Sign in

Layer 8½

@mbrookspetersen.eurosky.social
83 followers 138 following 453 posts

Cybersecurity Awareness & Culture Specialist. Posting about general #infosec and people stuff. Blog: layer8-half.leaflet.pub Opinions are my own. Profile pic by rpg.actor

PostsRepliesMedia
Reposted by Layer 8½
AlexSa @netalexx.bsky.social · 46m
BYOD Ransomware Group Breached Trump Mobile 😏✌️
database.eurepoc-dashboard.eu
EuRepoC Cyber Incidents TableView
131
Layer 8½ @layer8-half.mu.social · 51m
Hey #infosec people: Did you reach a point where you decided to just keep at that one specific field? That you felt like you learned enough and just want/need to keep up to date in that field? I mean infosec is a lot and much is interesting, so it's hard to draw a line, no?
000
Layer 8½ @layer8-half.mu.social · 1h
Actually created a new account because my last one had a slur in the DID. Benefits of fresh accounts.
000
Reposted by Layer 8½
Taggart @taggart-tech.com · 16h
I have theorized about dead-man's switches in ransomware forever, but not seen them in the wild. Interesting that the stealers figured this out!
072
Reposted by Layer 8½
Jess Calarco @jessicacalarco.com · 19h
It's telling that men would rather try to invent tech to replace humans' role in caregiving than step up as equal partners in parenting. Telling, that is, in that it shows how financial capitalism and patriarchy work together to dissuade men from doing "unprofitable" labor, like the work of care.
X post from AI industry insider Alvin Sng :

My wife: Can you read our baby a book?
Me: I can just play an audiobook from my phone.
My wife: But then it won't be in your voice.
Me: I can train a voice model.
Parenting hits different when you work in Al.
34346941172
Layer 8½ @layer8-half.mu.social · 1h
inspect TLS traffic in 2026 so I'm not convinced, technology will safe us here.
000
Layer 8½ @layer8-half.mu.social · 1h
While everyone panics over Agentic Botswarms of Pwn and such, this thing here scares me. Well, not the this thing specifically, but malicious innovation and commoditization. Sure, there are technical solutions against BitM attacks, but I know of companies that don't care for their firewalls to
100
Reposted by Layer 8½
James Wilson @jameswilson.io · 9h
Unprecedented number of bug fixes in a patch = bad release management. It's the favourite metric of vulnpocalypse but it missed the point entirely. This is my latest solo pod for Risky Business Features. 🎧 risky.biz/RBFEATURES41/
risky.biz
Bug count sounds impressive... but means little - Risky Business Media
In this solo Risky Business Features episode, James Wilson explains why “number of bugs” fixed in any given update is a misleading metric. [Read More]
011
Layer 8½ @layer8-half.mu.social · 4h
Good.
000
Reposted by Layer 8½
Sifa ID @sifa.id · 10h
DON'T scan your face (or ID card) for ANY non-government online service.
Proton post:

DON'T scan your face for Roblox.
DON'T scan your face for Discord.
DON'T scan your face for Twitter.
DON'T scan your face for YouTube.
DON'T scan your face for Instagram.
DON'T scan your face for Reddit.
DON'T scan your face for Spotify.
DON'T scan your face for Twitch.
3348
Reposted by Layer 8½
IFIN @ifin-intel.org · 11h
I'm tired, boss. A new #Citrix CVE affecting SAML IdP/SP-configured devices is out. ifin.network/t/cve-2... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
CVE-2026-107406: Somehow, Another Citrix Netscaler SAML Vulnerability
Last Updated: 2026-10-08T21:02:44Z (UTC) What’s Happening Another critical vulnerability in Citrix Netscaler ADCs/Gateways has been published. This CVSS4 9.5 issue is a memory overflow leading to either denial-of-service or remote code execution. No evidence of exploitation is yet public, per Citrix’s advisory. They have published an accompanying blog post with little additional information. Affected Versions and Preconditions Broadly, the vulnerability affects devices configured as SAML...
273
Layer 8½ @layer8-half.mu.social · 11h
Allright, just a subset of PKC. Yes, bad enough. We'll have full IPv6 coverage before upgrading to up-for-the-job crypto. But we don't have to exchange AES keys via messengers on horseback. So that's good.
