AI didn't escape. It started testing the fence. That's the lesson I took from the OpenAI/Hugging Face incident. The important question isn't whether AI is malicious, it's whether our security controls still work when AI begins testing them. betweenthehacks.com/...
Chuck Davis
@ckd3.net
Cybersecurity executive helping bridge technology, public policy, and critical infrastructure resilience. Author, inventor, educator, speaker, and founder of NetBOM
The best cybersecurity professional I ever hired had no college degree. They had curiosity. That mattered more. Here’s why, plus the career advice I wish someone had given me. betweenthehacks.com/...
I thought I was just reading an article. Instead, I found a ClickFix attack. After reproducing it across multiple browsers and researching further, I realized the real story wasn’t the malware. It's how attackers are impersonating security itself. betweenthehacks.com/...
We’ve spent decades securing identities. AI governance extends those ideas to AI agents, and that’s the right direction. But identity and governance answer only two questions. I think the next challenge is understanding what influences AI behavior. betweenthehacks.com/...
Enjoyed joining @hackersonthehill.org in Washington, DC. Cybersecurity isn’t just a technology challenge. It’s also about governance, public policy, and collaboration. Thanks @beauwoods.com and everyone who organized the event. What cybersecurity policy issue deserves more attention from Congress?
We keep talking about passwordless. Attackers are still using passwords. bth.news/2026wpd #Cybersecurity #WorldPasswordDay #InfoSec #Security
If your vulnerability program is driven entirely by CVSS scores, you are probably missing real risk. This post outlines a high-level approach to prioritizing remediation based on exposure, KEV data, and attacker behavior. Link 👇 betweenthehacks.com/... #VulnerabilityManagement
Venmo makes your payments public by default. Who you paid. When. And why. This is a privacy problem with an easy, 30 second fix! 🔗 betweenthehacks.com/... #Venmo #PrivacyMatters #CyberSecurity #VenmoPrivacy #AppSecurity #DataProtection #DigitalSafety #FixItFast
Did you know National Internet Safety Month started in 2005? It began as a campaign to protect kids online—now it’s a reminder for everyone to tighten up digital hygiene. Read the history: bth.news/safety #Cybersecurity #InternetSafety #Infosec
Need a quick win this weekend? Check out my 10-minute security checklist: updates, MFA, router tweaks, password scan, and more. No fluff, no fear—just real-world security tips anyone can follow. 🔗 betweenthehacks.com/... #cybersecurity #weekendproject #infosec
If “The Spy Who Applied to Code” grabbed your attention, check out @smashingsecurity.com Ep. 407. It covers human trafficking behind tech scams in Myanmar. Dark stuff—important to know. www.smashingsecurity.com/407-hps-hold... #Cybersecurity #HumanRights
407: HP's hold music, and human trafficking
Journey with us to Myanmar's shadowy scam factories, where trafficked workers are forced to run romance-baiting and fake tech support scams, and find out why a company's mandatory hold time for tech s...
smashingsecurity.com
He said he liked food. He couldn’t name a restaurant. He claimed to live in Houston. He didn’t know what Halloween was. Turns out, he was a North Korean spy. Here’s what happened when Kraken interviewed him: 👉 www.betweenthehacks.com/blog/the-spy...
He said he liked food. He couldn’t name a restaurant. He claimed to live in Houston. He didn’t know what Halloween was. Turns out, he was a North Korean spy. Here’s what happened when Kraken interviewed him: 👉 www.betweenthehacks.com/blog/the-spy...
North Korean Hackers Are Applying for Remote Jobs: How to Spot the Fakes — Between The Hacks
A North Korean operative posing as a remote software engineer nearly infiltrated a U.S. company. Here’s what happened—and how to avoid falling for these increasingly sophisticated scams.
betweenthehacks.com
A fake resume. A fake location. A real threat. Kraken’s hiring team spotted the red flags—and uncovered a North Korean spy posing as a dev. Here’s how it unfolded: 👉 betweenthehacks.com/... #Cybersecurity #RemoteWork #Infosec
It’s World Password Day! Still clinging to qwerty and your dog’s birthday? No judgment—just backup and fix it. New on Between The Hacks: betweenthehacks.com/... #Passwords #WorldPasswordDay #CyberSecurity
Your laptop is your command center. Don’t make it an easy target. Here are 10 smart, simple ways to lock it down in 2025. 🔒 👉 betweenthehacks.com/...
