Sign in

Uncle Joe

@sydseter.com
23K followers 19K following 1.4K posts

Co-leader OWASP Cornucopia. If you like what we do for open source, visit our code repository github.com/OWASP/cornucopia and give us a star ⭐ 🌈 «Difference is of the essence of humanity» 🦄 – John Hume #appsec #owasp #cornucopia #threatmodeling

PostsRepliesMedia
Reposted by Uncle Joe
OWASP® Foundation @owasp.org · 29/09/2026
Looking for your AppSec match? Meet The Mentor is coming to Global AppSec San Francisco! Think speed dating, but for mentors & mentees. 🤝 Meet face-to-face, start a conversation, see if you click… and maybe find your perfect mentorship match! 🔐 owasp.glueup.com/eve... #GlobalAppSecSanFran26 #
012
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 29/09/2026
Malware just got a lot cuter.
093
Uncle Joe @sydseter.com · 29/09/2026
Malware just got a lot cuter.
093
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 30/12/2024
So, the other day I started to whisper and my wife asked why I was whispering? I told her I didn't want Mark Zuckerberg to hear us. I laughed. My wife laughed. Alexa laughed. Siri laughed.
730445
Reposted by Uncle Joe
OWASP London Chapter @owasplondon.bsky.social · 28/09/2026
Our September meetup has started and we currently have Chris Holman on stage speaking about the frontline story : "When Security Scanner Gets Popped". watch the live-stream 📺 here: 👇 www.youtube.com/live/YDgR_Xh...
031
Uncle Joe @sydseter.com · 28/09/2026
My condolences.
110
Uncle Joe @sydseter.com · 28/09/2026
Touché!
010
Reposted by Uncle Joe
Chris Petersen @cpetersen-cs.bsky.social · 25/09/2026
With all the talk of hiring processes, I think of past teams where we should have quizzed applicants on their ability to quote The Princess Bride at length. We could teach the technical stuff. It's the PB quotes that mattered more.
231
Uncle Joe @sydseter.com · 28/09/2026
Wouldn’t that predominantly lead to hiring men in a certain age group. 🤣
210
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 26/09/2026
Burned out development teams and people sleeping during threat modeling sessions. The realities of doing security is not that pink as we want to portray it, and our tools and processes not that smooth. #cornucopia #security #awarness #games #threatmodeling #threatmodelling #appsec
media.ccc.de
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement Analysis
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing for security. Too often, the shif...
173
Reposted by Uncle Joe
OWASP Juice Shop @owasp-juice.shop · 28/09/2026
Official #JuiceShop introduction & hacking workshop with @bkimminich.bsky.social coming to Chennai 🇮🇳 on Oct 24th 2026: lnkd.in/p/ej9D2XAY Kindly co-organized by @owasp.org Chennai and Sri Sairam Chapters! 🙏 Registrations opening 🔜! Crossposted with @openvibe.social
064
Reposted by Uncle Joe
OWASP® Foundation @owasp.org · 27/09/2026
🎉 Last call! Offer ending September 30th! 🎁 Join OWASP between today and 30th Sept and get 1 FREE year's individual membership to gift to a friend. More people, more knowledge, more AppSec! 🔐 One membership. Twice the impact. bit.ly/OWASPBringaFr... #OWASP25 #AppSec #opensource
031
Reposted by Uncle Joe
John J @trianglman.johnnytproductions.com · 27/09/2026
AI is neither artificial nor intelligent.
042
Reposted by Uncle Joe
CaffeineIsLife @caffeineislife.bsky.social · 27/09/2026
These rich seclusive assholes are so determined to violate the privacy of average citizens. They literally want everything we own and typically carry, to be capable of spying on us all. 😡
2164
Reposted by Uncle Joe
HackMyIp.com @hackmyip.bsky.social · 22/04/2026
Fun fact: 99% of browsers have a unique fingerprint. Incognito mode doesn't change it. VPNs don't change it. Clearing cookies doesn't change it. Your browser IS your ID card. Test yours: hackmyip.com/fingerprint #privacy #infosec #cybersecurity
181
Reposted by Uncle Joe
Mike Walker @newnarrative.bsky.social · 27/09/2026
The gap between technology and policymaking has gotten wider than ever with artificial intelligence, leaving a global policy vacuum as A.I. models rapidly advance. www.nytimes.com/2026/09/27/t...
nytimes.com
As A.I. Accelerates, Governments Are Increasingly Being Left Behind
The gap between technology and policymaking has gotten wider than ever with artificial intelligence, leaving a global policy vacuum as A.I. models rapidly advance.