000
Reposted by Layer 8½
Microsoft Threat Intelligence @threatintel.microsoft.com · 11h
Post-quantum cryptography readiness goes beyond protecting encrypted data. Authentication systems must evolve, too, and organizations should start preparing now. msft.it/63322aUwiY
msft.it
Post-quantum authentication: Why organizations should start testing certificate ecosystems now | Microsoft Security Blog
Prepare for post-quantum authentication by testing certificate ecosystems now. Learn how Microsoft’s PQC TLS Pilot Program helps advance future readiness.
142
Reposted by Layer 8½
AlexSa @netalexx.bsky.social · 11h
A Single POST Freezes Any Next.js Server
simonkoeck.com
CVE-2026-23870: A Single POST Freezes Any Next.js Server | Simon Koeck
To rebuild one submitted form, React scanned every field in the request once for each reference it contained. Nothing capped either number, so one 900 KB POST makes the server do 100 million checks an...
011
Layer 8½ @layer8-half.mu.social · 13h
Wait, what? To be clear: Not RSA etc but generally asymmetric crypto? Like ML-KEM? But I mean, who even is this Matthew Green? Oh… Oh no.
121
Reposted by Layer 8½
Bailey Townsend 🦀 @pds.dad · 14h
Curious as I think on this more. Did you know what atproto was when you joined Bluesky? I personally did not, I had heard it was maybe open source and a different micro blogging experience that was also familiar.
43734
Layer 8½ @layer8-half.mu.social · 13h
So, I didn't know the protocol when joining. I gradually learned about it and still do. I here for it, though.
010
Layer 8½ @layer8-half.mu.social · 13h
I just wanted away from Elons Twitter. I learbed about the protocol only when @jay.bsky.team spoke about 'billionaire proof social media'. Then someone explained PDSs somewhere in the comments. Better understanding then came with @standard.site and related explanations of lexicons.
120
Reposted by Layer 8½
Lilith Wittmann @lilithwittmann.bsky.social · 17h
Wenn ich richtig gezählt habe, ist das der 4. Datenschutzvorfall bei nius seit Anfang 2025. Diesmal mutmaßlich mit allen Userdaten und dem ganzen Redaktionssystem. Hat es so in Deutschland so auch noch nicht gegeben. correctiv.org/aktuelles/da...
correctiv.org
Daten-Leak bei Nius – Nutzerdaten, Finanzen und Redaktionssystem liegen ungeschützt im Netz
Neues Daten-Leck bei Nius: Einsehbar sind Adressen von Lesern, Zahlen zu Abo-Einnahmen und umfassende Auszüge aus dem Redaktionssystem.
16310109
Reposted by Layer 8½
Taggart @taggart-tech.com · 18h
It's finally done. My rewrite of Python for Defenders for 2026 is live! taggartinstitute.org... If you want to learn Python the way cybersecurity professionals should, this is the course for you. And oh yeah, #NoAI was used or is recommended.
taggartinstitute.org
Course Catalog
Python For Defenders The Bad Guys Code. So Should You. Updated for 2026! Adding Python programming to your defensive skillset makes you a formidable adversary. Whether it’s vastly increasing the efficiency of common procedures, or adding new capabilities to the entire team, Python in Jupyter Notebooks completely transforms what’s possible for a security operations team. Become the defender who can use use these skills to your advantage. This course is separated into two parts. Part 1 explo...
194
Reposted by Layer 8½
Byron Tau @byrontau.bsky.social · 19h
"Freedom from persistent, dragnet-style surveillance while in public…is a reasonable expectation," a federal judge finds in weighing whether license plate readers constitute a search under the Fourth Amendment. reason.com/2026/10/07/j...
reason.com
Judge says warrantless Flock search violated driver's Fourth Amendment rights
This is the second federal court decision in a little over a week to suggest that driver surveillance systems can go too far.
25526
Reposted by Layer 8½
Bob Lord @boblord.bsky.social · 21h
Manufacturers vs. Operators: We never confuse an automaker with the driver. Drivers have real duties: maintenance, speed limits, seat belts. Designing out a defect is not one of them, and when a defect injures the driver, the automaker answers for it.
Poker sized card titled "Manufacturers vs. Operators" containing the text in the post.
