Social engineering & hacking videos, training, talks, tests, & workshops to protect the human element of security. Here to help your org get politely paranoid.
We are so excited for the new Music and Spoken Hacking Demo security awareness Training Videos we just released! Thank you to the orgs who already signed up, if you prefer to watch a demo without need for a phone call, here’s the form for that! https://t.co/bL9SAVYxXh
*ANNOUNCEMENT*
Presenting: the trailer for our new 🎶MUSICAL🎶 & spoken Security Awareness Videos! After the infosec sea shanty, dozens of teams DM’d me saying "The song worked! MFA usage up, reporting way up, pls make more songs!" So we got to work & you all it's finally here!🤖
WHOA @Google let me know they saw my tweet below last year & built a tool to defend against this exact call spoofing + AI voice clone attack!
As of today, fake call detection on Android alerts when someone is impersonating your contact.
Demo & thread of how it catches attackers:
👀 We asked @socialproofsec to hack us 110+ times.
Independent pentest across 13 attack types: deepfakes, injection attacks, AI-generated docs, emulators, replay attacks.
Zero mobile bypasses.
Full report ↓
https://t.co/YyIQbEQ8ZZ
One of the coolest parts of my job, getting to hack for good. Test every attack method used in the wild, assume there will be some vulns, and fix them quick.
Get our full Pentest Report from @IncodeIdentity and see what they can do at: https://t.co/wgPE1nJPcv
Tested mobile & browser: hard/software vid injection, deepfakes, replays, emulators, rooted devices, manipulated ids.
Mobile held up every time. Web flows were the 1 way in. When we got in w/ web hard/software vid injection, we gave those vulns to Incode & they fixed them quick.
I used deepfakes & injection attacks to hack an identity verification tool used for remote workforce, helpdesk, & onboarding…until they updated the tool to catch me.
Thank you @IncodeIdentity for having me hack you 110+ times to find the latest vulns and fix them together 🤖🤘
Canvas, the tool teachers and students are using for finals right now, was hit w/ ransomware by (folks who claim to be) ShinyHunters. Lots of students/educators saying this is making finals studying/tests v hard (not even considering the amount of data likely to be leaked here)!
Canvas is hacked and stressing out 230+ Million students, teachers and staff during finals. What does this mean and how do we stay safe? What are the next steps for the 8,800 affected schools during finals. Answered below in my video:
We are so excited for the new Music and Spoken Hacking Demo security awareness Training Videos we just released! Thank you to the orgs who already signed up, if you prefer to watch a demo without need for a phone call, here’s the form for that! https://t.co/bL9SAVYxXh
*ANNOUNCEMENT*
Presenting: the trailer for our new 🎶MUSICAL🎶 & spoken Security Awareness Videos! After the infosec sea shanty, dozens of teams DM’d me saying "The song worked! MFA usage up, reporting way up, pls make more songs!" So we got to work & you all it's finally here!🤖
@RachelTobac@wisporg We at @socialproofsec are proud to donate $4k to WISP to sponsor the local groups, new scholarships, events and more!! Who is matching our donation next?
.@socialproofsec Co-Founder & CEO @RachelTobac joined @JillMalandrino to discuss how to spot a deepfake video and how the technology is constantly evolving.
Watch the full video: https://t.co/OMqoLYa15H
The @ScammerPayback podcast was one of my favorite interviews of all time. I got to:
- do hard OSINT on Daniel, present my findings live and shock the glasses off him multiple times
- live hack his bank account in front of him by calling his friends and using AI voice clones to take over his account
- talk about the changes in hacking due to AI
- discuss how AI psychosis happens from a neuroscience perspective
- tell a never before heard story about how I almost got the worst job in history
- and what we can do to protect people from scammers in 2025 in our personal and professional life.
This is also probably the funniest interview I've done in years. I haven't gotten to laugh this hard on camera in a while.
https://t.co/SkEq0csiCa
*New live hack demo - stealing security question answers with AI voice clones*
At @defcon I went on @ScammerPayback podcast and hacked @daniel_payback by calling his friends & stealing answers to his bank's password reset identity questions using a voice clone within 10 seconds.
Me and @davegerryjr are live on @Nasdaq@TradeTalks right now with a live video and audio deepfake, security insights and takeaways to protect your family and company!