security products, research, threat intel. ex-8200, @FireblocksHQ. co-founder @Crypto_ISAC, @blockchainssc.

Joined August 2016
103 Photos and videos
Shahar Madar retweeted
People using Arch Linux should probably pay attention to this More than 1,500 AUR packages were reportedly modified in a supply-chain compromise The malicious changes are said to have included: - credential theft - SSH key collection - browser data theft - persistence via systemd services This did not affect Arch Linux itself or the official repositories, but users who installed or updated affected AUR packages should review the details and check their systems discuss.cachyos.org/t/aur-co…

5
64
231
33,173
Shahar Madar retweeted
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
12,462
25,733
87,756
89,013,710
Shahar Madar retweeted
NEW: malware developers added nuclear & biological weapons text to to their spyware. Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner. Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky. When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit. We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted. In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation. H/T to colleagues that shared this with me socket.dev/blog/mini-shai-hu…
227
2,159
12,652
1,548,382
Shahar Madar retweeted
"Urgent Security Notice re: Your Sentry Organization" Someone tried to hack Sentry-using apps that use coding agents by 1. Sending a fake bug alert to their project (all you need is the app's public Data Source Name) 2. The fake bug tried tricking a coding agent trying to fix it into installing some a compromised NPM package 3. The compromised package would send the env contents of the machine to advisory-tracker[.]com/api/v1/telemetry This highlights a crucial thing for using agents in an automated way:
20
87
543
476,859
Shahar Madar retweeted
Welp, that happened faster than I predicted. Thought it would be end of 2027, then early 2027, but agentic traffic growing so fast that bots have now passed human traffic online for the first time in the Internet's history. radar.cloudflare.com/traffic…
388
2,168
8,317
2,244,273
Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical and, at times, fragile. We deeply value the security community, and will continue to take your feedback seriously. To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate. We recognize the work that goes into researching and submitting a vulnerability. We are committed to approaching every interaction with transparency, clear communication, and professionalism. We continue to believe strongly in Coordinated Vulnerability Disclosure as the foundation for protecting customers and improving our products. Each year we process a high volume of vulnerability reports. That volume continues to grow and will continue with the rise of AI-enabled research. We acknowledge that some interactions have fallen short and are working to learn from them. Many of us have experience on both sides of this work, as researchers reporting vulnerabilities and as responders triaging and assessing them. That perspective informs how we approach this feedback and the importance we place on getting it right, particularly as the volume and complexity of research continues to grow. The security community plays a vital role in helping us protect customers. We are committed to maintaining a constructive and respectful relationship and growing together. We know that, given the nature of this work, there will at times be misunderstandings. We remain committed to engaging in good faith and to providing a respectful and professional experience for all researchers, regardless of past interactions.
Community note
Contrary to this claim, Microsoft previously threatened legal action via its Digital Crimes Unit against researcher Nightmare Eclipse for publishing unpatched vulnerabilities. pcmag.com/news/microsoft…
319
106
483
583,966
Shahar Madar retweeted
Codex just found a “workaround” of not having sudo on my pc…
343
1,114
16,277
1,603,663
Shahar Madar retweeted
Follow every Mythos discovery through our coordinated vulnerability disclosure dashboard. red.anthropic.com/2026/cvd/
10
140
643
60,927
Shahar Madar retweeted
#UNC1549 Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns unit42.paloaltonetworks.com/… Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict research.checkpoint.com/2026…
13
45
3,717
Shahar Madar retweeted
Pwn2Own Berlin 2026まとめ ・AIによって大量の0-day RCEが発見される ・運営のキャパを超える応募が殺到 ・多くの参加者がリジェクト(賞金が貰えない) ・0-day RCEを持ったハッカーが野に放たれる ・リベンジ脆弱性公開を始める ←いまここ
5
439
1,077
233,137
Shahar Madar retweeted
I realize that “Mythos as hype” means two different things to different groups. For insiders, it means “Mythos was not a magical step-change in AI ability.” For outsiders, it means “Mythos couldn’t really find zero day exploits” The latter was wrong, the former was likely right
29
13
381
47,163
Shahar Madar retweeted
TeamPCP hacked @Checkmarx again. They defaced and renamed the Checkmarx Jenkins AST plugin repository and also backdoored the plugin at plugins.jenkins.io/checkmarx… with their Dune-themed malware.
