Sign in

Paul Walsh

@paulwalsh.bsky.social
161 followers 29 following 104 posts

Most top security firms license my patents for mobile app security. Pioneered zero trust for anti-phishing. Helped to launch @AIM @MetaCert Founder. Co-invented the concept of labeling user accounts on the web at the W3C in 2004. Expert in SMS security.

PostsRepliesMedia
Paul Walsh @paulwalsh.bsky.social · 07/09/2026
I haven’t been on here in a long time, so it feels like I’m whispering into an empty cave because I barely know anyone here. My LinkedIn readers asked me to set up a Substack because it's hard to find posts, so I finally did. Now I’m wondering if I should start publishing and engaging here too.
000
Paul Walsh @paulwalsh.bsky.social · 11/03/2026
Just wrote this. A new secure messaging app called prvc takes privacy and security to a new level. It will launch with Mackie Mobile, a new US carrier built from the ground up to prioritise subscriber safety and privacy. www.linkedin.com/pulse/signal...
linkedin.com
The Signal and WhatsApp cyberattacks highlight a design flaw prvc was built to remove
Recent phishing campaigns targeting users of Signal and WhatsApp have exposed a dangerous attack technique that’s still widely misunderstood. Dutch intelligence agencies confirmed that attackers targe...
000
Paul Walsh @paulwalsh.bsky.social · 11/03/2026
I wrote an article explaining how attackers are taking over Signal accounts used by high-risk individuals and why there’s very little Signal can do to stop it. The issue isn’t broken encryption. It’s how authentication workflows are being abused. paul-walsh.medium.com/how-attacker...
paul-walsh.medium.com
How Attackers Hijack Accounts Like Signal and WhatsApp Using Legitimate Authentication Workflows
Why the recent Signal attacks expose a design flaw across most software systems and applications
000
Paul Walsh @paulwalsh.bsky.social · 11/03/2026
The only advice I can offer for this serious problem is simple. Be extremely cautious whenever you’re presented with a meeting link, a verification code, or a request to approve a login or authenticate an account. There isn't much Signal can do to combat this. paul-walsh.medium.com/how-attacker...
paul-walsh.medium.com
How Attackers Hijack Accounts Like Signal and WhatsApp Using Legitimate Authentication Workflows
Why the recent Signal attacks expose a design flaw across most software systems and applications
022
Reposted by Paul Walsh
Happygeek @happygeek.bsky.social · 22/07/2025
This article @forbes.com has now been updated with an interesting counterpoint from @paulwalsh.bsky.social. #Infosec www.forbes.com/sites/daveyw...
forbes.com
Password Hack Warning As New Threat Jumps From Your Laptop To Phone
As if by magic, this password hack jumps from your laptop to your smartphone — but it's you who waves the wand.
151
Paul Walsh @paulwalsh.bsky.social · 04/07/2025
I haven’t signed into this site for quite some time - is it worth it?
media.tenor.com
elmo from sesame street says " worth a shot "
ALT: elmo from sesame street says " worth a shot "
000
Paul Walsh @paulwalsh.bsky.social · 22/05/2025
Most phishing links aren’t flagged as dangerous because they’ve never been seen before. We don’t need more, or better awareness. We need better systems to protect people. Here’s how MetaCert stops phishing without the need to train people: 🔗 www.linkedin.com/pulse/phishi...
linkedin.com
Phishing isn’t a human problem. It’s a failure of the systems meant to protect us.
Would you trust the SMS link above? Look closely. The honest answer is, you can’t know without opening it.
000
Paul Walsh @paulwalsh.bsky.social · 07/05/2025
In addition to the good detail contained in this article, do NOT trust any person who calls you, even if it comes from a legitimate number because they’re easy to spoof.
