Gary McGraw
cigitalgem@sigmoid.social
<p>software security <a href="https://sigmoid.social/tags/swsec" class="mention hashtag" rel="tag">#<span>swsec</span></a> machine learning security <a href="https://sigmoid.social/tags/mlsec" class="mention hashtag" rel="tag">#<span>mlsec</span></a> Tech | Life | Music</p>
Posts
-
View post
As part of our wider #philanthropy program, we just crossed $75,000 in loans through #KIVA. We really like the microloan idea and aim most of our support to central and South America. https://www.garymcgraw.com/life/philanthropy/ You can join TEAM BIML on #KIVA here and start out with $25 --> https://bit.ly/cigitalgem-kiva https://www.garymcgraw.com/life/philanthropy/
-
View post
Look, this happens literally EVERY DAY. Why is this news? https://www.theguardian.com/technology/2026/sep/18/openai-hacked-anthropic-claude-chatbot
-
View post
What happens to recursive pollution in the recursive self-improvement scenario? What is the tipping point between a good attractor and a bad one? #MLsec https://www.nytimes.com/2026/09/16/science/ai-recursive-self-improvement.html
-
View post
More technical reality about OpenAI's illegal hacking of Hugging Face. This was not done by anything non-human with legal intent...it was done by computer programs designed and built and run by OpenAI. Why are hacking laws not being enforced? https://www.sentinelone.com/labs/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/
-
View post
Oh look, a voice of reason in the wilderness! Melanie Mitchell talks about #MLsec and #AI #security from the perspective of a seasoned AI researcher. @melaniemitchell@sigmoid.social https://aiguide.substack.com/p/misleading-metaphors-and-real-risks
-
View post
Why does everyone believe that the OpenAI Agentic (hugging face attacking) swarm did not get out of its container? Seriously? #MLsec https://www.theregister.com/security/2026/09/01/another-artifactory-cve-under-attack-by-ai-agents-or-humans/5293769
-
View post
About those idiots hacking the plane wifi while ON the plane
-
View post
Irregular egg on your face. #MLsec https://www.irregular.com/research/next-generation-of-cyber-evals https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing https://www.wired.com/story/ok-well-there-are-even-more-ai-agent-hacking-incidents/ https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
-
View post
Autonomy has its...um...benefits? #MLsec This is the beginning of the beginning. https://www.csoonline.com/article/4203630/microsoft-confirms-an-ai-worm-is-propagating-through-copilot-and-other-ms-apps.html
-
View post
Is escaping the sandbox new for #AI models? Nope. @roblemos@infosec.exchange provides important background on #AI crime (I am quoted in the story) #MLsec https://www.darkreading.com/cybersecurity-operations/incorrigible-ai-models-resist-rehabilitation
-
View post
Can #AI do crime? Why yes...yes it can. Who gets charged? #MLsec https://www.wired.com/story/openais-rogue-ai-agent-hacked-more-than-just-hugging-face/
-
View post
Use it. Don't use it. Buy it. Don't buy it. You need it. You don't need it. Angel says yes. Devil says no...or is that backwards? #ML #AI #MLsec https://arstechnica.com/ai/2026/07/us-army-faces-ai-use-limits-after-exhausting-years-supply-of-ai-tokens/
-
View post
Best writeup yet of the OpenAI/huggingface bromance. #MLsec #ML #AI https://coalfire.com/the-coalfire-blog/openai-gave-its-model-a-test-it-broke-out-of-its-sandbox-and-hacked-hugging-face-to-steal-the-answers
-
View post
Is this hugging face hack by OpenAI Agentic bots who escaped the lab important? https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html Yes, especially in light of this https://berryvilleiml.com/2026/06/05/biml-and-the-papernot-worm/ It is both inevitable and very concerning. Autonomy cuts both ways. As the arsenal of sneaky tricks gets bigger, we can expect more interesting exploit chains. #MLsec #AI
-
View post
What?! https://nysfocus.com/2026/07/14/new-york-humanoid-robot-teacher-salamanca-school-district
-
View post
You know what sucks? When you hit an invisible non-defined usage limit with chat-Jippety pro and they won't even let you pay them more money until some random future date. Fuck that.
-
View post
#AI is a useful tool. Linux is not an anti-AI technology. https://www.theregister.com/ai-and-ml/2026/07/15/linus-torvalds-tells-ai-haters-to-fork-off/5271894
-
View post
Today I was using gpt 5.6 in pro mode. I loaded it up with shit tons of my own content and set it to some small tasks. It actually wrote two things that were so funny I laughed out loud when I was reviewing its content. It was highly accurate with only a few super obvious blind spots.The humor was not because it was wrong or making mistakes...it was because it was looking at things sideways like I do sometimes. Real humor in a highly curated technical domain is not what I expected to emerge.
-
View post
Last night BIML spoke to German TV about the mythos/fable export control situation. Please help us get this thinking in front of people. #ML #AI #MLsec #infosec #security #LLMs https://www.youtube.com/watch?v=_Jsy7UBQv0c https://berryvilleiml.com/2026/06/13/irony-the-us-government-issues-an-export-control-directive-for-fable-5-and-mythos-5/
-
View post
@petergleick@fediscience.org weakling
-
View post
BIML is proud to release a new study today: No Security Meter for AI #AI #ML #MLsec #security #infosec #swsec #appsec #LLM #AgenticAI https://berryvilleiml.com/results/no-security-meter-ai.pdf
-
View post
How can you measure security in #ML systems? Maybe similarly to the way we measure security in software systems. #swsec #appsec BIML wrote about this in a new report released today: https://berryvilleiml.com/results/ Get your copy now, released for free under a creative commons license. Applied #MLsec
-
View post
The excellent @dennisf interviews me about BIML&#39;s new paper &quot;No Security Meter for AI&quot; Have a listen. Then read our report. #MLsec #ML #AI #security #infosec #swsec #appsec https://open.spotify.com/episode/74QW2kzelVz5VtglXlA87s?si=ll7a2xo0Rx2FSmyq-_8-HQ https://berryvilleiml.com/results/no-security-meter-ai.pdf
-
View post
No Security Meter for AI #MLsec https://berryvilleiml.com/results/
- View post
-
View post
Qualcomm Security Summit 2026 #swsec #MLsec https://www.qualcomm.com/company/events/product-security-summit
-
View post
Let&#39;s have #AI avatar thing explain our new paper about measuring security in #AI. Watch vRon mispronounce BIML. #MLsec https://youtu.be/6hpvMzxNyCM
-
View post
It&#39;s a great time to be a crackpot https://www.mcsweeneys.net/articles/were-diversifying-the-university-by-hiring-more-crackpots
-
View post
As always, great reporting from @dangoodin https://arstechnica.com/security/2026/05/chaos-erupts-as-cyberattack-disrupts-learning-platform-canvas-amid-finals/
-
View post
Fix the damn software #swsec #appsec #MLsec &quot;Those vulnerabilities have been fixed, and will never again be available to attackers. In the future, AIs automatically finding and fixing vulnerabilities in all software will be a normal part of the development process, which will result in much more secure software.&quot; https://www.theguardian.com/commentisfree/2026/may/08/how-dangerous-is-anthropics-mythos-ai