Chaser Systems

@chasersystems.bsky.social

DiscrimiNAT Firewall: A transparent NAT gateway alternative that allows product teams to discover and update narrow allowlists for their apps’ outbound connections, easily. https://chasersystems.com/

Three variations on subversive use of DNS by the Agent are documented in Hugging Face's technical writeup of the July 2026 security incident involving OpenAI models. In this article, @new23d.bsky.social discusses what each of these three types of DNS workarounds... chasersystems.com/blog/the-cur...

The Curious Incidents with DNS in the Sandbox at Escape-Time | Chaser Systems

What the Agent attempted with DNS in the Hugging Face–OpenAI Intrusion Incident of July 2026

chasersystems.com

DiscrimiNAT v2.40 shipped yesterday on GCP and day before on AWS. It has Canonical-supplied mitigations applied for Copy.Fail. It is also hardened to the CIS standard and therefore the exploits for Dirty Frag fail to work on it. We are monitoring the situation and will push an update if needed.

I was mighty upset with Google on 12 Feb. We had discovered that the issue affecting egress filtering for a DiscrimiNAT customer on GCP was in fact Post-Quantum Cryptography TLS handshakes. It was a combination of the most up-to-date OpenSSL version in a container image and server-side #PQC ...

Bild

Welcome to the team Lucas Pye! Lucas is joining us as an intern until mid-September and is researching what telemetry is gathered from developer machines by various popular agentic coding tools. When he's not intercepting #egress traffic you can find him climbing! (screenshot of MitMed Cursor)

BildBildBild

Wildcards are now GA from us for network egress on GCP. Took time to develop since we didn't want the solution to be trivially bypassable with SNI Spoofing [1] or cause interruptions to your traffic intermittently with false positives (as is the case with known issue FWAAS-1501 of Palo Alto [2]).

Bild