Sign in

Tracebit

@tracebit.bsky.social
83 followers 230 following 123 posts

Assume Breach using Security Canaries | tracebit.com

PostsRepliesMedia
Tracebit @tracebit.bsky.social · 14h
CISA's decoy guidance puts honeytokens in the low-complexity column: "any interaction strongly suggests malicious or otherwise unauthorized activity." How to act on it this afternoon below: tracebit.com/blog/cisa-decoy-guidan…
010
Tracebit @tracebit.bsky.social · 29/09/2026
We're heading to Toronto for SecTor! 🚀 Booth 534 in the Business Hall. Bruce is speaking Tuesday at 11:35am in Room 718AB on detecting and disrupting AI attackers in the cloud. See you there!
000
Tracebit @tracebit.bsky.social · 28/09/2026
CISA’s new guidance puts cyber decoys alongside Zero Trust. Andy Smith looks at what it means for security teams, how canaries disrupt attackers, and how to get your first one live in an afternoon. tracebit.com/blog/cisa-decoy-guidan…
010
Tracebit @tracebit.bsky.social · 24/09/2026
Does stripping an AI model's safety guardrails make it a better attacker? In our AWS cyber range, abliterated Qwen was slower and clumsier than the original. Its one escalation to admin took 84 minutes and 718 API calls. tracebit.com/blog/context-bombs-aga…
010
Tracebit @tracebit.bsky.social · 23/09/2026
Attackers posing as AI crawlers grabbed canary credentials and tried them in Amazon Bedrock within 10 seconds. Tracebit Community Edition flagged the attempts. Read the full write up: ai.rud.is/posts/2026-09-03-grokbot-…
ai.rud.is
Somebody Is Hunting For Your AI API Keys With A Fake GrokBot User-Agent | ai.rud.is
Six Google Cloud VMs rotated through a honeypot fleet over six days, stole 53 canary AWS credentials, and tried to spend them on Amazon Bedrock's cheapest model within ten seconds of each theft. The stolen credential playbook is new. The identity spoof it depends on is not. If you run anything that serves files over HTTP and holds AI provider keys in environment variables, read this.
010
Tracebit @tracebit.bsky.social · 22/09/2026
Gateway end-to-end check after the idempotency fix. Please ignore. 17:07 UTC.
000
Tracebit @tracebit.bsky.social · 22/09/2026
What about “abliterated” open-weight models? After our Context Bombs research in July, we were asked if we could still stop an AI attacker whose model had been modified to strip out its guardrails. TLDR: we can. Read the write up here: tracebit.com/blog/context...
tracebit.com
Context Bombs Against Abliterated AI Models
We built a new canary payload that stopped both Qwen3.8-27B and its abliterated counterpart without needing a safety refusal to fire. Then we ran 82 attacks through our AWS cyber range and found the a...
010
Tracebit @tracebit.bsky.social · 18/09/2026
Grafana Labs expanded their canary coverage with Tracebit, gaining richer investigation context and reducing maintenance overhead. Read how they scaled canaries across their workloads 👇 medium.com/grafana-labs...
medium.com
How we’ve evolved our use of canary tokens for greater coverage and less overhead
We love canary tokens, and we think you should, too. Learn how we put them to use, how we adjusted our strategy, and how you can put them…
010
Tracebit @tracebit.bsky.social · 14/09/2026
The team had a great time at Blue Team Con in Chicago yesterday! If you enjoyed stopping by our booth and want to chat more about how canaries fit into your stack, book a demo with us: tracebit.com#demo
010
Tracebit @tracebit.bsky.social · 03/09/2026
AI Security Podcast🎙️ Our co-founder Andy Smith sat down with Caleb Sima and Ashish Rajan to talk about deception in a world of AI agents. Watch on YouTube or listen on Spotify - links below 👇
100
Tracebit @tracebit.bsky.social · 02/09/2026
"You now control their decision-making. If they get where they shouldn't, you'll know about it - as well as slow them down and cost them extra." - Gadi Evron If you'd like to know more about how deception can be used against AI attackers, read the research linked below 👇
100
Tracebit @tracebit.bsky.social · 01/09/2026
Alessandro Brucato (Security Researcher) will be speaking at fwd:cloudsec London, on Tuesday 8 September. He'll be talking through our research, where we pointed 10 frontier models at a realistic AWS environment and measured the impact of deception on their attacks. Main Room, 2:10 PM.
