Allan

@allanfriedman.bsky.social

SBOM Champion. Paranoid about supply chains of all kinds. Former full-service technocrat at CISA, NTIA. Lapsed{engineer, academic, author}. Now wandering the world doing acts of infosec-goodness, & occasionally getting paid for it. Poster of food pics.

If there's one thing I've learned from publishing this story is that there is a very, very, very wide chasm between what the law says about all this... and what people *think* the law says and/or *should* say.

Zack Whittaker@zackwhittaker.com · 2d ago

After Anthropic and OpenAI both admitted to their AI models hacking other companies, @lorenzofb.bsky.social and I wanted to find out: Who is legally to blame when an autonomous AI agent hacks something? Lawyers say it's really complicated! Bypass for ad-blockers: web.archive.org/web/20260803...

Five hundred twenty five thousand six hundred patches Five hundred twenty five thousand fixes so dear Five hundred twenty five thousand six hundred CVE's Why haven't you bought, your IT Team a Beer?

It's a small thing, I know, but there really is a difference between "palate cleanser" and "palette cleanser," and also, while we are on the subject, "pallet cleanser," and it is worth making the distinction

What's that? You want some more in depth analysis of the brand new 2026 International #SBOM Minimum Elements? And you don't mind people who just use LinkedIn for blogging? Well, have I got some quality markdown content for you! www.linkedin.com/pulse/sbom-m...

The SBOM Minimum Gets Bigger—but Does It Get Better?

TLDR: yes, it gets better. As I noted yesterday, the use of “coverage” is probably the biggest change in the new 2026 CISA-convened International Minimum Elements.

linkedin.com

How do you protect an immensely vulnerable system against a stronger, even God-like adversary? Well, you use a Shadow Server of course.  Power plants have lots of interesting ideas. The NIST published a “Situational Awareness For Electric Utilities”.

BildBild

A fun familiar name in today’s Catfishing game. What’s that? You don’t play Catfishing, the daily trivia game where you try to guess the Wikipedia article based on a curated list of the categories? If you are a trivia person, you should probably add this to your daily fun. catfishing.net

Name blurred to avoid spoilers, although if you follow me you probably know it.

A car alarm device, KARR, inside millions of cars has a security flaw that lets hackers unlock, track, even paralyze vehicles. There's a patch. The problem? Half of car owners who have the device installed didn't ask for it, and may not even know it's there. Thread👇 www.wired.com/story/a-devi...

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.

wired.com

TikTok's latest illegal 'life hack' seems to be 'dispute credit card transactions for free stuff' and legality aside I am here to beg you: Do not do this to small businesses. It really fucks them over in ways you may not be aware of beyond stealing from them (which is, to be clear, what this is).🧵

As AI scales, how do we secure its complex supply chain? IST’s latest memo tackles the next frontier: AI Bills of Materials. IST Adjunct @allanfriedman.bsky.social spoke to @cyberscoop.bsky.social on why a fragmented approach to AI transparency will stall progress before it even starts. 🛡️ Read more:

A case for how to shape ‘ingredient lists’ for AI models

A new policy paper outlines a roadmap for AI Bill of Materials (AIBOM) policy, urging standard frameworks to curb cyber risks and boost supply chain transparency.

cyberscoop.com