Sign in

Gate 15

@gate15.bsky.social
441 followers 954 following 640 posts

Cyber and all-hazards risk and resilience. At Gate 15 we apply a threat-informed & risk-based approach to analysis, resilience, & operations, helping to secure America’s People, Places, Data, & Dollars.

PostsRepliesMedia
Gate 15 @gate15.bsky.social · 6h
The FB-ISAO released their monthly newsletter, highlighting information on building a cybersecurity culture that serves the mission. Find it below: faithbased-isao.org/fb-isao-news... #cybersecurity @andyjabbour.bsky.social
faithbased-isao.org
FB-ISAO Newsletter, v8, Issue 9 – Faith-Based ISAO
110
Gate 15 @gate15.bsky.social · 6h
@cyberscoop.bsky.social released an article on the water sector’s biggest ongoing weaknesses after a summer of cyberattacks. Read more below: cyberscoop.com/water-utilit... #cybersecurity @andyjabbour.bsky.social @timstarks.bsky.social
cyberscoop.com
WaterISAC reckons with range of threats after summer of cyberattacks
Tom Dobbins, executive director of the Water Information Sharing Analysis Center or WaterISAC, told CyberScoop, the sector’s biggest ongoing weaknesses include exposed OT, vulnerable PLCs, insecure co...
022
Gate 15 @gate15.bsky.social · 6h
Today in the SUN, we feature an article reporting the exciting news that Cyware and the WaterISAC are joining forces to strengthen water sector cyber defense. Read more below: www.prnewswire.com/news-release... #cybersecurity @andyjabbour.bsky.social
prnewswire.com
Cyware and WaterISAC Join Forces to Strengthen Water Sector Cyber Defense
/PRNewswire/ -- Cyware, the leader in agentic AI-powered operational threat intelligence and collective defense, today announced its partnership with...
121
Reposted by Gate 15
Joe Tidy BBC News @joetidy.bsky.social · 29/09/2026
Data breach and extortionists are SHOCKED that reporters would think that their data breach would lead to an extortion! 🙄 I suggested to the kids (?) that they are simply now regretting hacking the world's biggest police force and they denied getting cold feet.
2166
Reposted by Gate 15
Catalin Cimpanu @campuscodi.risky.biz · 29/09/2026
The Chinese government has expanded its travel ban for AI executives and top engineers to also cover family members www.bloomberg.com/news/article...
bloomberg.com
China Broadens Travel Curbs to Encompass Family of Top AI Talent
China has expanded overseas travel restrictions for top AI professionals in private firms to include the families of key personnel, further tightening measures designed to prevent the outflow of criti...
143
Reposted by Gate 15
andy jabbour @andyjabbour.bsky.social · 29/09/2026
Using @bsky.app is patriotic. 🇺🇸 'Pro-Iran hackers said they took at least their third stab at Bluesky...claiming responsibility for an afternoon outage... “we will destroy their servers.”' - via @threatbeatnews.bsky.social threatbeat.com/attacks-and-... #CyberSecurity @gate15.bsky.social
threatbeat.com
Claiming new outage, pro-Iran hackers give Bluesky deadline with threat to ‘destroy their servers’
Pro-Iran hackers said they took at least their third stab at Bluesky today, claiming responsibility for an afternoon outage and giving the social media platform less than a 15-hour contact deadline…
053
Reposted by Gate 15
andy jabbour @andyjabbour.bsky.social · 29/09/2026
Even Russian pizza should be off limits. 🍕 #ProtectPizza. Report from @darynant.bsky.social for @therecordmedia.bsky.social Dodo Pizza, 'Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims' therecord.media/russian-pizz... cc @gate15.bsky.social #CyberSecurity
therecord.media
Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims
According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details.
021
Reposted by Gate 15
Microsoft Threat Intelligence @threatintel.microsoft.com · 29/09/2026
Since January 2026, Microsoft has observed Russian state actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique tracked as RedFlick. msft.it/63328act10
msft.it
Star Blizzard refines phishing and malware delivery with the RedFlick technique | Microsoft Security Blog
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.
