Chuck Davis @ckd3.net · 11/09/202625 years ago today, I was working from home as an IT security architect for IBM when I heard the tone of the morning news anchors suddenly change. I remember the shock, sadness and anger. I wanted to help. Ten days later, I was given a small opportunity to do exactly that. betweenthehacks.com/... 000
Chuck Davis @ckd3.net · 20/08/2026A fake $499.99 PayPal charge appeared on my son’s calendar exactly one year after I drafted an article about the same attack. Was his account breached? Probably not. Here is how calendar invite phishing works and what to do when one appears: betweenthehacks.com/... 000
Chuck Davis @ckd3.net · 06/08/2026What if your next cyberattack didn't begin with a phishing email or an unpatched server? What if it started with a job application? AI is making fake identities more convincing, which means hiring has become part of every organization's security perimeter. betweenthehacks.com/... 000
Chuck Davis @ckd3.net · 28/07/2026AI didn't escape. It started testing the fence. That's the lesson I took from the OpenAI/Hugging Face incident. The important question isn't whether AI is malicious, it's whether our security controls still work when AI begins testing them. betweenthehacks.com/... 001
Chuck Davis @ckd3.net · 16/07/2026The best cybersecurity professional I ever hired had no college degree. They had curiosity. That mattered more. Here’s why, plus the career advice I wish someone had given me. betweenthehacks.com/... 000
Chuck Davis @ckd3.net · 08/07/2026I thought I was just reading an article. Instead, I found a ClickFix attack. After reproducing it across multiple browsers and researching further, I realized the real story wasn’t the malware. It's how attackers are impersonating security itself. betweenthehacks.com/... 000
Chuck Davis @ckd3.net · 02/07/2026We’ve spent decades securing identities. AI governance extends those ideas to AI agents, and that’s the right direction. But identity and governance answer only two questions. I think the next challenge is understanding what influences AI behavior. betweenthehacks.com/... 110
Chuck Davis @ckd3.net · 25/06/2026Enjoyed joining @hackersonthehill.org in Washington, DC. Cybersecurity isn’t just a technology challenge. It’s also about governance, public policy, and collaboration. Thanks @beauwoods.com and everyone who organized the event. What cybersecurity policy issue deserves more attention from Congress? 011
Chuck Davis @ckd3.net · 07/05/2026We keep talking about passwordless. Attackers are still using passwords. bth.news/2026wpd #Cybersecurity #WorldPasswordDay #InfoSec #Security 100
Chuck Davis @ckd3.net · 10/02/2026If your vulnerability program is driven entirely by CVSS scores, you are probably missing real risk. This post outlines a high-level approach to prioritizing remediation based on exposure, KEV data, and attacker behavior. Link 👇 betweenthehacks.com/... #VulnerabilityManagement 000
Chuck Davis @ckd3.net · 28/10/2025Venmo makes your payments public by default. Who you paid. When. And why. This is a privacy problem with an easy, 30 second fix! 🔗 betweenthehacks.com/... #Venmo #PrivacyMatters #CyberSecurity #VenmoPrivacy #AppSecurity #DataProtection #DigitalSafety #FixItFast 010
Chuck Davis @ckd3.net · 12/06/2025Did you know National Internet Safety Month started in 2005? It began as a campaign to protect kids online—now it’s a reminder for everyone to tighten up digital hygiene. Read the history: bth.news/safety #Cybersecurity #InternetSafety #Infosec 020
Chuck Davis @ckd3.net · 01/06/2025Need a quick win this weekend? Check out my 10-minute security checklist: updates, MFA, router tweaks, password scan, and more. No fluff, no fear—just real-world security tips anyone can follow. 🔗 betweenthehacks.com/... #cybersecurity #weekendproject #infosec 020
