Securely Built @securelybuilt.bsky.social · 28/09/2026Cybersecurity awareness month is almost here, don't forget to check in on your passwords! 000
Securely Built @securelybuilt.bsky.social · 26/09/2026If you're thinking about going beyond a Sec+ cert then take a look at this exam prep course: CompTIA CySA+ Exam Prep with Hands-On Labs Bonus: it's on sale at Udemy for the next 5 days if you use this coupon code: www.udemy.com/course/compt...udemy.comCompTIA CySA+ Exam Prep with Hands-On LabsThreat detection, vulnerability management, incident response and reporting, with 160 practice questions and 4 labs 000
Securely Built @securelybuilt.bsky.social · 24/09/2026So if you're thinking about a career in cyber, don't sleep on GRC. 000
Securely Built @securelybuilt.bsky.social · 24/09/2026GRC is one of those areas that is often overlooked when people think about roles most likely because it hasn't been glorified in the same ways that other roles have been. But guess what....those GRC roles are increasing and hold the top position in terms of demand. 100
Securely Built @securelybuilt.bsky.social · 24/09/2026I've spent a lot of time mentoring people who are looking to get into cybersecurity. And a lot of that time has been in convincing them that there is way more to cyber than what they believe.udemy.comGRC Fundamentals - Learn Governance, Risk, and ComplianceBuild a Unified Framework for Smarter Governance, Proactive Risk Management, and Sustainable Compliance 100
Securely Built @securelybuilt.bsky.social · 16/09/2026www.csoonline.com/article/4222...csoonline.comYou don’t have to join the hack-back program to inherit its riskWashington's new private offensive cyber program gives vetted vendors an untested criminal shield while leaving substantial residual risk in private hands. Underwrite that exposure before the operatin... 000
Securely Built @securelybuilt.bsky.social · 16/09/2026I mean, we're talking about the same organizations who are chronically understaffed/overworked just to keep up with the current cyberattacks and attack surface management. What a time to be alive. 000
Securely Built @securelybuilt.bsky.social · 16/09/2026On the bright side, I'm sure we're about to see a cottage industry of "hack-back" groups being contracted by companies who sign up for this. 100
Securely Built @securelybuilt.bsky.social · 16/09/2026Attribution is already tricky and this will open commercial infrastructure and resources to retaliatory attacks. So if you're in the banking industry and one of your peers joins this program, you're now likely in the cross-hairs for retaliation. Talk about an increase of attack surface. 100
Securely Built @securelybuilt.bsky.social · 16/09/2026What happens when a participating organization performs an offensive operation in foreign territory that is deemed a national security threat to the target? 100
Securely Built @securelybuilt.bsky.social · 16/09/2026Perhaps an oversimplification, but this can be viewed as the continued privatization of responsibility that should reside at the government level under the guise of "consumer protection" (yes, billions are lost a year in cyber-crime). 100
Securely Built @securelybuilt.bsky.social · 16/09/2026And if I read this right, a company can sign up, ask for permission to "hack-back", receive sign-off from the DoJ, and then....go hacking. What could possibly go wrong. 100
Securely Built @securelybuilt.bsky.social · 16/09/2026From the Department of Duh: "You don’t have to join the hack-back program to inherit its risk" A few weeks ago, the US Executive Branch decided to direct the National Coordination Center to build a program for companies to join a offensive cyber program. 200
Securely Built @securelybuilt.bsky.social · 10/09/2026Maybe it's time to think about attack surface budget (not just technical debt), and how we keep it as small as possible while still rendering services. Otherwise, we'll continue to have explosive CVE numbers and patching requirements that outpaces our ability to patch in a timely and safe manner. 100
Securely Built @securelybuilt.bsky.social · 10/09/2026without removing things that are no longer needed, used or accessed and all you are doing is building a bigger attack surface for defenders to defend and attackers to take advantage of. Even worse, almost half were elevation of privilege flaws giving the attacker admin/system-level access. 100
Securely Built @securelybuilt.bsky.social · 10/09/2026That brings the total number of patches released this year to over 2,600, more than double their previous record. I've been talking a lot about attack surface in my classes over the past two weeks, and the bottom line is this: add more components, software, hardware, SaaS, cloud services, etc... 100
Securely Built @securelybuilt.bsky.social · 10/09/2026The cycle never ends..... Microsoft has released its biggest ever patch update, addressing 974 security vulnerabilities across its Windows operating systems and other software. This massive update, which surpasses their previous record of 570 vulnerabilities fixed in July. 100
