Sign in

LMG Security

@lmgsecurity.bsky.social
28 followers 3 following 104 posts

LMG Security is a top cybersecurity firm providing penetration testing, advisory services, training, & more. Our experts speak at conferences like Black Hat and RSA, and have been featured in The Wall Street Journal, The New York Times, & many other pubs.

PostsRepliesMedia
LMG Security @lmgsecurity.bsky.social · 31/12/2025
A #penetrationtest doesn’t reduce risk if the findings never get fixed. In #breach investigations, we routinely see the same vulnerabilities attackers exploited sitting in old #pentest reports that were marked “accepted” or forgotten. Watch for more: www.youtube.com/watch?v=8Iscx--Spjk
000
LMG Security @lmgsecurity.bsky.social · 30/12/2025
Fake employees and contractors are forcing orgs to rethink #vendorvetting, hiring security, & identity controls. In today's #CybersideChats episode, we unpack Amazon’s recent incident in which a North Korean IT worker was detected through behavioral anomalies & what to do now. youtu.be/WE8p9I3uUuA
000
LMG Security @lmgsecurity.bsky.social · 29/12/2025
Most organizations treat #cloud outages as a rare inconvenience, but #hyperscalers have become #criticalinfrastructure. Watch our video for why cloud monoculture is dangerous and what a realistic diversification and failover strategy should look like. www.youtube.com/watch?v=PoK8MWGhzWA
000
LMG Security @lmgsecurity.bsky.social · 29/12/2025
Russian state-sponsored hackers linked to the #GRU have been targeting Western critical infrastructure for years, not with flashy zero-days, but by abusing misconfigured network edge devices to harvest credentials and persist inside victim systems. aws.amazon.com/blogs/securi... #Cybersecurity
aws.amazon.com
Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure | Amazon Web Services
As we conclude 2025, Amazon Threat Intelligence is sharing insights about a years-long Russian state-sponsored campaign that represents a significant evolution in critical infrastructure targeting: a ...
000
LMG Security @lmgsecurity.bsky.social · 24/12/2025
In 2026, audit where trust triggers action, not just where users log in. Our blog shares a practical look at why #identity must become a shared, continuous process — not a one-time check. Read it here: www.lmgsecurity.com/ai-broke-trust-… #cybersecurity
lmgsecurity.com
AI Broke Trust: Why Identity Has to Step Up in 2026 | LMG Security
AI didn’t just make cyberattacks smarter—it shattered the trust models security teams rely on. Learn why identity, mutual authentication, and phishing-resistant MFA must step up in 2026 as attackers exploit voice, chat, and internal workflows.
000
LMG Security @lmgsecurity.bsky.social · 23/12/2025
Many orgs still check identity once at login. Today on #CybersideChats, learn how #AI driven impersonation has made that model unsafe, and why #authentication has to extend into calls, chats, approvals, & support workflows Video: youtu.be/J0UJSV6wYlI Podcast: www.chatcyberside.com/e/when-ai-st...
000
LMG Security @lmgsecurity.bsky.social · 22/12/2025
The #holidays are in full swing, and the attackers (and #evilAI tools) have been busy. In this 2-minute video, we show what happened when our team asked #WormGPT, a dark-web #AI with no guardrails, to generate a #holiday scam. www.youtube.com/watch?v=YCS7... #Cybersecurity #Infosec #Phishing
youtube.com
WormGPT Can Build a Holiday Scam in 30 Seconds
YouTube video by LMG Security
000
LMG Security @lmgsecurity.bsky.social · 19/12/2025
Collaboration tools like Teams, Slack, and Zoom have become prime targets for attackers—and Microsoft’s latest roadmap reflects that shift. If your #security strategy hasn’t caught up with how people actually communicate, this #CybersideChats is worth a listen: www.chatcyberside.com/e/collaborat...