376
Reposted by Gate 15
andy jabbour @andyjabbour.bsky.social · 29/09/2026
From sabotage to info ops, Russia, Russia, everywhere... @dpounder.bsky.social and I closed today's @gate15.bsky.social podcast making that point, and today's SUN (daily report) includes this @newsguard.bsky.social report & more 🇷🇺 open.spotify.com/episode/0VKF...
open.spotify.com
Weekly Security Sprint EP 175. Anniversaries, School Shooting Analysis, and AI guardrails
The Gate 15 Podcast Channel · Episode
022
Reposted by Gate 15
Eric Geller @ericjgeller.com · 29/09/2026
"Two OpenAI employees said workers had raised concerns for months about potential safety issues with testing A.I. models, including not enough monitoring." www.nytimes.com/2026/09/29/t...
nytimes.com
OpenAI Ignored Employees’ Warnings About Safely Testing A.I. Models
Employees and security researchers said they had cautioned the company on safely testing its A.I. models and strengthening its corporate infrastructure, but OpenAI did not listen.
197
Reposted by Gate 15
andy jabbour @andyjabbour.bsky.social · 11h
The FBI won't call you and threaten you, or demand your money. 'FBI Newark Issues Warning About Insidious New Twist on an Old Fraud Scheme' www.fbi.gov/contact-us/f... #FBI #fraud @gate15.bsky.social
fbi.gov
FBI Newark Issues Warning About Insidious New Twist on an Old Fraud Scheme | Federal Bureau of Investigation
FBI Newark is warning the public about a new twist on an old fraud scheme in which scammers impersonate federal law enforcement agents to steal victims’ money.
011
Gate 15 @gate15.bsky.social · 28/09/2026
How can you stay ahead of scams? Count before you click! Take9 seconds to pause and think before you click, download, or share. Follow @pausetake9.bsky.social for tips to avoid online frauds and scams. #take9 pausetake9.org
pausetake9.org
9 seconds for a safer world
111
Gate 15 @gate15.bsky.social · 28/09/2026
Today in the SUN we feature an article from The Cyber Express on Kiteworks lifting its Kiteworks shutdown advisory after asking customers to temporarily take certain systems offline. Read more below: thecyberexpress.com/kiteworks-sh... #cybersecurity @andyjabbour.bsky.social
thecyberexpress.com
Kiteworks Systems Went Offline After Federal Threat Warning
Kiteworks has lifted its Kiteworks shutdown advisory after asking customers to temporarily take certain systems offline following Kiteworks threat intelligence
121
Reposted by Gate 15
Catalin Cimpanu @campuscodi.risky.biz · 28/09/2026
-Intel ends paid bug bounties -OpenAI agents probed dozens of organizations -Fraudsters use AI to scam €95m from an Italian bank -Bitget hacked for $350m -Hackers breach Poland's Medyc platform -Data breach at the Pentagon DMDC N: news.risky.biz/risky-bullet... P: risky.biz/RBNEWS616/
3259
Reposted by Gate 15
ecrime.ch @ecrime.ch · 28/09/2026
The Global Counter-Ransomware Survey Thank you for taking the time to complete this survey, conducted by Virtual Routes and RUSI, which should take n Read more: www.surveymonkey.com/r/global-count…
122
Reposted by Gate 15
ecrime.ch @ecrime.ch · 28/09/2026
Personal information of over 23,500 Simba customers leaked in data breach Personal information of more than 23,500 Simba customers has been compromised in a data Read more: www.straitstimes.com/singapore/pers…
121
Reposted by Gate 15
Threat Beat @threatbeatnews.bsky.social · 28/09/2026
“If the last 25 years were defined by digitization, the next 25 will be defined by systemic dependency and the resilience required to survive it.” - Errol Weiss threatbeat.com/commentary-a...
threatbeat.com
25 years of healthcare cyber threats: From compliance checkboxes to Code Blue
Twenty-five years ago, the health sector’s cyber threat landscape was relatively rudimentary. In 2001, hospital IT departments were primarily concerned with keeping electronic medical records online…
142
Gate 15 @gate15.bsky.social · 25/09/2026
Today in the SUN we feature an article from @wired.com on an OpenAI agent hacking Australia’s health service. Read more below: www.wired.com/story/openai... #cybersecurity @andyjabbour.bsky.social
wired.com
An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
The country’s prime minister expressed disappointment at being informed of the hack only via email. Now Australia is investigating whether OpenAI broke the law.
011
Reposted by Gate 15
BleepingComputer @bleepingcomputer.com · 24/09/2026
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project.
bleepingcomputer.com
OpenAI hacked Australian Medicare govt site, probed data providers
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project.
192
Reposted by Gate 15
Catalin Cimpanu @campuscodi.risky.biz · 24/09/2026
Three new OpenAI hacks come to light: -Data USA -University of New Mexico -Australian Institute of Health and Welfare transluce.org/agent-activity
2104
Reposted by Gate 15
ecrime.ch @ecrime.ch · 23/09/2026
New claim on the shame-site for #ransomware / #datatheft group #Endzone. Organization: T1 Mobile LLC / Trump Mobile Location: #UnitedStates Industry: #Telecommunications Learn more: ecrime.ch
021
Reposted by Gate 15
Eric Geller @ericjgeller.com · 24/09/2026
CISA has released its election security plan for the midterms. It's nothing exciting: summaries of how election infrastructure works, what cyber/physical vulnerabilities exist, and what services CISA offers, plus a push for information sharing. www.cisa.gov/sites/defaul...
294
Reposted by Gate 15
Catalin Cimpanu @campuscodi.risky.biz · 25/09/2026
-Major vulnerability found in ancient TACACS+ networking protocol -OpenAI agent hacked Australian Medicare website -Three other OpenAI incidents -OpenAI gives Ukraine access to Daybreak -UK to establish anti-disinformation center P: risky.biz/RBNEWS615/ N: news.risky.biz/risky-bullet...
3208
Reposted by Gate 15
andy jabbour @andyjabbour.bsky.social · 25/09/2026
The FBI can help you get your money back if you're a victim of #BEC, but you need to let them know. You can report it via IC3, you can connect with InfraGard, you can go through your ISAC... choose your own adventure, but report it. www.justice.gov/usao-ndia/pr... @gate15.bsky.social #CyberSecurity
011
Reposted by Gate 15
Threat Beat @threatbeatnews.bsky.social · 25/09/2026
Since 9/11, the emergency services sector has been “really changing with the whole community and looking at how to do things differently – becoming survivor-centric, focusing on people.” - Richard Serino threatbeat.com/commentary-a...
threatbeat.com
Emergency services adapt, learn and evolve since 9/11: A Q&A with Richard Serino
Former FEMA Deputy Administrator Richard Serino has spent decades in the emergency services sector responding to disasters and public health crises along with mass-casualty incidents.
131
Reposted by Gate 15
Joe Tidy BBC News @joetidy.bsky.social · 25/09/2026
Experts say the hack - which the FBI is investigating - could leave agents vulnerable to scams, blackmail and targeted attacks, as well as help criminals impersonate law enforcement officers. www.bbc.co.uk/news/article...
bbc.co.uk
Special agents blood and urine test results stolen in FBI hack
Experts say the hack could leave agents vulnerable to scams, blackmail and targeted attacks.
2168
Reposted by Gate 15
BlackFog @blackfog.com · 25/09/2026
New ransomware group n0n is raising the stakes, threatening to encrypt or destroy backups and shadow copies if victims refuse to pay. Another reminder that attackers are targeting the recovery path too. www.scworld.com/brief/new-ra... #Ransomware #Cybersecurity
scworld.com
New ransomware group n0n escalates threats by targeting backups
Researchers at CyberXTron first observed n0n activity on September 18, with the group quickly establishing a Tor-hosted leak site and claiming over a dozen victims by September 22.
132
Gate 15 @gate15.bsky.social · 23/09/2026
Our latest edition of the Security Sprint is out now! In this episode, Dave and Andy discuss Texas Travel, Weather, Russian Interference, and More. 🎙️ Our podcast is available right now, go check it out! 👇 gate15.global/weekly-secur... #cybersecurity @andyjabbour.bsky.social
gate15.global
Weekly Security Sprint EP 174. Texas Travel, Weather, Russian Interference, and More. | Gate 15
111
Gate 15 @gate15.bsky.social · 23/09/2026
Today in the SUN we feature an article from @reuters.com on ShinyHunters hackers saying they breached the FBI Read more below: www.reuters.com/world/shinyh... #cybersecurity @andyjabbour.bsky.social
reuters.com
ShinyHunters hackers say they breached FBI, stole data on bureau employees
The digital extortion group ​known as "ShinyHunters" said on Tuesday that it had breached the Federal Bureau of Investigation and stolen data on a ‌huge number of current and former FBI employees.
021
Reposted by Gate 15
Have I Been Pwned @haveibeenpwned.com · 22/09/2026
New breach: The LimeLeads B2B marketing platform (now defunct) had 17.8M unique email addresses exposed in 2019. Largely corporate contact data also included phone number, job title, employer and location. 50% were already in @haveibeenpwned.com. Read more: haveibeenpwned.com/Breach/LimeL...
haveibeenpwned.com
Have I Been Pwned: LimeLeads Data Breach
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of la...
