<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-08-03T03:40:49&#43;02:00</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by David J. Bianco (He/Him)</title>
  <author>
    <name>David J. Bianco (He/Him)</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub157vpu8dunkj3athnxxjs88xsu8mgffhtz5c8dzd4kml6lmznl8ks4vheax.rss" />
  <link href="https://nostr.ae/npub157vpu8dunkj3athnxxjs88xsu8mgffhtz5c8dzd4kml6lmznl8ks4vheax" />
  <id>https://nostr.ae/npub157vpu8dunkj3athnxxjs88xsu8mgffhtz5c8dzd4kml6lmznl8ks4vheax</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/285/858/639/578/273/original/90b1a10aacdd1118.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/285/858/639/578/273/original/90b1a10aacdd1118.jpg</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsyyuvwn3jepsrnd67jqd873e3lm7w8040zcwrpsprlygz97fqvp6gzyznes8sahjw6284w7vc62quu6rsldp9xav2nqa5fkkm0ltlv20u76vgs7d4</id>
    
      <title type="html">HuggingFace got hacked by an agentic system. That&amp;#39;s not the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyyuvwn3jepsrnd67jqd873e3lm7w8040zcwrpsprlygz97fqvp6gzyznes8sahjw6284w7vc62quu6rsldp9xav2nqa5fkkm0ltlv20u76vgs7d4" />
    <content type="html">
      HuggingFace got hacked by an agentic system. That&amp;#39;s not the important part. What really stuck out to me was the asymmetry in #AI guardrails they experienced. The attacker had basically no constraints, but HF&amp;#39;s initial response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local-only models. In the middle of an incident. &lt;br/&gt;&lt;br/&gt;Another aspect for your IR plans.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://huggingface.co/blog/security-incident-july-2026&#34;&gt;https://huggingface.co/blog/security-incident-july-2026&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/937/087/730/249/171/original/f0a57f05fe593540.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-07-17T21:59:16&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfjmp70rzl7ceffnq60xx07rj3upk9nw6ejrp978zl2c8v6vnp3cczyznes8sahjw6284w7vc62quu6rsldp9xav2nqa5fkkm0ltlv20u765h88un</id>
    
      <title type="html">For years, I&amp;#39;ve been very clear: &amp;#34;You can&amp;#39;t automate ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfjmp70rzl7ceffnq60xx07rj3upk9nw6ejrp978zl2c8v6vnp3cczyznes8sahjw6284w7vc62quu6rsldp9xav2nqa5fkkm0ltlv20u765h88un" />
    <content type="html">
      For years, I&amp;#39;ve been very clear: &amp;#34;You can&amp;#39;t automate threat hunting. It is an essentially human process.&amp;#34; Now I&amp;#39;m not so sure. &lt;br/&gt;&lt;br/&gt;Read why I&amp;#39;ve reconsidered my stance in my fresh new post: &amp;#34;The Hunter&amp;#39;s Paradox: Is it time to embrace automated threat hunting?&amp;#34;&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://blog.talosintelligence.com/the-hunters-paradox-is-it-time-to-embrace-automated-threat-hunting/&#34;&gt;https://blog.talosintelligence.com/the-hunters-paradox-is-it-time-to-embrace-automated-threat-hunting/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/930/275/263/014/075/original/19b56fafc373df09.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-07-16T17:06:46&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8jqf25lm3mm4973lk4alwk6gfnh95gv4hgtp80qnx4tccjsvmrvgzyznes8sahjw6284w7vc62quu6rsldp9xav2nqa5fkkm0ltlv20u76tcw06x</id>
    
      <title type="html">If you think you have a &amp;#34;supply chain&amp;#34;, you&amp;#39;re wrong. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8jqf25lm3mm4973lk4alwk6gfnh95gv4hgtp80qnx4tccjsvmrvgzyznes8sahjw6284w7vc62quu6rsldp9xav2nqa5fkkm0ltlv20u76tcw06x" />
    <content type="html">
      If you think you have a &amp;#34;supply chain&amp;#34;, you&amp;#39;re wrong. What you actually have is a &amp;#34;supply web&amp;#34;.&lt;br/&gt;&lt;br/&gt;Changing your mental model can help you gauge supply web risks more accurately.
    </content>
    <updated>2026-05-29T21:53:10&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfeh5eeltwcx8xm5r5uydjgcvzu9fn77mnya3jkf05knr4zw6e6tczyznes8sahjw6284w7vc62quu6rsldp9xav2nqa5fkkm0ltlv20u76yk5qmg</id>
    
      <title type="html">If AI driven attacks become more prevalent, it&amp;#39;ll only be a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfeh5eeltwcx8xm5r5uydjgcvzu9fn77mnya3jkf05knr4zw6e6tczyznes8sahjw6284w7vc62quu6rsldp9xav2nqa5fkkm0ltlv20u76yk5qmg" />
    <content type="html">
      If AI driven attacks become more prevalent, it&amp;#39;ll only be a matter of time before attackers push the token burden on to their victims, using the AI that&amp;#39;s already (probably) there. &lt;br/&gt;&lt;br/&gt;I&amp;#39;m calling it &amp;#34;living off the lAInd&amp;#34;.*&lt;br/&gt;&lt;br/&gt;*Jokey name. Probably will happen, though.
    </content>
    <updated>2026-05-20T22:55:47&#43;02:00</updated>
  </entry>

</feed>