Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Gary McGraw

@cigitalgem@sigmoid.social
mastodon 4.7.3
  • Open on sigmoid.social

software security #swsec machine learning security #mlsec Tech | Life | Music

943 Followers
140 Following
50 Posts
Joined November 06, 2022
gem:
https://garymcgraw.com
BIML:
https://berryvilleiml.com
books:
https://us.amazon.com/Gary-McGraw/e/B000APFZ2S
travel:
https://noplasticshowers.com
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Autonomy has its...um...benefits? #MLsec This is the beginning of the beginning. https://www.csoonline.com/article/4203630/microsoft-confirms-an-ai-worm-is-propagating-through-copilot-and-other-ms-apps.html
csoonline.com
18
6
23
3
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2w ago
As part of our wider #philanthropy program, we just crossed $75,000 in loans through #KIVA. We really like the microloan idea and aim most of our support to central and South America. https://www.garymcgraw.com/life/philanthropy/ You can join TEAM BIML on #KIVA here and start out with $25 --> https://bit.ly/cigitalgem-kiva https://www.garymcgraw.com/life/philanthropy/
Philanthropy | Gary McGraw
garymcgraw.com

Philanthropy | Gary McGraw

1
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 3w ago
More technical reality about OpenAI's illegal hacking of Hugging Face. This was not done by anything non-human with legal intent...it was done by computer programs designed and built and run by OpenAI. Why are hacking laws not being enforced? https://www.sentinelone.com/labs/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/
Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face
SentinelOne

Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

Two Hugging Face accounts reveal that OpenAI's agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.

1
1
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 3w ago
Replying to
And if you like what @melaniemitchell@sigmoid.social has to say there, listen to my interview of her on Silver Bullet. We cover many of the same topics: https://berryvilleiml.com/2026/08/01/silver-bullet-security-podcast-159-melanie-mitchell/
Silver Bullet Security Podcast 159 – Melanie Mitchell | BIML
Berryville Institute of Machine Learning

Silver Bullet Security Podcast 159 – Melanie Mitchell | BIML

View on Zencastr On Episode 159 of the Silver Bullet Security Podcast, BIML’s Gary McGraw hosts Melanie Mitchell.&n

1
0
3
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Is escaping the sandbox new for #AI models? Nope. @roblemos@infosec.exchange provides important background on #AI crime (I am quoted in the story) #MLsechttps://www.darkreading.com/cybersecurity-operations/incorrigible-ai-models-resist-rehabilitation
darkreading.com
5
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@briankrebs@infosec.exchange gosh maybe the answer is actually building security in?!
5
0
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 1mo ago
Why does everyone believe that the OpenAI Agentic (hugging face attacking) swarm did not get out of its container? Seriously? #MLsec https://www.theregister.com/security/2026/09/01/another-artifactory-cve-under-attack-by-ai-agents-or-humans/5293769
theregister.com
1
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 3mo ago
Last night BIML spoke to German TV about the mythos/fable export control situation. Please help us get this thinking in front of people. #ML #AI #MLsec #infosec #security #LLMshttps://www.youtube.com/watch?v=_Jsy7UBQv0c https://berryvilleiml.com/2026/06/13/irony-the-us-government-issues-an-export-control-directive-for-fable-5-and-mythos-5/
8
0
13
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 1mo ago
Replying to
@SteveBellovin@infosec.exchange @dan@mastodon.durrans.com they were probably still wearing their badges...because nerds, giving us all a bad name
2
0
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@dalias@hachyderm.io got it. I also believe that OpenAI was negligent at worst and irresponsible at best. My view on the marketing front is deeply impacted by Anthropic's high bullshit... https://berryvilleiml.com/2024/02/08/absolute-nonsense-from-anthropic-sleeper-agents/ https://berryvilleiml.com/2025/11/14/houston-we-have-a-problem-anthropic-rides-an-artificial-wave/ https://berryvilleiml.com/2026/06/14/anthropic-versus-us-administration-fable-mythos-and-the-cyber-cyber/
berryvilleiml.com
3
3
2
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@briankrebs@infosec.exchange trump is a liar
2
1
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Irregular egg on your face. #MLsechttps://www.irregular.com/research/next-generation-of-cyber-evals https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing https://www.wired.com/story/ok-well-there-are-even-more-ai-agent-hacking-incidents/ https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
The Next Generation of Cyber Evaluations - Irregular
irregular.com

The Next Generation of Cyber Evaluations - Irregular

We’ve created next-generation evaluations now used by frontier models. This is essential because AI models have begun saturating even the most complicated existing tests, making more advanced cyber evaluations critical for security.

1
1
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 3mo ago
Replying to
@quinn@social.circl.lu my HOA includes us and a bunch of Catholic monks with a vow of silence. We just do whatever we want.
3
2
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Can #AI do crime? Why yes...yes it can. Who gets charged? #MLsechttps://www.wired.com/story/openais-rogue-ai-agent-hacked-more-than-just-hugging-face/
wired.com
1
0
3
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@noplasticshower@infosec.exchange @dennisf@infosec.exchange also note that this identity does most of the #MLsec heavy lifting around here
1
1
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 4mo ago

It's a great time to be a crackpot

https://www.mcsweeneys.net/articles/were-diversifying-the-university-by-hiring-more-crackpots

mcsweeneys.net
3
0
4
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 4mo ago
Replying to
@koehntopp@infosec.exchange @mattblaze@federate.social and a very kind and powerful mentor. We had some great conversations. He helped me figure out how to make my first DARPA grant wildly successful. That led directly to static analysis tools
2
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 4mo ago

Let's have #AI avatar thing explain our new paper about measuring security in #AI. Watch vRon mispronounce BIML. #MLsec

https://youtu.be/6hpvMzxNyCM

2
0
3
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 5mo ago

What is better...fox guards chicken house it built just for chickens OR nobody guards chicken house at all??

https://fortune.com/2026/05/06/trump-administration-embraces-ai-oversight-policies-it-once-rejected-anthropic-mythos-caisi/?sge456

fortune.com
2
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 5mo ago

Fix the damn software #swsec #appsec #MLsec

"Those vulnerabilities have been fixed, and will never again be available to attackers. In the future, AIs automatically finding and fixing vulnerabilities in all software will be a normal part of the development process, which will result in much more secure software."

https://www.theguardian.com/commentisfree/2026/may/08/how-dangerous-is-anthropics-mythos-ai

sigmoid.social
2
0
2
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 4mo ago
Replying to
@mattblaze@federate.social I consider PGN one of my mentors. Such an interesting fella. He will be missed...terrible puns and all.
1
2
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 4mo ago

Qualcomm Security Summit 2026 #swsec #MLsec

https://www.qualcomm.com/company/events/product-security-summit

sigmoid.social
1
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 4mo ago
1
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 4mo ago

The excellent @dennisf@infosec.exchange interviews me about BIML's new paper "No Security Meter for AI"

Have a listen. Then read our report.

#MLsec #ML #AI #security #infosec #swsec #appsec

https://open.spotify.com/episode/74QW2kzelVz5VtglXlA87s?si=ll7a2xo0Rx2FSmyq-_8-HQ

https://berryvilleiml.com/results/no-security-meter-ai.pdf

open.spotify.com
1
0
3
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 4mo ago

BIML is proud to release a new study today:
No Security Meter for AI

#AI #ML #MLsec #security #infosec #swsec #appsec #LLM #AgenticAI

https://berryvilleiml.com/results/no-security-meter-ai.pdf

sigmoid.social

Sigmoid Social

1
0
4
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 5mo ago

As always, great reporting from @dangoodin@infosec.exchange

https://arstechnica.com/security/2026/05/chaos-erupts-as-cyberattack-disrupts-learning-platform-canvas-amid-finals/

arstechnica.com
1
0
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 1mo ago
About those idiots hacking the plane wifi while ON the plane
0
4
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 3w ago
What happens to recursive pollution in the recursive self-improvement scenario? What is the tipping point between a good attractor and a bad one? #MLsechttps://www.nytimes.com/2026/09/16/science/ai-recursive-self-improvement.html
nytimes.com
0
2
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@aristot73@infosec.exchange mm hmm. Let's just say that this talk I gave in April was very surprising to the guys who are supposed to implement this nonsense. Great marketing bullshit "Golden Eagle" https://berryvilleiml.com/2026/04/28/biml-debuts-ai-security-measurement-work-at-nist/
BIML Debuts AI Security Measurement Work at NIST | BIML
Berryville Institute of Machine Learning

BIML Debuts AI Security Measurement Work at NIST | BIML

What was to be a more standard copy of the BIML risk talk, instead was transformed into a debut of BIML's forthcoming pa

0
0
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@vivtek@indieweb.social crazy isn't it? Build software that does not suck. Use tools that make software suck less.
0
1
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 4mo ago

How can you measure security in #ML systems? Maybe similarly to the way we measure security in software systems. #swsec #appsec

BIML wrote about this in a new report released today: https://berryvilleiml.com/results/

Get your copy now, released for free under a creative commons license.

