Sign in

Petrus Vasenius

@vasenius.fi
133 followers 201 following 136 posts

Cloud Security leader @ U42 🛡️☁️ | Reposts/Likes ≠ Endorsements | #CyberSecurity | #SecOps

PostsRepliesMedia
Reposted by Petrus Vasenius
InfoSec @infosec.skyfleet.blue · 14/08/2026
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
theregister.com
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
Another one bites the dust
022
Petrus Vasenius @vasenius.fi · 22/04/2026
Exclusive Anthropic Cyber Tool Mythos Accessed by Unapproved Actors t.co/h8GhJPhlC6
t.co
https://gbhackers.com/exclusive-anthropic-cyber-tool-mythos-breached/
000
Petrus Vasenius @vasenius.fi · 08/03/2026
open.substack.com/pub/alexeyon...
open.substack.com
How I Dropped Our Production Database and Now Pay 10% More for AWS
I’m working on expanding the AI Shipping Labs website and wanted to migrate its current version from static GitHub Pages to AWS.
000
Petrus Vasenius @vasenius.fi · 21/02/2026
I created a blog post based on my talk in #Disobey2026: vasenius.fi/beyond-the-p... #CyberSecurity #DataSecurity #Honeytokens
vasenius.fi
Beyond the Perimeter: Mastering Data Deception in the Cloud Era - The Security Everywhere
I recently had the distinct pleasure of presenting at the Disobey 2026 event in Helsinki. My session, titled Data Honeytokens […]
010
Petrus Vasenius @vasenius.fi · 23/01/2026
We analyze novel attack vectors where malicious JavaScript is dynamically generated at runtime. This process leverages client-side API calls to trusted LLM services, initiated from an initially benign webpage (hiding malicious code in a text prompt). Read the threat brief here: bit.ly/4qQW0Cp
bit.ly
The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time
We discuss a novel AI-augmented attack method where malicious webpages use LLM services to generate dynamic code in real-time within a browser.
000
Reposted by Petrus Vasenius
Disobey_Fi @disobeyfi.bsky.social · 21/01/2026
We have a new badge competition starting ...now! Create a game or (mini)app for the badge! Join and win awesome (disclaimer: with relative degrees of "awesome") prizes at Disobey 2026! To find out more, visit: disobey.fi/2026/competi...
051
Petrus Vasenius @vasenius.fi · 21/01/2026
Our research has identified a characteristic within Azure Private Endpoint deployments that could expose Azure resources to denial of service conditions. This finding pertains to the Azure Private Link mechanism: bit.ly/4r1nzZd
bit.ly
DNS OverDoS: Are Private Endpoints Too Private?
We've identified an aspect of Azure’s Private Endpoint architecture that could expose Azure resources to denial of service (DoS) attacks.
000
Petrus Vasenius @vasenius.fi · 14/01/2026
#MongoBleed vulnerability CVE-2025-14847 can expose sensitive data from heap memory. This includes cleartext credentials, API keys, session tokens and PII. Read our latest Threat Brief for details: bit.ly/4qVOkOM
bit.ly
Threat Brief: MongoDB Vulnerability (CVE-2025-14847)
Database platform MongoDB disclosed CVE-2025-14847, called MongoBleed. This is an unauthenticated memory disclosure vulnerability with a CVSS score of 8.7.
000
Petrus Vasenius @vasenius.fi · 09/01/2026
Vibe Coding and Vulnerability: Why Security Can’t Keep Up The promise of AI-assisted development, or “vibe coding,” is undeniable: unprecedented speed and productivity for development teams. unit42.paloaltonetworks.com/securing-vib... #VibeCoding #AISecurity #RiskManagement #Unit42
unit42.paloaltonetworks.com
Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk
AI-generated code looks flawless until it isn't. Unit 42 breaks down how to expose these invisible flaws before they turn into your next breach.
010
Petrus Vasenius @vasenius.fi · 21/12/2025
I wrote a new blog post based on my talk on #CloudBrew2025. vasenius.fi/how-to-secur...
vasenius.fi
How To Secure AI Services to comply with EU AI Act in Azure - The Security Everywhere
Context: I held a talk with the same topic in CloudBrew 2025 in Belgium, about this subject and now I […]
020
Petrus Vasenius @vasenius.fi · 18/12/2025
Russia Hits Critical Orgs Via Misconfigured Edge Devices - www.darkreading.com/endpoint-sec...
darkreading.com
Russia Hits Critical Orgs Via Misconfigured Edge Devices
Amazon detailed a long-running campaign by Russia against critical infrastructure organizations, particularly in the energy sector.
010
Reposted by Petrus Vasenius
Cloud Tech Tallinn @cloudtechtallinn.com · 08/12/2025
Starting the new week strong! 👏 We are excited to announce the sessions for our #Security track! And what a power house of speakers and sessions! 🤩 Get your tickets here: 🎫 cloudtechtallinn.com 🗓️ cloudtechtallinn.com/agenda #VisitTallinn #CTTT26
053
Petrus Vasenius @vasenius.fi · 18/11/2025
6 Predictions for the AI Economy: 2026's New Rules of Cybersecurity www.paloaltonetworks.com/perspectives...
paloaltonetworks.com
2026 Cybersecurity Predictions
Secure the autonomous enterprise. Get 6 essential predictions detailing the new rules of cybersecurity required to innovate confidently in the AI-native economy.
010
Petrus Vasenius @vasenius.fi · 16/11/2025
Microsoft is increasing prices for many of its products due to changes in its Enterprise Agreement (EA) volume licensing, effective November 1, 2025. The company is eliminating tiered discounts. This change will result in a cost increase of 6% to 12% for many. www.microsoft.com/en-us/licens...
microsoft.com
Microsoft Online Services: Pricing Consistency Update | Microsoft Licensing Resources
Upcoming updates to Online Services pricing under volume licensing programs.
000
Reposted by Petrus Vasenius
Hacker & Security News @hacker.at.thenote.app · 11/11/2025
Struggling to manage it all at work? 5 ways to delegate like a pro - and lighten your load Leading isn't easy. Five business leaders share how to hand off responsibility, build trust, and focus on long-term success. #hackernews #news
zdnet.com
Struggling to manage it all at work? 5 ways to delegate like a pro - and lighten your load
Leading isn't easy. Five business leaders share how to hand off responsibility, build trust, and focus on long-term success.
011
Petrus Vasenius @vasenius.fi · 01/11/2025
If you want to learn more about how to use the #entraid advanced features for your blue team, check out my talk on Thursday at 11.45 AM! #iam #CyberSecurity #tallinn
021
Reposted by Petrus Vasenius
elainegoldie.bsky.social @elainegoldie.bsky.social · 24/10/2025
Amazon Outage is Waking People up Regarding Our Slavery to the Internet - U.S. Government Failing in Defense Against Cyberattacks medicalkidnap.com/2025/10/23/a...
medicalkidnap.com
Amazon Outage is Waking People up Regarding Our Slavery to the Internet – U.S. Government Failing in Defense Against Cyberattacks - Medical Kidnap
In the wake of the Amazon Web Services (AWS) outage earlier this week, there have been numerous articles published in the media concerning just how vulnerable our society has become to just a few Big ...
012
Petrus Vasenius @vasenius.fi · 22/10/2025
A foreign actor infiltrated the National Nuclear Security Administration’s Kansas City National Security Campus through vulnerabilities in Microsoft’s SharePoint browser-based app, raising questions about the need to solidify further federal security protections. www.csoonline.com/article/4074...
csoonline.com
Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
A foreign actor infiltrated the National Nuclear Security Administration’s Kansas City National Security Campus through vulnerabilities in Microsoft’s SharePoint browser-based app, raising questions a...
000
Reposted by Petrus Vasenius
Hacker & Security News @hacker.at.thenote.app · 19/10/2025
ConnectWise fixes Automate bug allowing AiTM update attacks ConnectWise released a security update to address vulnerabilities, one of them with critical severity, in Automate product that could expose sensitive communications to interception and modification. [...] #hackernews #news
bleepingcomputer.com
ConnectWise fixes Automate bug allowing AiTM update attacks
ConnectWise released a security update to address vulnerabilities, one of them with critical severity, in Automate product that could expose sensitive communications to interception and modification. [...]
011
Reposted by Petrus Vasenius
Phill Moore @handle.invalid · 19/10/2025
Week 42 - 2025 #DFIR thisweekin4n6.com/2025/10/19/w...
thisweekin4n6.com
Week 42 – 2025
Inside the Salesloft-Drift Breach: What It Means for SaaS & Identity SecurityIn this session, Permiso’s CTO will cover:- How attackers moved from GitHub → AWS → Salesforce using stolen OAuth to…
043
Reposted by Petrus Vasenius
dotnewstv.bsky.social @dotnewstv.bsky.social · 19/10/2025
China accuses US of cyberattack: Beijing says sensitive info stolen; what is National Time Center? Representative image (AI) China on Sunday accused the US National Security Agency (NSA) of carrying out cyberattacks on its National Time Service Center. It further warned that any damage to the…
dotnewstv.in
China accuses US of cyberattack: Beijing says sensitive info stolen; what is National Time Center?
Representative image (AI) China on Sunday accused the US National Security Agency (NSA) of carrying out cyberattacks on its National Time Service Center. It further warned that any damage to the facility could disrupt network communications, financial systems and power supply.The Ministry of State Security said in a WeChat post that the US agency exploited vulnerabilities in the messaging services of a foreign mobile phone brand in 2022 to steal sensitive information from devices used by the center’s staff.
011
Petrus Vasenius @vasenius.fi · 15/10/2025
Just shared a new blog post on how Microsoft Azure’s Security Suite gets even stronger with Palo Alto Networks’ tech and Unit 42’s intelligence. It’s about collaboration, visibility, and resilience across every layer of defense. Read here 👇 vasenius.fi/enhancing-mi...
vasenius.fi
Enhancing Microsoft Azure's Security Suite with Palo Alto Networks and Unit 42 - The Security Everywhere
Disclaimer: This post reflects my personal perspective as I begin my new role at Unit 42. The views expressed here […]
110
Reposted by Petrus Vasenius
Hacker & Security News @hacker.at.thenote.app · 13/10/2025
NDSS 2025 – Keynote 2: Towards Resilient Systems In An Increasingly Hostile World Author, Creator & Presenter: Dr. Kathleen Fisher PhD, Director, Information Innovation Office (I2O), US Defense Advanced Research Projects Agency (DARPA) Our thanks to the Network and Distributed … #hackernews #news
securityboulevard.com
NDSS 2025 – Keynote 2: Towards Resilient Systems In An Increasingly Hostile World
Author, Creator & Presenter: Dr. Kathleen Fisher PhD, Director, Information Innovation Office (I2O), US Defense Advanced Research Projects Agency (DARPA) Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the organization’s’ YouTube channel.
022
Reposted by Petrus Vasenius
InfoSec @infosec.skyfleet.blue · 13/10/2025
Financial, Other Industries Urged to Prepare for Quantum Computers
darkreading.com
Financial, Other Industries Urged to Prepare for Quantum Computers
Despite daunting technical challenges, a quantum computer capable of breaking public-key encryption systems may only be a decade or two off.
011
Reposted by Petrus Vasenius
InfoSec @infosec.skyfleet.blue · 13/10/2025
PoC Exploit Unveiled for Lenovo Code Execution Vulnerability Enabling Privilege Escalation
cybersecuritynews.com
PoC Exploit Unveiled for Lenovo Code Execution Vulnerability Enabling Privilege Escalation
021
Petrus Vasenius @vasenius.fi · 06/10/2025
Excited to be part of the new Evo Finland podcast episode on Security x AI 🎙️ We dive into when to build vs. buy AI tools, the newest AI-native threats, and why human oversight still matters. 🎧 Listen here: open.spotify.com/episode/5JbU... #AI #CyberSecurity #EvoFinland
open.spotify.com
Evo Finland #27 - Security & AI In Practice
010
Petrus Vasenius @vasenius.fi · 17/09/2025
Rolling out Microsoft Purview just got easier. This friendly deployment guide turns the latest models and the lightweight blueprint into a simple good, better, best path. Start fast, protect data, grow with confidence. Read more: vasenius.fi/how-to-choos... #MicrosoftPurview #DataSec
vasenius.fi
How to Choose the Right Microsoft Purview Deployment Model - The Security Everywhere
Rolling out Purview doesn’t have to feel like a maze. Microsoft has packaged its guidance into short, scenario driven “deployment […]
000
Petrus Vasenius @vasenius.fi · 09/09/2025
Anatomy of a Billion-Download NPM Supply-Chain Attack open.substack.com/pub/jdstaerk...
open.substack.com
Anatomy of a Billion-Download NPM Supply-Chain Attack
A massive NPM supply chain attack has compromised foundational packages like Chalk, affecting over 1 billion weekly downloads. We dissect the crypto-stealing malware and show you how to protect your p...
010
Petrus Vasenius @vasenius.fi · 08/09/2025
Unify SecOps with Sentinel Data Lake and Defender XDR. Learn RBAC hardening, onboarding, incident correlation, Purview audit logging, and cost aware retention. vasenius.fi/microsoft-pu... #MicrosoftSecurity #SecOps #SecurityOperations #MicrosoftSentinel #MicrosoftPurview
vasenius.fi
Microsoft Purview with Unified SecOps - Powerful Combination? - The Security Everywhere
Unify SecOps with Sentinel Data Lake and Defender XDR. Learn RBAC hardening, onboarding, incident correlation, Purview audit logging, and cost aware retention.
