Hey Friend,
I just came back from Sydney for Unprompted.AU the first conference focusing on AI Security in Australia.
The talks were really interesting, but I was surprised that almost all of them focused on using AI for vulnerability exploitation and research. It was nonetheless interesting to see how everyone is experimenting differently.
For my talk, I presented about AI Threat Intelligence, not AI for Threat Intelligence.

The AI ecosystem is introducing new challenges. The way we work and interact with technology is changing, which means the way attackers operate and target the ecosystem is evolving too.
I deeply believe that good security detection and protection come from a deep understanding of the threat landscape. The reason I advocate for this is that most AI security solutions are built on top of academic research or designed for an older world, rather than based on real observations from the field. This is good, but not enough.
Organisations want protection against threats that currently occur and will happen, not only theoretical threats.
In my talk, I presented some of the threats that we are currently observing at SecurityBreak. Through supply chain compromises, AI scanner evasion, orchestration, and automation.
Two years ago, I introduced the term Indicator of Prompt Compromise (IoPC) because I believe prompts are a new form of intelligence.

You, me, and attackers are using AI, and we use AI through natural language. This means there are typos, language patterns, and habits. Those are pieces of information that might be relevant for threat tracking, because if you can identify them, cluster them, and make sense of them, then you can track and inform.
Some of the techniques I presented were around Prompt Hunting. I explained my own pipelines using YARA and NOVA. We hunt for samples and malware leveraging AI, we look for API connection, specific SDK, or open weight model usage. Then we filter the samples to extract adversarial prompts (IoPC) we then use NOVA my open source framework for hunting IoPC.

I also discussed how I use NOVA for MCP and Skill scanning which is available here: https://novahunting.ai/scanner/
Lastly, I presented some of my early experimentation with Jev for agent monitoring. If you missed the news Jev is a new model released last week for data classification. It is fast and cheaper than traditional LLM. I used it to identify agent misalignment or being compromised and created a proof of concept that I demonstrated on stage.


I am still experimenting with Jev and I have more to show you. If you want to stay updated make sure to follow along through this newsletter or on social.
Unprompted AU was a great way to spark the AI security community in Australia. The industry is still experimenting but we can clearly see how things are accelerating.
AI is a tool, an attack surface, and a target at the same time.
There is still a lot we don’t understand about how attackers will target this ecosystem, and a lot more we need to unpack.
This is why I think AI Threat Intelligence is even more relevant.
Thomas