Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 17hFrom queries to clarity: Learn why runZero’s AI-assisted reporting changes the game. 🚀 Transform raw asset and exposure data into decision-ready intelligence in minutes with custom queries, seamless artifact exporting, and more. 👉 Read our blog for more details: www.runzero.com/blog/ai-assi... 011
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 21/09/2026🚀 Exciting news: runZero is joining Dragos alongside NetRise! Together, we're advancing the shared mission of protecting critical systems and safeguarding civilization by delivering a unified platform to defend IT, OT, IoT, and cloud environments. 👉️ Details: www.dragos.com/press-releas... 042
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 18/06/2026🚀 Big news: Accenture investing $4B— intends to acquire a majority stake in Dragos, Inc., and all of runZero and NetRise, to build an industry-transforming cybersecurity platform for OT/IT environments. 👏 Details at: www.runzero.com/newsroom/acc... 011
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 18/05/2026🎉 New GigaOm Radar for OT Security positions runZero as a Challenger & Fast Mover! 🚩 Webinar: Join GigaOm's Chris Ray & runZero CEO HD Moore on May 28 @ 12PM ET as they discuss hardening converged network defenses & the #OT Radar findings. Webinar reg & report: www.runzero.com/gigaom-radar... 011
Reposted by Jennifer WoodSean Hollister @seanhollister.bsky.social · 11/05/2026A million baby monitors and security cameras were left exposed. You might have one of these in your house and not even know — because this company's name isn't on the packaging. www.theverge.com/tech/926487/...theverge.comA million baby monitors and security cameras were easily viewable by hackersThey should be fixed now. Hopefully. 13711
Reposted by Jennifer WoodSam Sabin @samsabin.bsky.social · 04/05/2026New on @axios.com: As part of meetings with tech/cyber cos. + tech trade groups last week, ONCD floated an AI security framework that was already in the works before Mythos. On the table: DoD red-teaming of AI deployments at the federa/state/local government levels. www.axios.com/2026/05/04/t...axios.comTrump administration considering safety review for new AI modelsIn a post-Mythos world, the White House is re-evaluating its hard line against the AI security measures it once shrugged off. 014
Jennifer Wood @notnextjen.bsky.social · 30/04/2026Check out our latest release, 4.9! So many new capabilities for IT/OT converged environments. 👏 Plus, the visuals are not only informative, but also really cool (make sure to try out the 3D view). 🌎 010
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 27/04/2026🔈 New podcast alert! CEO HD Moore discusses runZero's upcoming 4.9 release on Risky Business with Casey Ellis. Hear how we're tackling converged IT/OT network challenges! 🎧 Listen to the full interview to learn more: www.runzero.com/resources/ri... #OTsecurity 031
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 21/04/2026If you missed last week’s runZero Hour with Caroline Wong, author of The AI Cybersecurity Handbook, here’s a peek at what you missed. Watch the full episode now for more AI insights, CVE program updates, AI trivia, and notable vulns from the month. Full episode: www.runzero.com/resources/ru... 011
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 20/04/2026Recently back from VulnCon 2026, runZero's @todb.hugesuccess.org shares his insights on AI's dual role in vuln discovery & defense, CVE ecosystem updates, and a cautiously optimistic outlook for the future of vuln disclosure and remediation. Read his blog today! 👇️ www.runzero.com/blog/vulncon...runzero.comDispatch from VulnCon: AI, CVEs, & cooperationtodb shares his key VulnCon 2026 takeaways, covers the rise of AI in vuln research, the role of CISA’s Vulnrichment, and the future of the CVE program. 032
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 14/04/2026Are you attending the DoW MPE Summit in Ft. Lauderdale this week? Be sure to connect with our team onsite to learn how runZero provides a single source of truth for exposure management across the total attack surface—without the friction of agents. 👉️ More details: www.ncsi.com/event/mpe/ag... 011
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 21/03/2026Need some downtime today during #BSidesSF 2026? Escape to the runZero sponsored Bar & Chill Out Space (inside) or Lounge (outside) from 9 AM-5:30 PM PT. Stop by, say hello, and snag some swag! 👉 Remember, two complimentary drink tickets were provided at registration! 011
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 17/03/2026Tomorrow on the runZero Hour: Deep dive into OT retroencabulation Join @todb.hugesuccess.org, Rob King, & Ulises Fuentes Venado from GuidePoint Security for an in-depth discussion on the evolving security challenges facing OT. 📅 March 18 | 1 PM ET / 10 AM PT www.runzero.com/research/run... 021
Reposted by Jennifer WoodKevin Collier @kevincollier.bsky.social · 28/02/2026One way to read the AI/Pentagon news from last night (I covered it but didn't skeet) is that the Department of Defense wants AI to automate weapons and/or spy on Americans and that Anthropic would have the best AI to do that, but OpenAI is at least the second-best so they'll just use that instead.nbcnews.comOpenAI strikes deal with Pentagon after Trump orders government to stop using AnthropicOn X, Defense Secretary Pete Hegseth said he had moved to label Anthropic as a "supply chain risk" and cancel Defense business with the company. 1113962
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 23/02/2026If everything is a priority, nothing is. @todb.hugesuccess.org helped build CISA KEV and his new runZero research finally makes it actionable. He sat down with Casey Ellis on @riskybusiness to talk about what KEV actually is and how to use it right. 🎧 www.runzero.com/resources/ri... 032
Reposted by Jennifer WoodLorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 11/02/2026NEW: U.S. prosecutors say the hacking tools that Peter "Doogie" Williams stole from defense contractor L3Harris Trenchant could have been used against "millions of computers and devices" worldwide. Williams said he didn't know the tools could end up in the hands of Russia or other governments.techcrunch.comDOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunchThe former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am... 196
Reposted by Jennifer WoodZack Whittaker @zackwhittaker.com · 11/02/2026Prosecutors have confirmed for the first time that Peter Williams, who ran L3Harris' Trenchant unit (which makes hacking tools for the U.S. govermment and its allies), sold the company's exploits to a Russian broker that were capable of accessing "millions of computers and devices" around the world.techcrunch.comDOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunchThe former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am... 22123
Reposted by Jennifer WoodrunZero (Official Account) @runzero.com · 05/02/2026🚨 New report + tool: CISA KEV analysis by former Section Chief @todb.hugesuccess.org + KEV Collider to help prioritize real exploits over noise. 📄 Report: www.runzero.com/resources/ke... 🧪 Tool: www.runzero.com/kev-collider/ ✍️ Blog: www.runzero.com/blog/making-... Ready to make KEV actionable? 042
Reposted by Jennifer WoodRaphael Satter @raphae.li · 04/02/2026Joseph Menn has been writing about cybersecurity since well before most journalists even understood it as a beat. Big loss for the Post and its readers, but also for the industry and the wider public, who will be less informed - and less safe - as a result. 313945
Jennifer Wood @notnextjen.bsky.social · 04/02/2026Why are pubs laying off talented journalists? We need reporters who understand security to continue covering it. It is disheartening to see this happening over and over again. 000
Jennifer Wood @notnextjen.bsky.social · 29/01/2026Good stuff here, folks! When you have a few minutes, read the article and the research (links below). #LLMsecurity Story: www.reuters.com/technology/o... Research: www.sentinelone.com/labs/silent-...reuters.comOpen-source AI models vulnerable to criminal misuse, researchers warnHackers and other criminals can easily commandeer computers operating open-source large language models outside the guardrails and constraints of the major artificial-intelligence platforms, creating ... 000
Reposted by Jennifer WoodThe Washington Post @washingtonpost.com · 27/01/2026The Federal Aviation Administration ignored warnings about a dangerous level of air traffic at Reagan National Airport before the midair collision between a commercial jet and U.S. Army helicopter that took 67 lives, federal investigators said.washingtonpost.comFAA ignored warnings from controllers before DCA crash, federal investigators sayFamilies hope the nearly year-long probe by the National Transportation Safety Board will promote aviation safety changes. 45131
