Sign in

Jennifer Wood

@notnextjen.bsky.social
317 followers 230 following 17 posts

Space geek, roaming gnome, comms @ runZero. Ex-USG: OMB, NASA, EPA, U.S. Senate. Formerly Luta Security, Kaspersky, Avast, BlackBerry, Microsoft/WE Comms. www.linkedin.com/in/jenniferjwood

PostsRepliesMedia
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 17h
From queries to clarity: Learn why runZero’s AI-assisted reporting changes the game. 🚀 Transform raw asset and exposure data into decision-ready intelligence in minutes with custom queries, seamless artifact exporting, and more. 👉 Read our blog for more details: www.runzero.com/blog/ai-assi...
011
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 21/09/2026
🚀 Exciting news: runZero is joining Dragos alongside NetRise! Together, we're advancing the shared mission of protecting critical systems and safeguarding civilization by delivering a unified platform to defend IT, OT, IoT, and cloud environments. 👉️ Details: www.dragos.com/press-releas...
042
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 18/06/2026
🚀 Big news: Accenture investing $4B— intends to acquire a majority stake in Dragos, Inc., and all of runZero and NetRise, to build an industry-transforming cybersecurity platform for OT/IT environments. 👏 Details at: www.runzero.com/newsroom/acc...
011
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 18/05/2026
🎉 New GigaOm Radar for OT Security positions runZero as a Challenger & Fast Mover! 🚩 Webinar: Join GigaOm's Chris Ray & runZero CEO HD Moore on May 28 @ 12PM ET as they discuss hardening converged network defenses & the #OT Radar findings. Webinar reg & report: www.runzero.com/gigaom-radar...
011
Reposted by Jennifer Wood
Sean Hollister @seanhollister.bsky.social · 11/05/2026
A million baby monitors and security cameras were left exposed. You might have one of these in your house and not even know — because this company's name isn't on the packaging. www.theverge.com/tech/926487/...
theverge.com
A million baby monitors and security cameras were easily viewable by hackers
They should be fixed now. Hopefully.
13711
Reposted by Jennifer Wood
Sam Sabin @samsabin.bsky.social · 04/05/2026
New on @axios.com: As part of meetings with tech/cyber cos. + tech trade groups last week, ONCD floated an AI security framework that was already in the works before Mythos. On the table: DoD red-teaming of AI deployments at the federa/state/local government levels. www.axios.com/2026/05/04/t...
axios.com
Trump administration considering safety review for new AI models
In a post-Mythos world, the White House is re-evaluating its hard line against the AI security measures it once shrugged off.
014
Jennifer Wood @notnextjen.bsky.social · 30/04/2026
Check out our latest release, 4.9! So many new capabilities for IT/OT converged environments. 👏 Plus, the visuals are not only informative, but also really cool (make sure to try out the 3D view). 🌎
010
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 27/04/2026
🔈 New podcast alert! CEO HD Moore discusses runZero's upcoming 4.9 release on Risky Business with Casey Ellis. Hear how we're tackling converged IT/OT network challenges! 🎧 Listen to the full interview to learn more: www.runzero.com/resources/ri... #OTsecurity
031
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 21/04/2026
If you missed last week’s runZero Hour with Caroline Wong, author of The AI Cybersecurity Handbook, here’s a peek at what you missed. Watch the full episode now for more AI insights, CVE program updates, AI trivia, and notable vulns from the month. Full episode: www.runzero.com/resources/ru...
011
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 20/04/2026
Recently back from VulnCon 2026, runZero's @todb.hugesuccess.org shares his insights on AI's dual role in vuln discovery & defense, CVE ecosystem updates, and a cautiously optimistic outlook for the future of vuln disclosure and remediation. Read his blog today! 👇️ www.runzero.com/blog/vulncon...
runzero.com
Dispatch from VulnCon: AI, CVEs, & cooperation
todb shares his key VulnCon 2026 takeaways, covers the rise of AI in vuln research, the role of CISA’s Vulnrichment, and the future of the CVE program.
032
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 14/04/2026
Are you attending the DoW MPE Summit in Ft. Lauderdale this week? Be sure to connect with our team onsite to learn how runZero provides a single source of truth for exposure management across the total attack surface—without the friction of agents. 👉️ More details: www.ncsi.com/event/mpe/ag...
