@virtualsteve

Leading the charge in AI security. Chief AI and Product Officer @ Exabeam, Author @ O'Reilly, Project Lead at OWASP #cybersecurity #ai #cloud

San Jose, CA
Joined May 2008
How will we use AI Agents in cyber defense? Check out this snippet from my interview in Davos.
5
1
11
831
Configuration is a claim. Behavior is evidence. Talked with @TheNewCISO abt CISO as defensive captain, verifying agent behavior w/ open-source tools (Praxen, Observra), h/t @virtualsteve why sealed governance records matter in healthcare & pro sports 🎧 ow.ly/AL4U50ZGcOb
On the latest episode of The New CISO Podcast, @SherriDouville, CEO at @medigram explains why the global shift toward AI makes trust the CISO's new superpower. Listen now! 🔗 ow.ly/YJa250ZGfHh #CISO #Cybersecurity #Trust #TheNewCISO
2
3
128
Steve Wilson retweeted
Hannes Bieger. Retenez bien son nom. C’est le nouveau Moroder, Vangelis ou Jarre. Proto disco seventies, bassline hypnotique, ces mecs pour qui le son a toujours autant compté que les notes. Black Hole | Hannes Bieger.
328
1,894
192
12,477
654,508
This is the first time Guns N' Roses ever played "Patience" live, a cramped room at CBGB, October 1987, about 100 people watching. Appetite was stalled at #65. Axl's reading the lyrics off a sheet because they'd just written it. Weeks later, everything changed.
207
1,625
124
12,461
1,009,721
Steve Wilson retweeted
Ok who did this? Brilliant! 🤣
1
11
1,281
It’s been an amazing reception for the new OWASP Top 10 for LLMs list. But one of my concerns while building the new doc is it has grown longer and more technical. Would we loose some of the audience that just needed basic education? That’s why I built Promptfall. A fun way to play yourself through learning the new list, with colorful graphics and a banging sound track. Check it out. Let me know what you think. open-agent-ai-security.githu…
4
136
Steve Wilson retweeted
We're excited to collaborate with @googlecloud to bring Exabeam New-Scale Analytics to Google Security Operations, giving security teams deeper visibility into insider threats across human and AI agent identities. ow.ly/nQZI50Zwcy6
1
1
169
Steve Wilson retweeted
AI agents are changing insider risk — and most security programs weren't built for them. Join @forrester VP & Research Director Joseph Blankenship and Scott Clinton, Chair of the @owasp GenAI Security Project. Register: ow.ly/ZI4f50Zp35l
1
1
103
Steve Wilson retweeted
Building AI agents securely is only the starting point. In this @ISMG_News clip, @virtualsteve explains why teams also need to think about what agents can access, how they behave, and what changes once they are active inside the enterprise. #AgenticAI #AISecurity
1
3
121
Building AI agents? What kinds of risk are you creating? Will your agent do it's job or drift dangerously into other territory. #Praxen can tell you! Free and open source: open-agent-ai-security.githu… #owasp #agentsecurity #cybersecurity #ai #behaviordrift #exabeam
2
1
2
161
Steve Wilson retweeted
Exabeam launched Praxen - agent verification as a Claude Code plugin. OWASP Gen AI security chair built it. Checks permissions, boundaries, controls. Pre-deployment. Every release. we run 5 agents. each with constraints.md. harness is the verification.
1
4
86
Steve Wilson retweeted
Today's read: Exabeam Expands AI Detection Coverage and Launches Observra Open Source Agent Telemetry 📣 ift.tt/hsNzDqW Read the full story by clicking on the link below ⬇️ Never miss a beat in telecoms. Catch the latest news on @TheFastMode 🚀 #tech #telecoms #techn…
1
2
51
Steve Wilson retweeted
Before you give an AI agent access to your files, GitHub, shell or MCP tools — run a security sanity check. Found Praxen: an open-source AI agent behavior verifier. It checks whether your agent’s declared policy matches reality. Basically: you write what the agent is allowed to do, then Praxen looks for places where the actual setup drifts from that intent. It can flag things like: - overbroad permissions - credential exposure - risky tool integrations - config gaps - capability drift - MCP / supply-chain risks - policy vs implementation mismatch The important part: it runs locally and doesn’t phone home. This is not a magic “make my agent safe” button. But if you’re running Claude Code, Cursor, MCP servers or custom agent scripts, this is exactly the kind of check you want before deploy. Most people are giving agents way too much power and hoping nothing weird happens. Bad strategy.
🤖 Made with AI
2
1
3
245
Steve Wilson retweeted
Intended behavior is not always equal to actual behavior. Meet Praxen, the open-source reference implementation for Agent Behavior Verification (ABV). ow.ly/IP9y50ZfS2g #AI #AIAgents #Cybersecurity #OpenSource
2
1
1
1,142
1/ Honored to contribute to this launch announcement and retweeting the @exabeam announcement now. Here is why Praxen b @virtualsteve matters more than most people realize yet 🧵A thread
Intended behavior is not always equal to actual behavior. Meet Praxen, the open-source reference implementation for Agent Behavior Verification (ABV). ow.ly/IP9y50ZfS2g #AI #AIAgents #Cybersecurity #OpenSource
1
1
2
162