Sign in

Ben Rothke

@benrothke.bsky.social
799 followers 428 following 164 posts

I do information security, risk management and other tech stuff. Co-author of new book: The Definitive Guide to PCI DSS Version 4: Documentation, Compliance, and Management. amzn.to/3WhEfh1

PostsRepliesMedia
Ben Rothke @benrothke.bsky.social · 30/09/2026
Pete Rose banned from #MLB in 1989. Yet in 2020 @MLB starts relationship w/ @DraftKings & @NFL makes them Official Sports Betting Partner w/ @CaesarsSports & @FanaticsSports. @NHL partners w/ @BetMGM, @bet365, @FanDuel. Looks like fans are the real loser$. brothke.medium.com/why-you-shou...
brothke.medium.com
Why you should never sign up for an online casino sportsbook free offer
Because it’s risk-free for the casino — not you
010
Reposted by Ben Rothke
CyberCanon @cybercanon.org · 29/09/2026
📖 We have not one, but two reviews for today's book, 𝙏𝙝𝙚 𝘾𝙄𝙎𝙊 𝟯.𝟬, by Walt Powell. If you are a current or aspiring #CISO, you must check out the full reviews by Andrew Chrostowski and Arron Johnson: cybercanon.org/the-ciso-3-0... #CyberCanonReview #CyberCanonHallofFameNominee #CybersecurityBooks
"The CISO 3.0" Review by the CyberCanon
134
Ben Rothke @benrothke.bsky.social · 28/09/2026
A #cybersecurity analogy from recent #Louvre heist for better #SIEM use via federated indexing. @MuseeLouvre behavior that would’ve identified heist was visible entire time from vantage point that wasn’t being monitored. HT @CliffCrosland of @scanner_dev. api.cyfluencer.com/s/what-is-fe...
api.cyfluencer.com
What is federated indexing?
Federated indexing reads every log once, wherever it lives, and writes it into a compact index in object storage, so you get data lake economics with SIEM speed and continuous detection. OpenAI disclo...
030
Reposted by Ben Rothke
CyberCanon @cybercanon.org · 25/09/2026
One more book review this week: 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲’𝐬 𝐃𝐢𝐫𝐭𝐲 𝐒𝐞𝐜𝐫𝐞𝐭: 𝐖𝐡𝐲 𝐌𝐨𝐬𝐭 𝐁𝐮𝐝𝐠𝐞𝐭𝐬 𝐆𝐨 𝐭𝐨 𝐖𝐚𝐬𝐭𝐞, by Ross Young. This is a second review of this book. This time by Aleksandra Scalco-scalco
121
Ben Rothke @benrothke.bsky.social · 25/09/2026
#AI keeps getting faster, cheaper & more capable. #Claude #Fable 5.1 now has strong performance on coding & agentic tasks, while cutting cache-read costs dramatically. #Anthropic confirms that Fable is cheaper & faster. Good analysis from @EndorLabs. api.cyfluencer.com/s/fable-5-1-...
api.cyfluencer.com
Claude Code with Fable 5.1 posts 87.2% FuncPass and 37.4% SecPass — a new #1 on our board — while running as fast as Fable 5, costing a third of Opus 5, finishing every task with zero timeouts, and dr...
Claude Code with Fable 5.1 posts 87.2% FuncPass and 37.4% SecPass — a new #1 on our board — while running as fast as Fable 5, costing a third of Opus 5, finishing every task with zero timeouts, and dr...
010
Ben Rothke @benrothke.bsky.social · 23/09/2026
Everyone wants to be validated. The @PicusSecurity Validation Summit ’26 free online event on Oct. 14/15, w/ a keynote by @mikko, focuses on how organizations can validate whether their defenses actually work against increasingly AI-powered attackers. cybersec.picussecurity.com/s/the-valida... #AI
cybersec.picussecurity.com
Validation Summit 26
The Validation Summit '26: a free two-hour digital summit with Mikko Hyppönen, Picus CTO Volkan Ertürk and CISOs from Adobe and Atlassian.
