Sign in

Securely Built

@securelybuilt.bsky.social
43 followers 26 following 333 posts

Securely Built is on the hunt for insecurity in the world where we can leverage our decades of experience in cyber and engineering to banish insecure technology from whence it came. Find out more at: securelybuilt.com

PostsRepliesMedia
Securely Built @securelybuilt.bsky.social · 28/09/2026
Cybersecurity awareness month is almost here, don't forget to check in on your passwords!
000
Securely Built @securelybuilt.bsky.social · 26/09/2026
If you're thinking about going beyond a Sec+ cert then take a look at this exam prep course: CompTIA CySA+ Exam Prep with Hands-On Labs Bonus: it's on sale at Udemy for the next 5 days if you use this coupon code: www.udemy.com/course/compt...
udemy.com
CompTIA CySA+ Exam Prep with Hands-On Labs
Threat detection, vulnerability management, incident response and reporting, with 160 practice questions and 4 labs
000
Securely Built @securelybuilt.bsky.social · 24/09/2026
I've spent a lot of time mentoring people who are looking to get into cybersecurity. And a lot of that time has been in convincing them that there is way more to cyber than what they believe.
udemy.com
GRC Fundamentals - Learn Governance, Risk, and Compliance
Build a Unified Framework for Smarter Governance, Proactive Risk Management, and Sustainable Compliance
100
Securely Built @securelybuilt.bsky.social · 16/09/2026
From the Department of Duh: "You don’t have to join the hack-back program to inherit its risk" A few weeks ago, the US Executive Branch decided to direct the National Coordination Center to build a program for companies to join a offensive cyber program.
200
Securely Built @securelybuilt.bsky.social · 10/09/2026
The cycle never ends..... Microsoft has released its biggest ever patch update, addressing 974 security vulnerabilities across its Windows operating systems and other software. This massive update, which surpasses their previous record of 570 vulnerabilities fixed in July.
100
Securely Built @securelybuilt.bsky.social · 03/09/2026
@manning.com is running their annual Labor Day Sale. It's your chance to grab some titles for a great price! Half off all books $10 liveProjects/ liveVideos $199.99 Subscriptions Annual team subscriptions are 20% off Pick up "The Application Security Program Handbook" while you're there!
110
Securely Built @securelybuilt.bsky.social · 01/09/2026
I've done variations of this drawing so many times over my teaching career, and each time it gets more complex.
100
Securely Built @securelybuilt.bsky.social · 26/08/2026
Defense in depth.....what a concept! No surprise to many, but Microsoft is declaring that the window for patching vulnerabilities is shrinking, and urging enterprises to adopt network-level containment strategies.
csoonline.com
Microsoft warns patch window is collapsing, urges shift to network-level containment
Azure networking executive Igor Sakhnov says enterprises must reduce exposure before patches are deployed as attackers outpace remediation.
100
Securely Built @securelybuilt.bsky.social · 19/08/2026
Remember STRIDE? For decades, STRIDE has been the process for identifying and labeling threats in a system. It’s worked for decades to model threats. But it’s slow, it doesn’t scale well, and there is little standardization around process/tools outside of “use STRIDE”.
100
Securely Built @securelybuilt.bsky.social · 11/08/2026
"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety" Can we please stop pretending that any of these devices are safe for any of us to use.
digitaltrends.com
Kids’ smartwatches are meant to keep children safe, but hackers can turn them into stalking devices
A $30 kids' smartwatch let researchers secretly track a wearer's location, snap photos, and record audio, exposing a much larger flaw shared across dozens of GPS smartwatch brands worldwide.
000
Securely Built @securelybuilt.bsky.social · 03/08/2026
It’s not clear from the article whether robots.txt or ai.txt files was there and configured correctly, but this should be a reminder that we have a simple mitigation that should be used to shape how these crawlers can access web sites.
heise.de
uniVersa: OpenAI AI crawler accessed customer data
uniVersa insurance companies experienced data protection incident. An AI crawler accessed customer data, including names, addresses, in some cases, bank details.
100
Securely Built @securelybuilt.bsky.social · 30/07/2026
Head over to Manning.com. for their summer sale and grab a copy of the Application Security Program Handbook while you're at it!
000
Securely Built @securelybuilt.bsky.social · 27/07/2026
I started in a kitchen. Ten years, thinking I'd be a chef. Then hardware engineering. Then a CS degree and software. Then, sitting one desk away from the application security team in a healthcare company, I got curious enough to change everything again when I pursued my master's in cyber.
youtube.com
Your Cybersecurity Career Has No Straight Path #careeradvice #cybersecurity #infosec
YouTube video by The Decloaked Podcast
100
Securely Built @securelybuilt.bsky.social · 26/07/2026
Not enough evidence here to make a judgement call, but if you are being asked to handover and unlock your phone without any reason, that to me seems like the right time to brick it. As brittle as it seems right now, we do have some constitutional rights left in the US.
androidauthority.com
GrapheneOS duress PIN could land a man in prison
A US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border search.
100
Securely Built @securelybuilt.bsky.social · 22/07/2026
The U.S. Department of Labor recently announced $162 million in funding for Registered Apprenticeships to bridge a growing skills gap. The investment shows how strong #learning and #development (L&D) strategies can help employees grow while strengthening the organization.
hrdive.com
How L&D and workforce readiness are connected
SHRM said “skills strategists” tend to align L&D to business priorities and create learning experiences that are relevant and accessible.
100
Securely Built @securelybuilt.bsky.social · 16/07/2026
AI tools may be making us more productive, but their also making us dumber and might be hiding a bigger problem. A June survey of 1,200 U.S. employees aged 25-64 found that almost 6 in 10 use AI to complete tasks without proper training. It's an efficiency boost and a growing 'learning debt'.
hrdive.com
AI may conceal growing ‘learning debt’ for fast-changing roles
Close to 3 in 10 workers surveyed by TalentLMS said they’ve delivered work they couldn’t fully explain if asked how they did it.
100
Securely Built @securelybuilt.bsky.social · 15/07/2026
GRC has been increasingly becoming a leading pillar in cyber for job seekers. With the US government's restrictions on AI models, the UK is pushing its AI sovereignty creating new opportunities for those who are familiar with the UK's regulatory environment and laws.
darkreading.com
Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife
The US government's restrictions on Anthropic frontier models intensifies calls in the UK to reduce reliance on US tech, with cyber implications.
100
Securely Built @securelybuilt.bsky.social · 14/07/2026
This Glean report examines the negative impacts of overreliance on AI in the workplace and reveals that while AI aims to free up worker time, employees end up spending more time fixing AI-generated errors or producing work they're unhappy with.
hrdive.com
Heavy AI users submit work they don’t understand, report finds
While the use of AI frees up time, Glean found, workers end up using that extra time to fix its mistakes — or simply ship products they can’t stand behind.
100
Securely Built @securelybuilt.bsky.social · 14/07/2026
If you are in the Nashville area on September 17-18, come to the InfoSec Nashville 2026 conference! You'll find me there giving a talk on the changing cybersecurity hiring landscape.
000
Securely Built @securelybuilt.bsky.social · 13/07/2026
Headlines say AI is stealing jobs, but the reality is more nuanced. While many roles will be automated, new ones are emerging at a breakneck pace. 73% of tech job postings now require at least one AI skill, up from just 15% two years ago. That means the demand for AI talent is skyrocketing.
hrdive.com
AI skills now listed in 73% of tech job postings
Highly regulated industries working to shape their AI implementation plans outpace other industries in the search for talent, according to Dice.
