#swsec

2026-03-14

A complete Silver Bullet archive (with episodes starting twenty years ago in 2006) can be found on my website.

#swsec #appsec #MLsec

garymcgraw.com/technology/silv

2026-03-14

The Silver Bullet Security Podcast rides again. Our first relaunch episode (episode 154 for those of you counting) can be found on the BIML website.

#MLsec #swsec #appsec #ML #AI

Future episodes are already planned with Giovanni Vigna, Phil Venables, and Nicolas Papernot.

Tune in and subscribe.

berryvilleiml.com/podcast/

2026-03-14

This is bad security engineering, but it is also a much harder problem to solve than most people realize. #swsec

theguardian.com/environment/20

2026-03-12

#AI is having a big impact on software development. Is this good or bad from #swsec? Nobody knows.

theguardian.com/technology/202

2026-03-09

It is both rewarding and daunting to be mentioned in this work along with Ken Thompson and Ross Anderson. Lots of ideas expressed in this essay are right on the money.

Have a read. Pass it on.

#MLsec #ML #swsec #appsec #security #infosec

medium.com/@maconstantino/trus

2026-03-06

Maybe the answer is "building security in" instead of "penetrate and patch," huh @gadi ?

#swsec #MLsec #appsec

wsj.com/tech/ai/send-us-more-a

2026-03-04

#ML and #AI deeply impacting time to exploit. The zero day clock shows this.

This is #security impacted by ML...not #MLsec

Guess we should have learned those lessons from #swsec 25 years ago

zerodayclock.com/

2026-03-04

@david_chisnall absolutely excellent third paragraph.

Writing software requires great clarity in either requirements or design or (the gods willing) both. AI dev tools appear to work properly only when architecture is clear and built by a human. Formally verified bad design is still bad design.

Security is an emergent system property that is difficult to specify formally without absurd logical contortions

Go

#swsec #appsec #MLsec #security #dev

2026-03-02

The Silver Bullet Security Podcast is back! Episode 154 is an interview with Gadi Evron. Have a listen and subscribe to the series.

#MLsec #ML #AI #security #swsec #appsec

berryvilleiml.com/2026/03/02/s

2026-02-15

@baldur the only answer is to try to be one of the authorities. This is why in 2006 there were three "popes" in #swsec. At least I had my own pope hat.

2026-02-11

Proud to have assembled and chaired the Irius Risk Technical Advisory Board. Irius Risk was bought by ThreatModeler in December. The TAB was a particularly potent group of advisors.

#swsec #appsec #threatmodeling

theoutpost.ai/news-story/threa

2026-01-21

Just got a briefing on how OpenAI develops and secures code internally using Codex5.1. Also got another briefing on the ONE MLsec-ssg that any of us have ever seen in a major enterprise.

The world is changing.

#MLsec #swsec #appsec #AI #ML

2026-01-21

Talking about VIBEguard and the emerging "SLOPopcalypse" in software dev during the LEGIT Technical Advisory Board.

#appsec #swsec

2025-12-07

@nuthatch there is also a book in my #swsec series about this a.co/d/f5OTVe9

2025-12-06

Two things. #AI #ML

1. Not only did Anthropic use seven of my books in their training set, ignoring copyright ownership. Horrors!

2. They did not access the most important books, thus putting together a statistically-incorrect version of my thinking about #swsec Double Horrors!

What happens to #MLsec when training sets are philosophically skewed?

berryvilleiml.com/2025/12/05/t

2025-12-01

Twenty years ago, we published this paper about software security BUGS. Brian Chess and I attempted to introduce a logical taxonomy for vulnerability. Later, mitre fucked it all up by pouring all the bugs into the same huge pot, adding water, and calling it soup. @peisert @Securityandprivacy

garymcgraw.com/wp-content/uplo

#swsec #appsec

Elias B. Sørensenelias_sorensen
2025-11-24

Here we go again npm: koi.ai/incident/live-updates-s. This time the malware will attempt to delete the victim's home directory if unable to obtain credentials.

Don't know many details yet. I guess it's not unfair to assume that the attackers are still utilizing something like the post-scripts aka rce-as-a-service functionality. Mitigate by setting `npm config set ignore-scripts true`. As other actions, freeze updates and get on top of your package tree.

2025-11-23

@windsheep this is exactly right on the money. Architectural view and understanding matters very deeply.

Coding a 10,000 line thing "automatically" is amazeballs but it does not reflect (at all) the scale or the architectural complexity of modern software. We are painting ourselves into an enormous maintenance problem corner.

#swsec #MLsec

2025-11-14

@nytimes @cademetz BIML has extremely deep expertise in both #ML (Katie did shazam, Harold wrote early birdnet, I wrote my first neural net in 1989 and was a Doug Hofatadter PhD student.) and security engineering (I helped invent #swsec and #appsec, richie published at usenix security as an undergrad).  The combination is all too rare.

The world needs more hard core #MLsec

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst