Sign in

lex

@infoseclex.bsky.social
438 followers 933 following 56 posts

infosec • I kept my blackberry as long as possible and now I’m on bluesky

PostsRepliesMedia
lex @infoseclex.bsky.social · 03/08/2025
@southflpalace.bsky.social Are there any good CPFC bars near Miami to watch the Community Shield next weekend?
100
lex @infoseclex.bsky.social · 18/06/2025
AI model logics flaws are the new open S3 buckets
010
Reposted by lex
Anuj Ahooja @quillmatiq.com · 01/06/2025
On vibe coding:
I want it to be easier for more folks to write code and understand how the software they use every day works. But software isn't just writing code. It's about learning good architecture: how data is accessed, how it flows, and, most importantly, who can access it and when. You can't just vibe your way through personal information and payment systems, because an issue there isn't just a bug; it has real-life consequences for average users who are entrusting you with their information.
416033
lex @infoseclex.bsky.social · 28/05/2025
The sheer stress of my dyscalculia brain having to enter the right MFA code before it rotates
000
Reposted by lex
Cynthia Brumfield @metacurity.com · 22/04/2025
Billion-dollar cyberscam industry spreading globally, UN says www.reuters.com/world/china/...
reuters.com
'Cancer' of billion-dollar cyberscam industry spreading globally - UN
Asian crime syndicates behind the multibillion-dollar cyberscam industry are expanding globally including to South America and Africa, as raids in Southeast Asia fail to contain their activities, the United Nations said in a report on Monday.
031
Reposted by lex
Lisa Forte @lisaforte.bsky.social · 15/04/2025
Use one of our exercise templates to test your response to an attack on one of your key SaaS providers that could for instance cause an outage of one of your important business services. www.linkedin.com/posts/lisa-f...
linkedin.com
Supply Chain Tabletop Exercise | Lisa Forte
Gartner predicts the cost of software supply chain attacks will triple by 2031 - jumping from $46 billion to a staggering $138 billion. Sounds like a big number. There are a lot of areas of discussio...
0102
Reposted by lex
InfoSec @infosec.skyfleet.blue · 13/04/2025
Hacktivism is back – but don't be fooled, it's often state-backed goons in masks
theregister.com
Are they hacktivists or state-backed goons in masks?
Feature: Military units, government nerds appear to join the fray, with physical infra in sights
051
lex @infoseclex.bsky.social · 28/03/2025
Infosec people: anyone know how to tag critical assets in S1 Singularity SIEM? Any docs on this?
000
Reposted by lex
Mike (beep boop era) @latimeriidae.bsky.social · 25/03/2025
This is one of the few things DOGE is looking to blow up I have very direct personal experience with and HOO BOY if they mess with NIST American manufacturing isn’t going to recover in my lifetime.
1014936
Reposted by lex
Silverman on Security @silvermansecurity.bsky.social · 18/03/2025
👇!!!!! The most insider of insider threats! Remember, during the 1st term, the counterintel folks kept finding Stingers attached to cell towers & other structures near the White House because everyone was trying to collect on Trump's calls using his unsecure personal cell phone. This is even worse.
02014
lex @infoseclex.bsky.social · 17/03/2025
Does anyone use MailEnable? Is it trustworthy? #infosec #IT
000
lex @infoseclex.bsky.social · 16/03/2025
My friend’s business got spammed by horrendous & false Google Reviews, and Google took his company off Maps & Reviews entirely. This is a huge hit on his business. He’s already appealed to Google, but not getting any response. Anyone know what he can do??
000
Reposted by lex
angela zhou @angelamczhou.bsky.social · 15/03/2025
Guess it's time to work on irresponsible and unsafe AI
13819
Reposted by lex
Lisa Forte @lisaforte.bsky.social · 05/03/2025
Equality isn’t women talking about women in cyber it is women talking about cyber.
46012
Reposted by lex
Catalin Cimpanu @campuscodi.risky.biz · 03/03/2025
Podcast: risky.biz/RBNEWS393/ Newsletter: risky.biz/risky-bullet... -Trump administration stops treating Russian hackers as a threat -Meta seeks permanent NSO ban -New Cellebrite 0-days come to light -3rd-party breaches are now a headache for cyber insurers -WazaWaka and Ermakov get home detention
12518
lex @infoseclex.bsky.social · 01/03/2025
Keep speaking up about shoddy security and privacy practices. Keep going. This doesn’t exactly feel like a “win” for privacy but it at least indicates we can, at times, vote with our voices and our consumer choices. thehackernews.com/2025/03/mozi...
thehackernews.com
Mozilla Updates Firefox Terms Again After Backlash Over Broad Data License Language
Mozilla updates Firefox Terms of Use again after privacy concerns over broad data rights language. Company clarifies no ownership over user content
020
Reposted by lex
Brian Fung @brianfung.me · 01/03/2025
ICYMI, I explained Apple's big new update for parents coming later this year, and why it may be a breakthrough in the fight over kids' online safety: youtu.be/iydHkvk5xmw
youtu.be
Apple's big update for parents, explained
YouTube video by BrainFungi
1177
Reposted by lex
NY Times Pitchbot @nytpitchbot.bsky.social · 01/03/2025
Volodymyr Zelensky's Oval Office visit ended early when Donald Trump and JD Vance began angrily yelling at him. Here's why women like Kamala Harris and Hillary Clinton are too emotional to be president.
141181693702
Reposted by lex
UK_Daniel_Card @mrr3b00t.bsky.social · 19/02/2025
This is why I do NOT link SIGNAL to any device! It's on its own! :D
0125
lex @infoseclex.bsky.social · 14/02/2025
If you give a mouse a browser cookie…
000
Reposted by lex
Jason Koebler @jasonkoebler.bsky.social · 14/02/2025
Scoop: The databases powering DOGE.gov are insecure, and people outside the government have already pushed their own updates to the site to prove it: www.404media.co/anyone-can-p...
404media.co
Anyone Can Push Updates to the DOGE.gov Website
"THESE 'EXPERTS' LEFT THEIR DATABASE OPEN."
400143625875
Reposted by lex
Matthew Guariglia @mguariglia.bsky.social · 10/02/2025
Newspaper headline from 1915: "Constant Surveillance Has Depressing Effect"
a newspaper headline from 1915 "constant surveillance has depressing effect"
2193
lex @infoseclex.bsky.social · 09/02/2025
Rut roh www.csoonline.com/article/3820...
csoonline.com
The SolarWinds $4.4 billion acquisition gives CISOs what they least want: Uncertainty
Analysts expect deep spending cuts as the private equity firm tries to boost margins at the cybersecurity vendor, preparing for a quick sale.
020
lex @infoseclex.bsky.social · 05/02/2025
I will never admit how many times a day I google “synonym for ____” while writing security reports
010
Reposted by lex
Nicolas Grégoire @agarri.fr · 04/02/2025
PSA 📢 Mozilla’s offline reader Pocket gives you access to complete Wired articles 🎁
041
lex @infoseclex.bsky.social · 02/02/2025
So will this teach us to stop deprioritizing infrastructure/ network security for feature development? Will anything?
000
Reposted by lex
Catalin Cimpanu @campuscodi.risky.biz · 02/02/2025
Johannes Bader has released Rösti (Repackaged Öpen Source Threat Intelligence), a tool that scans infosec reports and extracts IOCs and YARA rules rosti.bin.re
22211
lex @infoseclex.bsky.social · 31/01/2025
open.substack.com/pub/sashaing...
open.substack.com
Exclusive: The 23-year-old who infiltrated a North Korean laptop farm
Aidan Raney documented an operation to exploit U.S. businesses, one of the ways North Korea funds its weapons of mass destruction and ballistic missile programs.
010
lex @infoseclex.bsky.social · 29/01/2025
Just imagine how many insider risk cases you’d be dealing with if your company had this “deferred resignation” thing the US govt is doing
000
Reposted by lex
Alex de Campi @alexdecampi.bsky.social · 29/01/2025
volunteering or anything task-centric is a great way to break out of isolation without having to make a big effort to talk to people. you just show up and do the thing. and also you’re helping make one small corner of the world a little better
3381122
lex @infoseclex.bsky.social · 29/01/2025
www.crowdstrike.com/en-us/blog/c...
crowdstrike.com
CrowdStrike Falcon Earns Perfect Score in SE Labs’ Ransomware Evaluation
CrowdStrike Falcon® scores 100% in SE Labs 2024 Ransomware Test, earning the AAA Award with unmatched detection, protection, and accuracy against 15 ransomware families.
000
Reposted by lex
Zack Whittaker @zackwhittaker.com · 27/01/2025
New: SonicWall says hackers are exploiting a new zero-day bug in one of its products to breach corporate networks. This is the latest in a long list of bugs in security products that allow the hacking of big networks, which these devices are tasked with protecting. techcrunch.com/2025/01/27/s...
techcrunch.com
SonicWall says hackers are exploiting a new zero-day bug to breach customer networks | TechCrunch
SonicWall said the bug is "confirmed as being actively exploited in the wild" by malicious hackers.
02111
lex @infoseclex.bsky.social · 26/01/2025
Good write-up on cybersecurity focus at the World Economic Forum by Dan Lohrmann: www.govtech.com/blogs/lohrma...
govtech.com
World Economic Forum 2025: Navigating Cybersecurity in an Era of Complexity
What was the cyber outlook at the World Economic Forum in Davos, Switzerland, this past week? From President Trump’s address to new white papers, here’s your roundup.
001
Reposted by lex
kate conger @kateconger.com · 15/01/2025
If your reaction is “lol why now” you are correct. By leaving this til the last minute, the SEC is handing the mess to the incoming administration, letting Trump decide whether to pursue a case against a top donor www.nytimes.com/2025/01/14/t...
nytimes.com
S.E.C. Sues Elon Musk Over Twitter-Related Securities Violations
Regulators filed a lawsuit in federal court stemming from Mr. Musk’s $44 billion purchase of the social media company now called X.
551312283
Reposted by lex
InfoSec @infosec.skyfleet.blue · 20/12/2024
CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List
thehackernews.com
CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List
031
Reposted by lex
Kara Swisher @karaswisher.bsky.social · 20/12/2024
Well, she can fucking try. And it’s a low bar since it could not be worse than the current boneheaded management.
2452525279
Reposted by lex
InfoSec @infosec.skyfleet.blue · 18/12/2024
CISA orders federal agencies to secure Microsoft cloud systems after ‘recent’ intrusions
therecord.media
CISA orders federal agencies to secure Microsoft cloud systems after ‘recent’ intrusions
The Cybersecurity and Infrastructure Security Agency (CISA) issued a binding directive on Tuesday giving federal agencies a series of deadlines to identify cloud systems, implement assessment tools and abide by the agency’s Secure Cloud Business Applications (SCuBA) secure configuration baselines.
043
Reposted by lex
InfoSec @infosec.skyfleet.blue · 16/12/2024
Tic TAC Alert: A Remote Code Execution Vulnerability in Medical Imaging
cybersecuritynews.com
Tic TAC Alert: A Remote Code Execution Vulnerability in Medical Imaging
The vulnerability, CVE-2024-42845, is associated with a function in the software that processes the DICOM standard tag (0x0020, 0x0032).
0104
Reposted by lex
Lesley Carhart @hacks4pancakes.com · 10/12/2024
San Francisco: do you want to learn more about ICS incident response, SOC, and threat hunting? I will be teaching SANS ICS515: ICS Visibility, Detection, and Response in person and virtual next month. Sign up: www.sans.org/cyber-security-trainin…
24610
Reposted by lex
Mike Elgan @mikeelgan.bsky.social · 07/12/2024
Typeface of the moment: Times New Dumbass timesnewdumbass.co
0435
Reposted by lex
Catalin Cimpanu @campuscodi.risky.biz · 06/12/2024
Podcast: risky.biz/RBNEWS370/ Newsletter: news.risky.biz/risky-biz-ne... -Declassified documents reveal Russia's election info-ops in Romania -Salt Typhoon telco hack count reaches eight -Another Scattered Spider member detained -Turla hacked 6 other APTs -Iranian hackers target FBI director pic
13810
Reposted by lex
Matt Johansen @mattjay.com · 05/12/2024
🚨 Breaking: White House official Anne Neuberger reveals Salt Typhoon hacking campaign has compromised at least 8 US telecom providers - far more extensive than initially reported. Campaign impacts dozens of nations.
12616
lex @infoseclex.bsky.social · 05/12/2024
Inherited permissions can be risky. Just think about all the annoying traits you got from your parents.
042
lex @infoseclex.bsky.social · 04/12/2024
I say “please” and “thank you” to GenAI. I can’t help it and won’t stop.
110
Reposted by lex
Jay 🦋 @jay.bsky.team · 04/12/2024
What are the best starter packs you’ve found?
10845493601
Reposted by lex
Chad Bailey @chadbailey.net · 29/11/2024
my favorite Tech Tip is to let all the black friday emails pile up today, and then use gmail's "promotions" tab to select-all and unsubscribe. it's the best day of the year to catch 'em all
916133