011
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 21/03/2026
Need some downtime today during #BSidesSF 2026? Escape to the runZero sponsored Bar & Chill Out Space (inside) or Lounge (outside) from 9 AM-5:30 PM PT. Stop by, say hello, and snag some swag! 👉 Remember, two complimentary drink tickets were provided at registration!
011
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 17/03/2026
Tomorrow on the runZero Hour: Deep dive into OT retroencabulation Join @todb.hugesuccess.org, Rob King, & Ulises Fuentes Venado from GuidePoint Security for an in-depth discussion on the evolving security challenges facing OT. 📅 March 18 | 1 PM ET / 10 AM PT www.runzero.com/research/run...
021
Reposted by Jennifer Wood
Kevin Collier @kevincollier.bsky.social · 28/02/2026
One way to read the AI/Pentagon news from last night (I covered it but didn't skeet) is that the Department of Defense wants AI to automate weapons and/or spy on Americans and that Anthropic would have the best AI to do that, but OpenAI is at least the second-best so they'll just use that instead.
nbcnews.com
OpenAI strikes deal with Pentagon after Trump orders government to stop using Anthropic
On X, Defense Secretary Pete Hegseth said he had moved to label Anthropic as a "supply chain risk" and cancel Defense business with the company.
1113962
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 23/02/2026
If everything is a priority, nothing is. @todb.hugesuccess.org helped build CISA KEV and his new runZero research finally makes it actionable. He sat down with Casey Ellis on @riskybusiness to talk about what KEV actually is and how to use it right. 🎧 www.runzero.com/resources/ri...
032
Reposted by Jennifer Wood
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 11/02/2026
NEW: U.S. prosecutors say the hacking tools that Peter "Doogie" Williams stole from defense contractor L3Harris Trenchant could have been used against "millions of computers and devices" worldwide. Williams said he didn't know the tools could end up in the hands of Russia or other governments.
techcrunch.com
DOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunch
The former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am...
196
Reposted by Jennifer Wood
Zack Whittaker @zackwhittaker.com · 11/02/2026
Prosecutors have confirmed for the first time that Peter Williams, who ran L3Harris' Trenchant unit (which makes hacking tools for the U.S. govermment and its allies), sold the company's exploits to a Russian broker that were capable of accessing "millions of computers and devices" around the world.
techcrunch.com
DOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunch
The former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am...
22123
Reposted by Jennifer Wood
runZero (Official Account) @runzero.com · 05/02/2026
🚨 New report + tool: CISA KEV analysis by former Section Chief @todb.hugesuccess.org + KEV Collider to help prioritize real exploits over noise. 📄 Report: www.runzero.com/resources/ke... 🧪 Tool: www.runzero.com/kev-collider/ ✍️ Blog: www.runzero.com/blog/making-... Ready to make KEV actionable?
042
Reposted by Jennifer Wood
Raphael Satter @raphae.li · 04/02/2026
Joseph Menn has been writing about cybersecurity since well before most journalists even understood it as a beat. Big loss for the Post and its readers, but also for the industry and the wider public, who will be less informed - and less safe - as a result.
313945
Jennifer Wood @notnextjen.bsky.social · 04/02/2026
Why are pubs laying off talented journalists? We need reporters who understand security to continue covering it. It is disheartening to see this happening over and over again.
000
Jennifer Wood @notnextjen.bsky.social · 29/01/2026
Good stuff here, folks! When you have a few minutes, read the article and the research (links below). #LLMsecurity Story: www.reuters.com/technology/o... Research: www.sentinelone.com/labs/silent-...
reuters.com
Open-source AI models vulnerable to criminal misuse, researchers warn
Hackers and other criminals can easily commandeer computers operating open-source large language models outside the guardrails and constraints of the major artificial-intelligence platforms, creating ...
000
Reposted by Jennifer Wood
The Washington Post @washingtonpost.com · 27/01/2026
The Federal Aviation Administration ignored warnings about a dangerous level of air traffic at Reagan National Airport before the midair collision between a commercial jet and U.S. Army helicopter that took 67 lives, federal investigators said.
washingtonpost.com
FAA ignored warnings from controllers before DCA crash, federal investigators say
Families hope the nearly year-long probe by the National Transportation Safety Board will promote aviation safety changes.
