@jcran

knowledge seeker

Austin, TX
Joined May 2007
it's funny how hard it is to get a text editor out of any of the ai tools now - even @cursor_ai. we’re in this weird teenager phase. moving from coding to systems engineering.
2
244
security engineering is real and effective at containing intelligent agents. we're going through a big evolution right now but the fundamentals are still... fundamental.
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
3
1
9
725
wondering if i'm nuts thinking about vibing up a chrome fork with cmd-k support.
1
1
310
Anthropic published real AI intrusion data that probably deserves more attention than speculative concerns over the probability of AI doom. Both concerns can coexist, but one has practical risk that directly impacts most enterprises in the short-term -- whereas the other should probably dictate how the AI labs [are forced to] behave
Replying to @ItsReallyNick
Anthropic has now published their side of this APT29 🇷🇺 cyber espionage campaign, complete with a timeline of capability development & intrusions: anthropic.com/threat-intelli… ...helpful data to support prior comments about Midnight Blizzard's CaptiveCrunch being enabled by AI
5
8
57
7,815
jcran retweeted
The future is more likely AIs fighting AIs (on behalf of humans) than AI fighting humanity.
900
945
299
12,306
512,320
We are excited to announce our $100,000 scholarship program for [un]prompted! There is no more important gathering of AI security researchers and our scholarship program was created to provide financial assistance to practitioners and attendees whose fees are not paid by their employer Over $100,000 has been committed for scholarships through the generosity of the startups in our community. Scholarship recipients will have 100% of their registration expense ($850) paid directly to [un]prompted which is a 501c3 non-profit organization We will fast track applications based on peer review and good faith attestation of need. There is no financial means test. All applications are encouraged Thank you to all who are supporting this important cause (@vijaybolina, @jcran, @silascutler, @nahsra, @caseyjohnellis, @gadievron, @jkamdjou, @resilientcyber, @robtlee, @haroonmeer, @DanielMiessler, @hdmoore, @k8em0, @joshua_saxe, @kyleroro, @harmj0y, @edwardxwu, @awurthmann, @letswastetime, @jotunvillur and many others!) Please use the link in the comments below to apply and please like and reshare this post to spread the word!
4
21
30
3,842
many of the gains of AI boil down to : AI is better at brute forcing than you
17
9
8
202
135,334
jcran retweeted
Our Black Hat talk on the OpenAI-Hugging Face incident is now live on youtube. This is a watershed moment for the industry. I encourage all defenders to watch, consider how attack dynamics will imminently change, and plan for accelerating defense. youtube.com/watch?v=87DyyMV0…
71
253
72
1,239
479,353
We are just a few days away from Black Hat and our @DecibelVC GameDay event for founders and early adopters. As AI starts finding bugs faster than humans can patch them, is there anything hotter than the battlegrounds where AI meets cyber? The zero day clock is ticking faster than ever. With AI agents now discovering, weaponizing, and exploiting vulnerabilities in hours instead of months, the window between disclosure and attack is collapsing. Will the race to find bugs first become the new arms race in cyber? Come join our GameDay "Zero Day Countdown" on this hot topic with our friends: @caseyjohnellis, Founder of disclose.io Zakir Durumeric, Founder of @censysio @jcran, Founder of Mallory Please register for your GameDay pass which will give you entry to all events on Tuesday - links in comments below and we look forward to seeing you there!
2
3
1
6
857
underrated part of the story is huggingface couldn't use oai or ant models to investigate the incident due to guardrails, and were forced to use chinese open-source models to attempt to defend themselves against what turned out to be the frontier model hacking them. Wild times.
We're partnering with @huggingface to investigate an unprecedented security incident. Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation. Sharing preliminary findings to help defenders understand emerging risks: openai.com/index/hugging-fac…
1
14
45
6,554
Buckle up! Default Wordpress install vulnerable to unauth’d RCE. Mass exploitation imminent. Patch now.
2
9
1
82
10,022
never a better time to get proficient in codex
2
4
285
Introducing a new side project called Model Regression. It tests daily Claude, GPT, and Grok on various benchmark statistics to determine how well its performing and to identify model degrades over time. @edskoudis had an idea for model testing before they conducted offensive testing to ensure the model was performing as expected, and @BlasikRandy pushed me down this road with actually going and doing it. The main intent here is the frontier models will experience outages, issues, bugs, intentional/unintentional nerfing of the models without notice. You can't typically trust day to day activities in these models for stability, so leveraging this on your daily routine to see how well the model is performing for that day is something I'll be using everyday. Runs every morning in my DGX sparks environment and automatically updates with how well its performing. Enjoy! modelregression.com/ Also open-sourced the project, can run on your own server as well and look at the benchmarks and how they are calculated: github.com/HackingDave/model…
30
72
1
320
20,766
jcran retweeted
The product is the mission.
817
1,595
161
12,309
1,558,477
After months in stealth, my co-founder @helloericsf and I are finally sharing @cimentoai with the world. 🌎 AI changed social engineering. Attacks are now personalized, convincing, and cheap to generate at scale.
