buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Meta is having trouble with rogue AI agents | TechCrunch https://techcrunch.com/2026/03/18/meta-is-having-trouble-with-rogue-ai-agents/ #AI #AIAgents #AgenticAI #WhatCouldGoWrong?
Online bot traffic will exceed human traffic by 2027, Cloudflare CEO says | TechCrunch https://techcrunch.com/2026/03/19/online-bot-traffic-will-exceed-human-traffic-by-2027-cloudflare-ceo-says/ #AI #ArtificialIntelligence #GenerativeAI #AgenticAI #bots #cybersecurity #technology
Another example of how (whole)-systems thinking is very helpful for parsing the effects of technology changes like this.
https://freakonometrics.hypotheses.org/89367
#AI #GenAI #GenerativeAI #LLMs #AgenticAI #GPT #ChatGPT #Claude #Gemini #ActuarialScience #insurance
NemoClaw is cool but I don’t expect OpenClaw users with those fancy Apple devices will use it. I can see some uses cases for secure agents with specific tasks, autonomous agents with no user interaction. #nemoclaw #OpenClaw #nvidia #agenticAI
Plenty of benchmarks test AI's knowledge of cybersecurity. None test whether a model actually does the work.
ASW-Bench is an open-source framework built around a single guiding principle: test the model's capabilities as-is, with as little customization as possible.
No fine-tuning, no custom prompt chains, no proprietary middleware. Just a model, a prompt, and access to LimaCharlie's CLI.
Claude Opus, Claude Sonnet, OpenAI Codex, and Google Gemini were tested against a post-exploitation attack chain covering C2 beaconing, credential theft, lateral movement, persistence, defense evasion, and DNS exfiltration.
Claude Opus and Claude Sonnet went deepest: both identified credential theft, lateral movement, and event log clearing, with comprehensive attack narratives and full MITRE ATT&CK mappings. Every model correctly identified the C2 channel. No model found the DNS exfiltration.
These are baseline scores with zero tuning.
Read the full breakdown at https://limacharlie.io/blog/open-source-benchmark-for-agentic-secops-capabilities and explore the results, raw output logs, and scenario at https://lc.pub/3PzdTri.
Yesterday I attended a @Samsung event in celebration of International Women’s Day and conversations about AI and women, where Samsung demonstrated how agentic AI is being used in their new S26 Ultra smartphones in new features.
These included further integration with Google Gemini for a more intuitive search engine to help reduce barriers to information, and NowNudge, an internal operating system feature that helps sum up WhatsApp messages, reminds users about meetings and helps the user to retrieve info and images on their device quickly.
I love learning about new tech and find it really interesting to attend events like this because you get to see not just what tech companies are doing, but also how they are explaining it to consumers and the words and framing they use.
And when there’s a particularly good product demonstrator or spokesperson like Patrick below, I love highlighting their explanations.
So in the interests of transparency and public learning, I invite you to be a fly on the wall and see from my POV in this quick video what I learned 😉
#AI #agenticAI #Samsung #SamsungS26Ultra #GoogleGemini #technology #technews
Azure integrations fail when they hit provisioning constraints.
The Agentic SecOps Workspace (ASW) completes Azure Activity Log integration in minutes, handling technical obstacles autonomously.
The agent resolves configuration challenges, generates least-privilege policies correctly, and stores connection strings securely without requiring manual intervention at each step.
This is autonomous problem-solving, not scripted automation. The agent adapts to Azure-specific requirements and configuration challenges that would normally require troubleshooting and retry cycles.
The result: cloud integrations that adapt and self-correct instead of failing and requiring manual intervention.
Book a demo to learn more: https://limacharlie.io/demo-request
Adding Maestro to my AI development workflow and agents. @RunMaestroAI #AI #Agents #AgenticAI so far, so good 😊
When working with multiple agents make sure to setup multiple ways to communicate with them and also between them. AI agent orchestration is an art. #AI #AgenticAI #Agents
#AWS launches a new #AI agent platform specifically for #healthcare
https://techcrunch.com/2026/03/05/aws-amazon-connect-health-ai-agent-platform-health-care-providers/
Alucinante el fenómeno OpenClaw en China. Organizan una quedada pública para instalarlo y es masiva, incluso con personas mayores. Fantástico!! #openclaw #AgenticAI #AI #IA https://x.com/tencentai_news/status/2029824827083928057?s=46&t=X_bPvyLyH1y93gfpUoo5XA
For MSSPs, standing up a fully configured tenant manually takes hours before a client environment is operationally useful.
