Sign in

Adrian Sanabria

@sawaba.bsky.social
696 followers 267 following 399 posts

🎙️ Enterprise Security Weekly Podcast Host, 🤝 BSides Knoxville Founder, 🗣️ IANS Research Faculty, 🍳 Cooking, 🏎️ F1, ⛰️ Hiking

PostsRepliesMedia
Reposted by Adrian Sanabria
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 24/09/2026
My thoughts on CISA’s future of CVE white paper along with @sawaba.bsky.social Let’s hope Congress backs enough budget at CISA to hire the human expert resources to guide what will also require heavy automation investment. Thanks @shaunwaterman.bsky.social www.bankinfosecurity.com/cisa-lays-ou...
bankinfosecurity.com
CISA Lays Out Future of CVE Vulnerability Program
The U.S. Cybersecurity and Infrastructure Security Agency published a short whitepaper Wednesday, laying out four "dimensions of quality" it will pursue
1136
Adrian Sanabria @sawaba.bsky.social · 23/09/2026
The latest report in The Defenders Initiative's Breach Lessons series is out! This week's report is on Uber's 2022 breach, which was one in a series of Lapsus$ breaches done by a handful of British teenagers. www.defendersinitiative.com/p/breach-les...
defendersinitiative.com
Breach Lessons: the 2022 Uber Hack
Steal my creds once, shame on you, steal them a third time...
100
Adrian Sanabria @sawaba.bsky.social · 22/09/2026
Looking to get stickers made, suggestions that aren't StickerMule?
010
Adrian Sanabria @sawaba.bsky.social · 17/09/2026
Booz Allen is the latest to get into AI cybersecurity benchmarks. I checked them out and share my thoughts. Sanity check: benchmarks != real world capabilities, but they do give us a data point we can use to measure AI model changes over time. defendersinitiative.substack.com/p/theres-now...
defendersinitiative.substack.com
There’s now a Cyber Weapon Index
Apparently AI models are weapons now and they’re going to kill us all (but that’s a different post)
000
Adrian Sanabria @sawaba.bsky.social · 16/09/2026
The latest in our breach studies is the Capital One breach. I know, everyone knows it and I don't think there are any big surprises here, but the next few studies coming up are definitely going to be spicy! www.defendersinitiative.com/p/breach-les...
000
Adrian Sanabria @sawaba.bsky.social · 15/09/2026
Super excited I get to interview @joemenn.bsky.social about Cult of the Dead Cow this week at the Open Source Security Summit! It's a virtual event and free to attend, so come check it out Thursday morning! #opensourcesecuritysummit opensourcesecuritysummit.com
opensourcesecuritysummit.com
Open Source Security Summit | Bitwarden
Check out the free and virtual Open Source Security Summit to learn from industry visionaries and thought leaders about the latest cybersecurity advancements in open source technology.
022
Reposted by Adrian Sanabria
Best of r/cybersecurity @cybersecurity.page · 15/09/2026
A zero-day root RCE in Cisco Secure Email Gateway is being actively exploited. SQL injection appears to be the entry point, which is grim given the appliance's job is parsing untrusted mail all day. No patch details yet.
reddit.com
Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
View post on Reddit.
032
Adrian Sanabria @sawaba.bsky.social · 02/09/2026
Thanks to a lighter workload in August, I've been able to spend more time on breach analysis! The latest writeup is the British Library breach. What this breach lacks in technical details, it makes up for in details on process, priorities, and culture! www.defendersinitiative.com/p/breach-les...
000
Reposted by Adrian Sanabria
Kevin Beaumont @doublepulsar.com · 10/08/2026
Two things at play - ClickFix (website asks user to press Windows key + R, run a command) is *incredibly successful*, and just phoning the helpdesk and asking for password reset. The GenAI research stuff being pushed out by security and AI vendors is completely absent in the real world trenches.
49034
Adrian Sanabria @sawaba.bsky.social · 11/08/2026
My thoughts on 1Password’s first research publication from their brand new Off-by-1 Labs! www.defendersinitiative.com/p/reviewing-...
defendersinitiative.com
Reviewing initial research on using AI for vulnerability remediation
TL;DR: don't use AI to create patches
001
Adrian Sanabria @sawaba.bsky.social · 11/08/2026
IMO, the most interesting thing to come out of #HackerSummerCamp is that no one should be using AI to patch vulns 1password.com/blog/why-ai-...
1password.com
Off-by-1 Labs Research: AI-generated vulnerability patches require human review | 1Password
Defenders are increasingly turning to LLMs to to generate vulnerability patches. But our research showed that LLMs only successfully generate patches (without materially changing application behavior)...
011
Adrian Sanabria @sawaba.bsky.social · 10/08/2026
Windows Mobile is still alive and well at DFW
030
Adrian Sanabria @sawaba.bsky.social · 10/08/2026
Behold my restraint All these gadgets could have come with me to #hackersummercamp but I left them home because I have so much restraint
010
Adrian Sanabria @sawaba.bsky.social · 10/08/2026
Oh lawd he coming
000
Reposted by Adrian Sanabria
JoshCorman @joshcorman.bsky.social · 03/08/2026
We are on break for lunch, but rewind to see my opener… and stay tumed for 2hrs on water next. Quite timely.
111
Reposted by Adrian Sanabria
Chris Dwan (he/him) @somershade.bsky.social · 29/07/2026
Normalize making fun of people when they’re all proud of having used generative AI to do some trvial task. Yesterday’s example: A colleague made a sign that said ‘USE THIS DOOR, OTHER DOOR IS BROKEN.’ Yup. AI for that. 1/?
18422
Adrian Sanabria @sawaba.bsky.social · 29/07/2026
This voiceover artist nails one of the most annoying trends in cybersecurity right now www.instagram.com/reel/Da_K-z8...
instagram.com
Instagram
Create an account or log in to Instagram - Share what you're into with the people who get you.
000
Adrian Sanabria @sawaba.bsky.social · 29/07/2026
Happy to share that I will be speaking at BSides Las Vegas this year! My talk is "Destroyed by Breach: Corporate casualties of cybersecurity failures" Common Ground, Tuesday 10:00-11:00, Florentine F I'll be at Black Hat and DEF CON as well. Let me know if you want to meet up!
130
Adrian Sanabria @sawaba.bsky.social · 29/07/2026
This week on ESW: 1. O'Shea Bowens - network security for MCP 2. Jeremiah Grossman - there is no vulnpocalypse 3. Finally, we discuss the future of AI model use and the HuggingFace breach We went a little long on this one, but I think it was well worth it. www.youtube.com/watch?v=Em3F...
youtube.com
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - ESW #469
Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive…
000
Adrian Sanabria @sawaba.bsky.social · 08/06/2026
Spotted an interesting comment on LinkedIn this morning.
000
Adrian Sanabria @sawaba.bsky.social · 03/06/2026
In my latest post, I ponder whether Project Glasswing is just a private freemium tier, designed to hook the world’s largest software makers into fueling an endless token bonfire. open.substack.com/pub/defender...
open.substack.com
The unintended consequences of vulnmaxxing
The only way to fix vulns at AI scale is to use AI. Coincidence or cash grab?
231
Adrian Sanabria @sawaba.bsky.social · 03/06/2026
TL;DR - Reddit posts are now SEO/AEO, which means Reddit has become a battleground trying to fight off corporate marketing posts
010
Adrian Sanabria @sawaba.bsky.social · 22/05/2026
For anyone interested, I've shared the slides from my @bsidesknoxville talk hosted-files.sched.co/bsidesknoxvi...
110
Adrian Sanabria @sawaba.bsky.social · 19/05/2026
Happy DBIR day everyone! It's really good, as always. I wrote up some thoughts: www.defendersinitiative.com/p/verizons-1...
defendersinitiative.com
Verizon's 19th edition of the DBIR confirms the vulnpocalypse***
But with many asterisks! Read on to find out why 😅
131
Reposted by Adrian Sanabria
Eric Geller @ericjgeller.com · 18/05/2026
You've probably heard about Anthropic's Mythos, but did you know open-source AI tools have been doing the same thing for the past year? I wrote about these bug-finding systems and why they might be better than Mythos for critical infrastructure firms. www.cybersecuritydive.com/news/ai-vuln...
55618
Adrian Sanabria @sawaba.bsky.social · 18/05/2026
April 2026: LOL, enterprises would have to be mad to consider using OpenClaw internally May 2026: Oh, a client has a question about some OpenClaw vulns that affect them, this is normal
010
Adrian Sanabria @sawaba.bsky.social · 13/05/2026
Is NPM the new DNS? As in, "it's always NPM"
141
Adrian Sanabria @sawaba.bsky.social · 12/05/2026
Defense is Offense’s child, but Offense has traumatized its children #randomthoughts
010
Adrian Sanabria @sawaba.bsky.social · 08/05/2026
You know, for an OS that sets the standard for vulnerable implementations, at least the default lock screen image is nice to look at, right?
000
Reposted by Adrian Sanabria
Joe Uchill @joeuchill.bsky.social · 08/05/2026
This isn't an AI problem. In any context, if the reporter didn't observe the quote, they needed to cite their source. And that's more than just the wording of the quote. The reporter is responsible for the inferred meaning matching the actual context of a statement.
162
Adrian Sanabria @sawaba.bsky.social · 05/05/2026
Potential hot take: vulnerabilities are sparse if a vulnerability is required to have value to an attacker.
