Sign in

Gabriel

@morecoffeeplz.bsky.social
1.2K followers 500 following 441 posts

Distinguished AI Research Scientist at SentinelOne. Former OpenAI, Apple infosec. Lecturer at John’s Hopkins SAIS Alperovitch Institute. Deceiver of hike length and difficulty.

PostsRepliesMedia
Gabriel @morecoffeeplz.bsky.social · 06/07/2026
I wrote a blog about my approach to leveraging compaction in a reverse engineering harness. Tl;dr compaction is very helpful in our testing. 🧵 www.sentinelone.com/labs/context...
sentinelone.com
Context Engineering | Compaction & Agent Memory for Automated Malware Analysis
Compaction cut input tokens 86% across long-running agent evals with no quality loss. Context discipline matters as much as model selection.
111
Gabriel @morecoffeeplz.bsky.social · 29/05/2026
Velodrome for bicycle races, with mandatory dog in a sidecar.
020
Gabriel @morecoffeeplz.bsky.social · 25/04/2026
Before Stuxnet, there was fast16, a malware built for quiet sabotage. It didn’t break centrifuges, wipe disks or steal secrets. It targeted computation itself: patching engineering and simulation software as it loaded to subtly corrupt floating-point calculations for an entire lab. s1.ai/fast16
s1.ai
fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet
A previously unknown 2005 cyber sabotage framework patches high-precision calculation software in memory to silently corrupt results.
150
Gabriel @morecoffeeplz.bsky.social · 10/04/2026
@notalawyer.bsky.social @michaelhobbes.bsky.social The news cycle continues to bring fresh horrors, but Eric Adams is now an Albania citizen and we need an emergency IBCK update. (Also did you end up getting that seiko presage?)
011
Gabriel @morecoffeeplz.bsky.social · 19/03/2026
More great research from @philofishal.bsky.social evaluating LLMs for Malware Analysis. s1.ai/advers-llm - Multi-agent architecture for reversing macOS malware. - Each tool output as independent input for robust analysis - Specific deterministic bridge scripts for tool integrations
sentinelone.com
Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis
Single-tool LLM analysis produces reports that look authoritative but aren't. A serial consensus pipeline catches artifacts and hallucinations at source.
110
Gabriel @morecoffeeplz.bsky.social · 14/03/2026
Looking for an internship in AI Cybersecurity? We’re running AI-driven security challenges at NEBULA:FOG's hackathon today. Join us: nebulafog.ai/challenges I’ll be there live giving updates.
nebulafog.ai
Challenge Tracks | NEBULA:FOG 2026 AI x Security Hackathon
4 AI security hackathon tracks: adversarial AI, defense systems, zero-knowledge proofs, autonomous agents. $5K+ prizes. March 14, SF.
012
Gabriel @morecoffeeplz.bsky.social · 10/03/2026
I’ll be running panels at this event and helping out. There’s still plenty of room and we are looking for any AI/ML students in the bay who want to attend! And it’s free!
111
Gabriel @morecoffeeplz.bsky.social · 14/02/2026
This is a pretty important statement about engineering and experimentation speed. openai.com/index/harnes...
openai.com
Harness engineering: leveraging Codex in an agent-first world
By Ryan Lopopolo, Member of the Technical Staff
000
Gabriel @morecoffeeplz.bsky.social · 13/02/2026
Mossad or not-Mossad, but for model evals needing to be difficult, but not so difficult that they are written off as not a useful measurement.
010
Gabriel @morecoffeeplz.bsky.social · 29/01/2026
Everybody has a hard eval until gradient descent punches you in the face.
010
Gabriel @morecoffeeplz.bsky.social · 29/01/2026
New research from @silascutler.bsky.social and myself. We tracked 175k exposed Ollama endpoints for nearly a year. Collected and analyzed custom models, sizes, quantizations, system prompts, and more.
131
Gabriel @morecoffeeplz.bsky.social · 29/01/2026
*vague posts about upcoming research*
000
Gabriel @morecoffeeplz.bsky.social · 28/01/2026
Love getting malware under TLP:AMBER+S, when the S stands for “spite”. 🫖
000
Gabriel @morecoffeeplz.bsky.social · 27/01/2026
We about to have some Llama Drama :)
111
Reposted by Gabriel
ms foil @msfoil.xyz · 26/01/2026
and of course it’s chatgpt slop with the rhetorical flourish of a remedial high school debate club. “from X to Y — or worse” “This Isn’t X it’s Y.” “Replace X with Y and it’s Z.” “The most sobering part? It’s X.” “your no longer dealing with X. You’re facing Y”
022
Gabriel @morecoffeeplz.bsky.social · 26/01/2026
“Wow this dude has a really strong opinion about code review” *scans posts* “Oh that’s his only opinion”
000
Gabriel @morecoffeeplz.bsky.social · 23/01/2026
—dangerously-skip-permissions is the only thing keeping claude code installed on my machine.