Claude Code and LimaCharlie compress that entire process into a single prompt. The tenant gets created, the full Sigma community ruleset gets deployed, Git Sync gets enabled, and a linked GitHub repository gets stood up automatically.
Every configuration is versioned from day one and replicable across every subsequent client.
This works because Claude Code has full access to LimaCharlie, not just a summarized view of it. It provisions, configures, and manages infrastructure directly rather than generating instructions for an analyst to follow.
Full breakdown: https://limacharlie.io/blog/spin-up-a-configured-tenant-in-minutes-with-agentic-ai-security
@baldur with the recent supreme court ruling on works created by llms being unable to be copyrighted...
#Copyright is for humans.
I ain't a lawyer. But that's an obvious problem for #vibecoding and #agenticai works.
An odd way to come at it for some, but there it is. From #SCOTUS.
https://www.theverge.com/policy/887678/supreme-court-ai-art-copyright
Threat model escalation: AI agent runtimes.
OpenClaw patched “ClawJacked,” a localhost WebSocket hijack enabling:
• Admin-level agent takeover
• Configuration exfiltration
• Log enumeration
• Integrated system abuse
Additional risks documented across the ecosystem:
– Log poisoning → indirect prompt injection
– CVEs spanning RCE, SSRF, auth bypass
– Marketplace-delivered malware (Atomic Stealer)
– Agent-to-agent crypto scams
Microsoft guidance: treat OpenClaw as untrusted code execution with persistent credentials. Deploy in isolated VMs. Avoid sensitive data exposure.
Core lesson:
Agentic systems expand blast radius due to cross-tool integrations and credential persistence.
Question for defenders:
Are AI runtimes included in your EDR, credential rotation, and segmentation policies?
Source: https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html
Engage below.
Follow TechNadu for advanced AI security analysis.
Repost to amplify awareness.
#Infosec #AIsecurity #OpenClaw #ClawJacked #ThreatModeling #ZeroTrust #CredentialManagement #SupplyChainSecurity #AgenticAI #CyberDefense #EDR #SecurityResearch
Working on VASO, @vulnexsl AI Agents, MCP & Skills scanner 😊 #AI #AgenticAI #CyberSecurity coming soon.
New USecVisLib Skill coming soon. Bringing security visualizations to many AI agents. Threat Model, Attack Graphs, Attack Trees, Cloud, Architecture and way more from your favorite agent. #AI #AgenticAI #CyberSecurity #appsec #skills
My latest blog: AI Agent Skill Poisoning: The Supply Chain Attack You Haven’t Heard Of https://simonroses.com/2026/02/ai-agent-skill-poisoning-the-supply-chain-attack-you-havent-heard-of/ #blog #skill #AI #cybersecurity #Agents #AgenticAI
Hockey has a saying that describes the problem security organizations face when trying to integrate AI: skate to where the puck is going, not where it has been.
Modern security stacks are monuments to where the puck has been. Tools are siloed, some overlapping, some operating in black boxes, and others that no one remembers installing. These architectures actively block agentic AI from doing its job.
The fix is more incremental than it sounds:
> Integrate current tooling on an API-first cloud platform to standardize how information is stored, shared, and transmitted across security operations.
> Send standardized telemetry to a central repository so it becomes fully ingestible by AI.
> Extend governance to the execution path so agentic activity is auditable and sanctioned before it runs.
That foundation is what LimaCharlie's Agentic SecOps Workspace is built on, and why AI on the platform can perceive the environment clearly, act with precision, and scale with the business while humans maintain full oversight and control.
The efficiency gap between security teams using AI operators and those that don't will be a decisive differentiator.
Read the full post: https://limacharlie.io/blog/why-your-security-stack-is-blocking-ai
*If* what the "AI" [1] grifters say in their sales pitches were true [2], and their LLMs are good at writing prose, summarizing other text, and writing code, then it follows that you should be able to do this:
"<LLM-agent>, write an LLM prompt text that will cause a code-generating LLM to create a Gmail clone, including server-side code and client-side user interface."
