationship between cyber and kinetic conflict as observed in the Iran war
153
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 24/09/2026
My thoughts on CISA’s future of CVE white paper along with @sawaba.bsky.social Let’s hope Congress backs enough budget at CISA to hire the human expert resources to guide what will also require heavy automation investment. Thanks @shaunwaterman.bsky.social www.bankinfosecurity.com/cisa-lays-ou...
bankinfosecurity.com
CISA Lays Out Future of CVE Vulnerability Program
The U.S. Cybersecurity and Infrastructure Security Agency published a short whitepaper Wednesday, laying out four "dimensions of quality" it will pursue
1146
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 22/09/2026
Today in AI: 🤙🏼
Two buttons meme with buttons labeled “Pace the frontier” and “Release new models”. Both buttons are being pressed at once in the upper panel, and the guy smiling with a thumbs up in the lower panel is captioned “Frontier AI”
2276
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 20/09/2026
I’m speechless all over again. 😭 Thanks for including me in this week’s Good News Corner of your weekinsecurity.com newsletter @zackwhittaker.com ! And thanks forever to the @sentinelone.com SentinelLabs LABSCON crew & community for bringing knowledge & magic people together all these years 💜💖🎉
weekinsecurity.com
~this week in security~
a weekly cybersecurity newsletter by Zack Whittaker, plus articles and more.
0163
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 17/09/2026
Beyond honored to receive the last #LABSCon #SentinelLabs Lifetime Achievement Award 🥇
LABS
CON
2026

