You can catch @mikko and @tomituominen interviewing @halvarflake in their "Gentlemen Hackers" series.
Insightful, educational.. Worth it..
https://t.co/KFwX82ukNl
It's kinda been raised, but its nuts that (according to Mandiant/M-Trends) in 2025:
- vulnerabilities/exploits are the most frequently observed initial vector;
- the top 4 exploited vulns belong to security vendors.
What are we doing here? 🤯😱
@cybergibbons I think we're at the point where using a password manager & passkeys is the only reasonable advice. Nobody should know their passwords.
In security engineering, strictness and paranoia correlate with incompetence.
Easier to say ‘no’ than to deeply understand the use case and find middleground.
It's Baaaaaack!!
Our Credit Card Canarytokens are out of beta and on your Canarytoken servers..
- Grab one;
- Stash it somewhere "safe";
- We will notify you if it's ever used!
Read more about it at https://t.co/gqPXI0cf3j
Another CA fails the turing test, issuing a MITM certificate. This highlights ongoing issues with underperforming CAs. I’ve shared my thoughts on the incident and what to expect next. https://t.co/RFvoWBAmpq
Bingo.
The idea that there's some sort of meaningful foundational separation between "security" and "IT" in an organization is not only nonsensical but practically very destructive of efforts to implement good security.