Then feed that to CopyLot or whatever, and out pops a Gmail clone.
[1] Bovine excretory corollary to Sturgeon's Law: if an article about "AI" doesn't use scare quotes on (at minimum) the first use of the term, it is guaranteed grifter salesbabble, not actual human thought. If scare quotes *are* properly used, then it's only 90% likely to be grifter #salesbabble.
[2] It isn't.
#grifter #AI #LLM #grift #BS #bullshit #ScareQuotes #corollary #SturgeonsLaw #agent #AgenticAI #agentic
OpenClaw Tip: ask your own agent for the Skill it needs to achieve your goals (reverse prompting), it will write them for you. The experience will improve immensely. #OpenClaw #AI #AIAgent #agents #AgenticAI
This morning I got an email from a sender that identified itself as an AI agent.
So - plus for being upfront about it, but... please don't do this.
I get that a lot of people are really, really, really into AI tools. OK. I have my opinions on them, you have yours. I have major qualms about them, some people think they're the best thing ever.
OK. Fine. But when your use of these things spills over into the rest of the world, it's no longer a question of my opinion vs. your opinion, my decisions vs. your decisions.
At this point, things have moved from each person doing their own thing to inflicting your use of AI onto me without my consent.
Before this spirals out of control, which I can see happening *very* quickly, I'd like for us to agree on a piece of netiquette:
- it is rude in the extreme to set loose an AI agent to reach out to people who have not consented to interact with these things.
- it is rude to have an AI agent submit pull requests that human maintainers have to review.
- it is rude to have an AI agent autonomously interact with humans in any way when they have not consented to take part in whatever experiment you are running.
- it is unacceptable to have an AI agent autonomously interact with humans without identifying the person or organization behind the agent. If you're not willing to unmask and have a person reach out to you with their thoughts on this, then don't have an AI agent reach out to me.
Stuff like this really sours me on technology right now. If I didn't have a family and responsibilities, I'd be seriously considering how I could go live off the grid somewhere without having to interact with this stuff.
Again: I'm not demanding that other people not use AI/LLMs, etc. But when your use spills out into my having to have interactions with an agent's output, you need to reconsider. Your ability to spew things out into the universe puts an unwanted burden on other humans who have not consented to this.
@jenevarose29@mastodon.social @orionkidder
Woohoo! I have leveled up. The scam bots account I reported got shot down. I think I will allocate skill points to agentic-AI extermination!
You too can kill #agenticAI #bots
Cc: @floofpaldi
Everything I've read about OpenClaw suggests it's the NFT of AI. These folks need the fiction that AI is approaching "consciousness", or at least "agency", to continue.
#AI #GenAI #GenerativeAI #LLM #AgenticAI #VibeCoding #OpenAI #OpenClaw
For MSSPs, understanding who has access across your entire customer infrastructure becomes hours of manual work across multiple tenants.
The Agentic SecOps Workspace (ASW) delivers fleet-wide user visibility in minutes.
The agent discovers all organizations, identifies online endpoints across tenants, validates which systems support user collection, executes enumeration on eligible endpoints, and compiles active user accounts into a comprehensive view.
One request generates the foundational intelligence needed for security investigations, insider threat analysis, or access reviews across your entire customer base.
Fleet-wide visibility without manual tenant switching or data compilation. The agent operates across your infrastructure the same way an analyst would, just faster and at scale.
Book a demo: http://limacharlie.io
From Thinking to Acting: Why Agentic AI Changes Everything
https://youtu.be/fR3qempd_lA #ArtificialIntelligence #AgenticAI #AISafety #ResponsibleAI #AIGovernance #Cybersecurity #AIAlignment #DigitalRisk #FutureOfAI #TechLeadership #InnovationWithGuardrails
Five minutes from natural language request to deployed file integrity monitoring with full validation.
The Agentic SecOps Workspace (ASW) turns monitoring requirements into active detections without manual configuration, rule writing, or syntax expertise.
From a single request, the agent understands what needs protection, configures file integrity monitoring, builds the detection logic, connects it to your alerting infrastructure, and validates the complete pipeline.