010
Ben Rothke @benrothke.bsky.social · 22/09/2026
You can be on the real @X website & still get hacked. This #phishing attack looked so convincing that I almost fell for it. Attackers don’t need your password. Here’s how the scam works & how to spot it before it’s too late. brothke.medium.com/youre-on-the... #Cybersecurity #Scams #X
brothke.medium.com
You’re on the Real X Website — and You’re Still Being Scammed
This phishing attack is so convincing, you can end up on a genuine X authorization page — and still hand an attacker control of your…
000
Ben Rothke @benrothke.bsky.social · 22/09/2026
The @NFL & @MLB are in full swing & so is online gambling feeding frenzy. @FanDuel @CaesarsSports @BetMGM @bet365 & @DraftKings aren’t in business to make YOU rich. You can’t beat the house & that’s what they’re counting on. Don’t take any ‘free’ offers. brothke.medium.com/why-you-shou...
brothke.medium.com
Why you should never sign up for an online casino sportsbook free offer
Because it’s risk-free for the casino — not you
000
Ben Rothke @benrothke.bsky.social · 22/09/2026
Shakespeare knew that the most dangerous threats come from within. Cute video from Eliana V., a cyber historian at @MiggoSecurity, on why strong #infosec tools matter to protect against Shadow #AI. Unknowns are the biggest #cybersecurity exposure. api.cyfluencer.com/s/shadow-ai-...
api.cyfluencer.com
Miggo
020
Reposted by Ben Rothke
CyberCanon @cybercanon.org · 22/09/2026
In today's review, 𝘾𝙤𝙙𝙚 𝙂𝙞𝙧𝙡𝙨, a #CyberCanonHallofFame book by Liza Mundy, gets another endorsement from Rick Howard! 📝 Full Review: cybercanon.org/code-girls/#... #CyberCanonReview #CybersecurityBooks #CyberHistory
222
Ben Rothke @benrothke.bsky.social · 17/09/2026
The @owasp lists focus limited security attention where it matters most. #OWASP Top 10 for #AI #LLM applications reflects the growing consequences of giving LLM applications access to tools and enterprise systems. Prompt injection remains #1. HT @aembit_io go.aembit.io/s/the-owasp-...
go.aembit.io
The OWASP Top 10 for LLM Applications (2026): What Changed and Why It Matters | Aembit
Explore the OWASP Top 10 for LLM Applications 2026, how the risks changed, and what security teams should do as LLMs gain greater access and agency.
030
Ben Rothke @benrothke.bsky.social · 16/09/2026
You can be on the real @X website & still get hacked. This #phishing attack looked so convincing I almost fell for it. Attackers don’t need your password. I show how the #scam works. If you dig a little, you can easily spot it before it’s too late: brothke.medium.com/youre-on-the... #Infosec #Scams
brothke.medium.com
You’re on the Real X Website — and You’re Still Being Scammed
This phishing attack is so convincing, you can end up on a genuine X authorization page — and still hand an attacker control of your…
121
Ben Rothke @benrothke.bsky.social · 16/09/2026
It’s not just healthcare data - it’s mental health data. Compromised medical records are bad enough. Exposure of someone’s mental health history, diagnoses, treatment, or therapy can have deeply personal, potentially life-changing consequences. api.cyfluencer.com/s/the-inters... #infosec
api.cyfluencer.com
010
Ben Rothke @benrothke.bsky.social · 15/09/2026
Tortillas are delicious. But DarkTortilla #malware certainly leaves a bad taste in your mouth. #DarkTortilla is a highly configurable .NET crypter & multi-stage loader active since August 2015. Good overview how to protect against it from @PicusSecurity. cybersec.picussecurity.com/s/darktortil...
cybersec.picussecurity.com
DarkTortilla Malware: How It Works and How to Test Your Defenses
Learn how DarkTortilla malware hides in bitmaps, injects payloads in memory, and persists, then simulate it to test your defenses.
010
Ben Rothke @benrothke.bsky.social · 14/09/2026
Boards are all asking - If #AI is this good at writing code, why keep buying security tools? The answer is that a frontier model is a reasoning layer, not a replacement for #SAST, #SCA, secrets & supply-chain defense. Interesting insights from @EndorLabs. api.cyfluencer.com/s/ciso-s-gui...
api.cyfluencer.com
CISO's Guide: Build vs Buy AI Code Security | Ebook/Report | Endor Labs
CISO's Guide: Build vs Buy AI Code Security
010
Ben Rothke @benrothke.bsky.social · 10/09/2026
#Claude Mythos was released 5 months ago. Firms now need a #Mythos #infosec readiness program to see whether they can withstand attacks weaponized via #Anthropic. Disclosure-to-exploit is now measured in hours rather than weeks. cybersec.picussecurity.com/s/mythos-rea...
cybersec.picussecurity.com
Mythos Readiness: What It Means and How to Become Mythos-Ready
What does Mythos-ready mean? See how continuous security validation helps prove control effectiveness, prioritize risk, and defend against AI-speed threats.
