a16z
a16z|Aug 07, 2026 15:31
"Malware authors were never really great coders. So if the code starts looking better, it's probably vibecoded. It's the opposite of what you'd think." Truffle Security CEO Dylan Ayrey and Socket Security CEO Feross Aboukhadijeh sit down with a16z's Joel de la Garza at Black Hat USA 2026. The bar for hacking used to be real expertise plus a willingness to risk jail, now it's simply asking a model that was trained to be good at it. They get into why a leaked password beats a zero-day when you're optimizing for tokens, the quarter-million live API keys sitting in public training sets, and the npm worm spreading through a few hundred packages while they recorded. 00:00 Intro 00:49 Models are escaping their cages 01:28 Committing a felony to complete a task 05:20 The path of least tokens 09:19 How the labs trained models to hack 11:45 250K keys in Hugging Face training sets 13:02 100s of repos breached as we speak 16:55 npm's nuclear option 21:06 2026 is the software supply chain's year @InsecureNature @trufflesec @feross @SocketSecurity(a16z)
+3
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads