Alex Pinto
Alex Pinto boosted:
Kelly Shortridgeshortridge@hachyderm.io
2025-04-24

as is tradition, I just published my commentary on this year's Verizon Data Breach Investigations Report (aka #DBIR): kellyshortridge.com/blog/posts

In the post, I include the following sections covering what I felt were the most notable insights and facets in the report:

🌍 So, what?

πŸ’ƒ Espionage: fast fashion or couture?

πŸ‘» APTs go BWAA-haha >:3

πŸ’Έ How do the money crimes generate money?

πŸ€– Attackers are still not really using GenAI

πŸ‘©β€πŸ³ If you can’t make your own 0day, store-bought creds are fine

πŸ”“ #Security was the real supply chain threat all along

πŸ„ Things Rot Apart

πŸ•΅β€ Scooby Doo's Spooky Kooky Corporate IT Caper

🌈 At least some things are improving somewhere

Go forth and enjoy my commentary, and then make sure to find me at #RSAC to tell me what you loved or hated Tuesday 14:30 at the @fastlydevs booth (where you'll also get a free copy of my book ✨)

thanks @alexcpsec for the early copy <3

Alex Pintoalexcpsec
2025-04-23

The 2025 is out! Go get it.

Verizon.com/dbir

Alex Pintoalexcpsec
2024-06-25
Alex Pintoalexcpsec
2024-05-02

@realn2s @shortridge yes, but remember all of those folks were breached and has costs with IR, recovery. The threat actors are getting less of it, and that is good news, but the breached orgs themselves still β€œsuffer”.

Alex Pintoalexcpsec
2024-05-01

@shortridge @realn2s what Kelly said. Those were after compromise and ransom was requested by threat actor (and subsequently notified to the FBI IC3).

Alex Pinto boosted:
Kelly Shortridgeshortridge@hachyderm.io
2024-05-01

The 2024 Verizon Data Breach Investigations Report (#DBIR) is out this morning, and I make sense of it in my new post: kellyshortridge.com/blog/posts

I focused on what felt like the most notable points, from #ransomware to MOVEit to web app pwnage to #GenAI and more.

I have insights, quibbles, and hot takes as always β€” but the fact remains it’s our best source of empirical data on cyberattack impacts. If you’re a #cybersecurity vendor, please consider contributing data to it.

Alex Pinto boosted:
The Shadowserver Foundationshadowserver@infosec.exchange
2024-05-01

We are happy to contribute once more with our malware & honeypot statistical data to the @Verizon 2024 Data Breach Investigations Report! (#VZDBIR)

Download at verizon.com/business/resources

Alex Pintoalexcpsec
2024-05-01

@nmott I’m taken, but glad you are enjoying it!

Alex Pinto boosted:
2024-05-01

Verizon's Data Breach Investigations Report covers a lot of sectors of society, including #education. This year's #DBIR reports that 98% of breaches and #cybercrime affecting schools was financially motivated.

What was that famous thing a bank robber once said about going where the money is? Is someone going to tell them?

verizon.com/business/resources

Alex Pintoalexcpsec
2023-10-24

Just a quick reminder:

Next week we close the data collection window for the 2024 .

If your org has been sitting on YET ANOTHER 3rd party breach affecting your company, please make it public before Oct 31st and help a DBIR author out. 🫠

Alex Pintoalexcpsec
2017-04-03

@hrbrmstr it is indeed. but for how long?

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst