𝓼𝓱𝓮𝓮𝓹 🐑🌈

@j_@infosec.exchange
2 Followers
21 Following
202 Posts

IT security and privacy enthusiast. I'm primarily using this account to boost things that catch my attention.

Anything shared or boosted through this account does not represent my employer and does not necessarily represent my own views. Follow me at your own risk.

Internal workings of the Fediverse algorithm

New, at KrebsOnSecurity.com: Marko Elez, a 25-year-old employee at Elon Musk's Department of Government Efficiency (DOGE), has been granted access to sensitive databases at the U.S. Social Security Administration, the Treasury and Justice departments, and the Department of Homeland Security. So it should fill all Americans with a deep sense of confidence to learn that Mr. Elez over the weekend inadvertently published a private key that allowed anyone to interact directly with more than four dozen large language models (LLMs) developed by Musk's artificial intelligence company xAI.

https://krebsonsecurity.com/2025/07/doge-denizen-marko-elez-leaked-api-key-for-xai/

This is a good analogy for AI, if you don't like toast and that's not jelly.

This is fun. Google Gemini’s “Summarize email” function is vulnerable to invisible prompt injection utilized to deceive users, including with fake security alerts.

#infosec #cybersecurity #blueteam

https://0din.ai/blog/phishing-for-gemini

The GenAI Bug Bounty Program

We are building for the next generation in GenAI security and beyond.

0din.ai

A look at the recent sea surface temperature trend (annual mean) for the Gulf of Mexico... 🫣

See more at https://zacklabe.com/united-states-climate-indicators/

This is your regular reminder that if you are the smartest person in the room, go find another room. You are not going to run out of people or rooms.

"While these agents promise to make life easier by allowing users to “put your brain in a jar,” they can also gather valuable—and often sensitive—data. This is a core concern for #Signal, which is trusted by tens of millions of users, including those in government, military, human rights and journalism, for confidential communication and guaranteed #privacy."

https://observer.com/2025/07/signal-meredith-whittaker-agentic-ai-risk/

Signal Chief Meredith Whittaker Sounds Alarm On Agentic A.I.’s Privacy Threat

Signal Foundation President Meredith Whittaker warns that agentic A.I. could breach app-level security, threatening privacy for millions of users.

Observer

NEW: Over the weekend, Jack Dorsey launched an open-source chat app called Bitchat, which he promised to be “secure” and “private.”

He then later added a warning that the app not been tested or reviewed for security issues, asking people not to trust it as "it does not necessarily meet its stated security goals."

Security researchers are already finding flaws in it.

https://techcrunch.com/2025/07/09/jack-dorsey-says-his-secure-new-bitchat-app-has-not-been-tested-for-security/

Jack Dorsey says his 'secure' new Bitchat app has not been tested for security | TechCrunch

Dorsey admitted that his new messaging app had not been reviewed or tested for security issues prior to its launch.

TechCrunch

Good scoop by reporters with the Organized Crime and Corruption Reporting Project (OCCRP), who confirmed that Sergio Gor, the director of the White House Office of Presidential Personnel, was born in the former Soviet Union, specifically in Tashkent, Uzbekistan. Gor prompted speculation about his origins when he declined to say where he was born, saying only that it was not in Russia.

https://www.occrp.org/en/news/exclusive-top-trump-advisor-sergio-gor-was-born-in-the-soviet-union

Exclusive: Top Trump Adviser Sergio Gor Was Born in the Soviet Union

The birthplace of U.S. President Donald Trump’s director of personnel has been the subject of media speculation — fuelled by his refusal to answer the question.

