🚀 Big news: Accenture investing $4B— intends to acquire a majority stake in Dragos, Inc., and all of runZero and NetRise, to build an industry-transforming cybersecurity platform for OT/IT environments. 👏 Details at: www.runzero.com/newsroom/acc...
Jennifer Wood
@notnextjen.bsky.social
Space geek, roaming gnome, comms @ runZero. Ex-USG: OMB, NASA, EPA, U.S. Senate. Formerly Luta Security, Kaspersky, Avast, BlackBerry, Microsoft/WE Comms. https://www.linkedin.com/in/jenniferjwood/
🎉 New GigaOm Radar for OT Security positions runZero as a Challenger & Fast Mover! 🚩 Webinar: Join GigaOm's Chris Ray & runZero CEO HD Moore on May 28 @ 12PM ET as they discuss hardening converged network defenses & the #OT Radar findings. Webinar reg & report: www.runzero.com/gigaom-radar...
A million baby monitors and security cameras were left exposed. You might have one of these in your house and not even know — because this company's name isn't on the packaging. www.theverge.com/tech/926487/...
A million baby monitors and security cameras were easily viewable by hackers
They should be fixed now. Hopefully.
theverge.com
New on @axios.com: As part of meetings with tech/cyber cos. + tech trade groups last week, ONCD floated an AI security framework that was already in the works before Mythos. On the table: DoD red-teaming of AI deployments at the federa/state/local government levels. www.axios.com/2026/05/04/t...
Trump administration considering safety review for new AI models
In a post-Mythos world, the White House is re-evaluating its hard line against the AI security measures it once shrugged off.
axios.com
Check out our latest release, 4.9! So many new capabilities for IT/OT converged environments. 👏 Plus, the visuals are not only informative, but also really cool (make sure to try out the 3D view). 🌎
🚨 New runZero 4.9: We got you, defenders! 📈 Interactive attack path mapping 👁️ Multi-homed detection 🗺️ 2D/3D topology maps 🧠 Deep OT intel + field-level discovery ✅ Protocol exposures 🔥 Risk prioritization 💻 UI/UX enhancements 👉️ Release details at: www.runzero.com/blog/runzero... #OTsecurity
🔈 New podcast alert! CEO HD Moore discusses runZero's upcoming 4.9 release on Risky Business with Casey Ellis. Hear how we're tackling converged IT/OT network challenges! 🎧 Listen to the full interview to learn more: www.runzero.com/resources/ri... #OTsecurity
If you missed last week’s runZero Hour with Caroline Wong, author of The AI Cybersecurity Handbook, here’s a peek at what you missed. Watch the full episode now for more AI insights, CVE program updates, AI trivia, and notable vulns from the month. Full episode: www.runzero.com/resources/ru...
Recently back from VulnCon 2026, runZero's @todb.hugesuccess.org shares his insights on AI's dual role in vuln discovery & defense, CVE ecosystem updates, and a cautiously optimistic outlook for the future of vuln disclosure and remediation. Read his blog today! 👇️ www.runzero.com/blog/vulncon...
Dispatch from VulnCon: AI, CVEs, & cooperation
todb shares his key VulnCon 2026 takeaways, covers the rise of AI in vuln research, the role of CISA’s Vulnrichment, and the future of the CVE program.
runzero.com
Are you attending the DoW MPE Summit in Ft. Lauderdale this week? Be sure to connect with our team onsite to learn how runZero provides a single source of truth for exposure management across the total attack surface—without the friction of agents. 👉️ More details: www.ncsi.com/event/mpe/ag...
Need some downtime today during #BSidesSF 2026? Escape to the runZero sponsored Bar & Chill Out Space (inside) or Lounge (outside) from 9 AM-5:30 PM PT. Stop by, say hello, and snag some swag! 👉 Remember, two complimentary drink tickets were provided at registration!
Tomorrow on the runZero Hour: Deep dive into OT retroencabulation Join @todb.hugesuccess.org, Rob King, & Ulises Fuentes Venado from GuidePoint Security for an in-depth discussion on the evolving security challenges facing OT. 📅 March 18 | 1 PM ET / 10 AM PT www.runzero.com/research/run...
One way to read the AI/Pentagon news from last night (I covered it but didn't skeet) is that the Department of Defense wants AI to automate weapons and/or spy on Americans and that Anthropic would have the best AI to do that, but OpenAI is at least the second-best so they'll just use that instead.
OpenAI strikes deal with Pentagon after Trump orders government to stop using Anthropic
On X, Defense Secretary Pete Hegseth said he had moved to label Anthropic as a "supply chain risk" and cancel Defense business with the company.
nbcnews.com
If everything is a priority, nothing is. @todb.hugesuccess.org helped build CISA KEV and his new runZero research finally makes it actionable. He sat down with Casey Ellis on @riskybusiness to talk about what KEV actually is and how to use it right. 🎧 www.runzero.com/resources/ri...
NEW: U.S. prosecutors say the hacking tools that Peter "Doogie" Williams stole from defense contractor L3Harris Trenchant could have been used against "millions of computers and devices" worldwide. Williams said he didn't know the tools could end up in the hands of Russia or other governments.
DOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunch
The former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am...
techcrunch.com
Prosecutors have confirmed for the first time that Peter Williams, who ran L3Harris' Trenchant unit (which makes hacking tools for the U.S. govermment and its allies), sold the company's exploits to a Russian broker that were capable of accessing "millions of computers and devices" around the world.
DOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunch
The former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am...
techcrunch.com
🚨 New report + tool: CISA KEV analysis by former Section Chief @todb.hugesuccess.org + KEV Collider to help prioritize real exploits over noise. 📄 Report: www.runzero.com/resources/ke... 🧪 Tool: www.runzero.com/kev-collider/ ✍️ Blog: www.runzero.com/blog/making-... Ready to make KEV actionable?
Joseph Menn has been writing about cybersecurity since well before most journalists even understood it as a beat. Big loss for the Post and its readers, but also for the industry and the wider public, who will be less informed - and less safe - as a result.
Most of the Washington Post’s tech reporters were laid off today, including me. I have loved my time at the paper, which is where I wanted to work from age 15. I take some consolation in not being among the survivors who will have to work harder with less for fewer readers. On to better things.
Why are pubs laying off talented journalists? We need reporters who understand security to continue covering it. It is disheartening to see this happening over and over again.
Most of the Washington Post’s tech reporters were laid off today, including me. I have loved my time at the paper, which is where I wanted to work from age 15. I take some consolation in not being among the survivors who will have to work harder with less for fewer readers. On to better things.
Good stuff here, folks! When you have a few minutes, read the article and the research (links below). #LLMsecurity Story: www.reuters.com/technology/o... Research: www.sentinelone.com/labs/silent-...
Open-source AI models vulnerable to criminal misuse, researchers warn
Hackers and other criminals can easily commandeer computers operating open-source large language models outside the guardrails and constraints of the major artificial-intelligence platforms, creating ...
reuters.com
The Federal Aviation Administration ignored warnings about a dangerous level of air traffic at Reagan National Airport before the midair collision between a commercial jet and U.S. Army helicopter that took 67 lives, federal investigators said.
FAA ignored warnings from controllers before DCA crash, federal investigators say
Families hope the nearly year-long probe by the National Transportation Safety Board will promote aviation safety changes.
washingtonpost.com
ShinyHunters has claimed responsibility for an Okta voice-phishing campaign during which the extortionist crew allegedly gained access to Crunchbase and Betterment.
ShinyHunters claims Okta customer breaches, leaks data
: 'A lot more' victims to come, we're told
theregister.com
NEW: Microsoft handed the FBI the recovery keys to decrypt the hard drives of three laptops encrypted with BitLocker. BitLocker is enabled by default in modern Windows laptops, but Microsoft also prompts users to upload the recovery keys to the company's cloud, which opens up this possibility.
Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects' laptops: reports | TechCrunch
The FBI served Microsoft a warrant requesting encryption recovery keys to decrypt the hard drives of people involved in an alleged fraud case in Guam.
techcrunch.com
New, by me: Under Armour says it’s aware of data breach claims after 72M customer records were posted online. A spox. told me a "small percentage" of customers had sensitive information compromised but wouldn't say what it considers "sensitive," nor provide an accurate figure of affected customers.
Under Armour says it's 'aware' of data breach claims after 72M customer records were posted online | TechCrunch
TechCrunch obtained a sample of the stolen data, which contained names, email addresses, dates of birth, and the user's approximate geographic location. Under Armour confirmed some sensitive informati...
techcrunch.com
GPS attacks are increasing, relatively cheap to implement, spreading geographically, and present a significant threat to people's safety and the economy. If your org uses GPS data, it's time to update your threat models. Learn more: shostack.org/26-01
Threat Advisory: GPS Attacks [SA-26-01]
The dramatic increase in credible reports of GPS attacks, combined with geographic spread and the decreasing cost of hardware for the attack, indicate a change in the threat landscape. If your company...
shostack.org
Today is the day…#LABScon2025 is live from Phoenix, AZ. Get ready for two days of unique research and excellent speakers.
New: French phone giant Bouygues confirmed a data breach affects the personal information of 6.4 million customers. Bouygues disclosed the breach on a dedicated web page; however, the page is currently deliberately excluded from search engines using "noindex" code, making it more difficult to find.
Data breach at French telecom giant Bouygues affects millions of customers | TechCrunch
This is the latest cyberattack to hit a French cellular carrier in recent weeks, following an attack on Orange Telecom in July.
techcrunch.com
Enjoying the #threebuddyproblem podcast live from BH /Vegas!
If all goes to plan, I’ll be in Vegas for #BlackHat this week. DM me if you would like to meet. See y’all soon and safe travels to all!
Update: Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. Customers should apply these updates immediately. Full guidance and detection details: msft.it/6010sDzSE.
Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers - www.securityweek.com/microsoft-pa...
Microsoft Patches 'ToolShell' Zero-Days Exploited to Hack SharePoint Servers
Microsoft has started releasing updates to fix the exploited SharePoint zero-days tracked as CVE-2025-53770 and CVE-2025-53771.
securityweek.com