Joined June 2009
102 Photos and videos
One line from @AnthropicAI statement on the US government directive to suspend access to Fable 5 and Mythos 5 is interesting. "๐—ง๐—ต๐—ฒ๐˜€๐—ฒ ๐˜ƒ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—ฎ๐—น๐—น ๐—ฎ๐—ฝ๐—ฝ๐—ฒ๐—ฎ๐—ฟ ๐—ฟ๐—ฒ๐—น๐—ฎ๐˜๐—ถ๐˜ƒ๐—ฒ๐—น๐˜† ๐˜€๐—ถ๐—บ๐—ฝ๐—น๐—ฒ" You DON'T call vulnerabilities simple. You rank them as critical, high, medium, low. You can call an exploit as simple. The other one is the use of the word "appear". Security is fairly deterministic in classification of vulnerabilities once a qualified professional has done proper analysis so the choice of the word "appear" is interesting as well.
33
One thing I can't quite wrap my head around the @AnthropicAI Fable 5 / Mythos 5 shutdown. Most jailbreaks can typically be mitigated fairly quickly once the underlying technique or pattern is understood. This is standard practice across frontier AI labs. Researchers report a jailbreak, the lab analyzes the technique, implements a mitigation (even if temporary), and then works on a more robust fix. Most major AI companies have dedicated teams, tooling, and well-established processes for handling exactly this type of issue. So when @awscloud researchers surfaced a jailbreak, the obvious question is: why not patch it, even as a temporary, defense-in-depth, compensating control kind of fix, and move on, while a longer-term solution was being developed? And if the issue was serious enough that AWS leadership ultimately felt compelled to raise concerns with the U.S. Federal Government, what happened before that point? From the outside, it appears less like a technical challenge and more like a breakdown in vulnerability disclosure and remediation coordination. Both sides disagree on whether there was anything to patch. Anthropic says the technique surfaced previously known, minor issues, was reproducible on other public models, and did not point to a flaw in Fable 5's safety systems. In cybersecurity, the expectation is usually that researchers and vendors work together to understand the issue, validate the findings, and deploy fixes before matters escalate. What makes this different from a normal disclosure is the escalation path. This did not run through coordinated disclosure. A major investor (@amazon is a major investor in Anthropic) reportedly took it directly to @USTreasury , and the model came down through export controls rather than a patch cycle. I'm curious whether others see this as primarily a technical issue, a process issue, a trust issue, or something else entirely. #AISecurity #AISafety #Anthropic #ClaudeAI #CyberSecurity #VulnerabilityDisclosure #AIGovernance #ResponsibleAI #ModelSecurity #TrustAndSafety #CISO #AIPolicy
43
๐Ÿš€ Calling all students: the @Microsoft Student Ambassador program is open, and the 2026 version is built differently. No application. No interview. No gatekeeping. If you're a curious student in any discipline, you sign up, onboard, and start building. This is a global community of students who learn, lead, and grow together across AI, Cloud, Development, Cybersecurity, Data Science, and beyond. You don't need a coding background to start. You just need to be eager to learn and willing to help others do the same. What you get as you progress through Alpha, Beta, and Gold milestones: ๐Ÿค– Microsoft 365 Copilot access โ˜๏ธ $150/month in Azure credits ๐Ÿ’ป Visual Studio Enterprise ๐Ÿ“š LinkedIn Learning and certification vouchers ๐ŸŽ Exclusive Ambassador swag ๐ŸŒ A global network and real leadership experience ๐Ÿ… A pathway toward Microsoft MVP If you want to turn potential into proof and build a track record that speaks for itself, this is one of the best free programs out there for students. ๐Ÿ”— Get started: mvp.microsoft.com/studentambโ€ฆ Tag a student who should see this. ๐Ÿ‘‡ #MLSA #MicrosoftLearn #StudentAmbassador #AI #CloudComputing #Cybersecurity #DataScience #CareerGrowth #LearnBuildLead
1
26
The latest word on the street...the keyword here is "reportedly" Article link - thenextweb.com/news/amazon-jโ€ฆ I am doing a session on "Anthropic Claude Fable 5 & Claude Mythos 5 - A Real Primer For All" on Monday, June 15th 12 - 1 PM PDT which will have a lot of interesting tidbits like this. Don't miss it. Registration link - luma.com/tejas-e4j3