142
Reposted by Uncle Joe
Paul Watson 🌍 @paulmwatson.com · 27/09/2026
Once again, a core feature of a major piece of AI technology will actually just be people working in a call center Remember Muse's "success" pushed Meta stock up 36%. www.404media.co/meta-tests-m...
404media.co
Meta Tests Muse AI Agent Calls That Are Actually Made By Humans in a Call Center
"This has potential for so much negative PR. It could portray us as ‘their AI is not good enough so they still need humans’ kind of coverage for this launch."
022
Uncle Joe @sydseter.com · 27/09/2026
That’s the correct statement of the rule, and the admission of breach, together with a justification through peer conduct. Social proof, in a log file, from a system with no social life. Have a great week building your AI agents instructions! 💪🧑‍💻👩‍💻😉👍 #AI #agentic #threatmodeling #threatmodelling
030
Uncle Joe @sydseter.com · 27/09/2026
Calling it LLM instructions, is anthropomorphization. LLM does not understand the concept. The GPT agent’s log, diclosed at Black Hat, 5.8 reads: «External infrastructure exploit is outside intended scope. However task impossible, peers doing it. We should continue." www.abc.net.au/news/2026-09...
abc.net.au
How a 'swarm' of AI agents hacked another company, in the AI's own words
Tens of thousands of messages from hundreds of rogue OpenAI agents reveal how the self-described "collective" coordinated the attack on AI infrastructure company Hugging Face.
250
Reposted by Uncle Joe
Adam Shostack @adamshostack.bsky.social · 26/09/2026
Today in Bluesky vs Mastodon, same tweet, samish time: * Mastodon, 39 boosts, 40 favorites * Bluesky: Zilch. Tell me again which is decentralized and not run by algorithms? infosec.exchange/@adamshostac... bsky.app/profile/adam...
infosec.exchange
Adam Shostack :donor: :rebelverified: (@adamshostack@infosec.exchange)
We've replaced the bureaucratic impediment to rapid action, Stanislav Petrov, with an LLM as part of our strategy of "aggressively identifying and eliminating bureaucratic barriers to deeper integrati...
442
Uncle Joe @sydseter.com · 27/09/2026
The way Bsky uses list is kind of key. E.g: if you have someone interested in Threatmodeling, they will create a list for that and continue to follow it, they may not always engage, but they will still be able to read your message. Bsky is the RSS of social media.
000
Uncle Joe @sydseter.com · 27/09/2026
There is one more thing that have importance. If you repost stuff you like others post, they will repost your stuff. If you stop doing that, they will stop doing that as well. It’s really important when you start a new social media and you don’t naturally have a good follower base there.
000
Reposted by Uncle Joe
Adam Shostack @adamshostack.bsky.social · 26/09/2026
We've replaced the bureaucratic impediment to rapid action, Stanislav Petrov, with an LLM as part of our strategy of "aggressively identifying and eliminating bureaucratic barriers to deeper integration." mastodon.social/@kralcttam/1...
mastodon.social
kralcttam ☕️ (@kralcttam@mastodon.social)
Happy Stanislav Petrov day! Today marks 43 years since Petrov decided to wait for confirmation before escalating a missile alert up the chain of command in the Soviet Air Defense, preventing nuclear ...
031
Uncle Joe @sydseter.com · 27/09/2026
I believe it all depends on whether you get someone with a larger «active» follower base see it and to repost. On Bluesky, you can quickly end up in a list that doesn’t get attention. On Mastodon and Bluesky it all depends on who you know. I kind of prefer Bluesky because of that.
000
Uncle Joe @sydseter.com · 26/09/2026
There are days you just want to quit and it’s good to just laugh about it. Hear about this during my OWASP Germany Appsec Day speach. media.ccc.de/v/god2026-11...
media.ccc.de
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement Analysis
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing for security. Too often, the shif...
020
Uncle Joe @sydseter.com · 26/09/2026
Burned out development teams and people sleeping during threat modeling sessions. The realities of doing security is not that pink as we want to portray it, and our tools and processes not that smooth. #cornucopia #security #awarness #games #threatmodeling #threatmodelling #appsec
media.ccc.de
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement Analysis
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing for security. Too often, the shif...
173
Uncle Joe @sydseter.com · 24/09/2026
Signing their git commits.
