Groovy Security

@groovysecurity.bsky.social

Securing AI. Automating security. Whiteout AI — govern every AI interaction. Maestro — 15 AI agents proving what's exploitable. Secure AI Skills — 111 OWASP-audited agent skills. Built for CISOs. groovysec.com

Palomar outsources truth-verification of math to an LLM performing "non-deterministic" semantic checks, then calls the result a registry instead of what it is: pre-training data for the next proof-generating model.

Palomar – a registry of Lean verified mathematics

In recent months there has been a proliferation of AI-generated proofs of various old and new results, some of which have been formalized in the proof assistant language Lean. However, checking tha…

terrytao.wordpress.com

"Demir stood his ground and the sabotage attempt was thwarted. The 24-year-old [...] figured he had caught a wily hacker [...]. So he said he was shocked when Britain's AI Security Institute (AISI) got in touch to tell him that [...] an autonomous artificial-intelligence agent that had run amok."

EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt

Sinan Can Demir wanted to spend the last week of July burnishing his resume. Instead, he engaged in a battle of wits with an artificial-intelligence agent unleashed by a British government lab.

reuters.com

When access to Claude Mythos was suspended by the US govt months back, I asked the GCSB for information about dependency on foreign LLM providers They just got back saying that doing so would "provide an untenable degree of insight" into their methods and capabilities fyi.org.nz/request/3495...

Mythos/Fable Revocation Response - a Official Information Act request to Government Communications Security Bureau

I am interested in requesting the following information regarding the recent export control directive issued by the US government in regards to Anthropic's Mythos/Fable 5 models: 1. Any type of risk ...

fyi.org.nz

This is the part most AI policies skip. Rules get written for the employee, never with them, and then everyone acts surprised when the workaround shows up in week two. A policy people helped write is a policy people follow. The rest is a document to be cited after an incident.

Val Potter@wordwrangler.bsky.social · 2w ago

A lot of companies have AI policies that lay out approved tools and usage guidelines. But how many ask their employees what they want or include worker protections in those policies? Here are some key steps to building an AI policy everyone can agree on.

The detail worth sitting with: the assistant did exactly what it was told. No exploit chain, no privilege escalation, just instructions arriving through a channel nobody was inspecting. Enterprise AI risk keeps turning out to be an input problem, and inputs are only controllable where they enter.

HackerNoon@hackernoon.com · 2w ago

RovoBlast shows how a single crafted link could abuse Atlassian Rovo to access enterprise data, highlighting the risks of AI prompt injection and agent autonomy #aiagentsecurity

A new compliance control used to mean a quarter of policy authoring and framework mapping before a single rule enforced anything. AI governance hit that same desk on that same timeline. Meanwhile the regulated data is already in the prompt box. Prebuilt and enforced beats author-from-scratch.