CyberSecurity Awareness Month will be condensed to CyberSecurity Awareness Minute
#Secutity@MachineSpeed
Aristotelis Tzafalias
When buffers overflow into policy
Views are my own
European Court of Auditors: Special report 19/2026: Detecting and responding to cybersecurity incidents – EU cooperation framework progressing, but only partially effective due to implementation delays and limited information sharing
21 Sept. 2026
Has anyone using LLMs in their development lifecycle published stats on how many vulns were discovered post release before and after LLMs?
RE: @trailofbits@infosec.exchange
If your goal is to provoke an over reaction in policy circles and further restrictions on defenders, keep framing llm advances from an attacker's perspective like this:
"The expertise barrier that kept bespoke fuzzing campaigns out of reach for most attackers is gone. "
RE: https://infosec.exchange/@aristot73/116562947812685451
New entries added to the "When buffers overflow into policy" project references:
2026-07-17 — UK AISI — How Far Behind the Frontier are Leading Open Weight Models on Cyber? https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber
2026-07-17 — Katie Moussouris (Luta Security) — Gold Eagle: All that Glitters is Not Patched https://www.lutasecurity.com/post/gold-eagle-all-that-glitters-is-not-patched
2026-07-14 — The White House — GOLD EAGLE: federal vulnerability-coordination clearinghouse https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/
2026-07-14 — IMCO exchange of views with Anthropic (European Parliament) — cyber capability, export controls, and EU dependence on non-EU frontier AI https://tzafaar.codeberg.page/other/IMCO-2026-07-14-anthropic-exchange-transcript.html
2026-07-10 — heise online — With Zero-Days, BND and BfV to Become "Super Intelligence Agencies" https://www.heise.de/en/news/With-Zero-Days-BND-and-BfV-to-Become-Super-Intelligence-Agencies-11361538.html
2026-06-26 — Patching the Commons — Four OSS Coordination Initiatives Compared https://tzafaar.codeberg.page/other/oss-security-initiatives-comparison.html
2026-02-03 — He et al. — Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents https://arxiv.org/abs/2602.02164
Anthropic: Redeploying Fable 5 30 Jun 2026
"As of today, June 30, the export controls on Fable 5 and Mythos 5 have been lifted.
In the remainder of this post, we provide further details and updates in four areas:
-
A timeline of events, including updates we made to our safeguards. We discuss the events that led to the export control directive and how we addressed it with new safeguards.
-
A shared industry framework. Although we have reached a constructive resolution, these events have made clear that the industry needs a consistent way to assess and fix potential “jailbreaks” of AI models (techniques that bypass a model’s safeguards).
-
A shared standard for judging the severity of a given jailbreak would help AI developers triage new findings as they arise, launch highly capable models with greater safety, and communicate the level of risk consistently to government and industry partners. Together with Amazon, Microsoft, Google, and other Glasswing partners, we’ve started to develop such a framework, and we outline it below.
-
Deeper government collaboration. We’re also strengthening our level of collaboration with the US government on new pre-release testing, information sharing, and research collaboration. We describe this deeper collaboration in the final section."
RE: @aristot73@infosec.exchange
Six new bibliography entries, in https://tzafaar.codeberg.page/ newest to oldest:
GPT-5.5-Cyber Built a zlib Fuzzing Lab in a Day — Benjamin Samuels (@trailofbits@infosec.exchange of Bits), Jul 2 2026
https://blog.trailofbits.com/2026/07/02/field-reports-from-patch-the-planet/
The Privatization of Vulnerability Management — @jamesberthoty@bird.makeup (Latio Pulse), Jul 2 2026
https://pulse.latio.tech/p/the-privatization-of-vulnerability
Preliminary Report of the Independent International Scientific Panel on AI — UN, Jul 2026
https://www.un.org/independent-international-scientific-panel-ai/en/preliminary-report
BCP-05-X-01: AI-Assisted Vulnerability Information Annotation — GCVE Working Group, Jun 14 2026
https://gcve.eu/bcp/extension/gcve-bcp-05-x-01/, @gcve@social.circl.lu
Written Testimony on the AI Security Landscape — @jackhcable@mastodon.social Cable (Corridor), Jun 4 2026
https://www.corridor.dev/blog/testimony
No Security Meter for AI — @cigitalgem@sigmoid.social Figueroa, McMahon, Bonett (BIML), May 13 2026
https://berryvilleiml.com/docs/no-security-meter-ai.pdf
#Cybersecurity #AISecurity #VulnerabilityManagement #AIgovernance
The curl summer of Bliss with Daniel and Stefan
https://opensourcesecurity.io/2026/2026-09-curl-bliss-stefan-daniel/
I asked claude to check something. it did. I saved the result.
I upload the result - again to claude - for a second pass. Hit the guard rail.
2nd time today.
Have no idea what's going on :)
R. Addis et al., "LLM-based Intelligent Agents for Cybersecurity: A Tutorial and Survey of Automated Vulnerability Discovery," in IEEE Access.
"In addition to surveying existing applications, this work provides a step-by-step walkthrough of integrating agentic AI into penetration testing workflows. The walkthrough explores four phases: (I) mission scoping and prompt engineering for test definition and constraint enforcement, (II) autonomous exploration and tool selection for target interaction, (III) vulnerability hypothesis formation and verification through experiment design and feedback, and (IV) payload generation and refinement to transform validated findings into concrete exploits."