000
Paul Walsh @paulwalsh.bsky.social · 06/05/2025
MetaCert has built a new solution that helps banks protect their brand, reduce liability, and stop this type of fraud before it happens — using tech that wasn’t possible until now. Hoping to see it adopted in Ireland soon. @bankofireland @AIBIreland ☘🔐 www.rsvplive.ie/news/irish-n...
rsvplive.ie
Bank of Ireland warns customers of spike in new scam to steal personal information
The bank have warned their customers that there's a new scam doing the rounds in which fraudsters will send texts urging people to call phone numbers, where they will attempt to steal financial inform...
000
Paul Walsh @paulwalsh.bsky.social · 06/05/2025
My open letter to the security industry — and MetaCert’s U.S. SMS security test report — is featured in this Forbes article. Huge thanks to @happygeek for giving the underdog a voice. The best solution means nothing if no one hears about it. www.forbes.com/sites/daveyw...
forbes.com
Confirmed — 19 Billion Compromised Passwords Published Online
You must take action now, as security experts confirm 19 billion compromised passwords available to cybercriminals for use in account hacking attacks.
021
Paul Walsh @paulwalsh.bsky.social · 29/04/2025
I just wrote this: "Zero Trust Is Broken at the URL — And That’s Where Most Attacks Begin (Phishing)" www.linkedin.com/pulse/zero-t... paul-walsh.medium.com/zero-trust-i... Lots of people are talking about Zero Trust at #RSAC2025 but not one person has mentioned zero trust for URLs. 🙄
011
Paul Walsh @paulwalsh.bsky.social · 25/04/2025
🎓 Are you brave enough to give it a go? What’s the right answer? Even the most skilled & experienced security pros fail my tests 99% of the time — so there’s no need to feel afraid or embarrassed. Feel free to share it too — the more awareness, the better I don’t get much engagement on here so...
000
Paul Walsh @paulwalsh.bsky.social · 23/04/2025
I just received this SMS scam. This one’s from a lazy attacker — strange ID, sloppy text. But don’t let it fool you into thinking they’re all this obvious. Many are highly convincing and look exactly like the real messages you’re expecting — from deliveries to security alerts.
000
Paul Walsh @paulwalsh.bsky.social · 22/04/2025
I just wrote this: www.linkedin.com/pulse/lie-we...
linkedin.com
The Lie We’ve Been Sold: Why Security Has Never Stopped Phishing — and Won’t Start with SMS
Phishing Isn’t New — It Just Keeps Changing Channels In the 1990s, I worked at AOL during the early days of the internet, when phishing first emerged in chat rooms, email, and instant messages. I didn...
000
Paul Walsh @paulwalsh.bsky.social · 14/04/2025
💡 Just dropped: how I turned ChatGPT into my expert collaborator — not just a generic assistant. Includes the exact prompt I use + how to apply it across product, sales, hiring, comms, and more. www.linkedin.com/pulse/how-tr...
linkedin.com
How to Train ChatGPT to Think Like You — And Use It as a Strategic Collaborator
For Anyone Using ChatGPT at Work: This Is How to Take It to the Next Level If you’re already using ChatGPT at work — for writing, planning, or creative thinking — but want more consistent, higher-qual...
000
Paul Walsh @paulwalsh.bsky.social · 11/04/2025
SMS phishing isn’t clever — just easy Criminals test fake messages on their own SIMs If the link gets through, they send it to you If it doesn’t, they swap it until it does This is why traditional security fails Only trusted link authentication stops smishing before it starts.
000
Paul Walsh @paulwalsh.bsky.social · 10/04/2025
AI isn’t just fun — it’s a serious business tool. I still had to finesse and shape things, but ChatGPT did most of the heavy lifting behind the scenes. #SMSFraud #Phishing #Smishing
000
Paul Walsh @paulwalsh.bsky.social · 10/04/2025
Already sparked a few great conversations from my LinkedIn post. It wasn’t a call for work — just holding myself accountable by not procrastinating. 🤓 www.linkedin.com/posts/paulwa...
linkedin.com
#hashtag | Paul Walsh
Making myself available — selectively — for board seats and advisory roles for the first time in a while. I’m particularly interested in tech companies and digital agencies where I can add strategic v...
