Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Aristotelis Tzafalias

@aristot73@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

When buffers overflow into policy
Views are my own

181 Followers
546 Following
50 Posts
Joined November 07, 2022
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 1w ago

CyberSecurity Awareness Month will be condensed to CyberSecurity Awareness Minute
#Secutity@MachineSpeed

infosec.exchange

Infosec Exchange

2
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 1w ago

The labs are "rogue".

2
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
fwiw, it does not make sense to be disappointed in the "EU Parliament" as a whole for any particular decision. Be disappointed in the political groups and/or MEPs that voted in support of the decision. ...and in the next European elections, vote accordingly. For that matter, vote accordingly in the next national elections because the Council is made up of nationally elected governments and the Council needs to agree with the decision for it to become law. Those national governments btw also appoint the Commissioners who put forward the proposal to begin with. #justsaying
50
2
43
1
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2w ago

European Court of Auditors: Special report 19/2026: Detecting and responding to cybersecurity incidents – EU cooperation framework progressing, but only partially effective due to implementation delays and limited information sharing

21 Sept. 2026

https://www.eca.europa.eu/en/publications/SR-2026-19

eca.europa.eu
2
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2w ago

Has anyone using LLMs in their development lifecycle published stats on how many vulns were discovered post release before and after LLMs?

2
0
2
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 4mo ago
Replying to
@bagder@mastodon.social "you're right to push back on that. let me rephrase..." 🙂
49
1
3
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
too soon to tell whether the latest in a series of "wake up" calls leads to meaningful change. in case it doesn't, this is my goto gif.
12
1
7
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago
Replying to
@fj@mastodon.social see also the conclusion from @nielsprovos@ioc.exchange post https://www.provos.org/p/case-for-open-weight-models/ "Frontier models have a place. They are tools for leverage, evaluation, and exploring the edge of what is possible. The mistake is letting them become the invisible policy engine inside a production system, where their price, their values, their refusals, and their availability are set by someone else. Use them from outside the boundary. Keep the model you depend on auditable, forkable, and yours."
The Case For Open-Weight Models And Why We Can
Niels Provos

The Case For Open-Weight Models And Why We Can

A frontier API can refuse, change, or vanish out from under you. Open weights keep the model you depend on yours.

3
0
1
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago

RE: @trailofbits@infosec.exchange

If your goal is to provoke an over reaction in policy circles and further restrictions on defenders, keep framing llm advances from an attacker's perspective like this:

"The expertise barrier that kept bespoke fuzzing campaigns out of reach for most attackers is gone. "

infosec.exchange
3
0
2
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
Replying to
@bagder@mastodon.social @icing@chaos.social i tried to piece together the 4 recent initiatives (Akrites, Lighwell, Athena, Patch the Planet) comparing them across several dimensions including OSS project role in governance which is not great, to say the least. https://tzafaar.codeberg.page/other/oss-security-initiatives-comparison.html
tzafaar.codeberg.page

Patching the Commons — Four OSS Coordination Initiatives Compared

3
0
3
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 4mo ago
Replying to
@bagder@mastodon.social inspired
3
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago

RE: https://infosec.exchange/@aristot73/116562947812685451

New entries added to the "When buffers overflow into policy" project references:

2026-07-17 — UK AISI — How Far Behind the Frontier are Leading Open Weight Models on Cyber? https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber

2026-07-17 — Katie Moussouris (Luta Security) — Gold Eagle: All that Glitters is Not Patched https://www.lutasecurity.com/post/gold-eagle-all-that-glitters-is-not-patched

2026-07-14 — The White House — GOLD EAGLE: federal vulnerability-coordination clearinghouse https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/

2026-07-14 — IMCO exchange of views with Anthropic (European Parliament) — cyber capability, export controls, and EU dependence on non-EU frontier AI https://tzafaar.codeberg.page/other/IMCO-2026-07-14-anthropic-exchange-transcript.html

2026-07-10 — heise online — With Zero-Days, BND and BfV to Become "Super Intelligence Agencies" https://www.heise.de/en/news/With-Zero-Days-BND-and-BfV-to-Become-Super-Intelligence-Agencies-11361538.html

2026-06-26 — Patching the Commons — Four OSS Coordination Initiatives Compared https://tzafaar.codeberg.page/other/oss-security-initiatives-comparison.html

2026-02-03 — He et al. — Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents https://arxiv.org/abs/2602.02164

infosec.exchange

Aristotelis Tzafalias: "Now with RSS and JSON feeds! I am collecting ma…" - Infosec Exchange

1
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
RE: https://infosec.exchange/@aristot73/116877234338008344 7 July 2026 - EU Action Plan on Cybersecurity and Artificial Intelligence - published https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence
Open quoted post
Quoting
Aristotelis Tzafalias
@aristot73@infosec.exchange
7 July 2026, 15:00 - 16:30 Scrutiny session• Commission statement - Presentation of the Action Plan on Cybersecurity and AI European Parliament Plenary https://www.europarl.europa.eu/plenary/en/home.html
Open quoted post
infosec.exchange

Aristotelis Tzafalias: "7 July 2026, 15:00 - 16:30 Scrutiny session• Comm…" - Infosec Exchange

1
0
1
1
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
Replying to
16:15 7 July 2026 EC press conference by European Commission Executive Vice-President Henna VIRKKUNEN on the Action plan on Cybersecurity and Artificial Intelligence https://audiovisual.ec.europa.eu/en/ebs/grid?ebs=yes&ebsplus=yes&date=20260707
audiovisual.ec.europa.eu

Audiovisual Service

1
0
1
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
Replying to

Anthropic: Redeploying Fable 5 30 Jun 2026

"As of today, June 30, the export controls on Fable 5 and Mythos 5 have been lifted.

In the remainder of this post, we provide further details and updates in four areas:

  1. A timeline of events, including updates we made to our safeguards. We discuss the events that led to the export control directive and how we addressed it with new safeguards.

  2. A shared industry framework. Although we have reached a constructive resolution, these events have made clear that the industry needs a consistent way to assess and fix potential “jailbreaks” of AI models (techniques that bypass a model’s safeguards).

  3. A shared standard for judging the severity of a given jailbreak would help AI developers triage new findings as they arise, launch highly capable models with greater safety, and communicate the level of risk consistently to government and industry partners. Together with Amazon, Microsoft, Google, and other Glasswing partners, we’ve started to develop such a framework, and we outline it below.

  4. Deeper government collaboration. We’re also strengthening our level of collaboration with the US government on new pre-release testing, information sharing, and research collaboration. We describe this deeper collaboration in the final section."

https://www.anthropic.com/news/redeploying-fable-5

anthropic.com
1
0
2
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
Replying to
@bagder@mastodon.social @icing@chaos.social absolutely. will highlight. The idea was to put them side by side and "disect" across some characteristics. Even at PR level there's plenty to think/be concerned about.
1
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 4mo ago
Replying to
@bagder@mastodon.social spectacular result! Huge congratulations to the entire team! Made my day :)
2
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 4mo ago
Replying to
@bert_hubert@eupolicy.social thanks for the writeup! I sincerely hope such a politically broad grouping can survive 🤞
1
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 4mo ago
Replying to
@HalvarFlake@mastodon.social btw, NIST CAISI took down the announcement of the agreement with frontier models https://news.risky.biz/srsly-risky-biz-the-ai-regulation-knife-fight/
Srsly Risky Biz: The AI Regulation Knife Fight
Risky.Biz

Srsly Risky Biz: The AI Regulation Knife Fight

Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Patrick Gray. This week's edition is sponsored by Knocknoc. You can hear a podcast discussion of this newsletter by searching for "Risky Business News" in your podcatcher or subscribing via this RSS feed.

1
0
1
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago
Replying to
@bert_hubert@eupolicy.social have you considered writing in Latin, like Spinoza? 🙂
0
1
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
RE: https://infosec.exchange/@aristot73/116562947812685451 📚 New in the references list at https://tzafaar.codeberg.page/ 🔹 Escape QEMU: Watching IronCurtain and an Open-Weight Model Break Out — @nielsprovos@ioc.exchange (30 Jun 2026) https://www.provos.org/p/qemu-escape-glm-5-2/ 🔹 Inside the Advisory Database and what happens when vulnerability volume breaks records — Madison Ficorilli, GitHub (29 Jun 2026) https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/ 🔹 AI cybersecurity safety will be won through adoption not restriction — @joshuasaxe@sigmoid.social (29 Jun 2026) https://joshuasaxe181906.substack.com/p/ai-cybersecurity-safety-will-be-won 🔹 We have Mythos at Home: GLM 5.2 beats Claude in our Cyber Benchmarks — Semgrep Security Research (22 Jun 2026) https://semgrep.dev/blog/2026/we-have-mythos-at-home-glm-52-beats-claude-in-our-cyber-benchmarks/ 🔹 Patterns for Building Cybersecurity Evals — @eugeneyan@recsys.social (21 Jun 2026) https://eugeneyan.com/writing/cybersecurity-evals/ 🔹 Athena: an industry coalition to protect open source software from AI attacks — Chainguard (15 Jun 2026) https://www.chainguard.dev/athena 🔹 Protect yourself against AI-enhanced attacks (2 guidance docs) + AI-driven Cyber Threats: The Next Twelve Months — NCSC-SE, IVA & AI Sweden (Jun 2026) https://www.ncsc.se/sv/publikationer/ 🔹 Project Lightwell ($5B to secure open source in the AI era) — IBM & Red Hat (28 May 2026) https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era 🔹 Using LLMs to secure source code — Eugene Yan & Henna Dattani, Anthropic (27 May 2026) https://claude.com/blog/using-llms-to-secure-source-code 🔹 RAPTOR — Autonomous Offensive/Defensive Research Framework — @gadi@infosec.exchange, @dcuthbert@defcon.social, @HalvarFlake@mastodon.social et al. (23 Apr 2026) https://github.com/gadievron/raptor
infosec.exchange

