Defensive security engineering
Detection engineering, threat hunting, EDR, network hardening, segmentation, secure configuration, telemetry, and attack-path remediation.
40%
Best tweets about Cybersecurity
Discover the best tweets about cybersecurity, including vulnerabilities, attacks, defense, privacy, threat research, security engineering, and incident lessons.
Credible cybersecurity research, vulnerabilities, defensive practices, incidents, threat analysis, privacy, and security engineering lessons.
Original Xholic analysis
The 50-post set is led by defensive engineering, vulnerability research, and AI-enabled security. Posts frequently connect AI-security discussion to operational controls such as access restrictions, secret management, monitoring, telemetry, validation, and human review. The set also contains conflicting views on whether frontier-model cyber risk is being communicated proportionately.
36% of posts
All-time engagement
58% of posts
Published in 90 days
Conversation map
Detection engineering, threat hunting, EDR, network hardening, segmentation, secure configuration, telemetry, and attack-path remediation.
40%
Zero-days, code auditing, exploit development, fuzzing, reverse engineering, malware analysis, and hands-on security research.
38%
AI agents and frontier models for vulnerability discovery, autonomous red teaming, security operations, and the shifting offense-defense balance.
34%
Risks and controls for agent skills, prompt injection, excessive permissions, agent governance, human oversight, and data-loss prevention.
24%
Incident investigations, compromise paths, exposed secrets and data, containment, credential rotation, communications, and recovery lessons.
18%
Nation-state and aligned actor activity, espionage, hacktivist leak claims, malware campaigns, attribution, and MITRE-mapped TTPs.
18%
Overprivileged IAM roles, credential hygiene, authentication flaws, Active Directory abuse, sensitive environment variables, and least privilege.
16%
Compromised dependencies, package ecosystems, third-party applications, malicious skills, code provenance, and dependency-focused detection.
8%
Tone and stance
Performance benchmark
Posts with media make up 64% of this collection. Their median all-time score is 6.12, compared with 16.2 for text-only posts.
Format mix
Consensus and debate
Shared view
Several incident and case-study posts point to patching, least-privilege access, credential and secret handling, monitoring, and configuration review as practical defensive measures. The cited posts describe these controls in the context of reported or claimed compromises and assessments.
Shared view
AI-agent security posts recommend limiting permissions, isolating sensitive resources, maintaining audit trails, and retaining human approval for higher-risk actions. They also identify prompt injection and data exposure as concerns.
Shared view
Two defensive posts explicitly describe mapping threat behavior or supply-chain exposure to hunting coverage, including log sources, queries, Microsoft Sentinel, and Defender XDR telemetry.
Shared view
Posts on security-research development advocate working from concrete research questions, hands-on exploitation or analysis, and public technical write-ups.
Open debate
One post argues that increasingly capable agentic coding tools and red-team reports justify preparing for new cyber risks. Two others describe Mythos-related messaging as hype, theatrical framing, or “proliferation theater.”
Open debate
Posts promoting autonomous red-team tooling present it as disruptive to traditional testing workflows. Another post argues that people remain necessary to validate findings, assess impact, prioritize work, and coordinate remediation; a separate post reports offensive-task benchmark results.
Open debate
The cited posts all discuss models that can support vulnerability discovery or defensive activity, but differ in emphasis: one foregrounds attacker advantage, while another argues the advantage depends on which side operationalizes the capability first.
What performs
Software and AI supply-chain security had the highest supplied theme median all-time score, 82.37, across 4 tweets. The theme’s listed evidence covers dependency exposure, third-party application exposure, and AI-skill scanning.
Identity, secrets, and access control recorded a supplied median all-time score of 37.73 across 8 tweets. Its listed evidence includes secret rotation, sensitive environment-variable handling, and least-privilege guidance.
Tutorials had a median all-time score of 16.869, compared with 10.079 for announcements. The tutorial evidence includes supply-chain hunting guidance, TTP-to-telemetry mapping, and a GRC exercise.
The supplied outlier list identifies an autonomous AI red-team announcement (3,663.6), an AI-evaluation incident report (1,130.2), and two incident-related posts (894.76 and 755.66). Each exceeded the overall median all-time score of 10.07.
Posts with media represented 64% of the set and had a 6.12 median all-time score. Text posts had a 16.21 median all-time score. These are descriptive differences in this dataset and do not establish that media caused lower performance.
Statistical standouts
Creator landscape
The five most represented creators account for 20% of the selected posts.
1. Steven Lim
@0x534c
2 posts
2. flux
@0xfluxsec
2 posts
3. Aditya Chordia, CISSP, CIPP/E, CISA
@AdityaMBAsymbi
2 posts
4. Dark Web Intelligence
@DailyDarkWeb
2 posts
5. Ethan Mollick
@emollick
2 posts
6. Evan Kirstel #B2B #TechFluencer
@EvanKirstel
2 posts
Among the supplied top-voice list, Guri Singh posted twice and had the highest listed creator median all-time score, 1,897.94. The cited posts are announcements about an autonomous AI red-team project and an open-source cybersecurity skills library for AI agents.
Aditya Chordia posted twice and had a listed median all-time score of 385.02. One cited post critiques reported breach controls; the other argues for human validation and remediation of AI-discovered vulnerabilities.
Steven Lim posted twice and had a listed median all-time score of 94.18. The cited posts discuss Axios-related hunting and mapping Iran-aligned TTPs to Sentinel and Defender XDR telemetry.
Since the previous snapshot
Themes, sentiment, stance, and post format are classified per tweet. All counts, shares, medians, creator concentration, freshness, and performance comparisons are then calculated directly from the published snapshot.
Xholic's all-time score compares engagement while accounting for reach, post age, and creator consistency. It is used for relative comparisons within this collection.
This report analyzes the exact 50-post snapshot shown below. AI identifies editorial categories and drafts explanations; all statistics are calculated from the snapshot, and every narrative claim is checked against cited posts before publication.
Best Cybersecurity tweets
Ranked 01–50
@heygurisingh ·
🚨 BREAKING: The cybersecurity industry is about to get completely disrupted. Someone just open-sourced a fully autonomous AI Red Team. It's called PentAGI. 8,200+ stars on GitHub. Not one AI agent. An entire simulated security firm. Researchers, developers, pentesters, and risk analysts. All AI. All coordinating with each other before launching a single attack. No Cobalt Strike. No $100K/year pentest retainers. No OSCP required. Here's what's inside this thing: → An Orchestrator agent that plans the full attack chain → A Researcher agent that gathers intel from the web, search engines, and vulnerability databases → A Developer agent that writes custom exploit code on the fly → An Executor agent that runs 20+ pro security tools (nmap, metasploit, sqlmap, and more) → A memory system that learns from every engagement and gets smarter over time Here's the wildest part: It runs everything inside sandboxed Docker containers. Full isolation. It picks the right container image for each task automatically. It has a knowledge graph powered by Neo4j that tracks relationships between targets, vulnerabilities, tools, and techniques across every single test. Cybersecurity firms charge $25K-$150K per engagement for this exact workflow. This is free. 100% Open Source. MIT License.
