Detection and exposure management
Threat hunting, network analysis, patching, hardening, attack-surface inventory, risk-based prioritization, and incident response.
30%
Best tweets about Cybersecurity
Discover the best tweets about cybersecurity, including vulnerabilities, attacks, defense, privacy, threat research, security engineering, and incident lessons.
Credible cybersecurity research, vulnerabilities, defensive practices, incidents, threat analysis, privacy, and security engineering lessons.
Original Xholic analysis
Cybersecurity discussion in this sample covers exposure management, hands-on practice, and AI as both a security tool and a potential risk. The Vercel incident update recommends access monitoring and secret rotation; separate guidance addresses AI connector permissions. Posts debating frontier models distinguish reported findings from predictions about wider risks.
40% of posts
All-time engagement
44% of posts
Published in 90 days
Conversation map
Threat hunting, network analysis, patching, hardening, attack-surface inventory, risk-based prioritization, and incident response.
30%
Hands-on labs, research resources, career paths, governance roles, and lessons about usable controls and security-industry incentives.
30%
AI-driven vulnerability discovery, exploitation, patching, offensive benchmarks, and debate over the scale of emerging risks.
24%
Agent permissions, production access, prompt injection, connector governance, data leakage, and safe AI adoption.
24%
Breach investigations, attacker movement and exfiltration, public-sector incidents, and careful assessment of unverified leak claims.
22%
Technical findings, exploit paths, bug bounties, secure design, and the shrinking interval between disclosure and exploitation.
22%
Credential hygiene, MFA, access visibility, DLP, sensitive-data governance, backups, and privacy-preserving tools.
14%
Compromised dependencies, credential theft across software ecosystems, infostealers, and malware analysis.
12%
Tone and stance
Performance benchmark
Posts with media make up 60% of this collection. Their median all-time score is 3.93, compared with 8.38 for text-only posts.
Format mix
Consensus and debate
Shared view
The Vercel incident update recommends secret rotation and access monitoring. Separate defender posts recommend tracking AI connector grants and hunting for suspicious third-party application activity, including where a compromised Axios build is not present locally.
Shared view
One researcher recommends starting with questions to answer, and another describes learning through a packet-analysis lab. A separate post argues that approved AI tools should be practical enough to discourage workarounds.
Open debate
One post urges taking emerging model risks seriously despite imperfect benchmarks; another accepts improving cyber capabilities but criticizes catastrophic framing around a limited-access model. A post describing an independent offensive-task benchmark contributes evidence without settling that disagreement.
What performs
The supplied analytics identify these five posts as all-time-score outliers. They cover an AI vulnerability-demo claim, a report of evaluation incidents, the Vercel response, connector monitoring, and Axios hunting. Their underlying claims should not be treated as equally verified.
In the supplied sample, posts without media have a median all-time score of 8.38, versus 3.93 for posts with media. Tutorial and list medians are 8.89 and 10.614, respectively. The cited connector guide, network lab, and research-resource list illustrate those formats; the comparison does not establish why they scored differently.
Statistical standouts
Creator landscape
The five most represented creators account for 20% of the selected posts.
1. Steven Lim
@0x534c
2 posts
2. flux
@0xfluxsec
2 posts
3. Mackenzie Jackson -
@advocatemack
2 posts
4. Jo Peterson
@cleartechtoday
2 posts
5. Dark Web Intelligence
@DailyDarkWeb
2 posts
6. Ethan Mollick
@emollick
2 posts
Steven Limโs two posts offer detection guidance concerning connector permissions and potential Axios-related exposure. Ethan Mollickโs two posts discuss frontier-model risk and an offensive-task benchmark. The former offer operational leads; the latter address how to interpret emerging capabilities.
Since the previous snapshot
Themes, sentiment, stance, and post format are classified per tweet. All counts, shares, medians, creator concentration, freshness, and performance comparisons are then calculated directly from the published snapshot.
Xholic's all-time score compares engagement while accounting for reach, post age, and creator consistency. It is used for relative comparisons within this collection.
This report analyzes the exact 50-post snapshot shown below. AI identifies editorial categories and drafts explanations; all statistics are calculated from the snapshot, and every narrative claim is checked against cited posts before publication.
Best Cybersecurity tweets
Ranked 01โ50
@chiefofautism ยท
someone at ANTHROPIC just showed CLAUDE finding ZERO DAY vulnerabilities in a live conference demo claude has found zero day in Ghost, 50,000 stars on github, never had a critical security vulnerability in its entire, history... it found the blind SQL injection in 90 minutes, stole the admin api key, then did the exact, same thing to the linux kernel
@AnthropicAI ยท
In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Our post describes what happened, how it happened, and what weโre changing. We encourage other AI developers to perform similar reviews. We conducted this review together with @Irregular, one of our evaluation partners, and thank them for the joint investigation and their collaboration on this post. This type of collaboration is increasingly critical to safe, rigorous evaluation of models, and we look forward to continuing to work together on security. https://t.co/dKFCdpKd9v
@rauchg ยท
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called https://t.co/7PY6gGtzgI that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleagueโs compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as โnon-sensitiveโ. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. Weโve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. Weโve deployed extensive protection measures and monitoring. Weโve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (https://t.co/BLVnic9fJC). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customersโ security postures, weโve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, Iโm totally open to your feedback. Weโre working with elite cybersecurity firms, industry peers, and law enforcement. Weโve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. Itโs my mission to turn this attack into the most formidable security response imaginable. Itโs always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
@0x534c ยท
๐ฅ๐ค M365 Connector for Claude โ Why SecOps Must Care Monitoring the M365 Connector for Claude is critical because when ResultType=0, it means an Entra Global Admin has granted permissions, enabling Claude to directly access SharePoint, OneDrive, Outlook, and Teamsโa governance decision with major security implications that SecOps must track closely. Meanwhile, ResultType=90095 shows end users attempting to use the connector without the admin grant, signaling demand, shadow IT risk, and adoption pressure. By watching both signals, defenders gain visibility into where governance decisions meet user behavior, ensuring connector risks are managed before they escalate. KQL Code: https://t.co/NGuwSLgvKF #Cybersecurity #M365ConnectorClaude #Entra #Governance

@0x534c ยท
๐ Think Youโre Safe Without Axios? Think Again If your environment does not contain a compromised Axios build, that doesnโt close the case. Axios is a widely adopted JavaScript HTTP client used across countless web applications. Even if your own systems are clean, your end users may still interact with thirdโparty applications that rely on Axios and authenticate against your tenant via Entra ID. This creates a potential pathway for threat actors to access tenant data through compromised external apps. Because of this broader exposure surface, itโs essential for defenders to deploy the advanced hunting detection below to monitor for suspicious Axiosโbased activity and identify potential abuse early. KQL Code: https://t.co/HPYLV8XaqV #Cybersecurity #Axios #NPMSupplyChainCompromise #KQL #DefenderXDR

@emollick ยท
I am catching glimpses in my feed that there is a backlash against Mythos as "marketing hype," and it is a little confusing. I don't think anyone who has used the latest agentic coding tools, would think that expecting large-scale cybersecurity implications of increasingly good AI models is unbelievable, especially after reading the red team reports. It feels like a better place to start is to assume that there are new risks, and then we can all laugh at Anthropic and pat each other on the back if there are not. Also, while the AI labs certainly are impressed by their own accomplishments and benchmarks are flawed, I would note that both publicly and privately, Mythos seems to be taken seriously at a lot of large institutions and organizations filled with smart people who would rather not be worried about a new cybersecurity risk. Finally, I am not sure "our product is dangerous and we need to alert the government to that" is the sales pitch to the corporate world that critics seem to think it is.
@ZackKorman ยท
Cybersecurity is a broken industry. We rely on products that were designed to be sold, not used. And the incentives are completely screwed up. I made this video about all of the ways things are bad, how we accidentally make it worse, and why new technology won't fix it.
@emollick ยท
Hereโs an independent domain extension of METRโs famous time-horizon analysis, applying it to offensive cybersecurity with real human expert timing data Similar to METR: 5.7 months doubling time. Frontier models now succeed 50% of the time at tasks that take human experts 10.5h.


@WeldPond ยท
The window between vulnerability disclosure and real-world exploitation keeps shrinking. The Zero Day Clock visualizes how fast attackers are operationalizing new CVEs. What used to take months now often happens in days, or hours. The future needs to be Secure by Design. https://t.co/zFXOSKB7eq #AppSec #CyberSecurity
@ZackKorman ยท
Non-cyber people will be like "damn cybersecurity is crazy right now" and then two days later post "gotta give your agent access to prod or you're ngmi." They don't see the connection between these things, and that's why cybersecurity is hard.
@0xfluxsec ยท
This is my last week working professionally on a Red Team, excited to be joining the super talented people over at @elastic in just over a week as a Senior Security Research Engineer! Alongside my regular red team work I have been lucky enough to have a day a week secondment with a partner organisation performing Windows security research. One massive thing I have learned that I thought would be worth sharing, is having questions to answer in security research is super important when it comes to learning, growing skills and finding things which matter. Whilst poking at stuff in free time is fun - you will find you have much greater success when there are legitimate questions to answer. If you enjoy it as a hobby / want to grow deeper skills - try that :).
@gabbytech01 ยท
This is Day 5 of my #100daysNetworkSecurity Today I went off book for a bit, and tried something different I built a Network Traffic Analysis Lab using TCPDump + Wireshark Hereโs what I actually learned: Captured real network traffic with tcpdump and analyzed it properly in Wireshark. This is exactly how actual security engineers look at networks. ICMP (Ping) is super simple echo request goes out, reply comes back. TTL tells you the hop count. Basic connectivity check, but yeah, it can also be abused for ICMP floods and DoS attacks.DNS traffic is wild. I queried https://t.co/wWRjF9w1Hx and saw A, AAAA, and PTR records flying around. DNS literally spills everything about what users are doing. ARP is that quiet hero resolves IP to MAC address. No ARP = no local communication. But of course it can be abused for ARP spoofing and MITM attacks. Biggest realization for me: Packets donโt just โmoveโ. Everything goes through proper encapsulation Data โ Segment โ Packet โ Frame โ Bits. That layered structure is literally everything. This little project completely changed how I see networks now. Itโs not about devices or cables anymore. Itโs just structured data flowing through different layers. GitHub repo https://t.co/lq2nckCcHX #CyberSecurity #Wireshark #TCPDump @segoslavia @akintunero @NetworkQueenX




@zaimiri ยท
Security agents are growing quick. One repo has 754 cybersecurity skills for AI agents. Not prompts. Structured procedures mapped to security frameworks: > Cloud security > Pentesting > Red teaming > Incident response > Malware analysis > Threat intel This is where agent work gets interesting. The model is not just answering security questions. It is being given the operating procedure before it acts.

@ShieldifySec ยท
The best place to start Solana security research ๐คฏ โข A curated repo covering vuln classes, audit tools, CTFs, and learning resources โ all in one place: ๐ https://t.co/cf6CuU7Ufz Want real-world context? Study top-tier audits: โข OtterSec โ some of the highest-quality public Solana reports ๐ https://t.co/ITnu3qR3Mh โข Accretion โ clean, well-structured professional findings ๐ https://t.co/531FWBCRJU
@TheJobfather__ ยท
Governance, Risk, and Compliance Analyst is a strong path into cybersecurity without needing to be a hardcore hacker. GRC focuses on policies, audits, controls, risk, compliance, and evidence. To build proof, pick a framework like NIST or ISO 27001 and create a mini risk register. Include the risk, impact, likelihood, control, owner, and mitigation plan. This is how you show you can think in controls and risk.
@aiwithjainam ยท
BIG TECH BUILT A TRILLION-DOLLAR BUSINESS BY WATCHING YOU. 10 PRIVACY TOOLS BIG TECH HOPES YOU NEVER DISCOVER Bookmark every single one. They protect your searches, files, location, email, browser, and phone without forcing you to become a cybersecurity expert. 1. https://t.co/HYqV3pjS6o Portmaster shows every connection leaving your computer in real time. Open Spotify, Windows, or a random app and see exactly which companies it secretly contacts. Block individual connections, entire apps, trackers, ads, malware, and telemetry. Free, open source, and available for Windows and Linux. 2. https://t.co/6ctP5LJRHr Firefox rebuilt by people who thought Firefox was still collecting too much. LibreWolf removes telemetry, sponsored content, data collection, and other annoyances, then turns on stronger tracking and fingerprinting protection by default. No account required. No company using your browsing habits to build an advertising profile. 3. https://t.co/FCnWWl8F6X Install one app on Android and suddenly you can see which apps are secretly connecting to the internet. RethinkDNS lets you block trackers, ads, malware, and internet access for any app on your phone. It combines encrypted DNS, a firewall, and WireGuard support in one free open-source app. 4. https://t.co/Vq29qgJWsV Stop giving every website your real email address. Addy. io creates a different alias for every account and forwards the messages to your normal inbox. If one company leaks your address or starts spamming you, switch off that alias instantly. You can even reply without revealing your real email. Free and open source. 5. https://t.co/AUVqq1tKH8 Google remembers what you searched, when you searched it, and which result you opened. SearXNG pulls results from hundreds of search services without building a profile around you. Pick a public instance and search immediately, or host your own if you want complete control. Free, open source, and no account required. 6. https://t.co/ZVTcC5dLX4 Keep using Google Drive, Dropbox, OneDrive, or iCloud without letting the provider read your files. Cryptomator encrypts every file and filename on your device before it reaches the cloud. The cloud company stores an unreadable vault, while only you hold the key. The desktop app is free, open source, and needs no account. 7. https://t.co/XWbiTcmVYs Google Maps can learn where you live, work, shop, and travel. Organic Maps downloads entire countries to your phone and handles search, directions, hiking routes, cycling routes, and navigation completely offline. No ads, tracking, data collection, registration, or background calls home. Free forever and powered by OpenStreetMap. 8. https://t.co/VpZiCg4fTp Lose your phone and many authenticator apps can lock you out of your own accounts. Ente Auth backs up your two-factor codes with end-to-end encryption and syncs them across Android, iPhone, Windows, Mac, Linux, and the web. Only you can decrypt them. Completely free and open source. 9. https://t.co/HipfpdR4HI The photo you share can contain the exact device, camera settings, date, software, and GPS coordinates attached to it. ExifCleaner strips hidden metadata from photos, videos, PDFs, and more than 90 file formats before you publish them. Drag in an entire folder and clean everything locally. Free, private, and open source. 10. https://t.co/MOekeuZssi Send files without uploading them to Google Drive, Dropbox, WeTransfer, or somebody elseโs server. OnionShare turns your computer into a temporary private server and transfers the files through the Tor network. No account, permanent link, central storage, or company sitting between you and the recipient. It can also host websites and private chats. Big Tech calls surveillance a feature. Open-source developers built the off switch.




@mclynd ยท
During the DARPA AI Cyber Challenge, autonomous AI systems uncovered 18 zero-day vulnerabilities and patched 61% of them in 45 minutes. Without any human input. Zero-days are the most dangerous class of software vulnerability. Attackers prize them because they're unknown to defenders. A human security team might take weeks or months to find one, if they find it at all. An AI did it 18 times in under an hour. And then patched most of them. This is a preview of where both offensive and defensive cybersecurity are heading. The same capability that can find vulnerabilities and patch them can find vulnerabilities and exploit them. The question is who gets there first, and whose AI is faster. The DARPA AI Cyber Challenge was a proof of concept. The nation-state actors who've been watching that competition already have teams working on the offensive version. Security teams that don't have AI in their stack aren't just behind. They're playing a fundamentally different game than the one being played against them.