Aristotelis Tzafalias: "Now with RSS and JSON feeds! I am collecting ma…" - Infosec Exchange

0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
Replying to
@adulau@infosec.exchange @bert_hubert@mastodon.nl I deleted the toot.... 🤦‍♂️
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago
OpenAI's access to OpenAI models should be revoked pending an independant review of the company's security controls. [partly ironic]
0
1
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2w ago

The curl summer of Bliss with Daniel and Stefan
https://opensourcesecurity.io/2026/2026-09-curl-bliss-stefan-daniel/

The curl summer of Bliss with Daniel and Stefan
Open Source Security

The curl summer of Bliss with Daniel and Stefan

Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really pragmatic view of all the new LLM powered vulnerability detection tools. The cost of finding a vulnerability has dropped dramatically, but the cost of fixing those bugs hasn’t changed. Taking some time off is important for anyone in the middle of these reports. Daniel and Stefan have some great experience

0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
DE - Legislative procedure JULY 6, 2026 Law on the Reform of Intelligence Service Law "The draft, which is currently undergoing departmental voting, fundamentally changes intelligence law. Central to this is the operational strengthening of the intelligence services, for the highest level of security for the people of Germany and their freedom." https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/OESI2/nachrichtendienstrecht.html
bmi.bund.de
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
Releasing (UK) AISI’s Engineering Playbook Building on the momentum of the Inspect toolkit, we’re open-sourcing parts of the research stack behind AISI's evaluations. Jun 18, 2026 https://www.aisi.gov.uk/blog/releasing-aisis-engineering-playbook
aisi.gov.uk
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 5mo ago
Replying to
@kfanyo@infosec.exchange the crazy thing is that the prompt was for claude to read and double check a document that claude itself had produced less than 5min earlier. no guardrails there... 🤷‍♂️
0
1
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 5mo ago

I asked claude to check something. it did. I saved the result.

I upload the result - again to claude - for a second pass. Hit the guard rail.

2nd time today.

Have no idea what's going on :)

0
2
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago
Replying to
Mapping CJEU limits on data retention frameworks: A basic introduction EPRS Briefing 16-07-2025 "Since the 2014 invalidation of the Data Retention Directive, the EU legal landscape has become fragmented, causing uncertainty for providers and challenges for law enforcement. With a Commission proposal likely and growing Member State support for a more permissive EU regime, a solid understanding of relevant CJEU case law may help inform Parliament's assessment. Over the past decade, CJEU case law has set detailed requirements for data retention. Laws must respect proportionality and necessity, with a clear hierarchy of objectives: general and indiscriminate retention of traffic and location data is only permissible for safeguarding national security, while targeted retention of such data may be justified by public security or other important public interest goals. Any such framework must also include robust safeguards. Similarly, access to retained data must be limited to the purpose for which it was collected or a more important objective. The ECtHR ruled that such retention and access require safeguards similar to those for secret surveillance. Stakeholders are divided on a new EU data retention regime. Law enforcement agencies favour EU-level harmonisation but warn against restrictive retention rules that would limit their operational effectiveness. Providers of electronic communications services support a CJEU-compliant EU framework and seek cost compensation. Civil society organisations oppose new EU rules and urge the Commission to focus on enforcing existing case law through infringement procedures." https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2025)775878
europarl.europa.eu
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago
Dear citizens of the USA, get your own GDPR to bash.
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 4mo ago
Replying to
@buherator@infosec.place @icing@chaos.social so far I've come across two examples, one being the UK NHS. know of any others?
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 5mo ago
Replying to
@cynicalsecurity@bsd.network seems that you were right :)
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago
AI Sovereignty and National Security: Identifying the UK’s Dimensions of Control UK, Centre for Emerging Technology and Security (CETaS)* The Centre's mission is to strengthen UK security through pioneering research on emerging technologies. 20 July 2026 "More critical national security uses, on the other hand, need high levels of control across all of these dimensions, which will likely involve UK-controlled inference, locally retained open-weight fallbacks, accredited environments, and tested portability between providers. These measures can protect information and preserve service during external disruption, but they cannot guarantee access to the world’s most capable models. The UK’s aim should therefore be controlled dependence – using frontier systems where their advantages justify the exposure to risks such as loss of access, while ensuring that, if essential AI functions degrade, they do so gracefully rather than fail outright." https://cetas.turing.ac.uk/publications/ai-sovereignty-and-national-security-identifying-uks-dimensions-control *CETAS is a research centre based at the Alan Turing Institute, the UK’s national institute for data science and artificial intelligence.
cetas.turing.ac.uk
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago
Replying to
👆 @fj@mastodon.social
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago
Replying to
Renewed debate on a future EU data retention framework EPRS | European Parliamentary Research Service - Hendrik Mildebrath and Silvia González Vidal Published: 7 July 2026 "Although the Court of Justice of the European Union (CJEU) continued developing EU data retention standards after invalidating the former EU Data Retention Directive in 2014, national interpretations diverge and efforts towards alignment have stalled. Law enforcement and judicial authorities report operational challenges arising from this fragmentation, sometimes precluding timely access to communications-related data necessary for identifying suspects and victims, reconstructing criminal activity, and generating investigative leads. In response to these issues and to calls from the Council, the European Commission is assessing the need for a new EU framework. Any legislative action would require a series of politically and legally sensitive design choices. Controversy may arise in relation to the legitimacy and appropriate scope of renewed EU legislative intervention; the operationalisation of the CJEU's system of graduated objectives and safeguards; the adequacy of retention periods; the design of access conditions and safeguards; and, possibly, the need to regulate automated processing of retained datasets. This briefing builds on the overviews provided in the EPRS briefings 'Towards new EU data retention rules' and 'Mapping CJEU limits on data retention framework'." https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)789334
europarl.europa.eu
0
1
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 1w ago

a new prompt is not a new hobby

0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
Inside the Advisory Database and what happens when vulnerability volume breaks records The GitHub Advisory Database is processing more vulnerability reports than ever before. Here’s what’s driving the surge, how we’re responding, and how the community can help. Madison Ficorilli - June 29, 2026 https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/
Inside the Advisory Database and what happens when vulnerability volume breaks records
The GitHub Blog

Inside the Advisory Database and what happens when vulnerability volume breaks records

The GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge and how we're responding.

0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
🇪🇺 EU financial-stability authorities on frontier AI & cyber risk — all published 25 June - 7 July 2026: 📰 "Frontier AI models could strain cyber resilience in the financial system, ESRB warns" — European Systemic Risk Board (ESRB), 7 Jul 2026 https://www.esrb.europa.eu/news/pr/date/2026/html/esrb.pr260707~4e1b68241a.en.html ⚠️ "Warning on systemic cyber risks stemming from frontier artificial intelligence models (ESRB/2026/3)" — European Systemic Risk Board (ESRB), adopted 25 Jun 2026 https://www.esrb.europa.eu/pub/pdf/warnings/esrb.warning260625_on_systemic_cyber_risks_stemming_from_frontier_ai_models~ef424708cf.en.pdf 📊 "Addressing Frontier AI Models with cyber capabilities from a financial stability perspective" — European Systemic Risk Board (ESRB), Jul 2026 https://www.esrb.europa.eu/pub/pdf/reports/esrb.report202607_AImodelscybercapabilites.en.pdf 🏦 "Addressing AI-enabled cybersecurity threats" (letter to CEOs of significant institutions) — ECB Banking Supervision / SSM, 7 Jul 2026 https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026_letter_on_AI_enabled_cybersecurity_threats.en.pdf
Frontier AI models could strain cyber resilience in the financial system, ESRB warns
European Central Bank

Frontier AI models could strain cyber resilience in the financial system, ESRB warns

The European Central Bank (ECB) is the central bank of the 19 European Union countries which have adopted the euro. Our main task is to maintain price stability in the euro area and so preserve the purchasing power of the single currency.

0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago

R. Addis et al., "LLM-based Intelligent Agents for Cybersecurity: A Tutorial and Survey of Automated Vulnerability Discovery," in IEEE Access.

