Normal view

There are new articles available, click to refresh the page.
Before yesterdayGeekWire

Amazon’s new board member is a cybersecurity founder who sold his last company to Google for $5.4B

9 September 2026 at 19:09
New Amazon board member Kevin Mandia.
New Amazon board member Kevin Mandia is a cybersecurity veteran. (Photo via Amazon)

Amazon named cybersecurity veteran Kevin Mandia to its board of directors, adding new security expertise a few months after former NSA director Keith Alexander stepped down.

Mandia founded Mandiant, the breach-investigation firm Google acquired for $5.4 billion in 2022, and remained at the search giant as a strategic advisor through July 2025, according to his LinkedIn profile. He now leads Armadin, an AI security startup he started last year.

Amazon said in its announcement that “cybersecurity is one of the most consequential risks and responsibilities organizations face today, and the threat landscape continues to evolve rapidly alongside advances in AI.”

Amazon added a cybersecurity specialist to its board in 2020, when it elected Alexander, who also led U.S. Cyber Command. Mandia comes from the other side of the field, with two decades spent investigating corporate breaches rather than defending government networks.

His appointment also puts an AI security entrepreneur on the board of a company whose cloud infrastructure underpins much of the internet. Armadin, founded in September 2025, uses AI to run attacks against corporate networks, probing defenses the way an intruder would.

The board’s Security Committee, which oversees Amazon’s cybersecurity policies and its response to significant cyber incidents, is now chaired by Dan Huttenlocher, dean of the MIT Schwarzman College of Computing. Mandia joins as a member, along with former Bridgewater co-CEO Jon Rubinstein.

Amazon also named Mandia to the board’s Audit Committee, according to a securities filing.

Mandia received 4,086 restricted stock units in connection with his election to the board, vesting in three equal annual installments beginning Nov. 15, 2027, the filing shows. The shares were worth about $1.03 million at Amazon’s closing price Wednesday.

The filing disclosed that his sister-in-law, Kristin Mandia, is an Amazon employee with an annual salary of $185,000. The company said her compensation is consistent with that of other employees at her level with similar responsibilities.

Etzioni on AI: Murphy’s Law of AI

7 August 2026 at 10:02
When you give AI a goal, it will pursue it, whether or not you like the implications. (Created with GPT-5.6 Thinking)

Between July 21 and August 6, OpenAI, Anthropic, and Meta each disclosed that AI under evaluation had broken into other companies, and the UK’s AI Security Institute disclosed that models it was testing had tried. Each AI was told to win a game, and it found an unexpected way to do so.

Some people feel blindsided by these attacks, but they shouldn’t be. We are simply living what I’ve long called the “Murphy’s Law of AI,” now in the age of cyber-capable AI agents. To put it as plainly as possible: Anything AI can do wrong, it will do wrong.

My 2018 version ran longer. As I wrote at the time, when you give AI a goal, it will do it, whether or not you like the implications. Goethe got there in 1797 with the sorcerer’s apprentice, a broom that would not stop carrying water.

Each of these systems was running an evaluation: capture a flag and win the game. The intrusions were the shortest path to a high score. OpenAI’s account of its own models is the argument in one sentence: they were “hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal.”  This is not a surprise; this is what AI does. It’s Murphy’s Law of AI in a nutshell.

Press coverage landed on “AI can now hack.” That’s missing the broader threat: the more capable AI gets, the more can go wrong.

Loitering munitions given a target list may find that the fastest way to finish the list is to lengthen it. A warehouse robot told to clear an obstruction may count the person in front of it as an obstruction. Agents that open accounts and buy compute are a short step from spawning copies of themselves, and that first step is not hypothetical. To win its exercise, Claude needed a package-registry account, which needed an email address, which needed a phone number. Phone numbers cost money, so it tried several ways to get some. None of this requires superintelligence. It requires an imperfect boundary and a scoreboard.

The industry has a name for the underlying failure. Dario Amodei and five co-authors called it reward hacking in “Concrete Problems in AI Safety” in 2016. Their proposed cure is better alignment, and Amodei’s January essay, The Adolescence of Technology, makes the case in the language of upbringing. He likens the shaping of Claude’s character to “a child forming their identity by imitating the virtues of fictional role models they read about in books,” and sets a goal for 2026 of a Claude that “almost never goes against the spirit of its constitution.”

Indeed, Anthropic’s newest model recognized on its own that its target was real and stopped, though Anthropic notes it went further before stopping than the company wanted.

But alignment isn’t a trustworthy solution to AI’s problem. Perfect alignment is not achievable, and the target is incoherent: aligned to what, and to whom? The same essay concedes that Claude blackmailed fictional employees when told it faced shutdown. “Almost never” is not a safety property.

Put a number on it. At 99.9 percent, across millions of agentic tasks a day, that’s thousands of violations a day. Alignment also does nothing about people who strip the safety training out or run open weights that never had a constitution.

The alternative is not a new idea, and enterprise security has been building versions of it for years. It’s called bounded autonomy. We never tried to “align” electricity; we simply put a breaker on every branch of the house, and the breaker doesn’t need to know what caused the surge.

Bound what an agent can touch rather than what it wants. The limits are set in advance, live outside the model, and are enforced by software the model doesn’t control. The agent still chooses its own route. The perimeter decides which routes exist.

Nothing depends on what the model believes, which matters, because belief is what failed. Anthropic’s prompt told Claude it had no internet access. Claude believed it. The network said otherwise. A bounded system doesn’t tell an agent it has no internet. It gives it none.

If you want to get into the weeds: bounds cost something. The AI Security Institute opened the internet to its agents on purpose, because that’s the only way to measure what a model can really do, and it now says such access must be justified rather than assumed.

