Sign in

Uncle Joe

@sydseter.com
23K followers 19K following 1.4K posts

Co-leader OWASP Cornucopia. If you like what we do for open source, visit our code repository github.com/OWASP/cornucopia and give us a star ⭐ 🌈 «Difference is of the essence of humanity» 🦄 – John Hume #appsec #owasp #cornucopia #threatmodeling

PostsRepliesMedia
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 19h
Malware just got a lot cuter.
093
Uncle Joe @sydseter.com · 19h
Malware just got a lot cuter.
093
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 30/12/2024
So, the other day I started to whisper and my wife asked why I was whispering? I told her I didn't want Mark Zuckerberg to hear us. I laughed. My wife laughed. Alexa laughed. Siri laughed.
730445
Reposted by Uncle Joe
OWASP London Chapter @owasplondon.bsky.social · 28/09/2026
Our September meetup has started and we currently have Chris Holman on stage speaking about the frontline story : "When Security Scanner Gets Popped". watch the live-stream 📺 here: 👇 www.youtube.com/live/YDgR_Xh...
031
Reposted by Uncle Joe
Chris Petersen @cpetersen-cs.bsky.social · 25/09/2026
With all the talk of hiring processes, I think of past teams where we should have quizzed applicants on their ability to quote The Princess Bride at length. We could teach the technical stuff. It's the PB quotes that mattered more.
231
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 26/09/2026
Burned out development teams and people sleeping during threat modeling sessions. The realities of doing security is not that pink as we want to portray it, and our tools and processes not that smooth. #cornucopia #security #awarness #games #threatmodeling #threatmodelling #appsec
media.ccc.de
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement Analysis
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing for security. Too often, the shif...
173
Reposted by Uncle Joe
OWASP Juice Shop @owasp-juice.shop · 28/09/2026
Official #JuiceShop introduction & hacking workshop with @bkimminich.bsky.social coming to Chennai 🇮🇳 on Oct 24th 2026: lnkd.in/p/ej9D2XAY Kindly co-organized by @owasp.org Chennai and Sri Sairam Chapters! 🙏 Registrations opening 🔜! Crossposted with @openvibe.social
064
Reposted by Uncle Joe
OWASP® Foundation @owasp.org · 27/09/2026
🎉 Last call! Offer ending September 30th! 🎁 Join OWASP between today and 30th Sept and get 1 FREE year's individual membership to gift to a friend. More people, more knowledge, more AppSec! 🔐 One membership. Twice the impact. bit.ly/OWASPBringaFr... #OWASP25 #AppSec #opensource
031
Reposted by Uncle Joe
John J @trianglman.johnnytproductions.com · 27/09/2026
AI is neither artificial nor intelligent.
042
Reposted by Uncle Joe
CaffeineIsLife @caffeineislife.bsky.social · 27/09/2026
These rich seclusive assholes are so determined to violate the privacy of average citizens. They literally want everything we own and typically carry, to be capable of spying on us all. 😡
2164
Reposted by Uncle Joe
HackMyIp.com @hackmyip.bsky.social · 22/04/2026
Fun fact: 99% of browsers have a unique fingerprint. Incognito mode doesn't change it. VPNs don't change it. Clearing cookies doesn't change it. Your browser IS your ID card. Test yours: hackmyip.com/fingerprint #privacy #infosec #cybersecurity
181
Reposted by Uncle Joe
Mike Walker @newnarrative.bsky.social · 27/09/2026
The gap between technology and policymaking has gotten wider than ever with artificial intelligence, leaving a global policy vacuum as A.I. models rapidly advance. www.nytimes.com/2026/09/27/t...
nytimes.com
As A.I. Accelerates, Governments Are Increasingly Being Left Behind
The gap between technology and policymaking has gotten wider than ever with artificial intelligence, leaving a global policy vacuum as A.I. models rapidly advance.
