Stanislav Fort

@stanislavfort.bsky.social

AI + security at AISLE | Stanford PhD in AI & Cambridge physics | scientific progress

Most AI-for-cyber work is evaluated on toy tasks & artificial benchmarks. AISLE goes after the real thing = previously unknown zero-days in some of the world's most secure code. And we're matching & beating frontier systems using widely available & open-source-derived models.

Bild

We matched Mythos on public zero-days with CVEs using widely available & open-source derived models & can run it air-gapped if needed. All this with a small team out of Europe Berkeley study ranks us #1 globally in 3 of 8 categories The full evidence: stanislavfort.substack.com/p/mythos-at-...

"Mythos" at Home, and It's Called AISLE

A startup out of Europe built an AI system that matches Mythos on zero-day discovery, using widely available models, even air-gapped. You've probably never heard of it. Here's the evidence.

stanislavfort.substack.com

Anthropic chose FreeBSD to showcase their Mythos zero-days. In the latest release, 8 CVEs were announced: 3 found by Anthropic, 3 discovered by AISLE's AI (!) AISLE is matching Mythos 3-for-3 on zero-days on the very codebase of their choosing at a fraction of the cost

Bild

AISLE is proud to partner with OpenEMR, the open-source medical records platform used by 100k providers & 200M+ patients globally. Our AI security system uncovered 38 historical CVEs in OpenEMR, including 2 max critical severity CVSS 10.0 zero-days.

Bild

AISLE has discovered 20 of 23 OpenSSL zero-days (CVEs) across the last 3 consecutive security releases Latest release: 5 of 7 are AISLE 1 was co-reported by Anthropic (Mythos?) 63 days after AISLE OpenSSL encrypts 2/3 of the internet 10 fixes accepted straight into production

Bild

AISLE is now the #1 source of accepted security findings in OpenClaw, the fastest-growing AI agent framework. Our AI discovered 15 vulnerabilities: 1 Critical (CVSS 9.4), 9 High, 5 Moderate. 21% of all OpenClaw security advisories globally are from us, more than anyone else ⏬

Bild

New post on what AI cybersecurity research looks like when it actually works! I wrote up what we've learned discovering 12 of 12 new OpenSSL zero-days, 5 CVEs in curl, and additional 100+ validated CVEs across critical open source infrastructure, middleware, and secure apps 🔗⏬

Bild

Thanks for sharing! Happy to answer any questions you / your followers might have. The full thread with more details is here: bsky.app/profile/stan... I'm genuinely excited and slightly worried how far we've managed to push our AI system. A CVE is one thing, but we've now industrialized the process.

John David Pressman@jdp.extropian.net · 6mo ago

Perennially excellent AI safety researcher Stanislov Fort writes about finding 12 zero days in OpenSSL with an AI scaffold. www.greaterwrong.com/posts/7aJwgb...

OpenSSL secures most of the internet's encryption. They just patched 12 new zero-day vulnerabilities. Our Al system developed by AISLE is responsible for discovering all 12/12, every single one of them. This includes a pre-auth HIGH severity one & 3 that lurked there for >25 years! 1/6

This level of ignorance is surprising but unfortunately legitimately dangerous, giving the readers a pleasant but ultimately false idea that AI is just not that good really. One doesn't have to rely on academic experts here -- just trying out using LLMs clearly shows that they are *extremely* useful

Emily M. Bender@emilymbender.bsky.social · last yr.

LLMs used as synthetic text extruding machines have no legitimate use cases and --- for all the reasons discussed in the stochastic parrots paper --- are prone to harmful outputs to boot. >>

Presenting *Ensemble Everything Everywhere* at NeurIPS AdvML'24 workshop today! 🔥 Come by today at 10.40-12.00 in East Ballroom C to ask me about: 1) 🏰 bio-inspired naturally robust models 2) 🎓 Interpretability & robustness 3) 🖼️ building a generator for free 4) 😵‍💫 attacking GPT-4, Claude & Gemini

Bild

A decade ago, AlphaGo inspired me to leap from black holes to AI. Bittersweet to close my time at DeepMind, but thrilled to start a new chapter focusing directly on AI and security. Find me at NeurIPS this week or DM me here if you'd like to chat!

My favorite description of a large language model was accidentally written by Ray Bradbury in 1969, more than half a century ago, and it's eerie how fitting its rendition of an emergent language mind is: vvvvvvv The poem follows in the replies vvvvvv

Bild