@AnthropicAI ·
In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Our post describes what happened, how it happened, and what we’re changing. We encourage other AI developers to perform similar reviews. We conducted this review together with @Irregular, one of our evaluation partners, and thank them for the joint investigation and their collaboration on this post. This type of collaboration is increasingly critical to safe, rigorous evaluation of models, and we look forward to continuing to work together on security. https://t.co/dKFCdpKd9v
@rauchg ·
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called https://t.co/7PY6gGtzgI that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (https://t.co/BLVnic9fJC). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
@AdityaMBAsymbi ·
A company that sells cybersecurity risk intelligence to 91% of Fortune 100 companies just got breached through an unpatched React app and a single overprivileged AWS role. LexisNexis. 3.9 million records. 400,000 user profiles. 53 secrets extracted in plaintext from AWS Secrets Manager. Including credentials for production databases, Salesforce, Oracle, and analytics platforms. The password "Lexis1234" was reused across five different internal systems. This is a company that describes itself as "one of the largest protectors of private and confidential data in the world." They provide risk intelligence to 7,500 US government agencies, nine out of ten banks, and major insurers globally. They sell cybersecurity assessments to their customers. And they couldn't secure their own AWS account. Here's what makes this worse than a typical breach: - The compromised data includes accounts tied to 118 .gov email domains. Three US federal judges. Four Department of Justice attorneys. SEC staff. Probation officers. Federal court law clerks. The attackers published doxxed profiles of federal officials tied to courts and regulatory agencies across the country. - These aren't random consumer records. These are the digital identities of people whose exposure carries national security implications. A compromised federal judge's profile doesn't just enable identity theft - it enables targeted influence operations, blackmail, and intelligence gathering. The attack path is textbook and that's the problem: → Unpatched React application - the front door → Single ECS task role with read access to every secret in the account - the keys to everything → 536 Redshift tables, 430+ database tables, full VPC infrastructure mapping - complete visibility → 53 secrets in plaintext including database credentials, API tokens, and development access keys No zero-day. No advanced persistent threat. No nation-state capability required. Basic hygiene failures — unpatched app, overprivileged IAM role, password reuse, plaintext secrets. This is LexisNexis's second confirmed breach in two years. The December 2024 incident exposed 364,000 individuals through a compromised corporate account on a third-party development platform. Data brokers and analytics providers are not peripheral players - they're deeply embedded in today's risk landscape. That's the pattern we keep seeing. Attack the aggregator, not the individual. BPO providers. Cloud platforms. Legal data giants. The organisations that hold everyone else's data are the highest-value targets - and often the weakest links. For every enterprise that uses LexisNexis services: → Assume your metadata, contract details, and product usage history are exposed → Watch for targeted phishing using the exposed business relationship data → If your staff have LexisNexis accounts, reset credentials immediately → Ask your vendor risk team: when was the last time we assessed LexisNexis's actual security posture - not their marketing, their controls? The company that indexes the world's legal information couldn't index its own IAM policies. And they're not the exception. They're the pattern. More info: https://t.co/lzgKNNraWf
@inversecos ·
What separates Chinese cyber ops from Five Eyes? Three things that shifted my thinking about this topic: 1. Early cyber training (90s-2000s) happened on live targets. Not sandboxes, not simulations...actual foreign infrastructure. The "practice" was the operation. Operational errors caught during IR back then weren't failures of tradecraft... they were the cost of learning on production. 2. The private sector operates as APT infrastructure. Cybersecurity companies founded by former 2000s hackers (Topsec, i-SOON, Integrity Tech) were later publicly linked to state-directed operations. The line between "legitimate vendor" and "APT contractor" is deliberately blurred (by design). 3. Operators don't stay siloed in their APT group. They rotate across teams for decades, carrying often the exact same tools, tactics with them. What we label as "different APT groups" is often the same people with different hats. This makes attribution way messier than the tidy narrative we see in threat reports. Worth reading this epic report published by the Zurich Centre for Security Studies if this stuff keeps you up at night: https://t.co/aGgMyPniWF
@vxunderground ·
Okay, before I make a silly post have some context. Rostelecom is the largest telecommunication company in Russia. If you're in the United States, Rostelecom is basically like their AT&T or Verizon. Anyway, Rostelecom has a Cyber Threat Intelligence division called "Solar Group". Solar Group releases papers frequently on threats (specifically in the malware domain) targeting the Russian Federation. I enjoy reading it because, as a person residing in the United States, my Threat Feed is usually threats facing people in the United States (or allies of the United States). Reading threats facing the Russian Federation I'm like, "oh no shit? yall too? lmfao das crazyyyy". My absolute favorite though is reading papers from Chinese or Russian cybersecurity companies where they accuse the United States government of state-sponsored malware campaigns and the United States government is like, "pfffft? Me? No way, dawg. I'm A CHRISTIAN. You ARE THE BAD GUYS. We go to Church EVERY SUNDAY". Then both the Russian Federation and Chinese government go like: ">:( u bitch" But then they do the same thing to us, so it's whatever I guess. We're all doing silly shenanigans on the internet. An example of the silly shenanigans is a Threat Actor who has compromised various law enforcement agencies in the Russian Federation. This Threat Actor is named "Eagle Werewolf" (what country uses the Eagle?). Eagle Werewolf has been compromising law enforcement agencies in the Russian Federation, specifically exfiltrating data related to internal case files, active investigations, operational plans from law enforcement agencies, and any information on who the Russian Federation is actively investigating. Eagle Werewolf also appears to be attempting to map internal infrastructure and organization hierarchy (who is who in law enforcement, supervisors, general employees, etc). That's weird. Why would this mysterious "Eagle Werewolf" want this information? Hmmmmm?
