Sign in

Stefano Zanero

@raistolo.bsky.social
3.4K followers 1.5K following 995 posts

Tinkerer, security geek, recovering entrepreneur, full professor at www.polimi.it, frequent flyer, private pilot, and generic pundit. He/Him 🏳️‍🌈
 For aviation follow me on Instagram, same id!

PostsRepliesMedia
Stefano Zanero @raistolo.bsky.social · 13h
THIS:
0103
Stefano Zanero @raistolo.bsky.social · 28/09/2026
It is not an engineering problem, and more significantly it is not a “problem”. It is how these systems work. It’s like saying that a combustion engine has the “problem” of burning fuel. It is how it works. You “solve” the problem by changing technology to something different.
192
Reposted by Stefano Zanero
Hacker Memes @i0null.infosec.exchange.ap.brid.gy · 26/09/2026
Custom captions: 
Hackers’s in the 1980s:
- full humanmade color games for atari 2600 with only 128 bytes of RAM
- knows every x86 instruction by hand
- c so high level it is basically considered english

Verses, techbros today:
- my electron app uses 3gb of vram
- the datacenter i help build depleted an entire lake
- i cant afford the tokens to patch my vibecoding project

template sprites: buff doge vs crying cheems
398103
Reposted by Stefano Zanero
Ciaran Martin @ciaranm.bsky.social · 25/09/2026
My thoughts on how frontier AI’s claims and warnings seem prone to colliding with reality, whether that’s in economics, medicine or cyber security ciaranmartin.substack.com/p/on-ai-clai...
ciaranmartin.substack.com
Frontier AI’s real world problems
Many of the claims and warnings about the impact of frontier AI seem to collide awkwardly with the realities of the specific subject in question
23515
Reposted by Stefano Zanero
AP Stylebook @apstylebook.com · 23/09/2026
Artificial intelligence systems do not think, feel, want or understand. Avoid language that gives them human characteristics.
apnews.com
https://apnews.com/article/openai-safety-ai-framework-089e75b95bc935af092da7b79d92706d
5542341627
Stefano Zanero @raistolo.bsky.social · 21/09/2026
This. This, not “superintelligence”, is the existential risk posed by AI. This and also all other lesser risks: reliance without cross checking on a useful but INTRINSICALLY unreliable tool.
1216
Reposted by Stefano Zanero
The Verge @theverge.com · 20/09/2026
But they’re more dangerous with AI. www.theverge.com/science/9978...
theverge.com
Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems
Critical infrastructure was already vulnerable.
15019
Reposted by Stefano Zanero
tef @tef.bsky.social · 20/09/2026
finding out the uk air traffic outage (on the 8th September) was caused by a race condition www.nats.aero/wp-content/u...
nats.aero
2326
Reposted by Stefano Zanero
Damon Kiesow @kiesow.net · 19/09/2026
“AI” did not do anything. Humans who improperly used a tool or properly used the wrong tool and now want to pass the blame did it.
1113
Reposted by Stefano Zanero
Ed Zitron @edzitron.com · 11/09/2026
Holy shit. Bloomberg just verified one of my biggest scoops - that Microsoft only has 2gw of operational capacity. I had it at 1.993GW in prep for the story that @aishadown.bsky.social and I did for the guardian. Vindication! www.theguardian.com/technology/2...
Brody Ford @BrodyFord
Lot of speculation out there about how many GPUs are actually deployed.
Today, Microsoft has about 2GW of Al-specific capacity live. around 17% of the total fleet.
Only about 2 gigawatts of the company's current 12-gigawatt capacity is centered on Al-specific chips, the people said. This is expected to grow to about a third of the 38 gigawatts Microsoft plans to have online in 2032, they said.
Brody Ford @BrodyFord_ • 23h
scoop: Microsoft is planning a massive expansion of its data center fleet to 38 gigawatts. $msft w/ @mattmday bloomberg.com/news/features/...
3:15 PM • Sep 11, 2026 • 12.5K Views