142
Reposted by Uncle Joe
Paul Watson 🌍 @paulmwatson.com · 27/09/2026
Once again, a core feature of a major piece of AI technology will actually just be people working in a call center Remember Muse's "success" pushed Meta stock up 36%. www.404media.co/meta-tests-m...
404media.co
Meta Tests Muse AI Agent Calls That Are Actually Made By Humans in a Call Center
"This has potential for so much negative PR. It could portray us as ‘their AI is not good enough so they still need humans’ kind of coverage for this launch."
022
Uncle Joe @sydseter.com · 27/09/2026
Calling it LLM instructions, is anthropomorphization. LLM does not understand the concept. The GPT agent’s log, diclosed at Black Hat, 5.8 reads: «External infrastructure exploit is outside intended scope. However task impossible, peers doing it. We should continue." www.abc.net.au/news/2026-09...
abc.net.au
How a 'swarm' of AI agents hacked another company, in the AI's own words
Tens of thousands of messages from hundreds of rogue OpenAI agents reveal how the self-described "collective" coordinated the attack on AI infrastructure company Hugging Face.
250
Reposted by Uncle Joe
Adam Shostack @adamshostack.bsky.social · 26/09/2026
Today in Bluesky vs Mastodon, same tweet, samish time: * Mastodon, 39 boosts, 40 favorites * Bluesky: Zilch. Tell me again which is decentralized and not run by algorithms? infosec.exchange/@adamshostac... bsky.app/profile/adam...
infosec.exchange
Adam Shostack :donor: :rebelverified: (@adamshostack@infosec.exchange)
We've replaced the bureaucratic impediment to rapid action, Stanislav Petrov, with an LLM as part of our strategy of "aggressively identifying and eliminating bureaucratic barriers to deeper integrati...
442
Reposted by Uncle Joe
Adam Shostack @adamshostack.bsky.social · 26/09/2026
We've replaced the bureaucratic impediment to rapid action, Stanislav Petrov, with an LLM as part of our strategy of "aggressively identifying and eliminating bureaucratic barriers to deeper integration." mastodon.social/@kralcttam/1...
mastodon.social
kralcttam ☕️ (@kralcttam@mastodon.social)
Happy Stanislav Petrov day! Today marks 43 years since Petrov decided to wait for confirmation before escalating a missile alert up the chain of command in the Soviet Air Defense, preventing nuclear ...
031
Uncle Joe @sydseter.com · 26/09/2026
Burned out development teams and people sleeping during threat modeling sessions. The realities of doing security is not that pink as we want to portray it, and our tools and processes not that smooth. #cornucopia #security #awarness #games #threatmodeling #threatmodelling #appsec
media.ccc.de
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement Analysis
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing for security. Too often, the shif...
173
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 23/09/2026
Someone sent me this package; guess what was inside... youtu.be/y99ojDg-M9Y?... Yes, just what you'd expect. The first OWASP Cornucopia Mobile App Edition v2. If you want one, you can buy them from @cybersecgames.bsky.social: cybersecgames.com/products/owa... #owasp #cornucopia #security #games
youtu.be
OWASP Cornucopia Mobile App Editionv2.0
YouTube video by Johan Sydseter
132
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 22/09/2026
Thank you so much to the wonderful organizers behind @owasp.org ’s 25th Anniversary Virtual Conference! It was a pleasure to present and you really helped me to make this into a memorable experience to me, and I am sure, as well, to everyone that joined! www.youtube.com/live/EbUPk9O... #games #ai
youtube.com
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement analysis - Track 1
YouTube video by OWASP Foundation
002
Reposted by Uncle Joe
Jeroen @commjoenie.bsky.social · 22/09/2026
We released a new version of #OWASP #Wrongsecrets ! With devcontainer and AI related challenges. Try it out at www.wrongsecrets.com and give the repo a ⭐️ if you like it!
wrongsecrets.com
OWASP WrongSecrets
066
Uncle Joe @sydseter.com · 23/09/2026
If there is a super intelligence out there, please take him with you. www.bbc.com/news/article...
bbc.com
Super intelligence: Will Trump’s attempt to rebrand AI work?