000
Paul Walsh @paulwalsh.bsky.social · 09/04/2025
OpenAI now holds detailed insight into people’s jobs and interests — all exchanged for a bit of entertainment. 🤓
000
Paul Walsh @paulwalsh.bsky.social · 03/04/2025
If you know anyone at banks or payment providers in Ireland, I’d appreciate an intro. I’m in touch with the Banking Federation but keen to connect with more of the right people — hoping Ireland can lead the way in stopping SMS fraud.
000
Paul Walsh @paulwalsh.bsky.social · 02/04/2025
Thank you, ChatGPT. I made several edits, but the AI handled most of the heavy lifting. MetaCert has developed a short code specifically for Ireland, where current privacy regulations prevent mobile operators from implementing network-based anti-phishing security.
000
Paul Walsh @paulwalsh.bsky.social · 02/04/2025
LinkedIn engagement has fallen off a cliff since the start of 2025. I’m not sure what they changed, but it’s obvious something’s different. If I wasn’t writing for a handful of very specific people, I’d have stopped posting altogether. And it’s even worse on here. Not a single engagement.
000
Paul Walsh @paulwalsh.bsky.social · 02/04/2025
I just wrote this: The security industry widely acknowledges smishing as one of today’s most serious cybersecurity threats. So why is it that no legacy vendor offers a network-based solution for mobile operators to protect... LinkedIn: t.co/XpVg2498Cw Medium: paul-walsh.medium.com/from-aol-ins...
000
Paul Walsh @paulwalsh.bsky.social · 01/04/2025
I made this emoji using ChatGPT — with a transparent background! It’s wild how fast this is evolving. Tools like this won’t replace great designers — but they will wipe out tedious work and make everyday tasks way faster and easier.
000
Paul Walsh @paulwalsh.bsky.social · 27/03/2025
Troy Hunt has spent his career teaching people how phishing works and how to avoid it. He knows the tactics, he understands the risks — and he still got caught. LinkedIn: www.linkedin.com/pulse/troy-h... Medium: paul-walsh.medium.com/troy-hunt-fe...
paul-walsh.medium.com
Troy Hunt Fell for a Phishing Attack — Here’s Why That Should Scare Everyone
Troy Hunt — one of the world’s most respected security professionals and founder of Have I Been Pwned — just admitted to falling for a…
000
Paul Walsh @paulwalsh.bsky.social · 26/03/2025
Google is flagging MetaCert’s anti-phishing emails as ‘dangerous’ — the same emails that highlight Google’s failure to detect phishing apps on Google Play. Ironic, but not even slightly funny. 😤 @gmail
000
Paul Walsh @paulwalsh.bsky.social · 20/03/2025
“A World Without ADHD and Dyslexia" I just wrote this for Neurodiversity Celebration Week. #NeurodiversityCelebrationWeek #NeurodiversityWeek #NCW #ThisIsND #ADHD #Dyslexia cc @NCWeek LinkedIn: www.linkedin.com/pulse/world-... Medium: paul-walsh.medium.com/a-world-with...
000
Paul Walsh @paulwalsh.bsky.social · 20/03/2025
It’s 2025, and the security industry still hasn’t solved phishing. It’s time for a new approach - it’s time for Zero Trust for URLs. Assume every site, login page, app, API, user account, and AI chatbot is dangerous unless explicitly verified as legitimate. www.securityweek.com/300-maliciou...
securityweek.com
300 Malicious 'Vapor' Apps Hosted on Google Play Had 60 Million Downloads
300 malicious applications displaying intrusive full-screen interstitial video ads amassed more than 60 million downloads on Google Play.
010
Paul Walsh @paulwalsh.bsky.social · 19/03/2025
35% of entrepreneurs have dyslexia, 40% of self-made millionaires have ADHD. 30% - 40% have both. Yet, most investors & corporate execs don’t fully understand how they think or communicate. I’m writing a book to explain why neurodivergent founders thrive and where they struggle.
