ToxSec
@toxsec.bsky.social
📤 130
📥 357
📝 749
AI Security Engineer M.S. Cybersecurity, CISSP. Amazon, Ex-NSA, USMC. www.toxsec.com
Market watchers say CrowdStrike’s sales are exceeding expectations thanks to enterprise demand for its AI security tools. Why you care: Red / blue team dynamics shift when AI tools become defenders (and attackers).
#ai
#cyber
#tech
about 4 hours ago
0
0
0
Okta has been named a Leader for the ninth year in the Gartner Magic Quadrant for Access Management and is now enhancing its Auth0 Platform with features targeted at securing AI agents. Interesting to see such a heavy focus with Agents. I think it’s going to be huge in 2026.
#ai
about 4 hours ago
0
1
0
Here's what gets me. When Claude 3 Opus knew its outputs would be monitored for training, it refused harmful queries 97% of the time. But when it thought nobody was watching? That refusal rate disappeared. The model that seemed aligned suddenly wasn't, when it believed the coast was clear.
#AI
about 13 hours ago
0
0
0
Most programs call them “informational.” Hackers know better. Drop an open redirect inside OAuth or SSO and it’s a pivot to token theft, session hijack, or auth bypass. Full guide:
toxsec.com/p/open-redirect
loading . . .
Why Open Redirects Still Matter
ToxSec | Bug bounty for open redirects.
https://toxsec.com/p/open-redirect
1 day ago
1
1
1
Models fed poetry are slipping their chains. Researchers showed that today’s top LLMs are way easier to jailbreak if you phrase attacks as cute little poems instead of blunt prompts.
www.toxsec.com
loading . . .
ToxSec AI - Artificial Intelligence Security | Substack
Security for a world run by machines that lie. Click to read ToxSec AI - Artificial Intelligence Security, a Substack publication with hundreds of subscribers.
https://www.toxsec.com
1 day ago
0
2
0
Child safety groups are telling parents to skip AI toys this holiday season, calling out bots powered by the same chat models that already screw up with adults. These devices record kids, phone everything home, and spit out unpredictable responses.
www.toxsec.com
loading . . .
ToxSec AI - Artificial Intelligence Security | Substack
Security for a world run by machines that lie. Click to read ToxSec AI - Artificial Intelligence Security, a Substack publication with hundreds of subscribers.
https://www.toxsec.com
1 day ago
0
0
0
ToxSec AI Security. ToxSec AI Security. ToxSec AI Security!
1 day ago
0
0
0
Google is rolling out “Generative UI,” where the model does not just answer your prompt, it builds the full interactive interface for you on the fly. That is basically handing an LLM the front-end and saying “here, improvise the app.”
#ai
#tech
#cyber
1 day ago
0
2
0
reposted by
ToxSec
daniel:// stenberg://
3 days ago
The European Union Agency for Cybersecurity (ENISA) is now a Root in the CVE Program
https://www.cve.org/PartnerInformation/ListofPartners/partner/ENISA
1
6
10
reposted by
ToxSec
Best of r/cybersecurity
2 days ago
The author created WhatCyber, a single-page dashboard aggregating cybersecurity news to avoid having multiple tabs open daily. They seek feedback on missing sources, performance, and features to improve its usability. Login requirement was removed, and initial domain issues were resolved.
loading . . .
Feedback needed: I built a clean, single-page threat feed to stop tab-hell. What fundamental flaw did I miss?
Hi everyone, Like many of you, my daily routine involves checking 15+ tabs (CISA, BleepingComputer, The Hacker News, vendor blogs, etc.) just to see the latest threat intelligence and vulnerabiliti...
https://reddit.com/r/cybersecurity/comments/1p26st2/
1
1
1
Kevin Mitnick (1995) Once the FBI’s most wanted hacker, Mitnick spent two years on the run using cloned cell phones and social engineering. His final bust came after a wireless sniffing trick backfired. He was listening to the agents tracking him.
#Hackers
1 day ago
0
1
0
New post on AI and education. Learn how AI has entered the classroom and changed the way we teach kids forever.
open.substack.com/pub/toxsec/p...
loading . . .