100
Securely Built @securelybuilt.bsky.social · 05/07/2026
File this under the very full folder of insane and creepy things that Meta has foisted upon us over the years. Meta will go down in history as one of the few companies in the world that has actively sought out to make the world a worse place. futurism.com/artificial-i...
futurism.com
Meta Operated a Secret Program That Paid Hundreds of Contractors to Pretend to Be Children and Teenagers While Having Disturbing Conversations With AI
Meta hired hundreds of contractors to pose as children and teenagers while asking chatbots like ChatGPT about suicide and even cannibalism.
000
Securely Built @securelybuilt.bsky.social · 30/06/2026
The US automaker hired over 350 veteran engineers, referred to internally as “gray beards”, over the past three years....[they] will lead quality reviews after the automation issues cost the company billions of dollars...while some workers will also help improve and train the AI systems.
the-independent.com
Ford hired AI and sacked humans. It backfired badly
‘We didn’t pay as much attention as we should have to the experience of our most knowledgeable engineers,’ says automaker
000
Securely Built @securelybuilt.bsky.social · 23/06/2026
Curious about #software #security? You can pick up a copy of the Application Security Handbook for half off tomorrow (June 23)! Remember that, software security is a fundamental skill for modern developers and is most effective when it's considered from the start, not added as an afterthought.
021
Securely Built @securelybuilt.bsky.social · 06/06/2026
After more than a decade in software development and AppSec, I've learned that you live and die by your test suite. Unit tests, integration tests, SAST, DAST....they exist to catch the thing that bites you later. Enter Promptfoo for LLM apps.
securelybuilt.substack.com
Unit Tests for LLMs: Catching Model Drift Before Your Users Do
A practical walkthrough of eval-driven development with Promptfoo, from local calibration to a CI merge gate.
000
Securely Built @securelybuilt.bsky.social · 05/06/2026
I am excited to join security executives from Cisco, Abbott, and Truist at Cycode's virtual Agentic Development Security Summit on July 14. Join me by signing up here: cycode.com/agentic-deve...
111
Securely Built @securelybuilt.bsky.social · 05/06/2026
If you're working with agentic coding tools, you're probably familar with "skills". These are self-contained, human-readable instruction sets (usually Markdown or YAML) that hand an agent new abilities it wouldn't otherwise have.
blog.trailofbits.com
The sorry state of skill distribution
We recently bypassed ClawHub’s malicious skill detector, Cisco’s agent skill scanner, and all three of the scanners integrated into skills.sh.
100
Securely Built @securelybuilt.bsky.social · 03/06/2026
This WIRED article reports that DHS and FBI are warning of 'anti-tech extremism' tied to AI backlash, citing over 1,000 pages of internal reports. What's a threat? "expressed/implied threat," "observation/surveillance," "photography," "testing/probing of security," and "attempted intrusion."
wired.com
US Law Enforcement Warns of ‘Anti-Tech Extremism’ as AI Hatred Grows
As Americans stew over the looming risk of job-stealing AI and data centers in their back yards, the feds are raising the alarm about a new category of threat, documents obtained by WIRED show.
100
Securely Built @securelybuilt.bsky.social · 02/06/2026
Reading through this, my mind kept going to how PAM works, but then quickly realized that this is slightly different. Where PAM focuses on "who" can use privilege credentials a credential broker focuses on "how" they can be used by an NHI that cannot even see them. infisical.com/blog/credent...
infisical.com
Credential Brokering for AI Agents, Explained | Infisial
A simple guide to credential brokering for AI agents: protect against prompt injection by keeping credentials away from the agent.
100
Securely Built @securelybuilt.bsky.social · 01/06/2026
For those of you with some time on your hands who are looking to contribute to the #cybersecurity community.
bleepingcomputer.com
Flipper One project needs community help to build open Linux platform
Flipper Devices, the maker of the Flipper Zero pentesting tool, is asking the community to help build Flipper One, an open Linux platform for connected devices.
