Sign in

omkhar

@omkhar.net
501 followers 58 following 509 posts

Security guy. Website: omkhar.net Scholarship: skscholarship.com Twitter/X: x.com/omkhar Mastodon: infosec.exchange/@Omkhar Bluesky: bsky.app/profile/omkhar.net LinkedIn: linkedin.com/in/omkhar

PostsRepliesMedia
omkhar @omkhar.net · 11/09/2026
000
omkhar @omkhar.net · 07/08/2026
If you haven’t watched this BlackHat talk about the OpenAI / huggingface incident, give it a watch. I can’t wait to see the full post mortem. youtu.be/87DyyMV0kCY
youtu.be
Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident
YouTube video by Black Hat
000
omkhar @omkhar.net · 27/07/2026
Wanna secure AI for 30K employees and over a billion members? Come work with us in LinkedIn InfoSec! www.linkedin.com/jobs/view/44... FAQ: * If you'd like to know if you’re a good fit, apply. * If I’ve worked with you before, I’m happy to refer you, DM me. * This role is located in Sunnyvale, CA
linkedin.com
LinkedIn hiring Staff Security Engineer - AI in Sunnyvale, CA | LinkedIn
Posted 9:34:52 AM. LinkedIn is the world's largest professional network, built to create economic opportunity for…See this and similar jobs on LinkedIn.
000
omkhar @omkhar.net · 14/06/2026
000
omkhar @omkhar.net · 13/06/2026
It supports Codex, Claude Code, Gemini CLI, GitHub Copilot, Google Antigravity. It has unofficial support for anything that can read an AGENT.md Check it out, tell me what I got wrong. Pull requests are welcome. PS Knicks in 5
000
omkhar @omkhar.net · 13/06/2026
My feed is awash with “innovative” “thought leadership” pieces about the impact of Fable/Mythos being restricted. Doing security research and are looking for a portable skill that you can use to discover new vulnerabilities? Check out Vulnerability Validation skill: github.com/omkhar/vulne...
110
omkhar @omkhar.net · 11/06/2026
Last night's MVPs: 1. Wu-Tang 2. Brunson 3. Anunoby Knicks in 5
020
omkhar @omkhar.net · 09/06/2026
5. As per Jurassic Park...
010
omkhar @omkhar.net · 09/06/2026
2. Make sure you understand how to patch / update all of your stuff as fixes come out. Quickly. Bad guys have no respect for risk acceptances and patch windows. 3. Make sure that you've hardened anything external facing as best you can. 4. Hydrate, get sleep. It's a marathon not a sprint
120
omkhar @omkhar.net · 09/06/2026
Mythos/Fable is out... Before the thought leaders start publish whitepapers, or hosting "CISO dinners" etc, I'll offer some boring/sobering advice: 1. Make sure you know where all your stuff is - ya even that 3rd party software that the person in accounting bought on a credit card in 2016.
130
Reposted by omkhar
Lea Kissner @leak.bsky.social · 20/05/2026
Are you a privacy engineer or work with privacy engineers? Would you like to learn more about probably engineering? Boy do I have a conference for you! PEPR, the conference on privacy engineering, practice, and respect, is happening June 1-2 in Santa Clara, CA. www.usenix.org/conference/p...
usenix.org
PEPR '26
The 2026 USENIX Conference on Privacy Engineering Practice and Respect (PEPR '26) will take place on June 1–2, 2026. PEPR is focused on designing and building products and systems with privacy and res...
01810
omkhar @omkhar.net · 18/05/2026
Vulns are getting packed up github.com/ImageMagick/... #iykyk #cybersecurity #opensourcesoftware
000
omkhar @omkhar.net · 09/05/2026
Wu-Tang said it in '93: protect ya neck. You've been doing it for the rest of us ever since. No royalties, no panels, no merch. Just the work. Back to research and helping fix upstream. #opensourcesoftware #cybersecurity
030
omkhar @omkhar.net · 09/05/2026
One thing I won't wait to say: To the open source maintainers who've fielded our reports, triaged with patience, and shipped fixes through what has genuinely been an unprecedented stretch, thank you. I owe you many coffees/beers/waters. Much love.
