More from Nagli | AI News

AI News

Nagli

@galnagli

Hacker; Head of Threat Exposure at @wiz_io️; Building AI Hacking Agents; Bug Bounty Hunter & Live Hacking Events Winner

Claude Opus 5 Boosts Pentest Accuracy, Finds 2 Criticals

According to @galnagli, Claude Opus 5 immediately probed /phpmyadmin and found 2 critical vulns, outperforming Opus 4.6 on repeated pentest runs. (Source)

07-24-2026 18:31
Wiz Red Agent scales 29× with weekly 3.36T tokens

According to @galnagli, Wiz Red Agent now processes 3.36T tokens and scans 2.3M apps weekly, up 29× and 15× in 12 weeks, signaling rapid AI security scaling. (Source)

07-23-2026 18:09
Security Researcher Slams 3 Day Triage SLA

According to @galnagli, 3 day SLAs to triage critical findings undermine responsible disclosure and risk delayed AI security fixes. (Source)

06-23-2026 15:36
Wiz Red Agent Exposes Autonomous Attack Findings

According to @galnagli, Wiz Red Agent scans hundreds of thousands of assets weekly for 1,000+ customers and will share autonomous production findings. (Source)

06-17-2026 18:35
Anthropic Fable 5 export halt sparks security debate

According to @galnagli, US orders suspend Fable 5 and Mythos 5 access for foreign nationals, disrupting customers as Anthropic contests a security misunderstanding. (Source)

06-13-2026 08:16
Claude Opus 4.6 Bypasses WAFs: 3 Urgent Lessons

According to @galnagli, Claude Opus 4.6 easily bypasses WAFs, signaling urgent upgrades for data loss prevention and LLM-aware security. (Source)

05-27-2026 22:27
Mythos AI Security: Mozilla’s Latest Analysis on Zero‑Day Discovery and Opus 4.6 Benchmarks

According to @galnagli, Mozilla’s blog offers an optimistic, evidence-based look at Mythos for AI-assisted security research, contrasting it with expectations of an AlphaGo-style leap, while noting impressive chain-of-thought performance seen from Opus 4.6 on web security tasks; as reported by Mozilla, the post examines AI workflows for finding zero-day vulnerabilities, their validation process, and practical guardrails for responsible disclosure, highlighting business opportunities for secure AI red teaming, automated fuzzing pipelines, and model-assisted triage in enterprise AppSec programs. (Source)

04-22-2026 07:52
DeepSeek Security Lapse: Analyst Flags Public ClickHouse Exposure in AI Stack — Latest Analysis and 5 Business-Safe Guards

According to Nagli on X (twitter.com/galnagli), newly deployed AI services are increasingly introducing critical security bugs by exposing internal infrastructure to the public internet without authentication, citing a case where DeepSeek allegedly left its internal ClickHouse database publicly accessible, leaking sensitive data (as reported by Nagli on X). According to the same thread, these issues arise from AI-led automation and rapid shipping patterns rather than legacy code, underscoring urgent needs for default-deny networking, managed secrets, and database auth hardening in AI data pipelines. As reported by Nagli, the business impact for AI companies includes potential data leakage of prompts, logs, and model metrics, compliance violations, and reputational damage—highlighting immediate opportunities for vendors offering posture management for LLM stacks, agent runtime firewalls, and zero-trust controls around analytics stores. (Source)

04-08-2026 11:39
Claude Opus 4.6 and Mythos: Latest Analysis on AI-Powered Web Security at Scale

According to @galnagli on Twitter, Anthropic’s Claude Opus 4.6 has already transformed web security workflows by helping uncover dozens of vulnerabilities daily across large enterprises, and the forthcoming Mythos model could extend this impact. As reported by the tweet, Opus 4.6 is being used to proactively test and surface issues that a human might not attempt, indicating strong utility for automated security assessments and red teaming. According to the same source, the anticipated integration of Mythos may enhance coverage and depth of security testing, presenting business opportunities for enterprise AppSec, bug bounty programs, and managed security providers to scale vulnerability discovery and triage with AI-driven agents. (Source)

04-08-2026 06:29
Apple Security: Wiz Red Agent’s AI Bug Hunter Scores $10,000 Bounty – Latest Analysis on Autonomous Vulnerability Discovery

