Reposted by Lindsey O’Donnell WelchDecipher @deciphersec.bsky.social · 29/06/2026There's a lot more to cybersecurity than just finding and fixing more and more bugs. @k8em0.bsky.social knows. 2125
Reposted by Lindsey O’Donnell WelchDecipher @deciphersec.bsky.social · 05/12/2025"Communications networks are large, complex, and they require significant measures to be taken to secure them. So without some sort of accountability regime, we don’t really know what they’re doing, how effective it is, or how widespread those measures will be.” decipher.sc/2025/12/04/g...decipher.scGovernment, Private Sector Officials Mull Telecom Security Woes - DecipherA year after Salt Typhoon's telecom hack, private and public sector officials discussed next steps. 022
Reposted by Lindsey O’Donnell WelchDecipher @deciphersec.bsky.social · 17/10/2025Why WarGames is Still Predicting the Future 40 Years Later decipher.sc/2025/10/17/w... #decipher #deciphersecdecipher.scWhy WarGames is Still Predicting the Future 40 Years Later - DecipherWarGames may be 42 years old but its prescience about our current technocracy and race to take humans out of the loop is as clear as ever 012
Reposted by Lindsey O’Donnell WelchDecipher @deciphersec.bsky.social · 12/09/2025Catch up on all the week's security news, including the NPM package compromises, the Wyden letter to the FTC, and the new Apple memory safety push, in our latest podcast episode. decipher.sc/videos/npm-p...decipher.scNPM Package Compromises, Sen. Wyden’s Ransomware Letter, and Apple’s Memory Safety AdvanceDennis and Lindsey discuss the targeted compromises of NPM packages (1:00) and the pointed letter that Sen. Ron Wyden sent to the FTC chairman asking for Mic... 002
Reposted by Lindsey O’Donnell WelchDecipher @deciphersec.bsky.social · 04/09/2025When we launched in 2018, the first piece on the site was part one of our four-part oral history of the L0pht. We were able to rescue that series from the archives. Here's that first part again. Enjoy! decipher.sc/2025/07/24/w...decipher.sc‘We Got to Be Cool About This‘: An Oral History of the LØpht, Part 1 - DecipherIn the beginning, there was a hat factory. Factory is probably too grand a word for it, but the space that would eventually become the first home of L0p... 054
Reposted by Lindsey O’Donnell WelchDecipher @deciphersec.bsky.social · 05/09/2025New pod! We talked through the Salesloft fallout, the potential for a long tail from the incident, and a new shared vision on SBOM from CISA, NSA, and many foreign gov cyber agencies. youtu.be/HCxV7Fsh7v0?...youtu.beThe Salesloft Drift Fallout and SBOM Guidance From CISA and NSAYouTube video by Decipher 022
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 05/09/2025So much of what was said here still rings true 10 years later 011
Reposted by Lindsey O’Donnell WelchDecipher @deciphersec.bsky.social · 04/09/2025“The federal judiciary has repeatedly proven itself incapable of protecting the highly sensitive and confidential information with which it has been entrusted." @wyden.senate.gov decipher.sc/2025/09/03/w...decipher.scWyden Slams Federal Judiciary After Court Hack - DecipherIn a scathing letter, Sen. Ron Wyden (D-Ore.) blasted the federal judiciary for its handling of a (second) hack of the federal courts’ case management system... 002
Reposted by Lindsey O’Donnell WelchDennis @dennisf.bsky.social · 02/09/2025365 days since our last podcast episode, me and @lindseyodwelch.bsky.social are back and so is @deciphersec.bsky.social! Join us! We have lots of cool stuff on the way. 145
Reposted by Lindsey O’Donnell WelchDecipher @deciphersec.bsky.social · 02/09/2025Hello friends! We're very excited to let you know.... WE ARE BACK! Our first video and podcast is live now, and our new site is live as well. Please have a look, share, and follow us wherever you find fine internet content! youtu.be/2cg7ljpvzdg?...youtu.beDecipher Lives!YouTube video by Decipher 142
Reposted by Lindsey O’Donnell WelchJ Wolfgang Goerlich @jwgoerlich.bsky.social · 25/06/2025Invisible until it breaks: The risk of cutting costs and undervaluing cybersecurity www.fastcompany.com/91352486/inv... 033
Reposted by Lindsey O’Donnell Welchevacide @evacide.bsky.social · 20/06/2025Government internet shutdowns are quite common to silence dissent, but I think this is the first time that a government has shut down the internet in its own country as a defensive measure against cyberattacks. 68317
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 17/06/2025I didn’t know the depths to which Twitter could go in it’s unhinged dumpster fire cesspool-ness, but it surpassed my expectations this month 100
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 17/06/2025First time getting warm+butter as a New Englander used to cold+mayo. It was eye opening 000
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 13/06/2025Everyone needs a cybersecurity guy 120
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 15/05/2025Missed this week's @huntress.com Tradecraft Tuesday episode on infostealers? You can catch up on YouTube⤵️ www.youtube.com/live/pzjzdeA...youtube.comTradecraft Tuesday | Infostealers: A Crash CourseYouTube video by Huntress 000
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 10/05/2025Post-exploitation activities observed stemming from the Samsung MagicINFO 9 Server flaw, in a nutshell: www.huntress.com/blog/post-ex... 111
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 07/05/2025🎉 May Tradecraft Tuesday 🎉 Excited to talk about infostealers next week with Greg Linares as part of the @huntress.com May Tradecraft Tuesday. 110
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 06/05/2025I’m a big believer that the worst of human nature comes out in two places: on social media and on roundabouts 030
