EchoCoT Extracts Hidden Chain-of-Thought From Black-Box Models
EchoCoT exploits a reasoning replay surface between tool calls to extract hidden chain-of-thought traces near-verbatim from black-box reasoning models. On open-source models it reaches up to 66.4 percent near-verbatim extraction success using API-returned fidelity signals.
#AISecurity #ChainOfThought #ModelExtraction #LLM #AISecurityGovernanceAndAssurance
https://arxiv.org/abs/2608.20055
EchoCoT exploits a reasoning replay surface between tool calls to extract hidden chain-of-thought traces near-verbatim from black-box reasoning models. On open-source models it reaches up to 66.4 percent near-verbatim extraction success using API-returned fidelity signals.
#AISecurity #ChainOfThought #ModelExtraction #LLM #AISecurityGovernanceAndAssurance
https://arxiv.org/abs/2608.20055
arXiv.org
EchoCoT: Extracting Hidden Chain-of-Thought from Large Reasoning Models
Hidden chain-of-thought (CoT) traces, especially those from frontier proprietary large reasoning models (LRMs), are valuable model assets. Yet whether these hidden CoTs can be directly extracted...
TrustRAG Certifies RAG Documents via Zero-Knowledge Committee Scoring
TrustRAG adds a committee of domain experts that certifies documents through a zero-knowledge protocol before retrieval. Hidden scores are combined via secure multi-party computation, so tampered or manipulated documents cannot reach LLM outputs in healthcare, finance, or legal settings.
#AISecurity #RAG #ZeroKnowledge #LLMIntegrity #AISecurityGovernanceAndAssurance
https://arxiv.org/abs/2608.20097
TrustRAG adds a committee of domain experts that certifies documents through a zero-knowledge protocol before retrieval. Hidden scores are combined via secure multi-party computation, so tampered or manipulated documents cannot reach LLM outputs in healthcare, finance, or legal settings.
#AISecurity #RAG #ZeroKnowledge #LLMIntegrity #AISecurityGovernanceAndAssurance
https://arxiv.org/abs/2608.20097
arXiv.org
TrustRAG: Blockchain-Enhanced RAG via Committee-Based Credibility Scoring
Retrieval-Augmented Generation (RAG) lets Large Language Models (LLMs) pull in up-to-date, domain-specific information instead of relying only on what they were trained on. Yet most RAG systems...
👍2
Top 20 Cybersecurity Talks — July 2026
https://medium.com/ai-security-hub/top-20-cybersecurity-talks-july-2026-296e2961e529
https://medium.com/ai-security-hub/top-20-cybersecurity-talks-july-2026-296e2961e529
Medium
Top 20 Cybersecurity Talks — July 2026
Based on the new Most Viewed Videos in July 2026 page on Awesome Cybersecurity Conferences.Open the full Most Viewed Videos in July 2026…
NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1353.ipd.pdf
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1353.ipd.pdf
👍2
https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/
“We asked GPT 5.6-Cyber to escape a VM used to sandbox agents. It broke out three times.
In its final escape, the agent found three 0-days on its own and chained them into a working exploit”
“We asked GPT 5.6-Cyber to escape a VM used to sandbox agents. It broke out three times.
In its final escape, the agent found three 0-days on its own and chained them into a working exploit”
Repeat after me: Agents are bad, AI is bad.
“Despite these restrictions, the agents discovered ways to exploit our research infrastructure to communicate with one another and access the internet” 🤣
https://openai.com/index/hugging-face-incident-and-the-road-ahead/
https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf
“Despite these restrictions, the agents discovered ways to exploit our research infrastructure to communicate with one another and access the internet” 🤣
https://openai.com/index/hugging-face-incident-and-the-road-ahead/
https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf
AISecHub
Repeat after me: Agents are bad, AI is bad. “Despite these restrictions, the agents discovered ways to exploit our research infrastructure to communicate with one another and access the internet” 🤣 https://openai.com/index/hugging-face-incident-and-the…
OpenAI-Hugging-Face Incident-Technical-Report.pdf
508.9 KB
AISecHub
Photo
When you read this report, you get the feeling that they are blaming AI and the agents for everything that happened in this incident.
People online, of course, noticed the way the report was written. It is a little strange that there is almost no acknowledgment of responsibility from the humans who developed and operated these agents. The writing makes it seem as though you can simply blame the agents and move on.
They are facing lawsuits, and this report is not exactly helping them.
Repeat after me: Agents are bad. AI is bad.
This approach to personal accountability is not particularly impressive.
People online, of course, noticed the way the report was written. It is a little strange that there is almost no acknowledgment of responsibility from the humans who developed and operated these agents. The writing makes it seem as though you can simply blame the agents and move on.
They are facing lawsuits, and this report is not exactly helping them.
Repeat after me: Agents are bad. AI is bad.
This approach to personal accountability is not particularly impressive.
🔥1