@MwangoCapital Its good to recognize our own Talents as a country(Kenya) and leverage on this.
A good example is talented young people who have passed through @AfricaHackon and @cybersafehq
VERCEL GOT HACKED
ShinyHunters - the group behind the Ticketmaster breach - is selling Vercel's internal database for $2M on BreachForums
here's why every developer should care:
- they have NPM tokens and GitHub tokens
- Vercel owns Next.js - 6 million weekly downloads
- one malicious push = global supply chain attack
- Vercel confirmed the breach today, April 19
- they literally DMed the hackers on Telegram asking them to stop
rotate your env variables RIGHT NOW
NEVER UNDERESTIMATE A YOUNG MAN WHO’S GRINDING IN THE SHADOWS.
- Working
- Studying
- Eating healthy
- Going to the GYM
This man will OVERTAKE his peers while they’re too busy partying.
Dear Brother, Become this man.
After a certain age, your parents slowly become your children. They ask simple questions, repeat stories, and depend on your patience the way you once depended on theirs. Very few understand this role reversal.What looks like innocence or inconvenience is really time coming full circle. Don't correct them harshly. Don't rush them. Care for them the way they once protected you. This is not a burden. It is repayment.
UK government is rapidly improving it's cyber security and resilience of public services with the newly published "Government Cyber Action Plan"
The plan was released today ( 6 January 2026) alongside the Second Reading of the "Cyber Security and Resilience Bill" in the House of Commons. This Bill aims to:
1. Expand the scope of the 2018 NIS Regulations to include managed service providers, data centers, and large load controllers,
2. Mandate incident reporting within 24 hours for significant incidents, and
3. Increase maximum fines for serious breaches to £17 million or 4% of turnover.
I'm very happy to learn among others, this new plan allows the UK Government to initiate the Government Cyber Unit (GCU)
GCU, A new central unit led by the Government Chief Information Security Officer (CISO) - It coordinates risk management and incident response across all departments.
I'm sure this new cyber action plan will help the UK government to protect online public services and strengthen digital resilience across the public sector.
🆕New version of our #ransomware mapping is out on our GitHub!
➡️https://t.co/M9vmt1UZzj
V28 (!) includes latest newcomers and recent ecosystem evolutions.🔍
As always, feedback is welcome!
#cti#threatintel#blackbasta#ransomhub#lockbit
Data sovereignty is not just a checkbox; it's a critical responsibility. @cloudplexo & @aws are leading the charge in ensuring secure, compliant, and localized data solutions for a connected world.
#africahackon monthly meetup.
Free Online Cybersecurity Courses and Certifications in 2025.
Here are 15 FREE courses to help you master Cybersecurity 👇👇
1. IBM Cybersecurity Analyst Professional Certificate
🔗https://t.co/2jRxn10kjz
2. Microsoft Cybersecurity Analyst Professional Certificate
🔗 https://t.co/5e5eQxA84P
3. Cloud Application Development Foundations Specialization
🔗 https://t.co/9iWY5A2fup
4. Developing Applications with Google Cloud Specialization
🔗 https://t.co/Mi6gHvfJFN
5.Introduction to Cloud Computing
🔗 https://t.co/0uqyYL9iBK
6. Understanding Google Cloud Security and Operations
🔗 https://t.co/v8Z94BwtN4
7. Innovating with Data and Google Cloud
🔗 https://t.co/dnZ59ZTC9w
8. Microsoft Azure Fundamentals: Describe cloud concepts
🔗 https://t.co/gdHd2SlIra
9. GoogleCloud: Google Cloud Computing Foundations: Cloud Computing Fundamentals
🔗 https://t.co/b3CitYIFtB
10. Cloud Computing Basics (Cloud 101)
🔗https://t.co/vyKDyTcr1o
11. IT Fundamentals for Cybersecurity Specialization
🔗https://t.co/OgWdCensVa
12. Introduction to Cybersecurity Tools & Cyber Attacks
🔗 https://t.co/UbkohxmgJA
13. Cyber Security Course for Beginners
https://t.co/bBDau5ujRI
14. Introduction to Cyber Security
https://t.co/wpNGAmynDK
15. For Beginners
https://t.co/NGiPmE6aCt
Happy Learning 🌟
@cz_binance And to the builders on blockchain, dont forget to link up with me for Compliance and Risk questions and how best we can align with Global standards
🚨 SEC Prioritizes Crypto in 2025 Exams
The SEC will focus on cryptocurrency investments and compliance in 2025, examining trading practices, custody, and risk management. Amidst regulatory scrutiny, rumors suggest SEC Chairman Gary Gensler might step down post-elections.
Stay tuned for how these changes could reshape crypto oversight.
#Crypto #SEC
The NIST CSF 2.0 (Cyber Security Framework) Just Dropped. Whether you are Looking for a Career in GRC or you just want to Keep your Business Secure, this Security Framework is easy to Understand. Below is a Overview:
There are now 6 categories for the NIST CSF 2.0. By taking the time to review this framework, you will have a much better understanding of how to help an organization stay secure.
