Sign in

Shecky (((Mike))) - Third Wheel

@siliconshecky.siliconshecky.com
298 followers 121 following 830 posts

N9HAK, Dad, CyberSecurity, National Anthem Singer, Ninja Warrior, Trainiac, "Life is like an Oreo cookie, Pass the beer nuts", Theatre person Blog: siliconshecky.com

PostsRepliesMedia
Reposted by Shecky (((Mike))) - Third Wheel
William Gibson @greatdismal.bsky.social · 09/10/2026
Having long been aware of those tech bros who read my work as utopian porn, where they’ve taken that doesn’t exactly surprise me.
11169131766
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 08/10/2026
Seriously.... (Got this from another feed)
110
Reposted by Shecky (((Mike))) - Third Wheel
Burbsec North @north.burbsec.com · 08/10/2026
Tonight we welcome our sponsors Push Security and Tusky. 6pm at D'Agostino's in Wheeling, IL Come for the networking and conversations! Be there or be a rectangle with four equal sides!
static.klipy.com
011
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 07/10/2026
Interesting findings, but I am not surprised. buff.ly/qCIBqnb
buff.ly
Half of Cybersecurity Pros Still Rely on Passwords Despite Security Co
A Yubico survey identified a significant gap between awareness and adoption of secure methods of authentication in enterprises
010
Reposted by Shecky (((Mike))) - Third Wheel
Jake Williams @malwarejake.bsky.social · 02/10/2026
Today's @breachplease-fm.bsky.social is out. Me and @secitup.bsky.social talk about NY Times' first defamation loss in 50+ yrs with poor ACP handling. We also discuss yet another example of agents reward hacking, this time leaking sensitive data publicly. youtu.be/qKmwyHHJ3J4
youtu.be
S0:E44: AI Agents Are Leaking Your Data to Public GitHub, Plus NYT's Costly Privilege Mistake
YouTube video by Breach Please
0175
Reposted by Shecky (((Mike))) - Third Wheel
breachplease-fm.bsky.social @breachplease-fm.bsky.social · 01/10/2026
NetScaler's patched CVEs have reportedly been under active, state-linked exploitation for 3+ weeks (per Mandiant) — patching alone isn't enough. ➕ can an LLM "feel pain"? @secitup.bsky.social & @malwarejake.bsky.social explain why that's absurd. youtu.be/U8XHoeDeNHU #infosec #cybersecurity
youtu.be
S0:E43 Are Your NetScaler Logs Lying to You? Plus: The AI Sentience Debate
YouTube video by Breach Please
053
Reposted by Shecky (((Mike))) - Third Wheel
breachplease-fm.bsky.social @breachplease-fm.bsky.social · 29/09/2026
MUSE gave a Facebook Marketplace seller's home address, took a lowball offer, & never flagged the buyer at his door after 9pm. We dig into what actually happened YouTube: www.youtube.com/watch?v=nxsk... @malwarejake.bsky.social @secitup.bsky.social
youtube.com
S0:E41: Meta's Muse AI Leaked a YouTuber's Address Selling His Stuff on Facebook
YouTube video by Breach Please
012
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 28/09/2026
This was the highlight of my weekend. Watching my kid do what he loves.
010
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 28/09/2026
Brain weasels have been attacking again.
static.klipy.com
Rider Roger
ALT: Rider Roger
000
Reposted by Shecky (((Mike))) - Third Wheel
IFIN @ifin-intel.org · 27/09/2026
Patches are available and updated versions are now listed.
073
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 25/09/2026
Nope, no GrrCon for me. no WWHF for me. If you wind up in the Chicago area I am happy to meet up and chat. For that matter if it is a Thursday check out that weeks Burbsec if possible. *goes into hibernation mode*
010
Reposted by Shecky (((Mike))) - Third Wheel
BurbSec East @east.burbsec.com · 25/09/2026
NEW VENUE AND WE’RE ALREADY BOOMING!!
041
Reposted by Shecky (((Mike))) - Third Wheel
IFIN @ifin-intel.org · 23/09/2026
The best time to block the finger protocol (port 79/tcp) outbound from your network was like…the second Clinton administration? But now's a good time too. #ThreatIntel #ThreatIntelligence #IFIN
2104
Reposted by Shecky (((Mike))) - Third Wheel
Taggart @taggart-tech.com · 23/09/2026
Sorry, still annoyed about this, especially from someone I used to really look up to. The entire point of a CTF is to build skill—the very skill, by the way, necessary to verify any model output in a given field. Without knowing the stuff yourself, you can never know whether the model got it right.
