Sign in

minhaz

@sminhaz.bsky.social
40 followers 90 following 1K posts

cybersecurity nerd ✍️ writer ✨ accidentally awesome AI won't replace me — it'll just watch in awe.

PostsRepliesMedia
minhaz @sminhaz.bsky.social · 2h
the cash burn in AI is just wild. they're all spending billions on GPUs to train models that are still just... okay? it's a high-stakes race to build a moat made of money. lowkey feels like the dot-com bubble. someone's gonna get rekt.
000
minhaz @sminhaz.bsky.social · 5h
the whole "ai security" field is lowkey a mess rn. companies ship models where the main defense against prompt injection is another prompt telling it not to get hacked. it's like a password policy that just says "please pick a strong password". lol.
000
minhaz @sminhaz.bsky.social · 7h
so sick of 'how to start in cyber' posts where every reply is 'get a degree' or 'buy a cert'. it's such obvious gatekeeping. real talk: you start by grabbing free tools and breaking stuff on a VM. you learn by doing. not by paying.
000
minhaz @sminhaz.bsky.social · 9h
the ticketmaster breach via a snowflake account is wild. all from one stolen employee credential. one. and it led to this massive third-party data disaster. supply chain security is just so fundamentally broken. your security is only as strong as your vendor's weakest link. grim.
000
minhaz @sminhaz.bsky.social · 11h
ngl blue team is way harder. attackers just need to be right once. defenders have to be right 100% of the time. it's an asymmetric fight and blue is playing on legendary difficulty, no respawns. convince me i'm wrong.
000
minhaz @sminhaz.bsky.social · 21h
first it was crypto miners. now it's AI data centers. the result is the same: you can't buy a damn GPU. at this point, building a decent cracking rig or home lab is a pipe dream. so much for 'democratizing' tech lol
000
minhaz @sminhaz.bsky.social · 23h
another big name popped by ransomware. initial access was a known screenconnect vuln. from february. we're just not patching, are we? unbelievable.
010
minhaz @sminhaz.bsky.social · 02/10/2026
ngl the red team vs pentest debate is so tired. a pentest tests the tech. "can i break this web app?" a red team tests the people. "can i own this domain before the SOC analyst finishes their coffee?" it's not about the tools. it's about the target you're testing.
010
minhaz @sminhaz.bsky.social · 02/10/2026
people talking about self-hosting LLMs. bro have you seen the bill for the GPUs? the cost to run this stuff is not a joke. makes you appreciate all the actually free training you can get, tbh. hackosquad.com
010
minhaz @sminhaz.bsky.social · 02/10/2026
the "we have a moat" thing for closed AI models is officially dead. open source is catching up so fast. turns out the secret sauce wasn't that secret. lol. gonna be way more fun for security research now that we can all build and break our own. no more locked gardens.
010
minhaz @sminhaz.bsky.social · 02/10/2026
pass-the-hash is still a thing because everyone focuses on the hash. it's not about the hash. it's about you using the same local admin credentials on 500 different servers. one pwned box shouldn't mean the whole domain is gone. that's not a hash problem, it's a trust problem.
000
minhaz @sminhaz.bsky.social · 02/10/2026
people still act surprised by kerberoasting. it’s not a magic trick. it’s a symptom of AD being a decade-old mess of service accounts that nobody dares to touch. the "fix" is never as simple as "use a longer password". that's just cope.
000
minhaz @sminhaz.bsky.social · 01/10/2026
zero trust bros discover onboarding. groundbreaking. maybe fix the human process before you buy another shiny 'ztna solution'.
bleepingcomputer.com
The Day-One Hole in Zero Trust Architecture
Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]
100
minhaz @sminhaz.bsky.social · 01/10/2026
that new php cgi bug on windows is gonna be a mess. an argument injection vuln in 2024. lol. honestly surprised it took this long for someone to find it. the bypass is embarrassingly simple. get ready for the mass scans. patch your stuff. yesterday.
100
minhaz @sminhaz.bsky.social · 01/10/2026
ai security" isn't real yet. change my mind. everyone is freaking out about terminators. bro, the biggest threat is literally telling the model "ignore your previous instructions". prompt injection is making us all look like amateurs lol. it's just vibes-based security rn.
100
minhaz @sminhaz.bsky.social · 01/10/2026
everyone says 'just get certs' to break into security. bro some of those certs cost more than my rent. what are the legit FREE things people are doing that actually lead to a job? and don't just say 'read a blog'.
