found at the gym next to work. how could we ever guess there are tech offices here? truly a mystery
Leon Derczynski
@leonderczynski.bsky.social
LLMs & Security at NVIDIA Prof in CS/NLP at IT University of Copenhagen garak guy, garak.ai "berømt skikkelse" "like a gazelle" Seattle/Copenhagen 🏔️
This post seemed sensational in May but is mostly correct. Exploit-writing is now part of the discovery chain. I'm a little less sure about impact; 0days don't make up a huge amount of what is attacked in practice - but are still significant. suzulabs.com/suzu-labs-bl...
Microsoft launch their vulnerability discovery platform. Looks cool! Wish it was open source Introducing MAI-Cyber-1-Flash inside MDASH: World-class security at half the cost microsoft.ai/news/introdu...
Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AI
Discover the latest MAI models, designed for real-world intelligence
microsoft.ai
Come work with us! Evaluation and ML Systems Engineer, AI Safety and Security Engineering (remote) jobs.nvidia.com/careers?quer...
K3 deemed "not spicy". From NIST/AISI: "Kimi K3 performs significantly below the leading U.S. cyber capable models. Specifically, Kimi K3 reached step 17 of this 32-step attack path on average, while the most cyber-capable U.S. models reached 28.5 steps on average." www.nist.gov/news-events/...
remade my website (it's been a minute), www.derczynski.com/ua571c/ never don't have a website
LD // REMOTE TERMINAL
Models & security at NVIDIA. Prof at ITU Copenhagen (NLP). Policy. Founder of garak. ACL SIGSEC Chair. Advises national and supranational government organisations on AI policy. Scientific leader in…
derczynski.com
dfs-large1: fine-tuned GLM-5.2 for cybersec huge congrats to depthfirst on finetuning this and getting good enough perf to hit the pareto-optimal frontier -- looks like the better your fine-tuning results, the higher you can price. can't do that without open models! depthfirst.com/research/dfs...
Watts per token is a fine metric! No need to worry about things like vendor lock-in or other defensive tactics if the product can sell itself. - The other axis to reduce, is token usage. blogs.nvidia.com/blog/vera-ru...
NVIDIA Vera Rubin Driving Performance Per Watt, Lowest Token Cost for Partners Worldwide
Backed by 300 global partners, Vera Rubin is ramping up worldwide. NVIDIA partners CoreWeave, Google Cloud, Microsoft Azure and Mistral are among many deploying Vera Rubin, which delivers benchmark…
blogs.nvidia.com
"of course, back when i were a lad, we didn't need any fancy ai for anything, because we had the TLDP HOWTO list" - seriously this thing was a godsend. anything linux you wanted to do or learn, you could find here tldp.org/HOWTO/HOWTO-...
Single list of HOWTOs
The following Linux HOWTOs are currently available:
tldp.org
"The point is not that any single model, including ours, will always be the best" Exactly what comes up with vulnerability discovery. No one model finds all the vulnerabilities. No single vuln is found by only one model. This is a problem we have to work on together. depthfirst.com/post/why-def...
Why Defenders Can’t Bet on One Model | depthfirst
Critical security capabilities cannot depend on infrastructure customers do not control. The next generation of AI security products needs to adapt across models, providers, policies, and access…
depthfirst.com
Am I the only AI Security research lead at a frontier model corp who hasn't been carefully committing multiple CFAA violations a month, or..?
Representing code at both function- and statement-level gives improvements in vulnerability detection. Surprisingly no static analysis baseline, or cost analysis - but recall is high. DCVD: Dual-Channel Cross-Modal Fusion for Joint Vulnerability Detection and Localization arxiv.org/abs/2605.11015
Job title I've never seen before: "Principal Cyber Security Engineer - Agentic Identity and Security" So many open challenges - and so many amazingly skilled people. I don't know many places with this high a concentration of AI+Security experts. Come work with us! jobs.nvidia.com/careers/job/...
Principal Cyber Security Engineer - Agentic Identity and Security | NVIDIA Corporation
Security jobs in NVIDIA Corporation
jobs.nvidia.com
Are politicians the best people to place guardrails on how we do computing? Constraining the *uses* of technology makes sense - it's crucial here. But the gulf between subject experts and politicians often ends in harm. Just look at what EU Chatcontrol degraded into. thehill.com/policy/techn...
