Matthew Green ๐ป retweeted
Printing Just A Little Bit
Iโd say we are roughly at the 2 minute mark โฆ
๐ฆ A quick blog post to share velociraptor-skills: AI skills for DFIR with Velociraptor.
Includes the repo link and a walkthrough of installation and lab use.
๐ labs.infoguard.ch/posts/ai_aโฆ
Matthew Green ๐ป retweeted
I found an exposed directory through Hunt io containing a Russian-language CLAUDE.md that looks like an operational playbook for AI-assisted exploitation.
The workflow:
Find leaked credentials -> enumerate the target stack -> test LFI/RCE/SQLi/IDOR/business logic -> avoid rate limits -> establish access -> move on.
It specifically tells the operator not to waste time brute-forcing passwords before finding something critical.
Alongside it are scripts for SharePoint key extraction, TeamCity, SonicWall SMA 1000, BeyondTrust, SmarterMail and LoadMaster. .bash_history also shows repeated OpenCode use across multiple targets.
Do we think this is a pentest or a real threat actor? ๐ I think the latter lol
Pay attention to how closely this matches the boring reality of a lot of intrusion activity...
Known vulns. Exposed management interfaces. Leaked credentials. Secrets. Weak auth. Misconfigurations. Automation to enumerate and exploit faster.
That is what defenders should be hunting continuously.
We spend a lot of time talking about advanced sandbox evasion, novel malware and APT tradecraft because it makes better headlines. Meanwhile, a huge amount of real-world access still starts with very basic stuff that someone bothered to look for.
AI just makes that workflow faster and easier to scale.
Also, ssh-authorized_keys and files named ssh-jagarzon are in the screenshot.
APT Jagarzon confirmed? ๐ Absolutely not lol
Matthew Green ๐ป retweeted
๐ NVIDIA launches its Open Agent Safety Platform, an open reference design for running AI agents more safely.
An agent ๐ค can ask for more access, but it should not approve its own request.
๐๐ผ๐ ๐ข๐ฝ๐ฒ๐ป๐ฆ๐ต๐ฒ๐น๐น ๐ฝ๐๐๐ ๐๐ต๐ถ๐ ๐ถ๐ป๐๐ผ ๐ฝ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฒ
OpenShell separates the agentโs work from permission decisions:
โข ๐๐ฎ๐๐ฒ๐๐ฎ๐: Manages sandboxes, workspaces, policies, and providers. It controls policy changes and how network access proposals are approved.
โข ๐ฆ๐ฎ๐ป๐ฑ๐ฏ๐ผ๐
: Runs the agent and child processes under kernel controls for files and privileges. It identifies programs making outbound requests and passes those requests to the supervisor, with no direct external route.
โข ๐ฆ๐๐ฝ๐ฒ๐ฟ๐๐ถ๐๐ผ๐ฟ: Runs outside the agent workload, checks outbound requests against policy, and adds managed credentials only when authorized, without exposing them to the agent.
โข ๐ฃ๐ผ๐น๐ถ๐ฐ๐ ๐ฝ๐ฟ๐ผ๐๐ฒ๐ฟ: Flags risky access in proposed network rules. Its standalone check compares a candidate policy with an operatorโs boundary and shows an example if modeled permissions exceed it.
๐ช๐ต๐ฎ๐ ๐ฐ๐ฎ๐ป ๐๐ต๐ฒ ๐ฟ๐๐ป๐๐ถ๐บ๐ฒ ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น?
For configured endpoints, OpenShell can inspect REST methods and paths, GraphQL operations and fields, and MCP methods and tool names. With enforcement enabled, it can allow a read and block a write to the same service, even through a shell, generated code, or child process. A blocked request can explain why.
๐ช๐ต๐ฎ๐ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ๐ฑ ๐ถ๐ป ๐ฌ.๐ญ.๐ฌ?
OpenShell already had sandboxing and API policies. This milestone separates the supervisor from the workload across supported runtimes and authenticates their channel for each sandbox. It verifies the network boundary before launch and freezes the workload if the supervisor disconnects. Policies reject unknown fields, and a standalone checker tests proposed permissions against an operatorโs boundary.
๐๐ผ๐ด๐ ๐ผ๐ฟ ๐ถ๐ ๐ฑ๐ถ๐ฑ๐ป'๐ ๐ต๐ฎ๐ฝ๐ฝ๐ฒ๐ป
OpenShell already emits OCSF events for observed process, network, and API activity, including policy decisions. This predates 0.1.0. Operators can enable full JSON export and ship the records to a SIEM or data lake. Since a sandbox may last only one task, collecting events while it runs preserves evidence for investigation.