000
Securely Built @securelybuilt.bsky.social · 21/05/2026
Master AppSec Leadership For Half Off Leverage this #holiday weekend to bridge the gap between development and security. Gain the frameworks needed to build resilient programs with industry standards on building an #appsec program. @manning.com #discounts #memorialday
020
Securely Built @securelybuilt.bsky.social · 17/05/2026
Not surprising..... While technical controls, and an AI governance board should help lower the risk, employees need to be trained on proper use and impacts of AI tools.
techcrunch.com
US bank discloses security lapse after sharing customer data with AI app | TechCrunch
Community Bank, which operates in Pennsylvania, Ohio, and West Virginia, disclosed a cybersecurity incident that exposed customers’ names, dates of birth, and Social Security numbers.
000
Securely Built @securelybuilt.bsky.social · 08/05/2026
While this is impacting #highereducation, there is not much any individual university could do to ward this off. This is the fragility of our #supplychain #security. www.bbc.com/news/article...
bbc.com
International cyber attack disrupts swath of universities and schools
A hacking group breached the academic software Canvas, used by thousands of schools and universities across the globe.
010
Securely Built @securelybuilt.bsky.social · 30/04/2026
Our software is a mix and match of 3rd parties, tools, and services that continue to expand the attack surface. If you need an example, CVE-2026-41940 was recently identified as a critical authentication bypass in cPanel & WHM (and WP Squared), with a CVSS score of 9.8.
rapid7.com
CVE-2026-41940: cPanel & WHM Authentication Bypass
On April 28, 2026, a critical vulnerability affecting cPanel & WHM and WP Squared was announced. CVE-2026-41940 is an authentication bypass bug with a CVSS score of 9.8, and exploitation in the wild h...
101
Securely Built @securelybuilt.bsky.social · 23/04/2026
securelybuilt.substack.com/p/appsec-did...
100
Securely Built @securelybuilt.bsky.social · 22/04/2026
DM me if you "know a guy" that can do this 🤣 I'm not sure this is the future we all wanted. But it's the one we're getting.
000
Securely Built @securelybuilt.bsky.social · 21/04/2026
Attackers don't break in, they login. That's always been true (and it's still the dominant initial access vector), but today with the added acceleration of AI enabled attack tools/platforms the results are much different. thehackernews.com/2026/04/no-e...
thehackernews.com
No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks
Stolen credentials remain top breach vector as AI speeds phishing and testing, increasing ransomware and persistence risk.
100
Securely Built @securelybuilt.bsky.social · 15/04/2026
"comment and control" = Injecting malicious instructions into PRs, leading an AI agent to execute them. Researchers found a way to steal API keys and access tokens from Claude Code, Gemini, and GitHub Copilot by using prompt injection in GitHub Actions. #aisecurity #devsecops #appsec
theregister.com
Anthropic, Google, Microsoft paid AI bug bounties – quietly
Exclusive: Researchers who found the flaws scored beer money bounties and warn the problem is probably pervasive
000
Securely Built @securelybuilt.bsky.social · 09/04/2026
If you’re building your cybersecurity career, this Humble Bundle should be high on your list. Ethical hacking, blue‑team tactics, malware analysis, cloud security....all in one bundle. Best part, as always with Humble Bundle, you'll be supporting a good cause.
humblebundle.com
000
Securely Built @securelybuilt.bsky.social · 27/03/2026
When Claude Code knows you better than you think:
000
Securely Built @securelybuilt.bsky.social · 20/03/2026
For those Trivy users out there (I'm among them).
stepsecurity.io
Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity
On March 19, 2026, trivy — a widely used open source vulnerability scanner maintained by Aqua Security — experienced a second security incident. Three weeks after the hackerbot-claw incident on Februa...
011
Securely Built @securelybuilt.bsky.social · 18/03/2026
Nice write up on the AWS Bedrock AgentCore Code Interpreter issue. #cybersecurity #risk #ai #aiagents
open.substack.com
A Popular AI Sandbox Has a Back Door (Since August!)