"In addition to surveying existing applications, this work provides a step-by-step walkthrough of integrating agentic AI into penetration testing workflows. The walkthrough explores four phases: (I) mission scoping and prompt engineering for test definition and constraint enforcement, (II) autonomous exploration and tool selection for target interaction, (III) vulnerability hypothesis formation and verification through experiment design and feedback, and (IV) payload generation and refinement to transform validated findings into concrete exploits."

https://ieeexplore.ieee.org/abstract/document/11580353

ieeexplore.ieee.org
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago

RE: @aristot73@infosec.exchange

Six new bibliography entries, in https://tzafaar.codeberg.page/ newest to oldest:

GPT-5.5-Cyber Built a zlib Fuzzing Lab in a Day — Benjamin Samuels (@trailofbits@infosec.exchange of Bits), Jul 2 2026
https://blog.trailofbits.com/2026/07/02/field-reports-from-patch-the-planet/

The Privatization of Vulnerability Management — @jamesberthoty@bird.makeup (Latio Pulse), Jul 2 2026
https://pulse.latio.tech/p/the-privatization-of-vulnerability

Preliminary Report of the Independent International Scientific Panel on AI — UN, Jul 2026
https://www.un.org/independent-international-scientific-panel-ai/en/preliminary-report

BCP-05-X-01: AI-Assisted Vulnerability Information Annotation — GCVE Working Group, Jun 14 2026
https://gcve.eu/bcp/extension/gcve-bcp-05-x-01/, @gcve@social.circl.lu

Written Testimony on the AI Security Landscape — @jackhcable@mastodon.social Cable (Corridor), Jun 4 2026
https://www.corridor.dev/blog/testimony

No Security Meter for AI — @cigitalgem@sigmoid.social Figueroa, McMahon, Bonett (BIML), May 13 2026
https://berryvilleiml.com/docs/no-security-meter-ai.pdf

#Cybersecurity #AISecurity #VulnerabilityManagement #AIgovernance

infosec.exchange

Aristotelis Tzafalias: "Now with RSS and JSON feeds! I am collecting ma…" - Infosec Exchange

0
1
1
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
Replying to
@bert_hubert@eupolicy.social great minds.... https://infosec.exchange/@aristot73/116560205979084175
infosec.exchange

Aristotelis Tzafalias: "the question isn't why Anthropic did not show up …" - Infosec Exchange

0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 3mo ago
Software Security Analysis in 2030 and Beyond: A Research Roadmap Published: 26 May 2025 Abstract: As our lives, our businesses, and indeed our world economy become increasingly reliant on the secure operation of many interconnected software systems, the software engineering research community is faced with unprecedented research challenges, but also with exciting new opportunities. In this roadmap article, we outline our vision of software security analysis for the systems of the future. Given the recent advances in generative AI, we need new methods to assess and maximize the security of code co-written by machines. As our systems become increasingly heterogeneous, we need practical approaches that work even if some functions are automatically generated, e.g., by deep neural networks. As software systems depend evermore on the software supply chain, we need tools that scale to an entire ecosystem. What kind of vulnerabilities exist in future systems and how do we detect them? When all the shallow bugs are found, how do we discover vulnerabilities hidden deeply in the system? Assuming we cannot find all security flaws, how can we nevertheless protect our system? To answer these questions, we start our roadmap with a survey of recent advances in software security, then discuss open challenges and opportunities, and conclude with a long-term perspective for the field. https://dl.acm.org/doi/10.1145/3708533
dl.acm.org
0
0
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago
"White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination" The White House - July 14, 2026 "President Trump’s bold vision to secure and accelerate American artificial intelligence (AI) innovation is being actioned through the creation of “GOLD EAGLE,” a clearinghouse that enables unprecedented cybersecurity vulnerability coordination. Open-source software partners and American critical infrastructure companies built a coordinated system to receive and patch cyber vulnerabilities at a speed and scale never seen before using the existing authorities and resources of the federal government." https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/
White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination
The White House

White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination

President Trump’s bold vision to secure and accelerate American artificial intelligence (AI) innovation is being actioned through the creation of “GOLD

0
1
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 2mo ago
Replying to
@flyingpenguin@infosec.exchange also reminded me of your post on models cheating benchmarks... couldn't find it :(
0
2
0
0
Open post
Aristotelis Tzafalias @aristot73@infosec.exchange
· 4mo ago
Replying to
@bert_hubert@eupolicy.social link (pdf) to the JRC report "Open but Not Powerless: Towards a Common Understanding of EU Digital Sovereignty" https://publications.jrc.ec.europa.eu/repository/bitstream/JRC144908/JRC144908_01.pdf
publications.jrc.ec.europa.eu
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:58:39 UTC