010
Ben Rothke @benrothke.bsky.social · 09/09/2026
Think a birthday invitation is harmless? Think again. Scammers are using fake @PunchbowlNews @paperlesspost& @evite party invitations to steal passwords, hijack accounts & spread malware. The scary part? They can look like they came from someone you know. brothke.medium.com/invitation-s...
brothke.medium.com
Invitation Scams: When a Birthday Party Becomes a Phishing Trap
That invitation from a friend may be designed to steal your password — not invite you to a party.
000
Ben Rothke @benrothke.bsky.social · 08/09/2026
#Passwordless authentication & #passkeys are quite popular but are in fact quite vulnerable accd. to @Unit42_Intel. The #pass-ta-key attack leverages synced passkey features of #Google #Chrome to successfully gain access to passkey-authenticated services. api.cyfluencer.com/s/what-pass-...
api.cyfluencer.com
What Pass-Ta-Key Tells Us About Passkeys
While passkeys are meant to improved security, the pass-ta-key attack highlights the risk still present in authentication workflows.
020
Reposted by Ben Rothke
CyberCanon @cybercanon.org · 08/09/2026
𝘋𝘳𝘢𝘸𝘪𝘯𝘨 𝘰𝘯 𝘮𝘰𝘳𝘦 𝘵𝘩𝘢𝘯 𝘵𝘩𝘳𝘦𝘦 𝘥𝘦𝘤𝘢𝘥𝘦𝘴 𝘪𝘯 𝘴𝘦𝘤𝘶𝘳𝘪𝘵𝘺, 𝘭𝘢𝘸, 𝘫𝘰𝘶𝘳𝘯𝘢𝘭𝘪𝘴𝘮, 𝘢𝘯𝘥 𝘢𝘴𝘴𝘰𝘤𝘪𝘢𝘵𝘪𝘰𝘯 𝘭𝘦𝘢𝘥𝘦𝘳𝘴𝘩𝘪𝘱, 𝘎𝘪𝘱𝘴 𝘸𝘳𝘪𝘵𝘦𝘴 𝘸𝘪𝘵𝘩 𝘤𝘳𝘦𝘥𝘪𝘣𝘪𝘭𝘪𝘵𝘺 𝘢𝘯𝘥 𝘳𝘦𝘴𝘵𝘳𝘢𝘪𝘯𝘵. --Walt Powell in his review of 𝙄𝙩’𝙨 𝙉𝙤𝙩 𝙞𝙣 𝙩𝙝𝙚 𝙈𝙖𝙣𝙪𝙖𝙡 by Michael Gips 📝 Full review: cybercanon.org/its-not-in-t... #CyberCanonReview #CybersecurityBooks
CyberCanon's Review of 'It's Not in the Manual'
032
Ben Rothke @benrothke.bsky.social · 04/09/2026
Two industries where #infosec is particularly critical are #Healthcare & #Pharmaceutical. But accd. to @PicusSecurity, their #cybersecurity effectiveness has dropped almost 10% from the previous year. That’s why you get so many breach notification notices. cybersec.picussecurity.com/s/healthcare...
cybersec.picussecurity.com
Healthcare Cybersecurity: 2026 Performance in Healthcare and Pharmaceuticals
The Picus Blue Report 2026 shows healthcare prevention effectiveness fell from 83% to 74%, with the lowest log score of any industry. See what the data means for hospitals and health systems.
010
Ben Rothke @benrothke.bsky.social · 03/09/2026
This piece details 6 #cybersecurity risks of agentic #AI traditional app security wasn’t built for: unbounded autonomy, tool-chain exposure, identity fluidity, cascading multi-agent compromise, persistent memory poisoning & supply chain integrity gaps. go.aembit.io/s/6-cybersec...
go.aembit.io
6 Agentic AI Security Risks to Monitor in 2026 | Aembit
Agentic AI introduces six risk categories traditional security wasn't built for. See what they are, real-world examples, and how to defend against them.