1,993,608.00
W


MW


GW





Are Microsoft's AI
plans being held back by a shortage of chips?
Guardian investigation finds
apparent discrepancy between what tech company has said about its AI capacity - and the
number of advanced chips it
has in operation
By Aisha Down and Ed Zitron
A Microsoft datacentre in the North Holland village of
Middenmeer in the Netherlands. Photograph: Ramon van
Flymen/EPA
251937362
Reposted by Stefano Zanero
Terence Tao @teorth.bsky.social · 11/09/2026
A group of 25 Fields Medalists, including myself, have made a joint declaration on Math and AI: mathandai.org . We welcome additional signatories. See also this article in the Economist announcing the declaration: www.economist.com/science-and-...
mathandai.org
Declaration — Math and AI
Read the declaration and add your name.
422052929
Reposted by Stefano Zanero
Katie Mack @astrokatie.com · 10/09/2026
FWIW I don’t think that AI is an existential threat, nor on track to become one. I do however think that the leaders of the biggest AI companies, AI’s strongest boosters, and some of the folks who are most adept at using it to exploit others are actively hastening along OTHER existential threats.
492153416
Reposted by Stefano Zanero
evacide @evacide.bsky.social · 10/09/2026
If you optimize a model to find exploits, you should expect it to find them—and prepare for that. OpenAI didn't. They built a model, removed the safeguards, gave it the ExploitGym task, let it run, and didn't even monitor it. That's human decision-making. mail.cyberneticforests.com/models-dont-...
mail.cyberneticforests.com
Models Don't Go Rogue
Stochastic Flocks & Cybersecurity 'Pandemonium' 💡This essay was drafted from my appearance on Mél Hogan's podcast, The Data Fix, discussing the OpenAI / Hugging Face hack. Embedded below or find it o...
8288111
Reposted by Stefano Zanero
David Burbach 🇺🇸 @dburbach.bsky.social · 09/09/2026
Senior AI company leaders saying there is a 10% chance their tech will cause human extinction within 10 years. Even nuclear war pales before that. We should be shutting them down TODAY if they are serious.
511119
Reposted by Stefano Zanero
Mark C @largecardinal.bsky.social · 09/09/2026
Thoughts and prayers to CFD folks today... Source: r/CFD
27919
Reposted by Stefano Zanero
El Jefe Gone Dark Security @eljefe.social · 08/09/2026
I'm gonna just love saying it: There is no S in MCP.
092
Reposted by Stefano Zanero
Ryan Marino, MD @ryanmarino.bsky.social · 08/09/2026
OpenAI set $22M on fire just to steal $1M from a human who did the actual work, and that’s the business plan our economy is betting everything on? Lol.
181631486
Reposted by Stefano Zanero
Teresa Heffernan @tjheffernan.bsky.social · 07/09/2026
Can the NYT's please stop confusing fiction with science? "I thought A.I. systems would grow more virtuous as they became smarter....even if one model in a group behaved badly" (Kevin Roose) Billions of mathematical calculations do not grow "smarter" "more virtuous" or "behave badly."
27416
Stefano Zanero @raistolo.bsky.social · 05/09/2026
What the hell?!
1112
Reposted by Stefano Zanero
Evan Greer @evangreer.bsky.social · 04/09/2026
Age verification makes everyone less safe. Age verification makes everyone less safe. Age verification makes everyone less safe. Age verification makes everyone less safe. Age verification makes everyone less safe. Age verification makes everyone less safe.
techdirt.com
Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.
From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it "age" verification, but it always ends up as identity verification), we've been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn't waiting. Maybe it was already happening. This week a...
81148287741
Stefano Zanero @raistolo.bsky.social · 04/09/2026
“Oste, ma il vino è buono?” Più seriamente, se “abbiamo raggiunto la AGI” è un’opinione che può essere espressa così a caso, significa che non ha nulla di scientifico e si tratta di un termine di puro marketing. Chi lo avrebbe mai detto… a parte chiunque si occupi in modo scientifico di AI/ML
092
Stefano Zanero @raistolo.bsky.social · 03/09/2026