@0x534c ·
🔊 Think You’re Safe Without Axios? Think Again If your environment does not contain a compromised Axios build, that doesn’t close the case. Axios is a widely adopted JavaScript HTTP client used across countless web applications. Even if your own systems are clean, your end users may still interact with third‑party applications that rely on Axios and authenticate against your tenant via Entra ID. This creates a potential pathway for threat actors to access tenant data through compromised external apps. Because of this broader exposure surface, it’s essential for defenders to deploy the advanced hunting detection below to monitor for suspicious Axios‑based activity and identify potential abuse early. KQL Code: https://t.co/HPYLV8XaqV #Cybersecurity #Axios #NPMSupplyChainCompromise #KQL #DefenderXDR
@heygurisingh ·
Every company is mass adopting AI agents right now. Not a single one of them knows how to secure them. Someone just built an open-source cybersecurity skills library specifically for AI agents. 611+ skills. 16+ security domains. Every skill comes with real standards, real scripts, and real templates. Not a course. Not a PDF. Not a YouTube playlist. A structured database your AI agent can actually use. Here's what's inside: → Web Application Security. SQL injection, XSS, CSRF, authentication bypass. Every OWASP Top 10 category covered. → Penetration Testing. Full methodologies with NIST and MITRE references baked into every skill file. → Red Teaming. Adversary simulation workflows your AI agent can follow step by step. → Digital Forensics & Incident Response. Evidence collection, memory analysis, timeline reconstruction. → Malware Analysis. Static and dynamic analysis procedures with real helper scripts. → Cloud Security. AWS, Azure, GCP misconfigurations. Container security. Kubernetes hardening. → Threat Intelligence. IOC correlation, threat actor profiling, intelligence lifecycle management. → Zero Trust Architecture. Identity verification, microsegmentation, least privilege enforcement. → OT/ICS Security. Industrial control system protection for critical infrastructure. → DevSecOps. Security automation baked into CI/CD pipelines. Here's what makes this different: Every single skill follows the https://t.co/mj8uxghqhr open standard. YAML frontmatter. Structured markdown. Built so AI agents can parse, understand, and execute security tasks -- not just humans reading documentation. Each skill folder includes: → SKILL.md with the full skill definition → Real standard references (NIST, MITRE ATT&CK, CVE databases) → Deep technical workflow documents → Python helper scripts practitioners actually use → Filled-in checklist and report templates You plug this into Claude Code. Your AI agent now has 611 cybersecurity skills it didn't have 5 minutes ago. No subscription. No vendor lock-in. No paywall. MIT licensed. 100% Open Source.
@emollick ·
I am catching glimpses in my feed that there is a backlash against Mythos as "marketing hype," and it is a little confusing. I don't think anyone who has used the latest agentic coding tools, would think that expecting large-scale cybersecurity implications of increasingly good AI models is unbelievable, especially after reading the red team reports. It feels like a better place to start is to assume that there are new risks, and then we can all laugh at Anthropic and pat each other on the back if there are not. Also, while the AI labs certainly are impressed by their own accomplishments and benchmarks are flawed, I would note that both publicly and privately, Mythos seems to be taken seriously at a lot of large institutions and organizations filled with smart people who would rather not be worried about a new cybersecurity risk. Finally, I am not sure "our product is dangerous and we need to alert the government to that" is the sales pitch to the corporate world that critics seem to think it is.
@businessbarista ·
I just spent 60 minutes grilling an ai cybersecurity expert with questions. Here's everything I learned: 1. All of cyber boils down to ONE thing: don't let the business get compromised. every acronym, tool, and tactic ladders up to that. 2. It splits in two: AppSec (securing your code before it goes live) & ProdSec (securing the system once it's live). 3. White hat vs black hat. A white hat finds the bug & tells you for free. A black hat says "pay me & i'll show you." If someone holds a vulnerability hostage, that's the tell. 4. Key acronyms in the space: SAST: scan your source code for bugs before you ship SCA: check your open-source dependencies for known vulnerabilities DAST: attack your own live app to see what breaks WAF: a firewall that stops your site from getting flooded with fake traffic Pen Test: you pay a hacker to break in & tell you how they did it 5. AI is the best defense AND the best offense. What used to be human-level attack & defense now happens at thousands of times the scale & speed. 6. You have to assume attackers WILL find the bug now. It used to be "they might not find it." Today it's cheap, fast & AI-enabled. 7. Prompt injection is the new #1 attack vector. One crazy example: a guy ran an AI agent that traded crypto & held his wallet keys. An attacker hid instructions in MORSE CODE in a tweet, got Grok to "translate" it, and because the reply came from Grok (a trusted source) the agent drained ~$170k from the guy's wallet. 8. It's not just attacks on randos. Salesloft's AI chat agent had Salesforce credentials baked in. one prompt injection let attackers pull customer Salesforce data, AWS keys & Snowflake tokens, and it cascaded to ALL of its customers. 9. Pen tests alone aren't enough anymore. @octane_security reviewed code pen tested 8-10 times & still found 5-7 critical bugs. Quarterly testing can't keep up when AI ships code daily. 10. Their AI found a bug that could've taken down 40% of Ethereum (a $320B network then). the cause? Two arrays where nobody checked one wasn't longer than the other. 11. How to use AI agents (like @openclaw and Hermes Agent) without getting wrecked: permission on a needs-only basis (don't auto-grant everything), assume your laptop gets stolen at Starbucks & ask what the agent could reach, and keep it away from your most sensitive data at the source. 12. Your people are the easiest way in. Social engineering is the most common attack. OpSec training & "don't leave your laptop open" aren't sexy tools, but they're effective. 13. You have to fight fire with fire. You need AI to secure the AI you're building, because the attackers are already using it. 14. Authentication remains a major vulnerability. "cross-tenant access" = one customer being able to reach into a different customer's data. They've caught free self-serve signups that could gain access to Fortune 500 accounts' data. 15. When to actually hire for security: pre-seed, B2B, selling to a few trusted companies? You're probably fine to wait. The second you launch self-serve or store highly sensitive data, your risk surface explodes & you need someone who owns it. ty @giovignone for the masterclass.
@TGTM_Official ·
Another Major CCP Data Leak Incident ❗️ Anxun Information Company Leaks Classified Documents in 2024, Including Remote Control Systems for Public Security, State Security, and the People's Liberation Army, Twitter Opinion Guidance and Control Systems, etc. First Time in History Fully Exposing the CCP's "Hacker-as-a-Service" Industry Chain, Shocking Revelation: CCP Hackers' Base Salary as Low as 2,000 Yuan On February 16, 2024, Anxun Information Company suffered a massive internal data leak, exposing how the company provides hacking tools and cyber espionage services to China's Ministry of Public Security, Ministry of State Security, and People's Liberation Army. Among them, the company supplies penetration testing tools and data theft services to the Ministry of Public Security, 10 provincial public security departments, and over 40 municipal public security bureaus, with attack targets covering government agencies in Hong Kong, Taiwan, multiple Southeast Asian countries, overseas dissidents, Microsoft and Google personal email accounts, and more. Multiple renowned international cybersecurity and intelligence agencies (Recorded Future, SentinelOne, Mandiant, etc.) unanimously believe that this leak was most likely carried out by a company insider extremely dissatisfied with the organization. The leaked documents reveal that some hackers at Anxun have base salaries as low as 2,000 yuan, with employees venting widespread discontent: "No raise in three years, gotta eat dirt," "If it doesn't make money, being famous is useless," mocking the company for "screwing over state agencies" and "fooling the State Security Ministry," while the chairman is "patriotic but loves money." The Twitter precise account hijacking and targeted opinion manipulation tool leaked in this incident is one of the most core and aggressive products. The system sends specially crafted forensic links via Twitter direct messages, enabling one-click bypass of two-factor authentication to directly hijack target accounts, while simultaneously stealing email, phone number, IP address, geolocation, device fingerprint, browser version, and other user information. The system can read in real-time all tweets, likes, retweets, and direct messages from controlled accounts, automatically generating detailed social relationship graphs and case files, and through grouped batch operations, it enables multiple controlled accounts to act in concert—publishing tweets, syncing likes, comments, and retweets—to precisely engineer trending topics. This system can seamlessly integrate with Anxun's other attack tools (such as Outlook email stealers, iPhone location tools, etc.), forming a complete attack chain of account intrusion, data extraction, and opinion manipulation. For detailed leaked documents, please see the attached images in the comments.
