Thomas Garnier (@mxatone) 's Twitter Profile
Thomas Garnier

@mxatone

Horizontal Security Lead at Databricks. Worked at Google and Microsoft. Co-creator of Sysinternals Sysmon and Linux KRSI.

ID: 217011857

calendar_today18-11-2010 10:15:01

4,4K Tweet

2,2K Followers

380 Following

LaurieWired (@lauriewired) 's Twitter Profile Photo

I believe I just discovered a novel technique to get ChatGPT to create Ransomware, Keyloggers, and more. This bypasses the "I'm sorry, I cannot assist" response completely for writing malicious applications. More details in the thread.

I believe I just discovered a novel technique to get ChatGPT to create Ransomware, Keyloggers, and more.

This bypasses the "I'm sorry, I cannot assist" response completely for writing malicious applications.

More details in the thread.
Paul Rascagnères (@r00tbsd) 's Twitter Profile Photo

If you missed it yesterday, Microsoft released an advisory concerning the CVE-2023-36884: msrc.microsoft.com/update-guide/v…. This RCE is currently used by a TA and there is no patch. You should apply the mitigation described in the advisory. 1/4

If you missed it yesterday, Microsoft released an advisory concerning the CVE-2023-36884: msrc.microsoft.com/update-guide/v…. This RCE is currently used by a TA and there is no patch. You should apply the mitigation described in the advisory. 
1/4
Matei Zaharia (@matei_zaharia) 's Twitter Profile Photo

We're very excited to be one of the launch partners for Meta's Llama 2 🦙! We got to test Llama 2 in advance and were very impressed. The new version also has a much more permissive license. We've set everything up so you can run it on Databricks today. sprou.tt/1jAGDwOR7kX

Giuseppe Navarria (@b4dc0ffee) 's Twitter Profile Photo

Lol someone on reddit made a post about a made up feature introduced in WoW so that a news site using AI-driven scraping bots published an article about it and it worked

Lol someone on reddit made a post about a made up feature introduced in WoW so that a news site using AI-driven scraping bots published an article about it and it worked
Oliver Chang (@halbecaf) 's Twitter Profile Photo

The OSS-Fuzz team has been very busy the past few months in leveraging LLMs for fuzzing harness generation. See our initial results here! google.github.io/oss-fuzz/resea…

billy leonard (@billyleonard) 's Twitter Profile Photo

🚨 DPRK 🇰🇵 campaign against security researchers - new from Google TAGs Maddie Stone clem1 Adam on new 0day ITW and potential infection through a tool aimed at helping the research community. as wu said protect ya neck kids 🦇 blog.google/threat-analysi…

Bill Marczak (@billmarczak) 's Twitter Profile Photo

The way Kaspersky wrote this, it's an interesting case study of defenders working out how to capture a zero-click exploit. I especially like that Kaspersky said what they tried that *didn’t work*, in addition to what did ultimately work. Let’s dive in with a thread!

Thomas Garnier (@mxatone) 's Twitter Profile Photo

100%. Every security researcher should learn to code. It helps to understand how hard something is to fix. Security and engineering can partner better, get rid of classes of issues or lower the chances of common mistakes.

Ali Ghodsi (@alighodsi) 's Twitter Profile Photo

The founders of Databricks put together this strategy blog on where we think data platforms are headed in the future. We're moving Databricks quickly in this direction. This is very exciting and is the outcome of the MosaicML acquisition we did earlier this year!

Matei Zaharia (@matei_zaharia) 's Twitter Profile Photo

As good a time to say this as any: if you’re on the AI research job market, Databricks is hiring, with the mission to democratize AI. We power amazing customer use cases and we publish. Check databricks.com/company/careers or reach out.

LiveOverflow 🔴 (@liveoverflow) 's Twitter Profile Photo

The fact that they developed a complete zero-click to kernel chain, JUST to then force the device to open a web page to trigger the "real" chain, is the most bureaucratic exploit I can imagine 🙈 koeln.ftp.media.ccc.de/congress/2023/…

The fact that they developed a complete zero-click to kernel chain, JUST to then force the device to open a web page to trigger the "real" chain, is the most bureaucratic exploit I can imagine 🙈

koeln.ftp.media.ccc.de/congress/2023/…
Ali Ghodsi (@alighodsi) 's Twitter Profile Photo

Today we released an open source model, DBRX, that beats all previous open source models on the standard benchmarks. The model itself is a Mixture of Experts (MoE), that's roughly twice the brains (132B) but half the cost (36B) of Llama2-70B. Making it both smart and cheap. Since

Yanir Tsarimi (@yanir_) 's Twitter Profile Photo

I hacked Microsoft's AI bot for healthcare on a Friday night Within hours I could access data of multiple healthcare organizations, but it didn't stop there Microsoft fixed the issue, and then I did it again, and again, and again.. Here's the story of Lethal Injection: 💉

I hacked Microsoft's AI bot for healthcare on a Friday night

Within hours I could access data of multiple healthcare organizations, but it didn't stop there

Microsoft fixed the issue, and then I did it again, and again, and again.. 

Here's the story of Lethal Injection: 💉
Ryan T. Brown 🎮🩷 (@toadsanime) 's Twitter Profile Photo

There may never have been a day as big as today for indie games. On the back of mass layoffs of major AAA studios, today more high-profile and under-the-radar gems are releasing on May 9th than any other day in recent memory. They need your support. Here's a thread of 'em! 🧵

There may never have been a day as big as today for indie games. 

On the back of mass layoffs of major AAA studios, today more high-profile and under-the-radar gems are releasing on May 9th than any other day in recent memory. They need your support.

Here's a thread of 'em! 🧵
Databricks (@databricks) 's Twitter Profile Photo

Serverless compute is now GA! ✅ Focus on writing code while we handle the rest. Enjoy fully managed compute infrastructure with fast workload startup, high reliability, and simple operation. Learn more about our latest updates: bit.ly/3zPsCXp

Serverless compute is now GA! ✅ 

Focus on writing code while we handle the rest. Enjoy fully managed compute infrastructure with fast workload startup, high reliability, and simple operation.

Learn more about our latest updates: bit.ly/3zPsCXp