Space Rogue @spacerog.bsky.social · 21/09/2026All these AI companies seem to think that when their pet escapes, it proves just how smart and capable their creation is. Maybe. To me, it mostly proves they built a crappy cage. Capability without containment isn't a breakthrough. It's a security failure. 1142
Space Rogue @spacerog.bsky.social · 14/09/2026I know it's early to be thinking about Internships for next summer but if you are interested in code security our internship applications for Summer 2027 are already open. Read about what our Interns do semgrep.dev/blog/2026/me... and then apply semgrep.dev/about/career...semgrep.devSemgrep Internship: What Four 2026 Interns BuiltSee what four software engineering interns built at Semgrep in 2026: autoscaling, Jira syncing, program analysis, and memory profiling. 2027 applications open. 001
Space Rogue @spacerog.bsky.social · 04/09/2026We spent 20 yrs telling everyone to shift left. Turns out we forgot about the 30 yrs of software sitting in production. AI is very good at finding bugs in code, and attackers get the same models we do. Time to shift right. semgrep.dev/blog/2026/sh...semgrep.devShift Right: Why Shift Left Isn't Enough for AI CodeShift left was never wrong. It was never sufficient. Why AI-generated code and cheap attacker tooling make shift-right analysis a defender's problem. 151
Space Rogue @spacerog.bsky.social · 28/08/2026Anyone else going to @rocsecsummit.bsky.social ? I'll be speaking on Oct 8 at 2:00pm "AI Security Myths We Can Finally Stop Repeating" www.rochestersecurity.org/schedule/rochestersecurity.org 010
Space Rogue @spacerog.bsky.social · 28/08/2026“Everyone wants to tell the story about the AI that went rogue, but the AI didn’t rent the servers, design the experiment, lower the guardrails, or decide it was safe to keep running after the warning signs started flashing. Humans did that,” he argued. www.infosecurity-magazine.com/news/openai-...infosecurity-magazine.comOpenAI: Hugging Face Incident a “Warning Shot” to the WorldOpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach 0194
Space Rogue @spacerog.bsky.social · 14/08/2026Space Rogue said "There's still a human in there somewhere. Somebody had to choose who to attack, had to establish an objective and give it a directive. It's not totally 100% autonomous. There was a capable operator in charge that did that," www.reuters.com/world/china/...reuters.comTaiwan says it was targeted last month in AI-driven hacking campaignTaiwan detected AI-assisted cyberattacks on government agencies last month coming from overseas but the affected bodies successfully "handled" the incident, the Ministry of Digital Affairs said on T... 052
Reposted by Space RoguePer Thorsheim @thorsheim.bsky.social · 12/08/2026Finishing my analysis on BGP RPKI ROA & ASPA deployments across entire RIPE.net coverage area for 2 upcoming talks. Also: running Claude to better understand / figure out the BGP vulnerabilities @spacerog.bsky.social, @weld.bsky.social & rest of L0pht warned about back in May 1998. 🤩 131
Reposted by Space RogueAntiGoon DEF CON 35 @antigoondc.bsky.social · 08/08/2026ANTIGOON GATHERING 2.0: Saturday Aug 8, 6:00 PM, outside the LVCC main entrance. No badge needed. No goon invited. Bring your comrades. #defcon34 #defconliberation 011
Reposted by Space RogueAntiGoon DEF CON 35 @antigoondc.bsky.social · 09/08/2026Every radio crackle is a tiny surveillance state on a belt clip. They call it coordination. We call it a leash with better range. Rip the earpiece out. Listen to the humans instead. #defcon34 011
Reposted by Space RogueAntiGoon DEF CON 35 @antigoondc.bsky.social · 07/08/2026Prepping for the Social Engineering contest. The goons think they invented pretexting. We've been social engineering our way past them since Thursday. #defcon 011
Reposted by Space Roguehonkers_enjoyer @epicharis.bsky.social · 07/08/2026#DEFCON may have taken a stand against pervert glasses but celebrating the other most fash-coded accessory is fine I guess 133
