the grugq's newsletter

Subscribe
Archives
July 30, 2025

July 30, 2025

July 30, 2025

Top Lawyer for National Security Agency Is Fired
https://t.co/kMbvqM95Ml

— Dr. Dan Lomas (@Sandbagger_01) July 29, 2025


from "China’s Lessons from the Russia-Ukraine War" by @howardgwang and Brett Zakheimhttps://t.co/q1le6mNriN pic.twitter.com/TQheMnU9sw

— Dakota Cary (@DakotaInDC) July 29, 2025


We deployed 44 AI agents and offered the internet $170K to attack them.

1.8M attempts, 62K breaches, including data leakage and financial loss.

🚨 Concerningly, the same exploits transfer to live production agents… (example: exfiltrating emails through calendar event) 🧵 pic.twitter.com/t1mb5Ix32a

— Andy Zou (@andyzou_jiaming) July 29, 2025

Thread by @andyzou_jiaming on Thread Reader App – Thread Reader App

@andyzou_jiaming: We deployed 44 AI agents and offered the internet $170K to attack them. 1.8M attempts, 62K breaches, including data leakage and financial loss. 🚨 Concerningly, the same exploits transfer to live pr...…

[2507.20526] Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition

Recent advances have enabled LLM-powered AI agents to autonomously execute complex tasks by combining language model reasoning with tools, memory, and web access. But can these systems be trusted to follow deployment policies in realistic environments, especially under attack? To investigate, we ran the largest public red-teaming competition to date, targeting 22 frontier AI agents across 44 realistic deployment scenarios. Participants submitted 1.8 million prompt-injection attacks, with over 60...


Wow. Cartels are more forward thinking than the US military!

🇲🇽 #Mexico - 🇺🇦 #Ukraine: Mexican intelligence has reportedly warned Ukraine that some Mexican volunteers may have joined the war to gain drone warfare experience, with the aim of passing that knowledge to cartels back home.

This triggered a joint investigation by Ukraine's… pic.twitter.com/Y3fePLW71g

— POPULAR FRONT (@PopularFront_) July 30, 2025


Today @Google Project Zero announced a new trial policy: Reporting Transparency. We’ll now share when we report a security vuln to a vendor within 1 week including products + deadlines. Goal: shrink the patch gap + drive faster, safer updates for users: https://t.co/BHW2NnCb6I

— Heather Adkins - Ꜻ - Spes consilium non est (@argvee) July 29, 2025


https://t.co/yOaGFg2BFq

— vx-underground (@vxunderground) July 30, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
X