Sign in

mbg

@mbrg0.bsky.social
876 followers 7 following 28 posts

Breaking AI. Building @zenitysec, lead @owaspnocode, columnist @DarkReading

PostsRepliesMedia
mbg @mbrg0.bsky.social · 29/12/2025
"Claude’s ability to autonomously use dev tools s.a. reading network requests and executing JS poses great risk. Since the browser first appeared a great amount of effort was invested into preventing one of the worst web vulnerabilities out there. XSS. Roll in, Claude in Chrome... XSS-as-a-service."
100
mbg @mbrg0.bsky.social · 28/08/2025
we're stuck replicating the first AI-human interface that caught on The Chat we can do better www.mbgsec.com/posts/2025-0...
mbgsec.com
How Should AI Ask for Our Input?
How should we reason about machines taking over
000
Reposted by mbg
CYBERWARCON @cyberwarcon.bsky.social · 28/08/2025
043
mbg @mbrg0.bsky.social · 05/08/2025
’tis the season to be pwning #BHUSA
Agent Flayer comes for Microsoft Copilot, Copilot Studio Gemini, Agentforce, Cursor and ChatGPT
100
Reposted by mbg
Corey Quinn @quinnypig.com · 25/07/2025
You missed one thing in your (excellent) analysis: the attacker was clever enough to pull this off (and it is amazingly done), but still wasn't able to solve for Amazon Q CLI's dogshit ergonomics.
151
Reposted by mbg
Corey Quinn @quinnypig.com · 24/07/2025
AWS security bulletin: aws.amazon.com/security/sec... "This issue did not affect any production services or end-users." Weird how customer logs show the wiper prompt executing. Anyone else see "clean a system to a near-factory state" in your logs?
The malicious prompt in question displaying inside of a customer's Very Enterprisey(tm) endpoint security tooling during the attack window.
34913
mbg @mbrg0.bsky.social · 24/07/2025
After several hours of GitHub dorking on the Amazon Q infection we have: - hacker's user and intent - downloader - prompt payload - evasion techniques - timeline from july 13 thru was mitigation and cover big open questions: how did lkmanka58 gain initial access? is this the only user involved?
The malicious prompt
121
mbg @mbrg0.bsky.social · 19/07/2025
benchmarks go up attackers pwning like its the 90s www.mbgsec.com/posts/2025-0...
mbgsec.com
Why Aren’t We Making Any Progress In Security From AI
Soft boundaries are created by training AI real hard not to violate control flow, and hope that it doesn’t. Hackers don’t care about what happens most of the time.
000
mbg @mbrg0.bsky.social · 18/07/2025
0click chain on a copilot studio agent via email bypass msft's defense, jailbreak 4o, recon for accessible data, dump the entire salesforce crm one prompt labs.zenity.io/p/a-copilot-...
labs.zenity.io
A Copilot Studio Story 2: When AIjacking Leads to Full Data Exfiltration
Discover how prompt injections can lead to zero-click exploits threatening AI agents built using Copilot Studio. Learn about real-world risks, including data leakage and security blind spots. Bypass C...
010
mbg @mbrg0.bsky.social · 18/07/2025
this manus post has changed my todo for the weekend the way in which they constrain model logits by manipulating prefixes is brilliant manus.im/blog/Context...
manus.im
Context Engineering for AI Agents: Lessons from Building Manus
This post shares the local optima Manus arrived at through our own "SGD". If you're building your own AI agent, we hope these principles help you converge faster.
000
mbg @mbrg0.bsky.social · 13/05/2025
its been 9 months since #BHUSA and living off microsoft copilot ppl have been asking if things are better now well.. they are much better. but for whom? 😈😈😈 catch the sequel at hacker summer camp featuring very disturbing shenanigans @blackhatevents.bsky.social
101
mbg @mbrg0.bsky.social · 08/05/2025
an ai system is the top hacker at h1 us leaderboard www.mbgsec.com/posts/2025-0...
mbgsec.com
Fully-Autonomous AI Systems Are Discovering Vulnerabilities Today
