HN user

_tk_

3,704 karma

Information Security Officer at Fortune 50 global corporation.

Posts381
Comments173
View on HN
www.lovebigisland.com 2d ago

Lāhainā Noon in HawaiʻI: When and Where to See IT

_tk_
2pts0
www.zetter-zeroday.com 5d ago

Tracking Peter Stokes and the Com

_tk_
1pts0
economist.com 7d ago

Haunted Houses Are in Demand in Japan

_tk_
6pts0
techcrunch.com 8d ago

A new app alerts you if someone nearby is wearing smart glasses

_tk_
11pts2
restofworld.org 12d ago

Filipino virtual assistants behind LinkedIn's "thought leadership" content mill

_tk_
33pts4
umsteigen.app 15d ago

Daily Berlin Subway Puzzle

_tk_
2pts0
www.theguardian.com 16d ago

OpenAI's apparent failure to visit key site raises questions over UK investment

_tk_
6pts0
economist.com 17d ago

The biggest iceberg has melted away, aged 40 or so

_tk_
3pts0
www.nytimes.com 18d ago

Nearly a Million Investors Lost a Total of $3.8B on Trump Crypto Coin

_tk_
10pts2
www.404media.co 20d ago

Companies Are Throttling Employees' AI Use Because It's Too Expensive

_tk_
13pts4
www.wired.com 21d ago

Claude Helped a Hacker Find a Way to Issue Tickets to US Music Festivals

_tk_
5pts0
mynintendonews.com 21d ago

Nintendo has raised its employees base salary by 10%

_tk_
561pts352
www.eyeradio.org 29d ago

Vietnamese US deportee returns home after a year in South Sudan

_tk_
3pts0
www.youtube.com 1mo ago

A Visit to id Software (November 1993)

_tk_
3pts2
www.theregister.com 1mo ago

Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

_tk_
613pts361
git.churchofmalware.org 1mo ago

Bitlocker Bypass by Nightmare Eclipse

_tk_
2pts0
www.hankgreen.com 1mo ago

Four by Three

_tk_
2pts0
www.nytimes.com 1mo ago

They Tried to Catch a Predator. They Trapped Themselves Instead

_tk_
8pts1
www.nytimes.com 1mo ago

Charlie Bites, Badgers Dance and a Lettuce Endures in This Archive of Web Memes

_tk_
2pts0
www.politico.com 1mo ago

The Florida woman catfishing America's political class

_tk_
14pts0
www.theverge.com 1mo ago

The SpaceX IPO is great for Elon Musk and terrible for you

_tk_
10pts1
paulkrugman.substack.com 1mo ago

Europe versus America: A Response to the Critics

_tk_
6pts0
doublepulsar.com 1mo ago

Microsoft's stance on zero day exploits is a dumpster fire of their own making

_tk_
77pts32
www.theatlantic.com 2mo ago

Trump's Endgame Is Surrender

_tk_
16pts7
www.youtube.com 2mo ago

How These Doctors Keep Brains Going After Death

_tk_
2pts0
www.bloomberg.com 2mo ago

Trump's More Than 3,700 Trades Astonish Wall Street Insiders

_tk_
14pts3
www.bloomberg.com 2mo ago

Judge Says Krafton Must Rehire Fired 'Subnautica' CEO

_tk_
1pts0
www.vulture.com 2mo ago

The Feed Is Fake

_tk_
4pts0
www.gq.com 2mo ago

The Secret Machine That Shapes Your Opinion of Celebrities (2025)

_tk_
2pts0
www.washingtonpost.com 2mo ago

Officially, Marco Rubio is still banned from China. So how is he in Beijing?

_tk_
8pts0

I’m a little surprised with one of the statements given in huggingface‘s report.

“To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log, comprised of more than 17,000 recorded events.”

17,000 events? Big whoop. Security teams of medium sized companies process millions of events daily.

There’s a big debate in the cyber industry about the AI SOC and whether or not it’s necessary. It seems to me they are using that report to push that idea.

I was part of several third party risk management audits from a corporate perspective.

We regularly audited and questioned SMBs (and big corps) with regards to their security posture. We knew that small shops wouldn’t be able to be fully compliant to SOC2 Type 2 or have an ISO27001 certified environment. If it was clear that our business wanted the product, we either tried to help the company with the questionnaire or created a risk report that was then signed by the business. In other words: even if your customer asks you to be compliant, you don’t have to be if they care enough about your product.

If you seem intent on getting things right, that’s a big plus. Most of your competitors don’t even know what SOC 2 is.

The system card unfortunately only refers to this [0] blog post and doesn't go into any more detail. In the blog post Anthropic researchers claim: "So far, we've found and validated more than 500 high-severity vulnerabilities".

The three examples given include two Buffer Overflows which could very well be cherrypicked. It's hard to evaluate if these vulns are actually "hard to find". I'd be interested to see the full list of CVEs and CVSS ratings to actually get an idea how good these findings are.

Given the bogus claims [1] around GenAI and security, we should be very skeptical around these news.

[0] https://red.anthropic.com/2026/zero-days/

[1] https://doublepulsar.com/cyberslop-meet-the-new-threat-actor...

I’m a little surprised by the takes in the comments. Obviously, heads of departments or agencies, CEOs, or similar personnel are generally not in the same league as normal employees when it comes to compliance.

Productivity and efficiency are key for their work. I am sure there are lots of Sysadmins here, that had to disable security controls for a manager or had to configure something in a way to circumvent security controls from actually working. I have been in many situations where I have been asked by IT colleagues if doing something like that was fine, because an executive had to read a PowerPoint file NOW.