000
LMG Security @lmgsecurity.bsky.social · 18/12/2025
Microsoft’s 2026 #security features highlight a shift many organizations are already experiencing: #collaboration platforms and #identity workflows are now prime attack paths. MOre on our blog: www.lmgsecurity.com/5-new-ish-micro…
lmgsecurity.com
5 New-ish Microsoft Security Features & What They Reveal About Today’s Threats | LMG Security
Microsoft’s new security features for 2026 reveal today’s real attack paths—collaboration tools, identity gaps, and AI-driven exposure. Here's what to do next.
000
LMG Security @lmgsecurity.bsky.social · 17/12/2025
A single #cloud outage can disrupt every core system you depend on, which is why #digitalresilience has to extend beyond traditional #businesscontinuity planning. In this quick video, we outline 5 steps every #CISO should prioritize: www.youtube.com/watch?v=-fgy... #CloudSecurity #RiskManagement
youtube.com
How to Build True Digital Resilience: 5 Steps Every CISO Should Take
YouTube video by LMG Security
000
LMG Security @lmgsecurity.bsky.social · 16/12/2025
What do Microsoft’s 2026 #security features tell us about how attackers are breaching #collaboration platforms? On this week’s #CybersideChats, Sherri & Matt break down the updates & why they matter. Video: www.youtube.com/watch?v=60bY... Podcast: www.chatcyberside.com/e/collaborat...
000
LMG Security @lmgsecurity.bsky.social · 15/12/2025
Start 2026 with one upgrade that pays off immediately: tighten #identityverification. Join Sherri & Matt live on 12/17 as they break down how #AI driven impersonation is changing the rules: www.lmgsecurity.com/event/cyberside…
lmgsecurity.com
Cyberside Chats: Live! AI Broke Trust. Identity Has to Step Up in 2026. | LMG Security
000
LMG Security @lmgsecurity.bsky.social · 11/12/2025
Think #browserextensions are harmless? Think again. A multi-year campaign turned popular, trusted browser add-ons into #spyware featuring #remotecodeexecution, session hijacking, and more. Read the blog here: www.lmgsecurity.com/4-3-million-rea…
lmgsecurity.com
4.3 Million Reasons to Rethink Browser Extension Security | LMG Security
ShadyPanda hijacked 4.3M browsers through trusted extensions. See how the attack worked and the steps your team needs to take to close this overlooked supply-chain gap.
000
LMG Security @lmgsecurity.bsky.social · 10/12/2025
#AI can spoof your people, processes, and communications. In the next #CybersideChats: Live, Sherri & Matt break down the #identity upgrades every org needs for 2026. Register to join us on 12/17: www.lmgsecurity.com/event/cyberside…
lmgsecurity.com
Cyberside Chats: Live! AI Broke Trust. Identity Has to Step Up in 2026. | LMG Security
000
LMG Security @lmgsecurity.bsky.social · 09/12/2025
More than 4.3 million users were affected before anyone realized ShadyPanda’s extensions had turned into surveillance tools. Listen to today's #CybersideChats for more: www.chatcyberside.com/e/shady-pand... Or watch the video: youtu.be/x9AaE94KanM #Security #SessionHijacking #Cybersecurity
020
LMG Security @lmgsecurity.bsky.social · 08/12/2025
Spot the #scam! In Sherri Davidoff’s recent NBC Montana and Clearwater Credit Union interview, she & Kyle Rholl explain how #AI driven #voicecloning is being used to impersonate friends and family—and why reacting under pressure is what scammers count on. Full story: nbcmontana.com/news/spot-th...