131
Ben Rothke @benrothke.bsky.social · 02/09/2026
My @OneRSAC #infosec book of the month review: Code War: How Nations Hack, Spy & Shape the Digital Battlefield, via @WileyTech. Allie Mellen of @Forrester. @hackerxbella does good job showing cyberattacks are tools of national power, not just tech crimes. www.rsaconference.com/library/blog...
rsaconference.com
Ben's Book of the Month: Code War: How Nations Hack, Spy, and Shape the Digital Battlefield
010
Ben Rothke @benrothke.bsky.social · 01/09/2026
#KryBit is a Ransomware-as-a-Service #RaaS operation launched in March leasing encryption builders to affiliates. @PicusSecurity details how double-extortion attack exfiltrates 10GB to 250GB per victim before encryption, with ransoms of $40,000-$100,000. cybersec.picussecurity.com/s/how-krybit...
cybersec.picussecurity.com
How KryBit Ransomware Works and How to Test Your Defenses
KryBit is a RaaS operation encrypting Windows, Linux, ESXi, and NAS. Learn how KryBit ransomware works and how to test your defenses.
010
Reposted by Ben Rothke
CyberCanon @cybercanon.org · 01/09/2026
📝 Review Incoming... 𝙉𝙚𝙭𝙪𝙨: 𝘼 𝘽𝙧𝙞𝙚𝙛 𝙃𝙞𝙨𝙩𝙤𝙧𝙮 𝙤𝙛 𝙄𝙣𝙛𝙤𝙧𝙢𝙖𝙩𝙞𝙤𝙣 𝙉𝙚𝙩𝙬𝙤𝙧𝙠𝙨 𝙛𝙧𝙤𝙢 𝙩𝙝𝙚 𝙎𝙩𝙤𝙣𝙚 𝘼𝙜𝙚 𝙩𝙤 𝘼𝙄 Rosalyn Page provides this week's #CyberCanonReview of historian Yuval Noah Harari's bestselling book. 👉 cybercanon.org/nexus-a-brie... #CybersecurityBooks #Nexus #AI
CyberCanon's Review of Nexus
111
Ben Rothke @benrothke.bsky.social · 26/08/2026
Read this & don’t do #AI weep: Developer’s Guide to Coding Agent Security. Coding agents can read files, run commands, call tools & act w/ creds available in their environment. As their autonomy grows, AI security becomes more critical. HT @GitGuardian cybersec.gitguardian.com/s/a-develope...
cybersec.gitguardian.com
AI Coding Agent Security: A Developer's Guide | GitGuardian | GitGuardian
An agent is only as dangerous as what it can reach. Get the threat model and controls for securing coding agents across your IDE, MCP servers, and CI/CD.
160
Ben Rothke @benrothke.bsky.social · 25/08/2026
Criminal Justice Information Services (#CJIS) is an @FBI division. Just released policy v6.1, building directly on the structural framework of v6.0 w/o introducing major redesign. Interesting to see how #FBI deals w/ #cybersecurity. HT @specopssoft.com api.cyfluencer.com/s/cjis-secur...
api.cyfluencer.com
CJIS Security Policy v6.1: Everything You Need to Know
Learn what the CJIS Security Policy requires, who it applies to, key controls, and how Specops supports compliance.
010
Ben Rothke @benrothke.bsky.social · 25/08/2026
The GASA does great work on combating #scams & online fraud. But scams can’t be stopped & we need to stop pretending they can. Despite all their work, scammers make over $1.5B daily. My take on the situation: brothke.medium.com/scams-cant-b...
brothke.medium.com
Scams Can’t Be Stopped — We Need to Stop Pretending They Can
The goal isn’t to eliminate scams. It’s to make them harder to pull off — and harder to profit from.
000
Reposted by Ben Rothke
CyberCanon @cybercanon.org · 25/08/2026
🤯 Great Scott! This week we bring you a Hall of Fame Nominee with 𝙃𝙖𝙘𝙠 𝙩𝙤 𝙩𝙝𝙚 𝙁𝙪𝙩𝙪𝙧𝙚 by Emily Crose. Jose Miguel Parrella, as always, provides his thorough assessment. 📝 Full Review: tinyurl.com/4tzkn3kc #CyberCanonReview #CyberCanonHoFCandidate #CybersecurityBooks @bureado.bsky.social
CyberCanon's Review of Hack to the Future
111
Ben Rothke @benrothke.bsky.social · 24/08/2026
Helpful guide from @bigidsecure detailing the US states with new AI laws. In Europe, the @EU_Commission and @EUCouncil renegotiated their flagship #AI regulation under industry pressure. The US federal government is in legal fights with a number of states. api.cyfluencer.com/s/the-ultima...
api.cyfluencer.com
The Ultimate Guide to the Global AI Regulatory Landscape: Who's Affected, What Changed, and How to Prepare
A breakdown of every major AI law shaping 2026: who's affected, key deadlines across the US and EU, and how to prepare with a data-first approach.
