Jonathon Klobucar
San Francisco, California, United States
1K followers
500+ connections
View mutual connections with Jonathon
Jonathon can introduce you to 10+ people at Socket
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Jonathon
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Activity
1K followers
-
Jonathon Klobucar shared thisDid you know "Weapon of Choice" by Fatboy Slim is a song about Dune? Anyway. I'll be at hacker summer camp in Vegas next week. 🎰 If you're around, hit me up and we'll find some time to chat and catch up. I have more useless facts like this one, and I'm always up for talking security, supply chain or otherwise. See you in Vegas. 🎲
-
Jonathon Klobucar shared thisAttackers are only growing more sophisticated with how they are deploying attacks against and with packages.Jonathon Klobucar shared this🚨 An 18-package npm cluster spent three months quietly targeting AlibabaGroup.com developers with a full remote access trojan. What made this hard to catch: the attack was split across packages so no single one looked malicious. The RAT does command execution, arbitrary file upload/download, host recon, encrypted reverse TCP proxy, and persistence per-platform (.zshrc and a Launch Agent on macOS, replacing the core code of the Alilang security app on Windows, a binary in /tmp on Linux) Socket found it by examining dependency trees. The packages were published from different npm maintainer accounts, but the staging on April 27-28 was clearly coordinated. 👇 Full analysis and IoCs below
-
Jonathon Klobucar reposted thisJonathon Klobucar reposted thisWe're hiring a Head of Channel at Socket. Socket is growing over 5x year-over-year, making us one of the fastest growing companies in cybersecurity. We closed a $60M Series C at a $1B valuation in May. 3 of 5 FAANG companies are Socket customers. And channel demand has arrived ahead of the channel program: partners keep bringing us into deals, and nobody at Socket owns them yet. That's the job. You'd be our first dedicated channel hire, building from zero: partner strategy, deal registration, the portal, enablement, contracts, and our first five strategic partnerships. You'd work directly with me and our VP of Sales. What we're looking for: • A zero to one builder with founder energy. You spot the problem, get your hands dirty, and ship the fix without being asked. • The instincts of a great AE. You prospect, you follow up relentlessly, you treat partner pipeline like quota. • Technical enough to pitch and demo Socket without an SE in the room. • Security channel experience, with a bias for a few deep partnerships over a thousand shallow ones. • Relationships still matter, but they're not the job. If your playbook stops at golf and steak dinners, this role will feel too big for that toolkit. We're looking for someone who wants to build the channel at one of the fastest growing security companies, right as it inflects. If that's you, let's talk. Please apply here (https://lnkd.in/e2dMAJMG) and say you saw my LinkedIn post and I will personally review your application.
-
Jonathon Klobucar posted thisToday's my first day at Socket! Much of the industry spent a stretch of the last year in Shai-Hulud response and hardening. Malicious package waves, incident write-ups, one too many "is this in our tree?" mornings. Supply chain became the part of the job that followed me day to day. I was helping set up BSidesSF when Trivy got popped, then spent the conference watching all of us try to trace the reach and scope of the compromise. I haven't stopped thinking about it since. I was a user before I was an employee, and I can't think of a better reason to join a company. Security was a career change for me, and the last year showed me what I wanted out of this work. I got to defend one company against this problem. Now I get to work on it for everyone who depends on open source. Which is everyone. Open source is people sharing and building software with strangers for free, because they care. That's worth protecting. See some of you at hacker summer camp next week.
-
Jonathon Klobucar posted thisA year ago I joined Sublime Security. Today's my last day. The majority of my career before this was SRE. Security kept turning up in the work, but it was never what I was hired to do. Sublime gave me that chance. My job was securing Sublime — the company, and the product it shipped. That seat gave me a view into how customers were using what we built, and into what detection and response (DART) teams were finding on the other side of it, including what we missed. It's hard to appreciate how creative email attacks have gotten until you're inside the company trying to catch them. The AI shift hit in the middle of it, and the attacks I saw in my last few months looked nothing like the ones I saw in my first. I was the first security engineer here. When I started, the whole security org was smaller than the security engineering team is today. I'm proud of that growth, and even prouder of who we hired. The people we brought in are so good, and they're the reason the program doesn't lean on any one person anymore. There are far too many people to thank by name, which is its own kind of luck. Threat ops taught me about malware, and walked me through what our customers were actually getting hit with week to week. The engineers taught me how the thing worked under the hood, and made room for security in how it got built. I love my Sublime peeps and will see some of you at hacker summer camp in two weeks. Leaving was a hard call. I'm going somewhere that fits what I want out of this work, and I only knew what that was because of this year. I'll share where I'm going soon.
-
Jonathon Klobucar reposted thisJonathon Klobucar reposted thisLike everyone else who migrated to Anthropic’s Fable 5, I hit this error when kicking off my workflows monday morning. Model failure is annoying, but if specific models are now critical dependencies that can get cut off on a whim, we’re entering a new frontier for AI governance. Honestly, I’m not thrilled about it. If capability spikes in cyber, bio, or AI R&D can trigger export controls and abrupt availability changes after launch, people will look abroad for easier accessibility. The tradeoff is usually that these providers have less guardrails or controls. Before all of this, Anthropic put the Fable / Mythos class into a "Covered Models" bucket and said outright that perfect jailbreak resistance may not be achievable, but the defences will be world class. I'm inclined to believe them given the controls and testing on the model card, as well as the investment from the Anthropic security team over the years. I'm not alone in believing that Fable should be released, either. A lot of technical security folks feel the same way, enough that many of us have signed the Free Fable Letter (linked in the comments). If you're building like me, the lesson is simple: design for fallback if you're using public model providers... And maybe give Kimi-K2.7 a try while you're at it?
-
Jonathon Klobucar reposted thisJonathon Klobucar reposted thisI added my name to the Open Letter on Transparent AI Cyber Protections. I don't put my name on much. I put it on this. My reasoning is plain. Frontier models may make attackers faster. We know they make defenders faster. Those capabilities are not unique to any one frontier lab. Our adversaries are not waiting on an export license to use advanced models and harnesses. When we cut American security teams off from the best tools available, we do not slow the attacker. We blind the defender. This is not a stand against AI safety. I want a real safety regime, built on science, arrived at democratically, enforced fairly, and no broader than the public's safety requires. Arbitrary decisions made without a serious risk assessment give us none of that. They make a durable safety regime less likely, and they put American leadership at risk. American defenders should be able to do their work in the open and alongside our allies. Anything less serves no one but our adversaries. That is why I signed. Link in the comments.
-
Jonathon Klobucar reposted thisJonathon Klobucar reposted this🚀 ELITE Sponsor Spotlight: Sublime Security A great BSides experience is built by the community - and by the sponsors who help make the space worth staying in between sessions. We're excited to spotlight Sublime Security as an Elite Sponsor of BSides Vancouver 2026. They're also hosting the Activation Lounge, so if you're joining us for the main conference on Monday, June 1 at SFU Harbour Centre, make sure you stop by and check it out. Thank you to Sublime Security for supporting BSides Vancouver 2026 and helping make this community event possible. https://sublime.security/ #BSidesVancouver #CyberSecurity #InfoSec
-
Jonathon Klobucar reposted thisJonathon Klobucar reposted this🏆 We're honored to be named a Rising in Cyber 2026 honoree by Notable Capital! Rising in Cyber recognizes the 30 most promising private cybersecurity startups, selected not by analysts, but by 150 active CISOs and senior security executives. That makes this recognition especially meaningful to us. As AI reshapes how enterprises operate, the security challenges that come with them are unlike anything we've seen before. We built Sublime to tackle exactly that, and being recognized by the security leaders on the front lines of this shift validates that our work is moving the needle. 👉 Learn more about Rising in Cyber 2026: https://lnkd.in/eNc6q-86 #RisingInCyber #Cybersecurity #AgenticAI #AISecurity #Startup
-
Jonathon Klobucar liked thisYeeeeehaaaa! I get to work with Yevhen again. Corridor is so lucky to have this guy. So are our customers!!Jonathon Klobucar liked thisWe’re excited to welcome Yevhen Grinman to Corridor! Yevhen joins us from AppOmni, where he helped build and scale the company’s product security function. He previously held security engineering roles at Salesforce, Carta, and Iterable, and worked on several government contracts in the Washington, D.C. area. He loves building practical security tools and is especially passionate about software and supply chain security. Outside of work, Yevhen teaches Muay Thai, trains Brazilian jiu-jitsu as a brown belt, and enjoys gravel and road cycling. We couldn't be more excited to have him on the team!