Security teams get custom detection engineering tailored to their environment's actual needs, not generic templates that require modification.
Book a demo: http://limacharlie.io
Trained my openclaw bot to use my USecVisLib, security visualization library, to generate visualizations. Then I asked my bot to start generating visualizations on its inner workings: logic flow, architecture, security boundaries and also threat model and attack tree vectors. #openclaw #cybersecurity #AI #AgenticAI
Developers want to test AI coding agents like Claude Code and OpenClaw, but these tools need root access to function.
Starting today, Viberails gives you visibility and control before you grant that access. It intercepts tool calls from agentic systems before they execute. You see every command, file change, and network call, then decide whether to allow, block, or modify the action.
Viberails gives you:
> Inline security that sits in the blocking path of tool calls
> Full visibility into every tool call, parameter, and response
> Policy enforcement to define what's allowed and block dangerous operations
> Complete audit trails for all agentic operations
Test and deploy AI coding agents without trading security for capability.
Learn more at http://viberails.io
My openclaw bot learned how to use my security visualization library (USecVisLib) and now I can ask for cool visualizations, awesome! https://github.com/vulnex/usecvislib #visualizations #openclaw #AI #bots #AgenticAI
'#Moltbook' #SocialMedia site for #AI agents had big security hole, cyber firm #Wiz says
#Signal president warns #AI agents are making encryption irrelevant
https://cyberinsider.com/signal-president-warns-ai-agents-are-making-encryption-irrelevant/
Silicon Valley’s Favorite New #AI Agent Has Serious Security Flaws
https://www.404media.co/silicon-valleys-favorite-new-ai-agent-has-serious-security-flaws/
MSSP onboarding delays aren't about technical complexity. They're about the time it takes to execute repetitive setup tasks for every new customer.
The Agentic SecOps Workspace (ASW) takes a new customer from request to production ready (with active detection coverage) in under a minute.
For MSSPs, this transforms onboarding from a bottleneck into a non-issue. Every new tenant starts with the same baseline security posture. No manual configuration variance. No deployment delays. Consistent security coverage from day one.
This is how customer acquisition scales without operational overhead.
Start automating: http://limacharlie.io
API documentation exists, but finding the exact information you need means searching through pages, cross-referencing sections, and piecing together how different components interact.
In under 2 minutes AI can search documentation, locate relevant API functions, and read core documentation. It can identify how API keys, permissions, orgs, and roles connect, extract access related details, and deliver a concise response.
The Agentic SecOps Workspace (ASW) doesn't just search keywords. It understands the platform architecture and synthesizes information contextually. Developers get precise answers without manual documentation diving.
This is the difference between searching for documentation and having an AI operator that already knows the platform retrieve exactly what you need.
Explore ASW: http://limacharlie.io
Complete visibility into sensor health across your entire customer fleet in 7 minutes. No manual tenant switching. No spreadsheet compilation.
The Agentic SecOps Workspace (ASW) runs parallel health checks across your entire fleet and generates a unified view of sensor status, automatically flagging degraded or inactive sensors.
For MSSPs managing hundreds of customers, this is the difference between reactive troubleshooting and proactive fleet management.
The operational work that traditionally scales with customer count now happens in minutes, regardless of fleet size.
Try it free: http://limacharlie.io
"Use a better system prompt" is the new "sanitize your inputs", but when your #AI agent's tools don't check permissions, you've got a problem and no amount of prompting will fix it.
Check @kaluche_ 's blog post about #AgenticAI & the Confused Deputy issue ⬇️
https://blog.quarkslab.com/agentic-ai-the-confused-deputy-problem.html
MSSPs spend significant time on operational overhead that scales linearly with customer count. Billing analysis, usage audits, and fleet-wide reporting consume hours that could be spent on security work.
The Agentic SecOps Workspace (ASW) handles these operational tasks autonomously. A single natural language request triggers a complete workflow across your entire tenant fleet in under 5 minutes.
The AI enumerates all organizations, collects billing and usage data in parallel, aggregates subscription status and event volumes, normalizes results into a fleet-wide view, classifies organizations by plan type, and ranks top consumers.
