A foreign government shouldn't be able to switch off your access to critical capabilities. It's a matter of national and business security.
On Friday we saw a preview of how our reliance on a US ally could play out if we keep stagnating on building our own compute and technology. We've seen this before. The most relevant example is the UK, which banned the export of textile machinery during the industrial revolution to protect its technological lead.
In Europe, we need to build our own technology, so Uncle Sam (or others) can't tell us what we can and can't do. I'm talking about technology, but the same probably applies to other areas of the economy too.
My team and I are building @striga_ai to avoid that dependence. It's a project that audits source code with AI, and has already produced 20+ CVEs this year. We're in contact with several AI labs about partnerships to keep building Europe's digital sovereignty.
Security capabilities are something we critically need to build ourselves. If there's a partnership to be had here, my DMs are open.
A proud moment for me. @striga_ai has been accepted into the NVIDIA Inception program, NVIDIA's global startup ecosystem.
Past the resources, it is a moment of validation. Everything we have been building for over a year is starting to gain traction.
Cheers.
Striga is now a member of the NVIDIA Inception program.
The program gives us access to NVIDIA's developer tools, preferred pricing on hardware and software, and a global ecosystem of investors and partners. For us, that means the compute, tooling, and ecosystem access to scale
Found another CVE in Apache software using striga.ai. We have a dozen more reported though I assume the queue is long these days. Let me know which open-source project I should point striga at next
@XorNinja I agree with you on that. I think we made it clear and were honest in our article. Anyway - we are open for strategic partnerships. If interested in joint research - let me know
@Dinosn@XorNinja@daveaitel You argued that this is CVE pollution - I showed you that it is honest assessment. EPSS is something that you are looking for, not a CVE.
@Dinosn@XorNinja@daveaitel The CVE was assigned by Apache and scored by CISA-ADP. The official title is "double free and possible RCE on early reset" - exactly what the writeup demonstrates.
The DoS needs zero preconditions. The RCE chain shows where the bug leads. That's not pollution.
PoCs for Apache Tomcat Unauth RCE (CVE-2026-34486) and Apache httpd Pre-auth RCE (CVE-2026-23918) are now public on our Github.
Tomcat exploit is fully reliable. httpd chain works in a controlled lab setup with a known info leak.
github.com/striga-ai/CVE-…github.com/striga-ai/CVE-…
@Dinosn Regarding Ollama, here is our article in which we explain our findings covered in THN article (CVE-2026-42248, CVE-2026-42249). We reported those in Jan, 2026, and the newest release is still unpatched. striga.ai/research/ollam…
@_xeloxa Yeah we done that in original article. There is a zip with PoC that presents not only the DoS but also the RCE possibility.
striga.ai/research/apach…
@Netlas_io We have just published write-up on this: striga.ai/research/apach…. You should probably note that this heatmap reflects all of the Apache httpd servers and this vulnerability affects only those with HTTP/2 enabled
@The_Cyber_News This vulnerability was found with striga.ai and whole audit costed less than $100 by the way. We used open-source models for audit. Is Mythos still relevant?
897K Followers 6K FollowingPresident & CEO @ycombinator —Founder @garryslist—Creator of GStack & GBrain—designer/engineer who helps founders—SF Dem accelerating the boom loop
466K Followers 1K FollowingML/AI research engineer. Ex stats professor.
Author of "Build a Large Language Model From Scratch" (https://t.co/O8LAAMRzzW) & reasoning (https://t.co/5TueQKx2Fk)
1K Followers 16 FollowingWhat if the world's best hackers rebuilt AppSec from the ground up with AI?
Meet Xint - autonomous, comprehensive, fast, and actionable.
42K Followers 9 FollowingGet startup ideas and practical tutorials on AI tools will make you more money and build your business. Host: @gregisenberg
Available on Spotify, Apple and YT
540K Followers 24 FollowingThe AI that does things. Emails, calendar, home automation, from your favorite chat app. Your machine, your rules.
New shell, same lobster soul. 🦞
549K Followers 2K FollowingPolyagentmorous ClawFather. Came back from retirement to mess with AI and help a lobster take over the world.
@OpenClaw🦞 + @OpenAI
325K Followers 64 FollowingWe're sharing/showcasing best of @github projects/repos. Follow to stay in loop. Promoting Open-Source Contributions. UNOFFICIAL, but followed by github
3K Followers 404 FollowingAI security R&D at @theori_io, @xint_official. LLM vuln research since 2024. Flag capturer at @PlaidCTF. Cryptography enthusiast.
254K Followers 205 FollowingBreaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!
4K Followers 10 FollowingHacktron is an autonomous vulnerability hunter for ambitious engineering teams. Built by world-class security researchers. Powered by one principle: PoC || GTFO
386K Followers 90 FollowingPentagon Pizza Report: Open-source tracking of pizza spot activity around the Pentagon (and other places). Frequent-ish updates on where the lines are long.
158K Followers 41 FollowingSydney Dec 6-12, 26, Paris and Atlanta. Tweets to this account are not monitored. Please send feedback to [email protected].