







it was a not really sunny day in tpa, fl, when i got the message from cpp swift's president. it was an invite to help with their info sec conference, the Tech Symposium. they were looking for community members who would be willing to help with different aspects, tabling, ctf challenges, organization. my brain started to turn and i knew i wanted to do something really funny. last year in october, i had tabled at the CSUF's OSScon, ran by their security club, OSS. the tabling was fun and i got to present some malware that i was working on for a research project with mitre , which is avalible here. it was cool to get people to mess around with malware when they've never seen it before, but for the tech Symposium, i had a more substantial idea of what i wanted to do.
CLI quickstart – Codex Security | ChatGPT Learn
Set up Codex Security, run a local scan, and review the report, findings, and coverage.

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
Investigating three real-world incidents in our cybersecurity evaluations
In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Below we describe what happened, how it happened, and what we’re changing. We encourage other AI labs to perform similar reviews.
Attacking & Auditing Docker Containers Using Open Source tools
Software Security Engineer — Andrew Lilley Brinker
I’m a Principal Engineer at MITRE helping people make informed decisions about the software they depend on. I lead Hipcheck and contribute to the CVE system.

What happened after 2,000 people tried to hack my AI assistant — Fernando Irarrázaval
I built hackmyclaw.com, where anyone could email Fiu, my OpenClaw assistant, and try to make it leak the contents of a secrets.env file.
AI-SLOP: Develop best current practises for Open Source maintainers · Issue #178 · ossf/wg-vulnerability-disclosures
Open source projects are increasingly facing a wave of low-quality, AI-generated vulnerability reports and contributions—commonly referred to as "AI-slop." This issue aims to develop best...
Just a rumour of a bug is enough to find a security exploit these days
Thinking through how the conventional OSS security embargoes no longer buy us time, and what open source maintainers might do instead to respond


FOSDEM 2025 - Goblins: The framework for your next project!
Building peer-to-peer decentralised applications remains difficult and error-prone. Most attempts at this either abandon collaborative features entirely or fall back on centralised architectures. The Spritely Institute is working on this challenge by creating (among other things) Goblins, a Guile framework that makes secure, fault-tolerant peer-to-peer applications accessible to developers. These tools are especially valuable for developers building secure collaborative applications that aim to foster healthy online communities. This talk walks you through Goblins’ most powerful features, including the actor model, object capability security, networking, time travel debugging, and persistence.

Code Worth Writing - Ray Myers | SSW 2026
Project Glasswing: Securing critical software for the AI era
A new initiative to secure the world’s most critical software and give defenders a durable advantage in the coming AI-driven era of cybersecurity.

Josh Miller on Twitter / X
Starting today, Cory Hardman is @browsercompany's new head of security engineering. Cory was previously Head of Security for OpenSea, and a senior security engineer at Google (9 years) & Notion. Whether Arc for Teams or Dia for Consumers, security is a top 2025 priority.— Josh Miller (@joshm) January 8, 2025
Bastian Greshake Tzovaras (@gedankenstuecke@scholar.social)
It's great that a class of tool that by its very design is an unfixable security issue is forced into everything: «This works often enough that Måløy reported this to Microsoft as a security hole in March. He gave them a 90-day reporting window, Microsoft extended that twice to a total of 144 days, and they still didn’t have a solid fix. So Måløy posted about the hole on July 28th.» Copilot prompt injection goes viral in your documents https://pivot-to-ai.com/2026/08/03/copilot-prompt-injection-goes-viral-in-your-documents/
big milestone at the day job where we open sourced Resident, our low-level core tech aimed at hardware device developers: code sandboxes for microcontrollers idea is that end users can infinitely reprogram the products in their home info + GitHub over here... news.inanimate.tech/p/lab-notes-drum-loops-protot…