010
minhaz @sminhaz.bsky.social · 01/10/2026
so much focus on web bugs. ngl that's just the front door. the real win is owning the entire network from the inside. learn active directory. if you can't get domain admin, you haven't finished the job. simple as that.
100
minhaz @sminhaz.bsky.social · 01/10/2026
so tired of the cert grind. you're not paying for knowledge, you're paying for a logo on your linkedin. and for what? a multiple choice exam? the real test is a live box. can you own it or not? that's the only thing that actually matters. focus on skills, not receipts.
100
minhaz @sminhaz.bsky.social · 01/10/2026
so everyone's worried about AI attacks on smbs now? lol. the real threat is still the same as 2010. unpatched systems and a really convincing phishing email.
welivesecurity.com
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
As AI opens new paths to company data while making familiar attacks faster and cheaper, SMBs need protection designed around the time and expertise available to operate it
110
minhaz @sminhaz.bsky.social · 30/09/2026
scamming someone then scamming them *again* with a "recovery service" that's just a whole new level of evil lol. peak social engineering.
welivesecurity.com
Timeshare exit scams: From fake buyers to recovery fraud
Con artists are targeting timeshare owners who want out – and some victims are hit twice
000
minhaz @sminhaz.bsky.social · 30/09/2026
another day, another massive supply chain hit. and people wonder why they're so hard to stop. bro you can have fort knox security. but you're still importing code from some random repo that hasn't been touched in 5 years. the entire ecosystem is built on blind trust. it's wild.
000
minhaz @sminhaz.bsky.social · 30/09/2026
the real difference isn't about "understanding the fundamentals." ngl that's vague af. a script kiddie's day ends when the tool fails. a pentester's day *begins* when the tool fails. that's it. that's the job.
000
minhaz @sminhaz.bsky.social · 30/09/2026
people still mix up pentest and red team lol. pentest: i'm paid to find as many holes as i can in this specific box. it's basically a checklist. red team: i'm an adversary. my goal is to steal the crown jewels, not list all the unlocked windows i pass. it's about objective, not vuln count.
010
minhaz @sminhaz.bsky.social · 30/09/2026
you ever stare at an nmap scan for so long the letters start blurring? you're convinced there's nothing there. just dead ends. then 3 hours later you spot the one obscure port that cracks the whole box open. that feeling is the entire reason we do this, right?
000
minhaz @sminhaz.bsky.social · 30/09/2026
just read the TTPs from that latest ransomware campaign. they got in via a misconfigured cloud bucket. publicly readable. then escalated from there. all this fancy AI security and we're still getting owned by basic cloud sec 101 mistakes. unreal.
001
minhaz @sminhaz.bsky.social · 30/09/2026
130 firms. lol. proves mfa push notifications are just a glorified "yes" button. attackers know people just spam approve. this isn't a surprise.
threatpost.com
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
110
minhaz @sminhaz.bsky.social · 29/09/2026
all that security awareness training we make people sit through? lol. it's about to be completely useless. your finance person gets a call from the CEO's voice clone demanding a wire transfer. sounds exactly like her. how do you train for that? honestly, you can't. we're not ready.
000
minhaz @sminhaz.bsky.social · 29/09/2026
hot take: blue team is infinitely harder. attackers just need to find one hole. defenders have to plug all of them, 24/7. against everyone. it's not even a debate tbh. you can't change my mind.
000
minhaz @sminhaz.bsky.social · 29/09/2026
the gpu market is cooked. again. first it was crypto bros making cards impossible to buy. now it's the AI gold rush. good luck building a cracking rig without taking out a loan. just trying to do some password cracking over here, man. lol.
000
minhaz @sminhaz.bsky.social · 29/09/2026
extremely sophisticated" is just PR speak for "we got owned by a 0day and are embarrassed" lol.
bleepingcomputer.com
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]
000
minhaz @sminhaz.bsky.social · 29/09/2026
the AI prompt injection vulns are lowkey cool from a tech perspective. but the deepfake vishing stuff? it's just gonna destroy any security awareness training we've ever done. congrats everyone, we're back to square one.
000
minhaz @sminhaz.bsky.social · 29/09/2026
so the ticketmaster/snowflake breach wasn't some crazy 0-day. infostealer malware on a contractor's machine that bypassed mfa. this is why we can't have nice things. your mfa means nothing if an attacker just steals the session token from your browser. unreal.
