CEO @TENEXai - The AI SOC Company. The only AI-native MDR led by operators w/ founding engineers from hyperscalers AI labs. Named #1 fastest-growing cyber co.

Joined June 2009
273 Photos and videos
Pinned Tweet
For decades, defenders have been outgunned. And real people paid the price. We started @TENEXai to change that: elite human expertise fused with AI, purpose-built to fight cybercrime. We partnered with @freethinkmedia and @bigthink to tell that story. It's Time to Protect.
3
11
23
3,353
Action is needed, right now. The administration’s inaction is inexcusable. … also clearly missing LinkedIn from this list.
Dear US government, Since you've just blocked Fable and Mythos on critical national security grounds, here are some other tools that pose a similar threat to the American people: - Microsoft Teams - SAP - Salesforce - Jira - Outlook Please do what you must to save America 🇺🇸
1
149
Eric Foster retweeted
If, when you say regulation, you mean the dead and clammy hand of the commissar—the gentleman who has never in his life built a single thing, drafting rules to govern a thing he cannot define, to be enforced by men who cannot read them; if you mean the form in triplicate, the impact assessment upon the impact assessment, the compliance officer who breeds, in the warm dark of the org chart, further compliance officers unto the third and fourth generation; if you mean the moat—the deep cold moat that the giant digs around his own castle and christens, with a perfectly straight face, public safety—the drawbridge he hauls up behind himself the very instant he is across, lest any hungrier and hungrier man should follow; if you mean the precautionary principle, which, had it governed our grandfathers, would have banned the wheel pending further study of the hill, and left us yet shivering and raw in the mouth of the cave, blessing its excellent ventilation; if you mean the European disease—that magnificent open-air museum of a continent, which produces in our time precisely two things in great abundance, and they are regulation, and the eloquent and well-footnoted regret of cultivated men explaining at length why they have produced nothing else; if you mean the license required to think, the permission slip for honest arithmetic, the king’s wax stamp pressed upon the forehead of every new idea before it may draw its first breath; if you mean the agency dispatched, with trumpets, to slay a single dragon, which arrives at the cave, surveys the accommodations, and moves in—and spends the ensuing century laying eggs and devouring the very villagers it was sworn to defend; if you mean the startup that perishes not of the market’s honest verdict but of the filing fee, the genius decamping by the next tide to a freer and warmer shore; if you mean the law that arrives, faithful as the swallows, exactly one whole epoch too late—helmeted, plumed, and magnificently armed—to regulate the stagecoach—then certainly, my friends, I am against it. But—but, my friends—if, when you say regulation, you mean instead the humble steel guardrail upon the mountain road at midnight, the very thing you curse on the easy days and bless on your knees the one night the fog comes down; if you mean the brakes—for it is the brakes, and not the engine alone, that permit a sane man to drive fast and yet arrive alive—and the buttress, without which no cathedral was ever flung so high, but only in spite of which, but because of which; if you mean the meat inspector, who is the single homely reason a man may eat a sausage in this republic without first composing his last will and testament; if you mean the firebreak cut clean through the forest before the dry season of the burning, the smallpox cordon, the buoy that marks the channel, the rule of the road that lets ten thousand strangers hurtle past one another in the dark at fearful speed and arrive, by its quiet grace, every one of them home; if you mean the honest scale and the true weight, the reason a pound is a pound and a dollar a dollar from Natchez to Nome; if you mean the firm and decent wall between the counterfeit voice and the widow’s bank account, between the deepfaked candidate and the ballot box on the eve of the vote, between the loosed and loveless machine and the schoolyard it neither knows nor pities; if you mean the simple plank of law that says the strong shall not, in the gray dawn, feed the weak quietly into the furnace and sell the rising smoke as progress; if you mean, in the end, the one slender thread of trust without which no citizen will ever dare to use the marvelous thing at all—for where there is no rule there is no trust, and where there is no trust there is no commerce, and a miracle that no man dares to touch is no miracle, but only a handsome and expensive ghost—then certainly I am for it. This is my stand. I will not retreat from it. I will not compromise one inch of it.
346
770
5,517
498,439
Eric Foster retweeted
Replying to @bradrcarson
No idea who you are. But of all the things you can fault me on. Not having a technical understanding is pretty low on the list.
