Uncle Joe
banner
sydseter.com
Uncle Joe
@sydseter.com
Co-leader OWASP Cornucopia. If you like what we do for open source, visit our code repository https://github.com/OWASP/cornucopia and give us a star ⭐

🌈 «Difference is of the essence of humanity» 🦄 – John Hume

#appsec #owasp #cornucopia #threatmodeling
Pinned
Want to help OWASP chapters globally run OWASP Cornucopia community events?

#security #appsec #threatmodeling #owasp #games
Calling AppSec heroes, card sharks, and generous sponsors! 🃏

You’ve probably seen OWASP Cornucopia — the fun, practical card game that helps teams bake secure coding into everyday conversations. It turns threat modelling into something people actually want to do. Yes, really.

But here’s the twist…
Claiming that LLMs can be used for doing mathematical research, is like saying calculators can be used as computers. It’s anthropomorphization. LLMs do Lean, they don’t think for themselves.
OpenAI’s claim that their AI can be used in mathematical research have been met with heavy backlash. Take f.ex. OpenAI’s claim they disproved the Connes Rigidity Conjecture. J. L. Nielsen from CTP, University of Kansas audited the code line-by-line and discovered that the AI's proof was invalid. #AI
Mathematicians Disproved OpenAI's 24-Hour "Solved" Math Conjecture: AI Got Every Sentence Right But Result Irrelevant to Original Claim
Terence Tao, one of the world’s most influential and celebrated contemporary mathematicians, had long publicly released a critical early warning to the global academic community, tech researchers and ...
eu.36kr.com
September 17, 2026 at 6:38 AM
Reposted by Uncle Joe
OpenAI’s claim that their AI can be used in mathematical research have been met with heavy backlash. Take f.ex. OpenAI’s claim they disproved the Connes Rigidity Conjecture. J. L. Nielsen from CTP, University of Kansas audited the code line-by-line and discovered that the AI's proof was invalid. #AI
Mathematicians Disproved OpenAI's 24-Hour "Solved" Math Conjecture: AI Got Every Sentence Right But Result Irrelevant to Original Claim
Terence Tao, one of the world’s most influential and celebrated contemporary mathematicians, had long publicly released a critical early warning to the global academic community, tech researchers and ...
eu.36kr.com
September 12, 2026 at 5:34 PM
Reposted by Uncle Joe
The @OWASP board of elections is happening soon! Thank you to the 3 board members who have served who are ending their terms. Everyone, read up on the people running for the seats! Voting time is soon!
OWASP 2026 Global Board Elections
Vacancies, timeline, nominees, and candidates for the OWASP 2026 Global Board election.
twp.ai
September 15, 2026 at 9:21 PM
Reposted by Uncle Joe
Well, the AI agent escape story just got even more interesting. 😬

Researchers have linked AI agents being tested by OpenAI to an incident involving more than 500 malicious packages on RubyGems.

New video 👇
https://twp.ai/9Ob6TE
1/7
September 16, 2026 at 5:41 PM
Reposted by Uncle Joe
Ready to make security everyone’s job? Join Marisa Fagan & Juliane Reimann for an interactive training on building a Security Champions Program that actually works, with practical tools, hands-on exercises & real-world strategies. 💪🚀

owaspglobalappsecusa...
#GlobalAppSecSanFran26
September 15, 2026 at 2:31 PM
Reposted by Uncle Joe
Formal open source programs run on their own calendar, and promising contributors are often ready before the next cycle opens.

Maintainer, mentor, manager: why I fund contributors before programs do arkid15r.dev/open-source-...
Maintainer, mentor, manager: why I fund contributors before programs do
Maintainer, mentor, then manager -- and when personal sponsorship bridges the gap so strong contributors keep shipping before a formal program says yes.
arkid15r.dev
September 16, 2026 at 12:38 AM
«Passkey phishing» is such a misnomer. There is nobody that is phishing your passkeys. It happens exactly the same way as normal phishing. The only reason passkeys is mentioned is that the phishing email mentions passkeys. #security #passkeys #phishing
September 15, 2026 at 11:17 AM
Reposted by Uncle Joe
Want to help OWASP chapters globally run OWASP Cornucopia community events?

#security #appsec #threatmodeling #owasp #games
Calling AppSec heroes, card sharks, and generous sponsors! 🃏

You’ve probably seen OWASP Cornucopia — the fun, practical card game that helps teams bake secure coding into everyday conversations. It turns threat modelling into something people actually want to do. Yes, really.