000
Petrus Vasenius @vasenius.fi · 05/09/2025
Russian APT28 Deploys "NotDoor" Outlook Backdoor Against Companies in NATO Countries thehackernews.com/2025/09/russ...
thehackernews.com
Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries
APT28 deploys NotDoor Outlook backdoor via OneDrive DLL side-loading, enabling email-based data theft in NATO firms.
000
Petrus Vasenius @vasenius.fi · 29/08/2025
Cloud sovereignty = ensuring data stays under local laws while benefiting from cloud scale + innovation. Learn more: 🔹 Azure: learn.microsoft.com/en-us/indust... 🔹 AWS: aws.amazon.com/compliance/d... 🔹 Gaia-X: gaia-x.eu #CloudSovereignty #DataControl
learn.microsoft.com
110
Petrus Vasenius @vasenius.fi · 29/08/2025
This MVP Award kit is so cool! Hope to get some more disks into this in future. #MVPBuzz
030
Reposted by Petrus Vasenius
Tivi @tivilehti.bsky.social · 18/08/2025
GPT-5:n pettymys nosti esiin kiusallisen totuuden – Suomalaisprofessori avaa, miksi kielimallit kompuroivat
tivi.fi
GPT-5:n pettymys nosti esiin kiusallisen totuuden – Suomalaisprofessori avaa, miksi kielimallit kompuroivat
GPT-5:n epäonnistunut lanseeraus on herättänyt taas keskustelua kielimallien kehityksen hidastumisesta. Helsingin yliopiston tietojenkäsittelyprofessori Hannu Toivonen kertoo, että kielimallit eivät voi kehittyä loputtomiin.
021
Petrus Vasenius @vasenius.fi · 11/08/2025
Researchers Uncover GPT-5 Jailbreak and Zero-Click AI Agent Attacks Exposing Cloud and IoT Systems thehackernews.com/2025/08/rese...
thehackernews.com
Researchers Uncover GPT-5 Jailbreak and Zero-Click AI Agent Attacks Exposing Cloud and IoT Systems
Researchers bypass GPT-5 guardrails using narrative jailbreaks, exposing AI agents to zero-click data theft risks.
000
Petrus Vasenius @vasenius.fi · 06/08/2025
Check this out! 👇🏻 Project Ire autonomously identifies malware at scale www.microsoft.com/en-us/resear... #MicrosoftResearch
microsoft.com
Project Ire autonomously identifies malware at scale
Designed to classify software without context, Project Ire replicates the gold standard in malware analysis through reverse engineering. It streamlines a complex, expert-driven process, making large-s...
000
Petrus Vasenius @vasenius.fi · 06/08/2025
Cut down investigation time and surface real insider threats faster: automate your Insider Risk Management workflow in Microsoft Purview with policy templates, adaptive protection, and Power Automate. vasenius.fi/how-to-autom... #MicrosoftPurview #insiderriskmanagement #DataSecurity
vasenius.fi
How to Automate Insider Risk Management Using Microsoft Purview Risk Policies - The Security Everywhere
Learn how to turn insider risk detection into consistent, scalable action by automating workflows with Microsoft Purview risk policies, adaptive protection, and Power Automate - complete with playbook...
000
Petrus Vasenius @vasenius.fi · 04/08/2025
🚀 Thrilled to announce that I’ll be speaking at #CloudBrew2025, two-day Azure community conference in Mechelen, Belgium (11-12 December 2025)! Join me on Friday 12 Dec at 11:40 CET for my advanced security talk about AI Security at Alcazar room. #AzureSecurity #MicrosoftAI #Conference
040
Petrus Vasenius @vasenius.fi · 01/08/2025
I am pleased to share, that I have been nominated as Microsoft Security #MicrosoftMVP. I wrote a brief blog post about my journey: vasenius.fi/my-journey-t...
vasenius.fi
My Journey To Receive a Microsoft Security MVP Nomination - The Security Everywhere
I am pleased to publish, that I have been nominated as a Microsoft Security MVP in August, 2025. This milestone […]
030
Petrus Vasenius @vasenius.fi · 28/07/2025
Microsoft admits it 'cannot guarantee' data sovereignty www.theregister.com/2025/07/25/m...
theregister.com
Microsoft exec admits it 'cannot guarantee' data sovereignty
: Under oath in French Senate, exec says it would be compelled – however unlikely – to pass local customer info to US admin
000
Reposted by Petrus Vasenius
Nicole Tersigni @nicsigni.bsky.social · 23/07/2025
back from vacation (a week ago) and about to make it everyone’s problem
Painting of a woman at a table looking at another woman who is holding a serving tray. My caption “can I get you anything else?” “A new president and another coffee would be great.”
