Joined April 2026
Photos and videos
Missa retweeted
Career update: Iโ€™ve joined @OpenAI to lead Cyber with @michaelaiello. Why I joined, and what weโ€™ll be building: Itโ€™s clear that AI is fundamentally changing how software is being written and secured. Coding agents are writing the majority of code for many developers, software is getting shipped more quickly, and vulnerabilities that were latent for 20 years are being discovered at a rapid pace. The time to bug discovery, and exploitation once discovered, are trending down (H/T @EppSecurity and @gadievron). I believe we have an unparalleled opportunity to fundamentally ๐˜ช๐˜ฎ๐˜ฑ๐˜ณ๐˜ฐ๐˜ท๐˜ฆ cybersecurity in ways that were previously impossible. (H/T @bubblewireโ€™ BSidesSF keynote on reasons for optimism) Over 6 years at @Semgrep, I had the privilege of working with an amazing team building what has become the most popular open source security code scanning tool in the world, that many companies have built their application security program around. Now, at @OpenAI, Iโ€™m thrilled to be a part of a company helping shape how software is written, and how security work gets done. It is a massive opportunity, and responsibility, and I donโ€™t take that lightly. Here are my current thoughts about where things are headed: ๐‘๐ž๐ฌ๐ข๐ฅ๐ข๐ž๐ง๐ญ ๐›๐ฒ ๐๐ž๐ฌ๐ข๐ ๐ง. Defenders are not going to win playing bug whack-a-mole. We need to systematically eliminate classes of vulnerabilities, via generating secure code and streamlining the detect โ†’ validate โ†’ fix process. ๐€๐ฎ๐ ๐ฆ๐ž๐ง๐ญ ๐š๐ง๐ ๐ž๐ฆ๐ฉ๐จ๐ฐ๐ž๐ซ ๐ฉ๐ž๐จ๐ฉ๐ฅ๐ž. We should build models and tools that give defenders โ€œsuperpowers,โ€ enabling them to be more ambitious in the scope they tackle, shift from being reactive to proactive, and allow them to automate the drudgery so they can focus on the highest leverage work. ๐’๐ž๐œ๐ฎ๐ซ๐ž ๐ญ๐ก๐ž ๐œ๐จ๐ฆ๐ฆ๐จ๐ง๐ฌ. The world runs on open source software. OpenAI has already spent $Ms finding and patching vulnerabilities in the most popular and widely run software, including browsers, operating systems, and core libraries. More on this soon. Weโ€™re also working on helping secure critical infrastructure. ๐‚๐จ๐ฆ๐ฆ๐ฎ๐ง๐ข๐ญ๐ฒ ๐š๐ง๐ ๐ฉ๐š๐ซ๐ญ๐ง๐ž๐ซ๐ฌ. Securing the world is a community effort. Iโ€™m looking forward to partnering with cybersecurity vendors, researchers, practitioners, governments, and more to do together what we canโ€™t do alone. ๐“๐ข๐ฆ๐ž ๐ญ๐จ ๐›๐ฎ๐ข๐ฅ๐.ย Tactically, here are some domains Iโ€™m excited about: - Finding, validating, and reliably patching software vulnerabilities at scale. - Eliminating classes of vulnerabilities and making software resilient by design. - Giving broad access to the best cyber models to empower defenders, not just to a select few. - Creating and sharing Skills and playbooks that help in many security domains. - Building platforms that enable defenders to easily orchestrate security work. - Making enterprise agents safe and reliable. Time to build ๐Ÿ˜Ž โ€” What would help you most? What should we build? Let me know.
103
49
1,026
320,991
Missa retweeted
Early anthropic employees commuting to work post IPO
151
1,314
35,860
1,037,244
๐Ÿ›ฉ๏ธ This is so cool: A Redditor living under SFO's takeoff path built a ceiling projection that maps every plane flying over their house in real time, using ADS-B, the open radio signal aircraft broadcast on 1090 MHz. Same feed as FlightRadar24, picked up with a cheap SDR dongle and beamed onto the ceiling.
77
660
8,243
1,611,307
Missa retweeted
Holding cybersecurity vendors accountable for their claims is a critical part of improving security. I'm not a troll. I'm not lying. And I'm not harassing you. But since that's your response: Here we go again.
49
45
334
26,760
Missa retweeted
Launching oauthsentry.github.io Look up any OAuth app ID and find out what it actually is across thousands of legitimate, risky, and malicious apps (Entra, Google, GitHub). Multiple feeds, API, detection ideas and remediation guidance. Still improving the detections a bit ๐Ÿฆพ
3
42
187
22,825
Missa retweeted
"I remind you that this present you're so concerned about losing, you hated it in the first place." @juanandres_gs on why security practitioners should stop clinging to the broken thing and start imagining what the fixed thing looks like. New episode is live ๐Ÿ‘‡ open.spotify.com/episode/7K6โ€ฆ
3
16
36
7,324