For agent sandboxes needing domain-based #egress filtering on outbound traffic «without» TLS termination, #DiscrimiNAT OTF offers policy discovery, and SNI spoofing prevention. DNS spoofing and abuse of shared IPs on CDNs won't work thru it. Search in cloud console: DiscrimiNAT
Chaser Systems
@chasersystems.bsky.social
DiscrimiNAT Firewall: A transparent NAT gateway alternative that allows product teams to discover and update narrow allowlists for their apps’ outbound connections, easily. https://chasersystems.com/
Meet the team at @fwdcloudsec.org to see how we can secure your outbound network traffic - even if agents or otherwise tinker with DNS resolution to achieve intermittent #egress like they did in HF - OAI incident.
Come grab a pair! We've gone all in on socks this year for @fwdcloudsec.org EU 2026 🧦 Various sizes of ethically made, high quality socks, produced by the excellent people at @Stand4Socks Every sock has a sister pair that has been donated to a rough sleeper.
Come grab some free socks & stickers from us at @fwdcloudsec.org EU London 2026. The team are hard at work preparing the stall, fiddling with electronics 👨🔬 and trying the socks on for size 🧦
Three variations on subversive use of DNS by the Agent are documented in Hugging Face's technical writeup of the July 2026 security incident involving OpenAI models. In this article, @new23d.bsky.social discusses what each of these three types of DNS workarounds... chasersystems.com/blog/the-cur...
The Curious Incidents with DNS in the Sandbox at Escape-Time | Chaser Systems
What the Agent attempted with DNS in the Hugging Face–OpenAI Intrusion Incident of July 2026
chasersystems.com
v2.50 of DiscrimiNAT OTF now released on GCP. OTF* means Outbound Traffic Filtering. This version brings StartTLS SMTP support, and default rules, for #egress filtering on the cloud. *See MITRE D3FEND D3-OTF Release notes: chasersystems.com/docs/discrim...
DiscrimiNAT OTF Google Cloud Release Notes | Chaser Systems
Review DiscrimiNAT OTF Google Cloud features, fixes, compatibility changes, and deployment-module updates.
chasersystems.com
v2.50 of DiscrimiNAT OTF now released on AWS. OTF* means Outbound Traffic Filtering. This version brings StartTLS SMTP support, and default rules, for #egress filtering on the cloud. *See MITRE D3FEND D3-OTF Release notes: chasersystems.com/docs/discrim...
DiscrimiNAT OTF on AWS Release Notes | Chaser Systems
Review DiscrimiNAT OTF on AWS features, fixes, compatibility changes, and deployment-module updates.
chasersystems.com
Happy to reassure our users that the #egress evasion TTPs used by the Agent in the OpenAI & HuggingFace incident have long been mitigated in #DiscrimiNAT OTF (outbound traffic filtering). In fact in our demo, we show these attacks being caught. #2 is SNI spoofing, btw huggingface.co/blog/agent-i...
We were just assigned a /29 #IPv6 block by RIPE. We now have 633,825,300,114,114,700,748,351,602,688 IPv6 addresses. inet6num: 2a05:6340::/29 netname: UK-CHASERSYSTEMS-20260518 country: GB org: ORG-CSL88-RIPE admin-c: AA44781-RIPE apps.db.ripe.net/db-web-ui/lo...
DiscrimiNAT v2.40 shipped yesterday on GCP and day before on AWS. It has Canonical-supplied mitigations applied for Copy.Fail. It is also hardened to the CIS standard and therefore the exploits for Dirty Frag fail to work on it. We are monitoring the situation and will push an update if needed.
Is Post-Quantum Cryptography #PQC being used by your apps when calling other APIs? New feature in the works that'll let you capture your progress with updating the crypto libs #DiscrimiNAT is an #egress filter for your cloud with monitoring, analytics, dry-run & enforcement
Another fantastic review of our DiscrimiNAT Firewall. If you need a developer-friendly #egress filtering solution for AWS or GCP, book a demo here: chasersystems.com Link to review: www.g2.com/products/dis...
I was mighty upset with Google on 12 Feb. We had discovered that the issue affecting egress filtering for a DiscrimiNAT customer on GCP was in fact Post-Quantum Cryptography TLS handshakes. It was a combination of the most up-to-date OpenSSL version in a container image and server-side #PQC ...
v2.30 of DiscrimiNAT Firewall for egress filtering is now Generally Available. Key improvements include support for Post-Quantum Cryptography #PQC TLS handshake. AWS release notes: chasersystems.com/docs/discrim... GCP release notes: chasersystems.com/docs/discrim...
