AI, ML, research, data, cybersecurity, privacy, learning and improving, solution focused, critical thinking, startups, business, VALUE CREATION $

Global
aitization 𝕏  retweeted
0-day flaws in ChatGPT let a local unprivileged attacker bypass OpenAI's safeguards, subvert the agent on macOS, and take over your Dot. Responsibly reported to (and ack'd by) OpenAI. Our research into the (in)security of AI agents continues... 🫠
Dots are here! A new way to use AI that works 24/7 for you; get more of your time and attention back to work at a higher level. openai.com/index/introducing…
6
11
198
17,409
aitization 𝕏  retweeted
As AI systems become more capable at cybersecurity, an important question is emerging around who should be allowed to use that capability and under what conditions. Much of the current safety debate focuses on controlling access through proprietary models, API policies, usage restrictions, and safeguards designed to prevent advanced cyber capabilities from being misused. The problem is that cybersecurity is adversarial. Attackers do not respect acceptable-use policies, enterprise procurement rules, data residency requirements, or third-party risk controls. They can run open models locally, modify them, remove safeguards, and build systems around capabilities that already exist. Defenders are the ones operating under the strictest constraints, and that creates an asymmetric form of safety where legitimate security teams are restricted from capabilities that determined attackers can still obtain. Cybersecurity has been through a version of this debate before, in the late 1990s and early 2000s. Vulnerability disclosure, exploit development, scanners, and offensive security tools were all controversial, because the same technology could be used to attack systems or defend them. Over time, tools like Nmap and Metasploit, public vulnerability research, and reproducible exploits became part of the basic infrastructure of modern security. The takeaway was not that dual-use technology is harmless, but that restricting the knowledge available to defenders does not make the underlying offensive capability disappear. AI brings that argument back at a much larger scale. The question is not whether these capabilities can be misused. They can. The question is whether restricting legitimate access meaningfully restricts attackers once capable open models already exist. We think it increasingly restricts defenders instead. Machine-speed attacks require machine-speed defense, and defenders need models they can run, control, and improve inside the systems they are responsible for protecting.
today we're releasing apex-flash-1, our first open-weights model for security research post-trained on real vulnerabilities we found and got paid for. we are also releasing the abliterated variant for researchers who want fewer refusals in their own authorized workflows. how we built it: cantina.security/apex-flash
6
7
75
6,941
aitization 𝕏  retweeted
AI companies are calling for regulation in ways that let them set the rules, not independent parties. “If you read between the lines, everything [Amodei] advocates [for] is something that would help companies like Anthropic,” says AI Now's @bmilanov bit.ly/3TxmJbq
2
10
14
2,234
AI security, privacy, safety and reliability. 💯
52
obviously there’s a practical and clear solution to monitor / control AI systems / LLMs. it’s very simple. AI was designed and developed by humans therefore we can easily manage it. anything else is fluff and hype.
54
aitization 𝕏  retweeted
OpenAI’s leadership still doesn’t get it. Greg Brockman might be brilliant at training AI, but being brilliant at one thing doesn’t make you brilliant at everything. He either has nefarious intent, or he’s incompetent when it comes to acknowledging that OpenAI has a serious problem with testing, quality improvement, process management, release management, monitoring, alerting, incident response, and incident disclosure. OpenAI isn’t a startup. It’s a massive corporation with too much power. I have no problem calling it out in blunt language. Greg and Sam should be held accountable. I was first introduced to software testing when I helped to launch new technology and products at AOL. I was the Global Test Manager responsible for launching AOL Instant Messenger (AIM) in 1997. That stuff was easy. Leading the testing of significant telecom infrastructure and services is much more complicated. Changing an IP address might take a developer less than a minute, but seeking and receiving approval for that change could take 2 to 4 weeks depending on the potential risks associated with the change. A tiny API change might take a good developer 15 minutes. If that change could prevent 50 million people from paying you, spending 100x or 1,000x longer testing it than writing it is completely rational. You measure the potential impact of failure, understand your exposure, and apply controls accordingly. Process is everything. Good process is what allows you to move quickly without being reckless. You certainly shouldn’t release critical software without it. Test managers, testers, infosec professionals, release managers and other independent functions are just as important as the people writing the code. They should be involved from the first requirements document, through technical requirements, design, development, testing, release and production monitoring. Even when something meets every documented requirement, that doesn’t mean it’s fit for purpose. Testers are the people best placed to identify that gap because their job is to find what developers didn’t anticipate. Developers typically understand the piece they’re building better than anyone else, but that also means they rarely know the entire system. Good testers do. They understand how the whole system behaves end to end, where components depend on each other, where assumptions break, and what happens when something fails outside the happy path. Testers don't just confirm something works, they try their best to break it. And that's supposed to happen *before* anything is released to customers. Stopping or slowing development of anything, including model training, doesn't do anything to address the failures behind OpenAI’s security incidents. Those failures point directly to inadequate independent testing, containment, release controls, monitoring, alerting, incident response and disclosure around the people writing the code. Slowing training doesn't fix any of that. Training is not testing. Everything OpenAI says and does becomes another data point for cybersecurity professionals and people with serious testing backgrounds assessing how the company manages risk. OpenAI is now deploying models it says can find previously unknown vulnerabilities and develop ways to exploit them across well-protected systems without a person guiding each step. That makes weak testing, containment, monitoring, release management, and disclosure more serious, not less. If Greg and the team keep deploying systems with those capabilities after industry experts repeatedly identify failures in testing and release control, the liability argument gets much harder for them the next time one of their so-called "rogue agents" compromises a third party. The AI is not going rogue, the team building it are.
