Long-running AI agents face a memory problem, but compaction fixes it. SentinelLABS tested OpenAI’s compaction on a reverse-engineering harness: input tokens fell 86% and output fell 31%, with no loss in accuracy. Working memory stays in context; evidence goes to storage. https://s1.ai/CE-Compact
SentinelOne
@sentinelone.com
The world’s most advanced, autonomous AI-powered cybersecurity platform. We empower the world to run securely, with leading organizations trusting us to Secure Tomorrow™. Secure your enterprise: http://sentinelone.com/request-demo/
New Signals & Stories episode with @hegel.bsky.social from @sentinelone.com & @invisig0th.bsky.social We discuss: 🔹DPRK IT workers posing as job applicants 🔹Cross-functional intelligence sharing 🔹AI in CTI 🔹And more! #CyberSecurity #CTI #ThreatIntelligence www.youtube.com/watch?v=uQ1_...
A new macOS stealer called Reaper — a SHub variant tracked by @sentinellabs.bsky.social — runs an infection chain where each stage hides behind a different trusted brand.
This is what a realistic AI-era attack chain looks like. Drawn from 11,000+ anonymized cloud environments in our 2026 report. No zero-day. No prompt injection research paper. No novel technique. What we see instead is a misconfigured bucket, one hardcoded key, and a model connected to a CRM.
Frontier AI isn't being built in isolation. Neither is the frontier of cyber defense. That’s why we’re proud to be a partner in OpenAI’s Trusted Access for Cyber (TAC) Program. Read more: s1.ai/GPT5-5Cyb
Threat actors are in a turf war for ownership of your infrastructure. @sentinellabs.bsky.social has uncovered PCPJack, a predatory cloud credential worm that hunts its own kind. Its first move? A scorched-earth eviction of rival group TeamPCP.
In this @wired.com video about fast16, @agreenberg.bsky.social walks through the whole arc: A 2005 malware that sat in plain sight, the NSA leak that named it, and what @sentinellabs.bsky.social's Vitaly Kamluk and @jags.bsky.social finally figured out it was doing.
Frontier model. Frontier operators. Real threats, stopped before they become attacks.
LABScon 2026 Call for Papers is open. Sept 16–19, Scottsdale. Invite-only. Fifth year.
LABScon - Security Research in Real Time | LABScon
Join us September 16-19th for LABScon, an intimate, invite-only event for the top cybersecurity minds to gather, share cutting-edge research.
labscon.io
The history of cyberwar just got rewritten with a new @sentinellabs.bsky.social discovery by Vitaly Kamluk and @jags.bsky.social. Stuxnet wasn't the beginning of nation-state sabotage through software. It was just the first one we caught. Read the full @wired.com story by @agreenberg.bsky.social 👇
A newly decoded piece of sabotage malware called Fast16, created even before Stuxnet, was designed to silently tamper with/corrupt calculations in research and engineering software. Likely created by the US or an ally, and possibly used against Iran's nuclear program. www.wired.com/story/fast16...
The biggest risk in your AI strategy? What quietly disappears when AI handles the work that builds expertise. Here are three questions to pressure-test your exposure👇
Adversaries are now industrializing the breach. SentinelOne’s new Annual Threat Report is officially out, and this is one of the key takeaways. Targeting core systems like identity, infrastructure, and automation is not new—but executing these tactics at an industrial scale is.
Want an AI malware analyst you can actually trust? @sentinellabs.bsky.social just built a multi-agent architecture that brings the rigor of human peer review to automated malware analysis. This Adversarial Consensus Engine doesn’t just “think,” but doubts. 🤔 🧵
$9 billion. That’s how much Crypto crime has amassed approximately in illicit funds. In this LABScon 2025 video, @privyio.bsky.social’s @andrewmohawk.bsky.social breaks down how attackers steal and launder billions through modern crypto ecosystems. 🧵👇
Looking for an internship in AI Cybersecurity? We’re running AI-driven security challenges at NEBULA:FOG's hackathon today. Join us: nebulafog.ai/challenges I’ll be there live giving updates.
Challenge Tracks | NEBULA:FOG 2026 AI x Security Hackathon
4 AI security hackathon tracks: adversarial AI, defense systems, zero-knowledge proofs, autonomous agents. $5K+ prizes. March 14, SF.
nebulafog.ai
It takes a human analyst an average of 41 minutes to process a single CTI report. An LLM typically does it in 3.3 minutes. Our latest @sentinellabs.bsky.social evaluation shows LLM-driven pipelines can process threat intel 18x faster than manual workflows. But there’s a catch. ⚠️ 🧵
What happens when the FortiGate next-generation firewall protecting your network becomes the backdoor? 🚪 Our DFIR team has been tracking a wave of FortiGate NGFW compromises. The worst part? Most organizations lack the log retention to see how it happened. 🧵👇
Engineered to secure your AI. Built to give you the advantage in the age of AI Security. SentinelOne’s Autonomous Security Intelligence is coming to #RSAC 2026. Connect with us onsite: https://s1.ai/RSAC-Cnct
And we're live! Join here on LinkedIn: www.linkedin.com/video/live/u...
