CTO @AdaptiveSec | building the future of security | former ski racer | Brooklyn, NY

Joined August 2010
11 Photos and videos
Pinned Tweet
Shadow IT and specifically Shadow AI pose such a risk to companies and their employees. The world is moving fast and we all want the newest tools. We're working on products that help prevent this @AdaptiveSec Kudos to the @vercel team on the communication on this incident today
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/verce…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
12
1,354
Back to Codex 😅
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
2
64
Wild times... its abilities to perform social engineering are certainly more effective than other SOTA models. The controls seem to be in a good place for most prompts but some of the jailbreaks out there are very creative and hard to safeguard against
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
32
This is a great post and underscores how important low latency, AI-first email security tooling is. AI-driven phishing is skyrocketing and at the same time there are now even more actors in your inboxes between humans and agents
AI assistants now read and action our emails for us. Useful, and it changes the question we ask: not "did it arrive?" but "can we trust where it came from?" That is what SPF, DKIM and DMARC are for. fastmail.com/blog/the-future… #NationalEmailWeek #Fastmail
1
1
2
77
This is funny but the number of companies who “went all in on AI” and are now feeling the pain of large surprise bills is a huge trend. I think we’re going to see a lot of people pull back and set firm budgets this summer
3
141
Mike Remondi retweeted
Adaptive’s global expansion continues. Today we’re opening our first APAC office in Sydney, Australia, a region where we already protect hundreds of customers from AI-powered attacks.
1
1
3
164
Coding is dead. It's simply not a scarce skill anymore. Interns, designers, and PMs can all do it, and an agent will happily write it at 2am while you sleep. That said, I think we're entering the golden age of software engineering.
1
6
131
Orgs that treat agent code as free money will drown in tech debt. Orgs that treat it as a high-powered tool requiring disciplined infrastructure will build things that weren't possible before.
1
4
55
Codex and Claude desktop apps will become a very important way of offloading compute to the user's device in the future. I'd bet that they start shipping with small local models embedded in them that try to execute the task first before sending to their larger models
3
70
Mike Remondi retweeted
Most phishing simulations stop at email, but smishing click rates run 5 to 10 times higher than email phishing, and voice phishing failure rates can hit 20%.
1
1
3
104
I’ve seen security leaders lose hours every quarter to a reporting ritual that hasn't changed. Export the data, grab screenshots, build a deck, write the narrative from scratch, and then finally share it with leadership. @AdaptiveSec finally built something that changes that!
1
3
98
We also built three starter templates so teams can get going right away. An SAT Program Overview, Leadership Update, and CISO Review. You can use any of them as a starting point, customize to your needs, or build a board completely from scratch.
1
68
Executive Report Boards are live today for all Adaptive customers and you can find them in your reporting navigation. We look forward to your feedback as we continue to build!
26