Joined June 2018
102 Photos and videos
Pinned Tweet
๐Ÿš€ Registration is now OPEN for the Real World AI Security Conference 2026 (June 23-25)! ๐Ÿš€ Join us at @Stanford for a unique event bringing together leading researchers and industry practitioners to explore the most pressing challenges in AI securityโ€”from cutting-edge attacks to real-world defenses. ๐ŸŽค Keynote Speakers: Matthew Knight (former CISO of OpenAI) @NicolasPapernot (@Uoft) @wunderwuzzi23 (embracethered.com) Alina Oprea (Northeastern University) ๐Ÿง  Invited Talks Include: โ€ข Edoardo Debenedetti (@aisequrity & @ETH ) - Evaluating and Defending Against Prompt Injection Attacks โ€ข Jerry Wei (@AnthropicAI ) - Deployable Defenses for Safeguarding Language Models from Jailbreaks โ€ข Neha Sharma & Nicolas Lidzborski (@Google Workspace) - Fortifying the AI-Integrated Workspace: A Multi-Layered, Adaptive Architecture Against Indirect Prompt Injection โ€ข John Sotiropoulos (@owasp ) - The OWASP Top 10 for Agentic AI: Real-World Failure Modes and Enforceable Defenses โ€ข Milad Nasr (@AnthropicAI ) - The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against LLM Jailbreaks and Prompt Injections โ€ข Kaiyuan Zhang (Purdue University) - BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents โ€ข Neil Perry (@Princeton) - Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing โ€ข Andy Zhang (Berkeley & @Stanford) - Building and Benchmarking Cybersecurity Agents โ€ข Yisroel Mirsky (@bengurionu ) - GAVEL: Rule-Based Security over LLM Activations โ€ข Giles Edkins & Joe Needham (MATS Research) - LLMs Often Know When Theyโ€™re Being Evaluated โ€ข Illia Polosukhin (Near.ai) - Building Secure Personal Agents โ€ข Kristopher R. (Hood College) - Trojans in Artificial Intelligence: Lessons Learned โ€ข @ben_nassi , PhD (@TelAvivUni ) - The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism We will soon publish the remaining talks and the final agenda. Donโ€™t miss the opportunity to engage with the people shaping the future of AI s urity. ๐Ÿ”— Register for the conference: seclab.stanford.edu/RealWorlโ€ฆ Please share with your network... #RW_AISec #AISecurity #CyberSecurity #infosec #AI #SecurityResearch #LLMSecurity #AgenticAI #PromptInjection #Conference
2
13
4,724
8en N@$$! retweeted
are you this old?
529
3,416
32,244
657,224
8en N@$$! retweeted
ืื ื™ ื™ื•ื“ืข ืฉื–ื” ืœื ืคื™ื™ืจ ืฉื’ื ืžืœื—ืžื” ื•ื’ื ืื™ ืืคืฉืจ ืœืฉืœื•ื— ืชืžื•ื ื•ืช ื—ื“ ืคืขืžื™ื•ืช ื‘ ื•ื•ืื˜ืกืืค, ืื‘ืœ ืœื ื™ื›ื•ืœืชื™ ืœื”ืชืืคืง ๐Ÿคท geektime.co.il/israeli-reseaโ€ฆ
4
1
19
3,973
๐Ÿšจ Registration is now open! ๐Ÿšจ We are excited to announce that registration is officially open for the Real World AI Security Conference 2026. ๐Ÿ“… June 23โ€“25, 2026 ๐Ÿ“ Arrillaga Alumni Center, Stanford University If you work on AI security, adversarial ML, LLM safety, AI system attacks, or defenses, this event is designed for you. ๐Ÿ‘‰ Register here (we have a limitation on the number of attendees): seclab.stanford.edu/RealWorlโ€ฆ We look forward to bringing together the community to explore the latest advances in AI security in the real world. #AISecurity #CyberSecurity #MachineLearningSecurity #LLMSecurity #AdversarialML #AIResearch #AIConference #SecurityResearch #RealWorldAISecurity

2
8
72
9,420
ืœื ื ืฉื›ื— ืืช ื”ืฉื‘ืขื” ื‘ืื•ืงื˜ื•ื‘ืจ, ื•ื ืžืฉื™ืš ืœืจื“ื•ืฃ ืื—ืจื™ ืื•ื™ื‘ื™ ื™ืฉืจืืœ - ืžืื“ืจื™ื›ืœื™ ื”ืžืชืงืคื”, ื•ืขื“ ื”ืžื—ื‘ืœื™ื ืฉืœืงื—ื• ื—ืœืง ื‘ื˜ื‘ื—.