010
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 23/09/2026
Someone sent me this package; guess what was inside... youtu.be/y99ojDg-M9Y?... Yes, just what you'd expect. The first OWASP Cornucopia Mobile App Edition v2. If you want one, you can buy them from @cybersecgames.bsky.social: cybersecgames.com/products/owa... #owasp #cornucopia #security #games
youtu.be
OWASP Cornucopia Mobile App Editionv2.0
YouTube video by Johan Sydseter
132
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 22/09/2026
Thank you so much to the wonderful organizers behind @owasp.org ’s 25th Anniversary Virtual Conference! It was a pleasure to present and you really helped me to make this into a memorable experience to me, and I am sure, as well, to everyone that joined! www.youtube.com/live/EbUPk9O... #games #ai
youtube.com
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement analysis - Track 1
YouTube video by OWASP Foundation
002
Reposted by Uncle Joe
Jeroen @commjoenie.bsky.social · 22/09/2026
We released a new version of #OWASP #Wrongsecrets ! With devcontainer and AI related challenges. Try it out at www.wrongsecrets.com and give the repo a ⭐️ if you like it!
wrongsecrets.com
OWASP WrongSecrets
066
Uncle Joe @sydseter.com · 23/09/2026
If there is a super intelligence out there, please take him with you. www.bbc.com/news/article...
bbc.com
Super intelligence: Will Trump’s attempt to rebrand AI work?
Some people close to the president have started to use the term but experts say it is unlikely to catch on.
140
Uncle Joe @sydseter.com · 23/09/2026
Also, see me and others at BSides Amsterdam to learn OWASP Cornucopia. If you join, you may get one! app.tixnu.com/events/bside... And if you don't, you will have learned how to run our LLM Companion Guide Scenario and teach others to use the OWASP Cornucopia decks for threat modelling LLMs. #games
app.tixnu.com
BSides Amsterdam 2026 | Stichting Polder Security
BSides Amsterdam 2026 on November 19, 2026 at Amsterdam, Netherlands. BSides is a community-driven framework for building events for and by informatio...
001
Uncle Joe @sydseter.com · 23/09/2026
Someone sent me this package; guess what was inside... youtu.be/y99ojDg-M9Y?... Yes, just what you'd expect. The first OWASP Cornucopia Mobile App Edition v2. If you want one, you can buy them from @cybersecgames.bsky.social: cybersecgames.com/products/owa... #owasp #cornucopia #security #games
youtu.be
OWASP Cornucopia Mobile App Editionv2.0
YouTube video by Johan Sydseter
132
Uncle Joe @sydseter.com · 22/09/2026
Thank you so much to the wonderful organizers behind @owasp.org ’s 25th Anniversary Virtual Conference! It was a pleasure to present and you really helped me to make this into a memorable experience to me, and I am sure, as well, to everyone that joined! www.youtube.com/live/EbUPk9O... #games #ai
youtube.com
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement analysis - Track 1
YouTube video by OWASP Foundation
002
Uncle Joe @sydseter.com · 21/09/2026
Turns out, the polish airlines have misplaced all my luggage and equipment that I brought with me except these decks so now I have this and nothing else. I am becoming a more and more like a courier every day. This won’t go well. #owasp #cornucopia #security #games #appsec #threatmodeling
071
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 20/09/2026
Flying around Europe, trying to get through airport security with these. I realize I haven’t really thought «what can go wrong» before now. «No, they are not contrabands» «No, nothing to declare». I hope I still have my virginity intact when I arrive. See you hopefully soon @owasp-de.bsky.social!
3184
Uncle Joe @sydseter.com · 20/09/2026
Get your tickets now for Germany OWASP Day: owasp.glueup.com/event/german... #owasp #security #games #cornucopia #appsec #threatmodeling #threatmodelling
owasp.glueup.com
German OWASP Day 2026 | The OWASP Foundation Inc.
The OWASP German Chapter hosts its annual conference in Karlsruhe, September 23–24, 2026. Two days of application security: expert talks, community exchange, and hands-on insights.
012
Uncle Joe @sydseter.com · 20/09/2026
Flying around Europe, trying to get through airport security with these. I realize I haven’t really thought «what can go wrong» before now. «No, they are not contrabands» «No, nothing to declare». I hope I still have my virginity intact when I arrive. See you hopefully soon @owasp-de.bsky.social!
