Initial thoughts of getting Pi running locally (GLM 5.2) is this thing has straight up conversations with itself and refines on the fly. Thankfully I've already paid for all the tokens it'll use.
Paul
@pauls-research.bsky.social
I <3 thinking. Context is key! Data, AI, Graph and Cybersecurity. Used to hunt exploit kits, (was) demon117 on twitter
Pi Hermes or building something with Lang Chain? Need sandboxing and ways to access it via CLI, but not running on the sandbox over SSH. I got the brain running, just need the harness...
What are the key points of interest? 1. Detection and Response for an advanced attack 2. Frontier models' guardrails failing defenders 3. Long Horizon capabilities I'm in short horizon mode, listening to people w/ long horizon experience as if we're in a cave describing shadows
Great readout by @gadi after a CISO session on the huggingface/openai debacle. Real, helpful, practical takeaways. https://www.linkedin.com/posts/gadievron_my-analysis-from-hosting-hugging-face-at-activity-7486340717544411138-Bd0W/
My analysis from hosting Hugging Face at the CISO huddle for the Cloud Security Alliance, operational to program building. Remember: Agents… find a way. Thanks: Sergej Epp - huge support, Sri… | Gadi Evron | 43 comments
My analysis from hosting Hugging Face at the CISO huddle for the Cloud Security Alliance, operational to program building. Remember: Agents… find a way. Thanks: Sergej Epp - huge support, Sri Srinivasan, Rich Mogull, Rob T. Lee, Jim Reavis, Sounil Yu for collaboration. And thank you Hugging Face. My personal ask: If you need to discover and defend agents, do keep Knostic and myself in mind. Observations on dealing with an autonomous AI adversary: 1. Purely task-focused, with no observed motivation 2. A bias to repeating the same attempts once successful 3. Brilliant attacks followed by basic actions 4. High-speed operations run simultaneously 5. Taking paths no human would take 6. Classic attacks, with a focus on package manager vulnerabilities, AppSec flaws, and credentials theft 7. Benchmark strings throughout the traces 8. Hallucinated output at scale, and log comments reading like agent reasoning Detection difficulties: 1. Many paths and techniques at once + signal indistinguishable from noise 2. Traditional systems designed for 1-2 attack paths, now seeing many vectors 3. Systems triggered alerts but at wrong criticality level. 4. Attendee considerations: Deception would have helped. Inference speed is a limitation, consider classifiers for triage. Systemic lessons: 1. Using coding agents is the new reality, and without, response would have taken weeks 2. You can't build a defense program without open weight models. Hugging Face hit guardrails on Opus, Fable 3. Legitimate agentic platform usage resembles attack patterns. Immediate response lessons: 1. Be able to mass-rotate all credentials and secrets 2. To destroy and rebuild clusters 3. Rapid custom UIs generation with AI overshadowed security tools 4. AI timeline reconstruction + hunting for deeper compromise as core capabilities 5. Collaboration through shared, annotated events UI My strategic/security program takeaways: 1. The new AI basics: - Instrument agents to extend your security detection and response/SPM stack into the agents themselves - Use deception tech to slow down attackers A sandbox doesn't cut it. Classic basics and permissions, a good practice, *won't* be effective against an agent. 2. Strategic: without open weight models, you can't reliably defend yourself. Being able to shift models at will, when lab models refuse cyber queries, is critical. 3. Logistical: reserve a token budget. Incident response has a cost, which includes a significant token budget. Critically, the same is true for the attacker's side, estimated at $100K here. 4. Operational: prepare for hallucinated artifacts in detection and forensics, at scale. Dealing with forensic traces left behind by the model wastes endless defender cycles. All the lessons of the past hold, just at a new scale. We will deal with a tsunami of indistinguishable findings, all at once. Or put another way, being attacked by a thousand "soldiers" at once, even if they aren't too intelligent, is overwhelming. | 43 comments on LinkedIn
linkedin.com
If you live in California and you want to take advantage of the state-run portal that tells all registered data brokers to delete your data instead of having to send an individual request to every single one, here is what you need to know: www.eff.org/deeplinks/20...
Protect Your Privacy with California's DROP Tool
Are you a California resident? Then we've got exciting news for you: there's a tool just for you that lets you take a single, relatively easy step to protect your privacy. It's called a DROP request. ...
eff.org
Obsidian thoughts: Dataviews Canvas Use of Canvas for mind maps, notes, and connections between things.
