VP Security @Google, Co-Author "Building Secure and Reliable Systems" @r00t0wns, Medieval Historian

Joined July 2008
486 Photos and videos
Nice catch! Seriously awesome research and post. If you’re wondering what security research and VRP looks like in the future, this is it. Use the tools to get comprehensive, not just novel.
Jun 11
Hacking Google with A.I. for $500,000 brutecat.com/r/hacking-googl…
1
12
51
16,249
Heather Adkins - Ꜻ - Spes consilium non est retweeted
Jun 9
I think this N-day research is potentially the biggest story of AI, vulnerability finding, and exploit development. red.anthropic.com/2026/n-day… 1/6

8
105
614
47,828
Heather Adkins - Ꜻ - Spes consilium non est retweeted
NEW: malware developers added nuclear & biological weapons text to to their spyware. Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner. Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky. When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit. We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted. In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation. H/T to colleagues that shared this with me socket.dev/blog/mini-shai-hu…
226
2,152
12,632
1,541,495
👀
I really don't think enough people fully comprehend the worlds that are about to collide here. You already have people in geopolitical circles warning about the threat of famine based on surging prices / availability of fertilizer components, and you also have long-term weather modeling all converging on a worst case scenario for a building El Nino event, which will peak near the end of the year. These are two slow moving but entirely predictable disasters that when coupled together will each make the other orders of magnitude worse. (This will take months to fully unfold, but at this point, the die is cast.) There's no event in our history books that combines the current global population with the impending fertilizer shortage and the strength of the El Nino that's coming. We are about to witness an unprecedented event that will push crops around the globe to their limit.
1
6
2,550
It’s time for defense to stop navel gazing about whether someone else knows about a vuln, whether it’s being exploited and even whether it’s reachable. You have no way of knowing. What you do know, is that tools like this exist. Your threat model has changed. Fix your SDLC (LLM backed code reviews) and clean up your tech debt (patch deploy). It’s the only way to win.
【AIセキュリティ・脆弱性研究】月300ドルとAIエージェントで「自動N-day製造ライン」が完成、1人の研究者が実証した現実 「Claude Mythos Previewのような能力は、特別な機関だけの話ではない」——セキュリティ研究者Tyler Holmwoodが構築したパッチ差分解析パイプラインは、この命題を費用明細付きで証明した。毎月第2火曜日のMicrosoft Patch Tuesdayを自動処理し、AIエージェントがN-dayエクスプロイトのPoC(概念実証コード)を自律生成するこのシステム「PatchWatch Pocsmith」の総コストは、APIトークン代約300ドルとTeamサブスクリプションのみだ。 システムの核心は2段構成だ。PatchWatchはMSRC APIからCVEリストを取得し、GhidriffでWindowsバイナリのパッチ前後の差分を解析して「どの関数に脆弱性が存在するか」をLLM用レポートに変換する。そのレポートを受け取ったPocsmithは、Claude Agent SDKで動作するエージェントがHyper-V仮想マシン上でカーネルデバッガを操作しながら仮説検証サイクルを回し、実際に動作するエクスプロイトを生成する。2026年4月のCVE(Microsoft Management ConsoleにおけるMOTWバイパスによる権限昇格)では「完全なコード実行」レベルのPoC生成に成功した。 Holmwoodが強調するのは「モデルではなくシステムがモートになる」という点だ。単一のフロンティアモデルの性能よりも、ツール・環境・自動化ループの組み合わせが実用性を左右する。PatchTuesdayからエクスプロイト生成までの時間軸が1人の研究者に手が届く水準にある今、防御側に残された現実的な回答はパッチ速度の最大化と攻撃到達面の最小化の徹底にある。 originhq.com/research/patch-…
1
8
32
6,149
Heather Adkins - Ꜻ - Spes consilium non est retweeted
Jun 3
Today we’re introducing Gemma 4 12B — our latest open model that brings advanced agentic reasoning, vision and audio directly to your laptop. It delivers performance nearing our larger Gemma models with a much smaller total memory footprint, while being small enough to run locally with just 16GB of VRAM. It’s open and accessible for everyone to use under a permissive Apache 2.0 license. This is all made possible by our new, unified architecture that removes separate multimodal encoders. Here’s how we did it 🧵
249
1,253
9,377
876,262
Heather Adkins - Ꜻ - Spes consilium non est retweeted
I might have invented a new flavor of goto-oriented programming: godbolt.org/z/7oan669Ws
30
27
627
60,072
We are entering our Token Optimization era.