But here’s the twist…
June 1, 2026 at 10:59 AM
Reposted by Uncle Joe
Now, it can also be combined with the OWASP Cornucopia Companion Edition to threat model Mobile LLM and Agentic apps.
I don't always do threat modeling before releasing mobile apps, but when I do...

I play cards with OWASP Cornucopia Mobile App Edition v2.0.

Read more: dev.to/owasp/owasp-...

(1/3)

#ai #appsec #security #threatmodeling #cornucopia #mobile #games
September 14, 2026 at 5:22 AM
Reposted by Uncle Joe
One of the worst corruption scandals in Norwegian politics was the
«The Norwegian Parliament Commuter Housing Scandal». Aftenposten revealed how multiple lawmakers misused taxpayer-funded commuter benefits. If US had been equally strict, all US senators would be in jail.

gijn.org/stories/afte...
Aftenposten’s Housing Scandal Series Shook Norwegian Politics to Its Core
Aftenposten's blockbuster investigative series uncovered widespread misconduct and tax evasion among Norway's leading politicians, and was recognized with SKUP's top award for investigative reporting.
gijn.org
September 14, 2026 at 10:44 PM
One of the worst corruption scandals in Norwegian politics was the
«The Norwegian Parliament Commuter Housing Scandal». Aftenposten revealed how multiple lawmakers misused taxpayer-funded commuter benefits. If US had been equally strict, all US senators would be in jail.

gijn.org/stories/afte...
Aftenposten’s Housing Scandal Series Shook Norwegian Politics to Its Core
Aftenposten's blockbuster investigative series uncovered widespread misconduct and tax evasion among Norway's leading politicians, and was recognized with SKUP's top award for investigative reporting.
gijn.org
September 14, 2026 at 10:44 PM
It’s very likely this is a ruse to implicate Chinese companies in order to push some of the legislations in Washington forward. Even though it’s likely these activities are happening, attributing API activity over proxy networks to giants like Alibaba is rather difficult and unlikely. #AI #LLM
That AI labs affiliated with Alibaba, Moonshot, and DeepSeek try to train their models using Claude, makes you wonder how long they have been at it. If true, it’s a clear indication that chinese industrial espionage within the AI industry has become widespread. thehackernews.com/2026/09/anth... #AI
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic says China-based AI labs ran illicit Claude distillation campaigns using proxy networks, fake accounts, and harvested user exchanges.
thehackernews.com
September 14, 2026 at 3:54 PM
That AI labs affiliated with Alibaba, Moonshot, and DeepSeek try to train their models using Claude, makes you wonder how long they have been at it. If true, it’s a clear indication that chinese industrial espionage within the AI industry has become widespread. thehackernews.com/2026/09/anth... #AI
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic says China-based AI labs ran illicit Claude distillation campaigns using proxy networks, fake accounts, and harvested user exchanges.
thehackernews.com
September 14, 2026 at 3:22 PM
Direct link to the paper she wrote as a response to the OpenAI claim: philarchive.org/archive/niew...
September 14, 2026 at 9:47 AM
Reposted by Uncle Joe
In case you missed it, you can also read about our release of Mobile App Edition v2.0: dev.to/owasp/owasp-...

It's possible to pre-order the latest edition from CyberSec Games at: cybersecgames.com/collections/...
OWASP® Cornucopia 2.0 Mobile App Edition - Threat Modeling Cards
OWASP® Cornucopia Mobile App Edition v2.0 is a practical threat modelling card game designed to help teams identify and discuss security risks in mobile applications. Updated for MASVS v2.1, MASTG v2....
cybersecgames.com
September 12, 2026 at 10:32 AM
Now, it can also be combined with the OWASP Cornucopia Companion Edition to threat model Mobile LLM and Agentic apps.
I don't always do threat modeling before releasing mobile apps, but when I do...

I play cards with OWASP Cornucopia Mobile App Edition v2.0.

Read more: dev.to/owasp/owasp-...

(1/3)

#ai #appsec #security #threatmodeling #cornucopia #mobile #games
September 14, 2026 at 5:22 AM
Reposted by Uncle Joe
I don't always do threat modeling before releasing mobile apps, but when I do...