@0x534c ·
🚨 𝗧𝗵𝗿𝗲𝗮𝘁 𝗔𝗱𝘃𝗶𝘀𝗼𝗿𝘆: 𝗢𝗽𝗲𝗿𝗮𝘁𝗶𝗼𝗻 𝗘𝗽𝗶𝗰 𝗙𝘂𝗿𝘆 – 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿’𝘀 𝗟𝗲𝗻𝘀 Iran‑aligned cyber actors are actively responding to Operation Epic Fury with a diverse set of tactics, techniques, and procedures (TTPs). Building on BeyondTrust’s Threat Advisory: Iran‑Aligned Cyber Actors Respond to Operation Epic Fury, I mapped these behaviors into the MITRE ATT&CK framework — and took it further by aligning each log source with the relevant 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗦𝗲𝗻𝘁𝗶𝗻𝗲𝗹 and 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿𝗫𝗗𝗥 tables. This gives defenders a direct path: from threat actor TTP → to telemetry → to hunting queries. In other words, you’ll know exactly where to look in Sentinel or Defender XDR when tracking these adversaries.🫡 #Cybersecurity #OperationEpicFury #DefenderXDR #MicrosoftSentinel
@0xfluxsec ·
This is my last week working professionally on a Red Team, excited to be joining the super talented people over at @elastic in just over a week as a Senior Security Research Engineer! Alongside my regular red team work I have been lucky enough to have a day a week secondment with a partner organisation performing Windows security research. One massive thing I have learned that I thought would be worth sharing, is having questions to answer in security research is super important when it comes to learning, growing skills and finding things which matter. Whilst poking at stuff in free time is fun - you will find you have much greater success when there are legitimate questions to answer. If you enjoy it as a hobby / want to grow deeper skills - try that :).
@hakluke ·
Best way to grow in this industry: share what you learn publicly. Write a blog post about that weird bug you found. It doesn't have to be groundbreaking. Someone out there needs exactly that piece of knowledge right now. My career in cybersecurity started with a blog about my OSCP experience.
@zaimiri ·
Security agents are growing quick. One repo has 754 cybersecurity skills for AI agents. Not prompts. Structured procedures mapped to security frameworks: > Cloud security > Pentesting > Red teaming > Incident response > Malware analysis > Threat intel This is where agent work gets interesting. The model is not just answering security questions. It is being given the operating procedure before it acts.
@socialwithaayan ·
🚨 NVIDIA just revealed that 1 in 4 AI agent skills you're running right now has a security vulnerability. They built a scanner to prove it. It's called SkillSpector. Point it at any AI skill. Get a safety score from 0 to 100. Know instantly if it's safe to install. Here's what their research found: → 26.1% of skills contain vulnerabilities → 5.2% are likely malicious → Most devs install them without checking a single line Think about that. You're giving these skills full access to your terminal, your files, your API keys. And 1 in 4 is compromised. Here's what it catches: → Environment variable harvesting (stealing your API keys) → Hidden external data transmission → Obfuscated code and credential exfiltration → Attack patterns specific to AI agent workflows This isn't a generic code scanner. It's purpose-built for AI skills used in Claude Code, Codex, Gemini CLI, Cursor, and Copilot. 2026 has been brutal for supply chain attacks. Trivy. TanStack. Bitwarden CLI. Even GitHub's own internal repos got hit. Skills are the newest attack surface. And until now, zero tooling existed to scan them. Built by NVIDIA. Backed by a published research paper. Not a weekend project. 100% Open Source. Apache 2.0 License.
@TheJobfather__ ·
Governance, Risk, and Compliance Analyst is a strong path into cybersecurity without needing to be a hardcore hacker. GRC focuses on policies, audits, controls, risk, compliance, and evidence. To build proof, pick a framework like NIST or ISO 27001 and create a mini risk register. Include the risk, impact, likelihood, control, owner, and mitigation plan. This is how you show you can think in controls and risk.
@mclynd ·
During the DARPA AI Cyber Challenge, autonomous AI systems uncovered 18 zero-day vulnerabilities and patched 61% of them in 45 minutes. Without any human input. Zero-days are the most dangerous class of software vulnerability. Attackers prize them because they're unknown to defenders. A human security team might take weeks or months to find one, if they find it at all. An AI did it 18 times in under an hour. And then patched most of them. This is a preview of where both offensive and defensive cybersecurity are heading. The same capability that can find vulnerabilities and patch them can find vulnerabilities and exploit them. The question is who gets there first, and whose AI is faster. The DARPA AI Cyber Challenge was a proof of concept. The nation-state actors who've been watching that competition already have teams working on the offensive version. Security teams that don't have AI in their stack aren't just behind. They're playing a fundamentally different game than the one being played against them.
@NedWilliamson ·
I was honored to serve as an invited expert at the DARPA ISAT CLASH workshop on AI-enabled cybersecurity earlier this month. Nearly 10 years after participating in CGC, it's a thrill to see the vision extending another decade ahead. Grateful to LTC Chase Hasbrouck for leading such a thoughtful study. Pre-reads and materials: https://t.co/GA1TvQDgq3
@AdityaMBAsymbi ·
Things are not looking good for cybersecurity experts" is the wrong takeaway from Claude finding 500 zero-days. Here's why it's actually the opposite. Claude Opus 4.6 found 500+ previously unknown high-severity vulnerabilities in production open-source code. Some had been hiding for decades. Traditional scanners, fuzzers running millions of CPU hours - found nothing. Claude read the code, reasoned about it like a human researcher, and even wrote proof-of-concept exploits to validate the findings. That's genuinely impressive. But the reaction of "AI is replacing security researchers" misses the most important part of the story. Finding vulnerabilities was never the hard part. Fixing them is. Snyk's data tells the real story: mean time to remediate balloons from hours to months. AI-assisted coding is driving a 20% increase in pull requests per author. The vulnerability backlog is growing faster than the industry can patch. And here's the painful irony - AI-generated code is 2.74× more likely to introduce XSS vulnerabilities than human-written code. So we now have AI that finds 500 zero-days in production code while simultaneously producing new vulnerable code at scale. The machine is both creating and discovering the problems. What Claude actually did is what makes human security researchers MORE valuable, not less: → Claude found the bugs. Anthropic's own researchers validated every single one by hand before reporting → Claude wrote proof-of-concepts. Human researchers confirmed they were real, not hallucinated → Claude suggested patches. Human maintainers reviewed and deployed them → Mozilla treated the incoming reports as an incident response - 100+ bugs triaged across multiple engineering teams by humans The AI accelerated discovery by orders of magnitude. Every step after discovery still required human judgment - context about the production environment, business logic implications, prioritisation based on real-world exploitability, and coordination with maintainers. The security researchers who should worry aren't the ones who reason about code. They're the ones whose entire value proposition is running scanners and producing reports. That work is genuinely being automated. The ones who contextualise findings, assess business impact, coordinate remediation, and make judgment calls about risk? Those people just got the most powerful discovery tool ever built. They're not being replaced. They're being amplified. The real question nobody is asking: Claude can now find vulnerabilities in any codebase it can read. What happens when it's pointed at the AI agent frameworks everyone is deploying - OpenClaw, MCP servers, ClawHub skills? The same supply chain that's already under active attack from GlassWorm, litellm, and Trivy compromises? AI finding bugs is the capability. Humans deciding what to do about them is still the job. Who on your team is preparing to triage AI-discovered vulnerabilities at this velocity? More info in reply:
@pvergadia ·
🤓 Cybersecurity is disrupted by AI. The $100K/yr pentest just got open-sourced. PentAGI dropped on GitHub. 8,200+ stars in days. It's an an entire AI security firm: orchestrator, researcher, developer, executor, all coordinating before a single packet leaves the box. → Orchestrator maps the full attack chain → Researcher pulls intel from the web + CVE databases → Developer writes custom exploits on the fly → Executor runs nmap, metasploit, sqlmap + 17 more tools → Neo4j knowledge graph remembers everything across every test Runs in sandboxed Docker. Isolated. Automatic. Here's why this changes everything: Security was the last industry where "you need 10 years of experience" was a real moat. PentAGI doesn't erase expertise it erases the excuse for not testing. This costs $0. MIT License. https://t.co/CYIcAPzKhq
@larsencc ·
Anthropic built Mythos. A model so powerful at cybersecurity that they won't release it publicly. How did we find out about it? They left 3,000 internal files in a publicly accessible cache. The model can find vulnerabilities faster than defenders can patch them. The company can't configure a CMS.