Securely Built @securelybuilt.bsky.social · 03/09/2026@manning.com is running their annual Labor Day Sale. It's your chance to grab some titles for a great price! Half off all books $10 liveProjects/ liveVideos $199.99 Subscriptions Annual team subscriptions are 20% off Pick up "The Application Security Program Handbook" while you're there! 110
Securely Built @securelybuilt.bsky.social · 01/09/2026While the goals haven't changed, the methods certainly have. And teaching this topic throughout the school year is never boring. Who knows, maybe one day I’ll be putting up an idea from a current student on this board😀 000
Securely Built @securelybuilt.bsky.social · 01/09/2026Fast forward to today, and it's lightyears ahead of that. We have more tools, processes, and technology available to us to find security vulnerabilities to our hearts content. And by the time I was done drawing this board, there were likely new techniques and tactics being born somewhere far away. 100
Securely Built @securelybuilt.bsky.social · 01/09/2026Back in the old days of AppSec, when we had to walk uphill in the snow (both ways) to work, we essentially had a beast of a SAST product, some code review, and penetration testing at our disposal for testing the security of an application. 100
Securely Built @securelybuilt.bsky.social · 01/09/2026I've done variations of this drawing so many times over my teaching career, and each time it gets more complex. 100
Securely Built @securelybuilt.bsky.social · 26/08/2026Security strategies have always needed to focus on rapid patch deployment and real-time mitigation to stem the risk of rapid exploitation. Or.....we can just test in prod 😀 000
Securely Built @securelybuilt.bsky.social · 26/08/2026The objective is not to avoid patching but to create a meaningful layer of defense during the period when patching has not yet been completed. Again, MS is not breaking any ground with that viewpoint, but perhaps just putting into a different framing. 100
Securely Built @securelybuilt.bsky.social · 26/08/2026But, and I hope you're sitting down, most large enterprises don’t have one accurate view of their own systems, making it difficult to respond swiftly. 100
Securely Built @securelybuilt.bsky.social · 26/08/2026So now what? Defense has always required accurate asset inventories, exposure mapping, traffic visibility, application context, and centralized policy enforcement but now that needs to be available at a moments notice to make mitigation decisions while patches are tested and deployed. 100
Securely Built @securelybuilt.bsky.social · 26/08/2026With security research, public disclosures, proof-of-concept exploits, and threat intelligence circulating attackers are able to leverage this information to build PoCs and deploy exploits rapidly meaning that vulnerabilities become a threat almost immediately after they are discovered. 100
Securely Built @securelybuilt.bsky.social · 26/08/2026The issue? Vulnerabilities are now 'more visible, more widely distributed, and more rapidly weaponized than ever before.' and attackers are able to exploit vulnerabilities within hours, while many enterprises still require a release pipeline that can take weeks to test and deploy code/patches. 100
Securely Built @securelybuilt.bsky.social · 26/08/2026Defense in depth.....what a concept! No surprise to many, but Microsoft is declaring that the window for patching vulnerabilities is shrinking, and urging enterprises to adopt network-level containment strategies.csoonline.comMicrosoft warns patch window is collapsing, urges shift to network-level containmentAzure networking executive Igor Sakhnov says enterprises must reduce exposure before patches are deployed as attackers outpace remediation. 100
Securely Built @securelybuilt.bsky.social · 19/08/2026As with STRIDE, using this mnemonic to ask basic questions about your system/app can take just a few minutes to identify threats and form controls to reduce the overall risk. It’s not enough to secure the entire system, but it’s a start. Happy threat modeling! shostack.org/files/papers...shostack.org 000
Securely Built @securelybuilt.bsky.social · 19/08/2026 👉 Missing security engineering - Forgoing basic security controls and testing for the sake of speed. 👉 Biases - Inheriting the bias of the LLM training data. 100
Securely Built @securelybuilt.bsky.social · 19/08/2026 👉 Non-explainability - When your LLM is a core decision maker, it needs to be able to explain it output/actions. 👉 Training issues - Garbage in/Garbage out 👉 Over-reliance on the LLM - Handing over critical thinking to the LLM and shirking responsibilities as the human-in-the-loop. 100
Securely Built @securelybuilt.bsky.social · 19/08/2026 👉 Prompt injection - Similar to injection attacks with WebApps, prompt injection attempts to bypass the LLMs guardrails through confusing input. 👉 Hallucination - Where the model outputs information that is at odds with facts. 👉 Anthropomorphization - Attributing human traits to the LMM. 100