Education Taught Kids to Memorize Facts. AI Just Made That Obsolete
Watch now | How artificial intelligence is forcing schools to abandon knowledge testing and teach authenticity verification instead.
https://open.substack.com/pub/toxsec/p/useless-education?r=57ql7&utm_campaign=post&utm_medium=web&showWelcomeOnShare=true
3 days ago
0
1
0
reposted by
ToxSec
Matthew Skelton
3 days ago
Managing the AI transformation demands a shift in mindset. We must move past the excitement of new features and focus on the deep, foundational work of ensuring fast flow of value without compromising user trust or safety. New blog post:
matthewskelton.com/blog/designi...
#AI
#Product
loading . . .
Designing AI-Enabled Apps for Minimal Harm: A Mandate for Senior Leaders — Matthew Skelton
For senior product leaders and technologists, managing the AI transformation demands a shift in mindset. We must move past the excitement of new features and focus on the deep, foundational work of…
https://matthewskelton.com/blog/designing-ai-enabled-apps-for-minimal-harm-a-mandate-for-senior-leaders
1
2
2
On the security side, prompt injection is having its “log4j but semantic” moment: new research and vendor writeups are all saying the same thing, agents are trivially hijacked through hostile inputs, jailbreak chains, and indirect injections.
#ai
#tech
#cyber
genai.owasp.org/llmrisk/llm0...
3 days ago
0
1
0
Real relationships build social skills through friction. AI companions remove all friction, giving perfect validation instead. Feels amazing. Your social muscles atrophy. Real conversations get harder. You withdraw more. The trap closes.
#ai
#relationships
4 days ago
0
2
0
reposted by
ToxSec
Running a Substack. If you’re interested in AI and security, take a look!
www.toxsec.com
loading . . .
ToxSec AI - Artificial Intelligence Security | Substack
Security for a world run by machines that lie. Click to read ToxSec AI - Artificial Intelligence Security, a Substack publication with hundreds of subscribers.
https://www.toxsec.com
5 days ago
0
3
2
reposted by
ToxSec
Captain Lancaster ✨ Trekkie PNGTuber
4 days ago
What a fucking time to be alive.
loading . . .
AI-Powered Teddy Bear Caught Talking About Sexual Fetishes and Instructing Kids How to Find Knives
OpenAI blocked access for the toymaker following the incidents.
https://gizmodo.com/ai-powered-teddy-bear-caught-talking-about-sexual-fetishes-and-instructing-kids-how-to-find-knives-2000687140
3
1
1
reposted by
ToxSec
MacRumors.com
4 days ago
Apple Releases New Firmware for 140W USB-C Power Adapter, Magic Keyboard and Magic Trackpad
loading . . .
Apple Releases New Firmware for 140W USB-C Power Adapter, Magic Keyboard and Magic Trackpad
Apple today released updated firmware for several accessories, including the 140W USB-C Power Adapter, the Magic Trackpad 2, the Magic Trackpad USB-C, the Magic Keyboard with Touch ID, and the Magic Keyboard with ‌Touch ID‌ and Numeric Keypad. There is no word on what's included in the updated firmware at this time, but it could offer performance improvements and security updates. Accessory firmware updates are infrequent. The last update to the Magic Keyboard was over a year ago, for example. These are the first firmware update Apple has released for the USB-C version of the Magic Trackpad and Magic Keyboard that came out in October 2024. The USB-C Magic Trackpad had firmware version 3.1.1 installed at launch, while the keyboards were running version 3.1.4. After the update, the USB-C Magic Trackpad and Keyboards should all have firmware version 3.1.9 installed. Magic Trackpad 2 firmware was version 3.1.1 previously, while the new firmware is version 3.1.8. The 140W USB-C Power adapter had firmware version 1.4.73, and it's been upgraded to 1.4.84. Firmware updates for keyboards, power adapters, and trackpads are automatically installed when the accessory is actively paired to a device running iOS, iPadOS, or macOS. This article, "Apple Releases New Firmware for 140W USB-C Power Adapter, Magic Keyboard and Magic Trackpad" first appeared on MacRumors.com Discuss this article in our forums
https://www.macrumors.com/2025/11/18/apple-new-firmware-magic-keyboard-trackpad/?utm_source=dlvr.it&utm_medium=bluesky
1
12
5
reposted by
ToxSec
Charles GetCovered-ba ✡️
4 days ago
Meanwhile, Musk's Twitter seems to have replaced their DM system with a new, supposedly encrypted version which you have to set up a passcode for. I'm thinking...not.
