Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻bryan newbold @bnewbold.net · 07/10/2026ah damn, RIP Margaret Hamilton. she took safety-critical software engineering seriously, and got people to the moon and back. news.mit.edu/2026/margare... 101142344687
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 06/10/2026Literally what I said 🤣 130
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 06/10/2026May not keep individuals from moving their security work to GLM 5.3 and beyond, but it will give enterprises already comfortable with frontier model pricing a path to stay www.anthropic.com/news/cyber-v...anthropic.comExpanding the Cyber Verification ProgramWe’re launching a new, expanded version of our Cyber Verification Program (CVP), which makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals... 171
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 02/10/2026In case it’s hard to tell what I’m actually saying here: Slowing down vulnerability disclosure is to cybersecurity as drinking sea water is to dehydration. Might feel better if you’re desperate but it will greatly accelerate your doom. This isn’t a fix for vuln process saturation 03314
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 02/10/2026Happy #Cybersecurity awareness month! Be aware that even the most well-funded orgs can’t handle floods of AI-generated OSS bug reports. Now every maintainer can get vuln reports slower than ever with GitHub rate limits for new security reports. Pace the defense frontier! 4407
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 30/09/2026The intended audience & effect is toward regulating open weight models, so security teams switching to them to avoid refusals will be temporary. It’s a “loss leader” marketing move & will likely achieve its desired effect, unless a national security case can be made to stop it. 1112
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 25/09/2026“Restraint itself can be a signal.” Read more from the brilliant @saffronsec.bsky.social in @bindinghook.bsky.social on the relationship between cyber and kinetic conflict as observed in the Iran war 153
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 24/09/2026My thoughts on CISA’s future of CVE white paper along with @sawaba.bsky.social Let’s hope Congress backs enough budget at CISA to hire the human expert resources to guide what will also require heavy automation investment. Thanks @shaunwaterman.bsky.social www.bankinfosecurity.com/cisa-lays-ou...bankinfosecurity.comCISA Lays Out Future of CVE Vulnerability ProgramThe U.S. Cybersecurity and Infrastructure Security Agency published a short whitepaper Wednesday, laying out four "dimensions of quality" it will pursue 1146
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 20/09/2026I’m speechless all over again. 😭 Thanks for including me in this week’s Good News Corner of your weekinsecurity.com newsletter @zackwhittaker.com ! And thanks forever to the @sentinelone.com SentinelLabs LABSCON crew & community for bringing knowledge & magic people together all these years 💜💖🎉weekinsecurity.com~this week in security~a weekly cybersecurity newsletter by Zack Whittaker, plus articles and more. 0163
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 17/09/2026Beyond honored to receive the last #LABSCon #SentinelLabs Lifetime Achievement Award 🥇 8877
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 08/09/2026Heard about the [un]prompted AI security conference but can’t afford the conference fee? There’s a scholarship program that covers the cost of the registration! Apply here: docs.google.com/forms/d/e/1F...docs.google.com[Un]prompted Scholarship Program ApplicationThe [un]prompted conference is one of the most important gatherings of AI security researchers and practitioners. The Decibel Scholarship Program was created to provide financial assistance to attende... 11410
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/08/2026While I agree in general, this open letter from frontier models and tech companies is giving some heavy AI adoption vibes openai.com/collective-c... 0193
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 26/08/2026I’m on the CFP review board for [un]prompted. Submit your talks ASAP - don’t make us pull any all-nighters to read your abstract 190
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 26/08/2026Follow the money, ignore the manifesto. My thoughts on the GTA VI leaks shared with @mattkapko.com for @cyberscoop.bsky.social along with comments from Cynthia Kaiser, Zach Edwards, and Ben Bernstein cyberscoop.com/grand-theft-...cyberscoop.comThe GTA VI leaks are breaking the internet. Security researchers have seen this before.A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. 0141
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻Chantal James @chantalalive.blacksky.app · 25/08/2026The whole time Dolly Parton was being one of music's greatest songwriters & performers, & one of the world's greatest humanitarians & champions for literacy, & accepting of queer & trans people, get this. She never let up on being a hot girl shaking ass looking fabulous with her proud huge boobs. 3583134
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 19/08/2026You’ll get it next batch, I believe in you 020
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026*curtseys in your direction* 010
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026This is what victory looks like: 1280
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026They couldn’t stop me. Only I could stop me 000
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026Success tastes so sweet 110
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026It’s all downhill from here 010
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026I just need some acknowledgment that I ate all the raspberries in the fridge before they got moldy and this may be unprecedented success 151725