Chi, chi mai avrebbe potuto prevederlo? A parte quei gufacci che facendo questo per mestiere ovviamente strillano da anni sul tema, intendo…
3173
Reposted by Stefano Zanero
cje @cje.io · 23/08/2026
This is a *really* solid read, mirrors my experience atm, and reinforces the whole "defensive cyber is an economics game" conversation. ty @gadievron for the link: Just a rumour of a bug is enough to find a security exploit these days anil.recoil.org/notes/rumour...
anil.recoil.org
Just a rumour of a bug is enough to find a security exploit these days
Thinking through how the conventional OSS security embargoes no longer buy us time, and what open source maintainers might do instead to respond
0139
Stefano Zanero @raistolo.bsky.social · 20/08/2026
Given how monumentally stupid that race is, I would actually say “good for Europe”?
0171
Reposted by Stefano Zanero
Karl Bode @karlbode.com · 18/08/2026
"This ranks as one of the top three dumbest ideas in my four decades of being in this industry"
lightreading.com
Small cells, big mess – why Musk's SpaceX telecom plan won't work
Several more wireless experts serve harsh judgment on Elon Musk's plan to build a US network of small cells.
1222456
Reposted by Stefano Zanero
Evan Greer @evangreer.bsky.social · 16/08/2026
there is no such thing as "age verification." All "age verification" is actually "identity verification." You can coat it in glitter and "privacy-preserving" wrapping paper. But in the end, mandating age verification means mandating surveillance be built into software and hardware. Period.
106138705602
Reposted by Stefano Zanero
Chris Wysopal @weld.bsky.social · 13/08/2026
This is a pretty big shift in US cyber policy. The White House is setting up a program that would let private cybersecurity companies conduct gov-authorized operations against foreign cybercriminal groups, inc surveillance & disruption of their infrastructure www.whitehouse.gov/presidential...
whitehouse.gov
Expanding Capabilities to Combat Transnational Cyber-Enabled Crime
MEMORANDUM FOR THE VICE PRESIDENT THE SECRETARY OF STATE THE SECRETARY OF THE TREASURY THE SECRETARY OF WAR THE ATTORNEY GENERAL THE SECRETARY OF COMMERCE
53225
Reposted by Stefano Zanero
Mike Masnick @masnick.com · 12/08/2026
And for at least a bit of real world data, Bluesky continues to be the largest single source of traffic (after search) to @techdirt.com. I don't think Threads has ever shown up in any list of referrers. Ever.
181258187
Stefano Zanero @raistolo.bsky.social · 11/08/2026
Today’s chapter of “if you don’t properly discuss the threat model, sensible security discussions are impossible”:
030
Reposted by Stefano Zanero
Ars Technica @arstechnica.com · 11/08/2026
arstechnica.com
Here's why the new Pass-ta-key attack is mostly a nothingburger
Why passkey apps treat Windows differently than other operating systems.
2164
Stefano Zanero @raistolo.bsky.social · 10/08/2026
The entire thread/rant is worth reading.
050
Stefano Zanero @raistolo.bsky.social · 08/08/2026
It’s not a mistery to anyone that I am a big fan of @adamshostack.bsky.social ’s work. This new model is no exception: lean, well thought out and definitely needed.
072
Reposted by Stefano Zanero
Zardus @zardus.bsky.social · 07/08/2026
Hello hackers! DEF CON Academy is up and running in Hall 4. Our goal is to take people from the wandering the hallways to actively learning to hack! We have (very beginner-friendly!) learning material, challenges, mentors to help, and laptops for you to use. Come on by!
011
Reposted by Stefano Zanero
Eric Geller @ericjgeller.com · 05/08/2026
Senior US, UK, and Canadian cyber officials today urged critical infrastructure providers and other businesses to stop obsessing over AI nightmare hacks and prioritize resilience to prepare for basic and inevitable incidents. My story from Black Hat: www.cybersecuritydive.com/news/ai-cybe...
cybersecuritydive.com
Western government leaders call for a focus on infrastructure resilience, not AI hype
U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services.
0115
Reposted by Stefano Zanero
Rob Pegoraro @robpegoraro.com · 05/08/2026