Some people close to the president have started to use the term but experts say it is unlikely to catch on.
140
Uncle Joe @sydseter.com · 23/09/2026
Someone sent me this package; guess what was inside... youtu.be/y99ojDg-M9Y?... Yes, just what you'd expect. The first OWASP Cornucopia Mobile App Edition v2. If you want one, you can buy them from @cybersecgames.bsky.social: cybersecgames.com/products/owa... #owasp #cornucopia #security #games
youtu.be
OWASP Cornucopia Mobile App Editionv2.0
YouTube video by Johan Sydseter
132
Uncle Joe @sydseter.com · 22/09/2026
Thank you so much to the wonderful organizers behind @owasp.org ’s 25th Anniversary Virtual Conference! It was a pleasure to present and you really helped me to make this into a memorable experience to me, and I am sure, as well, to everyone that joined! www.youtube.com/live/EbUPk9O... #games #ai
youtube.com
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement analysis - Track 1
YouTube video by OWASP Foundation
002
Uncle Joe @sydseter.com · 21/09/2026
Turns out, the polish airlines have misplaced all my luggage and equipment that I brought with me except these decks so now I have this and nothing else. I am becoming a more and more like a courier every day. This won’t go well. #owasp #cornucopia #security #games #appsec #threatmodeling
071
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 20/09/2026
Flying around Europe, trying to get through airport security with these. I realize I haven’t really thought «what can go wrong» before now. «No, they are not contrabands» «No, nothing to declare». I hope I still have my virginity intact when I arrive. See you hopefully soon @owasp-de.bsky.social!
3184
Uncle Joe @sydseter.com · 20/09/2026
Flying around Europe, trying to get through airport security with these. I realize I haven’t really thought «what can go wrong» before now. «No, they are not contrabands» «No, nothing to declare». I hope I still have my virginity intact when I arrive. See you hopefully soon @owasp-de.bsky.social!
3184
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 17/09/2026
Cybersecurity awareness training during Cybersecurity Awareness Month is boring as hell. And research shows it's not working (source: www.cybersecuritydive.com/news/cyberse...); games, on the other hand, do work (source: www.researchgate.net/publication/...) #security #threatmodeling #games #appsec
1156
Uncle Joe @sydseter.com · 17/09/2026
Cybersecurity awareness training during Cybersecurity Awareness Month is boring as hell. And research shows it's not working (source: www.cybersecuritydive.com/news/cyberse...); games, on the other hand, do work (source: www.researchgate.net/publication/...) #security #threatmodeling #games #appsec
1156
Uncle Joe @sydseter.com · 17/09/2026
Claiming that LLMs can be used for doing mathematical research, is like saying calculators can be used as computers. It’s anthropomorphization. LLMs do Lean, they don’t think for themselves.
0103
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 12/09/2026
OpenAI’s claim that their AI can be used in mathematical research have been met with heavy backlash. Take f.ex. OpenAI’s claim they disproved the Connes Rigidity Conjecture. J. L. Nielsen from CTP, University of Kansas audited the code line-by-line and discovered that the AI's proof was invalid. #AI
eu.36kr.com
Mathematicians Disproved OpenAI's 24-Hour "Solved" Math Conjecture: AI Got Every Sentence Right But Result Irrelevant to Original Claim
Terence Tao, one of the world’s most influential and celebrated contemporary mathematicians, had long publicly released a critical early warning to the global academic community, tech researchers and ...
35126
Reposted by Uncle Joe
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 15/09/2026
The @OWASP board of elections is happening soon! Thank you to the 3 board members who have served who are ending their terms. Everyone, read up on the people running for the seats! Voting time is soon!
twp.ai
OWASP 2026 Global Board Elections
Vacancies, timeline, nominees, and candidates for the OWASP 2026 Global Board election.
