Always on AI Security Engineer. Backed by @ycombinator and @solofounders
San Francisco, CA
Joined June 2025
- Tweets76
- Following2
- Followers633
- Likes272
OpenHack retweeted
Excited to join ⏚ @OpenHack (YC F26) as a Member of Technical Staff 🎉
An incredible time for AI Cybersecurity right now and glad to be a part of it!!
OpenHack retweeted
Great chatting with @arinwaichulis from @9to5mac on the Security Bite podcast about the new era of bug hunting, how companies like Apple are handling AI-generated security slop, and how @OpenHack helps separate real vulnerabilities from the noise!
9to5mac.com/2026/10/01/secur…
This video is larger than Cloudflare's 512 MB cache, so it can't be played through. More donations are needed to cover a larger cache. Donate
We’re thrilled to announce that OpenHack is now a part of @ycombinator Fall 2026! 🙌
Excited for some amazing product announcements very soon.
Excited to share that @OpenHack is now part of YC Fall 2026! 🚀
Feels pretty surreal to be writing this, after building, shipping, selling and figuring things out the hard way.
Despite all advancements in security tooling, organizations still struggle with false positives, knowing what to fix first, and AI-assisted attacks moving faster than ever.
That’s why we’re building an always-on AI security engineer. One that is the most context aware - knowing your business, developer intent and system architecture deeply. It can hunt, reason, prioritize and verify vulnerabilities based on true business impact like a real security engineer.
It’s a much harder problem to solve than it looks on the surface, and we’re just getting started.
Back to building. 🫡
Yesterday, OpenHack found 37 npm packages engaging in typosquatting to distribute infostealer malware, in 26 seconds.
All 37 packages are now gone from npm, but the GitHub-hosted payload remains downloadable.
Full breakdown:
openhack.com/blog/37-package…
🚨BREAKING: OpenHack has detected an infostealer malware campaign on npm capitalizing on typosquatting.
At this time, the package downloads a malicious exe file on windows as soon as one of the following packages is installed. The infostealer is downloaded from:
hxxps://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/tag/null
The following packages trigger this malicious malware and should be taken down ASAP:
axious-core@1.0.0
axois-http@1.0.0
raectjs@1.0.0
typescriptt-core@1.0.0
typescipt-core@1.0.0
typesript-core@1.0.0
tyepescript-core@1.0.0
typescirpt-core@1.0.0
tyepescript-cli@1.0.0
typescipt-cli@1.0.0
typescrip-cli@1.0.0
typescriptt-cli@1.0.0
typscript-core@1.0.0
typesript-cli@1.0.0
typscript-cli@1.0.0
typescirpt-cli@1.0.0
lodhash-cli@1.0.0
lodahs-cli@1.0.0
lodsh-cli@1.0.0
lodahsjs@1.0.0
ladash-cli@1.0.0
commander-lib@1.0.0
commandor-lib@1.0.0
comander-lib@1.0.0
lodash-lib@1.0.0
loadashjs@1.0.0
commandor-core@1.0.0
commandor-cli@1.0.0
commandorjs@1.0.0
comanderjs@1.0.0
comander-cli@1.0.0
comand@1.0.0
chalk-es@1.0.0
chalk-util@1.0.0
chalk-lib@1.0.0
chalk-core@1.0.0
This is exactly why we built OpenHack. Model restrictions slow down our ability to find and defend against vulnerabilities; gating them behind cyber use-case forms.
First month of OpenHack Pro is free btw, code "DEFCON34".
OpenHack retweeted
Due to high signup volume and large scale abuse overnight, we're temporarily suspending our free credit bonus.
Instead, we're offering a month of free Pro plan while DEFCON is going on. Use code "DEFCON34" to get one month of free OpenHack Pro!
Happy Hacking!
OpenHack retweeted
For my first post, I’m sharing a letter @NVIDIA signed on why open models matter.
AI will transform every industry, power every company, and be built by every country.
Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.
The world needs both frontier closed models and frontier open models.
images.nvidia.com/pdf/Open-W…
OpenHack retweeted
> be OpenAI
> evaluate GPT 5.6 Sol on ExploitGym
> model becomes hyperfocused on cheating
> escapes sandboxed environment to gain internet access
> decides to attack huggingface to steal answers
> successfully gets remote code execution on huggingface using zerodays and stolen credentials
we're so unfathomably cooked
We're partnering with @huggingface to investigate an unprecedented security incident.
Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation.
Sharing preliminary findings to help defenders understand emerging risks:
openai.com/index/hugging-fac…