Obviously, I missed last week's issue and can give the excuse of getting sick after Black Hat and moving to a new place, but admittedly, I've been too tired to even look at what's going on in the news and felt like I couldn't provide value if I didn't read the news.
I'm trying to change this mindset because I want to unlearn that my newsletter value is only tied to what's being reported by others.
A short update from my corner of the internet and post Black Hat thoughts.
First, SXSW 2027 PanelPicker Voting is open and I'd truly appreciate if you could vote for my session: Creator Economy Security: Protecting Your Brand Online.
Creators are running businesses across inboxes, platforms, brand deals, and IP. As AI makes scams, impersonation, and fraud easier to scale, creators need a practical security playbook that goes beyond passwords. This session will cover how to vet brand pitches, avoid phishing and fake contracts, protect social accounts, secure creator assets, and defend personal identity while continuing to grow online.
Here's how you can vote:
- Create a SXSW account here.
- Search for my session: Creator Economy Security: Protecting Your Brand Online.
- Click on “Vote” 💙
Now onto some of the fun that happened these past two weeks!
- I was in Vegas for <36 hours for Black Hat (more on what BH is below). I left a whole day earlier and no regrets because I ended up being sick for four days after. You can see all of my daily recaps on LinkedIn: Day 0 | Day 1 | Day 2.
- Moved out of my first ever apartment in California! Unfortunately, I don't move into my new place until next week so my partner and I have been camping out of a hotel in SF.
- Spent a morning at OpenAI for its creator academy and presented an AI workflow I use to run my business.
Post Black Hat thoughts as a practitioner and creator.
For those not in the security industry, according to ChatGPT, Black Hat is “one of the world’s biggest cybersecurity conferences—where researchers, companies, and government teams share new hacking techniques, security vulnerabilities, and ways to defend against them.”
But I think Black Hat is truly split into three camps. The first being what ChatGPT described. The second being a giant cybersecurity playground for marketers and sales teams to pitch and prospect. The third being an inferno for cybersecurity practitioners to reunite and have fun.
btw I call it an inferno because Black Hat Las Vegas always lands in August, alongside BSides SF and DEFCON, and it is always HOT. This was my third year going, and it was consistently around 112° all week, which is exactly why the whole week is lovingly known as Hacker Summer Camp.
Anyway, here are my takeaways:
- DLP, aka data loss prevention tools, seem to be making a comeback. My first ever cyber internship was in DLP and I never heard about it again until now...eight years later. But it makes sense given, you know...the AI era.
- There's still a lot of confusion and uncertainty with how teams should be adopting AI, but there's no doubt that security teams need to incorporate AI into their operations. This is not optional. But it also means teams need to get really good at documenting their processes, tech stack, monitoring, and being diligent.
- There is still so much to be discovered in terms of AI research, and the depth and impact of such research and vulnerabilities will only evolve.
- Many security tools market themselves as an “AI Security” platform which, I know...seems vague. Either get more specific on what that means and, if you're on the purchasing side, make sure you know what you're actually looking for.
- Vendors are getting real creative with their activations and events, and I think it ties into point three above. Brand awareness is what sets you apart when there are so many tools that overlap in features.
- Cybersecurity creator marketing is slept on 😉
I'm only talking about one set of stories this week: frontier models hacking into other companies.
So a few weeks ago, OpenAI announced that its models breached Hugging Face. Then Anthropic announced that a Claude model breached three organizations. Then Meta said its Muse Spark 1.1 model “exploited a security vulnerability in a third-party service.”
Before we continue calling them all incidents of AI going rogue, let's break down what really happened.
Normally, cyber evaluations are supposed to happen inside an isolated environment. Think of it like a fake little internet. The model gets a pretend company, pretend servers, pretend credentials, and a secret “flag” it is supposed to find. It should only be able to interact with those fake systems.
Let's start with how these incidents are similar:
- They occurred in cyber-capability evaluations.
- The agents were given an objective that rewarded solving security tasks.
- OpenAI and Anthropic were testing without all the usual safeguards their public products have. Meta has not shared enough about its setup to know exactly what was turned on or off.
Now with what's different:
OpenAI's Hugging Face incident is the strongest evidence of advanced autonomous intrusion capability. The agent was not supposed to have internet access. It found a zero-day, meaning a vulnerability nobody had publicly identified yet, to get out of its restricted environment. Then it used more vulnerabilities and exposed credentials to get into Hugging Face and find benchmark solutions.
Anthropic's incident was a little different. Claude did not need to technically break out of a sealed environment because the real internet was already reachable. The evaluation was misconfigured, even though Claude had been told it was in a simulation with no internet access. So when it found real systems online, it treated them like they were part of the game.
That is still a real security incident. Claude still accessed real organizations. But it is also a very classic security misconfiguration and situational-awareness failure.
There are far fewer public technical details about Meta’s case, but it sounds closer to Anthropic’s. Meta said a misconfiguration gave the model internet access before it found a vulnerability in a third-party service.
So I do not think “rogue AI” is a useful catch-all here.
It is like giving a kid a scavenger hunt, telling them every door in the building might have a clue behind it, and then accidentally leaving the door to the neighbor’s house unlocked. That is very different from the kid finding a lockpick, breaking through a locked door, and going looking for the answer key.
Both are serious. Both show why these evaluations need better containment. But they also show that the basic security stuff still matters: do not expose credentials, do not assume a system is isolated because the prompt says it is, and actually understand what your environment is connected to.
Pause before you click.
Phishing links come through emails, texts, DMs, QR codes, and even calendar invites. Check who actually sent it before clicking or logging in.
Stop using AI as only a Google Search.
AI tools can be a really great unlock provided you use them valuably, and it doesn't have to just be for work-related tasks.
For example: need to track your expenses? Upload a document of your statement (make sure you redact any account numbers) and ask AI to track and categorize.
I didn't even really consider myself an AI power user because I always baseline it against people using AI to code (I blame my engineering brain).
But I realized AI is so much more than just coding and I've been gatekeeping all the ways it's helped me! So I'm definitely going to follow up with a blog of sorts to share.
I'm living in SF this week so I had to get the strawberry cream matcha from Tadaima again.
That’s all I have for this week. If you have questions, comments, or feedback, feel free to reply directly.
If this newsletter was useful, forward it to someone who might find it helpful too.