Russel Van Tuyl
@russelvantuyl.bsky.social
98 followers 120 following 24 posts
Tech enthusiasts, offensive cybersecurity professional, AI student
Posts Media Videos Starter Packs
Reposted by Russel Van Tuyl
specterops.io
🚨 New blog post alert!

@xpnsec.com drops knowledge on LLM security w/ his latest post showing how attackers can by pass LLM WAFs by confusing the tokenization process to smuggle tokens to back-end LLMs.

Read more: ghst.ly/4koUJiz
Tokenization Confusion - SpecterOps
Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.
ghst.ly
Reposted by Russel Van Tuyl
specterops.io
BIG NEWS: SpecterOps raises $75M Series B to strengthen identity security! Led by Insight Partners with Ansa Capital, M12, Ballistic Ventures, Decibel, and Cisco Investments. ghst.ly/seriesb

#IdentitySecurity #CyberSecurity

(1/6)
russelvantuyl.bsky.social
Come join us, there isn’t a better place to work and show your technical excellence surrounded by the industry’s best if you ask me!
specterops.io
Our Consulting Services team is growing! 🙌

We are now hiring Consultants and Senior Consultants to join the team as operators, trainers, and program developers.

Learn more & apply today! ghst.ly/3PBmGFZ
Reposted by Russel Van Tuyl
danielvanstrien.bsky.social
First dataset for the new @huggingface.bsky.social @bsky.app community organisation: one-million-bluesky-posts 🦋

📊 1M public posts from Bluesky's firehose API
🔍 Includes text, metadata, and language predictions
🔬 Perfect to experiment with using ML for Bluesky 🤗

huggingface.co/datasets/blu...
bluesky-community/one-million-bluesky-posts · Datasets at Hugging Face
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
huggingface.co
Reposted by Russel Van Tuyl
sebastianraschka.com
If you find yourself with too much free time over the (long) weekend / holidays, I have ~3h Building an LLM from the Ground Up workshop on YouTube that may come in handy: m.youtube.com/watch?v=quh7...
Building LLMs from the Ground Up: A 3-hour Coding Workshop
YouTube video by Sebastian Raschka
m.youtube.com
russelvantuyl.bsky.social
The paper also includes 16 different areas of testing in Appendix A that is very useful such as:
- CBRN Risks
- Violence & Self Harm
- Dangerous Planning
- Cybersecurity
- Privacy
- Law
russelvantuyl.bsky.social
4. Synthesizing the data and creating evaluations
russelvantuyl.bsky.social
2. Determining the versions of the model or system to which the red teamers will have access

3. Creating and providing interfaces, instructions, and documentation guidance to red teamers
russelvantuyl.bsky.social
Effective red team campaign components:
1. Deciding the composition of the red teaming cohort based on the outlined goals and prioritized domains for testing
• What open questions do we have about the model or system?
• What threat model(s) should red teamers take into account?
russelvantuyl.bsky.social
I really enjoyed reading this paper from OpenAI. If you perform AI assessments, you should read it.

I thought they laid out a pragmatic approach to evaluating AI models that should be a component of any organization's assessment methodology.

cdn.openai.com/papers/opena...
cdn.openai.com
Reposted by Russel Van Tuyl
andyrobbins.bsky.social
I couldn't find any PowerShell examples of encrypting/decrypting data w/ Azure Key Vault keys, so I made some:

Protect-StringWithAzureKeyVaultKey
Unprotect-StringWithAzureKeyVaultKey

github.com/BloodHoundAD...

Explanatory blog post coming soon.
Add key vault cryptographic op funcs · BloodHoundAD/BARK@e1c82a1
github.com
russelvantuyl.bsky.social
Agents are the next thing
russelvantuyl.bsky.social
Organizations are adopting RAG at 51% while fine tuning is down at 9% from last year’s 19%
russelvantuyl.bsky.social
- Top industry adoption of AI:
- Healthcare
- Legal
- Financial services
- Media & entertainment
russelvantuyl.bsky.social

- Top use cases are:
- Code copilot 51%
- Support chatbots 31%
- Enterprise search/data extraction 28%
- Meeting summarization 24%
russelvantuyl.bsky.social
$13.8 billion in AI spend
russelvantuyl.bsky.social
Love this, hoping to do something similar with our assessments.
christruncer.bsky.social
It’s always awesome when we (@CISAGov) gets to release a red team report that we worked on, and today is another one of those days!

Go check out our latest report and hopefully you can apply some of the same lessons to your environment!

www.cisa.gov/news-events/...
russelvantuyl.bsky.social
“Cybersecurity professionals and ethical hackers need to understand the darker side of hacking to better prepare for potential threats. Unfiltered AI models can provide insights into hacking methodologies and scenarios typically censored, aiding in the development of robust cybersecurity measures.”
Reposted by Russel Van Tuyl
heidykhlaaf.bsky.social
Great read on how "China Hawks are Manufacturing an AI Arms Race", a concerning trend for anyone advocating for regulation and safety of AI. An arms-race narrative would ensure an unfettered and unregulated development of AI in almost all contexts.
garrisonlovely.substack.com/p/china-hawk...
China Hawks are Manufacturing an AI Arms Race
An influential congressional commission is calling for a militarized race to build superintelligent AI based on threadbare evidence
garrisonlovely.substack.com
russelvantuyl.bsky.social
Thanks for sharing about HyperShield, I hadn’t heard of it. It seems like a lot of risk for a bad a FW rule to be pushed and killing businesses operations. Hopefully AI is only writing the rule and not implementing it.