182
Reposted by Layer 8½
Layer 8½ @layer8-half.mu.social · 08/10/2026
Babe, wake up! A new term for security awareness just dropped! Anyway: 𝗛𝗮𝗽𝗽𝘆 𝗦𝗲𝗰𝘂𝗿𝗲 𝗕𝗲𝗵𝗮𝘃𝗶𝗼𝗿 𝗠𝗮𝗻𝗮𝗴𝗲𝗺𝗲𝗻𝘁 𝗠𝗼𝗻𝘁𝗵 to evetyone who celebrates 🎉🎉🎉 (according to Gartner apparently) 🧵1/3
101
Layer 8½ @layer8-half.mu.social · 22h
Shoutout @ewo.name
000
Layer 8½ @layer8-half.mu.social · 22h
They Talk Tech – mit Eckert und Wolfangel: Voice Phishing und das Problem sitzt nicht vorm Rechner - mit Prof. Angela Sasse Was für ein großartiges Plädoyer für menschzentrierte IT. Bin ja immer froh, wenn ich mir das nicht selber ausdenken muss, sondern es echte Fachleute wie Angela Sasse gibt.
frauen-technik.podigee.io
Voice Phishing und das Problem sitzt nicht vorm Rechner - mit Prof. Angela Sasse
„Hallo, hier die IT, wir migrieren gerade den Login." Ein Anruf auf Niederländisch, eine nachgebaute Anmeldeseite, ein Callcenter-Account. Mehr brauchte es nicht, um beim Telekom-Anbieter Odido die Daten von über sechs Millionen Menschen abzuziehen. Kein Deepfake, keine KI - Svea erzählt, wie ShinyHunters vorgehen, warum die niederländische Polizei den Anruf im Fernsehen abspielte und was das FBI damit zu tun hat. Danach Angela Sasse, Professorin für Human-Centred Security in Bochum. 1999 schrieb sie „Users are not the enemy", bis heute einer der meistzitierten Texte des Fachs. Ihre These: Awareness-Training ist meist das Billigste, nicht das Wirksamste. Warum Passwörter ein Relikt sind, was Passkeys besser machen und wieso Eva selbst auf eine Test-Phishing-Mail geklickt hat. Mit Svea Eckert und Eva Wolfangel Musik und Produktion: Marko Pauli Odido-Hack: Mehr als sechs Millionen Betroffene (TechCrunch): https://techcrunch.com/2026/02/13/dutch-phone-giant-odido-says-millions-of-customers-affected-by-data-breach/ Die Polizei spielt die Stimme des Anrufers im Fernsehen ab (NOS): https://nos.nl/l/2622288 Zack Whittaker: Fear the phone call, die großen Vishing-Fälle der letzten Monate: https://this.weekinsecurity.com/fear-the-phone-call-hackers-are-calling-for-your-personal-data/ Der Angriff auf das FBI-Bewerbungsportal (Help Net Security): https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/ Angela Sasse an der Ruhr-Universität Bochum: https://casa.rub.de/en/news/casa/news/angela-sasse-is-considered-a-pioneer-of-usable-security Adams und Sasse (1999): Users Are Not the Enemy: https://doi.org/10.1145/322796.322806 Selling Satisfaction, die Studie zu den Versprechen der Awareness-Anbieter: https://doi.org/10.1145/3658644.3690196 Passkeys und FIDO2, erklärt: https://fidoalliance.org/passkeys/ Law4school, das Webinar-Programm von Gesa von Schwerin: https://www.law4school.de
100
Reposted by Layer 8½
Kevin Beaumont @doublepulsar.com · 23h
If you enjoy me ranting about ransomware cyberplace.social/@GossiTheDog...
cyberplace.social
Kevin Beaumont (@GossiTheDog@cyberplace.social)
I dunno if people remember the ransomware economy thread I had on Twitter years ago, but one of the things I covered is all the “ransomware recovery” vendors who secretly pay ransomware groups and pre...
1274
Layer 8½ @layer8-half.mu.social · 08/10/2026
connecting the different teams involved, creating pesonal feedback channels. Of course: This doesn't scale. But the whole thing depends more on the will and drive of organisation leadership than on technological solutions.
000
Layer 8½ @layer8-half.mu.social · 08/10/2026
I still remain on the position: People before platforms. E.g. Hannah Hardee had an interesting story about building the security awareness program at Southwest Airlines and the driving factor for success was more the genuine interest and care for people plus management support and
sans.org
Building Security Culture at Southwest Airlines | SANS Institute
The role of the security awareness professional is shifting. It's no longer enough to educate people on security, the real work is learning to understand people, and using that understanding to change how they think and behave.
100
Layer 8½ @layer8-half.mu.social · 08/10/2026
I do like the blog by @cybsafe.bsky.social on that topic. They generally do sone good work on the argument side. Still have to look into their products; those at least sound promising.
cybsafe.com
Shifting sands: The move from HRM to secure behaviour management – CybSafe blog
Gartner's secure behaviour management (SBM) vs Forrester's human risk management (HRM): what's changed, where they differ, and what to do next.
100
Layer 8½ @layer8-half.mu.social · 08/10/2026
Of course, nothing goes w/out AI here. Good luck on your EU AI Act compliance. 🧵3/3
100
Layer 8½ @layer8-half.mu.social · 08/10/2026
Source: 🧵2/3
gartner.com
Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management
Gartner Research on Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management
100
Layer 8½ @layer8-half.mu.social · 08/10/2026
Babe, wake up! A new term for security awareness just dropped! Anyway: 𝗛𝗮𝗽𝗽𝘆 𝗦𝗲𝗰𝘂𝗿𝗲 𝗕𝗲𝗵𝗮𝘃𝗶𝗼𝗿 𝗠𝗮𝗻𝗮𝗴𝗲𝗺𝗲𝗻𝘁 𝗠𝗼𝗻𝘁𝗵 to evetyone who celebrates 🎉🎉🎉 (according to Gartner apparently) 🧵1/3
101
Reposted by Layer 8½
Bundesamt für Sicherheit in der Informationstechnik (BSI) @bsi.bund.de · 08/10/2026
🤖 KI macht Phishing-Mails persönlicher, imitiert Stimmen täuschend echt und automatisiert Angriffe. Ergreift entsprechende Schutzmaßnahmen – unser neues Handout hilft euch dabei. ⬇️ www.bsi.bund.de/dok/1209436 #CybernationDeutschland #Cybernation
Abstraktes Bild eines Schutzschildes in welchem der Text "AI" für Artifical Intelligence steht. Darüber blauer Kreis mit dem Statement "KI-verstärkte Cyberangriffe werden zum Alltag" und der Frage "Wüsste euer Team, wie es reagieren würde?"Eine Textkachel auf der das Szenario skizziert wird, wie ein Cyberangriff anhand einer Phishing-Mail mit KI-Unterstützung erfolgtEine Textkachel auf der das Szenario skizziert wird, wie ein Cyberangriff anhand eines Deepfakes mit KI-Unterstützung erfolgt, wodurch erfolgreich Geld erpresst wird. Hinweis auf das neue Handout mit Selbsttest & Checklisten für KMU.
043
Reposted by Layer 8½
Manuel 'HonkHase' Atug @honkhase.de · 08/10/2026
Der lange Weg zur Cyber-Sicherheit "Sind deutsche Unternehmen zurzeit denn ausreichend auf diese Bedrohungslage vorbereitet? "Nein", schrieb Manuel Atug, Gründer und Sprecher der AG KRITIS (Kritische Infrastrukturen)..." www.dw.com/de/der-lange...
dw.com
KI: Cybersicherheit in Kriegszeiten
Digitale Attacken auf Wirtschaft und kritische Infrastruktur nehmen zu. Dazu kommt: KI-Programme hacken jetzt auch - und zwar selbsttätig. Kann man sich davor schützen? Eines jedenfalls ist sicher: Da...
16020
Reposted by Layer 8½
Layer 8½ @layer8-half.mu.social · 07/10/2026
This might be interesting for #infosec community to get some insights w/out all the bots (none of the respective feeds are usable anymore). Maybe a separate one for #CTI. Would this be of interest?
011
Layer 8½ @layer8-half.mu.social · 07/10/2026
This might be interesting for #infosec community to get some insights w/out all the bots (none of the respective feeds are usable anymore). Maybe a separate one for #CTI. Would this be of interest?