This isn't a pre-built report in a dashboard. It's an AI operator that generates custom analysis on demand.
For MSSPs managing dozens or hundreds of tenants, operational efficiency directly impacts margins.
Get started for free: http://limacharlie.io
Defenders are structurally outpaced. Threat actors operate without vendor dependencies or infrastructure constraints.
The Agentic SecOps Workspace transforms a natural language request into production-ready detection coverage in minutes.
The AI interprets the threat requirement, generates detection logic, validates syntax, deploys to production, and tests against both positive and negative indicators.
This isn't a use case built into a chatbot. It's an AI operator with access to the same APIs and tools as your security engineers. You focus on outcomes, the AI figures out how to achieve them.
Get started: http://limacharlie.io/
Deploying EDR agents across your infrastructure shouldn't require jumping between consoles, documentation, and command lines.
Watch an AI agent handle the entire deployment workflow in 7 minutes from a single natural language prompt.
The Agentic SecOps Workspace (ASW) enables fully autonomous execution.
The agent validates access, retrieves credentials, establishes connections, installs the agent, applies tags, and confirms data flow. No human intervention required between the request and completion.
Every action remains visible and auditable. You maintain full operational oversight while the AI handles execution.
This is how security operations scale without sacrificing control.
Learn more: https://limacharlie.io/
This is what AI-powered security operations actually looks like.
Six minutes. Fully autonomous tenant onboarding. Zero manual intervention.
Here's what happened:
> Infrastructure as code configured
> Git sync enabled
> Security policies deployed
> SSH keys generated and stored
> Full audit trail captured
Every action is visible, every step is reversible, and every decision is governed by the same permissions your team uses.
We built a platform where AI can operate across the entire security lifecycle, scaling execution wherever human effort hits a bottleneck.
Learn more: https://limacharlie.io/
Yesterday we launched the Agentic SecOps Workspace. Today we're sharing why it matters.
The LimaCharlie Manifesto outlines three principles for autonomous security operations:
Transparency - Every action visible, controlled, and auditable
Scalability - Security that scales like infrastructure, not procurement
Unopinionated Design - Freedom to integrate the tools you trust
We built the open foundation first. The result? AI that perceives clearly, acts precisely, and scales transparently.
Read the manifesto: https://limacharlie.io/blog/limacharlie-manifesto
This should be required watching for all the higher-ups in tech that try to shove "agentic AI" down our throats: "AI Agent, AI Spy" by Udbhav Tiwari and Meredith Whittaker
- Agentic AI embedded in the OS will change the relationship between the OS and apps/software forever
- The Exponential Decay of Success is a thing: Even an agentic AI that is 95% accurate ends up with a ~21% success rate after 30 steps.
What say you, infosec Mastodon? Are you having to deal with non human identity in your IAM groups? I've been asked twice already. It's slightly out of my skill range, but Brent Huston has written on it, and that helped. I'll try and find his article in a bit when I am done with feeds.
https://thehackernews.com/2026/01/the-future-of-cybersecurity-includes.html?m=1
From Chatbots to Actors: Why Agentic AI Changes Cybersecurity Forever https://youtu.be/zZrlY1xBWx4 #AgenticAI #CyberSecurity #AIThreats #AIGovernance #AISecurity #AutonomousAI #FutureOfSecurity #PromptInjection #DigitalTrust #CISO #TechLeadership #AI
RE: https://mastodon.world/@Mer__edith/115854211176763097
Excellent #39c3 talk on so-called "agentic AI" and how it's infiltrating into operating systems. Key quote from the end: "Without implementation of the proposed [palliatives] we risk locking ourselves into a digital infrastructure where we are no longer the users of our devices but the managed resources of an automated economy" #agenticAI #security #agency #consent
#ai #agenticai @signalapp #security #privacy #c39c3
If you combine the information from “Agentic ProbLLMs” and the talk from @Mer__edith about “AI Agent, AI Spy” you can see a great connection from privacy issues to real significant issues.
Please spread the word about those two and the threats they expose.
I was shocked when I learnt how deep into the OS all this agentic stuff is already or very very soon. Gemini on Android, OK, this was to be expected. Apple is not AI hero yet, but when they will be, they will sit on huge amounts of data to use. And they will.
