Sign in

Alex Pinto

@alexcp.bsky.social
719 followers 832 following 136 posts

Cybersecurity data storytelling. DBIR at Verizon Business. Previously serial founder and parallel shitposter. He/him.

PostsRepliesMedia
Reposted by Alex Pinto
Kenny Logins @kennylogins.bsky.social · 09/11/2024
Matt
@scriptumsent
Nathan Fielder descending through Dante's inferno going "oh ok" to everyone's stories
10:09 AM • 2022-07-30
11630246
Reposted by Alex Pinto
Shostack + Associates @shostackassociates.bsky.social · 21/08/2026
Adam has announced the second edition of his threat modeling classic! Half of the book is completely new or heavily rewritten to handle a decade of shifts in tech and security. If you want to build safer systems, pre-order today! Adam's written about it on the blog: shostack.org/blog/threat-...
022
Alex Pinto @alexcp.bsky.social · 29/07/2026
Exceptional detail. Very much worth the read.
030
Reposted by Alex Pinto
Gadi Evron @gadievron.bsky.social · 27/07/2026
Releasing: Post mortem analysis of the Hugging Face incident was written over the weekend by hundreds of CISOs (and reviewed by Hugging Face). Link: cloudsecurityalliance.org/artifacts/hu... (+free download) From CSA, SANSInstitute, Knostic, [un]prompted, RSAC, FIRST
cloudsecurityalliance.org
Hugging Face Incident Initial Post Mortem I CSA
AI Security Alliance's initial post-mortem on the Hugging Face incident, the first documented autonomous AI attack, with CISO guidance on detecting, responding to, and governing agentic AI risk.
22113
Alex Pinto @alexcp.bsky.social · 24/07/2026
This is 100% the correct take. Moreover, no one will be help responsible and it will be used for marketing by all involved.
031
Alex Pinto @alexcp.bsky.social · 27/06/2026
Art.
0160
Reposted by Alex Pinto
Dennis @dennisf.bsky.social · 17/06/2026
New podcast is up, a fascinating conversation with @alexcp.bsky.social on the first Breach Impact Study and the 2026 DBIR. open.spotify.com/episode/3F3j...
open.spotify.com
How Much Do Data Breaches Really Cost? | Alex Pinto
Decipher Security Podcast · Episode
011
Reposted by Alex Pinto
turning edelgard into things she edelgaren't @mousegard.bsky.social · 10/06/2026
there was a scientific study recently that showed using ai for even as little as 15 minutes reduces your persistence, making you more likely to give up on a task if you can't use ai for it, less likely to acquire new skills, and less able to work independently: arxiv.org/abs/2604.04721
arxiv.org
AI Assistance Reduces Persistence and Hurts Independent Performance
People often optimize for long-term goals in collaboration: A mentor or companion doesn't just answer questions, but also scaffolds learning, tracks progress, and prioritizes the other person's growth...
51291634
Reposted by Alex Pinto
Alex Pinto @alexcp.bsky.social · 19/05/2026
Time to update my pinned skeet because the 2026 #DBIR is out today! This year’s theme is about “keeping a strong foundation in the face of change” and boy have there been changes in the threat landscape last year. Get your report here: Verizon.com/dbir
verizon.com
2026 Data Breach Investigations Report (DBIR)
Read the complete 2026 Data Breach Investigations Report (DBIR) for an in-depth, authoritative analysis of the latest cyber threats, data breaches, and actionable cybersecurity risks.
142
Reposted by Alex Pinto
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 26/05/2026
New @lutasecurity.bsky.social blog: AI Vulnerability Coordination at Vulnapalooza — 1st #Mythos Encore @anthropic.com 1st Glasswing update surfaces bottlenecks in patch creation & deployment. Read about a systemic maturity approach to vulnerability coordination www.lutasecurity.com/post/vulnapa...
lutasecurity.com
AI Vulnerability Coordination at Vulnapalooza: Mythos Encore Insights
Anthropic published its first Glasswing update and the bottlenecks in patch creation and deployment need a systemic maturity approach.
