cje

founder @Bugcrowd && co-founder @disclose_io || dad x 2, hacker, entrepreneur, executive, advisor || عصا موسى || #w00w00

cje boosted:
2024-11-24

We've just launched the public edition of the CISO Lens 2024 Benchmark, drawing on data from 96 member organisations in Australia and New Zealand. www.cisolens.com/benchmark

Image is a screenshot from the benchmark and shows the table of contents
cje boosted:
Dave Aiteldave_aitel
2024-11-15

therecord.media/cyberattack-ca I feel like this entire conflict is under analyzed by the academic community. It would be cool if jags and costin did a huge rundown on the next podcast .

cje boosted:
2024-11-05

A registered Russian agent paid an X user $100 to post the bogus video about Haitians voting repeatedly in Georgia, CNN reports. I wonder if bigger names charge more. cnn.com/2024/11/04/politics/fa

cje boosted:
2024-10-28

Now live: the discussion I had with Chris Hughes and @caseyjohnellis on systemic issues in #cybersecurity:

resilientcyber.io/p/resilient-

In which I pulled a “Legally Blonde” on Casey; see if you can catch it 😉

👏👏👏

Doubling Down on Trusted Partnerships: Our Commitment to Researchers | @ONCD | The @White House whitehouse.gov/oncd/briefing-r

TLP:🌈

cje boosted:
Meredith WhittakerMer__edith@mastodon.world
2024-10-06

Case in point: there's no way to build a backdoor that only the "good guys" can use.

When the entire technical community says that the EU's ChatControl legislation + similar pose serious cybersecurity threats, we're not exaggerating for effect.

wsj.com/tech/cybersecurity/u-s

HPE patches three critical flaws in Aruba software • The Register theregister.com/2024/09/26/hpe

How to build a secure recon network using Tailscale | @Bugcrowd m.cje.io/4e8xRR8

Unveiling TE.0 HTTP Request Smuggling: Discovering a Critical Vulnerability in Thousands of Google Cloud Websites by @sw33tlie @bsysop @_medusa_1_ | @Bugcrowd m.cje.io/4d9TWxA

STOP. SHOOTING. THE. MESSENGER.

106 cybersecurity pros are urging Columbus, Ohio City Attorney Zach Klein to drop the lawsuit against Connor Goodwolf. Our argument is that prosecuting good faith security research diverts attention from the real threat—the ransomware group—and harms public safety efforts by reinforcing a chilling effect. The letter calls for transparency and refocusing on protecting citizens. #Cybersecurity #GoodFaithResearch #PublicSafety

Full letter: disclose.io/open_letter_columb

cje boosted:
Foone🏳️‍⚧️foone@digipres.club
2024-08-20

HEY FUN FACT: this was used as part of an Alexa/google home type thing! this is the "cloud" half, as in the part sitting in a warehouse somewhere.
It turns out every time the customer asked for something from the smart assistant, the WAV file was sent to the cloud box

where it is still stored. and I now have eleven thousand wave files

cje boosted:
2024-06-22

Yo, we did a @Deciphersec hacker movie pod episode on HEAT! W/ @caseyjohnellis and @MegGardiner, no less!

The Kelso character in HEAT is a fascinating hacker prototype, who happens to have a background at DARPA.

Full Deciphering HEAT podcast episode here, with
@MegGardiner1
and
@caseyjohnellis
: youtu.be/b2cfEXeWSn0

“The ecosystem for assessing and auditing AI models is still in its formative stages, but is growing rapidly,” said Casey Ellis, founder and chief strategy officer at Bugcrowd. “We're seeing a mix of traditional cybersecurity firms expanding their services to include AI security, as well as new startups specifically focused on AI risk management.”

duo.com/decipher/the-emerging-

“An attacker would be able to take control of the ICS/SCADA endpoint, effectively gaining physical access" #icssecurity #otsecurity #scada m.cje.io/3RqMBBG

Builders and Breakers: Partnering for Secure Elections #rsac2024 #protect2024 #electionsecurity #ittakesacrowd m.cje.io/4bWyEUj

Our panel from #rsac2024 is live... Enjoy!

"Bugs on a Plane: Implementing a Bug Bounty in an Airline IT/OT Environment"

buff.ly/3xdqfwF

The material impact [of #operationendgame] to attackers is that they’ve just had it laid out to them, very clearly, that there’s a capable, resourced, and persistent threat in play on the defender side.

cpomagazine.com/cyber-security

#dropper #malware #disruptops #takedown

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst