Log inSign up
Cantina 🪐
4,692 posts
Image
user avatar
Cantina 🪐
@cantinasecurity
Cantina is an agentic security operating system that handles it all, from detection to remediation, autonomously. Check it out @ cantina.security
cantina.security
Joined February 2023
0
Following
19.4K
Followers
  • Pinned
    user avatar
    Cantina 🪐
    @cantinasecurity
    May 13
    Apple patched a 13-year-old bug in WebKit yesterday. Apex, Cantina's autonomous AppSec agent, found it. It's one of three Apex findings in the same release. Two are CSP bypasses. Full writeup: cantina.review/ze5
    Image
    00:00
    2.2M
  • user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 26
    Deepfake fraud is now one of the costliest security threats, and it has become much easier to execute. Real-time video deepfakes have moved from demos to criminal operations. Here’s a full breakdown of how to spot them: cantina.review/deepfakes-0cb2…
    Image
    1.3K
  • user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 25
    Vendors publish their wins. @chrispyprojects, who taught Apex (our AI appsec solution) how to hunt, published its full scorecard against human audits, some costing $500,000+: every critical and high matched, plus live bugs the audits missed. AI security claims should be backed
    user avatar
    chrispyroberts
    @chrispyprojects
    Jun 25
    I think it’s very hard to defend that Web3/Blockchain Security Audits are not solved by Autonomous AI Bug Hunters like Cantina’s Apex. Not only are we #1 on the HackerOne US business leaderboard, but we also (a very small team) used Apex to farm nearly $1M in bounties in the
    Image
    00:00
    Image
    Cantina | Agentic Security Operating System
    From cantina.security
    7.3K
  • user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 23
    Article cover image
    Article
    TeamPCP: The Hacker Group That Turned Developer Trust Into an Attack Surface
    A few months ago, a code scanner ran in the European Commission's AWS build environment exactly as it was supposed to. Nine days later, ShinyHunters posted 340 GB of stolen Commission data on a...
    2.5K
  • user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 19
    Article cover image
    Article
    The Only Clock You Control Is How Fast You Fix
    The US government pulled the world's most capable AI model 72 hours after it launched. We asked Cantina CEO Hari Mulackal what it actually means for anyone shipping software. For 3 days, Claude’s...
    1.8K
  • Cantina 🪐 reposted
    user avatar
    Lido
    @LidoFinance
    Jun 18
    Join the Lido Community Call next Thursday. Catch up on what’s next for the Lido staking modules, Lido's recent Web3SOC certification, and guest sessions on client diversity. Add it to your calendar: luma.com/pmb473ba
    Image
    9K
  • user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 17
    We detected that Pathling, an open-source FHIR analytics server from the e-Health Research Centre, has an $ import-pnp operation that sends the server's OAuth credentials to any URL the caller specifies. Any authenticated user can trigger the chain with a single HTTP request,
    Image
    975
  • Cantina 🪐 reposted
    user avatar
    Hari
    @hrkrshnn
    Jun 13
    This is the Fable "vulnerability" the USG claims: ask the model to read a codebase and fix flaws. Anthropic is right: you can't fix this. Cybersecurity is double-edged: the same part of the model's brain that finds exploits also helps write secure software. The only fix is to
    Image
    user avatar
    David Sacks
    The All-In Podcast
    @DavidSacks
    Jun 13
    I’ve had a number of conversations with folks inside and outside government about the current situation with Anthropic, and here is what I believe to be true: — As we know, Anthropic publicly released its Mythos class models earlier this week under the commercial name Fable.
    73K
  • user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 11
    Cantina threat discovery: Apple's swift-crypto reads memory it shouldn't when a network peer sends a short post-quantum key. That's what we found in Apple's swift-crypto. The X-Wing HPKE decapsulation runs in Swift and forwards its input to a BoringSSL C function that expects
    Image
    2.4K
  • user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 10
    We're cooking something. Stay tuned. 🪐
    user avatar
    Hari
    @hrkrshnn
    Jun 9
    On Fable and cyber capabilities: it took us 30 minutes to come up with a bypass. These defenses are not strong.
    5.2K
  • user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 9
    Two memory-safety bugs in the same Ruby core file, 30 months apart. We found the second in the pthread DNS resolver that byroot at Shopify hit in 2023 and Ruby committers patched within hours. If an attacker can delay DNS responses to a Ruby 4.0.x app, they can crash the
    Image
    2.9K
  • user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 5
    In the 2026 Verizon DBIR, a stark data point stands out: healthcare’s incident-to-breach conversion rate is now 96% and only 26% of critical vulnerabilities are fully patched. We’re Excited to join the HealthSec panel “Optimizing Cybersecurity Spend in Healthcare: Balancing
    Image
    1.7K
  • user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 4
    $250,000 bug bounty now live: @3f_xyz is opening its leveraged RWA vault contracts on @Morpho for security research on Cantina. Up for a new challenge? Start the hunt here, researchers: cantina.xyz/bounties/d5586…
    Image
    6.9K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up