For vendors, three assumptions just broke:
→ 90-day disclosure timelines
→ Knowing if you're affected
→ Handling the volume
The 90-day action plan: https://t.co/N9r95FShiZ
If your vulnerability program is driven entirely by CVSS scores, you are probably missing real risk. This post outlines a high-level approach to prioritizing remediation based on exposure, KEV data, and attacker behavior.
Link 👇
https://t.co/saAvYZTBKJ
#VulnerabilityManagement
https://t.co/LnVIZwEP99 confirmed threat actors accessed a legacy system that wasn’t decommissioned properly.
It’s a reminder that old systems can become unmonitored entry points when they’re not retired or secured.
👉 https://t.co/QOyHVSmZgi
#Cybersecurity#LegacySystems
Legacy systems don’t just age. They accumulate risk.
✅ Identify
✅ Contain
✅ Harden
✅ Monitor
✅ Add to a risk register
Modernize before your own systems make the news.
Full story → https://t.co/QOyHVSmZgi
#Cybersecurity#ZeroTrust#RiskManagement
Thieves stole $100M in jewels from the Louvre, but the bigger story wasn’t the heist.
It was the outdated cameras, weak passwords, and legacy systems behind them.
Here’s what every enterprise can learn from it. 👇
#Cybersecurity#ZeroTrust#CISO
The only camera near the break-in faced the wrong way.
Some systems ran on Windows 2000.
And the password? “Louvre.”
Audits warned about these gaps a decade ago, but the risks never got fixed.
Many orgs are in the same position today.
June is National Internet Safety Month. But where did it come from? 🕵️♂️
Spoiler: It started in 2005, way back in the MySpace era.
Read the quick origin story 👉 https://t.co/u0CWhnz2q3
#Cybersecurity#Infosec#InternetSafetyMonth
You don't need to be a CISO to protect yourself online.
This 10-minute weekend security checkup covers 7 things anyone can do—from updates to MFA to backups.
Read it here: 👉 https://t.co/GzpaKUqBHr
#CyberSecurity#WeekendWin#MFA
A guy named “Steven” applied for a remote dev job. Said he lived in Houston. Couldn’t name a single restaurant & never heard of Halloween.
He wasn’t a dev, he was a North Korean spy.
Read about this!
👉 https://t.co/0m8s1ZhAu9
#Cybersecurity#SocialEngineering#RemoteWork
Still using 123456? It’s World Password Day—time to fix that.
Learn how to level up your logins and why passkeys > passwords.
👉 https://t.co/LXDF6Zc5Dv
#WorldPasswordDay#Cybersecurity#Infosec
🚨 New from Between The Hacks:
Quishing = Phishing + QR Codes
Attackers are hijacking the codes we trust every day.
😬 Parking meters
🍔 Menus
📧 Invoices
Learn how quishing works — and how to avoid it.
🔗 https://t.co/p16gG6zd2m
#cybersecurity#phishing#quishing#infosec
I blocked my smart thermostat from the Internet.
Support said, “Just put it in the DMZ.”
That’s not Zero Trust. That’s zero security.
So I built NetBOM. It’s like SBOM—but for network behavior.
🔗 https://t.co/DINEUc4a45
#NetBOM#IoTSecurity#CyberSecurity#ZeroTrust
NetBOM v2.0 is out!
🔐 Smarter and more secure.
It’s a new way to think about securing IoT + OT, software and apps on your network!
NetBOM turns “plug and play” into “plug and protect.”
📖 https://t.co/ITjSDOS9wF
#NetBOM#IoTSecurity#PlugAndProtect#Infosec
“Nice files you got there. Shame if something happened to them.”
Ransomware is big business.
How it works, who gets hit, and how to stay safe—plus a printer with attitude.
👉 https://t.co/rHOb7Z1Y75
#ransomware#cybersecurity