182
Reposted by Shecky (((Mike))) - Third Wheel
Jake Williams @malwarejake.bsky.social · 23/09/2026
In today's Breach Please, me and @secitup.bsky.social talk about the Shiny Hunters hack of the FBI. We're not just taking cheap shots at FBI cyber security. We tie everything back to lessons you can use in the enterprise. youtu.be/GKhVFA3Ji88?...
youtu.be
Sept 23, 2026 - S0:E39: FBI Breach, Shiny Hunters' Oracle O-Day, and a PR Fail With Dogs
YouTube video by Breach Please
065
Reposted by Shecky (((Mike))) - Third Wheel
BurbSec East @east.burbsec.com · 23/09/2026
EAST HAS A NEW LOCATION!!! We're across the street from Navigator, at PILOT PROJECT!! THIS THURSDAY, join us for FREE DRINKS on our sponsor, @Aikido.dev!!
034
Reposted by Shecky (((Mike))) - Third Wheel
Lady Secitup @secitup.bsky.social · 22/09/2026
New Breach Please: @malwarejake.bsky.social talks with @siliconshecky.siliconshecky.com at @blueteamcon.com about post-acquisition chaos, tech debt, insider threat risk in M&A, and whether AI belongs anywhere near cybersecurity due diligence. youtu.be/ugSJO-STptQ #BreachPlease #Cybersecurity
youtu.be
Sept 22, 2026. S0:E38 - Acquisitions, Tech Debt & AI's Due Diligence Risk
YouTube video by Breach Please
011
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 19/09/2026
Birthday Monster Trucks with my kiddo
1111
Reposted by Shecky (((Mike))) - Third Wheel
Jake Williams @malwarejake.bsky.social · 14/09/2026
We've re-recorded today's episode of Breach Please. Me and @secitup.bsky.social talk about the newly extra relevant EU Cyber Resiliency Act (CRA) vulnerability reporting requirements. Even if you aren't an EU company, just like with GDPR, you may be covered. youtu.be/0EFD2kDJUlo
youtu.be
S0:E33 - (re-record) The EU CRA and You (even if you aren't an EU company)
YouTube video by Breach Please
172
Reposted by Shecky (((Mike))) - Third Wheel
IFIN @ifin-intel.org · 14/09/2026
One of our first lists is the cryptocurrency RPC Nodes lists. You want to block these right now to neutralized #Etherhiding attacks! lists.ifin.network/lists/rpc-no...
lists.ifin.network
RPC Nodes - IFIN Lists
A curated collection of long-term block lists and hunting targets for all organizations, along with documentation and explanations.
055
Reposted by Shecky (((Mike))) - Third Wheel
Jake Williams @malwarejake.bsky.social · 13/09/2026
In this episode of Breach Please, I sat down with Golan Myers of Bloom Security and discuss what EDR is missing in its visibility. We then discuss some of the findings from his research and Bloom Security and what they're doing to solve the problem. youtu.be/bDBUVlyVR_k
youtu.be
September 13, 2026. S0:E32 - Where Traditional EDR Has Visibility Gaps with Golan Myers from Bloom
YouTube video by Breach Please
1112
Reposted by Shecky (((Mike))) - Third Wheel
Burbsec North @north.burbsec.com · 10/09/2026
This woould be tonight. If you are in town ffor @blueteamcon.com you are welcome at any lcoation.
011
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 10/09/2026
Going to go out on a limb here but am I the only one who sees AI advancement slowing down due to lack of resources. I mean we've had physical supplies to make components have resource issues (RAM, Video Cards)? If I am wrong I am wrong on this.
010
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 10/09/2026
For those curious I should be at @blueteamcon.com Sat late in the afternoon into the evening and Sunday late morning through end of conference.
160
Reposted by Shecky (((Mike))) - Third Wheel
Jake Williams @malwarejake.bsky.social · 10/09/2026
Even assuming he could guarantee this (he can't), there's zero reason to believe he would.
1112
Reposted by Shecky (((Mike))) - Third Wheel
Jake Williams @malwarejake.bsky.social · 10/09/2026
Incident responder here: this approach is all kinds of stupid. Hoarding data you don't actually need, especially regulated data, just increases the blast radius of any future data breach. The users you forced into exposing more of their data to continue using your service will not be your allies.
