Unsupported connected devices are becoming a global security risk, but public policy has not kept pace. At BSides LV, Paul Roberts and Silas Cutler will discuss emerging state legislation requiring clear end-of-life disclosures, minimum support transparency, and responsible vendor exit plans.
Chris Wysopal
@weld.bsky.social
Gray haired gray hat. Co-founder Veracode. Former L0pht security researcher. Builds tools to find and fix vulnerabilities in code at scale.
Wow! This is an amazing and useful @defcon.bsky.social badge! www.wired.com/story/defcon...
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.
wired.com
Polymarket lost ~$3M and their smart contracts worked perfectly. A compromised frontend vendor injected malicious JS client-side. The breach lived in the browser — the layer nobody monitors. Audit what runs, not just what you wrote. www.cybersecurity-insiders.com/software-sup...
Software Supply Chain Security Miss Drained $3M from Polymarket
Software supply chain security failures contributed to the $3M Polymarket loss, exposing risks from compromised dependencies and weak software controls.
cybersecurity-insiders.com
Who should get charged with a CFAA violation for the AI agent breach of Hugging Face? The people who built the model or those that operated it unsafely? Someone else?
If you own it, why can't you fix it? Join EFF, Adam Savage, and iFixit CEO Kyle Wiens on July 23rd for a live conversation about the Right to Repair movement. We'll answer that question and yours during the live Q&A. eff.org/livestream-r2r
Our first-ever keynote: Chris Wysopal @weld.bsky.social. Original L0pht vulnerability researcher, Veracode co-founder, and one of the first people to warn the world about insecure software. Boston hacker history, back on a Boston stage at MinuteCon. April 30 – May 1, 2027 minutecon.org
There is a new cybersecurity con coming to Boston this spring, MinuteCon! Boston has a long history of cybersecurity impact going back to the @l0pht.bsky.social days in the 90s but hasn't had a major hackerish oriented con since Source Boston 10 yrs ago. Looking forward to this! www.minutecon.org
KEYNOTE UNLOCKED_ Excited to have @weld.bsky.social opening up our conference with his Keynote: “WHEN EVERY ATTACKER CAN HAVE A RESEARCH TEAM” > Access talk details: nohat.it/talks #nohat2026 #CyberSecurity #InfoSec
Big win for farmers right to repair! fighttorepair.substack.com/p/the-deere-...
The Deere Dam Just Broke: FTC Settlement of Class Action Empowers Farmer Repair
The Federal Trade Commission, joined by the attorneys general of 5 states, announced a settlement with Deere & Company that dramatically expands farmers right to repair their agricultural equipment.
fighttorepair.substack.com
I'm very excited to speak and meet new colleagues at No Hat in Italy this October!
KEYNOTE UNLOCKED_ Excited to have @weld.bsky.social opening up our conference with his Keynote: “WHEN EVERY ATTACKER CAN HAVE A RESEARCH TEAM” > Access talk details: nohat.it/talks #nohat2026 #CyberSecurity #InfoSec
28 years ago today, 7 members of the hacking group L0pht Heavy Industries told the U.S. Senate they could "shut down the internet in 30 minutes."
Couldn’t agree more with @weld.bsky.social about @windowsnyder.bsky.social for @darkreading.bsky.social being “one of the most important security leaders of the past two decades," for her ability to achieve systemic change. Great #Darkreading20 special coverage.
As part of Dark Reading's 20th anniversary special coverage, we profile the CISOs, founders, researchers, criminals, and policymakers who rewrote the enterprise risk playbook. Read the full story here: https://bit.ly/438hvE8 #DarkReading20
AI is not going to flood you with real vuln reports unless you have a ton of real vulns. Adding resources to a vuln disclosure process to keep up with triage & bug fixing is a temporary investment at the loud end of the problem, not the right end.
We've just published the 2nd episode of our documentary series "How the World Got Owned". This one looks at the 1990s and features interviews with Kevin Poulsen, @weld.bsky.social, @thedarktangent.bsky.social and Alpeh One (Elias Levy). Subscribe to the stories feed now! risky.biz/HTWGO2-stori...