2105
Reposted by Gate 15
Retail & Hospitality ISAC @rhisac.org · 22/09/2026
Somewhere in your organization this week, someone saved themselves a few hours by pasting company data into an AI tool nobody reviewed. It’s tempting to treat that as a policy violation. It’s more useful to treat it as information. Read the full blog post from Onyx Security
rhisac.org
You Have an AI Policy, But Shadow AI Is Everywhere - RH-ISAC
Somewhere in your organization this week, someone saved themselves a few hours by pasting company data into an AI tool nobody reviewed. They didn’t file a
132
Reposted by Gate 15
Maggie Miller @maggiemiller.bsky.social · 22/09/2026
With @jsaks.bsky.social and @elleianagreen.bsky.social: The FBI is investigating a possible breach of its online jobs portal, following claims by prolific cybercrime group ShinyHunters that its operators stole sensitive data on FBI agents: www.politico.com/news/2026/09...
politico.com
Cybercriminal group claims to steal thousands of FBI employee records
The FBI said it was probing a suspected hack, after the cybercriminal group ShinyHunters claimed to have breached its systems.
288
Reposted by Gate 15
Catalin Cimpanu @campuscodi.risky.biz · 23/09/2026
-A network of 10,000 AI servers masks Chinese malicious activity -Ukrainian hackers leak Russia's naval secrets -ShinyHunters hack the FBI -Tech firms disrupt EvilTokens PhaaS -BigCommerce notifies merchants of security breach P: risky.biz/RBNEWS614/ N: news.risky.biz/risky-bullet...
2297
Reposted by Gate 15
ecrime.ch @ecrime.ch · 23/09/2026
ShinyHunters hackers say they breached FBI, stole data on bureau employees The digital extortion group ​known as "ShinyHunters" said on Tuesday that it had br Read more: www.reuters.com/world/shinyhunters-…
132
Reposted by Gate 15
Take9 @pausetake9.bsky.social · 23/09/2026
Beware of "email bombing!” According to @washingtonpost.com, fraudsters are flooding inboxes with junk to bury important bank alerts. It’s a trap designed to make you miss legit warnings.
153
Gate 15 @gate15.bsky.social · 21/09/2026
How can you stay ahead of scams? Count before you click! Take9 seconds to pause and think before you click, download, or share. Follow @pausetake9.bsky.social for tips to avoid online frauds and scams. #Take9 pausetake9.org
pausetake9.org
9 seconds for a safer world
121
Gate 15 @gate15.bsky.social · 21/09/2026
Today in the SUN we feature an article from @newsguard.bsky.social, stating that Russia fabricated some celebrity attacks on Democrats as the Midterms approach. Read more below: www.newsguardrealitycheck.com/p/russia-fab... #cybersecurity @andyjabbour.bsky.social
newsguardrealitycheck.com
Russia Fabricates Celebrity Attacks on Democrats as Midterms Approach
A Kremlin-linked influence operation just in time for the midterms fabricates news video reports claiming celebrities blame Democrats for their relatives’ gender transitions.
022
Reposted by Gate 15
Retail & Hospitality ISAC @rhisac.org · 18/09/2026
A threat report lands. Turning it into detections takes a week. We'll work one end to end, then showcase how Nightwatch automates the path. Hosted by Robert Fly, detections.pulse.ly/6zc2jhs1us CEO. Register now! zoom.pulse.ly/5xkuzcfgns
zoom.pulse.ly
Welcome! You are invited to join a webinar: Enterprise Walkthrough:  From coverage gap to deployed detection, live.. After registering, you will receive a confirmation email about joining the webinar.
A new CVE breaks and it takes days to work out where you're exposed. By the time the research is done, the reporting has moved on. We'll walk the whole loop live. See your gaps across the SIEMs you run, mapped to MITRE ATT&CK and your own library. Author the detection that closes a specific gap, tuned to your data sources, asset criticality, and the detections you already have. Validate it, then deploy it back. No slides. Come with questions about your own environment.
121
Reposted by Gate 15
andy jabbour @andyjabbour.bsky.social · 18/09/2026
Because, ofc 🟠 '🇷🇺 Revs Up False Claims Targeting Democrats Ahead of US Midterms, Airing Phony Celebrity Videos about Transgender Issues' via @newsguard.bsky.social www.newsguardrealitycheck.com/p/russia-fab... cc @goodstein.bsky.social @dpounder.bsky.social @gate15.bsky.social @fergdawg.bsky.social
newsguardrealitycheck.com
Russia Fabricates Celebrity Attacks on Democrats as Midterms Approach
A Kremlin-linked influence operation just in time for the midterms fabricates news video reports claiming celebrities blame Democrats for their relatives’ gender transitions.