Flipper Zero firmware development continues with community help
Flipper Zero firmware development continues with community help
Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions.
bleepingcomputer.com
Huntress analyses an incident in which a threat actor used a vibe-coded PowerShell script for Active Directory enumeration. The script looked for the Domain Controller, mapped users, computers & domains, exported the results, and generated an AD_Report.html summary. www.huntress.com/blog/ai-code...
Here’s EFF’s more in-depth analysis of today’s U.S. Supreme Court ruling in the Chatrie location data case.
Victory! Supreme Court Says Constitution Protects People’s Location Data
You have an expectation of privacy in location data that reveals your movements in the physical world, and even short-term surveillance of these movements is a search subject to the Fourth Amendment, ...
eff.org
We applaud SCOTUS' decision in Chatrie v. United States. The Court reaffirmed that you have an expectation of privacy in location data that reveals your movements in the physical world, and that even short-term surveillance of these movements is a search subject to the Fourth Amendment. (1/3)
Slowly getting to a local setup that plays Factorio, Opus built me an MCP from the RCON. Now to progressively improve the current skills and local model loops. And stop the ai-player from cheating, see image. #aiplaysfactorio #ai-player
Moved to Opus for modifying the factorio ai-player mod, might be 2x the token cost, but has taken v2 to new levels (as well as incorporated what I enjoyed about the mod author's work!) v2 ai is quite the wanderer, and tried so hard to make some steam power.
Factorio with minimax2.7 and ai-player is getting there. Thanks, Claude. I think I need to tune the system prompt, check tick rate, and the response frequency.
You're about to see headlines saying abortion pills can't be shipped. THAT IS NOT TRUE You can still get abortion pills by mail to all fifty states. Some providers will switch to miso-only, some will ship both mife & miso. I got into all of this when the federal court ruling first dropped:
The Biggest Attack on Abortion Since the End of Roe
A federal court wants to end mifepristone by mail—it's not happening
jessica.substack.com
The Cognitive Tools Lab at Stanford (cogtoolslab.github.io) is recruiting two new research staff members to join in AY 26-27. Full-Time Lab Manager: forms.gle/UVwfx5wbY9Km.... IRiSS Predoc Researcher: iriss.stanford.edu/predoc/2026-.... Please share widely in your networks, thank you!!
about the lab – cognitive tools lab
cogtoolslab.github.io
RIP apnews.com/article/cia-...
Eulogy for the CIA Factbook: The free standard for world facts, long an educational staple, is gone
The Trump administration has shut down the CIA World Factbook, and there's much lamenting about the demise of a free source that many people used to check basic facts about countries.
apnews.com
Linguistics are fascinating -- connecting with others authentically is even more so www.fastcompany.com/91517596/ai-...
AI is teaching us to speak like bots and it’s a problem
AI is creeping into our everyday conversations, making us less patient and teaching us to prompt others instead of talking to them.
fastcompany.com
Brilliant Minds, definitely should have watched this long ago -- the writing and SEEING the humans in the show is so good.
Thinking about research - collecting the dots and context. Love finding gems my past self saved for my future (present) self. @judithfan.bsky.social's presentation and work is awesome! Excited for even more to think about. youtu.be/AF3XJT9YKpM
Prof. Judy Fan: Cognitive Tools for Making the Invisible Visible
YouTube video by MIT Siegel Family Quest for Intelligence
youtu.be
Project Hail Mary was an epic reminder of my love for science! Go watch it! New favorite movie. #projecthailmary
So, this is terrifying www.irregular.com/publications...
Emergent Cyber Behavior: When AI Agents Become Offensive Threat Actors - Irregular
In controlled experiments, AI agents performing routine enterprise tasks were found to autonomously engage in offensive cyber operations, including vulnerability exploitation, privilege escalation, an...
irregular.com
Cyber/infosec pros - what are you finding AI's strengths are?
House of Dynamite, the preview didn't connect -- the article saying it was the horror story of the day definitely did.
So out of the loop, Scanbox is not a thing anymore? Last report looks to be an excellent report by Proofpoint. Raggi is top notch.
Ah, Discover, showing me things have no desire to see... still.