I’m excited to let you know that the talks from [un]prompted—the AI Security Practitioner Conference—are now live on YouTube. No fluff, no hype—just real-world AI security from people actually doing the work. www.youtube.com/playlist?lis...
[un]prompted 2026 - YouTube
youtube.com
RCE vulnerability in the Yamaha PSR-E433 synthesizer, discovered by Anna Antonenko, allows exploitation through crafted MIDI files that trigger a hidden firmware backdoor with hardcoded password "#0000". it4sec.substack.com/p/remote-cod...
Remote Code Execution (RCE) in Yamaha synthesizers: an exploit in MIDI files & a hidden backdoor 🎹♫💉👨🏻💻🎉
Security researcher and musician Anna Antonenko, aka “porta,” shares her security research on the Yamaha PSR-E433: it looks like the device accepts special MIDI messages that allow commands to be exec...
it4sec.substack.com
Doesn't everyone watch Akira on LaserDisc with their figurines?
Security debt is becoming a governance issue for CISOs 📖 Read more: www.helpnetsecurity.com/2026/03/02/c... #cybersecurity #cybersecuritynews #CISO #riskmanagement @weld.bsky.social
Security debt is becoming a governance issue for CISOs - Help Net Security
A new security debt report shows 82% of organizations carry year-old flaws as high-risk vulnerabilities rise and fix timelines remain long.
helpnetsecurity.com
We wished we had more time to find the right words, and it is with deep regret that we have to tell you that our founder Felix “FX” Lindner passed away on 2026-03-01. blog.recurity-labs.com/2026-03-02/F...
Farewell, Felix · The Recurity Lablog
blog.recurity-labs.com
Another NAFO legend has left us...💔 Jason Snitker @jasonsnitker (on Twitter) AKA Parmaster "Par" has passed away!🕯️ He was one of the first hackers, a legend in the hacking scene and a huge supporter of Ukraine and #NAFOfella. >> SIGNAL LOST: PARMASTER >> STATUS: GONE BUT NOT FORGOTTEN
🕯️There will be a online memorial for Par 🕯️ Jason Snitker "Parmaster" Memorial Service Feb 28, 2026 04:00 PM Confirmed Speakers: Par's Aunt Deb Wysopal Mudge John Lee Tom Sloan (former Secret Service) Registration Link: us02web.zoom.us/meeting/regi...
Welcome! You are invited to join a meeting: Jason Snitker "Parmaster" Memorial. After registering, you will receive a confirmation email about joining the meeting.
Debra Kavaler Wysopal will be hosting this online memorial service for Parmaster along with Jason's family from Atlantic City, NJ. Confirmed Speakers: Par's Aunt Deb Mudge John Lee Tom Sloan (former...
us02web.zoom.us
My wife @debdebdeb.bsky.social and I are heartbroken to share the sad news that our old friend @jasonsnitker.bsky.social AKA Parmaster, has passed away.
Jason Snitker Rebel. Legend. Friend. Rest in Peace, ParMaster
My wife @debdebdeb.bsky.social and I are heartbroken to share the sad news that our old friend @jasonsnitker.bsky.social AKA Parmaster, has passed away.
New $10k FULU bug bounty for Ring video doorbells just announced. bounties.fulu.org/bounties/rin...
Ring Video Doorbells
The ProductRing, owned by Amazon, makes Video Doorbells, which are widely used doorstep-monitoring cameras. Ring doorbells released in 2021 or newer are eligibl…
bounties.fulu.org
This is a new one for me. I'm #8 and #31 on this top 100 list. Do you want Chris the the CTO of Veracode or Chris the security pioneer. 😂 www.futuristsspeakers.com/top-100-cybe...
Top 100 Cybersecurity Thought Leaders | #1 Scott Steinberg
Top 100 cybersecurity thought leaders list: Hire famous AI & IT digital transformation consultant and futurist celebrity keynote speaker Scott Steinberg - 3000 brands served!
futuristsspeakers.com