000
Gabriel @morecoffeeplz.bsky.social · 20/01/2026
Benchmarks for cybersecurity are everywhere and mostly measuring the wrong thing. We reviewed evals from Microsoft, Meta and academia and found they don't measure what matters for defenders in real IR situations. 🧵 s1.ai/benchmk1
s1.ai
LLMs in the SOC (Part 1) | Why Benchmarks Fail Security Operations Teams
LLM cybersecurity benchmarks fail to measure what defenders need: faster detection, reduced containment time, and better decisions under pressure.
143
Gabriel @morecoffeeplz.bsky.social · 20/01/2026
Reviewing AI cyber benchmarking and evaluations may break me. Ya’ll will really LLM as a judge anything
000
Reposted by Gabriel
Kevin M. Kruse @kevinmkruse.bsky.social · 15/01/2026
Holy hell, what an obituary
nytimes.com
Renfrew Christie Dies at 76; Sabotaged Racist Regime’s Nuclear Program
17648801642
Gabriel @morecoffeeplz.bsky.social · 14/01/2026
Timely presentation from my colleague Jim on the current landscape of Hactivism and War. youtu.be/sNaORI-k-fY?...
youtu.be
LABScon25 Replay | Hacktivism and War: A Clarifying Discussion | Jim Walter
YouTube video by SentinelOne
010
Reposted by Gabriel
SentinelLABS @sentinellabs.bsky.social · 13/01/2026
✅ #LLM literacy is table stakes for defenders, CTI analysts, and #cybersecurity professionals of all stripes now. Still looking for a way into this complex field? 🤔 LABS has got you covered! Start here: s1.ai/inside-llm-1 @sentinelone.com
s1.ai
Inside the LLM | Understanding AI & the Mechanics of Modern Attacks
Learn how attackers exploit tokenization, embeddings and LLM attention mechanisms to bypass LLM security filters and hijack model behavior.
043
Gabriel @morecoffeeplz.bsky.social · 13/01/2026
Great post from @philofishal.bsky.social on the initials stages of the LLM training pipeline! www.sentinelone.com/labs/inside-...
sentinelone.com
Inside the LLM | Understanding AI & the Mechanics of Modern Attacks
Learn how attackers exploit tokenization, embeddings and LLM attention mechanisms to bypass LLM security filters and hijack model behavior.
030
Reposted by Gabriel
Dr Karl Kruszelnicki @doctorkarl.bsky.social · 10/01/2026
"this new chemical process operates at ambient temperature and pressure. It chemically dissolves the glue holding the blade together. The high-value carbon fiber can be recovered, cleaned, and reused in everything from new turbines to car parts." interestingengineering.com/energy/china...
interestingengineering.com
Ming Yang unveils world’s first fully recyclable wind turbine blade
Chinese energy giant Ming Yang Smart Energy has developed the “world’s first fully recyclable carbon fiber wind turbine blade.”
14482130
Reposted by Gabriel
ms foil @msfoil.xyz · 03/01/2026
‘CURTAINS FOR OPSEC? T-SMOG AND FRATBOY CAUGHT FLIPPING A GOV’
021
Reposted by Gabriel
Adam Serwer @adamserwer.bsky.social · 03/01/2026
Among the many reasons you don’t kidnap a foreign head of state at gunpoint even if you have the capability, is that it sparks consequences you can neither control nor anticipate.
360197494396
Reposted by Gabriel
paul khruangbin (Dan Lehner) @danlehner.bsky.social · 02/01/2026
Bill Watterson could do Sin City but Frank Miller could not do Calvin and Hobbes
373696957
Reposted by Gabriel
Seva @seva.bsky.social · 30/12/2025
everyone thinks they’re a bayesian until they have to update their priors
424642
Reposted by Gabriel
Silas Cutler @silascutler.bsky.social · 23/12/2025
I'm speaking at the @SANSInstitute #CTISummit on an operation against #Rhadamanthys years before #OperationEndgame. www.sans.org/u/1CtB
092
Gabriel @morecoffeeplz.bsky.social · 15/12/2025
More research and observations on LLMs and Ransomware from me and the team! www.sentinelone.com/labs/llms-ra...
sentinelone.com
LLMs & Ransomware | An Operational Accelerator, Not a Revolution
LLMs make competent ransomware crews faster and novices more dangerous. The risk is not superintelligent malware, but rather industrialized extortion.
100
Gabriel @morecoffeeplz.bsky.social · 09/12/2025
For anybody interested, my teammates and I wrote some predictions for next year.: www.sentinelone.com/blog/cyberse... thread below with some thoughts.
sentinelone.com
Cybersecurity 2026 | The Year Ahead in AI, Adversaries, and Global Change
Explore SentinelLABS' take on what 2026 may bring for cybersecurity, including emerging trends and actionable insights.