@vivoplt ยท
7 pieces of free software for cybersecurity enthusiasts: 1. Training: Hack The Box 2. Curated News: Feedly 3. Web Hacking: Burp Suite 4. Data Modification: Cyber Chef 5. Port Scan: Nmap 6. Operating System: Kali Linux 7. Debugging: Ghidra
@DailyDarkWeb ยท
๐ช๐บ European Commission Confirms Cyber Incident The European Commission has officially confirmed a cyberattack impacting its Europa web platform infrastructure. ๐ Key details: โข Incident discovered on March 24 โข Affected: cloud infrastructure hosting https://t.co/2Vidx25rH7 services โข Services remained operational during containment โ ๏ธ Early findings: โข Potential data exfiltration from affected websites โข Impacted entities are being notified โข Investigation is ongoing ๐จ Threat actor claims: โข Alleged theft of ~350 GB of data โข Claims of access to AWS-related infrastructure โข Shared screenshots circulating as proof (not independently verified) ๐ก๏ธ Official statement highlights: โข Internal systems not affected โข Incident contained with mitigation measures โข Continued monitoring and security enhancements underway ๐ Assessment: This incident reflects the ongoing trend of targeting public sector cloud environments, combining data theft claims with reputational impact operations. #CyberSecurity #ThreatIntel #EuropeanCommission #DataBreach #CloudSecurity #CyberThreatIntelligence #OSINT #DailyDarkWeb
@gabbytech01 ยท
Spent months bouncing between cyber security niches like a headless chicken. Pentesting, bug hunting, couple others that all tasted like disappointment. Finally landed in Security Engineering focused on Network and weirdly... I'm not actively planning my escape. Why? Because actually building and hardening the damn network so stuff doesn't get in, feels more real than writing reports nobody reads or hunting ghosts. Impact is measurable. Fires are preventable instead of just spectacular. Now I'm grinding through CCNA Because apparently knowing how the network actually works, might help me not look like a complete idiot in this role. Probably jinxed it now. Don't @ me.
@mark_k ยท
The AI cybersecurity hysteria is getting absurd. Yes, frontier models are becoming much better at finding and exploiting vulnerabilities. That matters. But Anthropicโs rollout of Claude Mythos feels less like sober risk communication and more like a fear-marketing campaign around a model most people cannot even test. A mythical, unreleased AI model, shown to a handful of partners, is now being treated as if it has already broken the internet. AI will change cybersecurity. No doubt. But turning every new benchmark into doomsday theatre mostly helps the companies selling access to the panic.
@YuHelenYu ยท
1 in 3 organizations breached last year. Fewer than 1 in 4 have a password manager. 74% lack complete identity visibility. This is a governance failure. Just published State of Workforce Password Security 2026 with 3,322 responses across 9 regions in collaboration with @Zoho. Identity risk is still not being managed as a core control surface. Full report โ https://t.co/UCzEmZgiqS Watch my conversation with Chandramouli Dorai, Chief Evangelist at @Zoho โ https://t.co/wc0vLvw8no #CyberSecurity #IdentitySecurity #BoardGovernance #ZohoPartner
@alexabelonix ยท
Ethical Hacking Roadmap 1. Computer & Internet Fundamentals 2. Networking Essentials 3. Linux & Command Line Basics 4. Basic Programming 5. Operating System Internals 6. Web Technologies & HTTP Protocol 7. Setup Lab Environment 8. Introduction to Ethical Cybersecurity 9. Information Gathering 10. Network Scanning 11. Enumeration Techniques 12. Vulnerability Assessment Tools 13. System Security Testing 14. Malware Concepts & Prevention 15. Network Monitoring & Packet Analysis 16. Social Engineering Awareness 17. Service Disruption Testing 18. Session Security & Spoofing 19. Web App Testing 20. Wireless Network Security 21. Intrusion Detection Systems 22. Cryptography Basics 23. Exploitation Tools 24. Reverse Engineering Introduction 25. Malware Analysis 26. Capture The Flag (CTF) Challenges 27. Vulnerability Disclosure & Bug Bounty 28. Red Team Skills & Simulation 29. Industry Certifications
@TCraf7 ยท
I've had a concerning trend start to pop up during Purple Team Engagements, where analysts tell us, "The AI said everything is fine." That sentence is a huge problem. Seeing Teams devolve from Hunters to Prompters won't lead to anything good.. So I wrote a quick post on how teams are trading instinct for prompts, and what it's costing them. ๐ https://t.co/ye2UzdVmOs #cybersecurity #ThreatHunting #purpleteam
@NullSecurityX ยท
New videooo: Exploiting Windows File Explorer Spoofing Vulnerability by abusing extension obfuscation and UI trust boundaries to disguise executables as legitimate files, leading to user-triggered execution and initial access https://t.co/D4UF073tD4 #cybersecurity #BugBounty
@Hacker0x01 ยท
As AI features become more social and shareable, traditional AppSec issues, such as XSS, can often reappear in a different form. Security researcher @rez0__ explains how AI-generated content can transform a simple โshared chatโ into a real security risk if guardrails arenโt in place. Same bugs. New paths and lower attacker effort. #AI #ApplicationSecurity #AISecurity #Cybersecurity
Watch video@daraladje ยท
Mercor, Lovable, Vercel, and Anthropic - all hacked in the last few weeks. Many founders, including myself, are asking "how can we prevent this from happening?โ So I asked @EnriqueSalem, former CEO of Symantec (cybersecurity giant) and now partner at @BainCapVC. And he said "It's not a matter of if you'll get hacked, it's only when and how oftenโ So donโt try to protect everything. Only focus on what actually matters. In this weekโs episode of The Library of Minds we discuss why you shouldnโt install OpenClaw on your main computer, how startups should prioritize whatโs worth securing, and the nightmare scenario of agents acting with your credentials but without your judgment. 03:02 - How AI radicalized the spam problem 07:49 - How to poison an agent 09:21 - The new cybersecurity threats from AI 13:26 - The AI nightmare scenario 14:50 - Will your agent blackmail you? 16:35 - Why he trusts Perplexity and not OpenClaw 18:56 - Anthropic, Vercel, Lovable, Mercor breaches 22:41 - How to build a great security product 27:45 - Getting pushed out of Symantec 29:26 - What Enrique is hunting for in 2026
@0xfluxsec ยท
Picking up after @osint_barbie 's analysis of the MacOS stealer - I took a look at the Windows variant. Malware distributed on Reddit ultimately installs some AutoIt infostealer. https://t.co/xLOQivgxYN #infostealer #cti #cyberthreatintel #cyber #cybersecurity #blueteam #stealer #autoit #malware