New post on Between The Hacks: Quishing: Phishing Got a Glow-Up QR codes are sneaky little traps. This post explains how attackers use them to phish for creds, how it works, and how to stay safe. bth.news/quishing #quishing #cybersecurity #infosec
DEF CON 33 talk submitted: What SBOMs Forgot About the Network NetBOM defines where devices should connect, then helps your firewall block the rest. It’s time to stop trusting by default. netbom.net #NetBOM #Cybersecurity #DEFCON33
Just when we thought cyber security wasn’t difficult enough
BREAKING. From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
My thermostat wouldn’t work without full Internet access. I tried to restrict it. Support said: “Put it in the DMZ.” Nope. I built NetBOM instead. It’s like SBOM—but for network behavior. Read the blog: betweenthehacks.com/... White Paper: netbom.net #NetBOM #Cybersecurity #IoTSecurity
Ransomware is no joke—but the time ransom notes started printing on lobby printers? Still kind of hilarious. New on Between The Hacks: what it is, how it works, and how to stay protected. 👉 betweenthehacks.com/... #Ransomware #InfosecHumor
Hey friends, we’ve updated our main URL! The new default is betweenthehacks.com. Same content, just a new domain. Check it out: betweenthehacks.com/...
🔐 Passwords are dead. Passkeys are here—and they’re everything passwords wish they were. ✅ Can’t be guessed ✅ Can’t be phished ✅ Seamless login with Face ID, Touch ID, or security key Full breakdown: betweenthehacks.com/passkeys #Passkeys #Cybersecurity #WebAuthn #DigitalSecurity
I’ve been talking about network segmentation for years. This week, I took action. ✂️ Cut the Ethernet cable 📡 Rotated the SSID every 60 seconds 🧊 Put the printer in the freezer Welcome to Physical Zero Trust™ www.ckd3.com/blog/cut-eth... (fixed link) #infosechumor #cybersecurity #iot
A flat network means any device, like a smart plug, light bulb, or fridge, can reach the Internet and your other devices. In my latest post, I explain how segmentation helps, but visibility is the next frontier. 🧠 www.ckd3.com/blog/everyth... #infosec #homeiot #security
Troy Hunt—yes, that Troy Hunt—clicked a phishing link. It’s a reminder that even the best in security are human. I broke down what happened and how to protect yourself (or your team): www.ckd3.com/blog/troy-hu... #infosec #phishing #cybersecurity
Even Cybersecurity Experts Fall for Phishing | What Troy Hunt’s Story Teaches Us — Between The Hacks
Cybersecurity expert Troy Hunt fell for a phishing attack. Learn what happened, how phishing tactics have evolved, and how to protect yourself in 2025.
ckd3.com
FBI seizes major cybercrime forums in coordinated domain takedown cyberscoop.com/fbi-seized-c...
FBI seizes major cybercrime forums in coordinated domain takedown
The Federal Bureau of Investigation, along with several other law enforcement departments, has seized control of several cybercriminal forms.
cyberscoop.com
New York Blood Center (NYBC), one of the largest nonprofit blood centers in the United States, says it is experiencing service disruptions after being hit by a ransomware attack techcrunch.com/2025/01/30/u...
US blood donation giant warns of disruption after ransomware attack | TechCrunch
New York Blood Center said it does not have a "specific timetable for system restoration" following the attack, which has led to canceled appointments and delays
techcrunch.com
Thrilled to announce that I’ll be joining the Tribunal for the ISE Cybersecurity Hackathon 2025 in Barcelona next week! 🎉 www.linkedin.com/posts/chuckd...
Charles Davis on LinkedIn: ISE 2025: The World-Renowned Tech Show | Feb 4-7 Barcelona
Thrilled to announce that I’ll be joining the Tribunal for the ISE Hackathon 2025 in Barcelona next week! 🎉 A big thank you to Integrated Systems Europe…
linkedin.com
The WEF & Oxford University have put out a new report on AI & Cybersecurity. "The use of AI is creating an expanded attack surface that might be exploited by threat actors. Existing methods need to be extended to address new vulnerabilities that are inherent in AI" www.weforum.org/publications...
Industries in the Intelligent Age White Paper Series
The Industries in the Intelligent Age White Paper Series examines AI’s transformative role across diverse sectors, offering insights into challenges, opportunities and strategies for responsible innov...
weforum.org