Advertisement · 728 × 90

Posts by Teri Radichel

Preview
Reducing Token Burn Rate With A Well-Designed Architecture Trying to put out the AI token fire - or at least manage it as a controlled burn by using deterministic scripts for gathering inputs and directing agents

Reducing Token Burn Rate With A Well-Designed Architecture
Trying to put out the AI token fire - or at least manage it as a controlled burn by using deterministic scripts for gathering inputs and directing agents

teriradichel.substack.com/p/reducing-t...

20 hours ago 0 0 0 0

I spoke about mistakes in this video. Make sure you add correction text so you don’t reinforce the mistakes.

21 hours ago 0 0 0 0
How I Use AI for Penetration Testing [Advanced] - Teri Radichel
How I Use AI for Penetration Testing [Advanced] - Teri Radichel YouTube video by AWS Community Day

How I Use AI for Penetration Testing. Presentation at the AWS Security Community Day at the Computer History Museum on YouTube

youtu.be/nWntvFRwiPw

1 day ago 0 0 0 1

Oh and by the way I don’t want a dumbed down solution that makes it easier but does not provide the same * network * not application layer controls. I looked at VPC Lattice and it is not equivalent.

1 day ago 0 0 0 0

BlueSky needs to allow edits and longer posts, or at least do what Threads does and break posts into multiple posts if someone enters one that is too long. Such a pain I post less here.

1 day ago 0 0 0 0

Lambda *layer. Such a pain to post all that. Not fixing.

1 day ago 0 0 0 0

Why can’t VPC endpoints be a more cost effective pay per use model like other things on AWS so smaller security conscious customers with a lower budget can afford them?

Maybe I’ll add that to my AWS wishlist on the builder center later.

1 day ago 1 0 1 0

I just need to use a few lambdas for an authentication solution and to run some jobs and that cost just to deploy the network is up over $50 and I’ve only had the endpoints running a partial month and barely sent any network traffic.

1 day ago 0 0 1 0

I’m creating a Lambda troubleshooter that has been able to help me uncover most of the issues, but the problem now is the cost.

1 day ago 0 0 1 0

As I learned last night using a lambda later also requires a Lambda endpoint.

Then you add the security group to each endpoint, make sure dns is configured correctly, etc. etc.

1 day ago 0 0 1 0
Advertisement

Oh you want to retrieve a secret?
secrets manager endpoint.

You wanted to use SSM parameters?
An SSM parameter endpoint

You want to deploy with CloudFormation?
There’s another endpoint

Execute a lambda using API gateway?
Execute endpoint.

1 day ago 1 0 1 0

AWS VPC Endpoints are so complicated and expensive but I really want to use them. They provide a unique level of security that a NAT does not replicate.

The problem is the rabbit hole you end up going down after you think you are “just” going to add the free gateway endpoints.

1 day ago 2 0 2 0
Preview
Pricing Learn about Anthropic's pricing structure for models and features

Claude pricing changing to pay per token. This makes sense as long as value per token remains consistent. This will make it difficult to compare to prior performance and I wonder how users can transparently measure the usage.

platform.claude.com/docs/en/abou...

5 days ago 2 0 0 0
AWS Secrets Manager now supports hybrid post-quantum TLS to protect secrets from quantum threats - AWS Discover more about what's new at AWS with AWS Secrets Manager now supports hybrid post-quantum TLS to protect secrets from quantum threats

AWS Secrets Manager now supports hybrid post-quantum TLS to protect secrets from quantum threats - AWS

aws.amazon.com/about-aws/wh...

5 days ago 2 0 0 0

AWS needs to extend CloudWatch with tools that make it a real SIEM. Don’t overlay it with complexities it doesn’t need. Just extend it.

5 days ago 0 0 0 0

This post is not about Mythos capabilities because I can’t know until I try it. Opus 4.6 was great until is changed and I presume Mythos is better.

These are questions I have about AI risks for businesses that rely on it that I don’t see anyone else asking - or answering.