OCCRP
Rolling Stone - Elon Musk’s Grok chatbot goes full Nazi, calls itself ‘MechaHitler’ https://www.rollingstone.com/culture/culture-news/elon-musk-grok-chatbot-antisemitic-posts-1235381165/
Elon Musk’s Grok Chatbot Goes Full Nazi, Calls Itself ‘MechaHitler’

Elon Musk's Grok chatbot unleashed a slew of antisemitic commentary and praised Hitler after apparent change allowed it to be 'politically incorrect'

Rolling Stone
×

New, at KrebsOnSecurity.com: Marko Elez, a 25-year-old employee at Elon Musk's Department of Government Efficiency (DOGE), has been granted access to sensitive databases at the U.S. Social Security Administration, the Treasury and Justice departments, and the Department of Homeland Security. So it should fill all Americans with a deep sense of confidence to learn that Mr. Elez over the weekend inadvertently published a private key that allowed anyone to interact directly with more than four dozen large language models (LLMs) developed by Musk's artificial intelligence company xAI.

https://krebsonsecurity.com/2025/07/doge-denizen-marko-elez-leaked-api-key-for-xai/

From the story:

Philippe Caturegli, “chief hacking officer” at the security consultancy Seralys, said the exposed API key allowed access to at least 52 different LLMs used by xAI. The most recent LLM in the list was called “grok-4-0709” and was created on July 9, 2025.

Grok, the generative AI chatbot developed by xAI and integrated into Twitter/X, relies on these and other LLMs (a query to Grok before publication shows Grok currently uses Grok-3, which was launched in Feburary 2025). Earlier today, xAI announced that the Department of Defense will begin using Grok as part of a contract worth up to $200 million. The contract award came less than a week after Grok began spewing antisemitic rants and invoking Adolf Hitler.

Mr. Elez did not respond to a request for comment. The code repository containing the private xAI key was removed shortly after Caturegli notified Elez via email. However, Caturegli said the exposed API key still works and has not yet been revoked.

@briankrebs spectacular.
@briankrebs i really really hope that we can refer to this sort of bullshit when anybody tries to hock something with "military grade" in its description, or "government security" or any of the other phrases that they think to use in an effort to say 'the government does it so obviously that means its the best and most secure and most efficient and overall the most well thought out possible option'
@Viss @briankrebs I would venture to suggest that government grade security meant a lot more than it does now that these private sector imbeciles are fucking around inside government.
Dare Obasanjo (@carnage4life@mas.to)

Anthropic, Google, OpenAI and xAI have all been granted contracts worth up to $200M by the U.S. Department of Defense to accelerate its adoption of “advanced AI capabilities to address critical national security challenges.” It seems your AI calling itself “MechaHitler” isn’t a dealbreaker for defense contracts. https://www.cnbc.com/2025/07/14/anthropic-google-openai-xai-granted-up-to-200-million-from-dod.html

mas.to
@Viss @briankrebs I've worked in both private industry and government. Government averages much better.
[edit to add] Speaking in the context of good practices and running a secure shop.
@Viss @briankrebs - The failure mode in this case was one that government can't directly protect against: We elected greedy stupid assholes to run the government.
The very same people who fuck up private companies.
@briankrebs the idiot's feud with Musk may actually be the best chance of these characters being forced back out of government systems given their almost guaranteed conflicts of interest/ loyalty to Elon not Donny
@fencepost @briankrebs Considering that the feud with Musk didn't stop xAI from getting that $200 million contract with DoD, I wouldn't hold my breath.
@kcivey @fencepost @briankrebs maybe the feud is a sham? After all Palpatine did run both sides of the clone war so as to divert eyes and accumulate even more power for himself...
@etenil @kcivey @briankrebs given the egos and issues of the individuals involved? Maybe I'm wrong but I think it's more likely that they'd be challenged by checkers than it is that they're playing 3d chess.

@briankrebs

Dear Doge Moron Marko Eliz,

Dogs sniff each others asses, so have another colleague sniff your code (as well as everything you touch).... It should smell the same. By the way, I have read about your racism. Disco your sessions, return your devices, data, and property, and go away. Play with tinker toys.

