Today is the day we finally get to announce that we closed funding of our seed round for our new company Evidence. This day represents over a decade of brainstorming and years of gathering data and talking to design partners.
This is a compression bomb + slowloris - basically large decompression and holding the socket open. Two unrelated DoS types chained together with Codex.
Introducing HTTP/2 Bomb: a remote DoS in nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora. A single client pins 32GB of server memory in 10s. Found by Codex.
Blog post: https://t.co/WO9MeExoun
PoCs: https://t.co/NpVgEHBHPl
For my Massachusetts homies, if you're on the south shore on Saturday, come see me at the Plymouth Public Library Local Author Fair. I'll be signing my books. If you ask nicely, I'll tell you a funny story about @ryanaraine or @RSnake. Or both.
Lib Theseus is out! It's basically a skill that removes your 3rd party code and replaces it with 3rd party code. It removes CVEs, and can actually dramatically improve security as a consequence, though it's mainly meant for compliance.
@eliedelkind@anton_chuvakin If we were always doing it and it worked there would be no compromises. So something has to fundamentally change for the average network if that is the answer since the average network is flat and non-compartmentalized and more or less one vuln away from wide open.
As I’ve been saying, the time from patch availability to exploit creation to target acquisition will reduce down to minutes -- even seconds in some cases. NO WAY patch management will be able to keep up. Defense models will be forced to change.
https://t.co/kTMuMZ3k6B
Most organizations don't know which vulnerabilities will actually cost them money. They're managing thousands, patching by severity scores, and still getting breached.
At RSA, our co-founder @RSnake sat down with Yahoo Finance's Tech Edge to talk about what tech-enabled underwriting actually looks like and why clean, financial-risk-driven data changes things entirely.
If you're in security, risk, or underwriting, this one's worth 10 minutes.
🔗 https://t.co/lY1or79Rbq
Couldn’t keep up with everything at #RSAC2026?
Join @RSnake, @paulfroberts & @charlie_jones3 as they break down the security trends worth your attention:
🔍 AI security verification
📦 Supply chain transparency
⚠️ Commercial software risk
🎁 10 attendees get a free copy of RSnake's book, AI’s Best Friend 👇
https://t.co/ouWjPQFRH1
📖 RL Book Club at #RSAC2026
Meet Robert @RSnake Hansen, author of AI’s Best Friend, at Booth #4328 on March 24.
🕑 2:00 PM Author discussion
✍️ 2:15 PM Signing & giveaway
🎁 First 100 attendees get a signed copy.
Into #AI security? Don’t miss it.
https://t.co/lEKhDJOtA7
#ArtificialIntelligence #RLBookClub
I’m trying to collect stories about bad things that happen to companies where the executives lose control of or almost lose control of their companies.
- Contract issues (poorly negotiated)
- Tech issues (hacking or outages or…)
- Customer shifts (lost revenue)
- Hostile takeover
- Deaths/departures of key employees
- Etc…
I want to hear your anecdotes, if you have seen or heard of these types of scenarios.
You have a huge monitor so that you can run multiple apps and see them all at once. I have a huge monitor so that my cat can block half of it and I can still work. We are not the same.