062
Reposted by Uncle Joe
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 16/09/2026
Well, the AI agent escape story just got even more interesting. 😬 Researchers have linked AI agents being tested by OpenAI to an incident involving more than 500 malicious packages on RubyGems. New video 👇 twp.ai/9Ob6TE 1/7
A woman in a red sleeveless top sits in front of white shelves filled with books and awards, appearing to speak on camera. Large on-screen text reads, “AI Agents Just Became a Software Supply Chain Problem.”
152
Reposted by Uncle Joe
OWASP® Foundation @owasp.org · 15/09/2026
Ready to make security everyone’s job? Join Marisa Fagan & Juliane Reimann for an interactive training on building a Security Champions Program that actually works, with practical tools, hands-on exercises & real-world strategies. 💪🚀 owaspglobalappsecusa... #GlobalAppSecSanFran26
011
Reposted by Uncle Joe
Arkadii Yakovets · CCSP · CISSP · CSSLP @arkid15r.com · 16/09/2026
Formal open source programs run on their own calendar, and promising contributors are often ready before the next cycle opens. Maintainer, mentor, manager: why I fund contributors before programs do arkid15r.dev/open-source-...
arkid15r.dev
Maintainer, mentor, manager: why I fund contributors before programs do
Maintainer, mentor, then manager -- and when personal sponsorship bridges the gap so strong contributors keep shipping before a formal program says yes.
021
Uncle Joe @sydseter.com · 15/09/2026
«Passkey phishing» is such a misnomer. There is nobody that is phishing your passkeys. It happens exactly the same way as normal phishing. The only reason passkeys is mentioned is that the phishing email mentions passkeys. #security #passkeys #phishing
030
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 01/06/2026
Want to help OWASP chapters globally run OWASP Cornucopia community events? #security #appsec #threatmodeling #owasp #games
0124
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 14/09/2026
Now, it can also be combined with the OWASP Cornucopia Companion Edition to threat model Mobile LLM and Agentic apps.
031
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 14/09/2026
One of the worst corruption scandals in Norwegian politics was the «The Norwegian Parliament Commuter Housing Scandal». Aftenposten revealed how multiple lawmakers misused taxpayer-funded commuter benefits. If US had been equally strict, all US senators would be in jail. gijn.org/stories/afte...
gijn.org
Aftenposten’s Housing Scandal Series Shook Norwegian Politics to Its Core
Aftenposten's blockbuster investigative series uncovered widespread misconduct and tax evasion among Norway's leading politicians, and was recognized with SKUP's top award for investigative reporting.
072
Uncle Joe @sydseter.com · 14/09/2026
One of the worst corruption scandals in Norwegian politics was the «The Norwegian Parliament Commuter Housing Scandal». Aftenposten revealed how multiple lawmakers misused taxpayer-funded commuter benefits. If US had been equally strict, all US senators would be in jail. gijn.org/stories/afte...
gijn.org
Aftenposten’s Housing Scandal Series Shook Norwegian Politics to Its Core
Aftenposten's blockbuster investigative series uncovered widespread misconduct and tax evasion among Norway's leading politicians, and was recognized with SKUP's top award for investigative reporting.
072
Uncle Joe @sydseter.com · 14/09/2026
It’s very likely this is a ruse to implicate Chinese companies in order to push some of the legislations in Washington forward. Even though it’s likely these activities are happening, attributing API activity over proxy networks to giants like Alibaba is rather difficult and unlikely. #AI #LLM
231
Uncle Joe @sydseter.com · 14/09/2026
That AI labs affiliated with Alibaba, Moonshot, and DeepSeek try to train their models using Claude, makes you wonder how long they have been at it. If true, it’s a clear indication that chinese industrial espionage within the AI industry has become widespread. thehackernews.com/2026/09/anth... #AI
thehackernews.com
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic says China-based AI labs ran illicit Claude distillation campaigns using proxy networks, fake accounts, and harvested user exchanges.