45131
Reposted by Jennifer Wood
Jessica Lyons @jessicalyons.bsky.social · 23/01/2026
ShinyHunters has claimed responsibility for an Okta voice-phishing campaign during which the extortionist crew allegedly gained access to Crunchbase and Betterment.
theregister.com
ShinyHunters claims Okta customer breaches, leaks data
: 'A lot more' victims to come, we're told
021
Reposted by Jennifer Wood
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 23/01/2026
NEW: Microsoft handed the FBI the recovery keys to decrypt the hard drives of three laptops encrypted with BitLocker. BitLocker is enabled by default in modern Windows laptops, but Microsoft also prompts users to upload the recovery keys to the company's cloud, which opens up this possibility.
techcrunch.com
Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects' laptops: reports | TechCrunch
The FBI served Microsoft a warrant requesting encryption recovery keys to decrypt the hard drives of people involved in an alleged fraud case in Guam.
32422
Reposted by Jennifer Wood
Zack Whittaker @zackwhittaker.com · 22/01/2026
New, by me: Under Armour says it’s aware of data breach claims after 72M customer records were posted online. A spox. told me a "small percentage" of customers had sensitive information compromised but wouldn't say what it considers "sensitive," nor provide an accurate figure of affected customers.
techcrunch.com
Under Armour says it's 'aware' of data breach claims after 72M customer records were posted online | TechCrunch
TechCrunch obtained a sample of the stolen data, which contained names, email addresses, dates of birth, and the user's approximate geographic location. Under Armour confirmed some sensitive informati...
21711
Jennifer Wood @notnextjen.bsky.social · 22/01/2026
GPS attacks are increasing, relatively cheap to implement, spreading geographically, and present a significant threat to people's safety and the economy. If your org uses GPS data, it's time to update your threat models. Learn more: shostack.org/26-01
shostack.org
Threat Advisory: GPS Attacks [SA-26-01]
The dramatic increase in credible reports of GPS attacks, combined with geographic spread and the decreasing cost of hardware for the attack, indicate a change in the threat landscape. If your company...
001
Jennifer Wood @notnextjen.bsky.social · 18/09/2025
Today is the day…#LABScon2025 is live from Phoenix, AZ. Get ready for two days of unique research and excellent speakers.
000
Reposted by Jennifer Wood
Zack Whittaker @zackwhittaker.com · 07/08/2025
New: French phone giant Bouygues confirmed a data breach affects the personal information of 6.4 million customers. Bouygues disclosed the breach on a dedicated web page; however, the page is currently deliberately excluded from search engines using "noindex" code, making it more difficult to find.
techcrunch.com
Data breach at French telecom giant Bouygues affects millions of customers | TechCrunch
This is the latest cyberattack to hit a French cellular carrier in recent weeks, following an attack on Orange Telecom in July.
24219
Jennifer Wood @notnextjen.bsky.social · 07/08/2025
Enjoying the #threebuddyproblem podcast live from BH /Vegas!
110
Jennifer Wood @notnextjen.bsky.social · 04/08/2025
If all goes to plan, I’ll be in Vegas for #BlackHat this week. DM me if you would like to meet. See y’all soon and safe travels to all!
010
Reposted by Jennifer Wood
Microsoft Threat Intelligence @threatintel.microsoft.com · 22/07/2025
Update: Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. Customers should apply these updates immediately. Full guidance and detection details: msft.it/6010sDzSE.
23730
Jennifer Wood @notnextjen.bsky.social · 21/07/2025
Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers - www.securityweek.com/microsoft-pa...
securityweek.com
Microsoft Patches 'ToolShell' Zero-Days Exploited to Hack SharePoint Servers
Microsoft has started releasing updates to fix the exploited SharePoint zero-days tracked as CVE-2025-53770 and CVE-2025-53771.
000
Reposted by Jennifer Wood
Joseph Cox @josephcox.bsky.social · 21/07/2025
New from 404 Media: a startup is selling data hacked from peoples' computers to debt collectors, divorce lawyers, more. People already hacked, now being re-vicitmized by startup. I used the tool, found peoples' personal addresses. “This is so gross and predatory.” www.404media.co/a-startup-is...
404media.co
A Startup is Selling Data Hacked from Peoples’ Computers to Debt Collectors
Infostealer data can include passwords, email and billing addresses, and the embarrassing websites you use. Farnsworth Intelligence is selling to to divorce lawyers and other industries.
