Security REsearch @Anthropicai · Breaking & Fixing AI Failure Modes | Founder @binarly_io · @SBOM_Tools · @REhints | Author “Rootkits & Bootkits" (bootkits.io)

San Francisco, CA
Agree on verification, but I'd push it further. Memory safety is a symptom, not the cause. We got here because of design decisions and trade-offs we made all along, and you can see it in pretty much every recent Linux kernel disclosure. Throwing more tokens at the attack surface won't save us either. Nothing we have today is ready for AI-driven vuln research at this scale, and finding and fixing bugs with AI doesn't change that. What we actually need is redesign and architecture validation with AI, formal methods where we can, and not accepting attack surface at the design phase in the first place. That's just not how we build software today. Patching known bugs doesn't touch the root cause, and hardware has the same problem.
Security will become a larger and larger function in software companies. Security is verification engineering (eg: “my code is probably memory-safe”), as well as capital allocation (“what surface should I throw most tokens at?”) For startups, it’s a challenge and opportunity. As the world’s paranoia grows given ever-more-sophisticated AI adversaries, how can you trust a 2-person-and-a-dog company? But conversely, given the dire state of global cybersecurity and increasing reliance on centralization, as always, there’re vast areas that small teams can now disrupt that I’m excited to invest in.
17
15
73
7,889
Alex Matrosov retweeted
I started learning low-level software when reading and implementing graphics engines. In the mid 90s, you wrote hand-optimized assembly to render via the CPU. The first x86 assembly I ever wrote was an anti-aliased scanline renderer. Analyzing this bug was blast from the past.
CVE-2026-86950: The Great Glyph Grift calif.io/research/the-great-…
2
7
50
4,310
Alex Matrosov retweeted
Introducing Claude Sonnet 5.5, the second model in the Claude 5.5 family. It’s a clear upgrade over Sonnet 5, runs more than 30% faster, and costs up to 30% less for most work.
1,928
4,458
55,733
12,516,361
Alex Matrosov retweeted
Replying to @ZackKorman
This topic is more complicated than it looks. As an industry, we've definitely made a lot of progress in cyber over the years. But this is different, very different from what we've dealt with before. Look at the spike in fixed vulnerabilities across all the big vendors. And this isn’t a one-off event, it's a continuous trend. What it shows is that our understanding of cybersecurity in general is right, but the way we've solved these problems in the past is not. AI is exposing all the obscurity and complexity across the tech stack, including hardware, in exactly the places where problems were traditionally hard for human researchers to find. At the same time, threat actors are getting a force multiplier from AI without investing in new resources or building new expertise. And on top of that, every new model outpaces the previous one, so yesterday's statements and assumptions quickly become wrong. This isn't a static risk. It's highly dynamic, and things are changing and escalating far faster than the industry, or the tech stack, can react.
3
4
41
2,991
Alex Matrosov retweeted
Our CFP is open and we're especially looking for hacking magic 👾🪩🪄 Learn more about the content we're looking for on our Sessionize! sessionize.com/districtcon
7
8
1,960
Alex Matrosov retweeted
Another point, the HW and FW security boundaries are our last frontier for building real hardwired boundaries for virtualization, memory isolation, and hardened agent sandboxing. In the end, the whole confidential computing movement is more about cloud cost optimization than anything else. It's just broken by design, you can't build a secure stack if what's underneath has been broken for many years.
3
26
2,338
Alex Matrosov retweeted
Our craziest escape yet: The @Accomplish_ai research team was able to exploit a vulnerability in Cloudflare Containers that let a sandbox read other customers' files - SQLite DBs, Chromium profiles, .env files etc, Cloudflare Sandboxes and Browser Run run on the same disk implementation and were affected too. We reported this to @Cloudflare, who super quickly fixed it. Read @CloudflareDev post in collaboration with Accomplish researcher @orenyomtov on their official blog: blog.cloudflare.com/containe…
36
89
802
129,588
Alex Matrosov retweeted
As Flare-On starts I am happy to announce the official Hex-Rays IDA MCP Server is out! 🥳 Details and links below ⬇️
10
73
379
20,177
Alex Matrosov retweeted
I'm hiring an exceptional Offensive Security Researcher for my team at NVIDIA (Offensive Security Research - OSR). Firmware, microcode, RISC-V, hypervisors, and shipping mitigations like HW CFI, Memory Tagging, and Pointer Masking from the ground up. jobs.nvidia.com/careers?quer…
12
84
469
45,460
Alex Matrosov retweeted
I put my @UnpromptedAU slides up at justdionysus.github.io/slide… — a bit of reflection on exploit development in the age of AI. My TL;DR is keep pushing to understand complex things, be honest with your own understanding, and use AI as a power tool to increase pace and depth.