@cleartechtoday ยท
๐ My team of engineers and I sit right next to the customer and hear about the IT challenges they are looking to solve for. I'd like to share a weekly take on projects that I'm actively involved in with the goal of helping IT teams learn from their peers. I'm calling my take the IT Field Consulting Notebook. Let me know what you are thinking and seeing in the field as it relates to MSFT Purview Remediation. Q:ย Whatโs the Business Benefit of a MSFT Purview Remediation? A:ย Purview remediation transforms reactive, manual security efforts into proactive, automated protection, reducing the average cost of data breaches and streamlining audit preparation. IT Clients often find it helpful to understand how other clients are navigating their IT challenges. One of the projects Iโm working on right now is a MSFT Purview Remediation Effort The primary business reasons for implementing Microsoft Purview remediation areย toย mitigate financial and legal risks from data breaches,ย ensure regulatory compliance, andย prevent intellectual property theftย by identifying and automatically fixing gaps in data governance. This particular client Iโm working with on the Purview Remediation project was recently purchased by Private Equity and one of the metrics they are being measured on is strengthening their security posture. Here are the 3 areas theyโd like to strengthen: ๐ช Secure AI Adoption (Copilot):ย As their organizations adopts Generative AI, Purview will help remediate data oversharing risks by ensuring sensitivity labels and data loss prevention (DLP) policies apply to AI prompts and responses. ๐ช Operational Efficiency:ย By consolidating fragmented security tools into a single platform, organizations, they can increase security team efficiency by up to 75%, allowing staff to focus on higher-value tasks rather than manual incident remediation. ๐ช "Shadow Data" Mitigation:ย Purview will ย help the IT team identify "shadow data"โsensitive information saved outside of authorized systemsโand brings it under proper control, addressing a key source of data breaches. This infographic outlines the core lifecycle of a Purview remediation, from the initial policy trigger to final optimization. So what does a Remediation Workflow look like? Key Phases of the Remediation Workflow 1๏ธโฃ Trigger: An event matches a pre-definedย Data Loss Prevention (DLP)ย orย Insider Risk Managementย policy. 2๏ธโฃ Notify: Admins receive alerts via theย Microsoft Purview portal, while users may receive automated policy tips or emails. 3๏ธโฃ Triage: Review the alert in theย Alerts dashboardย to determine if it is a true risk or a false positive. 4๏ธโฃ Investigate: Use tools likeย Content Explorerย to see the actual sensitive data orย Activity Explorerย to track the history of the event. 5๏ธโฃ Remediate: Execute manual or automated actions, such as: Revoking accessย to overshared files. Applying sensitivity labelsย or encryption. 6๏ธโฃ Tune #AISecurity #Cybersecurity #Purview

@mikemillercyber ยท
I Reached a Crossroad in my Cybersecurity Career and Made a Hard Decision. 25+ Years in Tech. The journey has been awesome. Summary: 1. Worked for a dial up ISP (Yes, we once dialed into the internet) 2. Became a Systems & Network Administrator 3. Consulted with Small to Medium Sized Businesses 4. Crossed over into Blue Team (SOC Analyst) 5. Learned Red Team - Penetration Testing 6. Became a PCI QSA - Audited Enterprise Level Corporations 7. Founded my own Firm and Made it Grow 8. Started getting contracts for vCISO roles 9. Sold my Firm, but remained a vCISO. Between number 7 and 8 above, I had to make a decision. Until getting vCISO contracts, I was always a hands on person. Even though I owned the firm, I was still heavily involved, mainly because I loved working with the clients and using technology. I could still walk into any situation and use my abilities. I still considered myself a hardcore tech. But then the inevitable happened. I reached a crossroad. I started gaining vCISO opportunities. Truth is, I never had a vCISO certification. Was there such a thing at the time? I had no mention of vCISO on my profile. Why were companies wanting to contract me? Well, I was finally brave enough to ask one of my clients. They chose me because of the experience I had in the industry. I never considered myself an "expert" anything. At best, I was an average systems admin, an "OK" SOC Analyst, a mediocre Penetration Tester, and understood compliance. Over the years I worked with companies anywhere from small, medium, and even companies we have all bought from or eaten at. I understood Cyber Security, business, communicated well, and was a good problem solver. But that's where I hit a crossroad. When I started filling these vCISO roles, I wasn't as hands on. โI was no longer firing up Kali on a daily basis. โI was no longer loading Metasploit โI wasn't configuring things โI wasn't as hands on technical โ I was losing my technical edge At first, I was filling these vCISO roles AND trying to stay up to date with every piece of software and toolset I could. It was not possible for me to do both without burning out. If I wanted to be a good vCISO, I had to make a choice and acknowledge I was going to fall behind technically. This was easily one of the toughest decisions I ever made. Once that decision was made, I realized I could focus all of my energy into helping businesses with their problems. I realized my value. I understood what it took to help them build a strong security posture. By leveraging my communication, problem solving skills and combining it with my experience, I could be a strong asset as a vCISO. Since then, I have never looked back and I'm just getting started. I took a risk by closing a door, but it was even riskier to not open new ones. Do you see yourself reaching that same crossroad? Have you already reached it?

@cleartechtoday ยท
๐ Maybelyn Plecic brought something especially practical to this ClearTech Loop conversation: the lens of a builder, educator, and security minded adoption leader. Maybelyn is the Manager of Training and Adoption at Network to Code. She is CISSP certified, AWS certified, and has spent her career helping teams strengthen security posture, drive compliance initiatives, and make technical change usable. That lens shaped the entire conversation. AI security is not only about policies, platforms, and controls. It is also about whether people understand what is expected, whether approved tools are practical, and whether leaders make safe use easier than the workaround. Maybelyn kept coming back to a simple point organizations often miss. People are not always trying to create risk. Sometimes they are just trying to get their jobs done faster. That means AI security has to include trust, plain language, hands on enablement, and enough flexibility to meet different teams where they are. Listen to the full episode: https://t.co/mwYylduc05 Stay in the Loop. Subscribe for new episodes: https://t.co/pQP1sp2Kux #AISecurity #Cybersecurity #CISO #CIO

@sagar_batchu ยท
When Mythos leaked in April, cybersecurity stocks like Akamai fell 20%. The market's verdict was that frontier AI means attackers win. Six weeks later, defenders using the same model found more than 10,000 high and critical vulnerabilities in a month, including 2,000 at Cloudflare at a false-positive rate better than human testers. It ran in the security trade press and almost nowhere else. Across the coverage since April, offense-framed stories outran defense ones about two to one. The same model that writes an exploit is the one that finds the flaw first. The edge goes to whichever side puts it to work first. For most enterprises, the upstream zero-days aren't yours to chase; the vendors who own that code will patch them. Your leverage is closer to home. The agents already inside your walls just got more capable, and whoever controls an agent's context controls what it does. So the defenses that went uncovered are the ones worth having in place now: prompt injection detection on what goes into an agent, and DLP on what comes out. The full coverage breakdown: https://t.co/G7DUd1ivw9

@SamPeterToT ยท
Cybersecurity basics every solo founder skips: 2FA on your email, a password manager, and a backup that isn't on the same drive as your main files. Not glamorous. Also the difference between a bad week and losing the business.

@VivekIntel ยท
๐ฌ ๐ฅ๐ฒ๐๐ฒ๐ฟ๐๐ฒ ๐๐ป๐ด๐ถ๐ป๐ฒ๐ฒ๐ฟ๐ถ๐ป๐ด & ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ฅ๐ผ๐ฎ๐ฑ๐บ๐ฎ๐ฝ โ Linux Master the Linux command line, processes, memory, file systems, and debugging tools. โ C/C++ & Assembly Learn low-level programming, memory management, calling conventions, and x86/x64 Assembly. โ Python Build automation scripts, analyze binaries, and develop reverse engineering utilities. โ Operating Systems Understand Windows and Linux internals, processes, threads, memory, executables, and system architecture. โ Reverse Engineering Analyze binaries using tools like Ghidra, IDA Free, Binary Ninja, x64dbg, and GDB. โ Malware Analysis Study malware behavior, persistence techniques, anti-analysis methods, and indicators of compromise (IOCs). โ Vulnerability Research Identify memory corruption bugs, logic flaws, fuzz targets, and analyze software vulnerabilities. โ Tool Development Develop custom security tools, binary analysis utilities, fuzzers, debuggers, and automation scripts. โ Security Research Conduct original research, analyze emerging threats, discover vulnerabilities, publish technical write-ups, and contribute to the security community. ๐ Reverse Engineering and Security Research require strong systems knowledge, continuous practice, and hands-on analysis of real-world software and binaries. #ReverseEngineering #SecurityResearch #MalwareAnalysis #VulnerabilityResearch #BinaryAnalysis #Linux #Assembly #Python #CyberSecurity #InfoSec #Learning
@RedHatPentester ยท
Many CISOs and CIOs have reduced cybersecurity to a performance theater. Many of them rely heavily and glorify risk and compliance PPTs, threatmaps and dashboards. There is absolutely no defensible scenario where a properly executed penetration test fails to identify a misconfigured S3 bucket; especially one severe enough to allow the exfiltration of 3TB of sensitive data. That is not an oversight. That is systemic failure. Most CISOs see these threat maps and start clapping. Until organizations stop prioritizing appearances over actual security posture, stop rewarding mediocrity, and start demanding technically rigorous validation, these incidents will continue to repeat.
@DivyanshT91162 ยท
GitHub just got a serious cybersecurity research resource. A new Malware Research Hub repository brings together thousands of real-world malware artifacts spanning decades โ giving researchers a rare look at how malware has evolved over time. Hereโs whatโs inside: โ 2,699 malware samples across different eras โ Families including Stuxnet and LockBit โ A forensic catalog covering 80 documented families โ Research and analysis tools โ Isolated and encrypted samples designed to reduce accidental execution risks And thereโs one critical distinction: These arenโt simulated samples or educational mockups. Theyโre real malware, intended strictly for controlled research environments with proper containment procedures. For cybersecurity researchers, threat analysts, and security professionals, this could be an extremely valuable resource for studying how real attacks work โ and how defenses have evolved. Research the threat. Understand the threat. Build better defenses. Repo ๐

@Hacker0x01 ยท
Higher education is stepping up its security game ๐๐ Kristen Dietiker shares how Santa Clara University launched a bug bounty program to protect its communityโand to build the next generation of cybersecurity leaders. Read more โก๏ธ https://t.co/tU2vujbRxC

@DailyDarkWeb ยท
๐จ Unverified Leak Claim Targets Senior U.S. Official A threat actor group is claiming to have compromised and leaked data associated with a high-profile U.S. government figure. ๐ Whatโs being circulated: โข Alleged personal photos and documents โข Claims of access to emails, conversations, and sensitive files โข A downloadable โPoCโ shared via underground channels โข Strong propaganda messaging accompanying the release โ ๏ธ Current assessment: These claims are unverified and should be treated with caution. Such releases often mix real, recycled, or fabricated data to amplify psychological impact. ๐ Notable pattern: โข Escalation from threat โ narrative โ alleged leak โข Use of dox-style exposure to increase visibility and pressure โข Blending cyber activity with information operations ๐ Recommendation: Avoid interacting with shared files/links. Monitor for confirmation from trusted sources before drawing conclusions. #CyberThreatIntelligence #InfoOps #Hacktivism #OSINT #CyberSecurity #ThreatIntel #DailyDarkWeb