18756362
Jennifer Wood @notnextjen.bsky.social · 21/07/2025
No patch but here’s the suggested mitigations from MSFT: Configure Antimalware Scan Interface integration in SharePoint and deploy Defender AV on all SharePoint servers, and/or consider disconnecting your server from the internet until a security update is available. www.forbes.com/sites/daveyw...
forbes.com
Microsoft Confirms Ongoing Mass SharePoint Attack — No Patch Available
Microsoft has confirmed that SharePoint Server is under mass attack and no patch is yet available — here’s what you need to know and how to mitigate the threat.
000
Reposted by Jennifer Wood
Cynthia Brumfield @metacurity.com · 25/06/2025
A website developed for the UK Home Office's 2022 "flop" anti-encryption campaign has seemingly been hijacked to push a payday loan scheme. www.theregister.com/2025/06/25/h...
theregister.com
Home Office anti-encryption site pushes payday loan scheme
: Company at center of findings blamed SEO on outsourcer
078
Reposted by Jennifer Wood
Eric Geller @ericjgeller.com · 25/06/2025
Iran's APT42 (Charming Kitten) hacker team is now conducting targeted spearphishing attacks on high-profile Israeli national security journalists and cybersecurity researchers, according to Check Point. blog.checkpoint.com/security/edu...
0124
Jennifer Wood @notnextjen.bsky.social · 23/06/2025
After five incredible years at @lutasecurity.bsky.social I’ll be moving on at the end of the month and looking for a new senior communications leadership role within the cybersecurity industry. For more info about my background, please read: tinyurl.com/yeyw4xb6. Thanks!
tinyurl.com
Dear friends, former colleagues, and extended network: | Jennifer (Jen) Wood
Dear friends, former colleagues, and extended network: After nearly five incredible years at Luta Security, I’ll be moving on at the end of the month and looking for a new senior communications leade...
071
Jennifer Wood @notnextjen.bsky.social · 29/05/2025
www.securityweek.com/czech-govern...
securityweek.com
Czech Government Condemns Chinese Hack on Critical Infrastructure
The Czech government issues a blunt warning to China after APT31 hackers linked to intrusion at critical infrastructure network.
010
Jennifer Wood @notnextjen.bsky.social · 29/05/2025
www.theregister.com/2025/05/29/b...
theregister.com
Billions of session cookies for sale sparks security warning
: Law enforcement crackdowns are gathering pace but online marketplaces still teeming with valuable tokens
000
Jennifer Wood @notnextjen.bsky.social · 16/04/2025
Phew…CISA extends MITRE-backed CVE contract hours before its lapse www.nextgov.com/cybersecurit...
nextgov.com
CISA extends MITRE-backed CVE contract hours before its lapse
“Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services,” an agency spokesperson said.
010
Jennifer Wood @notnextjen.bsky.social · 16/04/2025
Uncle Sam abruptly turns off funding for CVE program. Yes, that CVE program - by @jessicalyons.bsky.social at @theregister.com www.theregister.com/AMP/2025/04/...
theregister.com
Uncle Sam abruptly turns off funding for CVE program. Yes, that CVE program
: Because vulnerability management has nothing to do with national security, right?
010
Reposted by Jennifer Wood
Luta Security @lutasecurity.bsky.social · 20/03/2025
#Cryptocurrency Exchanges—Do you need a security assessment? Do you need an audit for your #bugbounty program? Hire LutaSecurity—the only company led by a co-author of the international standards on vuln disclosure & handling processes. @lutasecurity.bsky.social www.lutasecurity.com/bug-bounty-s...
lutasecurity.com
Bug Bounty Solutions | Luta Security
Luta Security provides bug bounty program audits, offers end-to-end vulnerability case resolution management, creates new VDP and bug bounty programs, and performs security maturity assessments.
001
Reposted by Jennifer Wood
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 22/01/2025
NEW: The Trump admin has fired members of the Cyber Safety Review Board, a committee that was lauded for its investigation into Microsoft hacks of 2023, and was working on the recent Salt Typhoon telco hacks. One source called it a “horribly shortsighted” decision. techcrunch.com/2025/01/22/t...
techcrunch.com
Trump administration fires members of cybersecurity review board in “horribly shortsighted” decision | TechCrunch
The Department of Homeland security told members of the Cyber Safety Review Board that their membership was terminated.
32441225
Jennifer Wood @notnextjen.bsky.social · 18/01/2025
Back in DC. Not for political reasons. Still feels like home.
010
Jennifer Wood @notnextjen.bsky.social · 12/12/2024
Who's ready to sign up for @lutasecurity.bsky.social's Long Spoons Workforce Platform?
030