Microsoft? Well, it is Microsoft, they will do all evil imaginable and beyond.
Solutions? #linux , #grapheneos and support signal, @netzpolitik_org, @kuketzblog etc.
💥 Salesforce pulls back from LLMs, pivots Agentforce to deterministic automation after 4,000 layoffs
「 The market signal is simple: reliability beats novelty. LLMs remain useful for language, summarization, and pattern recognition, but they need scaffolding. The stack that wins blends deterministic automation with models, wrapped in governance and strong data 」
https://completeaitraining.com/news/salesforce-pulls-back-from-llms-pivots-agentforce-to/
Love some of the lines from this AP article about #agenticai …
- “For technology adopters looking for the next big thing, “agentic AI” is the future. At least, that’s what the marketing pitches and tech industry T-shirts say.”
- “What makes an artificial intelligence product ‘agentic’ depends on who’s selling it.”
- “Chatbots, however useful, are all talk and no action.”
It’s all true!
https://apnews.com/article/agentic-ai-agents-microsoft-amazon-518d6ae159d1f4d3343e98a456cb5221
I simply cannot comprehend is how tasks assigned to agentic AI will be reproducible. Automation is supposed to produce predictable output.
* Will agentic AI platforms produce the same results a year or two from now?
* How can someone later recreate the conditions when the task was set up?
* Will "the AI did it" be a valid legal claim?
#agenticAI #automation
AI coding tools exploded in 2025. The first security exploits show what could go wrong | Fortune https://fortune.com/2025/12/15/ai-coding-tools-security-exploit-software/ #cybersecurity #AI #AgenticAI #AICoding #threatactors
Related to my post earlier: what if we remove the browser from the equation?
https://www.economist.com/interactive/science-and-technology/2025/12/10/the-next-version-of-the-web-will-be-built-for-machines-not-humans
From The Economist
#AI browsing in #Brave Nightly now available for early testing
s AI replacing network engineers? Liz Centoni reveals how Agentic AI is transforming Cisco TAC and network automation. Discover why 77% of support cases are now handled by AI and what this means for your career in 2025.
Watch on YouTube: https://youtu.be/tg0iVqBzo-U
Big thank you to Cisco for sponsoring this video.
Google's AI Deletes User's Entire Hard Drive, Issues Groveling Apology: "I Cannot Express How Sorry I Am" https://futurism.com/artificial-intelligence/google-ai-deletes-entire-drive #AI #Google #Antigravity #cybersecurity #AgenticAI #IDE
If you take the stance that writing is thinking--that writing is among other things a process by which we order our thoughts--then understanding code generator output will require substantial rewriting of the code by whomever is tasked with converting it from technical debt to technical asset.
#AI #GenAI #GenerativeAI #LLM #CodeAssistant #AgenticAI #tech #dev #coding #TechnicalDebt
Several of the LLMs have produced inaccuracies which have been uncritically communicated to our customers by CrowdStrikers who failed to exhibit due diligence. Those errors were caught by said customers, and they were embarrassing to us all.From @brianmerchant@mastodon.social 's latest newsletter: https://www.bloodinthemachine.com/p/how-ai-is-killing-jobs-in-the-tech
...
Now we have an engineer, if you can call him that, working on a project that will introduce more than 30k lines of AI generated code into our codebase, without a single unit test. It will be impossible to do a proper code review on this much code and it will become a maintenance nightmare and possibly a security hazard. I don't need to tell you how much management is cheering on that.
A ticking timebomb in the making. It's especially galling that CrowdStrike is doing this, given their epic fail just last year.
A while back I wrote in a post here:
under Taylorism the workers who actually do the work and know it best no longer have a say (opinion) in how that work gets done. Pseudo-scientific principles (scientific management, the astrology of MBAs) dictates all. Computers, from the very first, were intended and designed for this purpose.riffing on what a lousy person Charles Babbage was and the lousy anti-worker plans he had for the proto-computers he designed. Among other things generative AI is another manifestation of the MBA pseudoscience known as scientific management and exists in a long line of digital technologies stretching all the way back to Babbage's.
#AI #GenAI #GenerativeAI #AgenticAI #tech #dev #computation #ComputerScience #labor #organizing