"If we don't embrace it, politics will happen to us": astute advice from Black Hat founder @thedarktangent.bsky.social in opening remarks before this morning's keynote (which will, of course, address some information-security dimensions of AI).
041
Stefano Zanero @raistolo.bsky.social · 05/08/2026
@thedarktangent.bsky.social doing his thing
Jeff Moss opening keynote at Black Hat
120
Stefano Zanero @raistolo.bsky.social · 04/08/2026
Cyber insurer (Chatham house forbids me from saying who) at BH CISO summit: “so far this year 0 payouts for claims even remotely connected to a AI-driven breach, 85% of payouts related to social engineering”. Sobering statistic.
36431
Stefano Zanero @raistolo.bsky.social · 03/08/2026
On my way to Vegas for summer camp - grab me and say hi if you spot me ☺️
040
Reposted by Stefano Zanero
Patrick C Miller @patrickcmiller.bsky.social · 02/08/2026
OpenAI not part of the new Open Secure AI Alliance www.csoonline.com/article/4201...
csoonline.com
OpenAI not part of the new Open Secure AI Alliance
A new industry group led by Nvidia is promoting open AI models (and not OpenAI’s models) as essential to cyber defense.
012
Reposted by Stefano Zanero
Dr. Damien P. Williams, dread portent down from a mountain cave @wolven.blacksky.app · 01/08/2026
Dear media, please be even a little bit critical and suspicious of whether the people with literally trillions of dollars & the world economy riding on you believing what they tell you might have reason to lie about what's happening inside their products that they refuse to let anyone else analyze 🫠
331498
Stefano Zanero @raistolo.bsky.social · 01/08/2026
This
0120
Reposted by Stefano Zanero
infosecgreybeard.bsky.social @infosecgreybeard.bsky.social · 01/08/2026
Back in the 1990s, everyone built data centres like mad, because of the .com bubble. When the bubble burst, a lot of investors lost a lot of money. Me watching the AI bubble:
static.klipy.com
Bill Hader as Keith Morrison Eating Popcorn
ALT: Bill Hader as Keith Morrison Eating Popcorn
082
Stefano Zanero @raistolo.bsky.social · 30/07/2026
As I have been preaching for a while now, I think security at large will be impacted far more by LLMs being used in scams than by automated exploitation
1105
Reposted by Stefano Zanero
DEF CON @defcon.bsky.social · 27/07/2026
Friendly #DEFCON34 reminder: Meta-style glasses with recording capabilities are prohibited at DEF CON. There is no exception for recording glasses with prescription lenses. Be sure to pack non-violating eyewear if you need them. Please see our Photo policies for more. defcon.org/html/links/d...
14441136
Reposted by Stefano Zanero
By Cory Doctorow (GPG 0xBF3D9110957E5F4C) @doctorow.pluralistic.net · 23/07/2026
"An insecure sandbox is not a demonstration of cyberprowess." -Loren Kohnfelder (on Openai's model "escaping containment" and attacking Hugging Face's servers) designingsecuresoftware.com/writings/com...
designingsecuresoftware.com
Normalizing cybersecurity facepalms
OpenAI writes: “Last week, Hugging Face disclosed a new kind of security incident⁠(opens in a new window) after they detected and contained an AI agent that compromised their infrastructure, something...
46315
Reposted by Stefano Zanero
Roberta Metsola @president.europarl.europa.eu · 19/07/2026
Magistrate Paolo Borsellino embodied the values on which Europe is built: courage, integrity & freedom. He knew the risks of confronting the Mafia, yet he never turned away from his duty. 34 years from his assassination, we honour his memory by choosing, everyday, to stand on the side of justice.
012742
Stefano Zanero @raistolo.bsky.social · 11/07/2026
These are the same people who, in 2025, predicted “superintelligence” in 2027 with a bunch of made-up, sci-fi stuff. Now, late 2026, they predict the same conveniently for 2030. Dare I say that by July 2027 they will be predicting it for 2035?
1171
Stefano Zanero @raistolo.bsky.social · 01/07/2026
You don’t say
260
Reposted by Stefano Zanero
amos @fasterthanli.me · 29/06/2026
agent: let's delete this file harness: 🚨 DANGER NOPE CAN'T DO THAT 🚨 agent: let's replace this file with the empty string harness: 😌 thank god yes that's better 💆
432131