AWS Bedrock AgentCore Code Interpreter is powerful, managed, and isolated. It also talks to the internet over DNS. Here's why that’s a concern.
000
Securely Built @securelybuilt.bsky.social · 17/03/2026
Vulnerabilities in #Amazon Bedrock’s AgentCore Code Interpreter, LangSmith, and SGLang allow attackers to exfiltrate data and even achieve remote code execution (RCE) by abusing DNS queries, weak isolation boundaries, and misconfigured authentication flows. #cybersecurity
thehackernews.com
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE
DNS flaw in Amazon Bedrock and critical AI vulnerabilities expose data and enable RCE, risking breaches and infrastructure compromise.
001
Securely Built @securelybuilt.bsky.social · 15/03/2026
How does enabling E2EE make users "less safe"? The claims are that reduces the ability to "detect illegal activities, such as child sexual abuse material or terrorist propaganda, and flag them to law enforcement." It seems like those cases are already public on these platforms w/wo encryption.
thehackernews.com
Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026
Meta will end Instagram E2EE chats May 8, 2026, reversing a 2021 privacy test and reigniting debate over encrypted messaging oversight.
001
Securely Built @securelybuilt.bsky.social · 10/03/2026
Fact or fiction? programs.com/resources/op...
programs.com
How Many Cybersecurity Job Openings Are There? (Mar 2026) - Programs.com
Cybersecurity continues to be one of the fastest-growing sectors, with millions of job openings worldwide. Global demand for cybersecurity professionals has surged, driven by rising threats and expand...
000
Securely Built @securelybuilt.bsky.social · 10/03/2026
Check out yesterday's Department of Know.
youtube.com
Department of Know: March 9, 2026
YouTube video by CISO Series
000
Securely Built @securelybuilt.bsky.social · 06/03/2026
Making updates to some of my #training courses when I pick up faint snoring in the background. Yes, she snores. Should I go to HR about my coworker who sleeps 16 hours a day. If you're looking for some training on AppSec see the link below in the comments. #appsec #cybersecurity
100
Securely Built @securelybuilt.bsky.social · 04/03/2026
Burning the midnight oil is what we used to call it. Today, it's 10.8 extra hours per week. That's what cybersecurity professionals are averaging beyond their contracted schedules, according to new survey data. Nearly half are logging 11+ overtime hours weekly. One in five is pushing past 16.
helpnetsecurity.com
Cybersecurity professionals are burning out on extra hours every week - Help Net Security
Cybersecurity workforce burnout is accelerating as AI governance demands grow, training lags, and leaders work nearly 11 extra hours a week.
000
Securely Built @securelybuilt.bsky.social · 03/03/2026
"Across every domain — land, air, sea, cyber — the U.S. Joint Force delivered synchronized and layered effects." That's the Chairman of the Joint Chiefs publicly putting cyber operations on equal footing with traditional warfare in the Iran conflict. #cybersecurity #nationstate #cyberwarfare
theregister.com
Top general spotlights cyber role in Iran conflict
: No more hiding in the server closet: Cyber ops mentioned alongside kinetic warfare as critical to conflict
000
Securely Built @securelybuilt.bsky.social · 25/02/2026
The "everyone else is doing it, so why not us" argument. The collective action problem has always existed. Why unilaterally disarm if others won't. Even when you know the risks of doing so are plentiful and potentially catastrophic.
time.com
Anthropic Drops Flagship Safety Pledge
In an abrupt shift, the company may release future AI models without ironclad safety guarantees
000
Securely Built @securelybuilt.bsky.social · 24/02/2026
User compromise still reigns supreme when it comes to cyberattacks. #socialengineering #cybersecurity thehackernews.com/2026/02/unso...
thehackernews.com
UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors
UnsolicitedBooker targets Central Asian telecoms with LuciDoor and MarsSnake, while PseudoSticky and Cloud Atlas hit Russia.
000