010
Reposted by Adrian Sanabria
BSides Knoxville @bsidesknoxville.bsky.social · 01/04/2026
It's ticket time! bsides-knoxville-2026.eventbrite.com
011
Adrian Sanabria @sawaba.bsky.social · 30/04/2026
Hey Claude, is it possible that threat actors make more money off hacking firewalls/VPNs than companies make selling them #AIQuestions
000
Adrian Sanabria @sawaba.bsky.social · 30/04/2026
So yesterday: This vuln is being exploited in the wild Today: To date, threat actors have earned $247M from this vuln
000
Reposted by Adrian Sanabria
Filippo Valsorda @filippo.abyssdomain.expert · 29/04/2026
Copy Fail? Also looks like memory safety, but is actually complexity. xint.io/blog/copy-fa... I am going to link to this while rejecting changes to Go crypto for years. Anyway, feeling pretty validated in my "ssh in as root, only gVisor or Firecracker are an actual security boundary" approach.
xint.io
Copy Fail: 732 Bytes to Root on Every Major Linux Distribution - Xint
Xint Code disclosed CVE-2026-31431, an authencesn scratch-write bug chaining AF_ALG + splice() into a 4-byte page cache write. A 732-byte PoC gets root on Ubuntu, Amazon Linux, RHEL, SUSE. | AI for Se...
39819
Adrian Sanabria @sawaba.bsky.social · 28/04/2026
I'm putting together a webinar on modern vulnerability management and I'm REALLY trying to drive a point home So naturally, I bought 3 old Sonicwall firewalls
000
Adrian Sanabria @sawaba.bsky.social · 23/04/2026
yeah sure, okay
040
Adrian Sanabria @sawaba.bsky.social · 23/04/2026
Starting to get some coverage from the media on the Destroyed by Breach site! www.cybrsecmedia.com/breaches-don...
cybrsecmedia.com
Breaches Don’t Kill Companies. Being Unprepared Does.
Adrian Sanabria built "Destroyed By Breach" to cut through cybersecurity myth-making, and what he found is more uncomfortable than the fear-driven narrative the industry often sells.
130
Reposted by Adrian Sanabria
Jarmo Lahtiranta @naranek.bsky.social · 22/04/2026
This is _the_ most underrated cybersecurity project. Awesome to have a website instead of the spreadsheet 🥳
111
Reposted by Adrian Sanabria
Signal @signal.org · 22/04/2026
We are very happy that today Apple issued a patch and a security advisory. This comes following 404 Media reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted.
111789474
Reposted by Adrian Sanabria
Eric Geller @ericjgeller.com · 22/04/2026
Big news: Sean Plankey has withdrawn from consideration to be Trump's CISA director after his nomination languished for more than a year amid bipartisan holds in the Senate. CISA hasn't had a permanent director since Trump retook office. www.politico.com/news/2026/04...
politico.com
Trump’s pick to lead CISA withdraws nomination after months of political impasse
Resistance from Sen. Rick Scott (R-Fla.) stalled Sean Plankey’s nomination for over a year.
5266
Adrian Sanabria @sawaba.bsky.social · 22/04/2026
I am thrilled to announce that my Destroyed by Breach research project finally has a proper website! destroyedbybreach.com
360
Reposted by Adrian Sanabria
International Cyber Digest @intcyberdigest.bsky.social · 19/04/2026
🚨 BREAKING: Vercel has been breached. A threat actor has listed their customers' data, source code, databases, and keys up for sale. Vercel has also publicly disclosed they've identified a security incident involving unauthorized access to their internal systems.
136
Adrian Sanabria @sawaba.bsky.social · 20/04/2026
Some thoughts on the Vercel/Context breach turducken www.defendersinitiative.com/p/breach-les...
defendersinitiative.com
Breach Lessons - First Look: Vercel and Context AI
We usually wait for the investigation to complete, but there are already a ton of useful lessons here.
021
Reposted by Adrian Sanabria
The Register @theregister.com · 13/04/2026
Notepad sheds Copilot from toolbar as Microsoft gives subtlety a try
go.theregister.com
Notepad sheds Copilot from toolbar as Microsoft gives subtlety a try
AI gubbins still there, just tucked under 'Writing Tools' Copilot is on its way out of Notepad, but a return to the basic text editor is not on the cards.…
1153
Adrian Sanabria @sawaba.bsky.social · 04/04/2026
Saturday morning vibes Making brunch in the kitchen in utter silence like a psycho No music, no YouTube, no audiobook, no podcast
130
Reposted by Adrian Sanabria
CyberCanon @cybercanon.org · 23/03/2026
Monday #RSAC sessions with CyberCanon Committee Members and Authors: 🤖 Caroline Wong - The Foundations of AI 👁️ Adrian Sanabria - A Failure Is a Terrible Thing to Waste: The Case for Breach Transparency 🪖 Nicole Perlroth - Resilient Infrastructure as National Defense (part 1/3)
222
Adrian Sanabria @sawaba.bsky.social · 06/03/2026
Vulnerability management is in some trouble and I have thoughts on how to deal with it. TL;DR - exploitation is happening too fast for traditional vuln mgmt to be effective. open.substack.com/pub/defendersi…
112
Adrian Sanabria @sawaba.bsky.social · 28/02/2026
Saturday repair project time! My partners’ thousands of hours in Rocket League have taken their toll on these poor PS5 controllers.
010
Adrian Sanabria @sawaba.bsky.social · 28/02/2026
This Italian hacking magazine needs to calm down
020