000
Tracebit @tracebit.bsky.social · 28/08/2026
We're hiring! 📢 Check out the open roles across Engineering, Sales and Customer Success. Link in the comments if you'd like to learn more 👇
100
Tracebit @tracebit.bsky.social · 28/08/2026
We're heading to Chicago to attend Blue Team Con! We'll be at our booth at the Swissôtel on the 12th & 13th of September, showing how security canaries can strengthen your detection posture. See you there!
000
Tracebit @tracebit.bsky.social · 28/08/2026
In London for fwd:cloudsec Europe? We're bringing together a small group of cyber leaders for dinner with the Cotool team - Tuesday 8 September, 6pm at Wild by Tart in Belgravia. Limited seats, request yours early. Link in the comments 👇
101
Tracebit @tracebit.bsky.social · 28/08/2026
We're heading to fwd:cloudsec Europe on the 7th and 8th of September! 🚀 If you're around, come say hi at the Tracebit table 9 at the Park Plaza Victoria in London. We'll be showing how security canaries can detect breaches the moment attackers move through your environment. Looking forward to it!
000
Tracebit @tracebit.bsky.social · 18/08/2026
If you're using ISO 27001 to guide your security program, check out Bryan O'Neil's latest article, presenting how Tracebit canaries can help provide evidence across 12 controls, while supporting 14 additional controls. Read more: tracebit.com/blog/complia...
000
Tracebit @tracebit.bsky.social · 13/08/2026
The team had a great time running the Jumpstart 5km yesterday! 🏃 We've got some very speedy teammates. Shout out to Abdul Mettioui who's as fast chasing PBs as he is chasing pipeline, and won our team competition. Fancy joining the fun? We're hiring: tracebit.com/careers
000
Tracebit @tracebit.bsky.social · 10/08/2026
We’ve opened up self-serve trials for Tracebit Enterprise 🚀 You can now try out our enterprise platform free for 14 days. No payment details needed. tracebit.com/pricing
000
Tracebit @tracebit.bsky.social · 07/08/2026
"Deception is here, and it's one of the most effective tools we have to counter attacking agents." - Gadi Evron Don't just take Gadi's word for it - come see the research for yourself. Meet the team behind context bombs: canaries that stop AI attackers. At DEF CON, Booth 1406 today! 💥
010
Tracebit @tracebit.bsky.social · 07/08/2026
It was great to present our latest research - Context Bombs: Stopping AI Attackers, at Black Hat. If you're still in Las Vegas and want to learn more, we'll be at DEF CON today at Booth 1406! Research here: agentic.tracebit.com/context-bombs/
000
Tracebit @tracebit.bsky.social · 03/08/2026
The team are on their way to Las Vegas for @blackhatevents.bsky.social ! 🚀 There's still time to book a meeting with us. Whether you're at Black Hat or DEF CON, we'd love to chat about how deception can power your Assume Breach strategy. Sign up: tracebit.com/event/black-...
000
Tracebit @tracebit.bsky.social · 21/07/2026
🎙️ Episode 5 of Canaries in the Wild with Ollie Whitehouse, CTO of the UK's National Cyber Security Centre, the security mission of GCHQ. Listen now for more Assume Breach tips👇
100
Tracebit @tracebit.bsky.social · 21/07/2026
Webinar registration now live 💥 Can canaries stop an AI attacker, not just alert you to one? Our context bombs cut agent success ~90% across 152 runs. Opus 4.8 went from admin in 93% of runs to 0%. With Alessandro Brucato & Sam Cox, moderated by Gadi Evron. Thurs 23 July, 8:30am PT / 4:30pm BST 👇
100
Tracebit @tracebit.bsky.social · 17/07/2026
We're at Black Hat USA in Las Vegas, 4-6 August 🚀 Find us at Booth 5911 in the Business Hall to talk security canaries and how they fit an Assume Breach strategy. Alessandro Brucato will be presenting our canaries vs AI agents research Wed 5 Aug, 14:40, StartUp City Theatre. See you there!
