Earlier this week I gave a talk to our internal hacking teams about the difference between good hackers and great ones that have been able to impact our field. I included three extended quotes - two from writers and one from Hamming that influenced my approach early on. Maybe some of it is useful for you.
A pentest tells you what was exploitable. A vuln scanner tells you what might be. Neither tells you what's exposed right now. ActiveWatch does—continuous, attacker-style monitoring of your internet-facing assets. Only confirmed vulnerabilities. More here: https://t.co/3g4JEinakC
Hackers are no longer just going after the obvious targets. Retail. Healthcare. Finance. If you hold people's data and cannot afford to go offline, you are interesting to them now. Find out more in our Security Navigator: https://t.co/aMrlFZAwSw
Technical Tuesday: We came to investigate one compromised website and walked away with two new CVEs in CraftCMS 4.12.8, uncovered during live incident response. Classic scope creep, except this kind helps everyone. Find out more here: https://t.co/FsIgIxzq8z
I checked the AGSA report from 2013/2014, South African .gov has barely managed to improve 10 points in over 10 years - in case you're wondering why TA's are blowing through them.
The Auditor-General assessed 70 government entities in 2024/25. Forty-five had cybersecurity weaknesses. Only 36% had good controls. Unresolved recommendations are not a compliance footnote. We help organisations understand their exposure before someone else does. Get in touch.
#TechnicalTuesday: Leon Jacobs tested pre-installed software from six brands and found vulnerabilities in all six. This is not a careless brand story, but a "nobody tests this layer" story that runs elevated on everything you own. Read more: https://t.co/7M8VRRYwY7
Technical Tuesdays: In 2025, SensePost researcher Leon Jacobs explored how attackers exploit Windows named pipes, building pipetap. It routes connections via injected processes, bypassing identity checks to view and modify processes. Read more: https://t.co/Jt47L3pVHX
#TechnicalTuesday: A "no-touch" door sensor is built to let people in or out without touch. In testing, Michael Rodger triggered one from metres away using infrared light. It opened. Convenience and access control? Not the same thing. More here: https://t.co/Vx2BBVfdcR
Technical Tuesday: Isak Van Der Walt found a way to change what an app trusts without reversing the whole system. If trust can be edited at runtime, it stops being a safety net. When last did someone test whether yours could be? Read more here: https://t.co/Z4avzrsTaD
Technical Tuesdays: Your flat internal network could be handing your domain to attackers. A non-hierarchical setup lets them hijack sessions via shadow RDP, steal tokens, and impersonate users undetected. Aurelien Chalot explains how tiering helps: https://t.co/UQ4TEknDh2
Deep-Live-Cam needs you to pay to get the higher quality HyperSwap model support, so codex vibe'd it in for me based on FaceFusion's implementation. You can grab it below. You'll probably never believe me that this isn't actually the president of South Africa O_o