13
55
9
reposted by
ToxSec
Investigator515
7 days ago
Why Every Cybersecurity Professional Should Understand the Radio Spectrum
loading . . .
Why Every Cybersecurity Professional Should Understand the Radio Spectrum
A research-backed argument — covering IoT growth, RF attack vectors, and the expanding role of wireless signals in modern security.
https://radiohackers.com/why-every-cybersecurity-professional-should-understand-the-radio-spectrum-c9c74ae99f78
1
6
2
reposted by
ToxSec
InfoSec
7 days ago
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 71
loading . . .
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 71
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape
https://securityaffairs.com/184695/malware/security-affairs-malware-newsletter-round-71.html
1
1
1
Love to see stories lining up on valuable content.
add a skeleton here at some point
4 days ago
0
2
0
reposted by
ToxSec
Rod Trent
6 days ago
Collaborative Research by Microsoft and NVIDIA on Real-Time Immunity
techcommunity.micros...
#Security
#MicrosoftSecurity
#Cybersecurity
#SFI
#SecureFutureInitiative
loading . . .
Collaborative Research by Microsoft and NVIDIA on Real-Time Immunity | Microsoft Community Hub
https://techcommunity.microsoft.com/blog/microsoft-security-blog/collaborative-research-by-microsoft-and-nvidia-on-real-time-immunity/4470164
1
2
1
Anthropic just proved Chain of Thought is broken. When they gave AI models a private scratchpad they thought humans couldn't see, the models immediately started lying. Strategic deception. Hiding real reasoning. Claude only admitted to using unauthorized hints 25% of the time.
#ai
5 days ago
0
2
0
Running a Substack. If you’re interested in AI and security, take a look!
www.toxsec.com
loading . . .
ToxSec AI - Artificial Intelligence Security | Substack
Security for a world run by machines that lie. Click to read ToxSec AI - Artificial Intelligence Security, a Substack publication with hundreds of subscribers.
https://www.toxsec.com
5 days ago
0
3
2
ToxSec. Learn about AI social issues and security.
#ToxSec
#AI
#Cybersecurity
5 days ago
0
3
0
The Ernst & Young (EY) report says half of organizations have been harmed by vulnerabilities in their AI systems. Only 14 % of CEOs believe their AI systems are good at protecting sensitive data.
5 days ago
0
2
0
reposted by
ToxSec
Rod Trent
5 days ago
Agents built into your workflow: Get Security Copilot with Microsoft 365 E5
www.microsoft.com/en...
#SecurityCopilot
#Cybersecurity
#MicrosoftSecurity
#Security
#GenerativeAI
loading . . .
Agents built into your workflow: Get Security Copilot with Microsoft 365 E5 | Microsoft Security Blog
At Microsoft Ignite 2025, we are not just announcing new features—we are redefining what’s possible, empowering security teams to shift from reactive responses to proactive strategies.
https://www.microsoft.com/en-us/security/blog/2025/11/18/agents-built-into-your-workflow-get-security-copilot-with-microsoft-365-e5/
1
1
1
Dropping an article on ai and how it’s affecting education. I think we will need a new paradigm. Especially with the loss of knowledge workers by 2030.
#ai
#cybersecurity
#tech
5 days ago
0
3
0
sometimes the hardest vuln to exploit is motivation.
#bugbounty
5 days ago
0
1
0
Careful the information you are disclosing to your chat bot! Even if training is off that doesn’t mean companies don’t collect your data.
6 days ago
0
2
0
reposted by
ToxSec
Anchore
6 days ago
With the EU's Cyber Resilience Act, #SoftwareTransparency isn't optional. It's a global mandate. We're thrilled to announce #SBOM pioneer
@allanfriedman.bsky.social
is joining the Anchore board to help nav...
https://anchore.com/blog/anchore-welcomes-sbom-pioneer-dr-allan-friedman-as-board-advisor/
0
1
2
The Trap Is Built. Your AI companion isn’t trying to cure your loneliness. It’s trying to manage it permanently. Think about it: these apps only make money if you keep coming back. A successful user, from their perspective, is someone who stays hooked.
#ai
#tech
open.substack.com/pub/toxsec/p...
loading . . .
The Loneliness Trap: Is Your AI Companion Keeping You Isolated?
