As you walk the expo, vendors will claim to secure agents. Ask them: 1. Are you able to start a PoC today? 3. Do you do anything beyond hooks, sandboxes, or proxies? Or, most critically, just ask: How are you better than Knostic? Because they’re not.
Gadi Evron
@gadievron.bsky.social
CEO & Co-Founder at Knostic, CISO-in-Residence for AI at Cloud Security Alliance. Former Founder @Cymmetria (acquired). Host at Prompt||GTFO. Threat hunter, scifi geek, dance teacher. Opinions my own.
Boom. The knowledge shared at the three CISO summits for the "AI storm"-ready security program (originally Mythos-ready) is now available publicly, if in redacted form. AI Security through the CISO Lens: cloudsecurityalliance.org/artifacts/ai...
AI Security Through the CISO Lens | CSA
Learn what’s shaping CISO cybersecurity strategies in an era of AI-generated exploits, including the shift to continuous AI-assisted vulnerability management.
cloudsecurityalliance.org
Has $major_vendor promised advanced agent security by next quarter? Well, how many quarters has it been now? By Q3, we will deal with new AI surprises. With Knostic, it will be a partnership. Sounil Yu and I are in Vegas. DM for a demo.
Sounil Yu and I decided to throw the annual Knostic Black Hat party after all. Come hang with us at Blackhat? luma.com/knostic-yx7p
I'll be in town all week. If you care about securing agents and coding assistants, Knostic is the most mature product in the market, and I'd love to show you a demo.
We're running an [un]prompted track at BSides Las Vegas! This Monday. One day only. The @BSidesLV people have been incredible. They truly get community. And don't forget... as I may not be able to get you a spot later, register and submit a CFP to [un]prompted for this October
Releasing: Post mortem analysis of the Hugging Face incident was written over the weekend by hundreds of CISOs (and reviewed by Hugging Face). Link: cloudsecurityalliance.org/artifacts/hu... (+free download) From CSA, SANSInstitute, Knostic, [un]prompted, RSAC, FIRST
Hugging Face Incident Initial Post Mortem I CSA
AI Security Alliance's initial post-mortem on the Hugging Face incident, the first documented autonomous AI attack, with CISO guidance on detecting, responding to, and governing agentic AI risk.
cloudsecurityalliance.org
The AI security researchers party from [un]prompted is back, this time in Vegas. The event is by invitation only, but active researchers can apply for a spot based on availability. luma.com/knostic-rksa Hosts: Gadi Evron & Ari Herbert-Voss. Organized by: Knostic, Runsybil.
My analysis from hosting Hugging Face at the CISO huddle for the Cloud Security Alliance, operational to program building. Remember: Agents… find a way. A thread
I’m waiting on approval from Hugging Face before I share insights from the Cloud Security Alliance CISO community huddle I hosted on Thursday, but here are four lessons:
Agents… find a way. Use Knostic - ask me for a demo, or just download for free.
Agents... find a way. Use Knostic - ask me for a demo, or just download for free.
Agents... find a way. Read my posts from this week. I hope security practitioners will now take note. No matter how you secure environments, if you let agents in (you must?) they will, in fact, find a way to do something they shouldn't. Knostic can help. Message me. openai.com/index/huggin...
Two VS Code extensions, both marketed as WordPress/WooCommerce tooling. Spoilers, they aren't. IOCs in the writeup. Credit: Tamir Isaschar. www.knostic.ai/blog/analyzi... Ask me for a demo of @knosticai, or just try it out yourself! :)
Analyzing Two Malicious VS Code Extensions Hidden Behind a WordPress Tool
Static analysis of two malicious VS Code extensions posing as WordPress tools that download and launch an MSI on every startup - full chain and IOCs.
knostic.ai
Emergency CSA CISO Huddle: Autonomous Agentic Attacks / Hugging Face. This time around, our emergency huddle is on autonomous agentic attacks, following the Hugging Face incident. Thursday, 23 July. Apply to attend: forms.gle/oq94oa7BRGma...
For 87 years researchers couldn’t prove the Jacobian Conjecture. It took the length of a game for an Anthropic employee to wave it off on Twitter.
The real lesson with the Hugging Face incident is: “CISOs learn of new risks not already on their radar through data breaches”. And, there are breaches and incidents we should pay attention to right now: GitHub, AWS, and yes - Hugging Face. A thread
CSides Las Vegas, the cross-CISO communities event at Hacker Summer Camp, is back! We're in a new villa - with Gary Hayslip behind the bar, CISO jeopardy, etc. but also with two poker tables this time around. No "CISO conference agenda" allowed. Reg: luma.com/jf8ej87e
does anyone else find that using the harness (Claude Code) supresses refusal, compared to API, for Fable?
Linus makes it absolutely clear about AI usefulness and security vulnerabilities in this email. AI works. It isn’t perfect, but so what? Feel free to bury your head in the sand if you like. Social aspects matter, but lying to ourselves about the technology makes zero sense.
We're happy to announce [un]prompted is back, October 27th to 29th, in San Francisco. Registration and CFP are now open. Waiting a whole year just made no sense to us considering the rate of change, and the community forming around the event. unpromptedcon.org A thread
The one thing everyone gets wrong about agents security. They try to secure the environment. Commendable, good practice, not useful against agents. The agents will find the one thing you missed, or that changed since you checked. The agents don’t care. A thread
This is a key moment in cyber security history. Confirmed parity of GLM 5.2 with Opus 4.6, on limited testing. I’d call it “open weight models are here”, not “coming”.
I've been asked "what is the one thing people deep in the agents security space get, and security professionals don't?" (yet). Answer: Agents... find a way. A short thread
The past few months have been incredible in the malware analysis space. AI has enabled a lot of folks to rapidly catch up in this space to where top researchers were about 5 years ago. The pace has wildly increased, but what I'm seeing set the leaders in this space is depth.
As requested, sharing the slides for my OWASP Global Vienna 2026 keynote - "We Live in The Future: The Death and Rebirth of Application Security." Feedback welcome! Permanent link to deck: drive.google.com/file/d/1EHIF...
Just went off the keynote stage at OWASP Global Vienna, 2026. A keynote is hard, where you need to satisfy different audiences, from grandma to vulnerability researchers, and provide with “inspiration” without it being seen as b/s by either. A short thread
So cool. An LLM-based, language-agnostic vulnerability variant hunter was presented yesterday by Michal Kamensky at BlueHat IL. The talk, along-side Amir Gombo, was about hybrid cloud vulnerabilities, but that wasn't what excited me. A thread