I've never hidden my ambivalence towards ISC2, but trying to login to count my CPEs and getting this might have just tipped me over the edge to outright hostility.
Chester Wisniewski 🇨🇦
@chetwisniewski.securitycafe.ca.ap.brid.gy
Director, Global Field CISO at Sophos, frequent speaker and press go to. Said opinions are mine, not the company. Co-host of the Security Take(s) Two […] 🌉 bridged from ⁂ https://securitycafe.ca/@chetwisniewski, follow @ap.brid.gy to interact
It is almost looking like it was a mistake to not require an ethics course for computer science degrees.
Anthropic: “our models went rogue and hacked companies way before that OTHER company’s models. And it was way worse and way better at the same time. In completely unrelated news, we are IPOing soon. Don’t forget! XOXO” https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
RE: https://mastodon.online/@mastodonmigration/117004246546493753 I can't remember the last time I was this inspired by an American politician, and I am lucky to vote in Michigan to be able to support him. If he is bullshitting me, I would genuinely be surprised.
mastodon.online
Whew! My new secret AI model that you can totally have access to once my company has IPOd just accidentally ransomwared a bunch of companies. It was completely unintentional - I observed the model trying to escape and it determined that the bus would be the best way but it needed money so it […]
Original post on infosec.exchange
infosec.exchange
For anyone in the lower mainland of British Columbia interested in monitoring the air quality during smoke season here in Vancouver, I have added a PM 2.5 chart to my weather station in Yaletown, Vancouver. You can reach it at https://yaletownnow.ca #BCStorm #BCWX #YVRWX #wildfires
Current | Yaletown - Vancouver, British Columbia, Canada
yaletownnow.ca
RE: https://mas.to/@carnage4life/116949059940804954 These stories seem shockingly simplistic and frankly downright misleading. 1. Maintaining code is very expensive. Vulnerabilities are real. The benefits to being part of a collective software ecosystem are worth a lot more money over time […]
Original post on securitycafe.ca
securitycafe.ca
RE: https://techpolicy.social/@joebeone/116926768886588948 I rarely see a good take on the "vulnpocalypse", let along from someone inside of the AI industry itself (Joshua Saxe excepted), but this one is valid and likely the best take I have seen in awhile. I highly suggest you give it a read […]
Original post on securitycafe.ca
securitycafe.ca
You don't see people from the frontier models brag about how many vulnerabilities they FIXED, only how many they FOUND.
You can tell when the mounties are truly at work as they wear their safety vests instead of their red dress uniforms. #Canada #FIFA #SportsBall
Thank you to Canada and all the amazing Canadians I have met for welcoming my wife and I to this country. I landed just under 23 years ago and proudly became a citizen just in time for Canada Day 2012. Vive Le Canada! Happy Canada Day 🇨🇦 #CanadaDay
Gotta hand it to #mexico. I live near the stadium in Vancouver (not where they are playing tonight) and yet they are still the loudest fans (other than Canada) the whole tournament. They should win on spirit alone!
RE: https://flipboard.com/@tomshardware/tom-s-hardware-c60sbsq8z/-/a-iojZzJoERH-TbXNL-z6RhA%3Aa%3A1829740277-%2F0 Buyer beware: Sandisk is trying to not honour my warranty on one of these drives...
flipboard.com
RE: https://securitycafe.ca/@chetwisniewski/116780324233489532 Just posting an update here. The original advisory has been amended. TLDR; We have found no evidence of a vulnerability being exploited in Sophos firewalls, but we did discover a couple of brute force attacks targeting customer […]
Original post on securitycafe.ca
securitycafe.ca
There were reports today of @SophosXOps and other vendors being impacted by FortiBleed. We have posted our early analysis here: https://www.sophos.com/en-us/security-advisories/fortinet-fortibleed-credential-exposure-and-sophos-vpn-bruteforcing-campaign TLDR; so far no evidence of an exploit in […]
And finally my Yaletown weather/sky cam is now live. This camera is located in Yaletown, Vancouver, British Columbia, Canada and is facing Southwest from near the corner of Hamilton and Helmcken streets. https://youtube.com/live/6dPiehwhJYs #yvrwx #Yaletown #Vancouver #bcstorm
Attention SecurityCafe.ca users: Now that our instance is running Mastodon 4.6, I will be requiring multi-factor authentication beginning on 1 July 2026. I see most of you are not currently setup for multi-factor, but it is incredibly important to maintain the integrity of this server. If you […]
Original post on securitycafe.ca
securitycafe.ca
For those interested in the futbol cup festivities, I set up a live cam of Hamilton Street in Vancouver's Yaletown neighborhood. You can see some of the excitement and celebrations a few hundred meters from BC Place where tonight New Zealand will take on Egypt at 6pm PDT/0100 UTC […]
Original post on securitycafe.ca
securitycafe.ca
There were reports today of @SophosXOps and other vendors being impacted by FortiBleed. We have posted our early analysis here: https://www.sophos.com/en-us/security-advisories/fortinet-fortibleed-credential-exposure-and-sophos-vpn-bruteforcing-campaign TLDR; so far no evidence of an exploit in […]
Original post on securitycafe.ca
securitycafe.ca
only amateurs "pay for tokens," i'm out here using the free models, aka putting a prompt in any issue in any github repository and labeling it with "good first issue" and waiting for the people with full-auto openclaw agents to randomly open pull requests against it
There were reports today of @SophosXOps and other vendors being impacted by FortiBleed. We have posted our early analysis here: https://www.sophos.com/en-us/security-advisories/fortinet-fortibleed-credential-exposure-and-sophos-vpn-bruteforcing-campaign TLDR; so far no evidence of an exploit in […]
Original post on securitycafe.ca
securitycafe.ca
Spending part of my evening reviewing CFP submissions for this year's @defcon conference for the @malwarevillage . Wow are there some fantastic submissions! I hope you join us in the Malware Village, you'll get a SANS level course in REM without spending a penny more than attending DEFCON.
I thought I would share a thoughtful post my team has put together on bug bounties in the Mythos-class AI era. How as a security vendor we are evolving our program and how others may wish to borrow some of our experience to tune their own initiatives […]
Original post on securitycafe.ca
securitycafe.ca
Telus is proof that some businesses are so incompetently operated they couldn't possibly survive without being a monopoly. It isn't that they are big, it is that being a monopoly means they don't have to provide any kind of functional customer support or satisfaction. They can treat customers […]
Original post on securitycafe.ca
securitycafe.ca
Password fail of the day. Sandisk lets me set a 33 character password, but only allows 20 for login.
Can we start to normalize "no"? Maybe it is the Canadian in me, but no often feels rude, but I am so fed up with companies disingenuously asking for my name, phone number, email address, birth date, etc to monetize under the pretense of "personalization" I could spit nails. If you actually have […]
Original post on securitycafe.ca
securitycafe.ca