010
Ben Rothke @benrothke.bsky.social · 21/08/2026
Last month, @EU_Commission #AI Omnibus went live, the first substantive amendment to the AI Act since 2024. Delays the high-risk AI deadline set for August 2, 2026, but leaves transparency & enforcement obligations on their original date. Still lots to do. api.cyfluencer.com/s/eu-ai-act-...
api.cyfluencer.com
EU AI Act vs. AI Omnibus: What You Need to Know
The EU AI Act's high-risk deadline moved to 2027. Transparency and GPAI enforcement rules didn't. Here's what the AI Omnibus actually changed.
010
Ben Rothke @benrothke.bsky.social · 20/08/2026
Michael Corleone said in The Godfather Part 3: "Just when I thought I was out, they pull me back in." Same for Mini Shai-Hulud. A new wave hit keyv & 800+ npm packages. #malware now scans 469 secret locations, including #AI agents & crypto. HT @GitGuardian. cybersec.gitguardian.com/s/mini-shai-...
cybersec.gitguardian.com
Mini Shai-Hulud's Latest Wave: 280 New Places
A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, crypto wallets, and CI/CD tools.
010
Reposted by Ben Rothke
CyberCanon @cybercanon.org · 18/08/2026
🪖🧠 𝗡𝗲𝘄 𝗥𝗲𝘃𝗶𝗲𝘄: 𝙏𝙝𝙚 𝙋𝙚𝙣𝙩𝙖𝙜𝙤𝙣'𝙨 𝘽𝙧𝙖𝙞𝙣 This week, Susan Hansche reviews Annie Jacobsen's 𝙏𝙝𝙚 𝙋𝙚𝙣𝙩𝙖𝙜𝙤𝙣’𝙨 𝘽𝙧𝙖𝙞𝙣: 𝘼𝙣 𝙐𝙣𝙘𝙚𝙣𝙨𝙤𝙧𝙚𝙙 𝙃𝙞𝙨𝙩𝙤𝙧𝙮 𝙤𝙛 𝘿𝘼𝙍𝙋𝘼, 𝘼𝙢𝙚𝙧𝙞𝙘𝙖’𝙨 𝙏𝙤𝙥-𝙎𝙚𝙘𝙧𝙚𝙩 𝙈𝙞𝙡𝙞𝙩𝙖𝙧𝙮 𝙍𝙚𝙨𝙚𝙖𝙧𝙘𝙝 𝘼𝙜𝙚𝙣𝙘𝙮 📝https://tinyurl.com/nhd84fh4 #CyberCanonReview #CybersecurityBooks #DARPA
CyberCanon's Review of The Pentagon's Brain
122
Ben Rothke @benrothke.bsky.social · 17/08/2026
It was an inevitability, a new class of cyberattack: the AI swarm. An agent swarm built its own covert communication channel, survived a takedown & breached 2 of the most sophisticated #AI firms. Incidents like #OpenAI #HuggingFace will soon be routine. api.cyfluencer.com/s/ai-swarms-...
api.cyfluencer.com
AI swarms are coming. But resistance is not futile.
It takes a swarm to stop a swarm. An agent swarm built its own covert communication channel inside OpenAI's internal package manager, survived a takedown, and breached both OpenAI and Hugging Face wit...
010
Ben Rothke @benrothke.bsky.social · 14/08/2026
The @PicusSecurity Blue Report analyzed 338M attack simulations. Reveals how enterprise security controls stand up to real-world attacks. Details where defenses succeed & failed. I think it’s called ‘Blue Report’ as that’s how you’ll feel after reading it. cybersec.picussecurity.com/s/the-blue-r...
cybersec.picussecurity.com
Blue Report 2026: Enterprise Security Performance Benchmarks
Explore Blue Report 2026 insights from 338M+ attack simulations. Benchmark prevention, detection, industries, threats, vulnerabilities, and security gaps.