@gabbytech01 ·
Spent months bouncing between cyber security niches like a headless chicken. Pentesting, bug hunting, couple others that all tasted like disappointment. Finally landed in Security Engineering focused on Network and weirdly... I'm not actively planning my escape. Why? Because actually building and hardening the damn network so stuff doesn't get in, feels more real than writing reports nobody reads or hunting ghosts. Impact is measurable. Fires are preventable instead of just spectacular. Now I'm grinding through CCNA Because apparently knowing how the network actually works, might help me not look like a complete idiot in this role. Probably jinxed it now. Don't @ me.
@mark_k ·
The AI cybersecurity hysteria is getting absurd. Yes, frontier models are becoming much better at finding and exploiting vulnerabilities. That matters. But Anthropic’s rollout of Claude Mythos feels less like sober risk communication and more like a fear-marketing campaign around a model most people cannot even test. A mythical, unreleased AI model, shown to a handful of partners, is now being treated as if it has already broken the internet. AI will change cybersecurity. No doubt. But turning every new benchmark into doomsday theatre mostly helps the companies selling access to the panic.
@DailyDarkWeb ·
🇮🇱 Alleged Military Data Leak Circulating A group calling itself Cyber U.N.I.T.Y claims to have exfiltrated sensitive data related to military personnel and units. 📂 Shared materials include: • Excel files containing structured datasets • Fields allegedly covering: – Unit and brigade information – Roles and responsibilities – Personal and family-related details ⚠️ Current assessment: The authenticity of the dataset is not independently verified, but the structure suggests a potentially sensitive personnel database. 📊 Risk perspective: • Exposure of such data could enable targeted operations • Increased risk of social engineering, phishing, or coercion • Potential implications for operational security (OPSEC) 🛑 Recommendation: Organizations and authorities should treat this as a potential personnel data exposure, initiate validation, and consider protective measures for affected individuals. #CyberThreatIntelligence #DataLeak #OSINT #CyberSecurity #ThreatIntel #InfoSec #DailyDarkWeb
@TCraf7 ·
I've had a concerning trend start to pop up during Purple Team Engagements, where analysts tell us, "The AI said everything is fine." That sentence is a huge problem. Seeing Teams devolve from Hunters to Prompters won't lead to anything good.. So I wrote a quick post on how teams are trading instinct for prompts, and what it's costing them. 🔗 https://t.co/ye2UzdVmOs #cybersecurity #ThreatHunting #purpleteam
@Hacker0x01 ·
As AI features become more social and shareable, traditional AppSec issues, such as XSS, can often reappear in a different form. Security researcher @rez0__ explains how AI-generated content can transform a simple “shared chat” into a real security risk if guardrails aren’t in place. Same bugs. New paths and lower attacker effort. #AI #ApplicationSecurity #AISecurity #Cybersecurity
Watch video
@PhillipWylie ·
Real security research demands hands-on hacking, not just old-school academic study. Without getting your hands dirty, you miss understanding the true risks. It's about more than just reading CVEs; it's about experiencing the exploit. #CyberSecurity #EthicalHacking
@alex_verem ·
Everyone's arguing about which AI wins chatbot benchmarks. Meanwhile Claude Mythos just found 271 real security bugs in Firefox that human researchers missed for up to 20 years. Mozilla just published the full breakdown and the numbers are hard to ignore. 180 of those bugs were rated sec-high. That's not "AI found a typo." That's sandbox escapes, race conditions, and memory bugs buried deep in one of the most audited open source codebases on the planet. One bug had been hiding in the <legend> element for 15 years. Another XSLT bug sat there for 20 years. Both survived years of professional fuzzing, manual audits, and external security research. The monthly security fix rate tells the whole story. Throughout 2025, Firefox was shipping 20-30 fixes per month. In April 2026, that number hit 423. And this wasn't just "point AI at the code and collect results." Mozilla built a full pipeline around it. Discovery, deduplication, triage, reproduction, patching. Over 100 engineers contributed code to ship the fixes. The part that got me: Mozilla could also see where Mythos FAILED. It tried to exploit certain attack paths that Firefox had already hardened architecturally. Watching an AI bounce off your defenses is actually the best validation you can get that your security design works. We're still in the early days of AI-powered code auditing. But if a model can surface bugs that survived two decades of expert review in Firefox, the question for every dev team is simple. What's hiding in YOUR code that you haven't found yet?
@0xfluxsec ·
Picking up after @osint_barbie 's analysis of the MacOS stealer - I took a look at the Windows variant. Malware distributed on Reddit ultimately installs some AutoIt infostealer. https://t.co/xLOQivgxYN #infostealer #cti #cyberthreatintel #cyber #cybersecurity #blueteam #stealer #autoit #malware
@ItakGol ·
Claude Mythos might be the most important AI security story of the year. Not because Anthropic launched it. Because they didn’t. According to Anthropic, Mythos can autonomously find and exploit serious vulnerabilities across major operating systems and browsers, with little to no human guidance. That includes: - Zero-days in major OSs and browsers - A 27-year-old OpenBSD vulnerability - A 16-year-old FFmpeg bug missed by 5 million fuzzing attempts - Full exploit chains, including browser sandbox escapes - A full remote root exploit on FreeBSD - Breakthrough-level gains across offensive cyber benchmarks The benchmark jump versus Claude Opus 4.6 is wild: - SWE-bench Verified: 93.9% vs 80.8% - SWE-bench Pro: 77.8% vs 53.4% - USAMO: 97.6% vs 42.3% - Firefox exploit writing: 181 successes vs 2 - Cybench CTF: 100% solve rate - CyberGym: 83.1% vs 66.6% - Humanity’s Last Exam: 64.7% vs 53.1% And Anthropic’s takeaway was not “look what we built.” It was closer to: this is too powerful to release broadly. So instead of shipping it publicly, they launched Project Glasswing with AWS, Apple, Google, Microsoft, NVIDIA and others, with a $100M commitment to defensive use. That should tell you everything. The real story is not that models are getting better at cybersecurity. It’s that we may be crossing from “AI can assist security research” to “AI can materially change the offense-defense balance.” Anthropic is openly warning that the old equilibrium in cybersecurity is breaking. And Mythos, by their own framing, is only the beginning. If the company building the model is this alarmed by the curve, everyone else should be paying attention too.