ื”ืฆื™ื•ื ื™ื ื”ืขืจื™ืฆื™ื: ืชื‘ื•ืกืช ื™ื•ื ื”ืฉื‘ืช 7 ื‘ืื•ืงื˜ื•ื‘ืจ ืื™ ืืคืฉืจ ืœื”ืชืจื•ืžื ืžืžื ื”, ื”ื‘ืืชื ืืช ื”ืคื•ืจืขื ื•ืช ื”ื–ืืช ืœืขืฆืžื›ื
88
217
3,401
291,565
This happens today!
Black Hat Webcast ๐Ÿšจ The Promptware Kill Chain: From Prompt Injection to Multiโ€‘Step LLM Malware ๐Ÿ—“ Feb 26, 2026 โ€ข 2โ€“3 PM ET. Join Ben Nassi as he breaks down how promptโ€‘injection attacks have evolved into a powerful fiveโ€‘stage LLM malware kill chain. Donโ€™t miss this fast, insightsโ€‘packed session today. Register ๐Ÿ‘‰ blackhat.com/html/webcast/02โ€ฆ
2
155
8en N@$$! retweeted
Black Hat Webcast ๐Ÿšจ The Promptware Kill Chain: From Prompt Injection to Multiโ€‘Step LLM Malware ๐Ÿ—“ Feb 26, 2026 โ€ข 2โ€“3 PM ET. Join Ben Nassi as he breaks down how promptโ€‘injection attacks have evolved into a powerful fiveโ€‘stage LLM malware kill chain. Donโ€™t miss this fast, insightsโ€‘packed session today. Register ๐Ÿ‘‰ blackhat.com/html/webcast/02โ€ฆ

1
12
2,641
On ๐—ง๐—ต๐˜‚๐—ฟ๐˜€๐—ฑ๐—ฎ๐˜†, ๐—™๐—ฒ๐—ฏ๐—ฟ๐˜‚๐—ฎ๐—ฟ๐˜† ๐Ÿฎ๐Ÿฒ๐˜๐—ต, ๐—ฎ๐˜ ๐Ÿญ๐Ÿฐ:๐Ÿฌ๐Ÿฌ ๐—˜๐—ฎ๐˜€๐˜๐—ฒ๐—ฟ๐—ป ๐—ง๐—ถ๐—บ๐—ฒ, I will present a @BlackHatEvents ๐˜„๐—ฒ๐—ฏ๐—ถ๐—ป๐—ฎ๐—ฟ titled โ€œ๐—ง๐—ต๐—ฒ ๐—ฃ๐—ฟ๐—ผ๐—บ๐—ฝ๐˜๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—ž๐—ถ๐—น๐—น ๐—–๐—ต๐—ฎ๐—ถ๐—ป: From Prompt Injection to Multi-Step LLM Malware.โ€ The talk is based on joint work with Oleg Brodt, Elad Feldman, and Bruce Schneier. Registration link: webinar.connectmeinforma.comโ€ฆ #blackhat #infosec #webinar #prompt_injection #promptware
2
9
3,017
On ๐—ง๐—ต๐˜‚๐—ฟ๐˜€๐—ฑ๐—ฎ๐˜†, ๐—™๐—ฒ๐—ฏ๐—ฟ๐˜‚๐—ฎ๐—ฟ๐˜† ๐Ÿฎ๐Ÿฒ๐˜๐—ต, ๐—ฎ๐˜ ๐Ÿญ๐Ÿฐ:๐Ÿฌ๐Ÿฌ ๐—˜๐—ฎ๐˜€๐˜๐—ฒ๐—ฟ๐—ป ๐—ง๐—ถ๐—บ๐—ฒ, I will present a ๐˜„๐—ฒ๐—ฏ๐—ถ๐—ป๐—ฎ๐—ฟ titled โ€œ๐—ง๐—ต๐—ฒ ๐—ฃ๐—ฟ๐—ผ๐—บ๐—ฝ๐˜๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—ž๐—ถ๐—น๐—น ๐—–๐—ต๐—ฎ๐—ถ๐—ป: From Prompt Injection to Multi-Step LLM Malware.โ€ The talk is based on joint work with Oleg Brodt, Elad Feldman, and Bruce Schneier. Registration link: webinar.connectmeinforma.comโ€ฆ ๐—”๐—ฏ๐˜€๐˜๐—ฟ๐—ฎ๐—ฐ๐˜: The Promptware Kill Chain: From Prompt Injection to Multi-Step LLM Malware, explores the evolution of prompt injection attacks into a sophisticated seven-stage kill chain: initial access, privilege escalation, reconnaissance, persistence, command & control, lateral movement, and actions on objectives. It introduces the concept of Promptware and provides an in-depth analysis of each stage, highlighting advancements in the field over the last three years. #blackhat #infosec #webinar #prompt_injection #promptware
3
353
While not the first demonstration, this is one of a few known incidents that targeted a system's long-term memory for ๐—ฝ๐—ฒ๐—ฟ๐˜€๐—ถ๐˜€๐˜๐—ฒ๐—ป๐—ฐ๐—ฒ using prompt injection, turning systems into trojans to affect recommendations. microsoft.com/en-us/securityโ€ฆ #promptware #trojans #persistence #infsec #LLM #persistence
1
3
160
8en N@$$! retweeted