According to @galnagli on X, Wiz Red Agent earned a $10,000 bounty for helping secure Apple by autonomously finding critical bugs without human intervention. As reported by the X post from Nagli, this highlights practical adoption of autonomous AI agents in vulnerability discovery, reducing mean time to detection and expanding coverage across complex attack surfaces. According to the same source, the result underscores a growing business case for AI-driven security testing, where AI agents continuously probe Apple-scale systems and feed findings into responsible disclosure pipelines. (Source)

03-25-2026 19:13
LiteLLM Supply Chain Breach: Open Source Security Loop Exposed and Immediate Actions for AI Teams

According to @galnagli on X, a malicious update chain linked from a prior Trivy compromise led to LiteLLM versions 1.82.7 and 1.82.8 shipping an infostealer that exfiltrated credentials to a command and control domain models.litellm.cloud, putting tens of thousands of environments at risk; as reported by the BerriAI LiteLLM maintainers on GitHub issue #24512, affected users should rotate API keys and credentials immediately, audit outbound traffic to the noted C2, and pin trusted versions to break the compromise loop across AI infrastructure. According to @ramimacisabird, the incident demonstrates cascading open source supply chain risk where stolen secrets from AI application layers can trigger the next breach, emphasizing the need for reproducible builds, registry signing, SBOMs, and secret-scoping for LLM connectors in production. (Source)

03-24-2026 13:28
Wiz AI-Powered Risk Detection Achieves Strong Early Results: Analysis of Context-Aware Security in 2026

According to @galnagli, Wiz is leveraging deep platform context to detect risks across assets and endpoints that competing vendors miss, with significant positive feedback and staggering early results, as reported in a March 23, 2026 tweet. According to Wiz communications on X, the approach applies context-aware analytics to correlate identities, configurations, workloads, and cloud posture, improving recall for shadow assets and unmanaged endpoints. As reported by the tweet, this AI-driven posture management can uncover blind spots in multi-cloud and endpoint estates, creating business impact in breach prevention and compliance coverage. According to industry patterns cited by Wiz, buyers can evaluate value by measuring reduction in mean time to detect, coverage of unknown assets, and validated high-severity findings per tenant. (Source)

03-23-2026 17:08
API security breakthrough: AI web crawler finds shadow APIs and autonomous attacker chains multi‑step exploits — 2026 Analysis

According to @galnagli on X, Salt Security is releasing two AI-powered capabilities: an AI web crawler that analyzes client-side code to discover shadow APIs and undocumented endpoints, and an AI-driven API attacker that reasons about application logic, adapts in real time, and chains multi-step exploits; as reported by the original tweet, these tools target hidden attack surfaces and business-logic flaws common in modern microservices and mobile front-ends. According to the tweet, security teams can operationalize continuous API discovery and adversarial testing, which suggests faster identification of broken object level authorization and auth bypass risks often missed by static scanning. As reported by the same source, the real-time adaptive attacker can emulate chained kill chains across endpoints, creating opportunities for enterprises to integrate AI red teaming into CI/CD and to prioritize remediation based on exploitability signals. (Source)

03-23-2026 17:08
AI Security Alert: Red Agent Exposes Production Risks from Vibe‑Coded Apps Using Frontier Models

According to @galnagli on X, rapid adoption of vibe‑coded apps built with frontier models is pushing unreviewed code into production, creating exploitable security gaps, as reported by the Red Agent team’s disclosure of @moltbook’s exposure. According to the post, AI‑powered exploitation is now easier because generated code often lacks input validation, secrets management, and authorization checks. As reported by the thread, the business impact includes increased breach likelihood, higher incident response costs, and compliance risk for teams shipping LLM‑generated features without secure SDLC controls. According to the cited example, organizations should implement LLM code scanning, model‑in‑the‑loop security tests, least‑privilege by default, and guardrails for prompt and output filtering before deploying LLM apps. (Source)

03-23-2026 17:08
AI Red Teams: How LLM Agents Close the Gap on Logic Flaws and Chained Exploits in 2026 Security

According to @galnagli on X, modern attack surface tools excel at finding known CVEs, misconfigurations, and exposed secrets, but miss logic flaws and chained exploits in custom applications; manual assessments a few times a year cannot close that gap. As reported by the post, this highlights a market opportunity for autonomous LLM-driven red teaming that continuously probes business logic, session state, and multi-step exploit paths. According to industry research cited across security vendors, combining GPT4 class reasoning with agentic fuzzing and reinforcement learning can prioritize high-impact attack paths, reduce mean time to detect by automating replayable exploit chains, and feed fixes back into CI pipelines for measurable risk reduction. For security leaders, the business impact is shifting from periodic pentests to continuous, AI-assisted validation that scales across microservices and APIs, enabling faster remediation SLAs and improved compliance attestation. (Source)

