Heather Adkins - Ꜻ - Spes consilium non est
@argvee
Followers
14K
Following
3K
Media
479
Statuses
6K
VP Security @Google, Co-Author "Building Secure and Reliable Systems" @r00t0wns, Medieval Historian
California
Joined July 2008
BIG: A CNN investigation shows China has dramatically increased construction at more than 60% of 136 facilities tied to missile production and the PLA Rocket Force since 2020, adding over 21 million sq ft of new buildings. The buildup includes new bunkers, testing centers, and
31
271
839
Three Chinese men were arrested in Singapore for hacking websites with fraudulent permits, earning $3M in crypto, while holding sensitive data from foreign governments, and were sentenced to up to 28 months in prison. #CyberCrime #Hacking
channelnewsasia.com
The three men from China came to Singapore for a job offer posed by a Ni-Vanuatu citizen and were housed in a bungalow while they hacked into websites.
0
13
34
Fully automated kill chain isn’t far away. Great report from the Google Threat Intelligence Group.
Google Threat Intelligence Group details the ways threat actors are misusing AI tools, including how they are generating and executing AI-enabled malware. 🔗 Read this latest report on our blog: https://t.co/VfvwpLFQXn
0
4
19
I live in the real world and so I’m not really surprised to see this, but I am definitely shocked. As an incident response person, how do you spend all day supporting and watching your customer’s teams cope with the stress and grief of going through a ransomware incident and then
In a truly brilliant move, employees from DigitalMint and Sygnia, responsible for handling ransomware negotiations, were indicted for performing ransomware attacks under ALPHV ransomware group. - Kevin Tyler Martin, ransomware negotiator from DigitalMint - Ryan Clifford
1
2
20
Updated jmp (w @Henkel_JLuca) 1) Longer-horizon match quality data 2) Extended AI mechanism analysis 👇
1
3
25
This is a critical time where research is still emerging, and we remain committed to high-quality bug reports and fixes as things develop alongside our open source peers. Thanks to everyone who has dived into this discussion in the community – it’s an important one for the future
0
0
18
Beyond ffmpeg, we see Big Sleep, and its partner project Code Mender, as examples of vital tools that will become critical for the global OSS community. Long-term, we hope they can help development teams “shift left” on security, and automate the discovery and fixing of bugs
1
0
13
Finally, projects like ffmpeg are eligible for our long running Patch Rewards program ( https://t.co/M5w3uihhUr) that offers cash rewards for proactive improvements made to security in key open source projects ( https://t.co/7BjOaP0Q0j). 8/10
github.com
Contribute to google/bughunters development by creating an account on GitHub.
2
2
16
We’re also a customer of FFLabs ( https://t.co/7kIPQeoagv), a consulting company with some of ffmpeg’s core contributors, and have contracted with them in the past to build new features that everyone can use. 7/10
2
0
14
AI Infrastructure is exploding, where does “the network” stand? @Cisco President & CPO Jeetu Patel (@jpatel41) joins @DanielNewmanUV at Cisco’s Partner Summit to discuss the boom in AI infrastructure, emphasizing the pivotal role of the network in delivering secure, low-latency
0
1
6
As users of ffmpeg in our products, Google also makes regular contributions back to the project for performance and functionality improvements. https://t.co/xDmNEPXP8n 6/10
1
0
13
Google is also an advocate of ffmpeg’s goals. We have accepted the project into our Summer of Code program since 2006, as part of open source's longest running mentorship program supporting new contributors with direct funding. For example, in 2025: https://t.co/ANLoxeRwnj 5/10
summerofcode.withgoogle.com
Google Summer of Code is a global program focused on bringing more developers into open source software development.
1
0
19
Google has a long history of working to help improve the security of ffmpeg and protect its users. Between 2012 to 2014, Google worked closely with the project to report (and verify fixes) for over 1000 bugs found through fuzzing, which at the time was an emerging area of
security.googleblog.com
Posted by Mateusz Jurczyk and Gynvael Coldwind, Information Security Engineers At Google, security is a top priority - not only for our ow...
2
4
26
As part of the research process, the Big Sleep team has been looking at different code bases that present the models with unique technical challenges to solve. We believe transparency is very important, so these findings are shared in the Big Sleep tracker and currently include
1
1
16
Big Sleep and CodeMender are two projects between Google Deepmind and Project Zero to develop AI-first strategies for reasoning about code to find and fix software vulnerabilities. These projects are in their research phase, and as with all research projects, innovation will
deepmind.google
Using advanced AI to fix critical software vulnerabilities
1
2
19
We’re excited to see the security and OSS communities engage on vulnerability disclosure in light of new AI technologies that we believe will enable both defenders and attackers alike. Existing and emerging norms around disclosure are important debates, and we’ve noted the
6
32
98
At @NCSC we have just released guidance on using Privileged Access Workstations (PAWs) in Operational Technology (OT) environments.. https://t.co/UZkRYyNo6S
ncsc.gov.uk
Considerations for the use of Privileged Access Workstations (PAWS) in OT environments.
1
21
71
When I interviewed at Google 23+ years ago I was asked how I would do software upgrades on Mars. At the time I thought it was a fun hyperbolic scenario to tease apart the autonomy, reliability and safety elements of the problem. I guess they were serious about this computing in
Our TPUs are headed to space! Inspired by our history of moonshots, from quantum computing to autonomous driving, Project Suncatcher is exploring how we could one day build scalable ML compute systems in space, harnessing more of the sun’s power (which emits more power than 100
6
11
381
Shipping Containers, Logistics, Hacking... These are a few of my favorite things!
🚨 Hackers are now hijacking trucking/logistics firms — not just for data, but for the cargo itself. They’re loading up legit remote-management tools like ScreenConnect & LogMeIn, hijacking load-boards and booking real shipments of food/beverage. Read how →
0
0
1
Really great update from the DeepMind Code Mender project and their journey in writing safe code. Some great results so far. A ways to go!
deepmind.google
Using advanced AI to fix critical software vulnerabilities
0
5
14
A quick reminder of what’s really going on in the world… Now is not the time to stand still.
csoonline.com
AI agents are automating key parts of the attack chain, threatening to tip the scales completely in favor of cyber attackers unless new models of AI-assisted cyberdefense arise.
@DavidEGrayson It's someone's hobby project of an obscure 1990s decoder. A trillion dollar company is tasking an AI to find bugs and is assigning CVEs. Yet expects volunteers to fix it.
4
4
20