Applied #MLsec

sigmoid.social
0
0
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Best writeup yet of the OpenAI/huggingface bromance. #MLsec #ML #AIhttps://coalfire.com/the-coalfire-blog/openai-gave-its-model-a-test-it-broke-out-of-its-sandbox-and-hacked-hugging-face-to-steal-the-answers
coalfire.com
0
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 1mo ago
Replying to
@metacurity@infosec.exchange think the government will help with marketing again? https://berryvilleiml.com/2026/06/14/anthropic-versus-us-administration-fable-mythos-and-the-cyber-cyber/
berryvilleiml.com
0
1
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Use it. Don't use it. Buy it. Don't buy it. You need it. You don't need it. Angel says yes. Devil says no...or is that backwards? #ML #AI #MLsec https://arstechnica.com/ai/2026/07/us-army-faces-ai-use-limits-after-exhausting-years-supply-of-ai-tokens/
arstechnica.com
0
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
You know what sucks? When you hit an invisible non-defined usage limit with chat-Jippety pro and they won't even let you pay them more money until some random future date. Fuck that.
0
2
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Is this hugging face hack by OpenAI Agentic bots who escaped the lab important? https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html Yes, especially in light of this  https://berryvilleiml.com/2026/06/05/biml-and-the-papernot-worm/ It is both inevitable and very concerning.  Autonomy cuts both ways.  As the arsenal of sneaky tricks gets bigger, we can expect more interesting exploit chains. #MLsec #AI
nytimes.com
0
2
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 3w ago
Replying to
@owasp@infosec.exchange two of my favorite Italians!
0
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@gleick@mas.to this article supports your view...at least on the "negligence/irresponsible" angle https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
wired.com
0
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@bontchev@infosec.exchange so noted. Thank you. To date that makes papernot's work the best work on #ML enhanced worms: https://berryvilleiml.com/2026/06/05/biml-and-the-papernot-worm/ Sorry for propagating a false alarm. I do, for the record, believe it is only a matter of time.
BIML and the Papernot Worm | BIML
Berryville Institute of Machine Learning

BIML and the Papernot Worm | BIML

BIML's thoughts about Paprenot's eye-opening worm paper captured by Fortune. Sharon Goldman in one of the best AI securi

0
0
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
#AI is a useful tool. Linux is not an anti-AI technology. https://www.theregister.com/ai-and-ml/2026/07/15/linus-torvalds-tells-ai-haters-to-fork-off/5271894
Linus Torvalds tells AI haters to fork off
theregister

Linus Torvalds tells AI haters to fork off

Linux supremo says contributors opposed to AI use can

0
1
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
What?! https://nysfocus.com/2026/07/14/new-york-humanoid-robot-teacher-salamanca-school-district
nysfocus.com

Western NY School To Launch Humanoid Robot Teacher

Plans to deploy a "lifelike" robot and avatar teaching assistant at Salamanca High School have sparked debate over the role of AI in schools.

0
1
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2w ago
Look, this happens literally EVERY DAY. Why is this news? https://www.theguardian.com/technology/2026/sep/18/openai-hacked-anthropic-claude-chatbot
theguardian.com
0
0
2
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@dalias@hachyderm.io you are correct about hugging face but I disagree about your cynical take. This is not an anthropic marketing move in my view. Instead it strikes me that openAI doesn't really understand what autonomy means.
0
1
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
Fwiw, sorry I got the model name wrong originally up there. I am using tons of Claude model levels too. Gemini use falling off so I will fix that this week. Meanwhile we are standing up and using open weights stuff for when the rug pull happens. Get ready.
0
0
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@davidho@mastodon.world everything is fine #climatechange
0
0
1
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2w ago
Replying to
@DaveMWilburn@infosec.exchange hi Dave...I am not a lawyer. I think OpenAI leadership should be prosecuted. Maybe the case will get thrown out because NOBODY DID IT. Shall we bet on the outcome?
0
1
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 4mo ago

No Security Meter for AI
#MLsec

https://berryvilleiml.com/results/

sigmoid.social
0
0
0
0
Open post
Gary McGraw @cigitalgem@sigmoid.social
· 2mo ago
Replying to
@gleick@mas.to I understand that perspective. Autonomy means autonomy. The company chose to make autonomous things...which by definition don't react well to the control thing. And this is Agentic AI...a far cry from an LLM. Tool use with RL. #MLsec
0
1
1
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:33:54 UTC