1235
Reposted by Alex Pinto
Adrian Sanabria @sawaba.bsky.social · 19/05/2026
Happy DBIR day everyone! It's really good, as always. I wrote up some thoughts: www.defendersinitiative.com/p/verizons-1...
defendersinitiative.com
Verizon's 19th edition of the DBIR confirms the vulnpocalypse***
But with many asterisks! Read on to find out why 😅
131
Alex Pinto @alexcp.bsky.social · 19/05/2026
Time to update my pinned skeet because the 2026 #DBIR is out today! This year’s theme is about “keeping a strong foundation in the face of change” and boy have there been changes in the threat landscape last year. Get your report here: Verizon.com/dbir
verizon.com
2026 Data Breach Investigations Report (DBIR)
Read the complete 2026 Data Breach Investigations Report (DBIR) for an in-depth, authoritative analysis of the latest cyber threats, data breaches, and actionable cybersecurity risks.
142
Reposted by Alex Pinto
Mathew J Schwartz @mathewjschwartz.bsky.social · 19/05/2026
Verizon's latest Data Breach Investigations Breach Report finds vulnerability exploitation surging, patch rollout slowing and ransomware incidents rising. www.databreachtoday.com/verizon-brea...
databreachtoday.com
Verizon Breach Report: Vulnerability Exploitation Surges
The frequency of hackers exploiting vulnerabilities in hardware and software to gain initial access to a victim's environment continues to surge, and half of all
174
Reposted by Alex Pinto
Censys @censys.bsky.social · 19/05/2026
4 straight years powering the Verizon #DBIR w/ Censys Internet intelligence. The 2026 report reinforces a growing reality: Internet visibility has become foundational for defenders amid vulnerability exploitation, AI-enabled attacks & rapidly shifting infrastructure. bit.ly/4uYZPXD #DBIR
011
Reposted by Alex Pinto
Brian Honan @brianhonan.bsky.social · 19/05/2026
One of my must reads each year is the @verizonofficial.bsky.social #DBIR report. @irisscert.bsky.social is one of the contributors so I'm always interested to see what #cybersecurity trends are relative to Ireland, and indeed businesses elsewhere. bhconsulting.ie/lessons-for-...
bhconsulting.ie
Lessons for Irish Organisations from the Verizon 2026 Data Breach Investigations Report (DBIR)
Our CEO, Brian Honan, discusses his views and opinions on the Verizon DBIR 2026 and why the report is always a must read.
044
Reposted by Alex Pinto
Fellow Traveller @fellowtraveller.games · 01/05/2026
Forbidden Solitaire AND Titanium Court in ONE BUNDLE? (is that allowed?) That's two games that shouldn't exist at a very real discount of 15%! They forbade us, but we didn't listen! 💎 🏰 store.steampowered.com/bundle/72486...
215152
Alex Pinto @alexcp.bsky.social · 16/04/2026
Iguanodon is the correct answer.
210
Reposted by Alex Pinto
sephirAmy @sephiramy.bsky.social · 11/04/2026
🌕 ✨️ ✨️ 🌟 ✨️ ✨️ 🌟 🌟 🪂 🚀💦 🌊🌊🌊🌊🌊🌊🌊🌊🌊🌊🌊🌊
92056545
Alex Pinto @alexcp.bsky.social · 10/04/2026
Didn’t have “front seat to the vulnpocalypse” in my 2026 bingo card.
220
Reposted by Alex Pinto
cje @cje.io · 10/04/2026
Wrote about the attacker-defender asymmetry and why AI made it worse -- "AI for defense" is stuck polishing the top five turtles while adversaries live in the bottom ten. cje.io/2026/04/08/offense-scales-wi…
1126
Alex Pinto @alexcp.bsky.social · 02/04/2026
I know this was written from the perspective of cybersecurity detection workloads but it applies to absolutely everywhere where AI is being forced into the workplace without any forethought. www.sentinelone.com/blog/the-imp...
sentinelone.com
The Implementation Blind Spot | Why Organizations Are Confusing Temporary Friction with Permanent Safety
Our new blog post explores the ‘cognitive rust belt’ — how AI friction masks skill loss and why organizations must act now.