Reposted by Lindsey O’Donnell WelchSwiftOnSecurity @swiftonsecurity.com · 23/04/2025You have unlocked visual derision Taylor 31046
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 23/04/2025Went to the #DBIR for the footnotes. Was not disappointed. 010
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 23/04/2025Some good takeaways from @huntress.com’s recent Tradecraft Tuesday ft. Patrick Wardle: -The impact of Apple bringing TCC events to Endpoint Security -#Mac malware persistence techniques vs BTM -Security alert inundation for #macOS users Catch up here⤵️ www.huntress.com/blog/say-hel...huntress.comSay Hello to Mac Malware | HuntressIn this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features. 023
Reposted by Lindsey O’Donnell WelchCynthia Brumfield @metacurity.com · 23/04/2025So a ransomware attack on the federal public defender's office in Phoenix has delayed the trial of Donald Day, Jr, who is accused of inciting the unprecedented fundamentalist Christian terrorist attack in Wieambilla, Australia, in 2022. www.azfamily.com/2025/04/23/t...azfamily.comTrial delayed after ransomware attack on public defender’s office in PhoenixAt least one trial has been delayed after a ransomware attack hit the federal public defender’s office in Phoenix, which provides counsel to defendants in federal court. 033
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 18/04/2025What’s the going rate for the tooth fairy these days? 000
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 05/04/2025Post-exploitation activity we found for *that* critical-severity CrushFTP flaw: -MeshAgent installs ➡️ non admin users to local administrators groups -AnyDesk RMM installs ➡️ credential harvesting -Telegram bot malware 🤖 022
Reposted by Lindsey O’Donnell WelchMatt Johansen @mattjay.com · 04/04/2025👀 woah... Google announces Sec-Gemini v1, a new experimental cybersecurity model security.googleblog....security.googleblog.com Google announces Sec-Gemini v1, a new experimental cybersecurity model Posted by Elie Burzstein and Marianna Tishchenko, Sec-Gemini team Today, we’re announcing Sec-Gemini v1, a new experimental AI model focused... 296
Reposted by Lindsey O’Donnell WelchThe Shadowserver Foundation @shadowserver.bsky.social · 27/03/2025For the last few days we are also scanning & reporting out exposed Ingress NGINX Controller for Kubernetes (Admission Controller feature). These may possibly be also vulnerable to CVE-2025-1974 & other recently disclosed vulnerabilities. We see around 4000 IPs exposed. 163
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 27/03/2025Parenthood is judging people for sending their kids to daycare with a cough, and then sending your kid to daycare with a cough the next day 010
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 16/03/2025Pi day was Friday and St. Patrick’s day is Monday… therefore I made Shepard’s Pie 020
Reposted by Lindsey O’Donnell WelchFahmida Y Rashid @fyrashid.bsky.social · 12/03/2025a cybersecurity bracket looking at red team tools? Count me in. 053
Reposted by Lindsey O’Donnell WelchBishop Fox @bishopfox.bsky.social · 12/03/2025🚨 The 2025 Ultimate Red Team Tool Showdown is here! 🚨 We’re putting the top offensive security tools head-to-head, but only ONE will take the crown. And it’s all up to YOU! Check out the full bracket & cast your votes: bishopfox.com/redteam-tool... 002
Reposted by Lindsey O’Donnell WelchAndy Greenberg @agreenberg.bsky.social · 06/03/2025Garantex, a major Russian cashout point for dirty cryptocurrency of all kinds in recent years, is currently down with a law enforcement seizure notice. 78720
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 28/02/2025The only good thing about Zero Day on Netflix is that I got to explain to my husband what a zero-day flaw is 010
Reposted by Lindsey O’Donnell WelchCatalin Cimpanu @campuscodi.risky.biz · 25/02/2025The FTC emailed almost 3.7 million Avast customers who bought the company's antivirus and are now entitled to refunds due to the company illegally selling their data. Claim it quick before Musk takes this FTC division down 🤣 www.ftc.gov/news-events/...ftc.govFTC Announces Refund Claims Process for Avast Customers Impacted by Deceptive Privacy ClaimsThe Federal Trade Commission is sending claim forms to consumers who bought deceptively marketed antivirus software from Avast. 03626
Reposted by Lindsey O’Donnell WelchDennis @dennisf.bsky.social · 25/02/2025Is this still gonna happen? www.fcc.gov/CyberTrustMarkfcc.govU.S. Cyber Trust Mark 001
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 25/02/2025Highly do not recommend running 13.1 miles after couch potato-ing for 3 months 010
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 24/02/2025New Englanders emerging from their homes when the weather reaches 40 degreesmedia.tenor.coma polar bear cub is laying in a pile of hayALT: a polar bear cub is laying in a pile of hay 010
Reposted by Lindsey O’Donnell Welchlodrina.bsky.social @lodrina.bsky.social · 21/02/2025Boston, whatcha up to March 1-2? 113
Reposted by Lindsey O’Donnell WelchMatt Johansen @mattjay.com · 20/02/2025Ai broke hiring. From chatgpt answer generators to North Korean spies. Gonna get worse before it gets better. youtu.be/oLnX9ZfzAv4?...youtu.beai broke hiring.YouTube video by Matt Johansen 042
Reposted by Lindsey O’Donnell WelchDennis @dennisf.bsky.social · 20/02/2025Decipher forever and ever 041
Reposted by Lindsey O’Donnell WelchBeau Woods @beauwoods.com · 20/02/2025One year on, what systemic fixes have been undertaken by whom. - Last I heard, most industry groups are cool with things as is - HHS seemed like they might try to step up, but didn't - CISA went quiet on helping healthcare after the COVID Task Force was disbanded - A few Congressional proposals 023