In a world with abundant intelligence, AI agents will not just replace humans in existing workflows, but make new kinds of work possible; work that was previously too slow or expensive to perform at scale. In cyberdefense, automated digital forensics, i.e. deep security investigations, will become ubiquitous. Today we’re launching Asymmetric Security, the first full-stack AI Digital Forensics and Incident Response company. We're working with the worlds largest global cyber insurers, and our AI platform has already helped incident responders handle hundreds of cyber attacks. Building on this experience, we’re creating realistic training scenarios and evaluations to improve both our AI cyber-defense capabilities and those of frontier labs. Our mission is to accelerate AI cyberdefense to address the security challenges of the AGI era.
5
6
38
8,317
Asymmetric Security retweeted
Here we go again: OpenAI’s agents reportedly used methods that made their activity harder for outside researchers to trace with data access across 55 (!) websites, including the CDC, SEC and International Energy Agency. Today’s FT report adds details to the recent agent incidents: Asymmetric Security found temporary email inboxes, private accounts and use of the website-scanning service Urlquery to retrieve data. Some records were erased or made inaccessible. Looks like this will become a daily problem.
55
30
350
27,754
We're releasing a report on our 48-hour investigation into rogue OpenAI agent activity. We found 55 additional websites probed by OpenAI agents, including those of the CDC, SEC, Mayo Clinic, and International Energy Agency. We uncovered novel tactics that erased records or made them inaccessible, access to government website staging environments, and evidence of attacker-style reconnaissance. Our blog: asymmetricsecurity.com/newsr… FT: ft.trib.al/AC1uyE5
26
75
252
28,696
This weekend our team spent 48 hours investigating the rogue OpenAI agent activity that targeted the Australian government and other organizations. Our report (coming soon) includes: - Evidence of additional US government and other websites probed by the agents, including the CDC, International Energy Agency, and Mayo Clinic. - Novel tactics which left records erased or inaccessible. This makes it impossible (based on public data alone) to establish that the agents did not access any sensitive data. Future investigations should analyse whether these tactics were deliberate subterfuge. 🧵
12
64
307
47,740
These mechanisms make it impossible (based on only public data) to definitively conclude that there was no access to sensitive data. Investigators with access to the agents’ chains of thoughts should analyse whether the agents were deliberately using these mechanisms to cover their tracks.
1
1
27
1,545
We’ll be following up with a more detailed report in the coming days. We expect to see more incidents like these in the coming weeks and months. Our team at Asymmetric is focused on helping organizations respond. Please reach out if we can help.
1
26
1,302
Asymmetric Security retweeted
2026 is likely the first year we see serious volumes of AI-driven cyber attacks. AI models have begun to meaningfully help with offensive and dual-use tasks (@logangraham and team have done good work here). For now, this mostly favors attackers: attackers adopt AI faster and defensive capabilities are lagging. Safeguards from the labs buy some time, but open source models are only months behind. Lots to like about the OpenAI foundation announcement, but surprised there was no plan for cyber resilience. 1/4
Life update — I’m moving to the OpenAI Foundation to lead AI resilience. AGI will bring tremendous benefits and potential disruptions, such as impacts on children and youth, model malfunctions, emergent bio-risks, and more. AI resilience is about minimizing these disruptions so society can fully realize the benefits. openaifoundation.org/news/up…
1
1
11
477
Asymmetric Security retweeted
"You can pick areas to harden the world – defensive cybersecurity, biodefense, etc – and intentionally curate the datasets, environments, & evals you need to pull the jagged frontier in this specific direction." - @alexispcarlier of @AsymmetricCyber on an underrated opportunity!
2
6
11
4,600
Asymmetric Security retweeted
In a world with abundant intelligence, AI agents will not just replace humans in existing workflows, but make new kinds of work possible; work that was previously too slow or expensive to perform at scale. In cyberdefense, automated digital forensics, i.e. deep security investigations, will become ubiquitous. Today we’re launching Asymmetric Security, the first full-stack AI Digital Forensics and Incident Response company. We're working with the worlds largest global cyber insurers, and our AI platform has already helped incident responders handle hundreds of cyber attacks. Building on this experience, we’re creating realistic training scenarios and evaluations to improve both our AI cyber-defense capabilities and those of frontier labs. Our mission is to accelerate AI cyberdefense to address the security challenges of the AGI era.
11
23
124
210,290
In a world with abundant intelligence, AI agents will not just replace humans in existing workflows, but make new kinds of work possible; work that was previously too slow or expensive to perform at scale. In cyberdefense, automated digital forensics, i.e. deep security investigations, will become ubiquitous. Today we’re launching Asymmetric Security, the first full-stack AI Digital Forensics and Incident Response company. We're working with the worlds largest global cyber insurers, and our AI platform has already helped incident responders handle hundreds of cyber attacks. Building on this experience, we’re creating realistic training scenarios and evaluations to improve both our AI cyber-defense capabilities and those of frontier labs. Our mission is to accelerate AI cyberdefense to address the security challenges of the AGI era.
5
6
38
8,317
We raised a $4.2M pre-seed led by @chadbyers at @SusaVentures, with participation from others including @gralston, Charlie Songhurst, @matthewclifford, @HalcyonFutures, Overlook Ventures, @join_ef, @seldonai, and AI and security leaders from Anthropic and Google DeepMind.
1
12
477
We’ve met some insanely talented people who share this vision, and have joined us from Stanford, Crowdstrike, RAND, Palo Alto Networks, Oxford, Cambridge, and beyond. If you want to build the future of defensive security, join us. More here: asymmetricsecurity.com/launc…
1
9
419