Recent incidents from frontier labs have prompted me to re-evaluate the near term risks from AI threat actors. This Black Hat presentation should be required viewing: The OpenAI–Hugging Face Incident The incident gives us a clear view of a coordinated, agentic intrusion. I do not know how quickly this becomes normal, or the scale and shape of threat actor adoption. It will not be zero. My…
What is the "Vuln Apocalypse"? The cybersecurity community is realizing that AI can find security vulnerabilities in software at a scale we might not be prepared for. “A return to shallow bugs” is the framing I like most. It gives us permission to do practical things now instead of arguing over the exact size, shape, and sulfur content of the apocalypse. How does this impact a security program?…
This essay describes what the minimum viable probabilistic approach to cyber risk management looks like. That means, I’d do this even if nobody asked for a compliance report. It's free, requires no platforms, and allows you to start with no historical loss datasets. Any incident notes or internal metrics you already have will improve it, but they aren’t a prerequisite. Only effort and familiarity…
Posts on quant risk ( 1 , 2 , 3 by Caleb Sima have encouraged me to jump back into the quantified risk discussion. Here's my take across the primary points across those three posts. Having spent nearly a decade on this problem in a variety of roles I quickly hit my word limit on a response. From Caleb's first post: We count everything except the only thing that matters: the probability of a…
In this wonderfully detailed LinkedIn post, Stephen Schmidt (CSO @ Amazon) describes the trend where North Korean (DPRK) nationals land jobs in other countries. From there, the rogue employee collect wages, steals data, and extorts the victimized employer. I have been working in security incident response roles for nearly twenty years. I've only heard of this trend post-pandemic, but immediately…