-
Jonathon Klobucar liked thisAgents are changing everything about the way we use and build software and I couldn't be more excited to discuss what new security controls are required to deploy them successfully into production. Monday Night @ Blackhat - Signup Here: https://lnkd.in/gF8KS_xjJonathon Klobucar liked thisSecuring Your Coding Agent: The Road to The Software Factory is just two days away. Your coding agent has more access than you think. It's running with your credentials, your .env file, and can reach into every repo the host can touch. Software Factories will remain a topic of conversation rather than a practical reality without a secure design pattern for coding agents. On Thursday Snyk, Docker, Inc, and Keycard published Agent Baseline, a vendor-neutral reference architecture for safely building, deploying, and operating AI agents. Monday at Black Hat we're bringing Ian Livingstone CEO of Keycard, Eli Aleyner VP of Product Strategy & Alliances at Docker, Inc, and Ezra Tanzer AI Forward Deployment CTO at Snyk together on stage to discuss Agent Baseline and what a secure design pattern for coding agents looks like. What we'll get into: - The security, capability, and autonomy trilemma, and the architecture that stops it from being a two out of three choice - Why one shared API key across an agent fleet quietly kills attribution, and what per-action identity looks like instead - Sandboxing developers won't switch off: micro-VMs, default-deny egress, and credentials the agent never holds - Securing the agent supply chain and tracking agent behavior - Agent Baseline, why it was created, and how you can contribute Built for the engineers and security leaders already running coding agents in production who want to run them without holding their breath. See you at The Marquee in Las Vegas on Monday. Save your spot below.
-
Jonathon Klobucar liked thisJonathon Klobucar liked thisThe rumors are true! Everyone's favorite Santa Claus impersonator is headed to Vegas next week, backing Feross Aboukhadijeh and the whole Socket team at Black Hat and DEF CON. Timing's perfect, right? OpenAI just had an agent break out of its sandbox and pop Hugging Face. Anthropic went to check their own agents... and found three more broke loose. And what does every agent do? Installs packages. At machine speed. 1,000x the volume, zero "wait, what is this dependency" human instinct. We spent a decade teaching developers to think before they install. The fastest developer on your team is now a model that doesn't think at all (it predicts... which looks like thinking). Come find me in Vegas. Grab a slot with us, or just walk up to Jonathon Klobucar and I to tell us about the cybers. Meeting link in the first comment. 👇 See you in the desert.
-
Jonathon Klobucar reacted on thisJonathon Klobucar reacted on thisExcited to share that I'm joining The Walt Disney Company as a Sr. Principal SRE on the Media Engineering team, supporting Disney+, ESPN, and Hulu. I've always admired the level of craft and attention to detail Disney brings across every product, from theme parks to movies to live streaming. Getting to help build the reliability behind the experience, at scale, is an awesome challenge and I'm looking forward to what's ahead!