Remember to Save 💾 Bookmark this Post for Future Reference.
🟡 GOVERN (GV) - Making sure the organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.
1. Organizational Context
2. Risk Management Strategy
3. Roles, Responsibilities, and Authorities
4. Policy
5. Oversight
6. Cybersecurity Supply Chain Risk Management
🔵 IDENTIFY (ID) - Ensuring the organization's current cybersecurity risks are understood.
1. Asset Management
2. Risk Assessment
3. Improvement
🟣 PROTECT (PR) - Putting in safeguards to manage the organization's cybersecurity risks are used.
1. Identity Management, Authentication, and Access Control
2. Awareness and Training
3. Data Security
4. Platform Security
5. Technology Infrastructure Resilience
🟠 DETECT (DE) - Making sure possible cybersecurity attacks and compromises are found and analyzed.
1. Continuous Monitoring
2. Adverse Event Analysis
🔴 RESPOND (RS) - These are actions regarding a detected cybersecurity incident are taken.
1. Incident Management
2. Incident Analysis
3. Incident Response Reporting and Communication
4. Incident Mitigation
🟢 RECOVER (RC) - Ensuring assets and operations affected by a cybersecurity incident are restored.
1. Incident Recovery Plan Execution
2. Incident Recovery Communication
There is no need to reinvent the wheel. This Cyber Security Framework lays out a complete security posture that you can align with. Learning this framework inside out will help you:
✅ Enjoy a great Cyber Security Career in GRC
✅ Help Protect your Own Organization
This is the first major update since it's creation over a decade ago. Remember, knowledge is power. The more you learn, the more valuable you are as a Cyber Security Professional.
🚨 If you are struggling in your career and want help, PM me. 🚨
This week I’ll be sending 10,000 people Career Advice to help land a job. Signup at ➡️ https://t.co/GcdJet8jHq.
If this was helpful to you, consider ♻ reposting for others. Bookmark 💾 this post for future reference.
#cybersecurity #informationsecurity #infosec #leadershipbyexample
Limitations of the current bitcoin protocol
●Transactions are processed too slowly
●Transactions become too expensive when the networks becomes active/when congestion happens
Transactions per secomd Comparisons
■Visa-5000 to 65,000
■Bitcoin-5 to 7
■Ethereum 10-15
Here's a Secret Position in Cyber Security that you didn't think of. Were you aware of this?
Whether we like it or not, compliance is one of the biggest drivers for Cyber Security.
Compliance forces companies to comply with certain standards around their security implementation. Unfortunately, many companies are only spending money because of compliance. Compliance does not equal security, but it is still the reason companies are spending money to protect their digital assets.
There are various types of security frameworks that companies must comply to, but for this particular post I'm going to talk about one that I've been working with for years, which is PCI compliance. PCI stands for Payment Card Industry, meaning credit-debit cards.
The PCI framework was set in place to protect consumers from having their credit card information go into the wrong hands. PCI standards for compliance were developed and are managed by the PCI Security Standards Council.
Any business that takes a certain amount of credit cards must comply to PCI standards. There are 4 levels of merchants, which are determined by the amount of credit card transactions per year. Today I'm just going to talk about Level 1 merchants.
Level 1 merchants (processing over 6 million transactions) each year must have a RoC (Report on Compliance) sign off from a PCI-QSA which is someone who has been certified as an auditor from the PCI Council. These RoCs have over 300 security requirements that must be met by the business. At a high level, these include 12 major requirements for things such as firewalls, passwords, encryption, antivirus, physical protection requirements, vulnerability scans, penetration testing, and others.
A third party QSA is the only person that can sign off on a RoC for the business. QSAs are in extremely high demand. They do not have to be extremely technical, but they must know how to use their resources to gather documentation and evidence that the company is meeting standards.
Many merchants I've worked with over the years do not understand the PCI security requirements. It is the QSAs job to explain the requirements as effectively as possible to the business.
Often times there are PCI GAP assessments conducted prior to an actual QSA doing their assessment. This assessment can be done by anyone who understands the PCI framework and is able to help the business understand how well their infrastructure aligns with it. The cost is much less to have the business work with someone to do a GAP assessment to help them align with the requirements before a QSA does the actual assessment.
✅ Learn Compliance Requirements
✅ Help Businesses Solve Compliance Requirements
It's as simple as that. Is this something you could do?
Each week I email thousands of people exact directions on how to get a job in Cyber Security. Want my emails? Go to ➡https://t.co/GcdJet8jHq⬅.
Help keep this alive ♻.
#cybersecurity #informationsecurity #infosec #leadershipbyexample
@MarvinGakunyi Welcome to samsung Gang @SamsungMobileKE
I have used S22+(plus) since launch and I have never regreted, super fast as well, Quality pic👌