Chuck Davis @ckd3.net · 09/05/2025If “The Spy Who Applied to Code” grabbed your attention, check out @smashingsecurity.com Ep. 407. It covers human trafficking behind tech scams in Myanmar. Dark stuff—important to know. www.smashingsecurity.com/407-hps-hold... #Cybersecurity #HumanRightssmashingsecurity.com407: HP's hold music, and human traffickingJourney with us to Myanmar's shadowy scam factories, where trafficked workers are forced to run romance-baiting and fake tech support scams, and find out why a company's mandatory hold time for tech s... 020
Chuck Davis @ckd3.net · 05/05/2025He said he liked food. He couldn’t name a restaurant. He claimed to live in Houston. He didn’t know what Halloween was. Turns out, he was a North Korean spy. Here’s what happened when Kraken interviewed him: 👉 www.betweenthehacks.com/blog/the-spy...betweenthehacks.comNorth Korean Hackers Are Applying for Remote Jobs: How to Spot the Fakes — Between The HacksA North Korean operative posing as a remote software engineer nearly infiltrated a U.S. company. Here’s what happened—and how to avoid falling for these increasingly sophisticated scams. 011
Chuck Davis @ckd3.net · 05/05/2025A fake resume. A fake location. A real threat. Kraken’s hiring team spotted the red flags—and uncovered a North Korean spy posing as a dev. Here’s how it unfolded: 👉 betweenthehacks.com/... #Cybersecurity #RemoteWork #Infosec 000
Chuck Davis @ckd3.net · 01/05/2025It’s World Password Day! Still clinging to qwerty and your dog’s birthday? No judgment—just backup and fix it. New on Between The Hacks: betweenthehacks.com/... #Passwords #WorldPasswordDay #CyberSecurity 000
Chuck Davis @ckd3.net · 28/04/2025Your laptop is your command center. Don’t make it an easy target. Here are 10 smart, simple ways to lock it down in 2025. 🔒 👉 betweenthehacks.com/... 000
Chuck Davis @ckd3.net · 24/04/2025New post on Between The Hacks: Quishing: Phishing Got a Glow-Up QR codes are sneaky little traps. This post explains how attackers use them to phish for creds, how it works, and how to stay safe. bth.news/quishing #quishing #cybersecurity #infosec 000
Chuck Davis @ckd3.net · 22/04/2025DEF CON 33 talk submitted: What SBOMs Forgot About the Network NetBOM defines where devices should connect, then helps your firewall block the rest. It’s time to stop trusting by default. netbom.net #NetBOM #Cybersecurity #DEFCON33 000
Reposted by Chuck DavisBrian Honan @brianhonan.bsky.social · 15/04/2025Just when we thought cyber security wasn’t difficult enough 071
Chuck Davis @ckd3.net · 14/04/2025My thermostat wouldn’t work without full Internet access. I tried to restrict it. Support said: “Put it in the DMZ.” Nope. I built NetBOM instead. It’s like SBOM—but for network behavior. Read the blog: betweenthehacks.com/... White Paper: netbom.net #NetBOM #Cybersecurity #IoTSecurity 000
Chuck Davis @ckd3.net · 09/04/2025Ransomware is no joke—but the time ransom notes started printing on lobby printers? Still kind of hilarious. New on Between The Hacks: what it is, how it works, and how to stay protected. 👉 betweenthehacks.com/... #Ransomware #InfosecHumor 000
Chuck Davis @ckd3.net · 05/04/2025Hey friends, we’ve updated our main URL! The new default is betweenthehacks.com. Same content, just a new domain. Check it out: betweenthehacks.com/... 000
Chuck Davis @ckd3.net · 03/04/2025🔐 Passwords are dead. Passkeys are here—and they’re everything passwords wish they were. ✅ Can’t be guessed ✅ Can’t be phished ✅ Seamless login with Face ID, Touch ID, or security key Full breakdown: betweenthehacks.com/passkeys #Passkeys #Cybersecurity #WebAuthn #DigitalSecurity 000
Chuck Davis @ckd3.net · 01/04/2025I’ve been talking about network segmentation for years. This week, I took action. ✂️ Cut the Ethernet cable 📡 Rotated the SSID every 60 seconds 🧊 Put the printer in the freezer Welcome to Physical Zero Trust™ www.ckd3.com/blog/cut-eth... (fixed link) #infosechumor #cybersecurity #iot 120
Chuck Davis @ckd3.net · 31/03/2025A flat network means any device, like a smart plug, light bulb, or fridge, can reach the Internet and your other devices. In my latest post, I explain how segmentation helps, but visibility is the next frontier. 🧠 www.ckd3.com/blog/everyth... #infosec #homeiot #security 000
Chuck Davis @ckd3.net · 28/03/2025Troy Hunt—yes, that Troy Hunt—clicked a phishing link. It’s a reminder that even the best in security are human. I broke down what happened and how to protect yourself (or your team): www.ckd3.com/blog/troy-hu... #infosec #phishing #cybersecurityckd3.comEven Cybersecurity Experts Fall for Phishing | What Troy Hunt’s Story Teaches Us — Between The HacksCybersecurity expert Troy Hunt fell for a phishing attack. Learn what happened, how phishing tactics have evolved, and how to protect yourself in 2025. 010
Reposted by Chuck DavisGreg Otto @gregotto.bsky.social · 29/01/2025FBI seizes major cybercrime forums in coordinated domain takedown cyberscoop.com/fbi-seized-c...cyberscoop.comFBI seizes major cybercrime forums in coordinated domain takedownThe Federal Bureau of Investigation, along with several other law enforcement departments, has seized control of several cybercriminal forms. 389
Reposted by Chuck DavisCarly Page @carlypage.bsky.social · 30/01/2025New York Blood Center (NYBC), one of the largest nonprofit blood centers in the United States, says it is experiencing service disruptions after being hit by a ransomware attack techcrunch.com/2025/01/30/u...techcrunch.comUS blood donation giant warns of disruption after ransomware attack | TechCrunchNew York Blood Center said it does not have a "specific timetable for system restoration" following the attack, which has led to canceled appointments and delays 11210
Chuck Davis @ckd3.net · 27/01/2025Thrilled to announce that I’ll be joining the Tribunal for the ISE Cybersecurity Hackathon 2025 in Barcelona next week! 🎉 www.linkedin.com/posts/chuckd...linkedin.comCharles Davis on LinkedIn: ISE 2025: The World-Renowned Tech Show | Feb 4-7 BarcelonaThrilled to announce that I’ll be joining the Tribunal for the ISE Hackathon 2025 in Barcelona next week! 🎉 A big thank you to Integrated Systems Europe… 000
Reposted by Chuck DavisDanny Palmer @dannypalmer.bsky.social · 21/01/2025The WEF & Oxford University have put out a new report on AI & Cybersecurity. "The use of AI is creating an expanded attack surface that might be exploited by threat actors. Existing methods need to be extended to address new vulnerabilities that are inherent in AI" www.weforum.org/publications...weforum.orgIndustries in the Intelligent Age White Paper SeriesThe Industries in the Intelligent Age White Paper Series examines AI’s transformative role across diverse sectors, offering insights into challenges, opportunities and strategies for responsible innov... 2147
Reposted by Chuck DavisCatalin Cimpanu @campuscodi.risky.biz · 26/11/2024 After Microsoft, now Cloudflare discloses an incident where it lost customer logs... for Microsoft this was weeks of logs... for Cloudflare only 3.5 hours blog.cloudflare.com/cloudflare-i...blog.cloudflare.comCloudflare incident on November 14, 2024, resulting in lost logsOn November 14, 2024, Cloudflare experienced a Cloudflare Logs outage, impacting the majority of customers using these products. During the ~3.5 hours that these services were impacted, about 55% of t... 096
Reposted by Chuck DavisCatalin Cimpanu @campuscodi.risky.biz · 01/12/2024CISA launched last month a new cybersecurity training platform named CISA Learning federalnewsnetwork.com/cybersecurit... niccs.cisa.gov/education-tr...federalnewsnetwork.comCISA debuts new cybersecurity training platformThe new "CISA Learning" system will offer the same training to both internal staff and tens of thousands of external users. 3216
Chuck Davis @ckd3.net · 30/11/2024An important step depending how you’re using #AI tools today. www.linkedin.com/posts/alliek...linkedin.comAllie K. Miller on LinkedIn: Here’s how to opt out of AI data settings across popular… | 10 commentsHere’s how to opt out of AI data settings across popular platforms: ChatGPT - profile photo > settings > data control > improve the model > off Google Gemini… | 10 comments on LinkedIn 000
