Hot take: AI-driven adversaries operating inside your network in 2026 would be EASIER to catch than humans.
LLMs hallucinate, can't distinguish honeypots from production assets, and lack adversarial intuition.
Deploy deception. This is the one phase where the tech works in your favor.
Wrote about it here: https://t.co/wv5oLNFtKr
Do we need a recession?
The metrics are getting better, but for a lot of people things aren’t great - with some cheering for a downturn so they can buy a home or assets on sale.
But it doesn’t really work this way.
https://t.co/mnkD94hbLb
Microsoft Security has been tracking criminal actor DEV-0537 (LAPSUS$) targeting organizations with data exfiltration and destructive attacks - including Microsoft. Analysis and guidance in our latest blog: https://t.co/gTMXJCoPY5
Trying to write a thing a week.
First up, some basics! Covering domains, subdomains, nameservers, IPs/ASNs, how they all relate to each other, and how to use them to find additional attack surface!
https://t.co/eQc9HXuAv8
👀 A guide to learning blockchain/smart contract hacking, turn a LFI into an RCE and how to setup your own burp collaborator... and much more!
Here's our #HACKPACK12, perfect to start this new year! #BugBounty#YesWeRHackers 👇
https://t.co/cKyuvHeNmE
10 #Log4Shell Facts vs Fiction: a 🧵
1. 1.x is NOT vuln to this RCE. While it doesn't have another RCE, it requires access to send serialized data to a listener ON the log server. This is much MUCH harder to exploit and kind of rare for a Log4j server to be running.
Some Detections for this IR report
https://t.co/hGZLzekBCl:
https://t.co/Y3BvgeInbG
https://t.co/9BUpvMjSKE
https://t.co/wRfQ8jxzQu
https://t.co/KryLkzNEaO
https://t.co/DrfDvWTkiy
https://t.co/bGZXazMFJQ
New blog: We're sharing technical information about CVE-2021-35211 that we shared with SolarWinds via coordinated vulnerability disclosure. Learn how we found the issue and how we worked with SolarWinds to fix the vulnerability and mitigate the attacks. https://t.co/XIZHYP0Upv