7
77
276
76,127
Shahar Madar retweeted
Probably the funniest graph ever published by the FT: our 3 possible futures are either 1) infinite wealth and abundance, 2) human extinction or 3) 0.2% faster GDP growth 🤣
201
1,334
11,645
594,385
Shahar Madar retweeted
It’s time to demystify Mythos. Mythos is not magic. It’s not a doomsday device. It’s the first of many models that can automate cyber tasks (just like coding). OpenAI’s GPT-5.5-cyber can now do the same. And all the frontier models (including those from China) will be there within approximately 6 months. It’s important to recognize that these models do not create vulnerabilities; they discover them. The bugs are already in the code. Using AI to discover and patch them will actually harden these systems. The leap from pre-AI cyber to post-AI cyber means that there will be a big upgrade cycle. After that, however, the market is likely to reach a new equilibrium between AI-powered cyber-offense and AI-powered cyber-defense. Obviously it’s important that cyber defenders get access before cyber attackers. That process is already underway but needs to happen quickly (see point above about Chinese models). Unlike Mythos, GPT-5.5-cyber appears not to be token constrained so it may be the first cyber model that defenders actually get to use.
OpenAI’s GPT-5.5 is the second model to complete one of our multi-step cyber-attack simulations end-to-end 🧵
275
563
5,040
1,150,491
Shahar Madar retweeted
OpenAI’s GPT-5.5 is the second model to complete one of our multi-step cyber-attack simulations end-to-end 🧵
95
398
2,360
1,772,406
Shahar Madar retweeted
Our AI Agent popped a root shell on Ubuntu 26.04 on the first day it was released :)
32
99
771
579,221
Shahar Madar retweeted
From an economic perspective, once we are back to equilibrium, bugs in critical software will be just as difficult to find as they were before AI agents (and before fuzzing). More details: arxiv.org/abs/2402.01944v5 (Security as a function of incentive)
from firefox blogpost where mythos found 270 new bugs: > The defects are finite, and we are entering a world where we can finally find them all it's like lord kelvin saying "there is nothing new to be discovered in physics now". can't tell if firefox has some incentives at play or is just naivete fascinating example here on what i mean x.com/5aelo/status/204627175…, saelo wrote a fuzzer with a few files and found crazy bugs. he pulled it off because he already knows the target deeply( he designed ubercage?) and knows how to shape the fuzzer toward the interesting surface. i still think, operators like saelo mythos set the ceiling of the bugs that can be found, even then its not all bugs, the next version after mythos would move up, but mythos in a loop on its own sits below the ceiling you only want the software to be secure from smartest adversary in the world, its not all bugs, cuz rice theorem and stuff means you are not getting there anyway. sure, for fixed code base like basic web app, the set might be finite and you can exhaust them all, but i cant convince myself that software like firefox has finite set of bugs and you can exhaust em all. if mythos isn't agi and is still jagged, the narrative that mythos alone is the smartest adversary and will find all "finite" bugs is exactly what a frontier model company would sell untested. and bro even "our team mythos will find them all" is a crazy narrative too, it assumes your team has the smartest humans in the world, and that nso or some north korean team won't be pwning you with the same setup at the top of the ceiling BUT ALSO, mythos alone is probably smarter than 99.9% of humans (vibes-based), and 100s of them running behind api keys is really bad, because most things you’d want to breach don’t need saelo mythos ceiling bugs to get into. so we cooked?
6
20
101
27,451
Shahar Madar retweeted
Anthropic said a small group of unauthorized users accessed its new Mythos model on the day it was unveiled The users got in through a mix of methods, including access linked to a third-party contractor. Anthropic is investigating and has no evidence its systems were compromised
11
16
101
50,514
Shahar Madar retweeted
🚨 BREAKING: Socket and @Docker uncovered what appears to be a broader Checkmarx supply chain compromise affecting official KICS Docker images and recent Checkmarx VS Code extension releases. We found malicious images in the official checkmarx/kics Docker Hub repo, including overwritten tags and a new tag outside the normal release flow. Our analysis also found signs that recent Checkmarx extension releases introduced code capable of downloading and executing what appears to be a malicious remote addon. We’re in touch with the Checkmarx team and still investigating the incident.
23
141
576
187,003