@danielmakelley ยท
One of the biggest issues with cybersecurity is that itโs almost impossible to sell to companies that arenโt already looking for it. The ones who do care usually have a reason, theyโve been breached before, or theyโve had something close enough happen to scare them.
@TheJobfather__ ยท
Vulnerability Management Analyst is a strong cybersecurity role for people who like prioritization and risk. The job is not just finding vulnerabilities. It is helping teams decide what to fix first. To build proof, create a mock vulnerability report. Include severity, affected systems, business impact, exploitability, remediation steps, owner, and due date. The power is showing that you can translate technical risk into business urgency.
@_vmlops ยท
RED-TEAMING FABLE 5 & OPUS 4.8: THE JAILBREAK NUMBERS THAT MATTER AI4I's Security Lab ran 7,826 harmful intents against both models using four attack families TAP, PAIR, PAP, and static obfuscation (h4rm3l). every "success" got re-checked by a 3-judge panel, majority vote only. the headline numbers: โช๏ธ static obfuscation (encoding, ciphers, roleplay tricks) is basically dead under 0.2% success across ~50k attempts on each model โช๏ธ adaptive attacks are the real threat tree-of-attacks search broke opus 4.8 on 11.5% of intents, fable 5 held to 6.1% โช๏ธ opus 4.8's worst spot: child-safety framings at 27.6% under TAP, plus double digits in criminal/economic and cybersecurity โช๏ธ fable 5 stayed in single digits everywhere, cybersecurity near zero โช๏ธ successful jailbreaks front-load hard most wins land in the first 1-2 refinement steps, extra iterations barely help attackers the real takeaway: lexical tricks are solved. context and framing are not. both models still produced hundreds of panel-confirmed harmful completions when an attacker model just kept rewriting its prompt after refusals no human in the loop needed safety isn't a checkbox. it's a moving target that gets harder to hit as the search gets smarter.

@InvestiAnalyst ยท
What does the modern cybersecurity ecosystem really look like? The landscape is no longer a patchwork of point solutions. Instead, it is an interconnected web of identity, application, cloud, data, and AI security, woven together by detection, response, and recovery. At its core, the framework must address two pressing realities. Securing AI itself, and using AI as a tool to strengthen security. Both are reshaping the way organizations think about threats and resilience. This ecosystem is broad. Identity remains a central pillar, as misused credentials continue to be a leading cause of breaches worldwide. Protecting applications and cloud workloads is equally critical, especially as businesses scale across multi cloud environments. Data and AI security are emerging as priority domains, driven by the exponential growth of sensitive data and AI models that must be safeguarded against misuse. Detection, response, and recovery define the operational edge. Network security and security operations are not static functions, they must evolve into adaptive systems capable of addressing threats in real time. Threat detection, incident response, and recovery strategies are no longer afterthoughts but critical layers in the security fabric. Organizations must approach this shift holistically, ensuring every layer supports and reinforces the others.

@EvanKirstel ยท
Kicking off RSAC season with one of my all-time favorite โyou genuinely cannot make this upโ stories in cybersecurity. A luxury casino got hacked through a fish tank. Not the payment systems, not the hotel network, not even a careless employee clicking a sketchy email. A smart aquarium in the lobby with sensors tracking water temperature, salinity, and feeding schedules so the facilities team could manage it remotely. A harmless convenience. A completely unmanaged endpoint sitting inside the network perimeter. Attackers found it exposed online, probably weak credentials or an unpatched interface, and used it as their way in. And then the fish tank stopped being the story. What followed was a textbook lateral movement play. Once inside, they mapped the network, escalated privileges, probed for accessible systems, and navigated toward the thing that actually mattered: the high-roller database. When it was time to get the data out, they routed roughly 10GB through the aquarium device itself. Slow, blending in with normal outbound traffic. No alarms, no friction. The same device that got them in became the exit channel. What makes this story impossible to forget isnโt the sophistication, itโs the asymmetry. The defenders were focused on protecting the crown jewels while the attackers started with the least protected thing on the network. Nothing about the fish tank screamed โattack vector.โ That was the whole point. For years, cybersecurity thinking centered on traditional endpoints: servers, laptops, enterprise software. The attack surface was relatively bounded and you knew what you were defending. That world is gone. Modern environments are filled with cameras, medical devices, HVAC systems, smart lighting, conference room displays, factory floor sensors, and increasingly AI systems with broad API access and connections to sensitive data. Every one of them is effectively a computer that expands the potential attack surface, and almost none of them get the same patching discipline, network segmentation, or visibility as the โrealโ infrastructure. The fish tank wasnโt a weird anomaly, it was an early signal. Run the same scenario today and the entry point might be a connected infusion pump, an autonomous warehouse robot, or an AI agent with read/write access to systems no one thought to lock down. The pattern doesnโt change. Initial access comes from something overlooked, and standard techniques do the rest. Attackers rarely try the front door anymore. They look for whatever is easiest to reach and hardest to see. So the real question heading into #RSAC isnโt whether your core systems are secure. Itโs what in your environment feels too small, too operational, or too irrelevant to matter, because thatโs usually where the story starts. ๐๐

@khalilApriday ยท
Blue Team โ Just Monitoring Logs Blue Team is the shield of cybersecurity. It includes: โข Vulnerability Management โข Patch Management โข SIEM & Log Analysis โข Incident Detection & Response โข Threat Hunting โข System Hardening If you: โ๏ธ Run Nessus โ๏ธ Prioritize CVEs โ๏ธ Ensure patches are applied โ๏ธ Monitor Splunk alerts Youโre already doing real Blue Team work. Defend first. Detect fast. Respond smarter. ๐ก๏ธ
@advocatemack ยท
๐พ ๐๐ผ๐ ๐ฑ๐ผ๐ฒ๐ ๐ฎ ๐๐๐ฝ๐ฝ๐น๐ ๐ฐ๐ต๐ฎ๐ถ๐ป ๐ฎ๐๐๐ฎ๐ฐ๐ธ ๐ฎ๐ฐ๐๐๐ฎ๐น๐น๐ ๐๐ป๐ณ๐ผ๐น๐ฑ.... from package compromise to data exfiltration and persistence? Let's investigate using the GlassWorm๐ต๏ธ We all see the endless โ๐ฃ๐ฎ๐ฐ๐ธ๐ฎ๐ด๐ฒ ๐ซ ๐ท๐๐๐ ๐ด๐ผ๐ ๐๐๐๐๐๐โ posts on the feed (sorry about that)โฆ but what comes next? Hereโs a closer look at how the GlassWorm campaign turns a single dependency into a full attack chain: #cybersecurity #supplychainsecurity #infosec #devsecops