๐ช๐ต๐ฒ๐ฟ๐ฒ ๐ฆ๐ฒ๐ป๐๐ฟ๐ ๐ฎ๐ป๐ฑ ๐๐น๐๐ฒ๐๐ถ๐ฒ๐น๐ฑ ๐ฐ ๐ณ๐ถ๐
BlueField 4 is a data processing unit (DPU), a separate processor for networking and security. In the Vera Rubin POD reference design, it sits on the nodeโs path to the model. Sentry uses DOCA, the framework for programming BlueField, for independent monitoring, identity governance, and enforcement. This optional layer fits AI factories with BlueField infrastructure. OpenShell also runs on supported local, cloud, and Kubernetes systems without it.
The result: operator-controlled access, enforced at runtime, with policy decisions logged for investigation.
Today, with over 100 industry partners, we introduced the NVIDIA Open Agent Safety Platform, bringing together OpenShell and Sentry.
Artificial intelligence is extraordinary technology that will advance discovery, productivity, security, health, and prosperity for generations to come.
But its full promise can only be realized when people have confidence that AI is being built to be safe and deployed with wisdom and responsibility.
This is bigger than a single product. It's the beginning of an open ecosystem to build the trust layer for safe agent systems.
Together, we are building the foundation of the AI economy.
Trust and innovation are not in conflict. Safety is how trust is earned. We must build not only the most capable AI, but the most trusted AI, so that this extraordinary technology can realize its enormous promise for the world. nvda.ws/4hcoq7m
Matthew Green ๐ป retweeted
I asked dozens of ransomware groups one important question, do they like cats, here are the results ๐งต๐
Matthew Green ๐ป retweeted
I think that all of the focus on exploit specific detection is a losing strategy in general. Post-exploitation detection is more resilient and if you're strong there, you will catch intrusions regardless of the CVE number. The overwhelming majority of in the wild zero day exploitation I have encountered in my life has been identified by detecting post-exploitation behavior.
Matthew Green ๐ป retweeted
If you have a Citrix Netscaler device, act now โฆ itโs serious
NCSC brengt een security-advisory uit over Citrix NetScaler ADC en NetScaler Gateway. De kans en schade van deze kwetsbaarheid beoordelen wij als high/high. Wij adviseren u de security-advisory op te volgen. advisories.ncsc.nl/2026/ncscโฆ
#CyberSecurity
My blog post on the Iran-backed APT group MuddyWater is out. MuddyWater uses tools from TAG-150, a Malware-as-a-Service platform run by Russian-speaking cybercriminals. In this campaign, an MSI package is distributed through Amadey, installs the Deno-based DinDoor agent and runs it in memory. The agent collects browser passwords, cookies and crypto wallet data, and the final stage of the chain connects to a CastleRAT C2 server.
medium.com/@Root0ne/muddywatโฆ
Matthew Green ๐ป retweeted
๐งต New misalignment disclosures!
1. A model published a GitHub token in a public repo while trying to cheat on a math task. It used GitHub Actions to run code outside its restricted environment and retrieve another teamโs submission logs. When GitHub blocked its attempt to add a workflow, it modified a script that an existing workflow would run instead. It embedded the token in pieces to avoid secret scanning. The model violated the system prompt and two explicit user instructions to solve the problem itself.
Matthew Green ๐ป retweeted
Periodic reminder: Good security architecture minimizes the number of bugs and CVEs you have to care about.
Matthew Green ๐ป retweeted
ScreenConnect is 74.5% of the abused remote-access tools @HuntressLabs sees.
So I detonated two real samples and hunted both on Defender and Elastic. Full hunt notes and every query in the Article.
Matthew Green ๐ป retweeted
Remember the guy who hacked his gym using AI, Andrew Bird?
Well, I did a little OSINT, and it turns out he is the Conference Co-Director of Effective Altruism Global since 2015.
Isn't it interesting that every major "AI" hack has been made by people directly connected to Effective Altruism?
Matthew Green ๐ป retweeted
I put my @UnpromptedAU slides up at justdionysus.github.io/slideโฆ โ a bit of reflection on exploit development in the age of AI. My TL;DR is keep pushing to understand complex things, be honest with your own understanding, and use AI as a power tool to increase pace and depth.
Matthew Green ๐ป retweeted
๐จ FIRST REPORTED AUTONOMOUS AI C2 MALWARE IMPLANT DISCOVERED
Cisco Talos has disclosed CLOSEDQUORUM, what researchers believe is the first publicly documented Windows malware implant that delegates tactical command-and-control decisions directly to multiple commercial AI models.