010
Reposted by Alex Pinto
Rob Sheridan @rob-sheridan.com · 25/03/2026
Nothing but respect for MY formative young adult fantasy novel series
Dragon Lance Chronicles Vol 1: Dragons of Autumn Twilight by Margaret Weis and Tracy Hickman
2827536
Reposted by Alex Pinto
Pat Thomson @patthomson.bsky.social · 08/03/2026
Academic writers often feel uncomfortable but that’s often OK Here’s why patthomson.net/2026/03/08/g...
patthomson.net
getting comfortable with being uncomfortable
Good academic writing means sitting with a discomfort that never entirely goes away. It’s not a discomfort that comes from having nothing to say. Most of us have more than enough ideas crowding the…
76425
Reposted by Alex Pinto
Joseph Menn @joemenn.bsky.social · 24/02/2026
Here we go. Free, no-reg versions of favorite stories from my four years at the Washington Post. First, three pieces from our Pulitzer-finalist series on how India's ruling party coerced U.S. tech giants into violating their own policies. www.washingtonpost.com/world/2023/0...
washingtonpost.com
Under India’s pressure, Facebook let propaganda and hate speech thrive
Facebook has retreated from its professed ideals in India under pressure from Prime Minister Narendra Modi’s Bharatiya Janata Party.
616066
Reposted by Alex Pinto
Brandon Friedman @brandonfriedman.bsky.social · 09/02/2026
The nice commercial about helping kids find their lost pets was the scariest thing I've seen in my life
331591279
Reposted by Alex Pinto
SentinelOne @sentinelone.com · 29/01/2026
🧵 175,000+ exposed AI hosts. Zero guardrails. New research from @sentinellabs.bsky.social and @censys.bsky.social reveals a massive, unmanaged layer of open-source AI infrastructure operating in the shadows. s1.ai/si-llama Here is what you need to know about the "silent" AI network. ⤵️
142
Reposted by Alex Pinto
Anil Dash @anildash.com · 28/12/2025
By any reasonable historical standard — including that of the technology industry! — ChatGPT should be pulled from the market and its product managers and executives held accountable for creating a product that ROUTINELY tells teens to kill themselves. This is a basic, common sense standard.
202296499
Alex Pinto @alexcp.bsky.social · 09/12/2025
I have been thinking a lot about this too @jags.bsky.social
Excerpt from SentinelOne article about cybersecurity predictions: “The value
generated in 2026 and beyond is entirely
concentrated in filling that gap between
frontier capability and operational deployment.”
140
Reposted by Alex Pinto
Decipher @deciphersec.bsky.social · 14/11/2025
decipher.sc/2025/11/14/m...
decipher.sc
Marks and Spencer’s Profit Drop: The Financial Toll of Cyberattacks - Decipher
The financial impacts of cyberattacks are hard to measure - but they lend critical context to conversations around security risk at the boardroom level.
022
Alex Pinto @alexcp.bsky.social · 03/11/2025
2026 DBIR sneak peek: “Water plays an increasingly significant role in [ransomware] attacks. In 2024, 100% of recorded ransomware events were attributed to threat actors that drink water”
131
Alex Pinto @alexcp.bsky.social · 21/10/2025
What is an “AI-enabled Ransomware”?
310
Reposted by Alex Pinto
lauren @lauren.rotatingsandwiches.com · 03/10/2025
i'm inventing a new kind of roguelike where instead of poker, slot machines or coin flipping you play as a little guy with a sword
2852343
Reposted by Alex Pinto
holden m. accountable @noahs.bsky.social · 29/09/2025
THE MEME IS REAL
5591232749
Reposted by Alex Pinto
Adam Shostack :donor: :rebelverified: @adamshostack.infosec.exchange.ap.brid.gy · 26/09/2025
I did a long, in depth podcast with Shannon Lantzy, you can listen at www.shannonlantzy.com/post/from-mic…
shannonlantzy.com
From Microsoft's Crisis to Medical Device Revolution: The Evolution of Threat Modeling
The year 2002 marked a turning point in cybersecurity history, though few realized it at the time. Microsoft was hemorrhaging customers due to security vulnerabilities, worms were spreading unchecked, and patching costs were mounting. In the midst of this crisis, Bill Gates penned his famous memo on "trustworthy computing," setting the stage for a fundamental transformation in how we approach software security.At the center of this transformation was Adam Shostack, a critic-turned-insider who wo
011
Alex Pinto @alexcp.bsky.social · 16/09/2025
Putting the whole “chat bots are bad for your psyche” thing aside, this is brilliant experiment design. www.businessinsider.com/reddit-aita-...
businessinsider.com
Am I the jerk? Redditors say yes — but ChatGPT and other bots say no.
ChatGPT and other AI bots tell posters from Reddit's "AITA" board that, actually, they're not the jerks.
020
Alex Pinto @alexcp.bsky.social · 11/09/2025
As a Brazilian-American, my feelings about 9/11 are now very conflicted.
