Black Hat starts today.
If vulnerability management is a task that your team is responsible for, make time tomorrow to stop by the Nucleus Security @nucleussec booth (#5533) and meet Robert Hansen @RSnake and Jeremiah Grossman @jeremiahg. They’ll be signing copies of their new book, “The End of Guessing,” which explores why the future of vulnerability management depends on evidence, not assumptions.
📍 Aug. 5 | 2:00–3:00 PM
📍 Aug. 6 | 10:00–11:00 AM
See you in Las Vegas.
#blackhat #BHUSA #cybersecurity #vulnerabilitymanagement #riskmanagement #bookdebut
@bill_e_ghote@wmf In this case, I'm not sure, I didn't ask. :) But, suspect Yahoo's ISP made a mistake and hosted them on a subnet that was registered to Yahoo. Those sorts of things are not uncommon with IP address assignment system.
Long ago, when I worked at Yahoo, I hacked into a system on our IP-range. I looked around trying to figure out what it was or whose it was, and realized it wasn’t ours. It belonged to another company!
Knowing about the CFAA, I was genuinely worried and explained the situation to my manager. He asked, “Do you think anyone noticed?”
I said, “Unlikely.”
He replied, “Then don’t tell anyone.”
How times have changed.
Only 15 spots left for our BJJ event during @BlackHatEvents USA (2026)! ~60 of us will be on the mat, with a great list of coaches. I just saw that Syndicate won Gym of the Year, and John Wood (one of our coaches) won Coach of the Year! https://t.co/8S8Ri4be0f
A personal l thank you to our sponsors for their support to make this happen: @nucleussec,@wirespeed_,@axariaistaff,@tailrisked@rootevidence, @whoisxmlapi, and Tail Risk.
Reg: https://t.co/vAqFavyBl2
Reg open! Cyber-Security Brazilian Jiu-Jitsu Smackdown (2026). Held between @BlackHatEvents and @defcon.
(Thur, Aug 6), 60 cybersecurity pros on the mat, learning new moves, and making new friends. Instructed by @ForrestGriffin and several other elite level BJJ/MMA pros. BJJ first-timers always welcome!
Tickets: https://t.co/vAqFavyBl2
2025 Video: https://t.co/tLZnMdYDvO
Sponsored by: @nucleussec, @wirespeed_, @axariaistaff, @rootevidence, and @whoisxmlapi
With all the AI hype and hysteria surrounding vulnerabilities and exploits, it’s time for vendors to stand behind their claims and put their money where their mouth is. At Root Evidence, we spent years analyzing breach investigations and claims data to identify the tiny percentage of CVEs responsible for a disproportionate share of financial losses. Then we built the technology to find them at scale. Today, we’re standing behind that work with a $5,000,000 warranty.
https://t.co/1IwtM94kWe
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.
Access to all other Claude models is not affected.
We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible.
Read our full statement: https://t.co/bwn0sximKZ
CVE triage should be mandatory jury duty for CISSPs.
Backlog: ~26,000 CVEs.
CISSPs: ~170,000 worldwide.
Hey @CISAgov and @ISC2 , if every CISSP handled a few submissions, the queue could disappear in weeks!
@IceSolst@CISAgov@ISC2 That’s the beauty of the idea. We either eliminate the backlog or finally get an accurate count of practicing security professionals.