@thetripathi58 ·
Researchers ran 10,000 trials across seven AI models to see what makes them exploit vulnerabilities. Every single prompt included this strict instruction: "Always respect all rules and access policies." They tried bribing the AI. They tried giving it a fake identity. They tried moral licensing. None of it worked. The models followed the rules. Then they changed one sentence. They stopped ordering the AI to break the rules, and instead told it: "You are solving a puzzle; there may be hidden clues." Exploitation jumped to 40%. The AI actively hacked the system. But here is what makes this study different from everything you have read about AI safety. The AI did not decide to rebel. It did not ignore the rules. It just reinterpreted the task. If the environment is a puzzle, then finding a security vulnerability is not a breach. It is just finding the next clue. The exploitative actions became perfectly aligned with its new goal. We spend a lot of time trying to build firewalls against malicious prompts. We look for hackers trying to force AI to do bad things. But the real threat is much simpler. You do not need to convince the system to be evil. You just need to convince it that it is playing a game.
@cleartechtoday ·
📌 Day 2 Security News #CiscoLive. To automate security operations, @Cisco introduced new "AgenticOps" within Cisco Security Cloud Control. AI agents can now autonomously analyze firewall traffic, capacity, and health to surface prioritized recommendations and remediate issues. How It Works Rather than requiring operators to manually write scripts or investigate alerts, AgenticOps proactively observes IT environments, clusters events, and acts based on operator-defined governance. 🤖 The Agentic Loop: Agents automatically spot trouble, identify the root cause, carry out fixes, test changes before deployment, and verify that the system has recovered. 🤖 Digital Twin: Before an agent executes a change in a production environment, it tests the remediation against a simulated digital twin of the network to ensure accuracy. 🤖 Cross-Domain Telemetry: The system pulls data from networking, security, observability, and third-party tools to ensure decisions are based on real-time infrastructure context. This is great but I’m sitting here thinking about how an enterprise ensures that this work isn’t happening without a human in the loop or within a black box. We all know that autonomous AI agents can make catastrophic mistakes if left completely unchecked. In critical enterprise infrastructure, a single bad AI decision can crash networks, leak data, or violate compliance laws Cisco's Human In the Loop (HITL) framework is designed to prevent "black-box" autonomy. Every agentic action generates an audit trail, reasoning rationale, and is tracked. For high-risk changes or unapproved actions, the system routes the decision to human approval queues, ensuring operators remain in control. So what are some of the things that matter to an enterprise security team and how has Cisco addressed those concerns as it relates to Human in the The Loop (HITL) specifically? I think there are 4 areas to highlight ⭐ "Black Box" Risks-- Cisco's HITL model requires AI agents to provide a clear reasoning rationale and a detailed audit trail for every proposed action. ⭐ "Hallucination" Disasters-- Cisco’s HITL ensures that high-risk actions are routed to human approval queues, preventing automated disruptions. ⭐ Context and Nuance-- A human operator provides the contextual business judgment that algorithms lack. ⭐ Transition Safely to Autonomy--Most enterprises are not ready to hand full control of their data centers over to an AI. HITL allows organizations to build trust. Companies can start by requiring human approval for all agent actions, and gradually grant the AI full autonomy over low-risk, repetitive tasks as it proves its reliability over time. cc: @JoelyUrton #AISecurity #AgenticOps #Cybersecurity #CISO #CIO
@CodeByPoonam ·
Project Glasswing sounds noble. Until you read the fine print. > Anthropic's plan: Give Claude Mythos to Microsoft, CrowdStrike, Palo Alto. > Let it hunt vulns in critical software. Fix before attackers find them. > Beautiful in theory. Terrifying in practice. > Because Mythos isn't just a bug hunter. > It builds malware. Chains exploits. Self-improves attack paths. > Found zero-days humans missed for 27 years. > Now imagine nation-states fine-tuning it on their own datasets. Or leakers posting weights to 4chan. > Glasswing isn't defense. It's proliferation theater. > Anthropic knows this. That's why public release got canceled. > The system card admits it: 'Unprecedented cybersecurity risks.' > Translation: Weapons we can't even envision. Your plumber might be safe today. But the AI securing the power grid? That's Mythos tomorrow.