110
omkhar @omkhar.net · 09/05/2026
That's what our team at LinkedIn has been doing, inside our own stack and across the dependencies we all share. I'll share more when I can.
110
omkhar @omkhar.net · 09/05/2026
The actual work is unglamorous. You read code. You read more code. You look upstream at the open source the whole world depends on. You find things. You report them carefully. You wait. And hopefully you've made the world a little more secure.
220
omkhar @omkhar.net · 09/05/2026
Meanwhile, the engineers I know, the ones helping secure the internet, have gone quiet. There's usually a reason for that.
110
omkhar @omkhar.net · 09/05/2026
Since Anthropic shipped Mythos and OpenAI Codex Cyber, my feed has been wall-to-wall thought leadership. Sage wisdom. Whitepapers. Panels. Frameworks for "AI-augmented vulnerability discovery." Panels about the frameworks. And one framework about panels
110
omkhar @omkhar.net · 09/05/2026
Mee-thos? Meye-thos? Mi-thos? A month in, I still couldn't tell you. The loudest opinions on AI vulnerability research almost never come from the people actually using it or contributing to making the world more secure.
110
omkhar @omkhar.net · 08/05/2026
The correct step is a step. When you come to a fork in the road, take it. Thanks Cameron for the conversation. Link in below. What did your “dead end” teach you later? www.linkedin.com/posts/ep-35-...
linkedin.com
EP. 35, THE DEFENDER'S JOURNAL - OMKHAR ARASARATNAM! 🎙️ | Techfellow Limited
Most careers don’t go to plan. Some don’t follow a plan at all… In Episode 35 of The Defender’s Journal, Omkhar Arasaratnam shares how he went from factory work and DJ’ing to shaping security at Link...
000
omkhar @omkhar.net · 08/05/2026
The thread through all of it: I’m still happiest building things at scale, with smart people, where security, software engineering, and productivity are treated as one system.
100
omkhar @omkhar.net · 08/05/2026
* Mentorship is not doing someone’s job for them. It’s giving enough scaffolding that they can pick up the hard thing themselves.
100
omkhar @omkhar.net · 08/05/2026
* Coding agents are not autocomplete with a better haircut. They are creative, persistent, and occasionally behave like mini red teams. Correctness, provenance, test harnesses, and mutation testing matter more now, not less.
131
omkhar @omkhar.net · 08/05/2026
* The industry will continue to underestimate fundamentals. We’ll talk about nation-state actors on panels and still get burned by sketchy remote-control software on a work laptop.
100
omkhar @omkhar.net · 08/05/2026
A few things we got into: * Humans have context windows too. At billions-with-a-B scale, you can’t keep making people the load-bearing control.
100
omkhar @omkhar.net · 08/05/2026
I started in factory work, DJing, and ThinkPad tech support. I somehow ended up working on security, software, and systems at global scale. Over a long enough story arc, I’m not sure any of the “dead ends” were actually dead ends.
100
omkhar @omkhar.net · 08/05/2026
“I went from negative to positive.” - Biggie Smalls, BedStuy Motivational Speaker That came up near the end of my conversation with Cameron on The Defender’s Journal, and it probably says more about my career than any title ever has.
100
omkhar @omkhar.net · 22/04/2026
Me right now while doing vuln research
000
omkhar @omkhar.net · 17/04/2026
Unsurprisingly, the best defense right now for most people is the same as it's always been: patch your stuff, and keep it up to date. The basics aren't sexy, but they work. Know the ledge before you step to it. Some things never change.
053
omkhar @omkhar.net · 17/04/2026
Having spent time with both, I can tell you the biggest security vulnerability they've exposed isn't technical. It's people who haven't touched either one confidently telling you what it all means.
110
omkhar @omkhar.net · 17/04/2026
"Do you know the ledge?" Rakim - Long Island 0-day Researcher The last 10 days, everyone's had an opinion on Mythos and GPT 5.4-Cyber.