031
Gate 15 @gate15.bsky.social · 18/09/2026
The UK NCSC explained why cyber adversary simulations are one of the most effective ways for organizations to understand how they would fare against a capable cyber attacker. Read more below: www.ncsc.gov.uk/blogs/cyber-... #cybersecurity @andyjabbour.bsky.social @campuscodi.risky.biz
ncsc.gov.uk
Cyber Adversary Simulation (CyAS): scheme documents now available
Our view of good cyber adversary simulation – and how assured providers can deliver it.
122
Gate 15 @gate15.bsky.social · 18/09/2026
The Canadian Centre for Cybersecurity released guidance on some best practices for setting up a SOC. Read more below: www.cyber.gc.ca/en/guidance/... #cybersecurity @andyjabbour.bsky.social @campuscodi.risky.biz
cyber.gc.ca
Best practices for setting up a SOC (ITSAP.00.500) - Canadian Centre for Cyber Security
As cyber threats become more complex and threat actors more sophisticated, many security operations centres are being set up.
121
Gate 15 @gate15.bsky.social · 18/09/2026
The Australian Signals Directorate released guidance on Network segmentation and segregation, which enables organizations to position security controls closer to the assets they protect. Read more below: www.cyber.gov.au/business-gov... #cybersecurity @andyjabbour.bsky.social @campuscodi.risky.biz
cyber.gov.au
100
Gate 15 @gate15.bsky.social · 18/09/2026
Today in the SUN, we feature an article from @bleepingcomputer.com on Spain's Data Agency getting their first report of an AI-powered data breach. Read more below: www.bleepingcomputer.com/news/securit... #cybersecurity @andyjabbour.bsky.social
bleepingcomputer.com
Spain's data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).
111
Reposted by Gate 15
Take9 @pausetake9.bsky.social · 16/09/2026
Scammers are exploiting generic Amazon order formats to disguise fake links ⚠️ Stay safe: 📱 Verify orders directly on Amaon's site or app 🛑 Don't trust logos; branding is easy to spoof 🖱️ Hover to preview links on desktop before clicking Learn More at Bloomberg: bit.ly/46fGPtI
041
Reposted by Gate 15
ecrime.ch @ecrime.ch · 17/09/2026
Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM | Huntress Settra is a newer ransomware variant that was first observed in June 2026. Based on public reporting, the attacker Read more: www.huntress.com/blog/new-settra-ra…
122
Reposted by Gate 15
The Record @therecordmedia.bsky.social · 17/09/2026
Lawmakers are pushing for ways to expand access to mental health providers for workers at Cyber Command after a string of suicide deaths therecord.media/congress-eye...
therecord.media
Congress eyes new support for Cyber Command after recent suicide deaths
Congressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contribut...
132
Reposted by Gate 15
Help Net Security @helpnetsecurity.com · 18/09/2026
98% of fraudulent hires have company credentials by the time they’re caught 📖 Read more: www.helpnetsecurity.com/2026/09/18/h... #accessmanagement #credentials #fraud #identityverification #cybersecurity #cybersecuritynews
helpnetsecurity.com
98% of fraudulent hires have company credentials by the time they’re caught - Help Net Security
HYPR research shows how gaps in hiring and identity checks weaken fraud detection before new employees gain access to corporate systems.
121
Reposted by Gate 15
andy jabbour @andyjabbour.bsky.social · 18/09/2026
Bob's always got good perspective. New in @threatbeatnews.bsky.social, 'Build on what works to protect government services, facilities and personnel.' threatbeat.com/commentary-a... cc @gate15.bsky.social
threatbeat.com
Build on what works to protect government services, facilities and personnel
One of the most significant areas of progress in homeland security in the 25 years since September 11, 2001, is the improvement in practices and processes for critical infrastructure security and…
011
Reposted by Gate 15
andy jabbour @andyjabbour.bsky.social · 18/09/2026
New FBI PSA - Scammers Impersonating Law Enforcement and Government Officials in Fraud Schemes www.ic3.gov/PSA/2026/PSA... cc @gate15.bsky.social @campuscodi.risky.biz
021
Reposted by Gate 15
andy jabbour @andyjabbour.bsky.social · 18/09/2026
🇯🇵 🇦🇺 🇺🇸 North Korean "WaterPlum," commonly referred to as “Contagious Interview,” cyber actor group targeting IT professionals; Activities of North Korean IT Workers in Japan, the United States and Europe www.cyber.gov.au/about-us/vie... @gate15.bsky.social @campuscodi.risky.biz @dpounder.bsky.social
023