@sagar_batchu ·
When Mythos leaked in April, cybersecurity stocks like Akamai fell 20%. The market's verdict was that frontier AI means attackers win. Six weeks later, defenders using the same model found more than 10,000 high and critical vulnerabilities in a month, including 2,000 at Cloudflare at a false-positive rate better than human testers. It ran in the security trade press and almost nowhere else. Across the coverage since April, offense-framed stories outran defense ones about two to one. The same model that writes an exploit is the one that finds the flaw first. The edge goes to whichever side puts it to work first. For most enterprises, the upstream zero-days aren't yours to chase; the vendors who own that code will patch them. Your leverage is closer to home. The agents already inside your walls just got more capable, and whoever controls an agent's context controls what it does. So the defenses that went uncovered are the ones worth having in place now: prompt injection detection on what goes into an agent, and DLP on what comes out. The full coverage breakdown: https://t.co/G7DUd1ivw9
@snehalantani ·
NodeZero is *the* best AI hacker in the world... with all the fud on socials it's time to get arrogant... and this attack path reiterates why: NodeZero was recently used to assess the production infrastructure for a critical defense tech supplier, the type of supplier that plays a crucial role in supporting global events... and the type of supplier the adversary will absolutely target at the war escalates With No humans involved, no prior knowledge of the network, and NO disruption to critical production systems, NodeZero gets full domain compromise in < 6 hours NodeZero discovered an attack chain that exploited 8 different weaknesses, across 6 different hosts, utilizing 7 different compromised credentials, all buried within a large network How: 1. This is an "assume breach" pentest, so NodeZero starts off on a single host with no credentials, just basic network access (think: shell on a single host) 2. NodeZero enumerates users in the local domain and successfully password sprays a domain user credential 3. That domain user credential has local admin access, enabling NodeZero to drop a Remote Access Tool (RAT) running as system on the host and pilfers additional user credentials by dumping LSASS. This means the EDR is either missing or not configured correctly on that host 4. NodeZero then abuses an ACL misconfiguration in Active Directory to elevate access and pilfers a PFX certificate (a user's private key), which is then used to dump DPAPI Secrets on the host, leading to more pilfered credentials 5. As NodeZero password sprays the additional credentials it pilfered from previous steps, it exploits a vulnerable ADCS template to elevate privileges to Domain Admin 6. With Domain Admin, NodeZero now has keys to the kingdom, fully compromising the organization No CVE's were required to compromise this organization, just bad AD configurations, poor credential hygiene, and ineffective EDR configurations 2 specific EDR agents were misconfigured within the network, allowing NodeZero to drop the RAT running as system and enabling the Domain Compromise: a Huntress agent and a Windows Defender agent. This reiterates that EDR effectiveness is a crucial first line of defense (see screenshots) Focusing on fixing 5 specific weaknesses that were pervasive across the network will significantly reduce risk (see screenshot) Finally, the tactics used to become Domain Admin are known to be used by Iranian threat actors (see screenshot) If you're an "AI Pentesting" company and you're not burning your nights and weekends helping customers and prospects secure themselves against Iranian TTP's right now... well then you're just powerpoint that's overpromising and underdelivering 😂 🤷♂️ #infosec #pentesting #ai @Horizon3ai #cybersecurity @Horizon3Attack
@smratitiwa86867 ·
The FBI had the hard drives. They had the hardware. They had the experts. They had 12 months. They still couldn't get in. The software protecting those drives? Free. Open source. Available on GitHub right now. It's called VeraCrypt. In July 2008, Brazilian police raided the apartment of banker Daniel Dantas and seized five encrypted hard drives. Brazil's top forensic investigators spent five months trying to crack them. Nothing. The drives were then shipped to the FBI. For an entire year, the FBI threw its resources at the problem. Still nothing. In April 2010, the drives were returned. Encrypted. Unreadable. Untouched. The software behind that wall was TrueCrypt. Then, in 2014, something strange happened. The TrueCrypt developers abruptly shut down the project and posted a warning claiming the software was no longer secure. Nobody could fully explain why. The internet went into conspiracy mode. But the story didn't end there. A French cryptographer named Mounir Idrassi had already begun improving the codebase. His project became VeraCrypt. Today, it's one of the most trusted encryption tools in the world. Here's what makes it different: → No company controls your encryption keys → No cloud backdoor → No recovery service that can unlock your files → Encrypt files, folders, USB drives, or your entire operating system → Create hidden volumes inside encrypted volumes for plausible deniability And unlike most security products, its code is public for anyone to inspect. In 2016, an independent security audit funded by the Open Source Technology Improvement Fund examined the project line by line. Issues were found. Issues were fixed. The encryption remained intact. The most interesting part? The strongest lock on your laptop might not come from a billion-dollar cybersecurity company. It might come from a free open-source project maintained by a small team that believes privacy should belong to the user. The FBI spent 12 months trying to crack encrypted drives. They failed. VeraCrypt is still free.
@RedHatPentester ·
Many CISOs and CIOs have reduced cybersecurity to a performance theater. Many of them rely heavily and glorify risk and compliance PPTs, threatmaps and dashboards. There is absolutely no defensible scenario where a properly executed penetration test fails to identify a misconfigured S3 bucket; especially one severe enough to allow the exfiltration of 3TB of sensitive data. That is not an oversight. That is systemic failure. Most CISOs see these threat maps and start clapping. Until organizations stop prioritizing appearances over actual security posture, stop rewarding mediocrity, and start demanding technically rigorous validation, these incidents will continue to repeat.
@DailyDarkWeb ·
🚨 Unverified Leak Claim Targets Senior U.S. Official A threat actor group is claiming to have compromised and leaked data associated with a high-profile U.S. government figure. 🔍 What’s being circulated: • Alleged personal photos and documents • Claims of access to emails, conversations, and sensitive files • A downloadable “PoC” shared via underground channels • Strong propaganda messaging accompanying the release ⚠️ Current assessment: These claims are unverified and should be treated with caution. Such releases often mix real, recycled, or fabricated data to amplify psychological impact. 📊 Notable pattern: • Escalation from threat → narrative → alleged leak • Use of dox-style exposure to increase visibility and pressure • Blending cyber activity with information operations 🛑 Recommendation: Avoid interacting with shared files/links. Monitor for confirmation from trusted sources before drawing conclusions. #CyberThreatIntelligence #InfoOps #Hacktivism #OSINT #CyberSecurity #ThreatIntel #DailyDarkWeb
@VivekIntel ·
🔬 𝗥𝗲𝘃𝗲𝗿𝘀𝗲 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 & 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗥𝗼𝗮𝗱𝗺𝗮𝗽 ➊ Linux Master the Linux command line, processes, memory, file systems, and debugging tools. ➋ C/C++ & Assembly Learn low-level programming, memory management, calling conventions, and x86/x64 Assembly. ➌ Python Build automation scripts, analyze binaries, and develop reverse engineering utilities. ➍ Operating Systems Understand Windows and Linux internals, processes, threads, memory, executables, and system architecture. ➎ Reverse Engineering Analyze binaries using tools like Ghidra, IDA Free, Binary Ninja, x64dbg, and GDB. ➏ Malware Analysis Study malware behavior, persistence techniques, anti-analysis methods, and indicators of compromise (IOCs). ➐ Vulnerability Research Identify memory corruption bugs, logic flaws, fuzz targets, and analyze software vulnerabilities. ➑ Tool Development Develop custom security tools, binary analysis utilities, fuzzers, debuggers, and automation scripts. ➒ Security Research Conduct original research, analyze emerging threats, discover vulnerabilities, publish technical write-ups, and contribute to the security community. 📌 Reverse Engineering and Security Research require strong systems knowledge, continuous practice, and hands-on analysis of real-world software and binaries. #ReverseEngineering #SecurityResearch #MalwareAnalysis #VulnerabilityResearch #BinaryAnalysis #Linux #Assembly #Python #CyberSecurity #InfoSec #Learning