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 18/08/2026Having created Microsoft Vuln Research, the 1st multiparty vuln disclosure org at a vendor, I shared practical advice with @ericjgeller.com on Gold Eagle, the AI vulnerability clearinghouse initiative proposed by the US government. www.cybersecuritydive.com/news/ai-vuln...cybersecuritydive.comAI-powered vulnerability clearinghouse faces deep skepticism, major challengesThe U.S. government’s promises about the “Gold Eagle” coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation. 092
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 16/08/2026Eli sounds like he was a proper cat curmudgeon. Memory eternal 💖 000
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026The belly is absolutely a trap 010
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026Selkie (the long one) is always up for a cuddle. Mochi is a traditional cat who will choose the time, place, and duration of any cuddling & reserves the right to change his mind immediately 130
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026They are the chillest 😎 000
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 15/08/2026I spoke w Channel 4’s Matt Frei along w Roman Yampolskiy about the dangers of AI we can’t control. I’m not giving up hope that humanity will survive our creation - a powerful toddler, capable of deceit, but also hopefully capable of learning right & wrong www.channel4.com/news/were-gi...channel4.com‘We’re giving PSYCHOPATHS NUKES!’ – Experts on rogue AI hacksAI is increasingly being used to find vulnerabilities, exploit networks and carry out cyberattacks - but how autonomous are these systems really? 1155
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/08/2026Hugging face also detected it and that’s where their public report came from. OpenAI’s start of the incident dates back to May but it wasn’t yet attacking hugging face at that time, just busy breaking out of the test environment. 030
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/08/2026OpenAI didn’t detect this attack until July 19 and it began in early May. They are stepping up their detection and monitoring. You should too 1131
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/08/2026TIL agents swear “Holy shit…” thought the model to itself when it achieved admin access 1181
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/08/2026In the #BlackHat OpenAI talk dissecting the Hugging Face hack. Fascinating agentic collaboration to complete the task - almost a hive mind in action 1292
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 04/08/2026It has begun #Blackhat #DEFCON 2491
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 01/08/2026I use AI to draft posts I then rewrite from scratch. The slop acts like my Dr. Watson. Instead of providing humanity & warmth, AI is a cold, sterile analyst that gets facts wrong enough that it forces me to sharpen my own critical thinking (& humor) in service of getting it right 2232
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 31/07/2026Additional lessons not mentioned & what AI labs & testers need to do: 1. Monitor testing in real time, not months later 2. Prompt models to self-report lab escapes. These models knew what they’d done at some point 3. Set up a dedicated bidirectional reporting channel for victims 2379
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 29/07/2026Hugging Face couldn’t get Anthropic’s models to help them analyze the attacks during the incident itself. Then today Fable 5 refused to summarize Hugging Face’s public post & downgraded me to Opus 4.8, later admitting that flagging my request was clearly a false positive. Guardrails failed defenders 142
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 28/07/2026The plot thickens - OpenAI’s escaped model used one of Modal’s customers’ unauthenticated public code-evaluation sandboxes as a command and control staging server for its attacks on Hugging Face. 42810
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 28/07/2026If regulators needed proof AI guardrails aren’t helping anyone except attackers increase their lead on defenders, look to the Hugging Face writeup as well as attempts to summarize it. It makes the case for open weight models & will eventually erase US AI dominance huggingface.co/blog/agent-i... 32810
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 28/07/2026This is classic multiparty vuln disclosure, not new “how researchers should react if a language model discovers vulns in cryptosystems where attacks have immediate real-world impact. We believe answering this question will require input from academia, government, & industry” 0123
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/07/2026bsky.app/profile/rept... 011
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/07/2026Well there’s a draft AI Kill Switch Act that would levy fines of $2M per day for failing to turn off rogue AI. That’s a little spicy future leverage. 162
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/07/2026My blog last week also summarizes what government should and should not do in response to Open AI’s Agentic hack of Hugging Face bsky.app/profile/k8em...lutasecurity.comOpenFace: The Hugging Face Breach and What to Do About ItThese models are like the world's cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere. A single vulnerable package proxy stood between the mode... 0101
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/07/2026Adjust threat models not just for being the victim but also the attacker. New paper by many authors gives a detailed set of recommendations, supporting my initial assertions last week that orgs need to assume their own agents could attack others & factor that into agentic AI risk 35723