📺 Just A Sec: February Live Cybersecurity Briefing. In each episode, we break down what actually matters in cyber this month—no decks, no fluff, just frontline takeaways you can use now. We tackle… |...
📺 Just A Sec: February Live Cybersecurity Briefing. In each episode, we break down what actually matters in cyber this month—no decks, no fluff, just frontline takeaways you can use now. We tackle th...
linkedin.com
What a US-Iran Conflict Really Means for Cyber: Tomorrow, @stonepwn3000.bsky.social, Drea London, @dakotaindc.bsky.social, and @hegel.bsky.social will discuss in this livestream. 📆 RSVP 📺 On YouTube: www.youtube.com/watch?v=45TF... 💼 And LinkedIn: www.linkedin.com/events/74223...
What a US-Iran Conflict Really Means for Cyber: Tomorrow, @stonepwn3000.bsky.social, Drea London, @dakotaindc.bsky.social, and @hegel.bsky.social will discuss in this livestream. 📆 RSVP 📺 On YouTube: www.youtube.com/watch?v=45TF... 💼 And LinkedIn: www.linkedin.com/events/74223...
Everyone is studying ways to protect AI from data poisoning or prompt injections. But what happens when hackers target the AI controlling a robotaxi or a warehouse robot? 🤖🚗 s1.ai/Axs-PhyAI
The period of blind trust in AI agents is over, as it should be. Introducing ClawSec: The first open-source security suite built to harden OpenClaw agents against supply chain attacks and prompt injections. ⏬ Download from GitHub: s1.ai/ClwSec-GH 📄 Read the blog post: s1.ai/ClwSec-Bl
@reuters.com Exclusive: "The research, carried out jointly by SentinelOne and @censys.bsky.social ... offers a new window into the scale of potentially illicit use cases for thousands of open-source LLM deployments."
🧵 175,000+ exposed AI hosts. Zero guardrails. New research from @sentinellabs.bsky.social and @censys.bsky.social reveals a massive, unmanaged layer of open-source AI infrastructure operating in the shadows. s1.ai/si-llama Here is what you need to know about the "silent" AI network. ⤵️
🎬 We're live with the latest episode of Just a Sec, our cybersecurity briefing livestream with @stonepwn3000.bsky.social, @jags.bsky.social, @dakotaindc.bsky.social, and Drea London. Watch and your chat here: www.youtube.com/live/k0zJcfJ...
Just a Sec — From the Front Lines: January Live Cybersecurity Briefing
YouTube video by SentinelOne
youtube.com
You don’t need expensive spy gear to see through hotel room walls. In this LABScon 2025 talk, @viss.hax.lol shows how off-the-shelf millimeter-wave radar can monitor hotel rooms and detect human presence through walls — even when someone is standing perfectly still.
LLM security benchmarks look impressive. They’re also misleading. @sentinellabs.bsky.social found that today’s LLM security benchmarks don’t measure real security work. 🧵 Read the full report: s1.ai/benchmk1
LLMs in the SOC (Part 1) | Why Benchmarks Fail Security Operations Teams
LLM cybersecurity benchmarks fail to measure what defenders need: faster detection, reduced containment time, and better decisions under pressure.
s1.ai
Why does “powershell” get blocked — but “power” + “shell” gets through? Why can a nonsense suffix like “::sda_!!” hijack a model’s attention? It’s not magic — it’s math. We trace the LLM attack surface from tokenization to attention. s1.ai/inside-llm-1
Inside the LLM | Understanding AI & the Mechanics of Modern Attacks
Learn how attackers exploit tokenization, embeddings and LLM attention mechanisms to bypass LLM security filters and hijack model behavior.
s1.ai
Last month, in our 2026 cyber forecast, @sentinellabs.bsky.social warned that a US–Venezuela flashpoint would spill into cyber and information ops, pulling in Russia, China, and Iran. A few days later, real-world events underscored how quickly those pressures can reshape the threat environment.
✅ #LLM literacy is table stakes for defenders, CTI analysts, and #cybersecurity professionals of all stripes now. Still looking for a way into this complex field? 🤔 LABS has got you covered! Start here: s1.ai/inside-llm-1 @sentinelone.com
Inside the LLM | Understanding AI & the Mechanics of Modern Attacks
Learn how attackers exploit tokenization, embeddings and LLM attention mechanisms to bypass LLM security filters and hijack model behavior.
s1.ai