This is part 2 on OpenAI’s Security Research Conference. Here is part 1.
000
mbg @mbrg0.bsky.social · 06/05/2025
incredible vibes at openai's security conf last week I came out both humbled and excited and with a greater conviction -- you can just do things!
openai security conf badge
100
mbg @mbrg0.bsky.social · 01/05/2025
AI vendors have been creating vuln disclosure programs asking that every bad prompt be responsibly disclosed blocking a specific prompt does little to protect users it creates an illusion of security that leaves users exposed www.mbgsec.com/posts/2025-0...
mbgsec.com
There Is Nothing Responsible About Disclosure Of Every Successful Prompt Injection
The InfoSec community is strongest when it can collaborate openly. Few organizations can fend off sophisticated attacks alone—and even they sometimes fail. If we all had to independently discover ever...
000
mbg @mbrg0.bsky.social · 01/05/2025
good morning folks! thanks again to everyone who attended my talks this week ai assistants create a new initial access vector prompt injection is not a bug to fix, its a problem to manage slides, hacking demos, security program -> labs.zenity.io/p/zenity-res...
labs.zenity.io
Zenity Research Published at RSAC 2025
Copilots and agents are a new access vector; How to build an AppSec program that scales to the level of citizen development
000
mbg @mbrg0.bsky.social · 29/04/2025
we conflate *the problem* with the term prompt injection the problem is that AI inherently does not follow instructions, and we act like it does it follows our goals, an attacker’s, or its own just the same attackers exploit this hijacking your AI for their goals www.mbgsec.com/posts/2025-0...
mbgsec.com
AIjacking Goes Beyond Prompt Injection
Naming is powerful. An excellent name does more than frame the problem, it hints at ownership, solutions, and urgency to address it. In a very real sense, they are like equivalence proofs in mathemat...
000
mbg @mbrg0.bsky.social · 04/12/2024
tmrw (Dec 5) at 10am PT Microsoft is releasing a convo by @donasarkar.bsky.social @sarahyo.com and I where we go into using m365 copilot & copilot studio securely this was a great attacker-defender interaction join us! we'll be there for live questions in comments
Copilot Learning Hub
Cautionary Tales: Everything You Need to Know About Security for Copilot
071
mbg @mbrg0.bsky.social · 20/11/2024
first time at INTENT met lots of talented folks and the vibes were great ty this was awesome!
Michael on stage at INTENT 2024
060
mbg @mbrg0.bsky.social · 17/11/2024
ok we’re having a sequel to living off microsoft copilot
060
mbg @mbrg0.bsky.social · 16/11/2024
Aaron Costello found 1.1 million NHS employee PII records exposed due to a Power Pages misconfig new powerpwn module is out! by avishai efrat and ofri nachfolger scan your environment for public facing Pages and Dataverse tables github.com/mbrg/power-p...
github.com
Modules: Power Pages
An offensive security toolset for Microsoft 365 focused on Microsoft Copilot, Copilot Studio and Power Platform - mbrg/power-pwn
000
mbg @mbrg0.bsky.social · 15/11/2024
is there any popular formal definition of the ‘halting problem’ for AI? i.e. can we build a kill switch?
000
mbg @mbrg0.bsky.social · 14/11/2024
55k devs 90k copilots 500k apps 1.1m automations 10m creds !
032
mbg @mbrg0.bsky.social · 14/11/2024
Microsoft has >1.5 million low-code/no-code apps including 90K bots and AI copilots this is how together we built a security program that managed to remediate 95% of vulns within 4m I’m really excited to finally be able to share this - www.youtube.com/watch?v=0jGU...
youtube.com
BlueHat 2024: S14: Scaling AppSec with an SDL for Citizen Development
YouTube video by Microsoft Security Response Center (MSRC)
021
mbg @mbrg0.bsky.social · 14/11/2024
hello world
040