Kevin Noble

@kevinnoble.bsky.social

Cyber Security Consultant, enjoy all things infosec.

As SBOMs slowly progress at the federal level and in enterprises, the rise of AI coding assistants is fueling optimistic—and, some experts argue, “kind of insane”—claims about a future with vulnerability-free software. Check out my latest CyberScoop piece. 1/2 cyberscoop.com/sbom-adoptio...

The slow rise of SBOMs meets the rapid advance of AI

Despite progress from CISA and global regulators, SBOM adoption in the private sector remains slow as experts debate if AI-driven coding will improve or undermine software security and transparency.

cyberscoop.com

How Syrian army officers in final days of war with opposition were duped into 1) disclosing info to fake website about their rank/location and corps/division/brigade and 2) installing phone app that was actually spyware that recorded keystrokes, stole files/photos/call log and spied thru camera/mic

How a Spyware App Compromised Assad’s Army

An investigation reveals how a cyberattack exploited soldiers' vulnerabilities and may have changed the course of the Syrian conflict

newlinesmag.com

Failures in cybersecurity practices at a software company that helps federal agencies manage investigations and FOIA requests allowed two employees who had previously been convicted of hacking to delete government databases

Hack of Contractor Was at Root of Massive Federal Data Breach

Failures in cybersecurity practices at a software company that helps federal agencies manage investigations and FOIA requests allowed two convicted hackers to delete databases, according to internal d...

bloomberg.com

Thanks again for having me on the Three Buddy (& a Buddy) Problem podcast @ryanaraine.bsky.social @jags.bsky.social & @craiu.bsky.social ! It was great chatting with you about Chinese threat intel, CISA cuts, & spyware that dare not speak its name. Turning this into a musical episode was a fun bonus

Ryan Naraine@ryanaraine.bsky.social · last yr.

This week's pod is available on YouTube. Subscribe and show love 💕 youtu.be/DKpyYj1PcH0?...

NEW POD ALERT: Revisiting the US/Russia cyber stand down order and the diplomatic optics. Plus, a dissection of ‘The Lamberts’ and connections to US intelligence agencies, attribution around ‘Operation Triangulation’, VMware 0days and i-Soon indictments securityconversations.com/episode/revi...

Revisiting the Lamberts, i-Soon indictments, VMware zero-days - Security Conversations

Three Buddy Problem – Episode 37: This week, we revisit the public reporting on a US/Russia cyber stand down order, CISA declaring no change to […]

securityconversations.com