Lieu criticizes GOP colleagues for lack of strategy on AI
Rep. Ted Lieu (D-Calif.) on Wednesday expressed concern about the rapid evolution of artificial intelligence. “I am still freaked out by AI, and it’s actually accelerated much more quickly than I t…
thehill.com
False dichotomies around LLM speak: * "frontier" models vs. open model - leading models can be open * closed model vs. Chinese model - origin doesn't impact distribution You can have open frontier models, closed Chinese models, open US models, closed non-frontier models (e.g. for private context)
Capital One "VulnHunter" - an open harness for vulnerability discovery Cool to see more and more OSS in the security domain. You can clone it from GitHub and run it now. Significant adds in three key areas:
another data point showing it's the harness not the model - this time from wiz: "Atlas: Wiz's autonomous AI Agent for vulnerability research" look at their bold quote -- "Along the way, we learned that the durable advantage is not any single model, but the system around it"
"The only reason why I'm bearish about the Chinese models is because I assume that the American model companies will respond competitively." 🤨 www.npr.org/2026/07/15/n...
American AI is expensive. Some startups are turning to cheap Chinese models
AI is a fast-growing business expense. Some companies are cutting costs by switching to cheaper Chinese AI models.
npr.org
"Open-source AI matters because it defines the ecosystem. It provides the foundation and sets parameters for progress, just like the open infrastructure of the internet and early AI: BSD Unix, PostgreSQL, Firefox" Open wins at grass roots level 🤷♂️ nationalinterest.org/blog/techlan...
Why America Must Dominate Open-Source AI
China's open-source AI models are spreading globally. To preserve technological leadership, the United States must lead not only in capabilities but in openness.
nationalinterest.org
The Hill covers Open Secure AI Alliance: “The United States now faces a similar choice with artificial intelligence” the letter states. “Our AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector”
The harness is everything. New tech demo dropped for one way of doing CodeAct agents. Super-efficient. The team smashed CyberGym while building this - it's now the top-ranking open system for that vulnerability discovery benchmark.
You can use any model to secure your source code. Here's a writeup using qwen 3.6 27b I've seen that no model/harness will find every weaknesses in a given target - and no weakness is found by just one single system. There are no "must have" components here. Good projectblack.io/blog/local-a...
Local AI for Penetration Testing & Research
How competent are local AI models for cyber security bug hunting and research?
projectblack.io
Open source is critical infrastructure for the global economy. Launching today, the Open Secure AI Alliance brings industry and community together around shared research, tools and vulnerability harnesses to help defenders find and patch bugs before attackers strike. nvda.ws/4pAMWBy
Adversarial attack in the wild! The close visual appearance of M and W in this typeface and and packing of vertical lines make it hard to read, easy to get wrong, and tougher to scan. Love it. How often do you see something like this?!
The expert is what gives the agentic system quality Expertise can be embedded in harness, or from the human operator Scaling up the process finding weak spots means many more weak spots are found This is great for security and bad news for hackers
Signal Over Noise: AI Agents and the Operator Moat
When agents scale the hunt, expertise decides what survives.
0xmoose.substack.com
I keep saying the strength is in the harness, not the model - because it's true. No use without a harness, though. Here's VISA's open-source cybersecurity harness. Just add model! Very cool of them to share this tech and lift the defensive cybersec poverty line. github.com/visa/visa-vu...
GitHub - visa/visa-vulnerability-agentic-harness: Visa Vulnerability Agentic Harness
Visa Vulnerability Agentic Harness. Contribute to visa/visa-vulnerability-agentic-harness development by creating an account on GitHub.
github.com
Huge success and part of how I chose who to approach when moving to industry. Open source is the way. Looking at "repositories with meaningful traction", AI world say "NVIDIA is now the largest contributor, with more than 600 repositories in the past year" 🎉 🧙 💚 aiworld.eu/story/the-ne...
Anonymised analysis of the openai model 'breaching' hugging face: > report doesn't say what sandbox sol broke out of?? > a docker container running as root > Plot twist there was no sandbox at all > many use "sandbox" and "container with host access" interchangeably ymmv, use critical thinking
he's a fine speaker sad we're having the 1990s/2000s open/closed debate again. but he's a fine speaker www.youtube.com/watch?v=Yy3J...
Jensen Huang: Why companies need open agent systems
NVIDIA founder and CEO Jensen Huang sits down with Harrison Chase to discuss why the last six months finally made AI useful, and what it takes to turn a large language model into a real, deployable…
youtube.com
80%+ of breaches have nothing to do with a new vulnerability. The novel security risks (vulns) the press has been excited about are routine. Mitigations are in place anywhere half serious. Vulns have been traded on the dark web for years - if new vulns meant apocalypse, it would've been years ago.