@briankrebs Incident Response is woke

"the exposed API key still works and has not yet been revoked"

@briankrebs
"It's ok. The NPC don't know what a private key does." -BigBalls
@briankrebs
Ten guesses how Caturegli knew exactly which and how many systems the key worked on.
He stopped counting at 52....
@briankrebs America is going out with quite the whimper at the hands of the least intelligent people it has to offer. I'd almost feel proud if it were a bunch of geniuses born and raised here that were carrying out the country's destruction. Instead, it's Brick from the movie "Anchorman" with a bad spray tan, and a South African immigrant that lived here illegally in the 90s, and has now hired some random douchebros off the side of the road to dismantle Social Security, Medicare, Medicaid, the Department of Education... basically everything being tracked on https://www.project2025.observer/
Project 2025 Tracker

Track the progress on Project 2025

@Avitus

"...hired some random douchebros off the side of the road..." 🙂 you do have a way with words, concepts too! Thanks for the black laughter.

@briankrebs

@briankrebs This. Is. Sensational.

@briankrebs

Is he the one they call, sorry, who calls himself, "Big Balls"?
🙂

@Su_G @briankrebs No. This is "tiny balls" Elez.

@wcbdata @briankrebs

Oh, thanks for clarifying, my mistake! 😂

@briankrebs who ever would have guessed a #DOGE bro wouldn't have the best security hygiene?

https://cryptadamus.substack.com/p/the-crypto-grifters-of-doge

The Crypto Grifters Of DOGE

How many crypto grifters does it take to screw up the machinery of state?

The Cryptocalypse Chronicles

@briankrebs

Could we make it easier? Maybe adverserial hackers would enjoy a refreshment & shoulder massage as they're led comfortably into every aspect of government infrastructure?

@briankrebs the banal, incompetent face of evil, eh?
@briankrebs We shall now refer to him as Dorko E-loser.
@briankrebs 52 different LLMs , eh? I wonder what they're different in.

@fst @briankrebs have you ever heaed abaout AlphaGo zero. tl;dr: it learned playing Go by playing against itself.

let me introduce xAi, where it learns facts and history by talking to itself

@briankrebs This!

“If a developer can’t keep an API key private, it raises questions about how they’re handling far more sensitive government information behind closed doors,” Caturegli told KrebsOnSecurity.

@briankrebs Fun thing about chatbots is how naive they are. If you just ask politely enough and it will tell you info that you shouldn't have access to.
@briankrebs this myth of the private sector geniuses needs to end. Musk should surely be evidence enough that it’s often just smoke and mirrors, chutzpah and paid PR. Ok. And gullible fans and investors.

@briankrebs
> However, Caturegli said the exposed API key still works and has not yet been revoked.

> While still at Treasury, Elez resigned after The Wall Street Journal linked him to social media posts that advocated racism and eugenics. When Vice President J.D. Vance lobbied for Elez to be rehired, President Trump agreed and Musk reinstated him.

If you're a racist, you're stupid by definition.

(Does not rule our being harmful and dangerous.)

@briankrebs

What could possibly go wrong?

@briankrebs

Does Musk deliberately employ total fucking idiots or is this a side-effect of other selected for employee attributes? 🤦‍♂️🙄

@briankrebs Hi. Do you block VPN connections? I get an 403 error on your site.
@briankrebs If there was ever a time to insist on paper bank statement, it is now.
@briankrebs Alt text - man learning how to smile
@briankrebs Why is absolutely everything so very very stupid.

@briankrebs

It’s nice to know that I would be overlords not only enjoy hiring and competent white people to cabinet positions and government largely because they’re over government and they intend to destroy it and replace it with their own ideas.. (ahem), but they’re chosen foot soldiers also live in a world of arrogance, and with it comes indifference and incompetence.

@briankrebs Perfect opportunity for some nation state actor to do some rubber hose breaking of cryptography to gain access to such systems. And the body can be kept alive duct taped to a chair, fed intravenously, and continuously interrogated for information until the KGB finds a suitable building where he will fall out a window.
@briankrebs I say, jail for life for Marko. But very early release if jail for life for Elon can come out of this.