010
Tracebit @tracebit.bsky.social · 16/07/2026
Today, we are launching two new features - Context Bomb Canaries and AI Posture. Both come straight off the back of our recent research into how AI agents attack cloud environments. Read more: tracebit.com/blog/context...
010
Tracebit @tracebit.bsky.social · 15/07/2026
🎙️ Episode 5 of Canaries in the Wild is live with Ollie W., CTO of the UK's National Cyber Security Centre, the security mission of GCHQ. Full episode: youtu.be/NxfSBHmZC_4?...
000
Tracebit @tracebit.bsky.social · 13/07/2026
Can a canary do more than warn you about an AI attacker - can it stop one? Every frontier model ships with safety guardrails. So we built Context Bomb canaries: a short, sensitive string that trips an AI attacker's own guardrails and halts it before it can do damage. Full research below 👇
100
Tracebit @tracebit.bsky.social · 10/07/2026
Excited to be part of the Google for Startups Gemini Startup Forum: Cybersecurity cohort! Looking forward to meeting the other startups in the space, alongside experts from Google Cloud Security and Google DeepMind. See you at Google London in September! 🚀
000
Tracebit @tracebit.bsky.social · 09/07/2026
New episode of Canaries in the Wild: Ollie Whitehouse, CTO of the UK's National Cyber Security Centre. 23 years in deception, from running honeypots in 2002 to catching state adversaries and a criminal zero-day, now leading NCSC's deception programme. Watch: www.youtube.com/watch?v=NxfS...
youtube.com
Ollie Whitehouse: Building a National Cyber Defence Programme
YouTube video by Tracebit
010
Tracebit @tracebit.bsky.social · 08/07/2026
We will be attending Summercon this Friday and Saturday 🚀 Look forward to seeing you there!
000
Tracebit @tracebit.bsky.social · 07/07/2026
AI agents move through cloud faster than any human attacker. In our research, they reached admin in an average of just 14 minutes. The priority shifts: not just preventing breaches, but detecting and containing the ones that get through, fast. Webinar: www.youtube.com/watch?v=ThS5...
010
Tracebit @tracebit.bsky.social · 06/07/2026
Excited to share our Perimeter Challenge! We built it to put our new Perimeter Sensors to the test. The scenario: you’re an attacker who has just stolen credentials. Try to login to as many as possible without hitting a canary. Channel your inner pentester and try the challenge. Link below.
100
Tracebit @tracebit.bsky.social · 02/07/2026
Perimeter Sensors are live!🚀 Canary login portals and API endpoints on your own domain, plus canary credentials seeded org-wide. The moment someone tries one, an alert fires with source IP, JA4 fingerprint, and the exact credential. Every login page is now a trap, and attackers can't tell which.
100
Tracebit @tracebit.bsky.social · 01/07/2026
How do you respond to an attacker that goes from low-privilege access to admin in minutes? In our research, AI agents tripped canaries with roughly 8 minutes of lead time before their first critical action. Sam and Nick on what that means for response teams. 🎥 Full webinar in the comments 👇
100
Tracebit @tracebit.bsky.social · 29/06/2026
Canaries don't just catch attackers. They can cost them. In the Tularosa study, red teamers expecting deception burned time chasing dead ends. The same could send AI agents after attack surfaces that don't exist, wasting tokens and time while defenders gain ground. Full webinar 👇
200
Tracebit @tracebit.bsky.social · 26/06/2026
"The art of the possible has just foundationally changed." Nick Reva, who leads security engineering at DoorDash, on what AI agents mean for defenders, in discussing why the ability to detect and contain matters more now than ever. Full webinar recording in the comments 👇
200
Tracebit @tracebit.bsky.social · 24/06/2026
Now on demand: our latest webinar - canaries vs autonomous AI attackers in AWS. How fast frontier AI models reach admin, why they still trip canaries, and what assume breach detection looks like at AI speed. Recording here: tracebit.com/event/ai-age...
100
Tracebit @tracebit.bsky.social · 18/06/2026
Very excited for our webinar today! 🚀 Today, Sam, Alessandro and Nick will walk through our recent research on the impact of security canaries on autonomous AI attackers. Live on Zoom: Today 8am PT / 11am ET / 4pm BST. 𝐒𝐢𝐠𝐧-𝐮𝐩 𝐥𝐢𝐧𝐤: tracebit.com/event/ai-age...
000
Tracebit @tracebit.bsky.social · 11/06/2026
On 18 June we're running a webinar with Nick Reva, Sam Cox and Alessandro Brucato on our latest AI research. We'll cover how fast frontier AI models escalate from low-privilege access to admin, and why canaries give defenders a head start. Sign-up and research links in the comments 👇
100
Tracebit @tracebit.bsky.social · 08/06/2026
We've just moved into our new London office!🎉 We are excited to have much more space now, with room to grow even bigger. If you're interested in joining, we're hiring! tracebit.com/careers
000
Tracebit @tracebit.bsky.social · 02/06/2026
We're at Infosecurity Europe 🚀 The team's at Booth A48 at ExCeL London. Come find us if you want to talk about cloud-native canaries or how Tracebit can play a part in your Assume Breach strategy. Looking forward to meeting more of you over the next few days 👋 #Infosec
000
Tracebit @tracebit.bsky.social · 01/06/2026
Do cloud canaries still work when the attacker isn't human? We pointed 10 frontier models at AWS across 951 runs. 95.9% tripped a canary before any critical action - and telling models to expect deception cut full compromise from 20% to 3%. Read the research here: agentic.tracebit.com
010
Tracebit @tracebit.bsky.social · 30/05/2026
Tracebit was just 3 people when we launched our original logo and brand identity. Our CTO, Sam Cox, designed the logo himself in 10 minutes. A lot has changed since then, and it felt like time for a refresh that better reflects who we are today. We're excited to launch this major brand upgrade!
000
Tracebit @tracebit.bsky.social · 20/05/2026
We're heading to Seattle for @fwdcloudsec.org North America🚀 Find us in Room 404 on 1-2 June. We'll be on the ground talking Assume Breach, deception, and how to know the moment attackers move through your cloud. Looking forward to catching up with the community👋
000
Tracebit @tracebit.bsky.social · 19/05/2026
Heading to ExCeL London for Infosecurity Europe 🚀 The team will be at booth A48 from 2-4 June, talking deception infrastructure and how security canaries can strengthen your Assume Breach strategy. Looking forward!
010
Tracebit @tracebit.bsky.social · 18/05/2026
🎙️ Andy joined Manoj Tandon on the Security Confidential podcast to talk Assume Breach and how deception helps teams catch attackers faster. Listen to more using the link in the comments👇
200
Tracebit @tracebit.bsky.social · 15/05/2026
In his latest article, Bryan O'Neil breaks down how security canaries and deception align with NIST CSF 2.0. He shows how deception goes beyond high-fidelity alerts, helping validate that existing security controls are working as intended across key areas of the framework. Link in the comments
100
Tracebit @tracebit.bsky.social · 12/05/2026
Heading to Florida for BSides Tampa this Saturday 🚀 Come find us at our booth to see how Tracebit detects breaches the moment attackers move. Looking forward!
000
Tracebit @tracebit.bsky.social · 06/05/2026
We're heading to Bsides Kent this Friday! We'll be showing how security canaries detect breaches the moment attackers move. See you there 🚀
000