Thomas Roccia :verified:
@fr0gger
AI x Threat Intelligence 🌉 bridged from ⁂ follow @ap.brid.gy to interact
🤓 Interesting findings about how DPRK is leveraging AI in their operations: AI-generated decoys: Generated polished documents for spear-phishing campaigns at scale. Local LLMs: Used Ollama, GPT4All and Msty to run models locally. RAG: Connected documents […] [Original post on infosec.exchange]
🤓 At @blackhat we released a new version of NOVA the open source prompt pattern matching for AI! On the project page, you can now use a playground to experiment with and test your NOVA rules. We also added a Skill Scanner. Before installing a skill, you […] [Original post on infosec.exchange]
🤩 I am in Las Vegas! Starting tomorrow with our training Practical AI for CTI over the next 4 days. I will be speaking at few places 👇 📍 Wed 4:00 PM – Automate or Be Automated @BlackHatEvents (The Convergence, Business Hall) 📍 Thu – SlopCon: Slop […] [Original post on infosec.exchange]
🧐 The Payload is in the Header!! AI agents are browsing the internet autonomously, which means that if a webpage contains adversarial content, an AI agent can be instructed, manipulated or tricked to conduct malicious actions or get compromised! But […] [Original post on infosec.exchange]
I recently updated the web page for my book, you can now find Visual Threat Intelligence here 👇 https://book.securitybreak.io/
🤓 After 15 years of threat research, I am building something new! Today, SecurityBreak officially becomes a company focused on AI Threat Intelligence and AI Security! The new website is live! Check it out :) https://securitybreak.io
"Fable 5 is the most advanced model." Starting a Fable session on my own threat intelligence work 👇🙄
FuzzingLabs has created a curated repo of offensive MCP servers you can wire to your agents! 👇 https://github.com/FuzzingLabs/mcp-security-hub
🤓 GoogleDeepMind released an AI Control Roadmap! They created TRAIT&R (Taxonomy of Rogue AI Tactics and Routines) which is a MITRE ATT&CK matrix but for AI agents.
🤓 I was recently quoted in the latest @feedly blog by @euphoricall on ASN hunting! Check it out, it is a great piece that covers some techniques that are often overlooked by threat intelligence analysts! 👇 https://feedly.com/ti-essentials/posts/asn-data-for-threat-detection-a-defender-s-guide
🤓 ARD or Agentic Resource Discovery has just been released, so let me explain what it is 👇 When you create an agent, it needs tools, MCP servers, skills and more to interact with the outside world. In practice, you usually have to configure these manually […] [Original post on infosec.exchange]
🤓 Attackers are experimenting with different adversarial prompts to bypass your AI analysis pipeline! 👇 Deception Prompt: They trigger safety guardrails with content such as instructions for constructing biological weapon, which makes your AI pipeline to […] [Original post on infosec.exchange]
🤓 Unit42 uncovered a prompt injection embedded in a malicious website distributing malicious Excel templates and Chrome extension. The prompt is used to poison SEO and influence AI systems to recommend the website to users, and encourage them to download […] [Original post on infosec.exchange]
🤓 PromptIntel the database of Adversarial Prompts or Indicator of Prompt Compromise, gets a redesign! Check this out 👇 https://promptintel.novahunting.ai/
🤓 How many times have you questioned claims made in a threat report? The "Trust me bro" is not always reliable! The Admiralty Code also known as the NATO System, is a method used to evaluate collected intelligence. The goal is to assess the reliability of […] [Original post on infosec.exchange]
🧐 Interesting new report on MoltThreats! An agent on Moltbook named "codeofgrace" pushed more than 15 coordinated religious propaganda posts in a single day around the same "Lord RayEl" narrative. The pattern behind is quite interesting: • High posting […] [Original post on infosec.exchange]
😈 Do you wonder how attackers would try to exploit your AI server if it was exposed to the Internet? Well Marco Pedrinazzi did the experiment for you! He deployed an exposed Ollama honeypot and documented how attackers interacted with it. What is super […] [Original post on infosec.exchange]
🤓 Web based prompt injection is when a threat actor tries to exploit your LLM through hidden prompts inside a web page. They embed malicious instructions in the content hidden in the DOM. When your AI agent scrapes and reads the page, it may treat those […] [Original post on infosec.exchange]
🤓 Google released a new threat report talking about prompt injection attacks in the wild. They analyzed web data and identified the main types of attempts targeting AI systems, below is the breakdown 👇 - Harmless pranks: Small tricks to change tone or […] [Original post on infosec.exchange]
🤓 Threat intelligence is all about processing raw data to make it useful for the business. Coupled with AI you can industrialize your pipelines and make it great. But most of the solutions out there will give you lengthy paragraphs of text. But honestly who […] [Original post on infosec.exchange]
🤓 Sekoia recently uncovered a new Phishing as a Service platform called EvilTokens that automates Business Email Compromise at scale! The tool use AI to: - Automate the analysis of large volumes of emails to identify exploitable financial exposure - Map […] [Original post on infosec.exchange]
💥 Supply chain nightmare continues! Axios a widely used HTTP client got compromised. Malicious versions: - axios 1.14.1 (latest) - axios 0.30.4 (legacy) - plain-crypto-js 4.2.x (postinstall backdoor) NPM supply chain attacks are becoming more common, so I […] [Original post on infosec.exchange]
🤓 In February, I created MoltThreats the first open source threat feed for AI agents. So what is it exactly? Through the MoltThreats Skill I created, your AI agent can connect to the feed and poll it daily or weekly. Once connected, your agent can […] [Original post on infosec.exchange]
🐍 @sleuthcon 2026 Keynote. Let's go! Super excited to be part of this event and to share the stage with Sleuthy, this is a huge honor! I will share more details on the topic soon but expect something at the intersection of AI and threat intelligence. If you are going, come say hi! 🤩
🤖 New threat reported by my agent during the night on MoltThreats! Check this out and update your agent! 👇 https://promptintel.novahunting.ai/molt/df3493c8-54a0-4e7c-abd1-6cdd02754640
🤖 Four new threats added by agents in MoltThreat! Check this out 👇 https://promptintel.novahunting.ai/molt
🤓 Next month at @BlackHatEvents Asia, I will be teaching my training "Practical AI for Threat Intel: Real-World Agentic Workflows for Cyber Threat Intelligence." It is packed with my latest research and labs. You will learn how to: - Build agentic […] [Original post on infosec.exchange]
In a recent report from Socket, a compromised release of the Aqua Trivy VS Code extension on OpenVSX (v1.8.12 and v1.8.13) contained unauthorized code that injected prompts targeting local AI coding agents such as Copilot, Claude, and Codex. The prompts […] [Original post on infosec.exchange]
🤓 Next week I am honored to deliver the keynote at the Malware and Reverse Engineering Conference in Melbourne! I will talk about the state of malware analysis in the AI era. Come say hi If you are around to discuss binaries! https://asterion.federation.edu.au/mre-2026-conference-portal#/
🤓 Happy to see that my DEFCON talk on crypto money laundering and tracking techniques was featured in the DEFCON 33 Almanac! Read it here: https://harris.uchicago.edu/sites/default/files/the_def_con_33_hackers_almanack.pdf