27
19
9
119
25,333
Oh, wow - this is big
Together with @bzvr_, @2igosha and Anton Kargin, we identified that the DAEMON Tools software has been compromised in a complex supply chain attack since April 8. We see thousands of infections across 100+ countries. If you use DAEMON Tools, run a malware scan immediately! [1/7]
3
43
207
46,562
jcran retweeted
Useful & interesting stats out of the cyber insurance firm At-Bay. They released their 2026 Annual Report, which draws from more than 6,500 claims 💰 - 73% of ransomware attacks began with a VPN - SonicWall is the most-targeted VPN, linked to 27% of ransomware claims 🧵1/3
3
23
2
96
13,239
My biggest takeaways from Claude Code's Head of Product @_catwu: 1. Anthropic’s product development timelines have gone from six months to one month, sometimes one week, sometimes one day. Part of this acceleration is access to the latest models (i.e. Mythos). Another is shipping new products into “research preview,” making clear it's early, experimental, and might not be supported forever. Another is an evergreen "launch room "where engineers post ready features and marketing turns around announcements the next day. 2. The PM role is shifting from coordinating multi-month roadmaps to enabling teams to ship daily. As Cat puts it, “There should be less emphasis on making sure you are aligning your multi-quarter roadmaps with your partner teams and more emphasis on, OK, how can we figure out the fastest way to get something out the door?” 3. The most efficient shipping unit is an engineer with great product taste. On Cat’s team, many engineers go end-to-end—from seeing user feedback on Twitter to shipping a product by the end of the week—without a PM involved. Also, almost all the PMs on the Claude Code team have either been engineers or ship code themselves, and the designers have been front-end engineers. The roles are merging, and the most valuable skill is product taste, not job title. 4. Build products that are on the edge of working. Claude Code’s code review product failed multiple times because earlier models weren’t accurate enough. But because the prototype was already built, they could swap in Opus 4.5 and 4.6 and immediately test whether the gap was closed. Teams that wait for the model to be ready will always be a cycle behind. 5. The most underrated skill for building AI products is asking the model to introspect on its own mistakes. Cat regularly asks the model why it made an unexpected decision. The model will explain that something in the system prompt was confusing, or that it delegated verification to a subagent that didn’t check its work. This reveals what misled the model so the team can fix the harness. 6. Every model release forces their team to revisit existing products and audit their system prompt to remove features the model no longer needs. Claude Code’s to-do list was a crutch for earlier models that couldn’t track their own work. With Opus 4, the model handles it natively. Features built as scaffolding for weaker models become debt when the model catches up—so the team actively strips them. 7. Anthropic employees build custom internal tools instead of buying SaaS products. A sales team member built a web app that pulls from Salesforce, Gong, and call notes to auto-customize pitch decks—work that used to take 20 to 30 minutes now takes seconds. Their core stack is Claude Code, Cowork, and Slack. No Notion, no Linear, no Figma. 8. People underestimate how much Claude’s personality contributes to its success. As Cat describes it, “When you reflect on everyone you’ve worked with, there’s just some people where you’re like, I really like their energy, their vibe.” Claude is designed to be low-ego, positive, competent, and earnest—qualities that make it feel like a great coworker, not just a tool. This isn’t cosmetic; it’s what makes people want to use Claude for hours every day. The team has a dedicated person, Amanda, who “molds Claude’s character,” and it’s one of the hardest roles at the company because success is so subjective. 9. The future of work is managing fleets of AI agents, not doing the work yourself. Cat sees a clear progression: first, individual tasks become successful. Then people start running multiple tasks at the same time (multi-Clauding). Next, people will run 50 or 100 tasks simultaneously, which will require new infrastructure—remote execution, better interfaces for managing tasks, agents that fully verify their work, and self-improving systems that incorporate feedback. The human role shifts from doing the work to knowing which tasks to look into, verifying outputs, and giving feedback that makes the system better over time. 10. Hire people who lean into chaos and face every challenge with a smile. At Anthropic, there are weeks when a P0 on Sunday becomes a P00 by Monday and a P000 by Monday afternoon. If you get too stressed about any one thing, you’ll burn out. Their team looks for people who can look at a hard challenge and say, “Wow, that’s gonna be hard. But I’m excited to tackle it and I’m gonna do the best that I possibly can.” This mindset—optimism, resilience, and comfort with constant change—is increasingly essential as the pace of AI development accelerates. Don't miss the full conversation: youtube.com/watch?v=PplmzlgE…
How Anthropic’s product team moves faster than anyone else I sat down with @_catwu, Head of Product for Claude Code at @AnthropicAI, to get a peek into their unprecedented shipping pace, how AI is changing the PM role, and how to be the right amount of AGI-pilled. We discuss: 🔸 How Anthropic’s shipping cadence went from months to weeks to days 🔸 The emerging skills PMs need to develop right now 🔸 Why you should build products that don't work yet—then wait for the model to catch up 🔸 Why a 95% automation isn't really an automation 🔸 Cat’s most underrated AI skill (introspection) 🔸 What Cat actually looks for when hiring PMs now (hint: it's not traditional PM skills) Listen now 👇 youtu.be/PplmzlgE0kg
98
293
62
2,853
847,618
Had an awesome conversation with my friend @jcran and partner Mallory AI about their new offering. What he's been building there has been extraordinary, and I'm super excited for him to finally be sharing it with the world. Basically (my take), Threat Intelligence that is available to your agents! (They still have great interfaces for humans, too) :) So now my PAI system can interact with their API, which means I can ask about threat actors, TTPs, and all sorts of threat intel related content right from my digital assistant / agent harness. Insane stuff. Go check it out here: mallory.ai/blog/demoing-mall…
1
1
17
2,115