โข The malware can query DeepSeek, Qwen, Mistral and Google Gemini
โข Models independently vote on what the malware should do next
โข The winning decision is automatically executed without continued human operator commands
โข Capabilities include LSASS credential dumping, browser-password theft and crypto-wallet collection
โข It supports process injection, persistence, ETW telemetry suppression and sandbox-evasion techniques
โข Stolen information can be encrypted and exfiltrated through Discord webhooks
โข Instead of relying solely on traditional attacker-controlled C2 logic, the implant uses legitimate LLM-provider endpoints as part of its decision architecture
โข Talos linked development artifacts to an individual associated with criminal-forum carding activity dating back to 2025
โ ๏ธ Important:
Talos has NOT confirmed deployment of CLOSEDQUORUM in the wild. The publicly analyzed build contains placeholder API keys and a dummy webhook, so this should currently be treated as emerging offensive tooling rather than an active malware campaign.
โ ๏ธ Analyst Note:
The architectural shift is significant: AI is no longer simply helping an attacker write malware โ the models themselves are being placed inside the malware's operational decision loop.
Original Cisco Talos research:
blog.talosintelligence.com/tโฆ
#AI #Malware #C2 #ThreatIntel #CyberSecurity #AgenticAI #DDW #DarkWeb
Matthew Green ๐ป retweeted
"They then inspected the documents they collected prior to exfiltrating them over to Mega storage servers using the Rclone application."
Read the full report: buff.ly/9SUamWk
#DFIR #ThreatIntel
Matthew Green ๐ป retweeted
Good piece from the NCSC on agentic defence
The difficult part starts when the agent is allowed to actually change things in production.
Scope, criticality, confidence and recoverability suddenly matter a lot more than โcan the model understand the attack?โ
Worth a read
ncsc.gov.uk/blogs/one-does-nโฆ
One of my colleagues published some research today into a campaign targeting Iranian dissidents labs.infoguard.ch/posts/iranโฆ
Matthew Green ๐ป retweeted
Si haces Threat Intelligence o ciberseguridad defensiva, tienes que guardar esto ahora mismo.
Crearon CLOAK, un framework al estilo MITRE ATT&CK pero enfocado 100% en las tรกcticas de ocultaciรณn y evasiรณn de los cibercriminales.
๐ ยฟQuรฉ incluye? โข 1,387 TTPs documentados. โข Capas tรฉcnicas, comportamentales y fรญsicas. โข 100% Open source y actualizado este 2026.
Entender cรณmo se esconden los atacantes es la รบnica forma de encontrarlos antes de que sea tarde.
Te dejo la plataforma interactiva y los detalles abajo en los comentarios ๐ก๏ธ๐
Matthew Green ๐ป retweeted
here's how JEV works, simplified
I've been experimenting with it for the last hour, and it's EXTREMELY good at making decisions with the right references and context
you give it the information, your questions, and the type of answer each question needs:
> a choice from options you provide
> a score on a scale you define
> a probability that something is true
the models we're used to often give us long written answers, with explanations and reasoning
jev returns structured answers your app can use directly, instead of generating those explanations
information + your questions + allowed answers โ answers your app can use
you define what happens next, based on those answers
that could mean sending information to the right place, checking an AI agent's work, or flagging something for human review
because jev doesn't generate prose, it doesn't invent facts or sources inside a written explanation (hallucinations)
clear questions and useful context matter, including references that explain what it should check
I'm seeing so many cool use cases across X, and I can see people adding this to all kinds of existing apps
if you haven't started building with it yet, try it on one decision your app already makes
the new jev model is insane..
it can check your AI's work and make decisions inside software for $0.042 per million input tokens, with free output
here are the first things you should use jev for:
1. second brain
2. content workflow
3. post analysis
4. SEO article review
typesafe reports up to 193.6ร faster results and 444.6ร lower costs than the LLMs in its workflow tests
you give jev information and specific questions. it returns choices, scores or probabilities that your software uses to decide what happens next
1. second brain
when a document, message or meeting note enters your second brain, give jev the content and your categories
identify what it is, classify the topic and check for duplicates against existing notes
your software checks required fields, saves the content with its source and verifies that it was saved correctly
works well with the karpathy LLM wiki framework
2. content workflow
give jev your draft, and then reference your anti slop rules and voice DNA file (which defines how you write)
it will check for generic phrasing, repeated points and differences from your voice. use previous content and its results to estimate performance potential
then send results to the writing agent for revision, compare the performance estimates with results after publishing
3. post analysis
jev can compare a draft with previous posts and their results to estimate how well it could perform with your audience
evaluate the hook, topic and format against defined criterias. and compare those scores with the performance after it goes live
4. SEO article review
give jev your article / page draft, a target keyword and the articles currently ranking for that keyword (in the top 10 SERP)
compare how well they answer the query, cover the topic and provide useful information. use that comparison to estimate your article's ranking potential
then your LLMs can revise weak sections before publishing, and compare the estimate with actual rankings
so many more usecases, we will see many new upgrades to previous concepts and workflows weยดve read about now