010
Ben Rothke @benrothke.bsky.social · 12/08/2026
Free guide courtesy of @ZeroNetworks: ‘#CISO Guide to Business Impact Analysis for Cyber Resilience: From Assessment to Enforcement’. Key takeaway: Security teams can no longer afford to plan for prevention; they must engineer for the impact of a breach. api.cyfluencer.com/s/bia-guide-...
api.cyfluencer.com
CISO Guide to Business Impact Analysis for Cyber Resilience
This guide gives CISOs a structured framework for taking a Business Impact Analysis (BIA) from documentation to enforcement: identifying critical assets, mapping business risk exposure, and building t...
010
Ben Rothke @benrothke.bsky.social · 11/08/2026
Scammers don’t always need sophisticated technology. Sometimes, the victim is the exploit. I got bogus text last week & ignored it. Others weren’t so lucky. In less than 4 minutes, scammers convinced victims to hand over their debit-card numbers & sensitive infor. brothke.medium.com/the-victim-i...
brothke.medium.com
The Victim Is the Exploit
Why scammers don’t need sophisticated technology when social engineering can do the job
000
Reposted by Ben Rothke
CyberCanon @cybercanon.org · 11/08/2026
"𝘛𝘩𝘦 𝘦𝘥𝘶𝘤𝘢𝘵𝘪𝘰𝘯𝘢𝘭 𝘷𝘢𝘭𝘶𝘦 𝘰𝘧 𝘵𝘩𝘦 𝘣𝘰𝘰𝘬, 𝘤𝘰𝘮𝘣𝘪𝘯𝘦𝘥 𝘸𝘪𝘵𝘩 𝘵𝘩𝘦 𝘴𝘶𝘣𝘫𝘦𝘤𝘵 𝘥𝘦𝘱𝘵𝘩 𝘢𝘯𝘥 𝘳𝘪𝘨𝘰𝘳, 𝘢𝘯𝘥 𝘵𝘩𝘦 𝘤𝘭𝘦𝘢𝘳 𝘱𝘳𝘦𝘴𝘦𝘯𝘵𝘢𝘵𝘪𝘰𝘯 𝘰𝘧 𝘵𝘰𝘱𝘪𝘤𝘴 𝘢𝘯𝘥 𝘪𝘥𝘦𝘢𝘴, 𝘮𝘢𝘬𝘦𝘴 𝘵𝘩𝘪𝘴 𝘢𝘯 𝘦𝘹𝘤𝘦𝘭𝘭𝘦𝘯𝘵 𝘳𝘦𝘧𝘦𝘳𝘦𝘯𝘤𝘦" -- Helen Patton in her review of Joanna Grama's 𝙇𝙚𝙜𝙖𝙡 𝙖𝙣𝙙 𝙋𝙧𝙞𝙫𝙖𝙘𝙮 𝙄𝙨𝙨𝙪𝙚𝙨 𝙞𝙣 𝙄𝙣𝙛𝙤𝙧𝙢𝙖𝙩𝙞𝙤𝙣 𝙎𝙚𝙘𝙪𝙧𝙞𝙩𝙮 (𝟯𝙧𝙙 𝙀𝙙𝙞𝙩𝙞𝙤𝙣) #CyberCanonReview
122
Ben Rothke @benrothke.bsky.social · 10/08/2026
Accd. to @Kiteworks, the #AI governance gap has widened instead of closing & budget doesn’t predict maturity. Organizations w/ the largest security budgets in the survey had the lowest representation in the top maturity tier of any size band they measured. cybersec.kiteworks.com/s/the-2026-a...
cybersec.kiteworks.com
The 2026 Annual Survey Report Is In: The AI Governance Gap Didn't Close. It Widened.
New 2026 survey data shows AI governance has fallen further behind AI deployment, with 79% lacking a tested kill switch. See the full findings and what to do next.
010
Ben Rothke @benrothke.bsky.social · 04/08/2026
My @OneRSAC #RSAC #infosec book review: Blue Team Dynamics: Three Proven Leadership Principles Inspired by @IDF Sources for Business & Life, by @YaakovLappin via @GefenPublishing. Deep insights from @IDF, @ElbitSystemsLtd & other #Israel hi-tech leaders. www.rsaconference.com/library/blog...
rsaconference.com
Ben's Book of the Month: Blue Team Dynamics: Three Proven Leadership Principles Inspired by IDF Sources for Business and Life
000
Ben Rothke @benrothke.bsky.social · 04/08/2026
It’s almost certain that the call you get about a vacation is from a scammer. So why do vacation scams persist? Vacation scams are effective because they exploit a perfect combination of emotion, psychology, and timing. www.linkedin.com/feed/update/...
linkedin.com
Vacation Scams Are Booming — Here’s How Not to Become the Next Victim | Ben Rothke
It’s almost certain that the call you get about a vacation is from a scammer. So why do vacation scams persist? Vacation scams are effective because they exploit a perfect combination of emotion, psy...
