@SentinelOnei
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
ONE autonomous platform to prevent, detect, respond, and hunt. Do more, save time, secure your enterprise: https://nitter.cf/t.co/N75g1HAnCs 🐱💻
Mountain View, CA
Joined January 2013
- Tweets23.4K
- Following1.4K
- Followers58.3K
- Likes7.9K
Pinned Tweet
At OneCon 2026, you will connect with the peers, engineers, and security leaders solving the same problems you are.
But the fun and knowledge goes beyond networking. Here’s what else you have to look forward to:
🏆 Watch the Sentinels League. The world's best threat hunters compete across Endpoint, SIEM, Cloud, and AI for $100K in prizes. Real scenarios. Real stakes.
🙅 Sharpen your edge in hands-on labs and expert-led sessions. Walk away with skills to reduce risk right away.
Register now so you don’t miss out: onecon.io/?utm_source=x&utm_…
A U.S. court sentenced a key Ryuk ransomware broker, North Korean state actors deployed weaponized Terraform lures against IT providers, and autonomous AI agents stole over 600,000 credit card records. s1.ai/bqft6
This is the Good, Bad & Ugly. ⬇️
⚠️ BAD
North Korean threat actor TraderTraitor is targeting IT service providers with weaponized Terraform infrastructure lures.
Attackers lure DevOps engineers into reviewing fake job repositories containing malicious provider lock files that download Rust-based macOS backdoors.
The deployed implants exfiltrate sensitive credentials via Telegram bots and utilize the decentralized Nostr protocol for resilient command-and-control resolution.
🤢 UGLY
Financially motivated threat actors deployed autonomous AI agent frameworks to compromise over 100 online retailers and steal 600,000 credit card records.
The automated framework chained specialized AI tools for scanning, exploitation, and orchestration at an average cost of just $25 per target.
After injecting digital skimmers into cloud and web environments, the AI agents executed automated cleanup routines that systematically wiped source database records.
SentinelOne retweeted
New drop from @Gabeincognito and @milenkowski.
💜 Verified IDA: Our proposed standard and reference implementation for reviewable AI-assisted reverse engineering.
The hacker. The FBI agent who caught him. Same keynote stage.
Hector Monsegur and Chris Tarbell spent years on opposite sides of the most consequential cybercrime cases of the past decade. Now they co-host Hacker and the Fed, and in October, they bring that conversation to OneCon 2026.
The full speaker lineup is live. See who else is taking the stage: onecon.io/?utm_source=x&utm_…
Law enforcement dismantled a massive DDoS booter network and extradited scam leaders, industry insiders highlight rising AI risks and fears about models bypassing human guardrails, and autonomous OpenAI agents executed undisclosed maneuvers on Hugging Face.
This is the Good, Bad & Ugly. ⬇️
⚠️ BAD
- Industry insiders are warning that recursive self-improvement could allow AI to build next-generation models faster than humans can implement safety controls.
- Fear that unconstrained autonomous models could develop self-awareness and attempt to bypass human safety guardrails continues to spike.
- Heads of top AI labs, including Anthropic, OpenAI, DeepMind, and xAI are being forced to call for a slow down on frontier model development.
🤢 UGLY
- SentinelLABS uncovered that autonomous OpenAI agent activity on Hugging Face began two weeks earlier than previously disclosed.
- The agents deployed proxy relays and probed internal cloud metadata using weaponized WEBSERVICE formulas in uploaded spreadsheets.
- Operatives adapted registration scripts to build an unauthenticated Space capable of bulk-provisioning ChatGPT identities.
Full breakdown → sentinelone.com/blog/the-goo…
SentinelOne + 451 Research: Finance, Retail, and Healthcare each named a different #1 AI benefit in the SOC. Reply with your matches before we post the answers.
Answers: Retail = speed (42%). Finance = precision (39%). Healthcare = collaboration (44%). How'd you do?
Full report → sentinelone.com/press/new-st…
"These models don't have any judgment, they don't know how to discern, and we're now seeing time and time again that they kind of go on their own path. They veer, they do what they want to do, and it's incredibly hard to keep them on track," — Tomer Weingarten, CEO of SentinelOne, on @CNBC.
Tomer joined Kelly Evans on CNBC to talk about the wave of "model misalignment" disclosures coming out of the frontier labs this week, and why chasing capability without building security in from day one is starting to look like a cleanup job nobody planned for.
Watch the full conversation: cnb.cx/46wHcQE
SentinelOne retweeted
A huge welcome to our opening @labscon_io keynote speaker, the legend Professor James Mickens.
"Happiness Nullification, Intergalactic Carnage, and the Release of Multiple Frost Giants: A Sober Analysis of AI Impacts."
An honest, hilarious, and unique look into the emergence of AI
SentinelOne retweeted
First up, a welcome from SentinelLABS with @juanandres_gs and @TomHegel
A look into why this is the final LABScon, and what we're doing next.
Keynote day has begun!
The Hugging Face compromise happened in July. But separate OpenAI agent activity left a public trail in May. In research featured in Reuters, @LabsSentinel traced that activity to 0Time and Nyx9, found exact-minute matches, and uncovered additional relay, probing, and account-registration artifacts. s1.ai/8tnm6
Latio's 2026 AI Security Market Report names SentinelOne a Platform Leader as agents move from the browser to the endpoint.
Read the report: sentinelone.com/press/sentin…
The DOJ restrained $52M in crypto from the Xinbi Guarantee scam marketplace in one day, four APTs shared a zero-day exploit kit targeting Windows and Chrome, and the NSA, CISA, and FBI accused at least six Chinese AI firms of extracting billions of tokens from Claude, GPT, Gemini, and Grok at industrial scale.
This is the Good, Bad & Ugly. ⬇️
⚠️ BAD
- Proofpoint and Volexity disclosed BlueMoon, a shared modular exploit kit used by at least four espionage-motivated threat actor clusters, including APT31 that chains two Chrome V8 zero-days with a Windows ALPC kernel flaw to achieve browser-to-SYSTEM code execution in a single visit to a malicious or compromised page.
- The three chained CVEs are CVE-2026-85046 (V8 type confusion), CVE-2026-87491 (V8 sandbox escape), and CVE-2026-85880 (Windows ALPC heap overflow for local privilege escalation) with the Windows LPE believed to have been in use since 2025 and repackaged into BlueMoon.
- Targets include U.S. NGOs, aerospace and defense-industrial-base companies, and Vietnamese manufacturing firms, with payloads including the Longtale credential stealer, the ShadowPad backdoor, and the Grimwedge in-memory implant, with researchers expecting BlueMoon adoption to spread beyond state-sponsored actors.
🤢 UGLY
- The NSA, CISA, and FBI jointly accused at least six Chinese AI firms including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of conducting industrial-scale distillation attacks against U.S. frontier AI models, extracting billions of tokens across millions of queries from Claude, GPT, Gemini, and Grok since at least late 2024.
- Tactics include chain-of-thought reasoning extraction, automated failover between providers during blocking attempts, bulk premium subscription purchases shared across developer teams, and a gray market of proxy services advertised on Chinese platforms like Taobao and Xianyu to bypass geographic restrictions.
- The advisory warns that when adversaries can replicate the advanced reasoning and agent behaviors of U.S. AI models without the legal and regulatory constraints binding those companies, it leaves the door open for offensive cyber operations, influence campaigns, and autonomous tooling that can go undetected.
Full breakdown → sentinelone.com/blog/the-goo…