Is the appropriate response?: "OMG...AI is attacking us!!" or "Management now understands that it needs to let me implement the mitigations that we should have been doing all along!!"
Roger A. Grimes
@rogeragrimes.bsky.social
Computer security geek who's life's work mission is to make the Internet a far safer place to compute
Nerd question of the day. Given a piece of paper of the average thickness, how many times would you have to fold it over for it to reach from the Earth to the moon? 42 times! www.scientificamerican.com/article/how-...
Can folding paper take you to the end of the universe?
Folding a piece of paper makes it thicker. How many folds would it take to reach the moon—and beyond?
scientificamerican.com
If you follow AI and how it's hacking companies, this video short is hilarious: www.youtube.com/watch?v=zFbf...
Models "Escaping" Containment & Other Things That Didn't Happen
YouTube video by Shoshana (Disesdi) Cox
youtube.com
Check out my latest article: Hunt for the Huntsman Spider www.linkedin.com/pulse/hunt-h...
Hunt for the Huntsman Spider
I thought I would just share a little homeowner escapade: Tricia, my wife, was going to the bathroom in the master bathroom the other night and came face to face with a medium-sized Huntsman spider. Y...
linkedin.com
This past May, a military exercise using GPS jamming made a medivac aircraft with two pilots and two nurses slam into a mountain. www.wired.com/story/a-civi...
A Civilian Plane Crashed in New Mexico. Was the Military’s Tech to Blame?
Drone warfare is making the skies more dangerous, even for airplanes far from the battlefield.
wired.com
Technical Deep dive on how CrowdStrike Falcon works 0xdbgman.github.io/posts/inside...
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS...
0xdbgman.github.io
Check out my latest CSO piece, which delves into why, amid all the AI razzamatazz, plain old cybersecurity fundamentals are more important than ever. 1/2 www.csoonline.com/article/4204...
AI is making cybersecurity fundamentals more important than ever
As AI increasingly accelerates and individualizes cyberattacks, cracks in security leaders’ foundational defensive strategies are only becoming easier to find.
csoonline.com
AI is making cybersecurity fundamentals more important than ever (I'm quoted) www.csoonline.com/article/4204...
AI is making cybersecurity fundamentals more important than ever
As AI increasingly accelerates and individualizes cyberattacks, cracks in security leaders’ foundational defensive strategies are only becoming easier to find.
csoonline.com
25 Industry titan companies urge the White House and Congress not to restrict open weight AI models. Good call...not that making them illegal would have worked anyway. www.secureworld.io/industry-new...
The AI Industry Just Picked a Side—and the Implications Are Enormous
A coalition of more than 25 American technology companies published a joint letter urging the U.S. government not to restrict open-weight AI models.
secureworld.io
OpenAI is slashing prices by as much as 80% today. China's coming...
You should care and focus on features 100% and what those features give you that you didn't have before, do they help your environment, and not care if those new features were given to you by AI or not.
Developers will die laughing reading this. nesbitt.io/2026/06/26/i...
Incident Report: CVE-2026-LGTM
A series of unfortunate agents.
nesbitt.io
Be careful, hackers are exploiting hotel WiFi DNS to unknowingly redirect O365 users to bogus logon websites. I suspect this is not widespread, but hotel WiFi's are notoriously insecure (often unpatched, default passwords, etc.). Watch those logon URLs. www.bleepingcomputer.com/news/securit...
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.
bleepingcomputer.com
SIKE, RAINBOW, and now, HAWK, are your reminders that no PQC algorithm is provable secure. PQC is a (necessary) intermediate step toward truly secure quantum encryption decrypt.co/374600/claud...
Claude Mythos Cracked Post-Quantum Cryptography That Humans Spent Years Failing to Break - Decrypt
Anthropic’s locked model Claude Mythos found a new attack on a post-quantum signature scheme headed for U.S. federal standardization.
decrypt.co
Interesting case. My limited legal understanding is that your Constitutional rights do not apply at the border and if you don't allow border agents to inspect your stuff, they can ban you from coming into the country for a set number of years.
Using Claude or any AI agent on the same computer where you do banking is just asking for trouble. Until the security gets figured out, you must isolate your AI agents or accept the risk that your could be compromised at will.
26-yr-old man sentenced to 6 rs in prison for hacking/social engineering Snapchat accounts of young women and stealing nudes. On a related note, track coach was sentenced to 5 years for hiring the hacker to hack into female athlete accounts. www.bleepingcomputer.com/news/securit...
Man gets six years for hacking 750 women's Snapchat accounts
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos.
bleepingcomputer.com
OpenAI used stolen credentials and a 0-day to break into Hugging Face. Care to explain the stolen credentials more?
Hacker wipes Romania's entire land registry database risky.biz/risky-bullet... The hack[er] has brought Romania's entire real-estate market to a standstill. Notaries can't record new transactions while citizens can't obtain proof of ownership or detailed land records.
Risky Bulletin: Hacker wipes Romania's entire land registry database - Risky Business Media
A hacker has breached Romania's cadastre agency and wiped the country's entire land registry database following a failed extortion attempt [Read More]
risky.biz
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. www.bleepingcomputer.com/news/securit...
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.
bleepingcomputer.com
Cool website showing AI (and AI-related) vendor's expenses versus revenues. Basically, only the chip manufacturers are close to being profitable: isaiprofitable.com
Is AI Profitable Yet?
isaiprofitable.com
Oh, no, we must remove all constraints on AI and AI data centers ASAP!! The sky is falling!! www.msn.com/en-us/news/t...
Interesting. X code to be open source thenewstack.io/x-open-sourc...
Elon Musk: "We will make the entire codebase of X open source, with no exceptions."
Elon Musk says X will open-source its entire codebase after a security review, with third-party reviewers verifying the live production code matches.
thenewstack.io
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials thehackernews.com/2026/07/oaut...
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
OAuth client ID spoofing lets attackers test Entra accounts and stolen passwords without successful sign-ins, leaving application names blank in logs.
thehackernews.com
The Cognitive Security Institute is the SANS of human behavior! Dr. Matthew Canham and everyone involved is great! They are having a conference in Las Vegas, Aug 6-7. Bruce Schneier, Clifford Stoll, and others $100 off with code FriendOfCSI_2026. www.cognitivesecurityinstitute.org/cognitive-se...
Microsoft releases record 570 patches. krebsonsecurity.com/2026/07/micr... Looks like someone used AI...
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant ...
krebsonsecurity.com