Reposted by Jennifer WoodJessica Lyons @jessicalyons.bsky.social · 23/01/2026ShinyHunters has claimed responsibility for an Okta voice-phishing campaign during which the extortionist crew allegedly gained access to Crunchbase and Betterment.theregister.comShinyHunters claims Okta customer breaches, leaks data: 'A lot more' victims to come, we're told 021
Reposted by Jennifer WoodLorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 23/01/2026NEW: Microsoft handed the FBI the recovery keys to decrypt the hard drives of three laptops encrypted with BitLocker. BitLocker is enabled by default in modern Windows laptops, but Microsoft also prompts users to upload the recovery keys to the company's cloud, which opens up this possibility.techcrunch.comMicrosoft gave FBI a set of BitLocker encryption keys to unlock suspects' laptops: reports | TechCrunchThe FBI served Microsoft a warrant requesting encryption recovery keys to decrypt the hard drives of people involved in an alleged fraud case in Guam. 32422
Reposted by Jennifer WoodZack Whittaker @zackwhittaker.com · 22/01/2026New, by me: Under Armour says it’s aware of data breach claims after 72M customer records were posted online. A spox. told me a "small percentage" of customers had sensitive information compromised but wouldn't say what it considers "sensitive," nor provide an accurate figure of affected customers.techcrunch.comUnder Armour says it's 'aware' of data breach claims after 72M customer records were posted online | TechCrunchTechCrunch obtained a sample of the stolen data, which contained names, email addresses, dates of birth, and the user's approximate geographic location. Under Armour confirmed some sensitive informati... 21711
Jennifer Wood @notnextjen.bsky.social · 22/01/2026GPS attacks are increasing, relatively cheap to implement, spreading geographically, and present a significant threat to people's safety and the economy. If your org uses GPS data, it's time to update your threat models. Learn more: shostack.org/26-01shostack.orgThreat Advisory: GPS Attacks [SA-26-01]The dramatic increase in credible reports of GPS attacks, combined with geographic spread and the decreasing cost of hardware for the attack, indicate a change in the threat landscape. If your company... 001
Jennifer Wood @notnextjen.bsky.social · 18/09/2025Today is the day…#LABScon2025 is live from Phoenix, AZ. Get ready for two days of unique research and excellent speakers. 000
Reposted by Jennifer WoodZack Whittaker @zackwhittaker.com · 07/08/2025New: French phone giant Bouygues confirmed a data breach affects the personal information of 6.4 million customers. Bouygues disclosed the breach on a dedicated web page; however, the page is currently deliberately excluded from search engines using "noindex" code, making it more difficult to find.techcrunch.comData breach at French telecom giant Bouygues affects millions of customers | TechCrunchThis is the latest cyberattack to hit a French cellular carrier in recent weeks, following an attack on Orange Telecom in July. 24219
Jennifer Wood @notnextjen.bsky.social · 07/08/2025Enjoying the #threebuddyproblem podcast live from BH /Vegas! 110
Jennifer Wood @notnextjen.bsky.social · 04/08/2025If all goes to plan, I’ll be in Vegas for #BlackHat this week. DM me if you would like to meet. See y’all soon and safe travels to all! 010
Reposted by Jennifer WoodMicrosoft Threat Intelligence @threatintel.microsoft.com · 22/07/2025Update: Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. Customers should apply these updates immediately. Full guidance and detection details: msft.it/6010sDzSE. 23730
Jennifer Wood @notnextjen.bsky.social · 21/07/2025Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers - www.securityweek.com/microsoft-pa...securityweek.comMicrosoft Patches 'ToolShell' Zero-Days Exploited to Hack SharePoint ServersMicrosoft has started releasing updates to fix the exploited SharePoint zero-days tracked as CVE-2025-53770 and CVE-2025-53771. 000
Reposted by Jennifer WoodJoseph Cox @josephcox.bsky.social · 21/07/2025New from 404 Media: a startup is selling data hacked from peoples' computers to debt collectors, divorce lawyers, more. People already hacked, now being re-vicitmized by startup. I used the tool, found peoples' personal addresses. “This is so gross and predatory.” www.404media.co/a-startup-is...404media.coA Startup is Selling Data Hacked from Peoples’ Computers to Debt CollectorsInfostealer data can include passwords, email and billing addresses, and the embarrassing websites you use. Farnsworth Intelligence is selling to to divorce lawyers and other industries. 18756362