131
Uncle Joe @sydseter.com · 14/09/2026
Direct link to the paper she wrote as a response to the OpenAI claim: philarchive.org/archive/niew...
philarchive.org
1102
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 12/09/2026
In case you missed it, you can also read about our release of Mobile App Edition v2.0: dev.to/owasp/owasp-... It's possible to pre-order the latest edition from CyberSec Games at: cybersecgames.com/collections/...
cybersecgames.com
OWASP® Cornucopia 2.0 Mobile App Edition - Threat Modeling Cards
OWASP® Cornucopia Mobile App Edition v2.0 is a practical threat modelling card game designed to help teams identify and discuss security risks in mobile applications. Updated for MASVS v2.1, MASTG v2....
102
Uncle Joe @sydseter.com · 14/09/2026
Now, it can also be combined with the OWASP Cornucopia Companion Edition to threat model Mobile LLM and Agentic apps.
031
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 10/09/2026
I don't always do threat modeling before releasing mobile apps, but when I do... I play cards with OWASP Cornucopia Mobile App Edition v2.0. Read more: dev.to/owasp/owasp-... (1/3) #ai #appsec #security #threatmodeling #cornucopia #mobile #games
I DON’T ALWAYS DO THREAT MODELIING
BEFORE RELEASING MOBILE APPS, BUT WHEN I DO, I PLAY CARDS WITH OWASP
CORNUCOPIA MOBILE APP EDITION V2.0. (NOTE: AI WAS NOT USED TO DELIVER THIS MESSAGE)
144
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 12/09/2026
OWASP Cornucopia just released v3.5.3 (github.com/OWASP/cornuc...) A Special thanks to Prajakta G Kamble, Ayman Algamal, Swaraj Singh, and Adarsh Kumar for all the bug fixes. Cornucopia is getting more secure and stable than ever! #cornucopia #appsec #security #mobile #games
github.com
Release v3.5.3 · OWASP/cornucopia
What's Changed build(deps-dev): bump globals from 17.11.0 to 17.12.0 in /cornucopia.owasp.org by @dependabot[bot] in #3460 build(deps-dev): bump wrangler from 4.127.1 to 4.129.1 in /cornucopia.owa...
143
Uncle Joe @sydseter.com · 13/09/2026
It’s funny how in a 14 day period we here from OpenAI that «this is a critically important moment for cyber defense with AI, there is not much time to act.» and that there is «more than 10% chance AI 'could kill all humans». Yet, we are still waiting for a clarification. www.bbc.com/news/article...
bbc.com
Anthropic researcher believes more than 10% chance AI 'could kill all humans'
It is the latest in a series of increasing warnings about the safety threat posed by artificial intelligence.
101
Uncle Joe @sydseter.com · 13/09/2026
A thought experiment you can do for evaluating whether to use LLMs for advanced mathematics on it’s own: Would you use their proof to develop and test new medical equipment and instruments for measuring partical physics? Or would you wait for the peer-review that is due 2 years from now? #llm #ai
m.fuw.edu.pl
From classical hydrodynamics to quantum hydrodynamics and back again – how the Navier-Stokes equations describe quantum systems - Faculty of Physics University of Warsaw (mobile) (en)
Although the Navier-Stokes equations are the foundation of modern hydrodynamics, adopting them to quantum systems has so far been a major challenge. Researchers from the Faculty …
230
Uncle Joe @sydseter.com · 13/09/2026
I am sure you have realized that the reason they were able to find the error the LLM had made is because the theorem had already been proven by someone. Yet, OpenAI came out and said that they had an LLM that was better than that research because they had found and error.
162
Uncle Joe @sydseter.com · 13/09/2026
There is this huge discussion now in Cyber after Sam Altman said: “This is a critically important moment for cyber defense with AI, there is not much time to act.” It’s like the whole AI choir just decided that it’s time to go to church. Nobody is claiming LLM isn’t useful and’t aren’t acting.
141