omkhar

@omkhar.net

Security guy. Website: https://omkhar.net Scholarship: https://skscholarship.com Twitter/X: https://x.com/omkhar Mastodon: https://infosec.exchange/@Omkhar Bluesky: https://bsky.app/profile/omkhar.net LinkedIn: https://linkedin.com/in/omkhar

Wanna secure AI for 30K employees and over a billion members? Come work with us in LinkedIn InfoSec! www.linkedin.com/jobs/view/44... FAQ: * If you'd like to know if you’re a good fit, apply. * If I’ve worked with you before, I’m happy to refer you, DM me. * This role is located in Sunnyvale, CA

LinkedIn hiring Staff Security Engineer - AI in Sunnyvale, CA | LinkedIn

Posted 9:34:52 AM. LinkedIn is the world's largest professional network, built to create economic opportunity for…See this and similar jobs on LinkedIn.

linkedin.com

My feed is awash with “innovative” “thought leadership” pieces about the impact of Fable/Mythos being restricted. Doing security research and are looking for a portable skill that you can use to discover new vulnerabilities? Check out Vulnerability Validation skill: github.com/omkhar/vulne...

Mythos/Fable is out... Before the thought leaders start publish whitepapers, or hosting "CISO dinners" etc, I'll offer some boring/sobering advice: 1. Make sure you know where all your stuff is - ya even that 3rd party software that the person in accounting bought on a credit card in 2016.

Are you a privacy engineer or work with privacy engineers? Would you like to learn more about probably engineering? Boy do I have a conference for you! PEPR, the conference on privacy engineering, practice, and respect, is happening June 1-2 in Santa Clara, CA. www.usenix.org/conference/p...

PEPR '26

The 2026 USENIX Conference on Privacy Engineering Practice and Respect (PEPR '26) will take place on June 1–2, 2026. PEPR is focused on designing and building products and systems with privacy and res...

usenix.org

Mee-thos? Meye-thos? Mi-thos? A month in, I still couldn't tell you. The loudest opinions on AI vulnerability research almost never come from the people actually using it or contributing to making the world more secure.

“I went from negative to positive.” - Biggie Smalls, BedStuy Motivational Speaker That came up near the end of my conversation with Cameron on The Defender’s Journal, and it probably says more about my career than any title ever has.

"Do you know the ledge?" Rakim - Long Island 0-day Researcher The last 10 days, everyone's had an opinion on Mythos and GPT 5.4-Cyber.

Most security tools slow you down. Most fast tools ignore security. We wanted both. So we built Workcell. It started with a few co-conspirators asking: "How do we vibe code at yolo speed and not get owned?"

github.com

A few years ago, when I was working at @openssf.org , we partnered with @darpa.mil on the AI Cyber Challenge. Yesterday's news from @anthropic.com about Mythos and Glasswing both highlight the opportunity that we saw, and the primary reason we were so focused on securing open source software.

"Code Rules Everything Around Me, CREAM" - Method Man, Chief AI Scientist, Wu-Tang Clan Code got cheaper. Engineering didn’t.

AI coding agents : Claude Code, Codex, Copilot and their kin are changing how software gets built. Faster. Smarter. More autonomous. And that's exactly what keeps me up at night.

"Life's most persistent and urgent question is, 'What are you doing for others?" -- Dr. Martin Luther King Jr.

As we get over vibe code peak hype, many folks are discovering a new kind of software engineering. Slop Ops*: Turning what the LLMs have generated into performant, robust, maintainable code. What’s your Slop Ops:Vibe Code time spent ratio? *Saw this on the internet somewhere, must be true.

We're thrilled to announce our Fall 2025 @skscholarship.com recipients! These exceptional students represent the future of cybersecurity and embody our mission to build a more inclusive and diverse engineering community: Jenna Nandlall Nishat Islam Sai Anirudh Kondaveeti