142
Gabriel @morecoffeeplz.bsky.social · 02/12/2025
Scribbling in the margins of these LLM cyber capability evaluations: “horse difficulty has not been solved… absolutely nothing exists, which is scandalous!… unpreparedness disgraceful…  horse question in disgraceful state!”
000
Gabriel @morecoffeeplz.bsky.social · 01/12/2025
What questions do folks have about the global use of open source models?
010
Reposted by Gabriel
P(aul) Frazee @pfrazee.com · 27/11/2025
The kinds of databases: • Fancy files • 1970s stays winning • This would be so cool if it worked at scale • Oh, that's why google has a monopoly on search
1945646
Reposted by Gabriel
ms foil @msfoil.xyz · 21/11/2025
photo of Kendrick Lamar at the super bowl halftime show performing “Not Like Us” and calling Drake a pedophile
021
Reposted by Gabriel
sina @rejectionking.bsky.social · 18/11/2025
so you’re telling me that olives nuzzi isnt some sort of pasta dish?
171
Gabriel @morecoffeeplz.bsky.social · 15/11/2025
“Our model is very dangerous, but also not quite functional enough to cause damage Also here are no indicators that the community could use to identify more abuse.” Cmon folks, if you are serious about stopping AI abuse then let’s see less marketing and more actionable intel.
030
Reposted by Gabriel
Chris Paxton @cpaxton.bsky.social · 14/11/2025
DepthAnything3 slam
0191
Reposted by Gabriel
Kat Abughazaleh @katmabu.bsky.social · 05/11/2025
Good things are possible and we don’t have to settle.
246463558008
Reposted by Gabriel
Alex Pinto @alexcp.bsky.social · 03/11/2025
2026 DBIR sneak peek: “Water plays an increasingly significant role in [ransomware] attacks. In 2024, 100% of recorded ransomware events were attributed to threat actors that drink water”
131
Gabriel @morecoffeeplz.bsky.social · 03/11/2025
Our presentation from LabsCon25 for those who missed it - LLM Enabled Malware In The Wild. www.sentinelone.com/labs/labscon...
sentinelone.com
LABScon25 Replay | LLM-Enabled Malware In the Wild
Learn how to detect malware that generates code at runtime. SentinelLABS reveals hunting techniques and how to uncover novel AI-enabled threats.
041
Gabriel @morecoffeeplz.bsky.social · 31/10/2025
I miss when the internet was fun.
120
Reposted by Gabriel
Eugene Vinitsky 🍒 @eugenevinitsky.bsky.social · 23/10/2025
What if we did a single run and declared victory
Three panel thing. In the left panel we use error bars. In the second, we take statistical significance as the biggest number but still have error bars. In LLM science, we just have the biggest number
1333570
Reposted by Gabriel
sfbike.org @sfbike.org · 20/10/2025
"Sunset Dunes is a testament to what happens when San Francisco thinks big and invests in public spaces. [...] And it reminds us that we shouldn’t let fear of change keep us from imagining something better for our neighborhoods." www.sfchronicle.com/opinion/open...
sfchronicle.com
We’re small business owners in the Sunset. Reopening the Great Highway is the last thing we need
OPINION: Some candidates hoping to replace Supervisor Joel Engardio are pledging to reopen the Great Highway and close Sunset Dunes park. That’s a mistake, Britt-Marie Alm and Poppy Gilman write.
042
Gabriel @morecoffeeplz.bsky.social · 16/10/2025
The only people I know that refer to ChatGPT as “Chat” are those in romantic relationships with it. nypost.com/2025/10/16/b...
150
Reposted by Gabriel
Meredith Whittaker @meredithmeredith.bsky.social · 16/10/2025
"I don't have anything to hide why should I care about privacy?"
12410167
Reposted by Gabriel
🦇🎃💀 Riana-mator 💀🎃🦇 @riana.bsky.social · 15/10/2025
Normal person: I asked AI and it told me-- Every AI researcher:
02211
Reposted by Gabriel
sina @rejectionking.bsky.social · 14/10/2025
“What if you could fuck the singularity?” is the apotheosis of technofuturism (2025)
Dr McCoy in peak bisexual lighting The VibeCamp Archipelago So the nightmwate begins NSA and FBI just shocked at what they are seeing
083
Reposted by Gabriel
Sheryl Gay Stolberg @sherylnyt.bsky.social · 11/10/2025
BREAKING: Friday night massacre underway at CDC. Doznes of "disease detectives," high-level scientists, entire Washington staff and editors of the MMWR (Morbidity and Mortality Weekly Report) have all been RIFed and received the following notice:
833152088340