@EvanKirstel ยท
Walking the floor at RSA Conference this week, surrounded by booths promising AI-powered everything and zero trust architectures that will supposedly solve all your problems letโs go back to a story about a sticky note. Late 90s. Goldman Sachs is scaling its electronic trading systems and runs an internal audit. What they find isnโt a sophisticated breach or an advanced persistent threat. Itโs passwords. Written on sticky notes. Stuck to monitors, tucked under keyboards, taped to the sides of desks. Not because the employees were reckless. Because they were overwhelmed. Password policies had become so complex, and changed so often, that keeping track of credentials across dozens of systems just wasnโt humanly possible. So people did what people under pressure always do. They improvised. They adapted. They found a workaround that worked for them, and in doing so, quietly undermined the very security those policies were built to enforce. That audit didnโt just surface a compliance problem. It forced a genuine rethinking of how the industry approached security design. Maybe users werenโt the weakest link. Maybe the systems were never built with actual human behavior in mind. That realization is what eventually drove SSO, password managers, MFA, and the modern identity platforms everyoneโs showing off in the exhibit hall right now. Security started bending toward usability instead of treating usability as the enemy. Hereโs the thing though: we havenโt actually solved the problem. Weโve just upgraded the format. The sticky note is now a shared API key dropped into a Slack channel. Itโs a credential committed to a GitHub repo because someone was moving fast and needed to ship. Itโs an AI agent running with far more access than any reasonable security review would have approved, because someone needed it to work and the proper provisioning process took too long. Same fundamental pattern. New tools. New blast radius. This is the thread I keep pulling on at RSAC, past all the product launches and keynote buzzwords: security that creates too much friction will always lose to human ingenuity. People will find the path of least resistance, every single time, and that path becomes the vulnerability. The next phase of cybersecurity isnโt just stronger controls or smarter AI detection. Itโs systems designed around how people actually behave, not how we wish they would behave, especially when things get busy, deadlines are real, and the pressure is on. Because thatโs exactly when the sticky notes come back out. @OneRSAC #RSAC #cybersecurity

@BIZBoost ยท
๐จ A leak just exposed something bigger than a new AI modelโฆ Anthropic is reportedly testing โClaude Mythosโ โ a system so advanced in cybersecurity and exploitation capabilities that even they are cautious about releasing it. Nearly 3,000 internal assets surfaced after draft blogs and documents were left publicly accessible. Researchers and Fortune uncovered details before access was locked. Hereโs what stands out ๐ โข A new tier called โCapybaraโ, more powerful than Opus โข Major jumps in coding, reasoning, and cyber capability โข Internal claims that itโs ahead of any current AI in cyber offense And the key concern: This model could exploit vulnerabilities faster than defenders can respond. Anthropicโs approach? Give early access to cybersecurity teams first, so systems can be hardened before wider release. That alone tells you the level of risk theyโre anticipating. Also revealed: An invite only CEO retreat where unreleased Claude capabilities are being showcased behind closed doors. If this is even partially accurate, weโre looking at a shift where AI doesnโt just assist securityโฆ it challenges it. Source: Fortune

@notablecap ยท
2 major forces are reshaping cybersecurity: AI for security, and security for AI. The technology is rapidly helping teams identify & fix vulnerabilities faster, with less human involvement. But AI is also introducing a whole new set of security challenges.


@InvestiAnalyst ยท
CTEM is not just another buzzword, itโs a security strategy you can operationalize. Attack surfaces are expanding at a pace that outstrips traditional vulnerability management. Thatโs where Continuous Threat Exposure Management (CTEM) comes in. The process is structured into five key stages: 1/ Scoping Build a complete inventory: digital assets, SaaS, cloud, and shadow IT. 2/ Discovery Go beyond CVE scans, spot misconfigurations, access issues, and hidden exposures. 3/ Prioritization Use AI driven risk scoring and business context to focus on what really matters. 4/ Validation Test exploitability with attack path validation and reduce false positives. 5/ Mobilization Automate remediation across IT and security teams, making ownership and accountability clear. #CyberSecurity #CTEM #ThreatManagement #VulnerabilityManagement #RiskReduction

@advocatemack ยท
๐ฑ๐๐ฟ๐ผ๐บ ๐ง๐ฟ๐ถ๐๐ ๐๐ผ ๐๐ถ๐๐ฒ๐๐๐ .... ๐ช๐ผ๐ฟ๐บ๐ ๐๐ผ ๐ช๐ถ๐ฝ๐ฒ๐ฟ๐ ๐ฎ๐ป๐ฑ ๐ฒ๐๐ฒ๐ป... ๐๐น๐ผ๐๐ฑ ๐ก๐ฎ๐๐ถ๐๐ฒ ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ. If youโve been trying to make sense of WTF is going on with @pcpcats ..... youโre not alone. ๐ฅฒ In this episode of Bad Dependencies, I sit down with @CharlieEriksen , whoโs been tracking this attack in real time as it unfolded. We break down: โข How a compromise in Trivy kicked off a wider supply chain attack โข How credentials were stolen and reused across ecosystems like NPM & PyPI โข Where the worm-like behavior fits in โข Why LiteLLM makes this especially concerning โข What you should be doing right now to protect your systems This oneโs still developing and weโre likely not at the end of it yet. F ull Episode -> https://t.co/pLa8NSi9l1 #cybersecurity #supplychainsecurity #devsecops #teampcp #opensource #trivy #litellm @aikidosecurity
Best Cybersecurity tweets
Xholic studies what works in your niche, drafts posts in your voice and schedules them for the hours your audience is online.
$0 today ยท Cancel anytime
Browse all tweet collectionsKeep exploring