050
Alex Pinto @alexcp.bsky.social · 11/09/2025
This one did make the DBIR Breach Hall Of Fame 2019. First and only breach where the threat actor was outside planet Earth. github.com/vz-risk/VCDB...
github.com
NASA Astronaut Accused of Identity Theft in First Criminal Allegation from Space · Issue #13952 · vz-risk/VCDB
https://www.databreaches.net/nasa-astronaut-accused-of-identity-theft-in-first-criminal-allegation-from-space/ https://www.military.com/daily-news/2019/08/25/nasa-astronaut-accused-identity-theft-f...
040
Reposted by Alex Pinto
Cyber Threat Alliance @cyberalliance.bsky.social · 11/09/2025
Now available on-demand. What Gets Measured, Gets Done: A National Dashboard for Cybersecurity www.youtube.com/watch?v=yBeV... with lumanaries in the cyber measurement field. #cybersecurity #cybermetrics #threatintelligence
youtube.com
CTA Webinar What Gets Measured, Gets Done A National Dashboard for Cybersecurity
YouTube video by Cyber Threat Alliance
011
Alex Pinto @alexcp.bsky.social · 03/09/2025
If AI models were able to do all the things people claim they do, the foundational model companies would be raking in Trillions from the additional output and they would keep the AI itself under lock and key. It’s like buying a “how to get rich” course off the internet.
01310
Reposted by Alex Pinto
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️‍🌈 @hrbrmstr.dev · 14/08/2025
PHENOMENAL work by @censys.bsky.social w/special shout out to one of the best cyber researchers out there (Himaja, who is smartly not on social media). They discovered sophisticated proxy infra designed for long-term espionage operations, & most victims probably have no idea they're compromised.
censys.com
2025 State of the Internet: Digging into Residential Proxy Infrastructure
In-depth analysis of the PolarEdge botnet (first reported on by Sekoia in early 2025) a suspected ORB targeting edge devices since mid-2023. This blog covers infrastructure patterns, profiles current ...
034
Alex Pinto @alexcp.bsky.social · 09/08/2025
Are there any good write ups on the Salesforce data exfils that have been happening? Did ShinyHunters create a mass credential dump tool just like the one we had last year with Snowflake?
010
Alex Pinto @alexcp.bsky.social · 08/08/2025
It seems like berries really are the LLM model’s weakness.
111
Alex Pinto @alexcp.bsky.social · 07/08/2025
Rare glimpse of the 2026 DBIR editorial document: “Given the prevalence of file transfer and management servers in 2023 and perimeter devices in 2024, you may ask yourself which one of those led the vulnerability exploitation vector in 2025.” “The answer is, of course, yes.”
020
Alex Pinto @alexcp.bsky.social · 07/08/2025
Oh no! Terrible week for it.
010
Alex Pinto @alexcp.bsky.social · 05/08/2025
Trump subiu no telhado. (For all the PT-BR idiom enjoyers out there)
101
Reposted by Alex Pinto
Shannon Vallor @shannonvallor.bsky.social · 05/08/2025
I laughed so hard I thought I was going to cough up an organ. Every line is gold.
colincornaby.me
In the Future All Food Will Be Cooked in a Microwave, and if You Can’t Deal With That Then You Need to Get Out of the Kitchen
As a restaurant owner – I’m astounded at the rate of progress since microwaves were released a few short years ago. Today’s microwave can cook a frozen burrito. Tomorrow’s m…
710347
Reposted by Alex Pinto
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️‍🌈 @hrbrmstr.dev · 31/07/2025
• What these signals might reveal about attacker workflows • How defenders can use this information to act early Read the full research report here: www.greynoise.io/resources/ea... Always happy to discuss or answer questions about the data — just drop a line at research@greynoise.io.
greynoise.io
Early Warning Signals: When Attacker Behavior Precedes New Vulnerabilities
GreyNoise’s new research reveals a recurring pattern: spikes in malicious activity often precede the disclosure of new CVEs — especially in enterprise edge technologies like VPNs and firewalls.
042
Reposted by Alex Pinto
Eric Geller @ericjgeller.com · 28/07/2025
Three high-profile former CISA employees have joined @istorg.bsky.social to keep working on Secure by Design and figure out a stable future for the CVE program. www.politico.com/newsletters/...
0159
Alex Pinto @alexcp.bsky.social · 16/06/2025
Saving this to read tomorrow.
020