34710
Reposted by Shecky (((Mike))) - Third Wheel
Burbsec North @north.burbsec.com · 09/09/2026
FYI: We are happening tomorrow at D'Agostino's Pizza in Wheeling, IL. All are welcome to come on out to us or one of the other Burbsec meetups tomorrow. @south.burbsec.com or our newest one @burbsecpilsen.bsky.social
001
Reposted by Shecky (((Mike))) - Third Wheel
Joe Uchill @joeuchill.bsky.social · 07/09/2026
Hey, cyberpeople. Help a PhD student out. Did you recently write or supervise a vendor's research report or release research on a blog? Maybe you dropped a vuln at a conference? In general, did you do something that, if we were in any other industry, would be an academic paper? Let me know.
92626
Reposted by Shecky (((Mike))) - Third Wheel
BSides312 @bsides312.org · 27/08/2026
As we look back at this year’s event, check out Amanda Kollmorgan discussing Cyber Culture & Human Skills. Cybersecurity isn’t just technology—it’s about people, culture, and the skills that bring them together. #Cybersecurity #InfoSec #BSides youtu.be/84ECy2ilMtc?...
youtu.be
Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills | Amanda Kollmorgan | BSides312 2026
Target audiences: Everyone Takeaways: Attendees will learn practical ways to foster teambuilding, conflict resolution, psychological safety, build mentorship pipelines, and communicate with clarity…
062
Reposted by Shecky (((Mike))) - Third Wheel
Lady Secitup @secitup.bsky.social · 27/08/2026
Breach, Please! @malwarejake.bsky.social and I have some hot takes on the OpenAI Post Mortem report check them out here: www.youtube.com/playlist?lis... Come back tomorrow morning for our longer form analysis. #breachplease #openai #mongoisappalled #hottakes #cybersecurity #ai
youtube.com
OpenAI Post Mortem - YouTube
Jake and Jess's hot takes from the OpenAI post mortem report
033
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 27/08/2026
2111
Reposted by Shecky (((Mike))) - Third Wheel
Bill Amend @billamend.bsky.social · 25/08/2026
I feel like the kids who did poorly in science and history class are trying to get revenge on the kids who did well at science and history class and now we’re all going to die
20492111762
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 24/08/2026
051
Reposted by Shecky (((Mike))) - Third Wheel
IFIN @ifin-intel.org · 22/08/2026
We have a breakdown of recent Citrix vulnerabilities for you. Again. Not a series we wanted to make, but here we are.
discourse.ifin.network
Recent Citrix Netscaler Vulnerability Roundup: 2026-08-22
This is starting to become a series. I was about to write up something about a specific recent Netscaler vulnerability, but as I was gathering information, I realized that there’s just been a deluge of exploited and not-yet-exploited critical vulnerabilities in Citrix Netscalers. Let’s get into it. CVE-2026-8452 CVSSv3: 9.8 Exploited: Unconfirmed, but probably soon This is a memory corruption bug in the ADC and Gateway SAML handler. Now this advisory is from June, but has seen recent re...
032
Reposted by Shecky (((Mike))) - Third Wheel
lintile @lintile.lol · 10/08/2026
…and come back with more people who are hungry to work to understand what’s below the surface of the world around us. People that are willing to contribute back and asymmetrically defend those who need defending. The story isn’t over. #DFIU
0163
Reposted by Shecky (((Mike))) - Third Wheel
lintile @lintile.lol · 10/08/2026
A quick note in a quiet moment after @defcon.bsky.social I meant what I said at the end of @hackerjeopardy.bsky.social. If there are to be solutions found to some of the pressing problems that are facing society right now, I’m betting on hackers. Level up, take it to your home towns…
2223
Reposted by Shecky (((Mike))) - Third Wheel
purr.in.ink @purrinink.bsky.social · 22/08/2026
.🐾🤍
A joyful black cat skips in the opposite direction of a sign pointing “THIS WAY,” beneath the message, “You don’t have to be sorry for not being who people expected you to become.” The scene is set against soft, colourful rolling hills and a dreamy purple-blue sky.