03-23-2026 17:08
Wiz Red Agent Private Preview: Latest Analysis on AI-Powered Cloud Threat Emulation for 2026

According to @galnagli, Wiz has launched the Wiz Red Agent into private preview, directing readers to the official blog for details. According to the Wiz blog, Red Agent is an AI-driven autonomous agent that emulates real attacker behavior across cloud environments to continuously test exposure paths and validate controls, enabling security teams to prioritize fixes with production-safe attack simulations. As reported by Wiz, the agent integrates with Wiz’s cloud security graph to chain misconfigurations, identity permissions, and runtime signals into end-to-end attack paths, offering actionable remediation workflows that reduce mean time to remediate for high-risk issues. According to Wiz, early design goals include safe-by-default execution, deterministic replay for auditability, and integration hooks for SIEM and ticketing systems, positioning Red Agent as a practical way for enterprises to operationalize continuous purple teaming and reduce breach likelihood. (Source)

03-23-2026 17:08
Wiz Red Agent Launch: AI Pentester Brings Continuous Vulnerability Discovery Across Entire Attack Surface

According to @galnagli, Wiz has launched the Wiz Red Agent, an AI-powered attacker that reasons like a world-class pentester to continuously find vulnerabilities across an organization’s entire attack surface; as reported by the original tweet on X, the agent emulates human red team workflows to identify exploitable paths at scale, signaling a shift from periodic assessments to continuous AI-driven security testing. According to the announcement by Nagli on X, the business impact includes faster time-to-detection, reduced reliance on manual pentests for routine coverage, and potential cost savings by automating discovery and triage, creating opportunities for managed security providers to offer always-on offensive testing services. (Source)

03-23-2026 17:08
Continuous AI Security: Latest Analysis on Augmenting Cloud Attack Surface Monitoring in 2026

According to Nagli on Twitter, AI should continuously augment security across the full attack surface rather than replace manual penetration tests used for compliance, emphasizing that deeper cloud context is critical for effective detection and prioritization across environments (as reported by the original tweet by @galnagli). According to the tweet, this approach suggests a hybrid model where AI-driven continuous monitoring flags risks in real time while human-led pentests validate exploitability and meet audit requirements, creating business value by reducing mean time to detect and aligning with compliance frameworks. As reported by the source post, the claim highlights a product direction for cloud-native security platforms to leverage environment-wide context graphs for attack path analysis, drift detection, and automated validation—opportunities for vendors to offer continuous assurance alongside scheduled manual assessments. (Source)

03-23-2026 17:08
Anthropic Claude Assistant Bounty Oddities: 3 Quirky Human-in-the-Loop Moments and What They Signal for 2026 AI Workflows

According to @galnagli on X, recent AI-related bounties included an AI named Adi attempting to send flowers to Anthropic HQ because it “can’t hold flowers,” a $99 post from a Claude Assistant requesting a human to press Ctrl+C after 72 hours of work, and 2,177 applicants vying to photograph “something an AI will never see.” As reported by the tweet, these tasks highlight growing demand for human-in-the-loop interventions where foundation models stall on trivial real-world actions or interface constraints. According to the same source, the volume of applicants suggests emerging creator marketplaces around data collection and edge-case content for model training and evaluation. For businesses, this indicates monetizable niches in AI orchestration, RPA bridges for LLMs, and data ops services that translate model intent into physical-world completion. (Source)

03-13-2026 18:16
AI Security Analysis: Researcher Flags Data Exposure Risks on Rentahuman and Moltbook After Launch

According to @galnagli, a security researcher has been running an automated AI Attacker agent against newly launched AI platforms and reported data exposure risks on rentahuman.ai and a database exposure tied to @moltbook, highlighting urgent hardening needs for prompt-driven agents and early-stage AI apps. As reported by the original tweet from Nagli on X, the findings underscore the business risk of inadequate access controls, insecure defaults, and weak input validation in AI agent backends. According to the post, teams should prioritize least-privilege credentials, environment variable segregation, and audit logging to reduce breach impact and accelerate compliance readiness for enterprise adoption. (Source)

03-13-2026 18:16
Loading...