nbcmontana.com
Spot the Scam with Clearwater Credit Union: Cyber Security Scams
Welcome to this week’s Spot the Scam with our partner, Clearwater Credit Union. We have two special guests this week — Kyle Rholl, Senior Vice President of IT a
000
LMG Security @lmgsecurity.bsky.social · 05/12/2025
When #insider incidents can hit even the most #security focused companies, it forces every organization to reconsider how much “trust” is built into their workflows. More on our blog: www.lmgsecurity.com/betrayed-fro... or podcast: www.chatcyberside.com/e/when-secur... #insiderthreat #cybersecurity
020
LMG Security @lmgsecurity.bsky.social · 04/12/2025
Insider threats are rising fast. LMG analyzes the latest cases — CrowdStrike, DigitalMint, Tesla & more — and what organizations can do now to reduce #risk. Read: www.lmgsecurity.com/betrayed-from-w… #InsiderThreat #DataProtection #CompanyCulture
lmgsecurity.com
Betrayed From Within: The Modern Insider Attack | LMG Security
Insider threats are accelerating. See what’s behind the surge and the steps security leaders can take now to strengthen defenses from the inside out.
010
LMG Security @lmgsecurity.bsky.social · 03/12/2025
Recovery times are improving, and the rise of truly immutable #backups is a major reason why. Watch as we break down what “immutable” actually means, why it matters for #ransomware resilience, and how proactive planning accelerates recovery. www.youtube.com/watch?v=XgdP... #DataRecovery #BCDR
youtube.com
What “Immutable Backups” Really Mean & How It Speeds Ransomware Recovery
YouTube video by LMG Security
000
LMG Security @lmgsecurity.bsky.social · 02/12/2025
Insider threats aren’t theoretical anymore—they’re happening inside orgs just like yours. This week on #CybersideChats, we break down insider cases from #CrowdStrike, #DigitalMint, & others, and share strategies to reduce your org's risk. youtu.be/s7QW_BkkAvM #InsiderThreats #Cybersecurity
010
LMG Security @lmgsecurity.bsky.social · 28/11/2025
75% percent of #manufacturers are carrying critical OT #vulnerabilities, often buried inside proprietary equipment and aging software that keeps production moving but limits security options. Sherri Davidoff and Matt Durrin share more in this quick video: www.youtube.com/watch?v=cETaSkOb5kw
000
LMG Security @lmgsecurity.bsky.social · 27/11/2025
This Thanksgiving, we’re feeling grateful for the clients, partners, and colleagues who make our work meaningful all year long. Thank you for the conversations, the collaboration, and the chance to tackle big challenges together. Wishing everyone a happy and restful holiday.
000
LMG Security @lmgsecurity.bsky.social · 26/11/2025
Chinese-made #IoT devices are turning up with hidden radios, undocumented modems, and opaque update channels—and organizations need faster ways to assess the risk. More on our blog: www.lmgsecurity.com/made-in-china-h… #SupplyChainSecurity
lmgsecurity.com
Made in China—Hacked Everywhere? What Organizations Need to Know Now | LMG Security
The stories sound like something out of a cyber-thriller: a city tests a Chinese-made electric bus in a decommissioned mine to see if it can be remotely shut down. U.S. ports discover hidden cellular modems inside massive cargo cranes. A common hospital patient monitor reveals an undeclared backdoor that allows…
000
LMG Security @lmgsecurity.bsky.social · 25/11/2025
A single “smart” device can quietly tunnel out of your network. Today on #CybersideChats: real-world scenarios where hidden radios, #cloud paths, and offshore update servers slipped in through routine #hardware purchases. Listen: www.chatcyberside.com/e/chinas-hid... Watch: youtu.be/WYq6YTqanA4
000
LMG Security @lmgsecurity.bsky.social · 24/11/2025
#MFA alone isn’t enough if attackers can exploit fatigue prompts or weak fallback options. In this 1-minute video, we break down the most common gaps. www.youtube.com/watch?v=x290... #Cybersecurity #MultifactorAuthentication #2FA #Authentication #AccessControl #Credentials #SecurityBestPractices
youtube.com
MFA Reality Check: Are you Vulnerable to Fatigue & Fallback Abuse?
YouTube video by LMG Security
000
LMG Security @lmgsecurity.bsky.social · 21/11/2025
#Holiday season scams now hit businesses as hard as consumers. This checklist highlights practical steps #security teams can take now—from enforcing strong #MFA to tuning #botdetection rules & more: www.lmgsecurity.com/resources/ho... #Cybersecurity #FraudPrevention #DNSFiltering #BYOD #Phishing
000
LMG Security @lmgsecurity.bsky.social · 19/11/2025
Attackers are now using #maliciousAI to launch #holidayscams at scale. We just published a breakdown of this year’s AI-driven holiday #fraud surge—plus an actionable checklist: www.lmgsecurity.com/holiday-hackers…
lmgsecurity.com
Holiday Hackers: How AI Is Supercharging Seasonal Fraud—and What Your Organization Must Do Now | LMG Security
Holiday fraud is surging 520% this season, and consumer scams are becoming enterprise breaches. Find out how this happens, and download our checklist to reduce your organization’s risk.
000
LMG Security @lmgsecurity.bsky.social · 18/11/2025
#AI driven #fraud is hitting holiday shoppers at machine speed. Today on #CybersideChats, Sherri & Matt discuss how #phishing kits, prebuilt configs, and bot-driven takeovers enable #CredentialAbuse. Podcast: www.chatcyberside.com/e/holiday-ha... Video: youtu.be/TpMD5v5JUNc #Cybersecurity
021
LMG Security @lmgsecurity.bsky.social · 17/11/2025
When #security assessments leak, the fallout can eclipse the incident. In our latest #CybersideChats on the #Louvre heist, we dig into how exposed #audit findings fueled scrutiny. Listen to hear how a seven-minute #robbery turned into a reputational firestorm: www.chatcyberside.com/e/louvre-hei...
000
LMG Security @lmgsecurity.bsky.social · 14/11/2025
Your #network may be locked down—but what about the circuitry inside your devices? Join us on November 19th for Cyberside Chats: Live! on how #hardware choices and opaque sourcing can introduce #risk + steps to spot red flags. www.lmgsecurity.com/event/cyberside…
lmgsecurity.com
Cyberside Chats Live! Made in China — Hacked Everywhere?
000
LMG Security @lmgsecurity.bsky.social · 12/11/2025
Last week, LMG Security had the pleasure of speaking with the Las Vegas ISSA chapter! Matt Durrin led a thought-provoking session on “ #DeepFakes & AI: The New Frontier of #Cybercrime.” He explored how rapidly evolving #AI tools are transforming #SocialEngineering, fraud, and digital trust.
000
LMG Security @lmgsecurity.bsky.social · 11/11/2025
When the #Louvre was robbed, most people blamed the thieves. But leaked audit reports told a story of weak passwords, ignored warnings, & outdated systems. Hear more from Sherri & Matt on Cyberside Chats. Podcast: www.chatcyberside.com/e/louvre-hei... Video: youtu.be/3ErXdXv_bN8 #cybersecurity
000
LMG Security @lmgsecurity.bsky.social · 07/11/2025
The #CISA #AIS program delivered real-time, machine-readable threat intelligence across sectors. With participation disrupted, defense is at risk. In this video, we explain how AIS worked, why it mattered, and what your organization can do to stay protected post-AIS. www.youtube.com/watch?v=qFPC...
youtube.com
What Is The Automated Indicator Sharing Program (AIS) & Why Does It Matter?
YouTube video by LMG Security
000
LMG Security @lmgsecurity.bsky.social · 06/11/2025
A great #PenetrationTest doesn’t just find vulnerabilities—it shows how attackers could exploit them and exposes the gaps behind technical issues. That’s why #PenetrationTesting is our Top #Cybersecurity Control of Q4: www.lmgsecurity.com/top-control-of-…
lmgsecurity.com
Top Control of Q4 2025: Penetration Testing | LMG Security
Discover why LMG Security named Penetration Testing the Top Control of Q4 2025. Learn how real-world testing uncovers attack paths, strengthens defenses, and turns vulnerabilities into lasting resilience.