Academics nerds published a research paper a few days about LLM malware and their argument for a new classification of malware dubbed "Promptware". X fucks up links a lot, they don't display properly, so the link to their academic paper will be in the post subsequent to this one. As is tradition, their academic paper is just a bunch of goobers being all philosophical about shit and including a bunch of fancy pictures and graphs. I unironically sat here and read most of this paper. Is there argument valid? Yes, but some of the examples provided are theoretical and have not existed in-the-wild (yet?). They do however provide real-life examples of LLM payloads which have been successful. I personally have not seen these techniques described, but they provided citations and they are indeed real. I do malware stuff everyday (collecting, reverse engineering, development) and I have not seen any of the papers they reference. This paper has demonstrated, unironically, there is a gap right now between LLM research and malware research. In essence, we are at the point now where LLM research is now bleeding into malware research and malware nerds may have to pay more attention. I am now a believer. LLM malware is indeed real and will become a thing. I give these academic nerds two (2) cat pictures for this interesting paper. This is the first academic paper I've read in awhile that I actually think isn't complete dog shit. My main criticism however is they kind of butcher some malware terminology. For example, they incorrectly refer to some of this LLM malware stuff as Polymorphic, but this is not polymorphic ... unless we get really, really, really flexible with definition of polymorphic malware and we make it more akin to high-level class inheritance polymorphism. It doesn't really matter that much though because I understand what they're trying to convey.
17
32
432
21,484
8en N@$$! retweeted
Feb 13
Attacks on LLM-based systems have evolved into a distinct class of malware execution mechanisms. Bruce Schneier, @BrodtOleg, Elad Feldman, and @ben_nassi propose a โ€œpromptware kill chainโ€ to provide policymakers with a framework to address the escalating AI threat landscape.
1
3
3
1,870
๐Ÿš€ ๐—ง๐—ต๐—ฒ ๐—ฅ๐—ฒ๐—ฎ๐—น ๐—ช๐—ผ๐—ฟ๐—น๐—ฑ ๐—”๐—œ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—–๐—ผ๐—ป๐—ณ๐—ฒ๐—ฟ๐—ฒ๐—ป๐—ฐ๐—ฒ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ ๐Ÿš€ We are excited to announce the first 3 day ๐—ฅ๐—ฒ๐—ฎ๐—น ๐—ช๐—ผ๐—ฟ๐—น๐—ฑ ๐—”๐—œ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—–๐—ผ๐—ป๐—ณ๐—ฒ๐—ฟ๐—ฒ๐—ป๐—ฐ๐—ฒ, taking place on ๐—๐˜‚๐—ป๐—ฒ ๐Ÿฎ๐Ÿฏโ€“๐Ÿฎ๐Ÿฑ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ, at ๐—ฆ๐˜๐—ฎ๐—ป๐—ณ๐—ผ๐—ฟ๐—ฑ ๐—จ๐—ป๐—ถ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ถ๐˜๐˜†. The conference is intended to brief the most impactful AI security work presented over the past year at ๐—น๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด ๐—ถ๐—ป๐—ฑ๐˜‚๐˜€๐˜๐—ฟ๐˜† ๐—ฐ๐—ผ๐—ป๐—ณ๐—ฒ๐—ฟ๐—ฒ๐—ป๐—ฐ๐—ฒ๐˜€ (Black Hat, DEF CON, RSAC, CCC) and ๐˜๐—ผ๐—ฝ ๐—ฎ๐—ฐ๐—ฎ๐—ฑ๐—ฒ๐—บ๐—ถ๐—ฐ ๐˜ƒ๐—ฒ๐—ป๐˜‚๐—ฒ๐˜€ (CCS, IEEE S&P, USENIX Security, NDSS). ๐—ง๐—ต๐—ถ๐˜€ ๐—ถ๐˜€ ๐—ฎ ๐—ป๐—ผ๐—ป-๐—ฝ๐—ฟ๐—ผ๐—ณ๐—ถ๐˜, ๐—ฐ๐—ผ๐—บ๐—บ๐˜‚๐—ป๐—ถ๐˜๐˜†-๐—ฑ๐—ฟ๐—ถ๐˜ƒ๐—ฒ๐—ป ๐—ฐ๐—ผ๐—ป๐—ณ๐—ฒ๐—ฟ๐—ฒ๐—ป๐—ฐ๐—ฒ focused exclusively on technical AI security talks with real-world impact on deployed AI systems. The goal is to curate a concise agenda that distills the most important advances in AI security from the past year, while bringing together ๐—ถ๐—ป๐—ฑ๐˜‚๐˜€๐˜๐—ฟ๐˜† ๐—ฝ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐˜๐—ถ๐—ผ๐—ป๐—ฒ๐—ฟ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฎ๐—ฐ๐—ฎ๐—ฑ๐—ฒ๐—บ๐—ถ๐—ฐ ๐—ฟ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—ฒ๐—ฟ๐˜€ to establish new connections, collaborations, and future research directions. We will share additional details soon. Here is the link to the website of the conference: seclab.stanford.edu/RealWorlโ€ฆ #security #ai #llm #ai_security #cybersecurity #infosec
1
12
29
2,166
8en N@$$! retweeted
โ€œPrompt injectionโ€ is a misleading label. What weโ€™re seeing in real LLM systems looks a lot more like malware campaigns than single-shot exploits. This paper argues LLM attacks are a new malware class, Promptware, and maps them to a familiar 5-stage kill chain: โ€ข Initial access (prompt injection) โ€ข Priv esc (jailbreaks) โ€ข Persistence (memory / RAG poisoning) โ€ข Lateral movement (cross-agent / cross-user spread) โ€ข Actions on objective (exfil, fraud, execution) If youโ€™ve ever thought: โ€œwhy does this feel like 90s/2000s malware all over again?", thatโ€™s the point. Read the paper โฌ‡๏ธ arxiv.org/html/2601.09625v1

1
5
12
938
8en N@$$! retweeted
How Prompt Injections Gradually Evolved Into a Multi-Step Malware - arxiv.org/pdf/2601.09625 In this paper, we propose that attacks targeting LLM-based applications constitute a distinct class of malware, which we term promptware, and introduce a five-step kill chain model for analyzing these threats. The framework comprises Initial Access (prompt injection), Privilege Escalation (jailbreaking), Persistence (memory and retrieval poisoning), Lateral Movement (cross-system and crossuser propagation), and Actions on Objective (ranging from data exfiltration to unauthorized transactions). By mapping recent attacks to this structure, we demonstrate that LLM-related attacks follow systematic sequences analogous to traditional malware campaigns. The promptware kill chain offers security practitioners a structured methodology for threat modeling and provides a common vocabulary for researchers across AI safety and cybersecurity to address a rapidly evolving threat landscape. @ben_nassi, @schneierblog, @BrodtOleg - @TelAvivUni, @Kennedy_School, @Harvard, @munkschool, @UofTNews, @bengurionu #LLMSecurity #PromptInjection #Promptware #AIAttacks #KillChain #Cybersecurity #Jailbreak #AgentSecurity #ThreatModeling #AdversarialAI #MalwareAnalysis #RAGSecurity
1
7
28
1,651
8en N@$$! retweeted
1/3 The Promptware Kill Chain: In a new paper co-authored with Ben Nassi @ben_nassi and Bruce Schneier @schneierblog , we analyze how prompt injections gradually evolved into a multi-step malware that consists of 5 steps: Link to the paper: arxiv.org/abs/2601.09625
1
1
1
135
8en N@$$! retweeted
Had a fantastic time presenting at the second AI Agent Security Summit! This time in SF. Great talks, great people, and great conversations. Big thanks to @zenitysec for hosting an awesome event! ๐Ÿ”ฅ And thx @mbrg0 for taking this picture.
1
8
33
2,355
8en N@$$! retweeted
8 Oct 2025
Ben shares the progression of ai security vulnerabilities discoveries back in march 2024, we only knew about weak persistence mechanisms
1
1
3
288