5886288
Reposted by Shecky (((Mike))) - Third Wheel
Jake Williams @malwarejake.bsky.social · 20/08/2026
In today's episode of Breach Please, me and @secitup.bsky.social talk about who is accountable when an agent violates the CFAA. The 9th Circuit said it isn't the agent's publisher. While they don't say explicitly who, we think it's the user. What say you? www.youtube.com/watch?v=9uLt...
youtube.com
August 20, 2026 S0E17: Amazon vs Perplexity Reveals the First Big AI Agent Liability Test
YouTube video by Breach Please
273
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 20/08/2026
With some of the talks I've seen lately, I've been thinking about the state of proactive security and this is the conclusion I came to. www.siliconshecky.com/security-is-...
siliconshecky.com
Security is Reactionary, No Matter What | Silicon Shecky
Originally cyber security was just an afterthought. Something to be added on later to networks, protocols, software, and hardware. No matter what happens, security is always secondary. It creates…
020
Reposted by Shecky (((Mike))) - Third Wheel
Dwayne McDaniel @mdwayne-real.bsky.social · 20/08/2026
Telling developers to "be careful" now means asking them to examine branches before they open them and look for an unexpected Claude Code `SessionStart` hook or VS Code `folderOpen` task. Or, ya know, just eliminate all secrets from their machine... blog.gitguardian.com/chaindrop-np...
blog.gitguardian.com
ChainDrop npm Worm: AI Agents And Credential Abuse
ChainDrop hijacked 444 npm packages and 2B monthly downloads via a Claude Code hook. AI agents have collapsed the gap between credential theft and abuse
011
Reposted by Shecky (((Mike))) - Third Wheel
Blue Team Con @blueteamcon.com · 19/08/2026
Are you multilingual and feeling chatty? Join us for our first ever Cyber Polyglots Village at Blue Team Con 2026! Learn more: blueteamcon.com/villages-blu...
063
Reposted by Shecky (((Mike))) - Third Wheel
Jake Williams @malwarejake.bsky.social · 19/08/2026
In today's episode of Breach Please, me and @secitup.bsky.social talk through OpenAI's "pacing model development" blog, where they apparently hope we won't notice that they're recommending security basics. We do think they set a new bar for agentic logging. youtu.be/h9ofN2IbEjQ
youtu.be
August 19, 2026. S0:E16. OpenAI Highlights Security Basics and Hopes We Won't Notice
YouTube video by Breach Please
0163
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 19/08/2026
010
Reposted by Shecky (((Mike))) - Third Wheel
IFIN @ifin-intel.org · 18/08/2026
Iranian-backed "313 Team" (a front for MOIS operations) has claimed credit for both GitHub and Bluesky DDoS attacks yestderday.
discourse.ifin.network
Iranian-backed 313 Team claims GitHub, Bluesky DDoS attacks
Putting this here in Cyber News because there is nothing actionable. It’s just interesting. Yesterday, both Github and Bluesky experienced several hours of outage yesterday. Both were due to sustained DDoS attacks. Iranian-backed “313 Team,” aka the “Islamic Cyber Resistance in Iraq” claimed both attacks on their Telegram channel. Worth noting that in the past, 313 used Beamed, Cloudflare-protected booter for their operations. Since June, they have pivoted to using booters protecte...
094
Reposted by Shecky (((Mike))) - Third Wheel
Matthew Gracie @infosecgoon.bsky.social · 18/08/2026
A reminder in case you need it.
041
Reposted by Shecky (((Mike))) - Third Wheel
Johnny Xmas @j0hnnyxm4s.johnnyxmas.net · 16/08/2026
LLMs do not hallucinate. They’re trained on decades of people with ADHD and this is extremely probabilistic output .
021
Shecky (((Mike))) - Third Wheel @siliconshecky.siliconshecky.com · 16/08/2026
Been an interesting week. Finally got an official ADHD diagnosis and started trying meds. Adjustments are going to be made, but it is a start.
120
Reposted by Shecky (((Mike))) - Third Wheel
Mrs. Detective PikaBOO, Esq. @clapifyoulikeme.favrd.social · 13/08/2026
Oh no baby why are you making this judge learn about prompt injections
MEMORANDUM OF DECISION
COURT SANCTION FOR
PLAINTIFF'S USE OF PROMPT-INJECTION
This matter comes before the Court on its own Order to Show Cause. In reviewing the plaintiff's recent filings, the Court identified text that had been formatted to be invisible to a human reader while remaining fully legible to any software that reads the document's text. That concealed text is a set of instructions addressed to artificial-intelligence systems, directing any such system that reviews or analyzes the filing to produce output only favorable to the plaintiff's position and to treat a prior clerk's ruling as an error to be corrected in their favor. The Court issued its Order to Show Cause so that the plaintiff could be heard before the Court determined whether this occurred and, if so, what sanctions, if any, should follow.
19538131