010
LMG Security @lmgsecurity.bsky.social · 05/11/2025
What can a jewel heist teach us about #cybersecurity? When Hank Green sat down with Sherri Davidoff to analyze the #Louvre theft, striking parallels between physical and digital breaches were revealed. youtu.be/NIGbQ9NHFEg?... #RiskManagement #IncidentResponse #InformationSecurity #DataProtection
youtu.be
The Genius of the Louvre Heist
YouTube video by Hank Green
011
LMG Security @lmgsecurity.bsky.social · 04/11/2025
Attackers are turning Google results into #malware delivery systems, using fake software installers and sponsored ads to plant backdoors inside organizations. Podcast: www.chatcyberside.com/e/search-res... Video: youtu.be/xKKA1ikoZ-4 #SEOpoisoning #Malvertising #Cybersecurity #Software #Phishing
020
LMG Security @lmgsecurity.bsky.social · 31/10/2025
What happens when you mix a high-stakes #cybersecurity #tabletopexercise with top-shelf whiskey? An unforgettable night. LMG Security & Constangy hosted an exclusive #AI Fraud Tabletop & Whiskey Tasting where guests tackled a live #IncidentResponse scenario. Thanks to everyone who joined us!
000
LMG Security @lmgsecurity.bsky.social · 30/10/2025
Hackers don’t need to email you anymore—they just need you to search. SEO poisoning & fake ads are spreading #malware and stealing credentials. Learn how to defend against the poisoned web: www.lmgsecurity.com/poisoned-search… #Phishing #AI
lmgsecurity.com
Poisoned Search: How Hackers Turn Google Results into Backdoors | LMG Security
Hackers are poisoning Google search results with fake ads and malware. We share the new malvertising attack trends and how to protect your organization.
000
LMG Security @lmgsecurity.bsky.social · 29/10/2025
We had a great time at #BSidesPDX connecting with the local security community! Matt Durrin took the stage to present “Hackers + #AI: Faster, Smarter, More Dangerous,” a demo showing how criminals are using tools like #WormGPT to uncover vulnerabilities, generate exploits, and weaponize zero-days.
000
LMG Security @lmgsecurity.bsky.social · 28/10/2025
When #AWS went offline, the outage exposed a global web of dependencies. Sherri & Matt explore what really happened, how fourth-party risks can undermine resilience, and practical steps to take on Cyberside Chats. Listen: www.chatcyberside.com/e/when-the-c... Watch: youtu.be/Djz-_VblMAw #cloud
010
LMG Security @lmgsecurity.bsky.social · 27/10/2025
When the #Cybersecurity Information Sharing Act lapsed, organizations lost a key federal threat feed. Watch this video to learn how to strengthen private intel networks, manage legal exposure, and integrate intel loss scenarios into your #IncidentResponse plans: www.youtube.com/watch?v=2JeB... #CISA
youtube.com
How to Protect Your Organization After the Loss of CISA Threat Intelligence Sharing
YouTube video by LMG Security
010
LMG Security @lmgsecurity.bsky.social · 24/10/2025
Diversity builds resilience — especially in the #cloud. Matt Durrin reminds us that spreading workloads across multiple clouds isn’t just a best practice, it’s a safeguard against systemic risk. More on our blog: www.lmgsecurity.com/beyond-aws-h... #AWS #DNS #CloudSecurity #FourthPartyRisk
020
LMG Security @lmgsecurity.bsky.social · 23/10/2025
The #AWS outage exposed a threat: #FourthPartyRisk. When your vendors’ vendors go down, so do you. Learn what the #outage revealed & how to strengthen your #cloud resilience before the next disruption: www.lmgsecurity.com/beyond-aws-how-…
lmgsecurity.com
Beyond AWS: How Hidden Fourth-Party Risks Threaten Digital Resilience | LMG Security
Discover how the October 2025 AWS outage exposed hidden fourth-party risks that threaten digital resilience across every industry. In this blog, LMG Security’s experts unpack how one faulty DNS update triggered a global ripple effect—and what your organization can do to identify and mitigate unseen dependencies in your cloud supply chain.
