The recent Canvas LMS breach is a reminder that BOLA and BFLA remain two of the most dangerous API security flaws.
My latest blog explains how these weaknesses can lead to large-scale data exposure.
#Canvas#CyberSecurity#OWASP
https://t.co/i9Yr2Z9Ltf
OT systems built 30 years ago were designed for isolation, not connectivity. Today they run power, water and transport while connected for monitoring and remote access. The environment changed. The trust boundaries often didn’t. That’s where attackers live. #OTSecurity#CI
@Khalil_Elkurdi I’m not convinced this adds much over a well written natural prompt, apart from maybe consistency if you’re reusing it. Have you found it actually improves outputs?”
Microsoft woke up one day and decided to shove Copilot everywhere. Open OneDrive, check email, Office? Copilot. Now it even wants me to install Copilot on my phone just to access a shared file on OneDrive. Getting boring! #Microsoft#Copilot#AIfatigue (Photo Ai generated 🤷♂️😁)
Fantastic to see Dr Ahmed Abdalaal from the @UniWestminster speaking at the Diversity in Cybersecurity workshop at UWE Bristol.His talk “Reaching the Unreached: Offline-First Cryptography Education”, brings a fresh perspective on widening participation in Cybersecurity.
#dcs2026
@W_Naamani @fioredilo Oh misread it. You did exactly what most men would do. Some delivery services used to know what I want to eat the moment I called.
My latest article for the Conversation UK,
As long as the cybercriminals’ business model works, companies are vulnerable to attack https://t.co/5cHDBi66aQ via @ConversationUK
@iHady_ It is indeed. Lebanon even has some of the strongest allegedly "state-supported" APTs!
Maybe they should focus on building security instead of threat agents.
But then again, it’s Lebanon! Priorities for people in power are always different
@UK_Daniel_Card The biggest problem with social media, I think, is how it amplifies old issues, making them feel bigger than they are and creating a distorted reality.
@UK_Daniel_Card Daniel, this is getting ridiculous now. A company I worked with made their systems unusable in the name of “security.” Couldn’t copy text into their email system , not even an email address, yet I could forward the entire email to my personal account. Genius security 🤦♂️!