89
Most people assume that turning OFF training means their AI conversations aren't retained. That's not true. For consumer users of @AnthropicAI Claude (Free, Pro, and Max plans), conversations may still be retained for up to 30 days - even when you opt out of having your data used for model improvement. Let that sink in. Many users confuse: Model training, Data retention, Data deletion They are not the same thing. This is just one of many interesting facts I uncovered while researching the latest Anthropic Claude ecosystem. If you would like to know more, join us for this session: ๐ŸŽญ Anthropic Claude Fable 5 & Claude Mythos 5 โ€“ A Real Primer For All ๐Ÿ“… Monday, June 15, 2026 โฐ PM โ€“ PM PDT ๐Ÿ”— Registration link - luma.com/tejas-e4j3 #Anthropic #ClaudeAI #AISecurity #Privacy #CyberSecurity #GenAI #AIGovernance #CISO #ArtificialIntelligence #DataPrivacy
67
Happening now at 12 PM PST, June 12th 2026 Career Warm Up for Cyber Professionals No one's job is safe, it is better to warm up than be caught unawares. First 30 mins I will share some tips (my Top 9 mistakes) and next 30 mins we will be discussing as a group on what is working and what is not working and sharing best practices luma.com/tejas-31bs
5
Announcing the ๐—ง๐—ฒ๐—ท๐—ฎ๐˜€ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐—–๐—ฎ๐—บ๐—ฝ๐˜‚๐˜€ ๐—”๐—บ๐—ฏ๐—ฎ๐˜€๐˜€๐—ฎ๐—ฑ๐—ผ๐—ฟย Program ๐ŸŽ“โšก We are bringing cybersecurity learning, mentorship, and career opportunities directly to university campuses, and we are looking for student leaders to make it happen. As a Tejas Campus Ambassador, you will: ๐Ÿ”นRepresent Tejas at your university and host campus events ๐Ÿ”นGet direct mentorship from CISOs and security leaders ๐Ÿ”นReceive free General Membership ($150 value) plus early access to events and hackathons ๐Ÿ”นEarn a certificate, LinkedIn recommendation, and recognition across Tejas channels Open to BS/MS students in Cybersecurity, Computer Science, or related fields at US and international universities. We select a limited number of ambassadors per region each semester, and applications are reviewed on a rolling basis. ๐—”๐—ฝ๐—ฝ๐—น๐˜† ๐—ต๐—ฒ๐—ฟ๐—ฒ: docs.google.com/forms/d/e/1Fโ€ฆ If you are a professor, CISO, or security leader, tag a student who should see this. That one tag could launch a career. #Cybersecurity #CampusAmbassador #StudentLeadership #CyberCareers @tejascybernet #InfoSec
146
Just released - An ๐—”๐—œ ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜ ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ ๐—ฃ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐˜๐—ถ๐—ผ๐—ป๐—ฒ๐—ฟโ€™๐˜€ ๐—ฃ๐—น๐—ฎ๐˜†๐—ฏ๐—ผ๐—ผ๐—ธ from @Microsoft . This playbook is built from Microsoftโ€™s operational experience running AI incident response at scale. The primary use case here is @Microsoft365 Copilot and @Azure AI Servicesย but there are pointers on current state of AI investigation, covering the configuration, queries, and detection rules. For example there are queries like "Find agents with a configured MCP tool" or rules which alert on "AI agent ASCII smuggling detected". It is v1 so I am sure the future versions are only going to get better. microsoft.com/en-us/securityโ€ฆ @msftsecresponse @MicrosoftAI @msftsecurity @MSFTnews
1
2
34
Don't sleep on interesting AI work being done at Apple. They just launched the ๐—ง๐—ต๐—ถ๐—ฟ๐—ฑ ๐—š๐—ฒ๐—ป๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ผ๐—ณ ๐—”๐—ฝ๐—ฝ๐—น๐—ฒโ€™๐˜€ ๐—™๐—ผ๐˜‚๐—ป๐—ฑ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐— ๐—ผ๐—ฑ๐—ฒ๐—น๐˜€ machinelearning.apple.com/
18
Privacy from your own Smart TV: What you need to know about ACR. Most consumers are unaware that their Smart TVs come with a built-in tracking technology enabled by default. It is known as ๐—”๐˜‚๐˜๐—ผ๐—บ๐—ฎ๐˜๐—ถ๐—ฐ ๐—–๐—ผ๐—ป๐˜๐—ฒ๐—ป๐˜ ๐—ฅ๐—ฒ๐—ฐ๐—ผ๐—ด๐—ป๐—ถ๐˜๐—ถ๐—ผ๐—ป (๐—”๐—–๐—ฅ), and its scope is incredibly broad. How ACR works: ACR technology actively captures small snapshots of your screen or samples of your audio. This information is converted into a unique digital footprint and transmitted to the manufacturer's servers. There, it is matched against a comprehensive database of live broadcasts, streaming content, and advertisements. What it means for your data: This allows companies to build a highly