@MalwareJakei
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States Android App
Account-level information from X, not a live location or the device used for a specific post.
Breaker of software | VP R&D @hunterstrategy | CTI/DFIR | @ians_security faculty | Bookings: jake at malwarejake dot com | GSE #150 | He/him
Odenton, MD
Joined September 2009
- Tweets102K
- Following1.8K
- Followers151K
- Likes44.6K
Pinned Tweet
Let's not mince words:
* If you don't support trans people, you're a bad human
* If you have to add caveats to your support (e.g. "as long as my kids don't see"), you're one of the worst kinds of human
* Trans deserve your *unconditional* support for their humanity
Jake Williams retweeted
Cisco Secure Firewall Management Center had an unauthenticated bug allowing root access. It's already being used to drop JSP shells, run Cyclops Blink, and detonate Qilin ransomware. Feds had until Sept 12 to patch. If you're still checking this off your list, you're not early.
#CyberSecurity #InfoSec #Cisco #ThreatIntel
In today's episode, I sit down with Ariful Huq from @exaforceAI and Patrick McKinney from @turingcom and talk about the AI-powered SOC. Patrick has been an Exaforce customer for years and brings real-world experience to the conversation.
We talk specifically about why having an underlying data model matters and why API alone won't cut it for many advanced detections. Jess will be back tomorrow for more security banter.
youtu.be/8YwAdBow9eM
In this episode, me and Jess talk about an upcoming critical change to domains for M365 and Teams that are ironically going to disproportionately impact those with the best security the most. We conclude this is busy work that MSFT is causing. 1/3
Teams and Copilot (sadly somehow now M365) moving domains: computerworld.com/article/42…
We've re-recorded today's episode of Breach Please. Me and Jess talk about the newly extra relevant EU Cyber Resiliency Act (CRA) vulnerability reporting requirements. Even if you aren't an EU company, just like with GDPR, you may be covered. 1/2
The audio was garbage through a lot of it the original episode. I recorded on the Mac (an obvious mistake). Given the importance of this, we didn't want to sit on it. This is honestly a better episode. 2/2
Episode link: youtu.be/0EFD2kDJUlo
Are you at @BlueTeamCon and working on something innovative you want the world to know about?
I'll be around today and tomorrow with my DJI and mics and would love to grab a few minutes with you for a future episode of Breach Please.
Sure does feel like OpenAI, a company that for obvious legal reasons needs to know about data provenance, would KNOW whether "de-identified data derived from their usage" was accessed.
OpenAI needs a much better explanation here.
OpenAI’s official statement regarding their interactions with Tristan and Levent:
“We recognize the priority of their work on forced Euler”
“no specific user data was accessed in order to solve this problem”
“we cannot rule out that de-identified data derived from their usage of our products helped improve our models”
We are nowhere near AGI.
I challenge ANYONE claiming such to connect their bank account and credit cards to whatever model they claim to have AGI and let me make some simple requests. With true AGI, you won't need human in the loop approval and it will act within your desires.
Jake Williams retweeted
On the topic of whether anyone in infosec could predict that an agent would break out of a sandbox and cause damage to external systems pre-OpenAI / Hugging Face:
In today's Breach Please, me and Jess revisit the idea of detecting threat actors hiding in network devices to evade detection. This was inspired by a report from @sygnia_labs.
Real talk: how do YOU validate your network devices are free of malware?