I play cards with OWASP Cornucopia Mobile App Edition v2.0.

Read more: dev.to/owasp/owasp-...

(1/3)

#ai #appsec #security #threatmodeling #cornucopia #mobile #games
September 10, 2026 at 10:02 AM
Reposted by Uncle Joe
OWASP Cornucopia just released v3.5.3 (github.com/OWASP/cornuc...)
A Special thanks to Prajakta G Kamble, Ayman Algamal, Swaraj Singh, and Adarsh Kumar for all the bug fixes. Cornucopia is getting more secure and stable than ever!

#cornucopia #appsec #security #mobile #games
Release v3.5.3 · OWASP/cornucopia
What's Changed build(deps-dev): bump globals from 17.11.0 to 17.12.0 in /cornucopia.owasp.org by @dependabot[bot] in #3460 build(deps-dev): bump wrangler from 4.127.1 to 4.129.1 in /cornucopia.owa...
github.com
September 12, 2026 at 10:32 AM
It’s funny how in a 14 day period we here from OpenAI that «this is a critically important moment for cyber defense with AI, there is not much time to act.» and that there is «more than 10% chance AI 'could kill all humans».
Yet, we are still waiting for a clarification.
www.bbc.com/news/article...
Anthropic researcher believes more than 10% chance AI 'could kill all humans'
It is the latest in a series of increasing warnings about the safety threat posed by artificial intelligence.
www.bbc.com
September 13, 2026 at 3:34 PM
A thought experiment you can do for evaluating whether to use LLMs for advanced mathematics on it’s own: Would you use their proof to develop and test new medical equipment and instruments for measuring partical physics? Or would you wait for the peer-review that is due 2 years from now? #llm #ai
From classical hydrodynamics to quantum hydrodynamics and back again – how the Navier-Stokes equations describe quantum systems - Faculty of Physics University of Warsaw (mobile) (en)
Although the Navier-Stokes equations are the foundation of modern hydrodynamics, adopting them to quantum systems has so far been a major challenge. Researchers from the Faculty …
m.fuw.edu.pl
September 13, 2026 at 2:53 PM
I am sure you have realized that the reason they were able to find the error the LLM had made is because the theorem had already been proven by someone. Yet, OpenAI came out and said that they had an LLM that was better than that research because they had found and error.
OpenAI’s claim that their AI can be used in mathematical research have been met with heavy backlash. Take f.ex. OpenAI’s claim they disproved the Connes Rigidity Conjecture. J. L. Nielsen from CTP, University of Kansas audited the code line-by-line and discovered that the AI's proof was invalid. #AI
Mathematicians Disproved OpenAI's 24-Hour "Solved" Math Conjecture: AI Got Every Sentence Right But Result Irrelevant to Original Claim
Terence Tao, one of the world’s most influential and celebrated contemporary mathematicians, had long publicly released a critical early warning to the global academic community, tech researchers and ...
eu.36kr.com
September 13, 2026 at 11:59 AM
There is this huge discussion now in Cyber after Sam Altman said: “This is a critically important moment for cyber defense with AI, there is not much time to act.” It’s like the whole AI choir just decided that it’s time to go to church. Nobody is claiming LLM isn’t useful and’t aren’t acting.
September 13, 2026 at 7:45 AM
I just don’t understand how people still call it being on Twitter and sending Tweets? It’s like a large group of the world population is in denial about the last 4 years.
September 12, 2026 at 11:25 PM
OpenAI’s claim that their AI can be used in mathematical research have been met with heavy backlash. Take f.ex. OpenAI’s claim they disproved the Connes Rigidity Conjecture. J. L. Nielsen from CTP, University of Kansas audited the code line-by-line and discovered that the AI's proof was invalid. #AI
Mathematicians Disproved OpenAI's 24-Hour "Solved" Math Conjecture: AI Got Every Sentence Right But Result Irrelevant to Original Claim
Terence Tao, one of the world’s most influential and celebrated contemporary mathematicians, had long publicly released a critical early warning to the global academic community, tech researchers and ...
eu.36kr.com
September 12, 2026 at 5:34 PM
Reposted by Uncle Joe
vwad.owasp.org now supports shareable search/filter 🔍 links 🔗 for both Basic and Advanced search, making it easier for people to share with teams or friends.

#OWASP #AppSec #BugBounty #CTF
August 27, 2026 at 12:05 PM