accurate profile of your media consumption. They track: *๏ธโƒฃ Which apps you open *๏ธโƒฃ Exactly what content you watch *๏ธโƒฃ How much time you spend on specific channels or platforms *๏ธโƒฃ Perhaps the most concerning aspect is that ACR is input-agnostic. It does not matter if you are watching a native Smart TV app like Netflix, playing a local file from a USB drive, or gaming on a console like a PS5. If the pixels are on the screen, the TV is processing them. Data privacy starts in the living room. It's worth taking a few minutes to dive into your TV's settings and toggle ACR off. Note - Many times ACR is buried in setup under a friendly label like "Viewing Information Services."
105
One of the bigger highlights from @Microsoft Build 2026 for me is ๐— ๐—ซ๐—– or ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—˜๐˜…๐—ฒ๐—ฐ๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐—–๐—ผ๐—ป๐˜๐—ฎ๐—ถ๐—ป๐—ฒ๐—ฟ๐˜€ย which form the policy layer, defining and instrumenting isolation and containment for agents while relying on native Windows operating system constructs to apply these policies. OpenClaw, NVIDIA OpenShell, Hermes are all now leveraging MXC MXC is a sandboxed code execution system for running untrusted code (model output, plugins, tools) on Windows, Linux, and macOS. MXC also supports multiple containment backends: ProcessContainer, Windows Sandbox, LXC, Bubblewrap, Seatbelt (macOS), MicroVM (NanVix), Hyperlight, IsolationSession, and WSLC github.com/microsoft/mxc blogs.windows.com/windowsdevโ€ฆ
35
๐Ÿ›ก๏ธ Heading to Redmond next week for the @Microsoft Applied AI Safety & Security Summit! I'm genuinely excited to be attending this summit and to go deep on the innovation Microsoft is driving around AI safety and security. ๐Ÿค And before the summit, I'm hosting a Cyber Leaders Meetup with @tejascybernet on Monday, June 8th evening. If you're in the area, come connect with fellow security leaders and let's talk AI, security, and what's next. RSVP ๐Ÿ‘‰ luma.com/tejas-hu26 #AISafety #AISecurity #Cybersecurity #AgenticAI #Microsoft #Tejas #CISO #AIGovernance
1
2
52
7 New AI Models from @Microsoft *๏ธโƒฃ MAI-Thinking-1 *๏ธโƒฃ MAI-Code-1-Flash *๏ธโƒฃ MAI-Image-2.5 *๏ธโƒฃ MAI-Transcribe-1.5 *๏ธโƒฃ MAI-Voice-2 Read more about it here - microsoft.ai/news/building-aโ€ฆ @MicrosoftAI
1
15
686
Excited to share that I'll be speaking at an exclusive evening on the future of AI security. ๐Ÿ” What happens when cybersecurity leaders, AI innovators, and practitioners gather in one room? Emerging threats turn into actionable insights, conversations become partnerships, and challenges become opportunities to shape what's next. I'm honored to join a panel of industry leaders I deeply respect: ๐Ÿ‘ค Allison Johnson, Head of Customer & Executive Marketing at Okta, who leads global customer engagement and hosts Okta's Executive Exchange. ๐Ÿ‘ค Den Jones, Founder & CEO of 909Cyber, a Zero Trust pioneer with 35 years and former CSO roles at Banyan Security and SonicWall. ๐Ÿ‘ค Sangram Dash, CISO & VP of IT at Sisense, who has built bank-grade security programs across PayPal, Square, and SVB. Together we'll dig into securing intelligent systems and navigating the next generation of cyber risks. ๐Ÿ“ The Rooftop at Werqwise, San Francisco ๐Ÿ“… Wednesday, June 17, 2026 โฐ 5:30 PM to 7:00 PM Great wine. Meaningful conversations. The next era of AI security. Register here: paperlesspost.com/go/G4vqBbWโ€ฆ #AISecurity #Cybersecurity #CISO #AI
1
1
38
The job situation is going to get only worse. A few pointers 1. IRL "In Real LIfe" is the theme this year. Meet as many folks "in person" as possible. They key word here when you ask to meet people, is to take the uncertainty out on who is paying. Use words like - "lunch is on me", "my treat" 2. Do as many micro favors as you can. Don't sleep without having helped someone 3. Get visible, increase the surface area of your luck by attracting opportunities. 4. Share information - this is kind of a micro favor, as you are building implicit trust and establishing your bonafides as a well wisher 5. Upskill - Set 2-3 hours of daily study time with no distractions. We are knowledge workers and no amount of soft skills are going to save us unless we upskill to gain hard skills and adapt to a changing world.