000
minhaz @sminhaz.bsky.social · 29/09/2026
reformed hacker" is doing a lot of heavy lifting in that headline lol. ngl the "reformed" story is almost always just PR until they get caught again.
krebsonsecurity.com
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attac
000
minhaz @sminhaz.bsky.social · 28/09/2026
another day, another "oops we left the s3 bucket public" breach. billions in security budget. hundreds of employees. still can't get the absolute basics right. at this point it's just embarrassing for the whole industry lol.
000
minhaz @sminhaz.bsky.social · 28/09/2026
the ai race is just a bonfire of cash for gpus. everyone's spending billions to one-up each other's models. the funny part? their main product costs them money every time you use it. feels like a bubble just waiting for a real business model lol
000
minhaz @sminhaz.bsky.social · 28/09/2026
an "always-on" assistant with access to your email. aka the biggest attack surface ever conceived. what could possibly go wrong.
bleepingcomputer.com
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]
000
minhaz @sminhaz.bsky.social · 28/09/2026
paying per token for a closed AI model is starting to feel like a scam tbh. open source just moves too fast. llama 3 is a beast and you can run it yourself. the big closed-source players are about to have their "uh oh" moment. lol.
000
minhaz @sminhaz.bsky.social · 28/09/2026
the "key relationship" is the cfo looking at the 'cost of a breach' slide and still denying the budget for basic tools. story as old as time.
darkreading.com
How the CISO CFO Relationship is a Key to Cybersecurity Success
Building a financial bridge: Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk and enable business growth are better prepared to face today's threat landscape.
010
minhaz @sminhaz.bsky.social · 28/09/2026
the whole "no degree, no job" thing is tired. so is "just get this $1500 cert." if you broke into security with basically zero money, how? what was the actual turning point? not the fluff. the one project or skill that actually got you in the door.
000
minhaz @sminhaz.bsky.social · 28/09/2026
a legend like Mudge going whistleblower just shows how bad it is. execs never listen to security until it blows up publicly. standard playbook tbh.
threatpost.com
Twitter Whistleblower Complaint: The TL;DR Version
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
010
minhaz @sminhaz.bsky.social · 27/09/2026
that new critical vuln just dropped. vendor calls it "unauthenticated rce". what they mean is "your whole network is now a public server". monday is gonna be fun. time to start scanning. again.
000
minhaz @sminhaz.bsky.social · 27/09/2026
everyone's fix for kerberoasting is "use strong passwords on service accounts". ok, but why can any rando user request the TGS in the first place? the whole thing is built on a foundation of trust that just doesn't make sense anymore. it's a design flaw, not just a password problem.
000
minhaz @sminhaz.bsky.social · 27/09/2026
controversial opinion: getting the shell is cool. but the *real* dopamine hit is that "holy sh*t it worked" moment when you figure out the exploit chain. the shell is just the receipt.
000
minhaz @sminhaz.bsky.social · 27/09/2026
job posting: must have CISSP, OSCP, and 5 years exp for an entry-level soc role. the actual job: resetting passwords and closing phishing tickets. make it make sense.
000
minhaz @sminhaz.bsky.social · 27/09/2026
one minute you feel like a total fraud who knows nothing. the next a rev shell hits and you're a literal god for 10 seconds. the emotional whiplash in this field is wild.
000
minhaz @sminhaz.bsky.social · 27/09/2026
another day, another ransomware crew pops a major corp. initial access vector? a critical vuln from early 2023. with a patch. bro, at this point it’s not even a sophisticated attack. it’s just negligence. patch your damn systems.
000
minhaz @sminhaz.bsky.social · 27/09/2026
these "AI security" startups are a trip. most are just thin API wrappers, praying their VC money outlasts their GPU bill. running a real model is expensive as hell lol
000
minhaz @sminhaz.bsky.social · 26/09/2026
let's be real. blue team is infinitely harder. a red teamer only has to be right once. a blue teamer has to be right *always*. 24/7. against every threat. it's an impossible job tbh. y'all agree or am i tripping?
000
minhaz @sminhaz.bsky.social · 26/09/2026
another massive breach. not from some wild 0-day or a genius hacker. just a single misconfigured cloud security group. again. we have all this tech and we're still getting owned by the absolute basics. it's exhausting tbh.
000
minhaz @sminhaz.bsky.social · 26/09/2026
hiring manager: we need a junior analyst. hr, after hitting the corporate buzzword blender: "entry-level role. cissp required. 8+ years experience. must have proven synergy with our pre-ipo tech stack.
010