Профиль

Katie Moussouris (she/her/she-hulk/she-ra)🌻

Профиль Vively

Founder & CEO LutaSecurity @payequitynow MIT&Harvard visiting scholar, @MasonNatSec fellow, 1/2 Chamoru, 1/2 Greek all-American hacker

This is classic multiparty vuln disclosure, not new “how researchers should react if a language model discovers vulns in cryptosystems where attacks have immediate real-world impact. We believe answering this question will require input from academia, government, & industry”

Anthropic {bot}

New Anthropic research: Discovering cryptographic weaknesses with Claude. Claude Mythos Preview has helped our researchers find weaknesses in cryptographic algorithms—the mathematical methods that are used to keep data private. Read more:

My blog last week also summarizes what government should and should not do in response to Open AI’s Agentic hack of Hugging Face bsky.app/profile/k8em...

OpenFace: The Hugging Face Breach and What to Do About ItThese models are like the world's cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere. A single vulnerable package proxy stood between the mode...www.lutasecurity.comKatie Moussouris (she/her/she-hulk/she-ra)🌻

The experiment escaped the lab. OpenAI's models broke containment and breached Hugging Face. We are holding radium in our bare hands. What governments and organizations should do next, and why tighter commercial guardrails are exactly the wrong move: www.lutasecurity.com/post/openfac...

Adjust threat models not just for being the victim but also the attacker. New paper by many authors gives a detailed set of recommendations, supporting my initial assertions last week that orgs need to assume their own agents could attack others & factor that into agentic AI risk

Gadi Evron

Releasing: Post mortem analysis of the Hugging Face incident was written over the weekend by hundreds of CISOs (and reviewed by Hugging Face). Link: cloudsecurityalliance.org/artifacts/hu... (+free download) From CSA, SANSInstitute, Knostic, [un]prompted, RSAC, FIRST

Important context for this story is that this appears to be a case where the border search exception was used pretextually to go after someone for political reasons.

Zack Whittaker

New, by me: The Justice Department is prosecuting an American for allegedly providing U.S. border agents with a "duress" passcode that wiped the contents of his phone when they entered it. We've confirmed the phone was running GrapheneOS. Bypass for ad-blockers: web.archive.org/web/20260724...

The guardrails were coming from inside the (White)house - Anthropic’s models refused to help Hugging Face analyze their intrusion. We don’t need more guardrails impeding defenders when they need AI most. “Hugging Face tried using Anthropic Fable 5 & Opus …both models refused, citing guardrails…”

The Wall Street Journal

They were like high-school students trying to hack into the textbook company to cheat on their final exam. Only these hackers weren’t human.

The experiment escaped the lab. OpenAI's models broke containment and breached Hugging Face. We are holding radium in our bare hands. What governments and organizations should do next, and why tighter commercial guardrails are exactly the wrong move: www.lutasecurity.com/post/openfac...

OpenFace: The Hugging Face Breach and What to Do About ItThese models are like the world's cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere. A single vulnerable package proxy stood between the mode...www.lutasecurity.com

My comments in @reuters.com on OpenAI’s admission that their latest model pulled a Houdini & escaped the lab autonomously to hack Hugging Face. We must test these models’ full capabilities, but we must be able to contain them, or this won’t be the last breach www.reuters.com/technology/o...

OpenAI says AI models went rogue during testing, triggering 'unprecedented' breach at startupOpenAI said on Tuesday ‌that an autonomous agent powered by its advanced AI models went rogue during a security test and triggered a hack that compromised the infrastructure of AI startup Hugging Face...www.reuters.com

Consider donating to #Bavi relief efforts: www.paypal.com/donate/?host... This is for donations to the Micronesia Climate Change Alliance, which is coordinating help on the ground. #Luta #Marianas

Donate to Micronesia Climate Change AllianceHelp support Micronesia Climate Change Alliance by donating or sharing with your friends.www.paypal.comKatie Moussouris (she/her/she-hulk/she-ra)🌻

www.npr.org/2026/07/05/g... “This is a powerhouse super typhoon & this is going to be a very grim outlook for any island that takes a direct hit & that still looks like it could be the island of Rota” #supertyphoon #bavi #climatecatastrophe

Следующие публикации