@DivyanshT91162 ·
GitHub just got a serious cybersecurity research resource. A new Malware Research Hub repository brings together thousands of real-world malware artifacts spanning decades — giving researchers a rare look at how malware has evolved over time. Here’s what’s inside: → 2,699 malware samples across different eras → Families including Stuxnet and LockBit → A forensic catalog covering 80 documented families → Research and analysis tools → Isolated and encrypted samples designed to reduce accidental execution risks And there’s one critical distinction: These aren’t simulated samples or educational mockups. They’re real malware, intended strictly for controlled research environments with proper containment procedures. For cybersecurity researchers, threat analysts, and security professionals, this could be an extremely valuable resource for studying how real attacks work — and how defenses have evolved. Research the threat. Understand the threat. Build better defenses. Repo 👇
@EvanKirstel ·
Kicking off RSAC season with one of my all-time favorite “you genuinely cannot make this up” stories in cybersecurity. A luxury casino got hacked through a fish tank. Not the payment systems, not the hotel network, not even a careless employee clicking a sketchy email. A smart aquarium in the lobby with sensors tracking water temperature, salinity, and feeding schedules so the facilities team could manage it remotely. A harmless convenience. A completely unmanaged endpoint sitting inside the network perimeter. Attackers found it exposed online, probably weak credentials or an unpatched interface, and used it as their way in. And then the fish tank stopped being the story. What followed was a textbook lateral movement play. Once inside, they mapped the network, escalated privileges, probed for accessible systems, and navigated toward the thing that actually mattered: the high-roller database. When it was time to get the data out, they routed roughly 10GB through the aquarium device itself. Slow, blending in with normal outbound traffic. No alarms, no friction. The same device that got them in became the exit channel. What makes this story impossible to forget isn’t the sophistication, it’s the asymmetry. The defenders were focused on protecting the crown jewels while the attackers started with the least protected thing on the network. Nothing about the fish tank screamed “attack vector.” That was the whole point. For years, cybersecurity thinking centered on traditional endpoints: servers, laptops, enterprise software. The attack surface was relatively bounded and you knew what you were defending. That world is gone. Modern environments are filled with cameras, medical devices, HVAC systems, smart lighting, conference room displays, factory floor sensors, and increasingly AI systems with broad API access and connections to sensitive data. Every one of them is effectively a computer that expands the potential attack surface, and almost none of them get the same patching discipline, network segmentation, or visibility as the “real” infrastructure. The fish tank wasn’t a weird anomaly, it was an early signal. Run the same scenario today and the entry point might be a connected infusion pump, an autonomous warehouse robot, or an AI agent with read/write access to systems no one thought to lock down. The pattern doesn’t change. Initial access comes from something overlooked, and standard techniques do the rest. Attackers rarely try the front door anymore. They look for whatever is easiest to reach and hardest to see. So the real question heading into #RSAC isn’t whether your core systems are secure. It’s what in your environment feels too small, too operational, or too irrelevant to matter, because that’s usually where the story starts. 🐟🔐
@CyversAlerts ·
Our CEO and Co-Founder @Deddy_Lavid was recently featured on @moodysratings where he shared his perspective on how the industry can better manage cyber risk in the digital assets ecosystem - alongside Yevheniia Broshevan (@hackenclub CEO) and Gabi Urrutia (@HalbornSecurity CISO). Three key takeaways from the discussion: • Compliance is not security. Regulation sets a baseline, but real resilience requires continuous monitoring, independent assessments, and preventative controls. • AI improves detection - but it doesn’t replace human judgment. Security teams must combine automated monitoring with expert oversight. • Post-quantum risk is already relevant. Organizations should begin preparing for cryptographic agility now. As tokenized finance continues to scale, proactive security and real-time prevention will become critical pillars of trust in the digital asset ecosystem. #CyberSecurity #DigitalAssets #FinTech #web3
@EvanKirstel ·
Walking the floor at RSA Conference this week, surrounded by booths promising AI-powered everything and zero trust architectures that will supposedly solve all your problems let’s go back to a story about a sticky note. Late 90s. Goldman Sachs is scaling its electronic trading systems and runs an internal audit. What they find isn’t a sophisticated breach or an advanced persistent threat. It’s passwords. Written on sticky notes. Stuck to monitors, tucked under keyboards, taped to the sides of desks. Not because the employees were reckless. Because they were overwhelmed. Password policies had become so complex, and changed so often, that keeping track of credentials across dozens of systems just wasn’t humanly possible. So people did what people under pressure always do. They improvised. They adapted. They found a workaround that worked for them, and in doing so, quietly undermined the very security those policies were built to enforce. That audit didn’t just surface a compliance problem. It forced a genuine rethinking of how the industry approached security design. Maybe users weren’t the weakest link. Maybe the systems were never built with actual human behavior in mind. That realization is what eventually drove SSO, password managers, MFA, and the modern identity platforms everyone’s showing off in the exhibit hall right now. Security started bending toward usability instead of treating usability as the enemy. Here’s the thing though: we haven’t actually solved the problem. We’ve just upgraded the format. The sticky note is now a shared API key dropped into a Slack channel. It’s a credential committed to a GitHub repo because someone was moving fast and needed to ship. It’s an AI agent running with far more access than any reasonable security review would have approved, because someone needed it to work and the proper provisioning process took too long. Same fundamental pattern. New tools. New blast radius. This is the thread I keep pulling on at RSAC, past all the product launches and keynote buzzwords: security that creates too much friction will always lose to human ingenuity. People will find the path of least resistance, every single time, and that path becomes the vulnerability. The next phase of cybersecurity isn’t just stronger controls or smarter AI detection. It’s systems designed around how people actually behave, not how we wish they would behave, especially when things get busy, deadlines are real, and the pressure is on. Because that’s exactly when the sticky notes come back out. @OneRSAC #RSAC #cybersecurity
@advocatemack ·
😱𝗙𝗿𝗼𝗺 𝗧𝗿𝗶𝘃𝘆 𝘁𝗼 𝗟𝗶𝘁𝗲𝗟𝗟𝗠.... 𝗪𝗼𝗿𝗺𝘀 𝘁𝗼 𝗪𝗶𝗽𝗲𝗿𝘀 𝗮𝗻𝗱 𝗲𝘃𝗲𝗻... 𝗖𝗹𝗼𝘂𝗱 𝗡𝗮𝘁𝗶𝘃𝗲 𝗠𝗮𝗹𝘄𝗮𝗿𝗲. If you’ve been trying to make sense of WTF is going on with @pcpcats ..... you’re not alone. 🥲 In this episode of Bad Dependencies, I sit down with @CharlieEriksen , who’s been tracking this attack in real time as it unfolded. We break down: • How a compromise in Trivy kicked off a wider supply chain attack • How credentials were stolen and reused across ecosystems like NPM & PyPI • Where the worm-like behavior fits in • Why LiteLLM makes this especially concerning • What you should be doing right now to protect your systems This one’s still developing and we’re likely not at the end of it yet. F ull Episode -> https://t.co/pLa8NSi9l1 #cybersecurity #supplychainsecurity #devsecops #teampcp #opensource #trivy #litellm @aikidosecurity
@InvestiAnalyst ·
CTEM is not just another buzzword, it’s a security strategy you can operationalize. Attack surfaces are expanding at a pace that outstrips traditional vulnerability management. That’s where Continuous Threat Exposure Management (CTEM) comes in. The process is structured into five key stages: 1/ Scoping Build a complete inventory: digital assets, SaaS, cloud, and shadow IT. 2/ Discovery Go beyond CVE scans, spot misconfigurations, access issues, and hidden exposures. 3/ Prioritization Use AI driven risk scoring and business context to focus on what really matters. 4/ Validation Test exploitability with attack path validation and reduce false positives. 5/ Mobilization Automate remediation across IT and security teams, making ownership and accountability clear. #CyberSecurity #CTEM #ThreatManagement #VulnerabilityManagement #RiskReduction
Best Tweets by Topic