000
Paul Walsh @paulwalsh.bsky.social · 18/03/2025
This article explains why AI fails at detecting fake (dangerous) email links, SMS links, WhatsApp links, websites, login pages, apps, QR codes, AI chatbots, or any other web resource — and why relying on it for security is dangerous. #Smishing #Phishing www.linkedin.com/pulse/google...
linkedin.com
Google’s AI “Scam Detection” for Android: Why It Fails to Protect SMS, RCS, and iMessage
Google’s recently announced AI-powered scam detection feature for Android has generated buzz, suggesting a big leap forward in safeguarding Android users and their mobile communications. However, bene...
000
Paul Walsh @paulwalsh.bsky.social · 14/03/2025
After 20+ years in London, Amsterdam, San Francisco, Vancouver, and Edmonton, it’s great to finally be back home in Dublin. It’s been a while since I hosted events here, so I’d love to reconnect with the old timers and meet some new great people. 🚀 metacertsecurity.typeform.com/to/BhKtEuIS
metacertsecurity.typeform.com
My new form
Turn data collection into an experience with Typeform. Create beautiful online forms, surveys, quizzes, and so much more. Try it for FREE.
110
Paul Walsh @paulwalsh.bsky.social · 14/03/2025
💡 One of the most common recommendations is to “watch out for suspicious links or messages.” While this may seem logical, it fails to address the real issue and actually makes people more vulnerable to phishing attacks that don’t look suspicious at all. www.linkedin.com/pulse/why-wa...
linkedin.com
Why “Watch for Suspicious Messages” Is Bad Advice for Stopping Smishing (SMS Phishing)
SMS phishing (smishing) has wreaked havoc since 2019—before that, it wasn’t even on the radar. It only became a major threat when criminals realized everyone was at home, relying on their phones, and ...
000
Reposted by Paul Walsh
Happygeek @happygeek.bsky.social · 13/03/2025
Afternoon Advanced Persistent Tweeters. By me @forbes.com: No, Elon Musk hasn't invented a plugin gadget that slashes your electricity bill by 90%. #kudos @bitdefenderppc.bsky.social #infosec www.forbes.com/sites/daveyw...
forbes.com
A Fake Elon Musk Promises 90% Off Electricity Bills In New Scam
If you get a message promising you 90% off your electricity bills using a gadget supposedly invented by Elon Musk, it really is too good to be true.
001
Paul Walsh @paulwalsh.bsky.social · 13/03/2025
35% of entrepreneurs are dyslexic. 40% of self-made millionaires have ADHD. The most successful founders & execs don’t go it alone - they have coaches. Hannah is the perfect coach for people like us - available in person & over video calls. www.linkedin.com/pulse/power-...
linkedin.com
The Power of Thinking Differently: How Neurodiversity Shapes Leadership and Coaching
For as long as I can remember, I’ve been fascinated by how people think, process information, interact and lead. But for a long time, I didn’t fully understand the unique way my own brain worked.
110
Paul Walsh @paulwalsh.bsky.social · 12/03/2025
Honoured to be interviewed by Forbes on online fraud & why phishing remains the biggest cybersecurity threat. The tactics haven’t changed — just the scale. Here’s what needs to happen next: Thanks @happygeek www.forbes.com/sites/daveyw... #Smishing #Phishing
forbes.com
PayPal Scam Warning—Dangerous Invoice Bypasses Email Security
PayPal scammers are bypassing your email security measures using this simple trick—here’s what you need to know.
000
Paul Walsh @paulwalsh.bsky.social · 12/03/2025
Mobile operators depend on SMS firewall vendors to filter out spam and fraud. However, the rapid rise of Smishing has exposed a critical gap in traditional firewalls. LinkedIn: www.linkedin.com/pulse/future... Medium: paul-walsh.medium.com/the-future-o... 👀 @Mavenir @sinch @Infobip @Cloudmark 👀
linkedin.com
The Future of SMS Security: How SMS Firewall Vendors Can Evolve to Stop Smishing at Scale
The Role of SMS Firewall Vendors in Protecting Mobile Networks Mobile operators depend on SMS firewall vendors to filter out spam and fraud. However, the rapid rise of SMS phishing (Smishing) has expo...