Jennifer Wood @notnextjen.bsky.social · 21/07/2025No patch but here’s the suggested mitigations from MSFT: Configure Antimalware Scan Interface integration in SharePoint and deploy Defender AV on all SharePoint servers, and/or consider disconnecting your server from the internet until a security update is available. www.forbes.com/sites/daveyw...forbes.comMicrosoft Confirms Ongoing Mass SharePoint Attack — No Patch AvailableMicrosoft has confirmed that SharePoint Server is under mass attack and no patch is yet available — here’s what you need to know and how to mitigate the threat. 000
Reposted by Jennifer WoodCynthia Brumfield @metacurity.com · 25/06/2025A website developed for the UK Home Office's 2022 "flop" anti-encryption campaign has seemingly been hijacked to push a payday loan scheme. www.theregister.com/2025/06/25/h...theregister.comHome Office anti-encryption site pushes payday loan scheme: Company at center of findings blamed SEO on outsourcer 078
Reposted by Jennifer WoodEric Geller @ericjgeller.com · 25/06/2025Iran's APT42 (Charming Kitten) hacker team is now conducting targeted spearphishing attacks on high-profile Israeli national security journalists and cybersecurity researchers, according to Check Point. blog.checkpoint.com/security/edu... 0124
Jennifer Wood @notnextjen.bsky.social · 23/06/2025After five incredible years at @lutasecurity.bsky.social I’ll be moving on at the end of the month and looking for a new senior communications leadership role within the cybersecurity industry. For more info about my background, please read: tinyurl.com/yeyw4xb6. Thanks!tinyurl.comDear friends, former colleagues, and extended network: | Jennifer (Jen) WoodDear friends, former colleagues, and extended network: After nearly five incredible years at Luta Security, I’ll be moving on at the end of the month and looking for a new senior communications leade... 071
Jennifer Wood @notnextjen.bsky.social · 29/05/2025www.securityweek.com/czech-govern...securityweek.comCzech Government Condemns Chinese Hack on Critical InfrastructureThe Czech government issues a blunt warning to China after APT31 hackers linked to intrusion at critical infrastructure network. 010
Jennifer Wood @notnextjen.bsky.social · 29/05/2025www.theregister.com/2025/05/29/b...theregister.comBillions of session cookies for sale sparks security warning: Law enforcement crackdowns are gathering pace but online marketplaces still teeming with valuable tokens 000
Jennifer Wood @notnextjen.bsky.social · 16/04/2025Phew…CISA extends MITRE-backed CVE contract hours before its lapse www.nextgov.com/cybersecurit...nextgov.comCISA extends MITRE-backed CVE contract hours before its lapse“Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services,” an agency spokesperson said. 010
Jennifer Wood @notnextjen.bsky.social · 16/04/2025Uncle Sam abruptly turns off funding for CVE program. Yes, that CVE program - by @jessicalyons.bsky.social at @theregister.com www.theregister.com/AMP/2025/04/...theregister.comUncle Sam abruptly turns off funding for CVE program. Yes, that CVE program: Because vulnerability management has nothing to do with national security, right? 010
Reposted by Jennifer WoodLuta Security @lutasecurity.bsky.social · 20/03/2025#Cryptocurrency Exchanges—Do you need a security assessment? Do you need an audit for your #bugbounty program? Hire LutaSecurity—the only company led by a co-author of the international standards on vuln disclosure & handling processes. @lutasecurity.bsky.social www.lutasecurity.com/bug-bounty-s...lutasecurity.comBug Bounty Solutions | Luta SecurityLuta Security provides bug bounty program audits, offers end-to-end vulnerability case resolution management, creates new VDP and bug bounty programs, and performs security maturity assessments. 001
Reposted by Jennifer WoodLorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 22/01/2025NEW: The Trump admin has fired members of the Cyber Safety Review Board, a committee that was lauded for its investigation into Microsoft hacks of 2023, and was working on the recent Salt Typhoon telco hacks. One source called it a “horribly shortsighted” decision. techcrunch.com/2025/01/22/t...techcrunch.comTrump administration fires members of cybersecurity review board in “horribly shortsighted” decision | TechCrunchThe Department of Homeland security told members of the Cyber Safety Review Board that their membership was terminated. 32441225
Jennifer Wood @notnextjen.bsky.social · 18/01/2025Back in DC. Not for political reasons. Still feels like home. 010
Jennifer Wood @notnextjen.bsky.social · 12/12/2024Who's ready to sign up for @lutasecurity.bsky.social's Long Spoons Workforce Platform? 030