4
68
240
32,493
Alex Matrosov retweeted
Introducing Claude Opus 5.5, the first model in our new Claude 5.5 family. It performs at the level of Claude Fable 5.1 for most tasks, and costs 40% less to run than Opus 5.
3,342
9,034
97,071
28,006,502
Alex Matrosov retweeted
We implemented 1024-bit RSA signature forgery in nearly SNFS time! Temporary access to an HSM allows an attacker to forge arbitrary signatures (without factoring). Join work with Laura (1st author!), Adam, Nadia, and Emmanuel github.com/ucsd-hacc/NSNFSSS…
9
45
169
52,718
Unfortunately, the complexity of the hardware and firmware supply chain has the same negative effect on how cryptographic artifacts are managed, or mismanaged, across the ecosystem. This is a reminder of the scale of the problem, based on just one documented data breach.
⛓️Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem. It appears that Intel BootGuard may not be effective on certain devices based on the 11th Tiger Lake, 12th Adler Lake, and 13th Raptor Lake. Our investigation is ongoing, stay tuned for updates.
3
16
73
10,461
Another point, the HW and FW security boundaries are our last frontier for building real hardwired boundaries for virtualization, memory isolation, and hardened agent sandboxing. In the end, the whole confidential computing movement is more about cloud cost optimization than anything else. It's just broken by design, you can't build a secure stack if what's underneath has been broken for many years.
3
26
2,338
Alex Matrosov retweeted
The era of AI requires a significant paradigm shift in the hardware and firmware layers. Today we are building on top of hardware and computational primitives that were defined decades ago, and they don’t serve us well for the future of AI infrastructure at the current exponential scale. If you look back at history, it’s always outdated patterns that hold us back from progress. Every transformational shift happens when we invent a new paradigm that defines the next breakthrough in technology evolution. I’m very excited about it, and it’s time to build an AI-native hardware ecosystem.
Chips, memory, interconnects, storage, robotics. Compute hardware infrastructure is undergoing the largest transformation in 30 years. Whatever innovation challenges lie ahead, computer science will be central to the solution. And we've raised $1.1B to help that along.
3
6
30
5,027
Alex Matrosov retweeted
Your weekend reading assignment has arrived early. A first taste of the upcoming, still-under-wraps Phrack 73: “THE PROXY THAT MADE NO SENSE” by @mikko. archives.phrack.org/dl/73/th…
2
55
160
30,871
Alex Matrosov retweeted
The slides from my talk at Microsoft Bluehat Singapore are public here: thomasdullien.github.io/abou… It's my first BlueHat talk since the Vista days.
24
126
692
161,281
This tweet has aged a few months, and frontier progress has only strengthened my feelings in this direction. Twelve months ago my thought was that AI is just another tool, automating parts of the RE/VR process. Now I'm more of the impression that it operates like the creative mind of an experienced researcher, who thinks beyond established patterns and finds new attack paths. The most effective vulnerability researcher is no longer human.
Lately I've been thinking about how AI is changing vulnerability research and reverse engineering. VR and RE are some of the hardest workflows to parallelize. Even with great knowledge transfer and team practices, you usually default to one person per vuln or RE task. The work is just too context-heavy to split. AI breaks that ceiling. It's no longer "one researcher, one task", it's you working one angle while Claude annotates disassembly code, explores another path, or helps you piece together what the last result means. Watching this land in domains we assumed were fundamentally serial is wild.
8
11
81
8,910
Alex Matrosov retweeted
We've reached the moment in time where (unsafeguarded, unmonitored) AI actually does just pose a national security risk. The biological misuse we caught is the most concerning to me. We work hard to stop this. But in a world of proliferation, we need to rapidly build defenses against it. (I'm actually fairly optimistic about biodefense + cyberdefense) This is an incredible megareport by our threat intel team
We're publishing our most detailed threat intelligence report to date. It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them. We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies. These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve. We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop. Read the report: anthropic.com/threat-intelli…
59
101
832
159,041