25
Catch security issues as Claude writes code. Official plugin from @AnthropicAI github.com/anthropics/claudeโ€ฆ code.claude.com/docs/en/secuโ€ฆ

35
If you would like to disable @Google @GeminiApp from keeping a record of all your activities, this is the direct link to disable it. myactivity.google.com/producโ€ฆ If you would like to keep the setting on, I would recommend changing the default "Auto-delete activity older than" to 3 months from the default 18 months.
1
33
A top-tier @MIT of Technology security course just hit YouTube. Free. All 19 lectures. 6.566: Computer Systems Security (Spring 2026), Prof. Nickolai Zeldovich, at @MIT_CSAIL Course Details: โ†’ AI agent security (the CaMeL approach) โ†’ Supply chain security with Russ Cox โ†’ TLS 1.3, WebAuthn, Signal, Tor โ†’ 5 hands-on labs YouTube Playlist - youtube.com/playlist?list=PLโ€ฆ #CyberSecurity #AISecurity #CISO #AppSec
60
Most MCP servers in production right now have no authentication. Yours might be one of them. So I'm running a 90 minutes hands-on session to fix exactly that. ๐Ÿ”ง ๐—•๐˜‚๐—ถ๐—น๐—ฑ, ๐——๐—ฒ๐—ฝ๐—น๐—ผ๐˜† ๐—ฎ๐—ป๐—ฑ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป ๐—ฎ๐—ป ๐— ๐—–๐—ฃ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐—ณ๐—ฟ๐—ผ๐—บ ๐—ฆ๐—ฐ๐—ฟ๐—ฎ๐˜๐—ฐ๐—ต This is not another "hello world" tutorial. You will build a working MCP server, then attack it and harden it yourself. We go straight into the controls that matter in production: โ†’ Authentication and token handling โ†’ Least-privilege tool scoping โ†’ Prompt-injection and tool-poisoning defenses โ†’ Secrets management, network and container hardening โ†’ Audit logging and CI/CD security gates You leave with a hardened reference server, a working threat model, and a checklist you can apply to any MCP deployment Monday morning. Built for security engineers, AI/platform engineers, DevSecOps practitioners, and security-minded developers. Also valuable for CISOs and leaders who want a grounded technical view of what MCP changes about their trust model. ๐ŸŽŸ๏ธ ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐—ท๐—ผ๐—ถ๐—ป: โœ… Free for Tejas Cyber Network Executive Members and Tejas Global Cyber Founders. Not a member yet? Two ways in: โ–ช๏ธ For Practioners - Become a Tejas Cyber Network Executive Member: tejas-cyber-network.circle.sโ€ฆ Learn more: tejascybernetwork.com/ Membership benefits: docs.google.com/document/d/1โ€ฆ โ–ช๏ธ For Cyber Founders - Join the Tejas Global Cyber Founders Network: tejas-cyber-network.circle.sโ€ฆ Learn more: tejascybernetwork.notion.sitโ€ฆ Everyone else can grab a ticket directly. This one is paid, but worth every minute. ๐Ÿ’ฌ In transition or a student? Message me directly and I will send you a complimentary code. No one who wants to learn this gets left out. ๐Ÿ“… Register here: luma.com/tejas-505m #MCP #AISecurity #AgenticAI #Cybersecurity #DevSecOps #CISO #TejasCyberNetwork
2
124