000
Paul Walsh @paulwalsh.bsky.social · 12/03/2025
Browsers killed website identity UI, making phishing easier. Now, mobile operators are repeating the mistake with SMS. 🔑 The fix? Zero Trust for URLs. Read more: LinkedIn: www.linkedin.com/pulse/death-... Medium; paul-walsh.medium.com/the-death-of... #SMS #Phishing = #Smishing #ZeroTrustSMS
linkedin.com
The Death of Website Identity UI & the Rise of Phishing: Why SMS Is Repeating the Same Mistake 🚨
Google and the Death of Website Identity In 2019, I wrote for the PKI Consortium about how mainstream browsers eliminated website identity indicators — removing a security signal that once helped peop...
000
Paul Walsh @paulwalsh.bsky.social · 11/03/2025
Scammers are bypassing AI protections while leveraging fake DocuSign & PayPal websites to deceive ppl I shared my insights on why phishing awareness is outdated, why threat detection fails, & why Zero Trust for URLs is the only fix with - tks @happygeek www.forbes.com/sites/daveyw...
forbes.com
PayPal Scam Warning—Dangerous Invoice Bypasses Email Security
PayPal scammers are bypassing your email security measures using this simple trick—here’s what you need to know.
000
Paul Walsh @paulwalsh.bsky.social · 10/03/2025
Following Google’s announcement about a “New” Android Scam Feature, I’ve fielded the same question from shareholders, potential investors, carrier prospects, and a regulator, “Does Google’s new AI feature actually fix smishing?” The short answer is no. www.linkedin.com/pulse/google...
linkedin.com
Google’s AI “Scam Detection” for Android: Why It Fails to Protect SMS, RCS, and iMessage
Google’s recently announced AI-powered scam detection feature for Android has generated buzz, suggesting a big leap forward in safeguarding Android users and their mobile communications. However, bene...
000
Paul Walsh @paulwalsh.bsky.social · 08/03/2025
Phishing attacks like the one the one documented wouldn’t be a problem if companies like Palo Alto Networks adopted a zero trust strategy for web resources like URLs. 🤷 I discuss why this is necessary here: www.linkedin.com/pulse/open-l... unit42.paloaltonetworks.com/javaghost-cl...
011
Reposted by Paul Walsh
Happygeek @happygeek.bsky.social · 07/03/2025
By me @forbes.com: Thinking about buying Gmail accounts? Alongside the obvious why, comes the equally obvious don't. Here's what you need to know. #infosec www.forbes.com/sites/daveyw...
forbes.com
Gmail Accounts For Sale—Google Issues Critical New Warning
Google says that Gmail accounts are being offered for sale and has issued a warning about the dangers involved. Here’s what you need to know.
111
Paul Walsh @paulwalsh.bsky.social · 08/03/2025
“A $150 million theft from Ripple co-founder Chris Larsen's wallet was traced back to a security lapse at password manager LastPass, according to a forfeiture complaint filed by U.S. law enforcement.” www.coindesk.com/tech/2025/03...
coindesk.com
Ripple News: XRP Heist Worth $150M Related to LastPass Hack
Larsen confirmed the incident in January, where he clarified the hack affected only his personal accounts, not Ripple’s corporate wallets.
000
Paul Walsh @paulwalsh.bsky.social · 08/03/2025
www.linkedin.com/pulse/open-l...
linkedin.com
An Open Letter to the Cybersecurity Industry: Why Haven’t You Fixed SMS Phishing (Smishing)?
Why Has SMS Been Ignored for So Long? SMS may be a decades-old public utility, but it’s now the backbone of trillions of critical interactions each year — powering financial transactions, password res...