Sponsoring the local #Rust meetup in #Cambridge is way we bring the community together a few times a year. Follow the event page at www.meetup.com/cambridge-ru... and @cambridgerust.bsky.social here Rust has played a critical role in the cloud security solutions we ship in terms of speed & safety
What data do coding agents send, and where to? Our report seeks to answer some of our questions for the most popular coding agents. Incidentally, a side-effect was running into OWASP LLM07:2025 System Prompt Leakage. You can see the system prompts in the appendix. chasersystems.com/blog/what-da...
Looking at us-east-1 this morning like... 👀 We're giving away 1,000 of our "It's always DNS" stickers and sticky-notes to decorate your laptops! Fill in the linked form below and we'll get it mailed directly to you, wherever you are in the world. forms.office.com/e/14jHFdU9Kv #aws #itsalwaysdns
Azure default outbound access connectivity change postponed from 30 Sep '25 to 31 Mar '26. azure.microsoft.com/en-us/update...
Azure updates | Microsoft Azure
Subscribe to Microsoft Azure today for service updates, all in one place. Check out the new Cloud Platform roadmap to see our latest product plans.
azure.microsoft.com
v2.20 of DiscrimiNAT Firewall now available on GCP 🎉 chasersystems.com/docs/discrim...
Release Notes | Chaser Systems
version 2.20 (2025-08-27)
chasersystems.com
v2.20 of DiscrimiNAT Firewall just released on AWS 🎉 chasersystems.com/docs/discrim...
Release Notes | Chaser Systems
version 2.20 (2025-08-27)
chasersystems.com
Another short-lived credential leak causes widespread data theft. Here at @chasersystems.bsky.social we're researching & prototyping practical second-factor methods for service account style usage. cloud.google.com/blog/topics/...
Widespread Data Theft Targets Salesforce Instances via Salesloft Drift | Google Cloud Blog
UNC6395 stole data from Salesforce instances by exploiting compromised OAuth tokens from the Salesloft Drift app.
cloud.google.com
Cambridge Rust meetup August 13th 🦀 www.meetup.com/cambridge-ru... Event sponsored by Chaser Systems: chasersystems.com! #rust #cambridge
Monthly Rust Meetup, Wed, Aug 13, 2025, 6:45 PM | Meetup
## Details Join us for the new and improved monthly Cambridge Rust meetup, hosted at Quantinuum's office on Hill's Road. Speaker: **Ian Jackson** Ian Jackson is a longst
meetup.com
Welcome to the team Lucas Pye! Lucas is joining us as an intern until mid-September and is researching what telemetry is gathered from developer machines by various popular agentic coding tools. When he's not intercepting #egress traffic you can find him climbing! (screenshot of MitMed Cursor)
We're back at @fwdcloudsec.org again today, drop by our booth and try our mini-CTF to win a #YubiKey. Only 4 left, so be sure to come by early!
We're demoing DiscrimiNAT Firewall at the venue this year. See you in Denver!
We're happy to announce Chaser Systems is a Bronze sponsor for fwd:cloudsec North America 2025! chasersystems.com
TLS ECH (formerly ESNI) is an emerging threat in traffic observability. Learn about what it is, its background and original purpose, and how to disable it in controlled environments - especially Chrome and headless Chrome in the linked solution article: chasersystems.com/blog/disabli...
Our founder @new23d.bsky.social's talk accepted for @fwdcloudsec.org at Denver in June on AWS IAM Roles Anywhere with ACME-enabled PKI certs distribution (using Let's Encrypt Staging) Videos will be available on YouTube later and we'll post an update when they are.
We make it easier for you to enable an outbound network traffic firewall in full allowlist enforcement mode -- with discovery, dry run and micro-segmentation. Available on AWS and GCP. Search for DiscrimiNAT Firewall in your cloud web console. #egress #filtering
Wildcards are now GA from us for network egress on GCP. Took time to develop since we didn't want the solution to be trivially bypassable with SNI Spoofing [1] or cause interruptions to your traffic intermittently with false positives (as is the case with known issue FWAAS-1501 of Palo Alto [2]).