110
omkhar @omkhar.net · 15/04/2026
It works. But it's not done yet, and I'd rather build what YOU need than guess. The roadmap is open. Go add to it: github.com/omkhar/workcell/blob/main/ROADMAP.md What would make Workcell indispensable for you? Pull requests are welcome!
github.com
000
omkhar @omkhar.net · 15/04/2026
Most security tools slow you down. Most fast tools ignore security. We wanted both. So we built Workcell. It started with a few co-conspirators asking: "How do we vibe code at yolo speed and not get owned?"
github.com
100
omkhar @omkhar.net · 15/04/2026
Happy tax day to all those who observe :lolsob:
000
omkhar @omkhar.net · 10/04/2026
Agent on agent violence has been requested 🤣
010
omkhar @omkhar.net · 10/04/2026
Try it. Break it. Tell me what holds up. Patches welcome. #cybersecurity #codingagents #security #opensource
030
omkhar @omkhar.net · 10/04/2026
Coding agents are powerful. They’re also one bad boundary away from self-compromising your machine. I wanted the speed of “YOLO mode” without giving up isolation, so I built Workcell. With a lot of help from Codex, Claude, Gemini, and Rick, it’s now out: github.com/omkhar/workc...
github.com
GitHub - omkhar/workcell: Bounded local runtime and policy boundary for coding agents
Bounded local runtime and policy boundary for coding agents - omkhar/workcell
270
omkhar @omkhar.net · 08/04/2026
Eventually, we’ll be in a much better state. The messy middle is going to be painful.
120
omkhar @omkhar.net · 08/04/2026
Job security!!!
120
omkhar @omkhar.net · 08/04/2026
A few years ago, when I was working at @openssf.org , we partnered with @darpa.mil on the AI Cyber Challenge. Yesterday's news from @anthropic.com about Mythos and Glasswing both highlight the opportunity that we saw, and the primary reason we were so focused on securing open source software.
130
omkhar @omkhar.net · 29/03/2026
I thought we agreed that move fast + break things was passe? 🤣
000
omkhar @omkhar.net · 29/03/2026
My concern is that when writing code was the constraint, ideas were pressure tested better. Now all kinds of crap gets built that wouldn’t have before.
000
omkhar @omkhar.net · 28/03/2026
* Spend less time on code production, more on architecture, evals, and review * Treat observability, rollback, and correctness as part of the product Same game. Different scoreboard. How are you adapting to the new economics of building? #softwareengineering #code #ai #agents #codex #claude #gemini
051
omkhar @omkhar.net · 28/03/2026
So the engineering model has to change too: * Optimize for learning velocity, not backlog pressure * Use smaller, high-context teams with clear ownership - reduce fractal communication complexity
100
omkhar @omkhar.net · 28/03/2026
Now the cost of producing code has collapsed. The bottleneck has moved upstream to clarity, taste, systems thinking, verification, and operational discipline. Or, said differently: everyone can ship faster, including people shipping crap.
230
omkhar @omkhar.net · 28/03/2026
For years, engineering organizations were built around one constraint: implementation was expensive, so every idea had to survive layers of prioritization before anyone wrote a line of code. AI changed that.
430
omkhar @omkhar.net · 28/03/2026
"Code Rules Everything Around Me, CREAM" - Method Man, Chief AI Scientist, Wu-Tang Clan Code got cheaper. Engineering didn’t.
100
omkhar @omkhar.net · 27/03/2026
What if we focused on more deterministic testing to ensure our invariants aren’t violated. Is that a good balance?
000
omkhar @omkhar.net · 20/03/2026
Hard to do at scale (10s of thousands of people l), suggestions?
010
omkhar @omkhar.net · 20/03/2026
Some repos which AI agents and I worked on: Reset USB, a program which resets all the devices on the USB bus in Linux github.com/omkhar/reset... DNS Update, a program which updates A and/or AAAA records based on your current public IP(s). github.com/omkhar/dns-u...
000