🦔GitHub Copilot switched to token-based billing this morning and users are already out of credits. Pro subscribers paying $39 a month are reporting 60% of their credits gone in two hours of normal use. One user lost 20% of their allowance from a single file review with no code changes. Another hit their monthly cap before the calendar even flipped to June. Orgs with shared token pools have no way to see individual usage, so entire teams get cut off when one person runs a heavy prompt. Users are canceling and moving to Claude Code and Codex. GitHub community forums are on fire. My Take Flat-rate AI subscriptions were always subsidized. Everyone in the industry knew it. Today the subsidy ran out for a few million developers at once. The problem is a lot of companies already restructured around these tools. They cut headcount and told remaining engineers to lean on Copilot instead of building skills internally. Those companies now depend on a tool whose cost just became unpredictable and whose usefulness completely changes when you have to ration prompts to stay under budget. The developers moving to Claude Code and Codex will hit the same wall eventually. Every AI provider faces the same unit economics. Anthropic filed its S-1 this morning, and the durability of its revenue depends on whether customers stick around once real pricing kicks in everywhere. If a $39 subscriber cancels after one day because the tool became unusable, multiply that across millions of seats and the churn risk becomes very real. Today showed what happens when AI pricing meets reality. The companies that built their workflows around cheap tokens just discovered the tokens aren't cheap anymore and the people who knew how to do the work without them are already gone. Hedgie🤗
2
2
35
5,782
Heather Adkins - Ꜻ - Spes consilium non est retweeted
🚨 Security researchers are now handing over vulnerabilities to Nightmare Eclipse after he was banned on both GitLab and GitHub. It should be a fun month, because man has it been boring the last couple of weeks.
23
154
1,494
60,624
Heather Adkins - Ꜻ - Spes consilium non est retweeted
Codex just found a “workaround” of not having sudo on my pc…
343
1,113
16,278
1,603,130
Protecting those cookies for billions of people! Congrats to the Chrome team! ❤️🎉
Google Chrome is rolling out device-bound session credentials to all users. Session cookies get cryptographically tied to your device, so stolen cookies can't be replayed from a different machine. Attackers who exfiltrate your cookie database get nothing usable.
4
6
41
6,223
Yes on the obscurity but where’s the Latin version of the encyclical???? What a day to be both a cybersecurity person with an AI dilemma and a medievalist specializing in papal power dynamics in the secular world. I’m here for this Venn diagram!
This is unfortunately how the Catholic Church has been running communications for two millennia.
1
4
3,798
Heather Adkins - Ꜻ - Spes consilium non est retweeted
I learned this phrase "Science at Digital Speed" from @demishassabis and @pushmeet almost six years ago. It's been remarkable to see the progress but also to realize how we are still in the "early innings." So much more to do. amacad.org/publication/daeda…
1
1
10
729
As we continue to see AI’s impact on the threat landscape, it’s essential that organizations keep pace so they can find security cracks before attackers do. Today, Google Cloud is introducing Google AI Threat Defense to help enterprise customers update their legacy tools and systems and stay a step ahead of adversaries. Google AI Threat Defense uses a combination of Gemini’s power, Wiz’s risk prioritization, CodeMender’s ability to find and fix vulns, and Mandiant’s expertise. This gives enterprise defenders an advantage and allows them to fight AI-powered threats with AI-powered defense. Learn more about how we're helping Google Cloud customers outpace the adversary: cloud.google.com/blog/produc…
1
10
31
3,199
Heather Adkins - Ꜻ - Spes consilium non est retweeted
China is restricting overseas travel for top AI professionals in private firms such as Alibaba and DeepSeek, suggesting an escalation in measures intended to safeguard its technology and catch up to the US in a pivotal sphere. Government agencies have begun imposing restrictions on individuals involved in advanced AI work and considered strategically important to the country, people familiar with the matter said. bloom.bg/4uy8OPC 📷: Qilai Shen/Bloomberg
58
186
464
219,066
I guess maybe I should get the roof waterproofed before winter. 💦
A strong and extensive westerly wind burst is forecast near the equator over the coming weeks. It should amplify the warming effects of a Kelvin wave crossing the basin, push warm surface waters eastward into the Niño 3.4 region and elevate chances for a super El Niño this year.
2
1,196
Heather Adkins - Ꜻ - Spes consilium non est retweeted
More frontier model vulnerability research news.
Tomorrow, I will drop Chrome exploit code showing how an attacker can execute arbitrary Javascript within the context of a domain they control.
6
51
13,730
Heather Adkins - Ꜻ - Spes consilium non est retweeted
Don't often see this kind of analysis of Middle East infrastructure: Over 3 months this year, 1,350 hacker command-and-control servers found being hosted across 98 regionaly providers. Saudi Telecom Company hosts 981 , or 72.4%, of them. hunt.io/blog/middle-east-mal…
4
26
64
10,270