Gadi Evron

@gadievron.bsky.social

CEO & Co-Founder at Knostic, CISO-in-Residence for AI at Cloud Security Alliance. Former Founder @Cymmetria (acquired). Host at Prompt||GTFO. Threat hunter, scifi geek, dance teacher. Opinions my own.

As you walk the expo, vendors will claim to secure agents. Ask them: 1. Are you able to start a PoC today? 3. Do you do anything beyond hooks, sandboxes, or proxies? Or, most critically, just ask: How are you better than Knostic? Because they’re not.

Boom. The knowledge shared at the three CISO summits for the "AI storm"-ready security program (originally Mythos-ready) is now available publicly, if in redacted form. AI Security through the CISO Lens: cloudsecurityalliance.org/artifacts/ai...

AI Security Through the CISO Lens | CSA

Learn what’s shaping CISO cybersecurity strategies in an era of AI-generated exploits, including the shift to continuous AI-assisted vulnerability management.

cloudsecurityalliance.org

Has $major_vendor promised advanced agent security by next quarter? Well, how many quarters has it been now? By Q3, we will deal with new AI surprises. With Knostic, it will be a partnership. Sounil Yu and I are in Vegas. DM for a demo.

We're running an [un]prompted track at BSides Las Vegas! This Monday. One day only. The @BSidesLV people have been incredible. They truly get community. And don't forget... as I may not be able to get you a spot later, register and submit a CFP to [un]prompted for this October

The AI security researchers party from [un]prompted is back, this time in Vegas. The event is by invitation only, but active researchers can apply for a spot based on availability. luma.com/knostic-rksa Hosts: Gadi Evron & Ari Herbert-Voss. Organized by: Knostic, Runsybil.

Bild

I’m waiting on approval from Hugging Face before I share insights from the Cloud Security Alliance CISO community huddle I hosted on Thursday, but here are four lessons:

Two VS Code extensions, both marketed as WordPress/WooCommerce tooling. Spoilers, they aren't. IOCs in the writeup. Credit: Tamir Isaschar. www.knostic.ai/blog/analyzi... Ask me for a demo of @knosticai, or just try it out yourself! :)

Analyzing Two Malicious VS Code Extensions Hidden Behind a WordPress Tool

Static analysis of two malicious VS Code extensions posing as WordPress tools that download and launch an MSI on every startup - full chain and IOCs.

knostic.ai

The real lesson with the Hugging Face incident is: “CISOs learn of new risks not already on their radar through data breaches”. And, there are breaches and incidents we should pay attention to right now: GitHub, AWS, and yes - Hugging Face. A thread

CSides Las Vegas, the cross-CISO communities event at Hacker Summer Camp, is back! We're in a new villa - with Gary Hayslip behind the bar, CISO jeopardy, etc. but also with two poker tables this time around. No "CISO conference agenda" allowed. Reg: luma.com/jf8ej87e

Bild

Linus makes it absolutely clear about AI usefulness and security vulnerabilities in this email. AI works. It isn’t perfect, but so what? Feel free to bury your head in the sand if you like. Social aspects matter, but lying to ourselves about the technology makes zero sense.

BildBild

We're happy to announce [un]prompted is back, October 27th to 29th, in San Francisco. Registration and CFP are now open. Waiting a whole year just made no sense to us considering the rate of change, and the community forming around the event. unpromptedcon.org A thread

The one thing everyone gets wrong about agents security. They try to secure the environment. Commendable, good practice, not useful against agents. The agents will find the one thing you missed, or that changed since you checked. The agents don’t care. A thread

Bild

This is a key moment in cyber security history. Confirmed parity of GLM 5.2 with Opus 4.6, on limited testing. I’d call it “open weight models are here”, not “coming”.

Bild

The past few months have been incredible in the malware analysis space. AI has enabled a lot of folks to rapidly catch up in this space to where top researchers were about 5 years ago. The pace has wildly increased, but what I'm seeing set the leaders in this space is depth.

Just went off the keynote stage at OWASP Global Vienna, 2026. A keynote is hard, where you need to satisfy different audiences, from grandma to vulnerability researchers, and provide with “inspiration” without it being seen as b/s by either. A short thread

BildBild

So cool. An LLM-based, language-agnostic vulnerability variant hunter was presented yesterday by Michal Kamensky at BlueHat IL. The talk, along-side Amir Gombo, was about hybrid cloud vulnerabilities, but that wasn't what excited me. A thread

BildBild