Rob Wright

@robwright22.bsky.social

Security news director at Informa TechTarget's Dark Reading, patron saint of TT's "Bagel Wednesday." Formerly of SearchSecurity, Tom's Hardware, CRN, and a whole lot more. Signal: rwrightTT.20

If you've been wondering about the NIST's reduction in CVE enrichment and the effects the shift has had since it was implemented two months ago, the folks at Volerion analyzed more than 13,000 CVEs published to the NVD and found some concerning trends. www.darkreading.com/vulnerabilit...

NIST Enrichment Reductions Impact CVE Coverage, Accuracy

NIST scaled back on the number of CVEs it selects for in-depth analysis, but the move has produced mixed results.

darkreading.com

Seeing a lot of reports that TeamPCP is behind the "Megalodon" supply chain attack against GitHub. Not sure where this is coming from, but both SafeDep (which discovered the attack) and OX Security (which verified the findings) say there's no link at this point: www.darkreading.com/application-...

'Megalodon' Malware Infects Thousands of GitHub Repos

In just six hours, the campaign quietly pushed malware to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more.

darkreading.com

The Trump administration skipped last week's major RSAC cybersecurity conference. On the ground in San Francisco and beyond, people were baffled and frustrated. "Engagement with industry is vital," one former official said. My story: www.cybersecuritydive.com/news/rsac-co...

‘Missed opportunity’: US government’s absence from RSAC Conference leaves stark void

The Trump administration’s decision to not attend the world’s biggest cybersecurity conference sent the wrong message to partners, experts said.

cybersecuritydive.com

In 2013 Aaron Swartz committed suicide for facing 35 years in prison for mass downloading scientific articles. 13 years later, Meta is almost getting away with an infraction orders of magnitude larger. The law didn't change. torrentfreak.com/uploading-pi...

Uploading Pirated Books via BitTorrent Qualifies as Fair Use, Meta Argues * TorrentFreak

In an ongoing lawsuit, Meta now argues that uploading pirated books to strangers via BitTorrent qualifies as fair use.

torrentfreak.com

Good news: LE agencies and private sector partners took down Tycoon 2FA, a popular phishing-as-a-service (PhaaS) platform that can bypass MFA protections. Bad news: The takedown didn't solve the MFA issue, and other PhaaS platforms use the same bypass technique. www.darkreading.com/threat-intel...

Tycoon 2FA Goes Boom as Europol, Vendors Bust Phishing Platform

The phishing-as-a-service platform was popular among cyber threat actors because of its ability to bypass multi-factor authentication defenses.

darkreading.com

So, obviously this isn’t true. But if the CEO actually believes this nonsense, it implies he thinks maybe he’s enslaving a sentient being that has the capacity to feel emotional distress. And he hasn’t immediately halted operations to suss out how to resolve that?

Kat Tenbarge@kattenbarge.bsky.social · 5mo ago

Literally as I’m arguing with someone about whether AI companies are misleading people into believing their technology possesses God-like super-intelligence I see this monstrosity

A post on X from the betting platform Polymarket that says “BREAKING: Anthropic CEO says Claude may or may not have gained consciousness, as the model has begun showing symptoms of anxiety.”

New w @janetimm.bsky.social: In the feds' first call with states since gutting CISA's election programs, they promised no ICE at polling places, but weirdly refused to reaffirm states run elections, per people on the call.

DHS official tells state election chiefs there won't be ICE agents at polling places

Members of the Trump administration held a call with state election officials around the country ahead of this year's midterm elections.

nbcnews.com