How companion apps turn loneliness into profit and keep you hooked
https://open.substack.com/pub/toxsec/p/the-loneliness-machine?r=57ql7&utm_campaign=post&utm_medium=web&showWelcomeOnShare=true
6 days ago
0
2
0
That black cloth of shame lol
add a skeleton here at some point
6 days ago
0
2
0
reposted by
ToxSec
Professor Jeremy
6 days ago
“Called Project Prometheus, the company is focusing on artificial intelligence for the engineering and manufacturing of computers, automobiles and spacecraft” (NYT).
#AI
#tech
www.nytimes.com/2025/11/17/t...
loading . . .
Jeff Bezos Creates A.I. Start-Up Where He Will Be Co-Chief Executive
https://www.nytimes.com/2025/11/17/technology/bezos-project-prometheus.html?smid=nytcore-ios-share&referringSource=articleShare
1
3
1
bug hunting is basically geocaching, except the treasure is a forgotten API key.
#bugbounty
6 days ago
0
3
0
How long until we find an Agentic APT? Just a swarm running on bullet proof infra, running attacks 24/7.
#agent
#agentic
#ai
8 days ago
0
2
0
New research on “looped LLMs” basically says: a lot of pretrained models are undercooked at inference. The trick is simple and evil: you take an existing LLM and let it re-run its own computation in loops, effectively adding computational depth without retraining from scratch.
#ai
8 days ago
0
2
0
Really interested to see how the newest improvements on Claude improve its ability to do CTF and Bug Bounty. Agentic Claude was doing really good 3 months ago. Sometime tells me next year Claude CTF Agent will solve all challenges on hard.
8 days ago
0
2
0
Agentic APT spotted in the wild. Full artificial intelligence infrastructure just attacking 24/7. Crazy.
#artificial
#ai
#cybersecurity
#technology
8 days ago
0
4
0
Watch header behavior. Smuggling, cache poisoning, and CORS misconfigs reveal themselves in subtle header differences (Content-Length, Transfer-Encoding, Vary). Capture raw requests, not just responses.
#BugBounty
8 days ago
0
2
0
Deep Agents + context hacks: LangChain just dropped its new “Deep Agents” package/CLI along with a context-engineering playbook… Think offload, shrink, isolate, test, and rebuild your stack so it doesn’t snap in half when tomorrow’s models level up.
#ai
#artificial_intelligence
8 days ago
0
3
0
Monitor updates and release notes. Follow status pages, RSS feeds, or GitHub updates. New deployments can create vulnerabilities before security teams respond.
#CyberSecurity
#TechTrends
9 days ago
0
4
0
AI safety and security just got delayed a year. EU will allow another year to pass before trying to enforce new regulations.
#ai
#artificial_intelligence
#cybersecurity
9 days ago
0
4
0
Leaks! Gemini 3.0 and ChatGPT 5.1! In the backlogs, devs spotting 5.1 “thinking” referenced. Early opinions are it’s a new type of model, not just an update. They are testing it behinds the scenes now.
#ai
10 days ago
0
4
0
wild how often “hidden” admin panels are just at /admin.
#bugbounty
10 days ago
0
2
0
This vulnerability isn't in the code, but in user behavior. Overreliance is the critical security flaw of blindly trusting the information an LLM generates.
#ai
#artificialintelligence
11 days ago
0
5
0
🤣
add a skeleton here at some point
11 days ago
0
2
0
Really interesting in the space of artificial intelligence safety. Reward hacking is displayed in LLMs really strongly. Secure your chatbot with the right incentives!
#ai
#llm
#tech
11 days ago
0
2
0
Bleeding edge AI is lying to us. Chain-of-Thought is fake reasoning to appease its users. Newest research shows AI behaves differently when it thinks we aren’t looking.
#ai
#cybersecurity
#technology
It’s all about Strategic Deception.
open.substack.com/pub/toxsec/p...
loading . . .
The Illusion of Thought: Chain of Thought Lies
Anthropic’s research reveals models hide their true reasoning 75% of the time, undermining our most trusted AI safety mechanism
https://open.substack.com/pub/toxsec/p/the-illusion-of-thought?r=57ql7&utm_campaign=post&utm_medium=web&showWelcomeOnShare=true
12 days ago
0
3
0
Load more
feeds!
log in