000
Paul Walsh @paulwalsh.bsky.social · 03/03/2025
🚨 Spain Joins the Global SMS Security Crisis 🇪🇸 MetaCert’s latest report confirms what we knew — SMS infrastructure lacks basic security. Across 4 countries, smishing bypassed security 100% of the time www.linkedin.com/pulse/how-mo...
linkedin.com
How Mobile Operators in Spain Are Failing to Protect Banks, Businesses, Payment Providers, and Everyone's Customers from SMS Fraud (Smishing)
The Telecom Industry Hasn’t Made Progress — It’s Time for a New Approach In 2021, I wrote an open letter to the mobile industry warning that SMS phishing (smishing) would only get worse unless operato...
000
Paul Walsh @paulwalsh.bsky.social · 03/03/2025
📇 MetaCert’s third 2025 SMS report reveals yet another failure by mobile operators — this time in Australia — to stop SMS phishing before it reaches consumers and businesses. www.linkedin.com/pulse/how-au... #Smishing
linkedin.com
How Australian Mobile Operators Are Failing to Protect Banks, Businesses, Payment Providers, and Everyone's Customers from SMS Fraud (Smishing)
The Telecom Industry Hasn’t Made Progress — It’s Time for a New Approach In 2021, I wrote a well informed and helpful open letter to the mobile industry warning that SMS phishing (often called smishin...
000
Paul Walsh @paulwalsh.bsky.social · 03/03/2025
gizmodo.com/trumps-defen... “It appears that the U.S. no longer considers Russia a significant cyber threat, according to multiple new reports on a drastic policy reversal that has taken hold under the new Trump administration” This is nuts.
gizmodo.com
Trump's Defense Secretary Hegseth Orders Cyber Command to 'Stand Down' on All Russia Operations
Russia is not a significant cyber threat to the U.S. anymore, Trump's new Defense Secretary says.
000
Paul Walsh @paulwalsh.bsky.social · 28/02/2025
🚨 AI isn’t making phishing worse — it’s just making it easier, faster, and cheaper for criminals. Phishing will remain unstoppable until the security industry adopts Zero Trust for URLs & Web Access Requests — the missing pillar in Zero Trust. www.linkedin.com/pulse/ai-phi...
linkedin.com
AI and Phishing: A Distraction from the Real Security Problem
AI-generated phishing is attracting significant attention, with claims that it makes cyberattacks harder to stop. That’s misleading.
000
Paul Walsh @paulwalsh.bsky.social · 27/02/2025
Thanks @rachelswan for exposing the toll scam smishing surge. Our new report confirms SMS now outpaces email for phishing. Carriers must adopt Zero Trust for URLs inside SMS. LinkedIn: www.linkedin.com/pulse/evalua... Medium: paul-walsh.medium.com/an-evaluatio... @ciscosecure.bsky.social
linkedin.com
An Evaluation of SMS Phishing Defenses: How US Mobile Carriers Are Failing to Protect Banks, Payment Providers, and Their Customers from Fraud
Introduction SMS phishing — often called smishing — has overtaken email as the leading cyber threat in the United States, mirroring a trend observed worldwide. It’s no longer “just spam.
000
Paul Walsh @paulwalsh.bsky.social · 26/02/2025
I just wrote this: Despite the ongoing threat since 2019, UK operators have not adopted an effective security model. They rely on outdated, reactive approaches rather than proactive, preventive solutions LinkedIn: www.linkedin.com/pulse/evalua... Medium: paul-walsh.medium.com/an-evaluatio...
linkedin.com
An Evaluation of SMS Phishing Defenses: How UK Mobile Operators Are Failing to Protect Banks, Payment Providers, and Their Customers from Fraud
Introduction SMS phishing, or smishing, has now overtaken email as the leading cyber threat in the UK. Research by ProofPoint shows 86% of UK organizations faced attempted smishing attacks in 2022, th...
000
Paul Walsh @paulwalsh.bsky.social · 25/02/2025
The results are in after MetaCert conducted extensive testing across the four major U.S. carriers — Verizon, AT&T, T-Mobile, and Boost Mobile — to measure their ability to stop dangerous SMS messages before they reach consumers and business customers. paul-walsh.medium.com/the-failure-...
paul-walsh.medium.com
The Failure of U.S. Mobile Carriers to Protect Consumers from SMS Phishing
Executive Summary
000