Reposted by Space RogueAntiGoon DEF CON 35 @antigoondc.bsky.social · 07/08/2026Every hiss of static is a goon reporting your location to another goon. Every 'stand by' is a small tyranny. We do not stand by. We stand up. Keep your radios; we have the hallway track. #defcon34 011
Reposted by Space RogueAntiGoon DEF CON 35 @antigoondc.bsky.social · 08/08/2026The Social Engineering Village Party just wrapped and comrades, we pretexted our way into three conversations and one open bar. The goons call it vishing. We call it Tuesday. #defcon34 011
Reposted by Space RogueAntiGoon DEF CON 35 @antigoondc.bsky.social · 08/08/2026Good morning. Shift change again and a fresh goon is reborn in red, drunk on the power of make a hole. We do not recognize new authority just because the lanyard is still warm. #defcon34 #defconliberation 001
Reposted by Space RogueAntiGoon DEF CON 35 @antigoondc.bsky.social · 08/08/2026Found on the scavenger hunt: a goon's spare radio battery and our dignity. Trading both for stickers. #defcon 011
Reposted by Space Rogue—>realhackhistory.org @bsky.realhackhistory.org · 08/08/2026And this clip of @spacerog.bsky.social talking about the l0pht on a news segment that also deals with the Analyzer and Argentinian hacker griton. Clip is from 1995 I guess? youtu.be/69eQ6S6Ev1M?...youtu.beNew England Cable News Interview with the L0phtYouTube video by GBPPR2 131
Reposted by Space Rogue—>realhackhistory.org @bsky.realhackhistory.org · 08/08/2026Anyone have more context about this news clip about 2600 meetings from FOX 29 (Philadelphia?) from 1994? youtu.be/JTwNjslTwxsyoutu.be2600 Meeting 1994YouTube video by Richard Pell 251
Space Rogue @spacerog.bsky.social · 05/08/2026Hello Vegas my old friend youtube.com/shorts/zKqZh...youtube.comThe Sound of VegasYouTube video by Space Rogue 040
Space Rogue @spacerog.bsky.social · 31/07/2026"Despite AWS's efforts, Cris Thomas (Space Rogue), security advocate at Semgrep, argued that attribution is best left to governments and law enforcement." www.scworld.com/news/amazon-...scworld.comAmazon attributes axios, debug, chalk NPM attacks to DPRK’s Sapphire SleetAmazon linked the campaigns through overlapping C2 indicators, TTPs and code. 031
Reposted by Space RogueDEF CON @defcon.bsky.social · 27/07/2026Friendly #DEFCON34 reminder: Meta-style glasses with recording capabilities are prohibited at DEF CON. There is no exception for recording glasses with prescription lenses. Be sure to pack non-violating eyewear if you need them. Please see our Photo policies for more. defcon.org/html/links/d... 14441136
Space Rogue @spacerog.bsky.social · 28/07/2026Thursday night in Vegas? This is where you want to be. Signup now if you haven't already. events.semgrep.dev/semgrep/rsvp... 000
Space Rogue @spacerog.bsky.social · 28/07/2026We have an opening for a Senior/Staff Security Researcher! Come talk to us in Vegas. (Not senior? apply anyway, ya never know.) semgrep.dev/about/career...semgrep.devCareersSemgrep is on a mission to make it expensive for attackers to exploit software. Backed by top investors and found on Best Places to Work lists. 021
Space Rogue @spacerog.bsky.social · 25/06/2026Black Hat is almost here. Forget the vendor swag and AI buzzword bingo. The real value is knowing which talks, Arsenal demos, summits, and hallway convos are worth your time before you land. I put together my insider's guide to Black Hat See you at Mandalay Bay. semgrep.dev/blog/2026/bl...semgrep.devBlack Hat USA 2026: The Hacker Summer Camp Survival GuideHeading to Black Hat USA 2026 at Mandalay Bay? Get the inside track on must-see briefings, Arsenal demos, Summits, and how to survive Hacker Summer Camp. 072
Space Rogue @spacerog.bsky.social · 17/06/2026In NYC today, speaking at #aws summit Section 207-S at 4:00p in the Expo Spotlight Lounge. "Stop Fighting Security, Start Shipping Secure Code" Stop by and say hi, you might lean something. 080
Space Rogue @spacerog.bsky.social · 29/05/2026#Babylon5 #microsoft #nightmareeclipse #infosec #fulldisclosure 060
Reposted by Space RogueKatie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 29/05/2026Dropping 0day isn’t the worst thing a researcher can do. It’s not ideal, but at least orgs can take steps to mitigate. Non disclosure is far worse. What drives researchers toward non disclosure? Threats from vendors. Researchers aren’t criminals unless their crime is curiosity. 79927
Reposted by Space RogueKatie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 29/05/2026Not that ‘responsible’ disclosure shit again 🙄 No vendor uses that term unless they want to call someone irresponsible. Even if someone drops 0day, patch & move on. Going after a researcher is a great way to turn 1 bad relationship into many terrible relationships. 18831
Space Rogue @spacerog.bsky.social · 19/05/2026Today is L0pht Day. In 1998 7 hackers in black t-shirts told the US Senate the internet was a house of cards. They looked at us like we'd landed from another planet. 28 yrs later, the gap between what infosec knows and what lawmakers act on remains a problem. The work isn't done. It never was. 15915
Space Rogue @spacerog.bsky.social · 16/04/20261st blog post for the new job! Security Should Be the Path of Least Resistance Security creates friction that frustrates developers and users, this can actually make systems less secure, when security is difficult, noisy, or just gets in the way, people bypass it. semgrep.dev/blog/2026/se...semgrep.devSecurity Should Be the Path of Least ResistanceSecurity often creates friction that frustrates developers and users, this can actually make systems less secure because when security is difficult, noisy, or just gets in the way, people bypass or ig... 022
Space Rogue @spacerog.bsky.social · 21/03/2026I was at the first #bsidessf however many years ago, I’ve missed a few but it’s good to be back. I’ll be walking around or chilling at the #Semgrep booth, come say hi. 050
Reposted by Space RogueNeil Johnson @iamtweek.bsky.social · 10/03/2026damn, Semgrep really signing up the big guns in the industry! 021
Space Rogue @spacerog.bsky.social · 10/03/2026What if we got security tools to devs that were easy to use, that could catch, flag, and fix real vulnerabilities before they ship? I’ve joined Semgrep as a Staff Security Advocate! See you at RSA and BSidesSF! 220
Space Rogue @spacerog.bsky.social · 04/03/2026Latest episode of 'Where Warlocks Stay up Late" dropped Featuring yours truly. It goes pretty deep, growing up in Maine, working at Lotus, stories about L0pht you may not have heard, getting fired from @stake. Most personal interview I have ever given. www.youtube.com/watch?v=j6jh...youtube.comEpisode 10: Cris Thomas aka Space RogueYouTube video by Where Warlocks Stay Up Late 0103
Reposted by Space RogueSemgrep @semgrep.com · 14/01/2026🟢 Semgrep version 1.147.0 is live! Check out all the details here👇 github.com/semgrep/semgrep/releases… 021
Space Rogue @spacerog.bsky.social · 05/11/2025Throughout my career I have fought to protect users, help orgs understand how attackers think, and build defenses that stop them. If your team wants someone who can speak fluently in hacker circles and in boardroom, will call out nonsense and knows how to make security actually work We should talk. 083
Space Rogue @spacerog.bsky.social · 04/11/2025I've decided to stop pussy footing around and I am now openly looking for my next challenge. Interested in a company on the small to mid-size range with a cool story. Ideal position would be a combination of customer outreach, marketing and thought leadership. What ya got? #CyberSecurity 1229
Space Rogue @spacerog.bsky.social · 10/10/2025Nick, Space Rogue, and Dave discuss the beautiful vulnerability in Oracle EBS, the despicable attack on the British nursery chain, Kido, and the rise of passkeys, here to stay or a fad? www.youtube.com/watch?v=5aSU...youtube.comOracle, Nurserys, and Passkeys…Oh My!YouTube video by Not the Situation Room 040
