SITUATION DETECTED: President Trump signed a historic National Security Memo empowering U.S. federal law enforcement to leverage private-sector tech innovations to actively hunt, track, and execute cyber operations against foreign-based transnational criminal organizations.
This past week I’ve been asked several times by people of different ages “how do you research and publish so much?”. It’s awesome to be asked. I love sharing tips and I try to give my techniques for maintaining a research pipeline. But I also want to be honest about my reality. At times, it’s an unhealthy coping technique. I’m getting much better at it, but in the past I’ve not been so good. I’ve skirted psych wards on multiple occasions, been given a “multiple weeks off work with several therapy sessions” order, been on various psych meds, torpedoed family events and holidays etc... Social media highlights the wins, but I try and be honest about the lows too where I can.
This industry is awesome, for many of us it gives us the chance to pursue our hobbies and passions. But it does encourage unhealthy routines. There is a reason that alcohol, drugs and mental health issues are embedded in infosec culture. And while sharing a new blog post or cool vuln can inspire people to want to be doing more, it shouldn’t come at the expense of a healthy mind.
An old boss once said “we want you doing this for a long time, not doing a lot in a short time”.. I still think about this now. Stay healthy h4xx0rz!
Swipe app for iOS with cyber security news from 188 RSS feeds. No account needed, no ads, promises no tracking.
Made by “merillmatt011” (not sure if this person has a profile here).
https://t.co/BMsTI05ld0
https://t.co/KMoIeoiX0G
If you want to age your sys admins 30 years overnight, remember that Active Directory is fully unicode compatible, so you can rename your laptop with emojis it its hostname, and it will reflect like that in AD
ping desktop-🤷♂️👍👌.mycompany.local
After 11 years of silence at Black Hat, I am delivering a speech today.
In memory of a legendary APT Hunter, Mr Sergey Mineev, who passed away 40 days ago.
If you cannot attend, here is the write-up: https://t.co/JUO4VBtnSZ
This is what it takes to work in JUST Entra and Purview alone. LLMs cannot teach you this. Context matters.
What is Entra? 491 pages
https://t.co/1Dn8jEZZfd
Entra Authentication: 1356 pages
https://t.co/fQMq3a0gqk
Entra Application Management: 897 pages
https://t.co/fQMq3a0gqk
Entra RBAC: 581 pages
https://t.co/WNc3ZnNqxA
Entra User Management: 623 pages
https://t.co/vGI1703FOD
Entra Conditional Access: 424 pages
https://t.co/ziZ9ZMd7Wy
Entra Device Identity: 399 pages
https://t.co/MWGtmdgoPz
Entra Hybrid Identity: 2546 pages
https://t.co/TCepteXy5H
Entra Application Provisioning: 742 pages
https://t.co/I8AZJelNil
Entra Application Proxy: 350 pages
https://t.co/E5IabbRC8H
Entra Managed Identities for Azure Resources: 210 pages
https://t.co/pvv3XMEpMS
Application Integrations: 12741 pages - but a reference
https://t.co/DLIVtw5oiu
Entra Monitoring and Health: 438 Pages
https://t.co/hozqciI1bX
Entra Multitenant: 214 pages
https://t.co/5xHGbOn6gH
Entra Domain Services: 458 pages
https://t.co/O7gxFVcDLD
it goes on and on and on...
Then you have a separate documentation repository for B2C, probably a few thousand more pages: https://t.co/WnzlifV96G
Microsoft Identity Platform: 2182 pages
https://t.co/seWtGOAWRn
Purview Documentation: 8876 pages
https://t.co/HwJNMYUpaR
I wonder if that Cisco root password (CVE-2025-20309) was something really simple like root, toor, devroot or if they used something more complex.
You are welcome to post some funny wrong passwords 😺