6 days ago 2 0 0 0

Go Hornets! We’re kinda neighbors and sort of have a connection to the high school where KK went. 🏀 Had to take a break after doing the necessary. Back on all things AI tomorrow. Finally. Can’t wait! 🤖

6 days ago 0 0 0 0
Advertisement

Go Hornets! We’re kinda neighbors and sort of have a connection to the high school where KK went. 🏀 Had to take a break after doing the necessary. Back on all things AI tomorrow. Finally. Can’t wait! 🤖

6 days ago 0 0 0 0

There are varying levels of exploits in terms of complexity but technically my fuzzer at RSA 2020 generated exploits. Without AI. It produced a working script and performed attacks. I did review manually. But I have so many more ideas for that fuzzer with and without AI - bound by time and compute.

6 days ago 3 0 0 0
Preview
Anthropic Mythos Anthropic released a new model they claim is scary good at finding security vulnerabilities. What questions should we be asking?

Anthropic Mythos ~ Anthropic released a new model they claim is scary good at finding security vulnerabilities. What questions should we be asking?

This is not a hot take. I’m just pondering how much we can trust a model, the purported ROI, and how we can evaluate the risk of relying on it.

1 week ago 1 0 0 1
https://cdn.tailwindcss.com (()=>{var qv=Object.create;var Hi=Object.defineProperty;var $v=Object.getOwnPropertyDescriptor;var Lv=Object.getOwnPropertyNames;var Mv=Object.getPrototypeOf,Nv=Object.prototype.hasOwnProperty;var df=...

I am looking at messages in Google Developer tools and it is saying cdn.tailwindcss.com should not be used in production so if you are….
tailwindcss.com/docs/insrall...

1 week ago 2 0 0 0
Post image

I’ve added links to my presentation on how I use AI 🤖 for pentesting 😈 in this post. Most of the slides have a related blog post and I’ll probably write more about all these topics as I research this further. The PDF has links to related posts.

teriradichel.substack.com/p/how-i-use-...

1 week ago 1 0 0 0
Intro to S3 Files
Intro to S3 Files YouTube video by AWS Developers

Awesome video on S3 files youtu.be/zb8TdNJhZCk

1 week ago 1 0 0 0
Post image Post image

The Computer History Museum is such an awesome place for a conference. Thanks to everyone who came to the AWS Community Day!

1 week ago 4 0 0 0

🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖
Pentesting is not a scanner or a fuzzer - whether SAST, DAST, AI, deterministic or non-deterministic. Pentesting is a human * using those tools * to see if they can find a security problem that your teams and tools may have missed.
🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖

1 week ago 1 0 0 1

I read all the Mythos hype right before I submitted my talk for today at the Computer History Museum. Did I need to change my slides? Nope.

1 week ago 2 0 0 0

users on Reddit and developer forums reported that the default was quietly shifted from high to medium for many subscribers, which explains the sudden change in performance. *

Need to check this out later. Flying out to speak at AWS Community Day in Mountain View.

1 week ago 0 0 0 0
Advertisement

Wonder if this has anything to do with performance degradation of anthropic models. But are you now paying more for same effort you were getting previously if you change this?

* Default Shift: In March 2026…

1 week ago 1 0 1 0
Preview
FBI: Americans lost a record $21 billion to cybercrime last year U.S. victims lost nearly $21 billion to cyber-enabled crimes last year, driven primarily by investment scams, business email compromise, tech support fraud, and data breaches, the Federal Bureau of In...

FBI: Americans lost a record $21 billion to cybercrime last year

www.bleepingcomputer.com/news/securit...

1 week ago 0 0 0 0
Preview
China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware Storm-1175 exploits 16+ CVEs since 2023, including zero-days, enabling rapid Medusa ransomware attacks within 24 hours.

Was part of a wave of attacks on rural hospitals during Covid. I believe the ransomware was Medusa but I thought they said was attributed to Russia. Attribution is difficult. You might not really be sure, especially with AI.

thehackernews.com/2026/04/chin...

1 week ago 0 0 0 0