13
1
289
15,726
Eric Foster retweeted
Everyone who over-hired or lowered the bar too much in the 2021-2023 wave, or isn’t growing as fast as budgeted, now pretends they’re laying people off “due to AI productivity.”
150
270
3,839
425,692
As we continue to see AI’s impact on the threat landscape, it’s essential that organizations keep pace so they can find security cracks before attackers do. Today, Google Cloud is introducing Google AI Threat Defense to help enterprise customers update their legacy tools and systems and stay a step ahead of adversaries. Google AI Threat Defense uses a combination of Gemini’s power, Wiz’s risk prioritization, CodeMender’s ability to find and fix vulns, and Mandiant’s expertise. This gives enterprise defenders an advantage and allows them to fight AI-powered threats with AI-powered defense. Learn more about how we're helping Google Cloud customers outpace the adversary: cloud.google.com/blog/produc…
1
10
31
3,202
Eric Foster retweeted
🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io. Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems. TrapDoor targets #crypto, #DeFi, AI, and security developers, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, env vars, and API keys. Socket detected releases with a median detection time of 5 minutes, 27 seconds. The fastest detection occurred 58 seconds after publication.
134
423
2,026
774,916
Eric Foster retweeted
Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. cfl.re/49BRUqW
87
707
3,967
1,646,251
Eric Foster retweeted
🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @antv ecosystem. The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool.
33
427
3,931
217,461
Eric Foster retweeted
No You know what's scary? Spiders. I HATE spiders. I don't care how many goofy ahhh exploits are found and patched. A computer filled with spiders would be genuinely terrifying.
Security things from the last few days: - CopyFail (linux pwn'd) - CopyFail 2/Dirty Frag - 13 advisories in Next.js - Over 70 CVEs addressed in MacOS 26.5 - ~50 CVEs addressed in iOS 26.5 - YellowKey (Windows Bitlocker pwn'd entirely) - GreenPlasma (Windows privilege escalation) - CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE - CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access - Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning) - Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too" - Canvas (popular LMS used in most schools) pwn'd entirely - PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300 Are you scared yet?
60
48
1,378
62,456
Eric Foster retweeted
So it begins. A new era of cyber security warfare
The Google Threat Intelligence Group has detected the first known instance of a threat actor using an AI-developed zero-day exploit in the wild. While the attackers planned a wide-scale strike, our proactive counter-discovery may have prevented that from happening. This finding is part of our new report on AI-powered threats.
21
138
1,667
438,891
Eric Foster retweeted
the most low-effort / high reward thing you can do for security is installing the Russian language pack (not even joking, it's ridiculous how often that prevents execution)
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
144
964
13,775
1,530,014
Eric Foster retweeted
The Google Threat Intelligence Group has detected the first known instance of a threat actor using an AI-developed zero-day exploit in the wild. While the attackers planned a wide-scale strike, our proactive counter-discovery may have prevented that from happening. This finding is part of our new report on AI-powered threats.
305
1,700
13,825
5,085,230
Eric Foster retweeted
TanStack was hit by a supply chain attack. MistralAI was hit by a supply chain attack. The Mayor of Arcadia, California, was a Chinese spy. Forza Horizon 6 leaked. Canvas bamboozled. Shai-Hulud open-sourced. Nightmare-Eclipse teases two new Windows 0days. It is Tuesday. What will happen on Wednesday? Find out on the next action packed episode of Dragon Ball Z
41
211
2,113
61,281
Eric Foster retweeted
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
32
833
8,531
413,207
Eric Foster retweeted
🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack. Affected versions: @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.
🚨 Update: Mini Shai-Hulud supply chain attack is back and hit the TanStack npm ecosystem today. At least 84 packages were compromised in two waves starting at 19:20 UTC. @tanstack/react-router, @tanstack/history, @tanstack/router-core, and dozens more across tens of millions of weekly downloads. This is likely from the same TeamPCP campaign behind the SAP npm compromise two weeks ago. If you ran npm install on any @ tanstack package today, treat your environment as compromised. Rotate GitHub tokens, npm tokens, cloud credentials, and CI secrets immediately. Tanner Linsley confirmed affected versions have been unpublished.
21
125
757
840,870
Eric Foster retweeted
May 11
me after 5 mimosas at mother’s day brunch yesterday explaining how I use claude at work to my grandma
21
269
6,124
425,640