Securely Built @securelybuilt.bsky.social · 19/08/2026PHANTOM-B attempts to apply the same quick approach that can be useful with STRIDE. A 15 minute conversation to identify a set of threats that can be a starting point for managing the risk. And, as with STRIDE, PHANTOM-B is a mnemonic: 100
Securely Built @securelybuilt.bsky.social · 19/08/2026Worse, there is no direct coverage in STRIDE for systems that are non-deterministic and talk to LLMs. But help is coming. Along with Microsoft’s AI threat modeling recommendations, NIST’s Generative AI Profile, and OWASP’s Top 10 for LLMs, we now have PHANTOM-B from Adam Shostack 100
Securely Built @securelybuilt.bsky.social · 19/08/2026Remember STRIDE? For decades, STRIDE has been the process for identifying and labeling threats in a system. It’s worked for decades to model threats. But it’s slow, it doesn’t scale well, and there is little standardization around process/tools outside of “use STRIDE”. 100
Securely Built @securelybuilt.bsky.social · 11/08/2026"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety" Can we please stop pretending that any of these devices are safe for any of us to use.digitaltrends.comKids’ smartwatches are meant to keep children safe, but hackers can turn them into stalking devicesA $30 kids' smartwatch let researchers secretly track a wearer's location, snap photos, and record audio, exposing a much larger flaw shared across dozens of GPS smartwatch brands worldwide. 000
Securely Built @securelybuilt.bsky.social · 03/08/2026And according to the European Data Protection Board’s own guidance, lack of a robots.txt file does not amount to consent. The real question is whether OpenAI redacts sensitive data before collection as is expected and best practices. 010
Securely Built @securelybuilt.bsky.social · 03/08/2026It’s not clear from the article whether robots.txt or ai.txt files was there and configured correctly, but this should be a reminder that we have a simple mitigation that should be used to shape how these crawlers can access web sites.heise.deuniVersa: OpenAI AI crawler accessed customer datauniVersa insurance companies experienced data protection incident. An AI crawler accessed customer data, including names, addresses, in some cases, bank details. 100
Securely Built @securelybuilt.bsky.social · 30/07/2026Head over to Manning.com. for their summer sale and grab a copy of the Application Security Program Handbook while you're at it! 000
Securely Built @securelybuilt.bsky.social · 28/07/2026Correct, but it sounds like just running GrapheneOS is enough to raise suspicion. Land of the free.... 000
Securely Built @securelybuilt.bsky.social · 27/07/2026If you're trying to break in and your background looks nothing like a "cyber person," that's not the disqualifier you think it is. It might be the thing that makes you worth a second look. 000
Securely Built @securelybuilt.bsky.social · 27/07/2026We keep trying to build a factory that turns out identical security graduates. It doesn't work. Everyone I know in this field fell into it through some specific, un-repeatable sequence of jobs and curiosity (feel free to tell me I'm wrong). 100
Securely Built @securelybuilt.bsky.social · 27/07/2026Eventually I was running product security teams. What did that path teach me? There is no straight line into cybersecurity. I've never met two people who took the same one. 100
Securely Built @securelybuilt.bsky.social · 27/07/2026I started in a kitchen. Ten years, thinking I'd be a chef. Then hardware engineering. Then a CS degree and software. Then, sitting one desk away from the application security team in a healthcare company, I got curious enough to change everything again when I pursued my master's in cyber.youtube.comYour Cybersecurity Career Has No Straight Path #careeradvice #cybersecurity #infosecYouTube video by The Decloaked Podcast 100
Securely Built @securelybuilt.bsky.social · 26/07/2026Not enough evidence here to make a judgement call, but if you are being asked to handover and unlock your phone without any reason, that to me seems like the right time to brick it. As brittle as it seems right now, we do have some constitutional rights left in the US.androidauthority.comGrapheneOS duress PIN could land a man in prisonA US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border search. 100
Securely Built @securelybuilt.bsky.social · 22/07/2026With technology changing as rapidly as it is, employers are not looking for someone that can mentally reverse a string with C++ code, but someone that can think about problems, provide viable solutions, and communicate them effectively to a team. 000
Securely Built @securelybuilt.bsky.social · 22/07/2026For those looking to advance their careers, this signals a need for continuous learning and flexibility while trying to advance technical skills and cultivate the "softer" skills such as: Communication Strategic thinking Problem solving Adaptability 100
Securely Built @securelybuilt.bsky.social · 22/07/2026Michael Carney (president of the chamber) put it bluntly as a 'mismatch' in the labor market where employers can’t find workers with the right skills, while young people struggle to find clear paths into the workforce. Sound familiar? 100