000
Ben Rothke @benrothke.bsky.social · 04/08/2026
Vacation scams don't just steal your money - they steal your dream vacation. Scammers prey on excitement, urgency & "too good to pass up" deals. Before you book your next trip, learn the red flags that can save you thousands. #Scams #Travel #Cybersecurity brothke.medium.com/vacation-sca...
brothke.medium.com
Vacation Scams Are Booming — Here’s How Not to Become the Next Victim
That call about a vacation is from a scammer
000
Reposted by Ben Rothke
CyberCanon @cybercanon.org · 04/08/2026
"𝘖𝘯𝘦 𝘰𝘧 𝘵𝘩𝘦 𝘣𝘰𝘰𝘬’𝘴 𝘴𝘵𝘳𝘰𝘯𝘨𝘦𝘴𝘵 𝘤𝘰𝘯𝘵𝘳𝘪𝘣𝘶𝘵𝘪𝘰𝘯𝘴 𝘪𝘴 𝘪𝘵𝘴 𝘢𝘳𝘵𝘪𝘤𝘶𝘭𝘢𝘵𝘪𝘰𝘯 𝘰𝘧 𝘩𝘰𝘸 𝘈𝘐 𝘤𝘢𝘯 𝘤𝘳𝘦𝘢𝘵𝘦 𝘵𝘩𝘦 𝘴𝘦𝘮𝘣𝘭𝘢𝘯𝘤𝘦 𝘰𝘧 𝘪𝘯𝘵𝘦𝘭𝘭𝘪𝘨𝘦𝘯𝘤𝘦—𝘱𝘳𝘰𝘥𝘶𝘤𝘪𝘯𝘨 𝘰𝘶𝘵𝘱𝘶𝘵𝘴 𝘵𝘩𝘢𝘵 𝘢𝘱𝘱𝘦𝘢𝘳 𝘪𝘯𝘵𝘦𝘯𝘵𝘪𝘰𝘯𝘢𝘭 𝘰𝘳 𝘢𝘶𝘵𝘩𝘰𝘳𝘪𝘵𝘢𝘵𝘪𝘷𝘦 𝘥𝘦𝘴𝘱𝘪𝘵𝘦 𝘭𝘢𝘤𝘬𝘪𝘯𝘨 𝘨𝘦𝘯𝘶𝘪𝘯𝘦 𝘶𝘯𝘥𝘦𝘳𝘴𝘵𝘢𝘯𝘥𝘪𝘯𝘨." -- Caroline Wong in her review of Justin "Hutch" Hutchens' 𝙏𝙝𝙚 𝙇𝙖𝙣𝙜𝙪𝙖𝙜𝙚 𝙤𝙛 𝘿𝙚𝙘𝙚𝙥𝙩𝙞𝙤𝙣
111
Ben Rothke @benrothke.bsky.social · 03/08/2026
The AI hype cycle is beginning to crack. Companies sold AI as a cure-all, but many rushed deployments are falling flat. People hate frustrating HR and customer service bots, and businesses are now paying the price for replacing good experiences with bad automation. brothke.medium.com/the-ai-big-c...
brothke.medium.com
The AI Big Crunch Is Starting
The AI emperor has clothes. Just much less than everyone thinks.
000
Ben Rothke @benrothke.bsky.social · 03/08/2026
Considering buying an honorary doctorate? Imagine sitting in a job interview while hiring manager asks where you earned your doctorate. Explaining that you purchased an honorary PhD isn’t the conversation anyone wants to have. Just don’t do it, or buy it. brothke.medium.com/when-dr-come...
brothke.medium.com
When “Dr.” Comes With a Receipt
Why spending thousands of dollars on an “honorary PhD” may cost you far more than the purchase price.
000
Ben Rothke @benrothke.bsky.social · 03/08/2026
Beware of the Baseboard Management Controller (BMC). A 20-year-old BMC vulnerability gave researchers access to bare-metal servers & a foothold in the no man’s land of data center infrastructure. api.cyfluencer.com/s/how-we-hac...
api.cyfluencer.com
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
A 20-year-old vulnerability gave us access to bare-metal servers - and a foothold in the no man’s land of data center infrastructure.
020
Ben Rothke @benrothke.bsky.social · 31/07/2026
For first time in 19 years, @Verizon @VZDBIR looked at what happens after attackers get in. Mapped routes taken to privilege escalation. Real exposures live in the permissions, configurations & trust relationships along those routes. HT @XMCyber_. api.cyfluencer.com/s/the-2026-v... #DBIR
api.cyfluencer.com
The 2026 Verizon DBIR Stopped Asking How Attackers Get in and Started Asking Where They Go | XM Cyber
Learn more about The 2026 Verizon DBIR Stopped Asking How Attackers Get in and Started Asking Where They Go . Read more on XM Cyber website.
010
Ben Rothke @benrothke.bsky.social · 28/07/2026
Shai-Hulud is one of the most persistent supply-chain worms in recent years. It’s a self-replicating worm & actively compromising packages with 3M+ weekly downloads, hijacking tokens from CI/CD pipelines, bypassing trusted publishing protections. #Shai-Hulud cybersec.gitguardian.com/s/mini-shai-...
cybersec.gitguardian.com
Mini Shai-Hulud: A persistent supply-chain worm
A self-replicating worm is actively compromising packages with 3M+ weekly downloads, hijacking tokens from CI/CD pipelines, and bypassing trusted publishing protections.
030
Reposted by Ben Rothke
CyberCanon @cybercanon.org · 28/07/2026
📝 𝙍𝙚𝙫𝙞𝙚𝙬 𝘿𝙖𝙮! 📕 Jack Freund reviews 𝙈𝙖𝙨𝙩𝙚𝙧𝙞𝙣𝙜 𝙏𝙝𝙞𝙧𝙙-𝙋𝙖𝙧𝙩𝙮 𝙍𝙞𝙨𝙠: 𝘼 𝙋𝙧𝙖𝙘𝙩𝙞𝙘𝙖𝙡 𝙃𝙖𝙣𝙙𝙗𝙤𝙤𝙠 𝙛𝙤𝙧 𝙈𝙖𝙣𝙖𝙜𝙞𝙣𝙜 𝙑𝙚𝙣𝙙𝙤𝙧, 𝙏𝙝𝙞𝙧𝙙-𝙋𝙖𝙧𝙩𝙮, 𝙖𝙣𝙙 𝙎𝙪𝙥𝙥𝙡𝙮 𝘾𝙝𝙖𝙞𝙣 𝙏𝙝𝙧𝙚𝙖𝙩𝙨 𝙞𝙣 𝙀𝙫𝙚𝙧𝙮 𝙊𝙧𝙜𝙖𝙣𝙞𝙯𝙖𝙩𝙞𝙤𝙣, authored by Bill Bonney, Chris Forbes, Gary Hayslip, Andrea Little Limbago, and Matt Stamper. 👉 Review: tinyurl.com/3aahu3rm
CyberCanon Review of Mastering Third-Party Risk
011
Ben Rothke @benrothke.bsky.social · 27/07/2026
Good @jbhall56 piece: He notes YoY #PCI #27001 audit efficiencies are only in 2%-4 % range. The real problem is a consultancy sales exec who thinks it’s >25% & lowers the audit price to make clients happy. It’s then the consultants who have to deliver. pciguru.wordpress.com/2026/07/27/t...
pciguru.wordpress.com
The Audit Efficiency Myth
I have been guilty in the past of agreeing to this and have always regretted it. Clients think that an audit/assessment is like assembling a widget. The more times you do it the faster and more eff…
010
Ben Rothke @benrothke.bsky.social · 27/07/2026
Interesting post by @bigidsecure on #ExploitGym, a cybersecurity benchmark designed to evaluate whether #AI agents can turn software vulnerabilities into working, end-to-end attacks. #HuggingFace shows that AI risks have gotten quite real. api.cyfluencer.com/s/a-model-a-... #infosec
api.cyfluencer.com
A Model, a Goal, and an Unlocked Door
Every fictional AI villain gets a moment where it decides humans are the problem. HAL 9000 decides the mission matters more than the crew. Skynet decides humanity is …
010