Experience
Volunteer Experience
-
Organizer / Lead
BSidesSF
- Present 1 year 7 months
Science and Technology
https://bsidessf.org/
BSides San Francisco is a non-profit organization designed to advance the body of Information Security knowledge by providing an annual, two-day, open forum for discussion and debate for security engineers and their affiliates. We produce a conference that is a source of education, collaboration, and continued conversation for information technologists and those associated with this field. The technical and academic presentations at BSidesSF are given in the spirit of…https://bsidessf.org/
BSides San Francisco is a non-profit organization designed to advance the body of Information Security knowledge by providing an annual, two-day, open forum for discussion and debate for security engineers and their affiliates. We produce a conference that is a source of education, collaboration, and continued conversation for information technologists and those associated with this field. The technical and academic presentations at BSidesSF are given in the spirit of peer review and advanced knowledge dissemination. This allows the field of Information Security to grow in breadth and depth and continue in its pursuit of highly advanced, scientifically based knowledge. -
Volunteer (Registration / QM)
BSidesSF
- 2 years
Science and Technology
https://bsidessf.org/
BSides San Francisco is a non-profit organization designed to advance the body of Information Security knowledge by providing an annual, two-day, open forum for discussion and debate for security engineers and their affiliates. We produce a conference that is a source of education, collaboration, and continued conversation for information technologists and those associated with this field. The technical and academic presentations at BSidesSF are given in the spirit of…https://bsidessf.org/
BSides San Francisco is a non-profit organization designed to advance the body of Information Security knowledge by providing an annual, two-day, open forum for discussion and debate for security engineers and their affiliates. We produce a conference that is a source of education, collaboration, and continued conversation for information technologists and those associated with this field. The technical and academic presentations at BSidesSF are given in the spirit of peer review and advanced knowledge dissemination. This allows the field of Information Security to grow in breadth and depth and continue in its pursuit of highly advanced, scientifically based knowledge.
View Jonathon’s full profile
-
See who you know in common
-
Get introduced
-
Contact Jonathon directly
Other similar profiles
Explore more posts
-
Revibe Digital
70 followers
Hummingbird (WPMU DEVs caching/speed plugin) just got a critical RCE write-up: CVE-2026-83627, versions up to 3.21.0. Short version: if Page Caching + Debug Log are on, an unauthenticated attacker can push PHP into a web-accessible log file. Non-default settings, but nasty when they’re enabled. If you run Hummingbird on any client sites, patch past 3.21.0 and turn debug logging off unless you actively need it. Then check the uploads/logs paths for anything that shouldn’t be there. This is why fleet ops matter. One plugin, many sites, same blind spot. CMS Inspect is built for WordPress and Joomla fleets — uptime, safer updates, backups, and a clear view of what’s still sitting on an old version. https://cmsinspect.com #CMSInspect #WordPress #Hummingbird #WebOps #RevibeDigital
-
JFrog
111K followers
Stop switching tabs. Start shipping verified artifacts. JFrog is officially live on the Cursor Marketplace! You can now bring JFrog’s #SoftwareSupplyChain security directly into your AI-native IDE. Ask Cursor to check for vulnerabilities, and it will use JFrog's verified security data to analyze your code and recommend precise remediation. 🛠️ Install now: https://lnkd.in/gUZUP-2d #CursorAI #DevSecOps #AI
130
-
Move78 International
4 followers
If your org is running OpenClaw, MoltBot, or ClawdBot — or evaluating any autonomous AI agent stack — this is your wake-up call. Here's what happened in the last 72 hours: → CVE-2026-25253: One-click RCE via malicious links (CVSS 8.8–9.8) → 21,000+ publicly exposed OpenClaw instances found with weak/no auth → Malicious "skills" on ClawHub delivering malware & credential theft → China's MIIT: "High security risk due to blurred trust boundaries and over-privileged operations" The pattern is clear: Agentic AI = high privilege automation, not "just a chatbot." Regulators now treat these agents like RMM tools — because a single misconfigured instance can cascade across your entire environment. Three things you need to do this week : 1. Audit: Scan for public facing agent gateways; verify auth, TLS, network ACLs 2. Isolate: Move agents to dedicated, segmented hosts with egress control 3. Govern: Freeze marketplace skill installation until you have a vetting pipeline We're tracking this daily for our clients. DM if you need a rapid risk assessment or OpenClaw hardening roadmap. 📎 Sources: MIIT NVDB advisory, Belgian CCB alert, runZero CVE analysis
1
3 Comments -
ALTIORE LABS
75 followers
Manifold just closed an $8M seed to secure autonomous endpoint AI agents at runtime. Their focus is runtime protection, not just post-event monitoring. This means any business shipping LLM agents on endpoints is staring down a new attack surface. Product, security, and data teams who roll out agents now need to rethink mutation, drift, adversarial input, and what runtime actually covers. This is exactly what we build at Altiore Labs. Our AI SaaS development and Enterprise AI Automation projects already implement runtime agent controls, not just static rules. If this is relevant to your stack, see how we build secure agent systems at https://lnkd.in/dMYAp9RK. What’s your procedure if an endpoint agent goes rogue today?