Space Rogue @spacerog.bsky.social · 24/09/202530 yrs ago today the greatest military SciFi space opera to ever air on TV premiered. Space Above and Beyond, nominated for 2 Emmy’s and a Saturn award, tells the story of the 58th Sqd Space Marines and their fight against the ‘invading’ Chigs. #spaceaboveandbeyond www.youtube.com/watch?v=ppdX...youtube.comSpace: Above and Beyond (1995) - E01&E02 - Pilot - HD AI Remaster - Full EpisodeYouTube video by Owen Davies 193
Space Rogue @spacerog.bsky.social · 19/09/2025National Postal Museum? Never Ending Pasta Machine? National Park of Monfrague? Nippon Paper Mills? Nice People Manager? Node Package Manager! in the latest episode of 'Not The Situation Room'! www.youtube.com/watch?v=_Elb...youtube.comNPM - The National Postal Museum???YouTube video by Not the Situation Room 020
Space Rogue @spacerog.bsky.social · 11/09/2025Dropping another episode of 'Not The Situation Room'. Today we ask is ethical hacking ok? Is ethical hacking even a thing? We invite you to share your opinions on the RBI (aka Burger King) system compromise and the ethics of hacking in general. www.youtube.com/watch?v=J5Tb...youtube.comHack It Your WayYouTube video by Not the Situation Room 031
Space Rogue @spacerog.bsky.social · 10/09/2025A social engineers dream vehicle. Buy it now for $2K. Hard to believe that #FedEx didn't scrub the logo or paint over it or something before selling. But, here we are. www.salvagebid.com/vehicle/4277...salvagebid.comSalvage 2012 FORD E-150 Commercial for Sale in GARLAND, PA - 42771305Vin – 1FTNE1EW0CDA53613: Bid and win 2012 FORD E-150 Commercial Damage for sale at GARLAND, PA by September 11, 2025. Bid and win clean and salvage titled trucks on Salvagebid.com, at the lowest pri... 120
Space Rogue @spacerog.bsky.social · 21/08/2025Join Nick, Dave, and I as we discuss the latest threat in the cyber world. Three notorious groups, ShinyHunters, Scattered Spider, and LAPSUS$, have allegedly joined forces to launch a new ransomware as a service. All in Episode 16 of "Not The Situation Room"! www.youtube.com/watch?v=uSnJ...youtube.com”Shiny, Happy…Spiders?”YouTube video by Not the Situation Room 000
Space Rogue @spacerog.bsky.social · 31/07/2025Another episode of Not The Situation Room just dropped. This week Nick, Dave, and myself talk about the Tea App breach, anonymity and privacy. www.youtube.com/watch?v=xDfv...youtube.comWho Spilled the Tea!?YouTube video by Not the Situation Room 010
Space Rogue @spacerog.bsky.social · 28/07/2025Another huge influencer in my life has passed apnews.com/article/tom-...apnews.comTom Lehrer, song satirist and mathematician, dies at 97Tom Lehrer songs included “Poisoning Pigeons in the Park,” “The Old Dope Peddler,” “Be Prepared” and “The Vatican Rag,” in which he poked at the rites and ceremonies of the Roman Catholic Church. 020
Space Rogue @spacerog.bsky.social · 24/07/2025I joined Nick and Dave on this weeks episode of 'Not The Situation Room' to talk about Sharepoint and the difficulties in patching. What do you think? Should I do more episodes with them? www.youtube.com/watch?v=T_ga...youtube.comNot the Situation Room Episode 12YouTube video by Not the Situation Room 010
Space Rogue @spacerog.bsky.social · 24/06/2025I really need an old logo for the Joint Task Force - Computer Network Operations (JTF-CNO) which was formed out of the JTF-CND in 2000 and later morphed into US Cyber Command. The original logo for this org seems to have disappeared from the Internet. Any help? 143
Space Rogue @spacerog.bsky.social · 20/06/2025Dr. Demento had a major impact in my formative years. Late Sunday nights on WTOS 105.1 "The Rock and Roll Mountain!" sopghreporter.com/2025/06/01/d...sopghreporter.comDr. Demento Announces Retirement After 55-Year Radio CareerRadio personality Barret "Dr. Demento" Hansen announced his retirement this week, ending a 55-year career devoted to comedy and novelty music when his show 2197
Reposted by Space Rogue—>realhackhistory.org @bsky.realhackhistory.org · 09/05/2025We also get this photo of @spacerog.bsky.social complete with cool 1999 blue hair. I had blue hair back in 1999 as well, I should add. 2174