195172112057
Reposted by Petrus Vasenius
InfoSec @infosec.skyfleet.blue · 24/07/2025
Plankey vows to boot China from U.S. supply chain, advocate for CISA budget
cyberscoop.com
Plankey vows to boot China from U.S. supply chain, advocate for CISA budget
President Donald Trump’s pick to lead CISA told senators Thursday that he would prioritize evicting China from the U.S. supply chain.
011
Petrus Vasenius @vasenius.fi · 27/06/2025
Suomi aikoo hankkia ensimmäiset omat satelliitit ­puolus­tuskäyttöön yle.fi/a/74-20169892
yle.fi
Suomi aikoo hankkia ensimmäiset omat satelliitit ­puolus­tuskäyttöön
Uutiset nopeasti ja luotettavasti.
010
Petrus Vasenius @vasenius.fi · 23/06/2025
www.hs.fi/paakirjoituk...
hs.fi
Kolumni | Linkedin näyttää, kuinka epävarmuus ja pelko leviävät keskiluokassa
Digitalisaatio on mullistanut korkeakoulutettujen työelämän. Myöhäiskapitalismin säikäyttämät ihmiset tuottavat outoa synteettistä henkilöstöhallintokieltä, ruutuväsymyksen esperantoa.
020
Petrus Vasenius @vasenius.fi · 18/06/2025
We're at @zure.com are proud to share that we've earned two more Microsoft Specializations: 🔹 Build AI Apps on Microsoft Azure 🔹 Threat Protection That brings us to a total of six Specializations—an exciting milestone for our growing team of Azure experts.
032
Petrus Vasenius @vasenius.fi · 06/06/2025
Microsoft offers to boost European governments' cybersecurity for free www.reuters.com/sustainabili...
reuters.com
Microsoft offers to boost European governments' cybersecurity for free
Microsoft is offering free of charge to European governments a cybersecurity programme, launched on Wednesday, to bolster their defences against cyber threats, including those enhanced by artificial intelligence, it said.
000
Petrus Vasenius @vasenius.fi · 30/05/2025
Lately, I’ve been working with Data Management Landing Zones (DMLZ) and have compiled a set of practical insights and deployment tips for successful implementation. vasenius.fi/getting-star... #DataManagement #DataSecurity #DMLZ
vasenius.fi
Getting started with Azure Data Management Landing Zone - The Security Everywhere
The Data Management Landing Zone (DMLZ) is the cornerstone of Microsoft’s Cloud-Scale Analytics framework. When implemented correctly, it gives every […]
010
Petrus Vasenius @vasenius.fi · 21/05/2025
I wrote a brief collection of Security updates, picked from the MS Build "Book of News”. MS Build is an annual developer conference hosted by Microsoft. 🔗 Read the list from here: vasenius.fi/microsoft-bu... #AISecurity #MSSecurity #CloudSecurity #MSBuild
vasenius.fi
Microsoft Build 2025 — Security Highlights in the “Book of News” - The Security Everywhere
Microsoft Build (often shortened to MS Build) is an annual developer conference hosted by Microsoft. It’s designed primarily for software […]
020
Reposted by Petrus Vasenius
Micah Lee @micahflee.com · 19/05/2025
DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage's archive server micahflee.com/ddosecrets-p...
micahflee.com
DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage's archive server
This morning, Distributed Denial of Secrets published 410 GB of data hacked from TeleMessage, the Israeli firm that makes modified versions of Signal, WhatsApp, Telegram, and WeChat that centrally arc...
613476
Reposted by Petrus Vasenius
Tivi @tivilehti.bsky.social · 20/05/2025
⭐ Suomi saa IQM:n tehokkaimman kvanttitietokoneen – VTT:n tilaamassa laitteessa kuusinkertainen määrä kubitteja nykyiseen verrattuna
tivi.fi
Suomi saa IQM:n tehokkaimman kvanttitietokoneen – VTT:n tilaamassa laitteessa kuusinkertainen määrä kubitteja nykyiseen verrattuna
Uuden kvanttitietokoneen on määrä valmistua kahden ja puolen vuoden kuluessa. Kubittimäärä nousee jopa kolmeensataan.
031