Jennifer Wood

@notnextjen.bsky.social

Space geek, roaming gnome, comms @ runZero. Ex-USG: OMB, NASA, EPA, U.S. Senate. Formerly Luta Security, Kaspersky, Avast, BlackBerry, Microsoft/WE Comms. https://www.linkedin.com/in/jenniferjwood/

New on @axios.com: As part of meetings with tech/cyber cos. + tech trade groups last week, ONCD floated an AI security framework that was already in the works before Mythos. On the table: DoD red-teaming of AI deployments at the federa/state/local government levels. www.axios.com/2026/05/04/t...

Trump administration considering safety review for new AI models

In a post-Mythos world, the White House is re-evaluating its hard line against the AI security measures it once shrugged off.

axios.com

Recently back from VulnCon 2026, runZero's @todb.hugesuccess.org shares his insights on AI's dual role in vuln discovery & defense, CVE ecosystem updates, and a cautiously optimistic outlook for the future of vuln disclosure and remediation. Read his blog today! 👇️ www.runzero.com/blog/vulncon...

Dispatch from VulnCon: AI, CVEs, & cooperation

todb shares his key VulnCon 2026 takeaways, covers the rise of AI in vuln research, the role of CISA’s Vulnrichment, and the future of the CVE program.

runzero.com

Need some downtime today during #BSidesSF 2026? Escape to the runZero sponsored Bar & Chill Out Space (inside) or Lounge (outside) from 9 AM-5:30 PM PT. Stop by, say hello, and snag some swag! 👉 Remember, two complimentary drink tickets were provided at registration!

Bild

One way to read the AI/Pentagon news from last night (I covered it but didn't skeet) is that the Department of Defense wants AI to automate weapons and/or spy on Americans and that Anthropic would have the best AI to do that, but OpenAI is at least the second-best so they'll just use that instead.

OpenAI strikes deal with Pentagon after Trump orders government to stop using Anthropic

On X, Defense Secretary Pete Hegseth said he had moved to label Anthropic as a "supply chain risk" and cancel Defense business with the company.

nbcnews.com

NEW: U.S. prosecutors say the hacking tools that Peter "Doogie" Williams stole from defense contractor L3Harris Trenchant could have been used against "millions of computers and devices" worldwide. Williams said he didn't know the tools could end up in the hands of Russia or other governments.

DOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunch

The former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am...

techcrunch.com

Prosecutors have confirmed for the first time that Peter Williams, who ran L3Harris' Trenchant unit (which makes hacking tools for the U.S. govermment and its allies), sold the company's exploits to a Russian broker that were capable of accessing "millions of computers and devices" around the world.

DOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunch

The former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am...

techcrunch.com

Joseph Menn has been writing about cybersecurity since well before most journalists even understood it as a beat. Big loss for the Post and its readers, but also for the industry and the wider public, who will be less informed - and less safe - as a result.

Joseph Menn@joemenn.bsky.social · 7mo ago

Most of the Washington Post’s tech reporters were laid off today, including me. I have loved my time at the paper, which is where I wanted to work from age 15. I take some consolation in not being among the survivors who will have to work harder with less for fewer readers. On to better things.

The Federal Aviation Administration ignored warnings about a dangerous level of air traffic at Reagan National Airport before the midair collision between a commercial jet and U.S. Army helicopter that took 67 lives, federal investigators said.

FAA ignored warnings from controllers before DCA crash, federal investigators say

Families hope the nearly year-long probe by the National Transportation Safety Board will promote aviation safety changes.

washingtonpost.com

NEW: Microsoft handed the FBI the recovery keys to decrypt the hard drives of three laptops encrypted with BitLocker. BitLocker is enabled by default in modern Windows laptops, but Microsoft also prompts users to upload the recovery keys to the company's cloud, which opens up this possibility.

Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects' laptops: reports | TechCrunch

The FBI served Microsoft a warrant requesting encryption recovery keys to decrypt the hard drives of people involved in an alleged fraud case in Guam.

techcrunch.com

New, by me: Under Armour says it’s aware of data breach claims after 72M customer records were posted online. A spox. told me a "small percentage" of customers had sensitive information compromised but wouldn't say what it considers "sensitive," nor provide an accurate figure of affected customers.

Under Armour says it's 'aware' of data breach claims after 72M customer records were posted online | TechCrunch

TechCrunch obtained a sample of the stolen data, which contained names, email addresses, dates of birth, and the user's approximate geographic location. Under Armour confirmed some sensitive informati...

techcrunch.com

GPS attacks are increasing, relatively cheap to implement, spreading geographically, and present a significant threat to people's safety and the economy. If your org uses GPS data, it's time to update your threat models. Learn more: shostack.org/26-01

Threat Advisory: GPS Attacks [SA-26-01]

The dramatic increase in credible reports of GPS attacks, combined with geographic spread and the decreasing cost of hardware for the attack, indicate a change in the threat landscape. If your company...

shostack.org

New: French phone giant Bouygues confirmed a data breach affects the personal information of 6.4 million customers. Bouygues disclosed the breach on a dedicated web page; however, the page is currently deliberately excluded from search engines using "noindex" code, making it more difficult to find.

Data breach at French telecom giant Bouygues affects millions of customers | TechCrunch

This is the latest cyberattack to hit a French cellular carrier in recent weeks, following an attack on Orange Telecom in July.

techcrunch.com