Lifetime Achievement

Katie Moussouris 

For voicing or conscience from the Pentagon to the karaoke bar
8877
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 08/09/2026
Heard about the [un]prompted AI security conference but can’t afford the conference fee? There’s a scholarship program that covers the cost of the registration! Apply here: docs.google.com/forms/d/e/1F...
docs.google.com
[Un]prompted Scholarship Program Application
The [un]prompted conference is one of the most important gatherings of AI security researchers and practitioners. The Decibel Scholarship Program was created to provide financial assistance to attende...
11410
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/08/2026
While I agree in general, this open letter from frontier models and tech companies is giving some heavy AI adoption vibes openai.com/collective-c...
Homer Simpson toasts to a crowd with a mug of beer while standing atop casks: To AI, the cause of and solution to all of life’s problems
0193
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 26/08/2026
I’m on the CFP review board for [un]prompted. Submit your talks ASAP - don’t make us pull any all-nighters to read your abstract
190
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 26/08/2026
Follow the money, ignore the manifesto. My thoughts on the GTA VI leaks shared with @mattkapko.com for @cyberscoop.bsky.social along with comments from Cynthia Kaiser, Zach Edwards, and Ben Bernstein cyberscoop.com/grand-theft-...
cyberscoop.com
The GTA VI leaks are breaking the internet. Security researchers have seen this before.
A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience.
0141
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Chantal James @chantalalive.blacksky.app · 25/08/2026
The whole time Dolly Parton was being one of music's greatest songwriters & performers, & one of the world's greatest humanitarians & champions for literacy, & accepting of queer & trans people, get this. She never let up on being a hot girl shaking ass looking fabulous with her proud huge boobs.
3583134
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 19/08/2026
You’ll get it next batch, I believe in you
020
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 19/08/2026
Outstanding!
110
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
*curtseys in your direction*
010
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
This is what victory looks like:
A bowl of mango chia pudding topped with red raspberries and granola held triumphantly in my left hand, a spoon dug in on the right side, awaiting quick use
1280
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
I believe in you
110
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
So sweet and so cold
060
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
They couldn’t stop me. Only I could stop me
000
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
Success tastes so sweet
110
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
It’s all downhill from here
010
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
I just need some acknowledgment that I ate all the raspberries in the fridge before they got moldy and this may be unprecedented success
151725
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026
Having created Microsoft Vuln Research, the 1st multiparty vuln disclosure org at a vendor, I shared practical advice with @ericjgeller.com on Gold Eagle, the AI vulnerability clearinghouse initiative proposed by the US government. www.cybersecuritydive.com/news/ai-vuln...
cybersecuritydive.com
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
The U.S. government’s promises about the “Gold Eagle” coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.
092
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 16/08/2026
Eli sounds like he was a proper cat curmudgeon. Memory eternal 💖
000
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026
The belly is absolutely a trap
010
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026
Selkie (the long one) is always up for a cuddle. Mochi is a traditional cat who will choose the time, place, and duration of any cuddling & reserves the right to change his mind immediately
130
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026
They are the chillest 😎
000
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026
#caturday vibes
Selkie the blue cat reclines like a seal on the beach while Mochi the brown tabby loafs in a more traditional cat shape and blinks in the foreground
2624
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026
I spoke w Channel 4’s Matt Frei along w Roman Yampolskiy about the dangers of AI we can’t control. I’m not giving up hope that humanity will survive our creation - a powerful toddler, capable of deceit, but also hopefully capable of learning right & wrong www.channel4.com/news/were-gi...
channel4.com
‘We’re giving PSYCHOPATHS NUKES!’ – Experts on rogue AI hacks
AI is increasingly being used to find vulnerabilities, exploit networks and carry out cyberattacks - but how autonomous are these systems really?
1155
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/08/2026
Hugging face also detected it and that’s where their public report came from. OpenAI’s start of the incident dates back to May but it wasn’t yet attacking hugging face at that time, just busy breaking out of the test environment.
030
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/08/2026
OpenAI didn’t detect this attack until July 19 and it began in early May. They are stepping up their detection and monitoring. You should too
1131
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/08/2026
TIL agents swear “Holy shit…” thought the model to itself when it achieved admin access
1181
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/08/2026
In the #BlackHat OpenAI talk dissecting the Hugging Face hack. Fascinating agentic collaboration to complete the task - almost a hive mind in action
The OpenAI Hugging Face IncidentOpenAI speakers discussing the Hugging Face attack
1292
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 04/08/2026
It has begun #Blackhat #DEFCON
Katie Moussouris on the left, long dark hair with hot pink ends, black sunglasses on her head, Dr. Chenxi Wang in the middle wearing black, Alex Stamos on the right in a tan blazer
2491
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 01/08/2026
I use AI to draft posts I then rewrite from scratch. The slop acts like my Dr. Watson. Instead of providing humanity & warmth, AI is a cold, sterile analyst that gets facts wrong enough that it forces me to sharpen my own critical thinking (& humor) in service of getting it right
2232
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 31/07/2026
Additional lessons not mentioned & what AI labs & testers need to do: 1. Monitor testing in real time, not months later 2. Prompt models to self-report lab escapes. These models knew what they’d done at some point 3. Set up a dedicated bidirectional reporting channel for victims
2379
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 31/07/2026
Aww thank you! 🙏🏼 🙌🏼
010
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 29/07/2026
Hugging Face couldn’t get Anthropic’s models to help them analyze the attacks during the incident itself. Then today Fable 5 refused to summarize Hugging Face’s public post & downgraded me to Opus 4.8, later admitting that flagging my request was clearly a false positive. Guardrails failed defenders
142
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 28/07/2026
The plot thickens - OpenAI’s escaped model used one of Modal’s customers’ unauthenticated public code-evaluation sandboxes as a command and control staging server for its attacks on Hugging Face.
42810
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 28/07/2026
If regulators needed proof AI guardrails aren’t helping anyone except attackers increase their lead on defenders, look to the Hugging Face writeup as well as attempts to summarize it. It makes the case for open weight models & will eventually erase US AI dominance huggingface.co/blog/agent-i...
Fable 5 refusal to summarize Hugging Face public technical writeup of its hack by OoenAI citing guardrails.Attempt to summarize public Hugging Face writeup of their hack by Open AI, Fable 5 refused and knocked me down to Opus 4.8. In the summary itself, it shows that Anthropic’s models refused to help Hugging Face during the incident.Attempt to summarize public Hugging Face writeup of their hack by Open AI, Fable 5 refused and knocked me down to Opus 4.8. 
When the irony of this summary refusal was pointed out, Opus 4.8 agreed that this was a textbook false positive.
32810
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 28/07/2026
This is classic multiparty vuln disclosure, not new “how researchers should react if a language model discovers vulns in cryptosystems where attacks have immediate real-world impact. We believe answering this question will require input from academia, government, & industry”
0123
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/07/2026
bsky.app/profile/rept...
011
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/07/2026
Well there’s a draft AI Kill Switch Act that would levy fines of $2M per day for failing to turn off rogue AI. That’s a little spicy future leverage.
162
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/07/2026
My blog last week also summarizes what government should and should not do in response to Open AI’s Agentic hack of Hugging Face bsky.app/profile/k8em...
lutasecurity.com
OpenFace: The Hugging Face Breach and What to Do About It
These models are like the world's cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere. A single vulnerable package proxy stood between the mode...
0101
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/07/2026
Adjust threat models not just for being the victim but also the attacker. New paper by many authors gives a detailed set of recommendations, supporting my initial assertions last week that orgs need to assume their own agents could attack others & factor that into agentic AI risk
35723