-
Vistem Solutions, Inc.
322 followers
If your organization uses JFrog Artifactory, treat this as urgent. Admin-level access can put software pipelines, artifacts, credentials, and downstream systems at serious risk. Security teams should act immediately: ✅ Apply the latest JFrog patches ✅ Review admin token activity ✅ Rotate credentials and secrets ✅ Restrict network access to Artifactory ✅ Check logs for suspicious authentication events Your software supply chain is only as secure as the systems protecting it. Need help reducing risk and strengthening cyber resilience? Vistem Solutions is here to help. 📩 sales@vistem.com #Cybersecurity #JFrog #Artifactory #SupplyChainSecurity #VulnerabilityManagement #BusinessSecurity #CyberResilience #VistemSolutions #VistemElevate
-
P0 Security
3K followers
The next era of identity security just landed! 🚀 Yesterday we launched NHI Management and the Authz Control Plane for AI agents, bringing humans, machines and first‑party AI agents under one unified access model for the first time. We’ve eliminated standing permissions and now enforce least‑privileged access at runtime, ensuring automation and AI agents can only act within approved policy and intent. See what’s new in this release — and how P0 enables innovation without compromising security: https://lnkd.in/gkbgd634
6
-
Josh Bressers
Open Source Security Podcast • 6K followers
I was thinking about what could be a second order effect from the #CRA for #opensource developers The CRA does have carve outs that spare individual open source contributors from many of the requirements, but I wonder if we will see those projects receiving requests from companies to provide evidence While the companies using the software are on the hook to track #security #vulnerabilities and evidence like #SBOM, there's nothing stopping those companies from asking an open source developer to help them out, just this once Now multiply this by several thousand and we have a problem I would value thoughts from Roman Zhukov and Daniel Thompson-Yvetot, am I missing something important?
9
23 Comments -
HackTricks
43K followers
AWS CodeBuild: when your CI/CD pipeline becomes your attack surface Researchers at Wiz uncovered how an unanchored regex in CodeBuild webhook filters allowed attackers to bypass trust checks on pull requests. This made it possible to run arbitrary code in privileged build environments, dump in-memory credentials, and ultimately take over critical GitHub repositories, including the JavaScript SDK used by the AWS Console itself. Once a malicious PR runs in CI, attackers can steal tokens and push code to trusted branches, turning a small pipeline misconfiguration into a supply-chain attack. CI/CD is critical infrastructure, if untrusted PRs can trigger privileged builds, one mistake is enough. In HackTricks Training we’ve added a brand-new lab reproducing this exact attack path, so you can practice it hands-on in a realistic environment: https://lnkd.in/e2gQYX5x Learn how AWS CodeBuild misconfigurations can lead to full supply-chain compromise: https://lnkd.in/eE9VYU9G #AWS #CodeBuild #CloudSecurity #SupplyChain #DevSecOps #RedTeam #Security
63
-
Benjamin Fabre
La French Tech New York • 9K followers
Attackers are now using AI to reverse-engineer client-side security logic in minutes. Traditional JavaScript obfuscation is no longer sufficient when LLMs can decompile, analyze, and reconstruct protection mechanisms at scale. That’s why we’re excited to announce the release of Virtual Machine (VM) obfuscation for DataDome Device Check & Slider, our most significant advancement in client-side protection to date. Instead of shipping readable detection logic to the browser, we execute it inside a custom virtual machine. The detection code is transformed into bytecode that is interpreted at runtime, dramatically increasing the complexity and cost of reverse engineering, for both humans and AI systems. Combined with dynamic code regeneration and WebAssembly, this creates a layered client-side defense designed for the AI era, with zero impact on performance. Hang tight, this is just the beginning! For the more technical among you, you can dive into all the details here: https://lnkd.in/eZ3gptnJ
29
1 Comment
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content