insane new research from my colleague, Joe
tl;dr @gitlab gives you a private email address to create issues. If leaked, anyone who has it can push code, execute CI/CD jobs, and bypass IP restrictions across all of your public and private projects. 🙃
As a @deel customer ourselves, we've seen firsthand how their platform simplifies hiring a distributed team. Now we're an official Deel partner, giving Deel's customers a direct path to Aikido's security platform through the same relationship they already have.
Learn more:
We ran GPT-6 Luna and Sol on our 32-CVE cyber benchmark and the results were unexpected! 🤯
Luna rediscovered 53.1%
Sol reached 68.8%
Neither beat GPT-5.6 variants on recall
But both got A LOT cheaper per vulnerability found:
Luna $3.43 → $2.01/CVE
Sol $56.88 → $34.18/CVE
🧵 1/3
We're tracking the "supplychain.local" worm, which hit the MemTensor npm and pypi packages:
npm: [@]memtensor/memos-cloud-openclaw-plugin@0.1.25
pypi: MemoryOS@2.0.34
It contains a novel worm, written in Go. Seems likely to be written by LLMs.
I've had a lot of conversations lately about LLM models, cyber security, and sovereignty. So I'm really excited about the news that we've started investing into sovereign security intelligence that can run inside the environment it protects.
👁️ you can preserve capabilities despite pruning to get the cost per task down.
Artisan pruning, retained 92% of BF16's recalls at just 21.4% of the original size (:
I'm excited to announce Altar-1, our first open-weight security model.
The first of many to come from @AikidoSecurity's wider investment in applied AI research to advance the performance and accessibility of security intelligence for all.