spencer @bsky.ethicalthreat.com · 04/03/2026I’m at zero trust world today and tomorrow. If you see me say what’s up! 100
spencer @bsky.ethicalthreat.com · 04/03/2026How long until Active Directory is “dead?” I don’t think it will ever be, look at this slide that Cliff Fisher shared on the hybrid identity podcast. 020
spencer @bsky.ethicalthreat.com · 03/03/2026If you’re an IT admin or CIO/CISO, you probably want to know what cybersecurity threats you’re up against. This is that episode… Ps - don’t focus on the numbers, focus on the trends and the techniques Listen/watch here 👇 🎧 offsec.blog/episode-170-... 000
spencer @bsky.ethicalthreat.com · 27/02/2026The barrier to entry for threat actors continues to get lower, but for defenders, it almost seems like its getting higher... 📰Source: awesomeagents.ai/news/ai-powe... 000
spencer @bsky.ethicalthreat.com · 27/02/2026Supply chain attack that drops openclaw instead of malware or a more typical payload. Buckle up folks! 🦞🔥 clawdint.com/cases/203 001
spencer @bsky.ethicalthreat.com · 26/02/2026🔔TADA! Cyber Threat Perspective podcast videos are now on Spotify! 🔗https://open.spotify.com/episode/3EJzP3qAasERZHKWBU2jQQ?si=bfc148cdb9e74432 000
spencer @bsky.ethicalthreat.com · 25/02/2026Things that seem like a bad idea: ATMs running on Windows 210
spencer @bsky.ethicalthreat.com · 25/02/2026How many average commits are there on a large open source project per day, week, month, year? The Linux kernel had 75k commits in 2025 according to grok. So 1.2% is 900. 900 potential bugs. Now extrapolate that out to “vibe coding” where there’s probably 10x more commits than that. 🤯 011
spencer @bsky.ethicalthreat.com · 25/02/2026What I’ve learned maybe the most from this AI revolution thing is that, if you want to have an impact, build things that solve problems you have yourself or that scratch your own itch and then release it to the world. If it gains traction, double down on it. 000
spencer @bsky.ethicalthreat.com · 25/02/2026The difficult part about "misconfigs" is that you have to know 1) where to look and 2) what to look for. If you manage Windows endpoints, this video is for you! youtu.be/gcKejfmPea4?... 110
spencer @bsky.ethicalthreat.com · 24/02/2026👨💻 I'm presenting a super cool Active Directory hacking lab at Zero Trust World, next week, Wed March 4th. It's at 4:30pm but I recommend getting there early. If you're going to be there, come say what's up.🤘Adam Savage has a keynote this year, thats cool 🗺️https://ztw.com/agenda cc @threatlocker 000
spencer @bsky.ethicalthreat.com · 24/02/2026Heads up IT admins…Kerberos (AES) changes coming in April Source: www.linkedin.com/posts/jerry-... 110
spencer @bsky.ethicalthreat.com · 10/02/2026Who you choose to test your environment matters just as much as what they test... Read here👇 📖https://x.com/techspence/status/2021223106434506863 100
spencer @bsky.ethicalthreat.com · 01/07/2025more alerts != better threat detection i'm a big fan of deception for a couple reasons: 1) because of the quality of the alerts 110
spencer @bsky.ethicalthreat.com · 24/06/2025What a great idea...time to spin up an AI agent to analyze all of John Hammond's videos 😋😎 For real though someone build this and open source it. 10/10 would use it 010
spencer @bsky.ethicalthreat.com · 20/06/2025If you think these graphic design skills are good, just wait until you see the webinar... Agenda: convince anyone not using deception currently to start... us06web.zoom.us/webinar/regi... 000
spencer @bsky.ethicalthreat.com · 28/05/2025What’s the cybersecurity equivalent of a tourniquet? Isolation/containment via EDR… Logging a user out everywhere in M365… Pulling the power cord… What else? 120
spencer @bsky.ethicalthreat.com · 27/05/2025I was trying to get ChatGPT to create mock-ups of heatmaps or "x-rays" I can use to better articulate where specific risks/vulns/misconfigs are present. This is my first attempt...is it wrong? 😅😂 111
spencer @bsky.ethicalthreat.com · 26/05/2025You know you're doing this security thing right....or horribly terribly wrong when you log into your VM and upon logon to a host you see this... Did I do that? 🤔😅 010
spencer @bsky.ethicalthreat.com · 20/05/2025This question…but for cybersecurity. My response: Trust by default. Now it’s verify everything, assume breach, least privilege, segmentation, etc. What do you think? 000
spencer @bsky.ethicalthreat.com · 16/05/2025The thing is... I don't see this ever changing. People will always find the path of least resistance to get their work done. We have to design and secure in spite of that, not try to change it. Source: 2025 Verizon DBIR 230
spencer @bsky.ethicalthreat.com · 13/05/2025Every Monday I send a free weekly newsletter that includes a combination of...My take on current events and actionable tips for defenders to help you secure your environments. Inboxes are noisy these days, but I would love the chance to earn a spot in yours. go.spenceralessi.com/mylinks 010
spencer @bsky.ethicalthreat.com · 06/05/2025You've got about 2 weeks to patch edge devices when vulnerability or exploitation information is publicly disclosed, but to be honest I think that's a bit generous... Source: Mandiant M-Trends 2025 020
spencer @bsky.ethicalthreat.com · 05/05/2025As much as the industry is moving forward and security is getting so much better, there's an equal amount of systems and processes that are still very much stuck in the past... 000
spencer @bsky.ethicalthreat.com · 01/05/2025It’s probably time we retire VPNs. There’s much better options now, like zscaler and tailscale and others. The rate at which these VPN appliances are being attacked and exploited doesn’t seem to be slowing down Source: 2025 Verizon DBIR 321
spencer @bsky.ethicalthreat.com · 22/04/2025Prevention > Detection. Let’s make attackers hate their life. No doubt EDR is essential, but it’s not a silver bullet. 040
spencer @bsky.ethicalthreat.com · 07/04/2025Life as a sysadmin, am I right? Sometimes I miss the job… 😅🤘🎸 021
spencer @bsky.ethicalthreat.com · 03/04/2025Security is a journey, we all know that...You don’t need to overhaul everything overnight, nor could you even if you wanted to. But you do need to start. Prioritize one item per month. Small wins over time really add up... 041
spencer @bsky.ethicalthreat.com · 25/03/2025Who needs the latest and greatest C2 when you've got RMM, RDP and a dream... 000
spencer @bsky.ethicalthreat.com · 24/03/2025You can always count on Reddit.. “Landlord added two factor authentication” 110
spencer @bsky.ethicalthreat.com · 22/03/2025Posted this on social media 5 years ago. Crazy how fast time passes us by… 120
spencer @bsky.ethicalthreat.com · 18/03/2025Make no mistake about it…if it’s exploitable and on the internet you have ~24 hours to patch it or take it offline 030
spencer @bsky.ethicalthreat.com · 14/03/2025👨💻 Me: ‘Hey, we should invest in cybersecurity.’ 💼 Execs: ‘Nah, we’re fine.’ 🔥 Breach happens. 💼 Execs: ‘How much $$$ do you need??’ Classic. 020