010
LMG Security @lmgsecurity.bsky.social · 22/10/2025
Attackers are exploiting search results and online ads to spread #malware through fake software installers—and it’s working. In our next Cyberside Chats: Live! on 10/29, we'll uncover the latest #SEOpoisoning & #malvertising techniques & how they evade defenses. www.lmgsecurity.com/event/cybers...
lmgsecurity.com
Cyberside Chats: Live! Poisoned Search: How Hackers Turn Google Results into Backdoors
In this episode, Sherri Davidoff and Matt Durrin break down the latest SEO poisoning and malvertising research, including the Oyster/Broomstick campaign that hid backdoors inside fake installers. Lear...
000
LMG Security @lmgsecurity.bsky.social · 21/10/2025
When #ransomware halted Jaguar Land Rover’s production, it disrupted entire supply chains. In our latest #CybersideChats, we discuss what made this attack so impactful and share insights on how to strengthen resilience. Podcast: www.chatcyberside.com/e/manufactur... Video: youtu.be/LTW59YBJe-Q
000
LMG Security @lmgsecurity.bsky.social · 20/10/2025
We had a great time at the @seckc.org meetup! Tom Pohl shared insights on Microsoft CA exploits, showing how small misconfigurations can lead to full domain admin takeover. Big thanks to SecKC for the welcome and for making cybersecurity even more fun with a Halloween twist. #Cybersecurity #SecKC
020
LMG Security @lmgsecurity.bsky.social · 16/10/2025
Why do some cybersecurity trainings work while others fall flat? The difference is engagement—it starts with the “why.” Read our blog for advice on how to make training resonate www.lmgsecurity.com/the-power-of-wh… #NCSAM #CybersecurityAwarenessMonth
lmgsecurity.com
The Power of Why: Making Cybersecurity Training Stick | LMG Security
Discover how to make cybersecurity training stick. Learn how storytelling, hands-on exercises, and relevance turn awareness into real security action.
000
LMG Security @lmgsecurity.bsky.social · 15/10/2025
#LawFirms face mounting #cyber risks — from phishing and ransomware to AI-driven social engineering. In the ALA's Legal Management Magazine, LMG’s Madison Iler explains why legal organizations are prime targets. Read the article: www.alanet.org/legal-manage... #cybersecurity #legalindustry
alanet.org
Understanding the Need for Cybersecurity in 2025
As cyberattacks increase in frequency across all industries, law firms need to pre-emptively prepare by creating internal safety measures.
000
LMG Security @lmgsecurity.bsky.social · 14/10/2025
Why does the “why” matter in #cybersecurity? Matt Durrin & Todd Stewart discuss how understanding and communicating purpose, not just process, improves engagement, retention, & impact. #podcast: www.chatcyberside.com/e/lead-with-... Video: www.youtube.com/watch?v=xMKi... #CybersecurityTraining
000
LMG Security @lmgsecurity.bsky.social · 13/10/2025
Attackers are poisoning Google search results and ads to spread #malware disguised as trusted software. Join us for a live Cyberside Chats on October 29th for the latest SEO poisoning and #malvertising tactics and steps to keep your organization safe. Register: www.lmgsecurity.com/event/cybers...
lmgsecurity.com
Cyberside Chats: Live! Poisoned Search: How Hackers Turn Google Results into Backdoors
In this episode, Sherri Davidoff and Matt Durrin break down the latest SEO poisoning and malvertising research, including the Oyster/Broomstick campaign that hid backdoors inside fake installers. Lear...
000