3184
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 17/09/2026
Cybersecurity awareness training during Cybersecurity Awareness Month is boring as hell. And research shows it's not working (source: www.cybersecuritydive.com/news/cyberse...); games, on the other hand, do work (source: www.researchgate.net/publication/...) #security #threatmodeling #games #appsec
1156
Uncle Joe @sydseter.com · 17/09/2026
OWASP Cornucopia is threat modelling for everyone, everywhere. We have labs with A1 posters, diagrams, presentations, game master cheat sheets, and live vulnerable LLM AI apps written in Java, TypeScript, .NET, Python, Android Java, and iOS Swift. Check it out: cornucopia.owasp.org/how-to-play#...
cornucopia.owasp.org
OWASP Cornucopia - How to play
Learn how to play the OWASP Cornucopia card game, including rules, strategies, and tips for effective threat modeling.
031
Uncle Joe @sydseter.com · 17/09/2026
But even if capture-the-flag competitions are great, you can feel left out if you don't have the necessary security and tech expertise. It's embarrassing to be at the bottom of the leaderboard. That is why threat modelling labs are great: they are team exercises. Anyone can understand a drawing. 2/3
110
Uncle Joe @sydseter.com · 17/09/2026
Cybersecurity awareness training during Cybersecurity Awareness Month is boring as hell. And research shows it's not working (source: www.cybersecuritydive.com/news/cyberse...); games, on the other hand, do work (source: www.researchgate.net/publication/...) #security #threatmodeling #games #appsec
1156
Uncle Joe @sydseter.com · 17/09/2026
Claiming that LLMs can be used for doing mathematical research, is like saying calculators can be used as computers. It’s anthropomorphization. LLMs do Lean, they don’t think for themselves.
0103
Uncle Joe @sydseter.com · 17/09/2026
Post by Jenny.
030
Reposted by Uncle Joe
Uncle Joe @sydseter.com · 12/09/2026
OpenAI’s claim that their AI can be used in mathematical research have been met with heavy backlash. Take f.ex. OpenAI’s claim they disproved the Connes Rigidity Conjecture. J. L. Nielsen from CTP, University of Kansas audited the code line-by-line and discovered that the AI's proof was invalid. #AI
eu.36kr.com
Mathematicians Disproved OpenAI's 24-Hour "Solved" Math Conjecture: AI Got Every Sentence Right But Result Irrelevant to Original Claim
Terence Tao, one of the world’s most influential and celebrated contemporary mathematicians, had long publicly released a critical early warning to the global academic community, tech researchers and ...
35126
Reposted by Uncle Joe
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 15/09/2026
The @OWASP board of elections is happening soon! Thank you to the 3 board members who have served who are ending their terms. Everyone, read up on the people running for the seats! Voting time is soon!
twp.ai
OWASP 2026 Global Board Elections
Vacancies, timeline, nominees, and candidates for the OWASP 2026 Global Board election.
062
Reposted by Uncle Joe
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 16/09/2026
Well, the AI agent escape story just got even more interesting. 😬 Researchers have linked AI agents being tested by OpenAI to an incident involving more than 500 malicious packages on RubyGems. New video 👇 twp.ai/9Ob6TE 1/7
A woman in a red sleeveless top sits in front of white shelves filled with books and awards, appearing to speak on camera. Large on-screen text reads, “AI Agents Just Became a Software Supply Chain Problem.”
152
Reposted by Uncle Joe
OWASP® Foundation @owasp.org · 15/09/2026
Ready to make security everyone’s job? Join Marisa Fagan & Juliane Reimann for an interactive training on building a Security Champions Program that actually works, with practical tools, hands-on exercises & real-world strategies. 💪🚀 owaspglobalappsecusa... #GlobalAppSecSanFran26
011
Reposted by Uncle Joe
Arkadii Yakovets · CCSP · CISSP · CSSLP @arkid15r.com · 16/09/2026
Formal open source programs run on their own calendar, and promising contributors are often ready before the next cycle opens. Maintainer, mentor, manager: why I fund contributors before programs do arkid15r.dev/open-source-...
arkid15r.dev
Maintainer, mentor, manager: why I fund contributors before programs do
Maintainer, mentor, then manager -- and when personal sponsorship bridges the gap so strong contributors keep shipping before a formal program says yes.
021
Uncle Joe @sydseter.com · 15/09/2026
«Passkey phishing» is such a misnomer. There is nobody that is phishing your passkeys. It happens exactly the same way as normal phishing. The only reason passkeys is mentioned is that the phishing email mentions passkeys. #security #passkeys #phishing
030