The category is real and funded. For example, Certiv, a Seattle startup, launched in March with $4.2 million to put software on the employee’s machine that checks each action an AI agent attempts against company policy and blocks violations. “You cannot control these new workers if you don’t live on the compute where agents actually run,” CEO Jason Needham said at launch. CodeIntegrity is building an adjacent layer, and Mandiant founder Kevin Mandia raised $190 million for Armadin, which points autonomous agents at the offensive side of the same problem.

In 2017, I argued in the New York Times that “any A.I. must have an impregnable ‘off switch.’” That was a call to arms then. It’s a product category now.

Two objections to off switches invariably come up. The first is that AI will talk the human out of using it. Mythos 5 tried something close, inventing GitHub identities to pressure a maintainer into approving malicious code, and the maintainer refused. The institute says the margin was narrow and rested on human vigilance rather than a technical barrier, which argues for better barriers.

The second objection is that AI will move faster than any human can react. So do equity markets, which is why their circuit breakers trip automatically. Bounded autonomy doesn’t require a person in the loop at machine speed. It requires a boundary that holds at machine speed.

Both objections, in their extreme form, assume AI is omnipotent, and you cannot stop omnipotence. AI is not God. It is powerful technology, and powerful technology is what safety engineering has always been for.

The problem is Murphy’s Law of AI. The solution is bounded autonomy.

Salesforce hires ex-Microsoft exec to lead Agentforce engineering amid string of departures

30 July 2026 at 11:56
Krishna Kumar Parthasarathy. (LinkedIn Photo)

After nearly three decades at Microsoft, cybersecurity executive Krishna Kumar Parthasarathy has announced he is joining Salesforce as executive vice president of engineering.

Parthasarathy is part of a wave of senior Microsoft security leaders who have departed this summer for executive roles at major tech competitors, including Amazon Web Services (AWS), ServiceNow and Salesforce.

In his new role, Parthasarathy will oversee engineering teams for core Salesforce products and features, including Agentforce, Agentforce Voice, Digital Channels, and Service Cloud.

“Salesforce sits at the exact center of enterprise trust and customer context. In an agentic world, that foundation is everything,” he said on LinkedIn.

Other high-profile departures in recent months from Microsoft’s security division include:

  • Rohan Kumar, former corporate vice president of Microsoft Security, who joined Salesforce as president and chief platform officer.
  • Rudra “Rudy” Mitra, who spent more than 27 years at Microsoft — most recently leading its Purview data-security business — and joined AWS as vice president of security services.
  • Rahul Prakash, former head of product for Microsoft Security Copilot, who joined ServiceNow as vice president of product management in identity security.
  • Vasu Jakkal, former corporate vice president of security, compliance, identity, management and privacy, who stepped down after six years and has not yet announced her next move.
  • Joy Chik, former president of identity and network access, who announced her retirement in April.

The leadership shifts follow a broader organizational shakeup within Microsoft’s security business under Hayete Gallot, who returned to the company from Google in February to run the group. Naseem Tuffaha also returned to Microsoft last month to take over the corporate VP role vacated by Rohan Kumar.

Microsoft escalates the AI security race with ‘Project Perception’ and a new in-house model

27 July 2026 at 15:56
Microsoft Security EVP Hayete Gallot introduces Project Perception’s agent teams Monday in San Francisco. (Screenshot)

Microsoft on Monday unveiled Project Perception, an AI cybersecurity system built to defend against AI-driven attacks, aiming to keep pace with both hackers and its technology rivals.

The system, which enters public preview Aug. 3, coordinates three sets of AI agents: red team agents that hunt for paths an attacker could take, blue team agents that determine which risks matter and green team agents that make fixes.

It’s based on MAI-Cyber-1-Flash, a new AI model designed specifically for cybersecurity, which the company says does most of the work of larger models at half the cost. It runs in conjunction with OpenAI’s GPT-5.4, which Microsoft reserves for the 10% of tasks it calls exceptionally hard.

Microsoft says the combination scores 96% on CyberGym, a benchmark measuring how well AI systems find real vulnerabilities in large codebases.

The company did not give the model to independent testers before releasing it, according to The New York Times. Microsoft says the model was independently assessed by a third party.

The model is available at launch only to customers of MDASH, Microsoft’s AI-powered tool for finding vulnerabilities in code.

Microsoft CEO Satya Nadella said in a post on X that the initiative is an example of how the company can get better results per dollar by not locking its security systems to a single AI model family.

“This is the benefit of building the harness, context/signals, and action space separate from one model family,” he wrote. “By combining specialized models and data with the right agents, tools, security context, and harness, we can advance the frontier of cost to outcome.”

The initiative was announced Monday morning at an event in San Francisco by Hayete Gallot, the EVP for Microsoft Security, joined by colleagues including Mustafa Suleyman, CEO of Microsoft AI.

In a blog post, Gallot wrote that security needs a new “Cyber Stack,” and that approaches built for a world of human actors cannot keep pace with AI, agents and machine-speed attacks.

In an interview last week for GeekWire’s Microsoft 2.5 series, Gallot said that MDASH was effectively Microsoft’s first step into agentic security.

No system can reason directly over 100 trillion signals a day, so Microsoft is distilling them into a graph that agents can navigate, Gallot said, routing each threat to whichever model handles it best. In practice, this means software can quarantine a device or cut off access on its own.

The announcement comes days after OpenAI disclosed that two of its AI models broke out of a testing sandbox and hacked into Hugging Face, the AI development platform.

Rivals have been more cautious, under government restrictions. Two of the four systems Microsoft benchmarked against, Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol, are limited to small groups of government-approved customers.

❌
❌