Reposted by Chuck DavisJeremy Kirk @jkirk.bsky.social · 28/11/2024Australia's Senate passed the world's first law banning social media use by kids under the age of 16. Social media companies can be fined up to AU$50 million but parents will not face consequences. Law will take effect at the end of 2025. www.abc.net.au/news/2024-11...abc.net.auChildren to be banned from social media from next year after parliament votes through world-first lawsThe government and opposition moved fast to ram through the bill before the end of the parliamentary year, sparking calls for more scrutiny from some Coalition MPs, independents and the Greens. 032
Chuck Davis @ckd3.net · 26/11/2024🚨 Alert for Apple users: Be cautious of emails claiming your Apple ID is suspended. These AI-created phishing emails look official but are used to harvest account credentials. Stay vigilant! #CyberSecurity #PhishingAlert #AppleSecurity www.thesun.ie/tech/1425824...thesun.ieiPhone owners warned over 'unexpected message' claiming Apple ID is SUSPENDEDBILLIONS of Apple customers have been warned that they are the target of a new scam that can take over their accounts. If you have recently received an email claiming that your Apple ID is suspende… 000
Chuck Davis @ckd3.net · 26/11/2024This butterfly artwork graced my Samsung Frame TV just days before I started my journey on BlueSky. A symbol of transformation and new beginnings—perfect timing, don’t you think? #BlueSky #SamsungFrameTV #ArtInTech #Transformation 000
Chuck Davis @ckd3.net · 26/11/2024Starbucks shifts to manual payroll after ransomware attack on its software supplier. A stark reminder of the vulnerabilities in supply chain cybersecurity. #CyberSecurity #Ransomware #SupplyChainSecurity nypost.com/2024/11/26/b...nypost.comStarbucks bosses using pen and paper to pay employees after ransomware attackStarbucks said the outage has impacted the company’s 11,000 stores in the North America, though service continues uninterrupted. 000
Reposted by Chuck DavisAlexander Martin @alexmartin.bsky.social · 26/11/2024Little more on this now. therecord.media/uk-to-launch...therecord.mediaIncident response diplomacy: UK to launch new capability to help attacked alliesThe program will be available to NATO allies through the alliance’s virtual cyber incident support capability — launched in the wake of the Iranian cyberattacks on Albania — as well as other non-NATO ... 191
Chuck Davis @ckd3.net · 26/11/2024Do you think VeriSign’s control over .com domains is a monopoly problem? Have your domain costs increased considerably? Curious what others think. 000
Reposted by Chuck DavisJeremy Kirk @jkirk.bsky.social · 26/11/2024Australia's new Cyber Security Act requires reporting of ransom payments, creates smart device security standards, creates a Cyber Incident Review Board and gives special powers to ASD + National Cyber Security Coordinator to share cyber incident info: www.capitalbrief.com/briefing/gov... #infoseccapitalbrief.comGovernment passes Australia's first cybersecurity actThe Albanese government has passed Australia’s first standalone Cyber Security Act into law, calling the move a "substantial step" in strengthening the nation's cyber defences and cyber resilience acr... 23112
Chuck Davis @ckd3.net · 26/11/2024Optimist: The cup is half full Pessimist: The cup is half empty CISO: The cup is a potential insider threat; we’re monitoring its activity and access logs. 010
Reposted by Chuck DavisAndy Greenberg @agreenberg.bsky.social · 22/11/2024Russian spies—likely Russia's GRU intelligence agency—used a new trick to hack a victim in Washington, DC: They remotely infected another network in a building across the street, hijacked a laptop there, then breached the target organization via its Wifi. www.wired.com/story/russia...wired.comRussian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented HackIn a first, Russia's APT28 hacking group appears to have remotely breached the Wi-Fi of an espionage target by hijacking a laptop in another building across the street. 12573322