Practical guidelines on securing frontier RL training, reflecting our current learnings:
15
29
94
4,779
aitization 𝕏  retweeted
As private companies, OpenAI and Anthropic are overwhelmingly financed by the world's richest people. When Dario Amodei or Sam Altman were running around telling the media that AI was going to destroy most jobs, make most white-collar workers unemployed, and usher in an era of 'hyper-inequality,' as Amodei put it, they weren't talking to you or me. Their target audience for this pitch was global investors - aka the world's richest people. Capital piled into these companies at an unprecedented rate. The AI buildout is currently on track to raise more capital than anything else in history. A technology that was *explicitly marketed* as a jobs-destroying poverty-generation machine got the global rich more excited than anything else in history. The AI bubble will burst. But we won't forget. Join a union. Tax the rich.
31
289
827
21,069
aitization 𝕏  retweeted
It continues to be notable how many AI researchers (who understand how AI actually works) believe in neither AI doom nor massive uncontrollable acceleration, while non AI researchers (who have limited knowledge) have very definite and certain views on the topic.
85
35
354
23,772
aitization 𝕏  retweeted
Hearing AI regulation is in the air, especially with a misguided tone of “open dangerous, closed safe” so it felt timely to re-up this one. There are ways to make the AI industry safer without kneecapping transparency, education, and competition. interconnects.ai/p/banning-o…
14
31
120
17,309
aitization 𝕏  retweeted
The AI Productivity Delusion: As with previous technological revolutions, it is natural to focus on AI's net effects: Will it create more than it destroys? But unlike previous eras of creative destruction, the real question this time is, “Create more of what?” project-syndicate.org/commen…
31
75
326
31,776
Stay focused. move fast. learn quickly and most importantly avoid drift and noise from the outside. 😎📈
1
125
aitization 𝕏  retweeted
🛡️ Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access Details: cybersecuritynews.com/linux-… A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying host system. The issue affects KVM/arm64 environments where nested virtualization is enabled, creating a serious risk for multi-tenant cloud infrastructure and systems that allow untrusted users to create virtual machines. The bug affects how the kernel calculates the size of a memory region it must invalidate from the virtual CPU’s pseudo-Translation Lookaside Buffer, or pseudo-TLB. Under normal conditions, KVM must invalidate stale memory translations after memory mappings change. #cybersecuritynews
5
40
177
7,482
aitization 𝕏  retweeted
Please don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀 Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life. But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it. Let me show you. 🧵
Introducing Muse, the personal agent that understands your goals and works 24/7 to get things done for you.
42
131
657
235,318
aitization 𝕏  retweeted
AIs and LLMs don’t have agency. Period. Autonomy ≠ agency. Conflating the two is how we end up fear mongering and politicking.
86
42
348
10,345
aitization 𝕏  retweeted
nit: when someone says 10,000 agents they really mean 1 model pursuing 10,000 threads/contexts in parallel. it's not the same diversity of thought as 10,000 people.
38
25
313
72,841
aitization 𝕏  retweeted
Agents can be AI, but agency is human. It is every individual’s responsibility to empower our own agency, with the help of tools. But the North Star should always remain human centered.
194
381
2,435
179,202
aitization 𝕏  retweeted
Almost everyone is watching their AI spend more closely these days. As the price of LLM tokens moves closer to their real cost, teams have to start to optimize spend as much as they can. Prompt caching is one of the key areas that can help but most teams are likely not using this very much yet. The article below discusses a number of prompt caching patterns using the Converse API with Bedrock on AWS. One thing I didn't know is that cache entries can be shared within an account and Region. This means there will be multi-tenancy implications and an approach like prepending a SHA-256 hash of a tenant ID may be needed. This article from Daniel ABIB also discusses the current limits and costs. Some working notebooks for each scenario are included as well. Check it out! lckhd.eu/fHZGmT #Bedrock #PromptCaching #GenerativeAI #FinOps #MultiTenancy
9
11
18
880
aitization 𝕏  retweeted
NEW: Apple is preparing to implement a kernel level EDR system in iOS When activated, the watchdog, known as com.apple.iokit.EndpointSecuritySE, which is still in beta, will monitor deep system telemetry in order to spot signs of exploitation More details:
23
156
1,581
140,815