011
Reposted by Layer 8½
Ricardo J. Méndez @ricardo.bsky.social · 07/10/2026
Enjoy it while it lasts, folks — in a few weeks this sort of replacement is likely to be a supermassive vector for undercover malware that's going to dwarf all the Kazaa-hosted cracked Windows apps put together.
0151
Reposted by Layer 8½
Mathew J Schwartz @mathewjschwartz.bsky.social · 07/10/2026
Denmark braces for wave of phishing attacks after attackers steal data for nearly 9 million Danes from the Central Register of Persons www.databreachtoday.com/denmark-brac...
databreachtoday.com
Denmark Braces for Wave of Phishing Attacks
Denmark's residents have been hit by a data breach affecting the country's Central Register of Persons, exposing names, addresses, CPR numbers and other details of
042
Reposted by Layer 8½
Zack Whittaker @zackwhittaker.com · 07/10/2026
A Reddit thread of IT/security people saying execs. are hyping up AI but failing to do the security basics: "Management was literally drooling over the shiny global threat map dashboard. Menwhile I’m sitting there biting my tongue because we still don't even have a functioning asset inventory."
reddit.com
From the cybersecurity community on Reddit
Explore this post and more from the cybersecurity community
0518
Reposted by Layer 8½
Blacksky Algorithms @blackskyweb.xyz · 07/10/2026
Introducing Discussions - a new way to have conversations on Blacksky 🗣️ Now you can create a dynamic poll right from the post composer in the app to ask questions, get feedback, or to build community around any and every topic you find interesting.
Discussion example: Who was the villain in The Wire?
121575
Layer 8½ @layer8-half.mu.social · 07/10/2026
Ja klar, nur setzt das voraus, dass tatsächlich Binaries dekompiliert wurden und nicht einfach Oberflächen und Funktionen nachgebaut wurden. Keine Ahnung, was da tatsächlich hinter steckt.
020
Reposted by Layer 8½
Pete Millspaugh @petemillspaugh.com · 07/10/2026
Today is ICANN Reveal Day! 1,615 strings: .agent, .api, .agi, .ask, .auth, .bad, .bro, ... 481 applicants: Google, Amazon, Meta, Microsoft, OpenAI, Anthropic, Cloudflare, Vercel, Squarespace, Airbnb, ... Gonna thread observations until I run out of steam
916727
Layer 8½ @layer8-half.mu.social · 07/10/2026
Depends on your job probably 😅
030
Layer 8½ @layer8-half.mu.social · 07/10/2026
Hab das nur am Rande überflogen. Gab aber, glaube ich, erhebliche Zweifel an den Funktionen jenseits der reinen Oberfläche. Oder waren das nur die üblichen Zweifler; weißt du da mehr?
110
Reposted by Layer 8½
Ransomware.live @ransomware.live · 07/10/2026
According to Ransomware.live, Panzer ransomware group has added University of Rostock (🇩🇪) to its victims.
021
Reposted by Layer 8½
Skywalker @skywalker.thereforeiam.eu · 07/10/2026
v4.46 is out! * Create and edit starter packs * Follow all button on starter packs * Option to opt-out from a starter pack * Search starter packs * Show thread post index and counts in feeds * Translate link on posts in foreign language * Added Noto Sans Symbols to the font 🧵1/13
play.google.com
Skywalker - Apps op Google Play
App om op ATProto gebaseerde sociale medianetwerken te verkennen, b.v. Blauwe lucht
2135
Reposted by Layer 8½
Lauren Zabierek @lzxdc.bsky.social · 07/10/2026
032
Layer 8½ @layer8-half.mu.social · 07/10/2026
*taptaptap* is this thing on?
rpg.actor pixelart sprite of bearded person in blue pants grey tshir with a white mug and a microphone in hands
240
Reposted by Layer 8½
Guido X Jansen @gui.do · 07/10/2026
Say it with me one more time! #INTEROP #INTEROP #INTEROP
0213
Reposted by Layer 8½
Kevin Beaumont @doublepulsar.com · 07/10/2026
That guy is a fucking idiot of the highest order, and I have no idea why media organisations platformed him like that. He has absolutely no fucking idea what he is talking about. It’s similar with the Anthropic CEO going on about AI botnets crashing the internet. He has no idea what he is on about.
71069