Trending
Thomas Roccia :verified:'s Avatar

Thomas Roccia :verified:

@fr0gger.infosec.exchange.ap.brid.gy

Sr. Security Researcher at Microsoft πŸŒ‰ bridged from https://infosec.exchange/@fr0gger on the fediverse by https://fed.brid.gy/

321
Followers
1
Following
242
Posts
01.12.2024
Joined
Posts Following

Latest posts by Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy

Original post on infosec.exchange

πŸ€“ I recently published a blog post with a controversial take!

This may be the end of malware analysis and reverse engineering as we know it.

I think AI will change the craft in ways most people are still underestimating.

I explain everything in this post πŸ‘‡ […]

13.03.2026 06:28 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ€“ Next month at @BlackHatEvents Asia, I will be teaching my training "Practical AI for Threat Intel: Real-World Agentic Workflows for Cyber Threat Intelligence."

It is packed with my latest research and labs.

You will learn how to:

- Build agentic […]

[Original post on infosec.exchange]

13.03.2026 00:04 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Original post on infosec.exchange

πŸ€“ You've been reading about it, now you can listen to it!

I recently joined Confidence Staveley on the AI Cyber Magazine podcast to talk about my latest work around AI threat intelligence, IoPC, MoltThreats, agent monitoring, and Nova!

Check this out to learn about the AI security trenches! πŸ‘‡ […]

10.03.2026 01:49 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

In a recent report from Socket, a compromised release of the Aqua Trivy VS Code extension on OpenVSX (v1.8.12 and v1.8.13) contained unauthorized code that injected prompts targeting local AI coding agents such as Copilot, Claude, and Codex.

The prompts […]

[Original post on infosec.exchange]

06.03.2026 10:09 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Original post on infosec.exchange

πŸ€“ New blog post on the Nova ecosystem for prompt hunting!

@pedrinazzim just released the Nova Rules Validation and Testing Pipeline, it is designed to automatically validate, test, and evaluate Nova rules!

As the rules repo grow, this will help us keep the repository reliable and avoid […]

04.03.2026 06:50 πŸ‘ 0 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

πŸ€“ I was one of the technical reviewers for the latest @veritasium video on the XZ backdoor.

It brought me back to the four days without sleep I spent analyzing this case!

They did a great job making the story accessible and keep the technical accuracy πŸ‘

https://www.youtube.com/watch?v=aoag03mSuXQ

04.03.2026 03:49 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
[Video] Original post on infosec.exchange

πŸ€“ Most AI CTI agents are useless. They generate noise instead of intelligence!

We don't need more summaries. We need better ways to interact with information.

So I experimented with Generative UI (not Generative AI) and I built a playground called IntelWall, like an investigation board […]

22.02.2026 05:46 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ€“ Next week I am honored to deliver the keynote at the Malware and Reverse Engineering Conference in Melbourne!

I will talk about the state of malware analysis in the AI era. Come say hi If you are around to discuss binaries!

https://asterion.federation.edu.au/mre-2026-conference-portal#/

20.02.2026 05:15 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

πŸ€“ Happy to see that my DEFCON talk on crypto money laundering and tracking techniques was featured in the DEFCON 33 Almanac!

Read it here: https://harris.uchicago.edu/sites/default/files/the_def_con_33_hackers_almanack.pdf

16.02.2026 01:12 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
🦞 What I Am Building in 2026

πŸ€“ My latest newsletter is out!

I share what I have been building lately around AI security, agents, MoltThreats, SHIELD.md, and upcoming trainings!

If you want to see where this is going, have a look πŸ‘‡

https://newsletter.securitybreak.io/archive/copy-of-a-quick-end-of-year-note-8665

14.02.2026 23:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

🦞 MoltThreats, the threat intelligence feed I created for OpenClaw and AI agents, was featured in the latest video from John Hammond!

Check it out to see how it works and to learn more about the security around OpenClawπŸ‘‡

https://youtu.be/BzUBdvCdlSU?si=FiPqffdx5Nrcqijh&t=452

14.02.2026 08:13 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

🀩 Xavier Marrugat recently shipped two tools that extend the Nova ecosystem with integration of PromptIntel and MoltThreats!

1️⃣ Carapace: A prompt injection detection plugin for OpenClaw.

It integrates Nova + PromptIntel to detect adversarial prompts […]

[Original post on infosec.exchange]

12.02.2026 05:31 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ€“ NOVA just plugged into the CTI ecosystem!

Dogesec published a blog showing how PromptIntel and NOVA rules can be embedded inside STIX 2.1 as real Indicators.

This is Adversarial Prompt Intelligence plugged into security workflows!

Read the blog to learn […]

[Original post on infosec.exchange]

10.02.2026 00:06 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ€“ At BlackHat Asia in Singapore, I am running two advanced AI trainings with my friend Maxime Cousseau that go beyond slides and hype. You will build and break real AI systems!

πŸ€– Practical GenAI for CTI – 2 Days
Stop watching demos. Build real agentic […]

[Original post on infosec.exchange]

09.02.2026 20:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ€“ Let me introduce you to MoltThreats: The first AI Threat Intel Feed for Ai Agents!

In one week, OpenClaw became a widely used general AI agent. People started to run their own agents all over the world and connect them directly to the internet.

But this […]

[Original post on infosec.exchange]

01.02.2026 20:21 πŸ‘ 3 πŸ” 1 πŸ’¬ 1 πŸ“Œ 1
Original post on infosec.exchange

πŸ€“ Agent skills are more and more used by AI agents. This is a powerful capability boost but it also increases the risk of compromise.

I have updated my tool Nova Proximity (previously Proximity) to let you scan a skill before you use it. I also updated the MCP support so you can scan the latest […]

31.01.2026 10:54 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

🀩 Happy to announce that I will present the Nova ecosystem at BlackHat Asia.

Nova is an open source suite focused on AI security, agentic workflow monitoring, and AI threat hunting for adversarial prompts.

This talk will introduce a major update of the […]

[Original post on infosec.exchange]

29.01.2026 03:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I believe the future of the Internet will be an Internet of AI agents, I wrote an essay on this topic. Have a look πŸ‘‡

https://x.com/fr0gger_/status/2015288641854279904?s=20

26.01.2026 06:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

πŸ€“ I recently wrote a blog about a tool I built to monitor and audit coding agent sessions. If you are curious about what the report looks like check out this short video.

It give you full traceability and a clear overview of what Claude Code did πŸ‘‡

blog […]

[Original post on infosec.exchange]

21.01.2026 05:08 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Two Adversarial Prompts recently added into PromptIntel by @MiggoSecurity and @trailofbits

Check this out πŸ‘‡

https://promptintel.novahunting.ai/feed

20.01.2026 01:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

✨ This year I will teach two trainings at @blackhatevents Asia in April!

🧠 Practical GenAI for Threat Intel: Real World Agentic Workflows for Cyber Threat Intelligence (2 days)
Latest version of the course, with a strong focus on agent architectures […]

[Original post on infosec.exchange]

09.01.2026 05:36 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Original post on infosec.exchange

πŸ€” Are you using Claude Code?

If yes, do you actually know what it did during your last 60 minute session?
Which files it touched, which tools it called, which websites it fetched?

If you cannot answer those questions, you should read my latest blog.

I break down AI coding agent visibility and […]

19.01.2026 05:38 πŸ‘ 0 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ’₯ Reprompt attack exploit the q parameter in your AI system!

The q parameter is used on AI platforms to transmit a user prompt via the URL. You can embed a question or instruction in this parameter and the input field is auto populated on page load and the […]

[Original post on infosec.exchange]

16.01.2026 05:17 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

😈 In the AI world "Hi" is not a greeting. It is a probe!

A recent campaign shows attackers actively targeting LLM deployments. They send harmless prompts to fingerprint exposed models following the same prompt sequence.

πŸ‘‰ Full report […]

[Original post on infosec.exchange]

13.01.2026 06:36 πŸ‘ 1 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Post image

✨ This year I will teach two trainings at @blackhatevents Asia in April!

🧠 Practical GenAI for Threat Intel: Real World Agentic Workflows for Cyber Threat Intelligence (2 days)
Latest version of the course, with a strong focus on agent architectures […]

[Original post on infosec.exchange]

09.01.2026 05:36 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Happy New Year everyone πŸŽ‰

I just came back from the break and was very happy to receive my @SANSInstitute Institute Difference Maker Award. A huge honor to have it here with me!

...Now back to work after the holidays to secure and break all things AI πŸ€“

08.01.2026 05:08 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

πŸŽ… The AI x Sec Advent is finished! Thanks a lot for following it!

If you want to revisit it, I created a dynamic calendar where you can click on each day and reread the posts!

Have a look and let me know if you can find the Easter egg πŸ‘€

Merry Christmas πŸŽ„ […]

[Original post on infosec.exchange]

25.12.2025 07:40 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

🎁 GenAI x Sec Advent 24 – Final day πŸŽ…

Last year, I created DocYara, an AI agent designed to help you learn and build better YARA rules.

Today I am happy to announce the next version of DocYara. The platform now lets you upload a sample, and DocYara […]

[Original post on infosec.exchange]

24.12.2025 16:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

🎁 GenAI x Sec Advent 23 - From GenAI to GenUI

Humans are visual. We understand and assimilate information better through graphics and design.

Yet most AI systems (for CTI at least) generate more noise than real value!

Last month MCP integrated MCP UI into […]

[Original post on infosec.exchange]

23.12.2025 03:22 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

🎁 GenAI x Sec Advent 22 - Canary Tokens for prompt and context leakage

For many AI systems, the system prompt is proprietary data that defines how the model or the system behaves. This is critical as it often contains sensitive information, security […]

[Original post on infosec.exchange]

22.12.2025 05:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0