@strandjs

I will light the way by the bridges I burn. Retired Senior SANS Instructor IANS Faculty Black Hills Information Security Active Countermeasures

Spearfish, SD
Joined August 2008
Ready to take your pentesting skills further? Join Red Siege CEO @TimMedin for Penetration Testing: Beyond the Basics at @WWHackinFest Deadwood, Oct. 6–7. Go beyond the fundamentals and add new techniques to your toolkit. There's still time to register! 🔗👇
1
2
5
607
Cyber hot take, delivered somewhere on a mountain bike trail. No packets were harmed. Same can't be said for my quads...
8
5
3
45
5,738
Hunting CVE-2026-85706 in GitLab logs? A 400 saying "branch is required" is not a failed attempt. It means the file was read. We proved it by planting files with known contents and watching the error change. activesoc.blackhillsinfosec.…
1
6
2
16
3,066
oh wait... its @eric_capuano! how cool.. great read on the GitLab vuln.
Hunting CVE-2026-85706 in GitLab logs? A 400 saying "branch is required" is not a failed attempt. It means the file was read. We proved it by planting files with known contents and watching the error change. activesoc.blackhillsinfosec.…
1
10
1,221
Got a hot take on cyber today, brought to you by a guy currently doing zero cyber...
5
4
55
3,128
Quick thoughts on the Anthropic report that bad people are using AI. I guess I am shocked that people are shocked.
1
2
1
18
1,689
Hacking back is now (partially..) legal for U.S. companies. Our founder John Strand breaks down what Trump's new memo actually allows and the big questions still unresolved. cybrsecmedia.com/trumps-hack…
2
1
7
1,515
NSA, FBI, CISA, DOE, and EPA just went public with AI-assisted attacks on Siemens PLCs hitting critical infrastructure. When the NSA says something like this, people listen, and I weighed in on what it means in this article. scworld.com/news/unspecified…
5
45
6
181
21,219
Live from Black Hat, I was invited to sit down with G Mark Hardy on the CISO Tradecraft podcast. Thanks for having me on. We had wide-ranging conversation about the future of AI, cybersecurity careers, penetration testing, automation, and the skills that will actually matter next. Go check it out! youtube.com/watch?v=8KJcXoHf…
1
3
2,180
The Goons at this years Defcon are amazing. Helpful and very kind. Hats off to the whole group. Backdoors and breaches at Defcon Groups is still going very strong.
1
2
24
1,851
Backdoors and Breaches tournament in effect! Come play a round with me in the defcon groups room.
1
25
2,060
AI is already here in cybersecurity. Join the FREE Infosec: Age of AI Summit for real lessons, risks, and honest talks. Less hype, more security. Register now! learning.antisyphontraining.…
1
1
542
And that's not all! Join our FREE 6-hour Infosec: Age of AI Summit on August 14th for real-world AI cybersecurity insights from experts. Register free and boost your skills! learning.antisyphontraining.…
1
2
510
Hey folks, John Strand (@strandjs) returns to Black Hills Information Security 's weekly webcast! There has been a lot of discussion lately about AI and what it means for penetration testing. Depending on who you talk to, AI is either going to replace every pentester on the planet or completely revolutionize the way we work. Join John for a candid discussion about what Black Hills Information Security is actually seeing in the field. Where AI is helping, where it’s hurting, what we’re doing at BHIS, & why he believes there is still plenty of opportunity ahead for security professionals willing to adapt. Thu, Jul 16, 2026 1:00 PM EDT Register: events.zoom.us/ev/Al_Jad5ZPg… P.S. On August 14, 2026, @Antisy_Training and BHIS are hosting the free virtual Infosec: Age of AI Summit! Explore how AI is impacting the industry — antisyphontraining.com/event…
2
4
1,466
"As new vulnerabilities emerge, the race to identify and mitigate them begins. But how do we, the guardians of the digital realm, rapidly pinpoint these threats as they become public?" Read more: blackhillsinfosec.com/how-to… How to Identify and Exploit New Vulnerabilities by: Matthew Eidelberg Published (in blog format): 05/13/2026
3
15
2,058
Apparently AI has already replaced every pentester, hacked every government, writes flawless malware, cured cancer, and probably folded your laundry before breakfast. Let's separate the hype from reality. We'll dig into the AI arms race, the NSA rumors, what's actually changing in cybersecurity, and where AI helps... and where it confidently makes a complete mess. If you’re looking for a practical discussion with a healthy dose of skepticism, some historical context, and a few stories about what we’ve learned the hard way, join us. events.zoom.us/ev/As7GlHatqc…
3
9
1,362
A huge thank you to @CorelliumHQ for supporting the class, Practical iOS Application Security Testing with Cameron Cartier and Dave Blandford, at WWHF - Deadwood 2026 and providing licenses at no cost to students! wildwesthackinfest.com/https…
2
2
714
Hey folks! Let's look at what's happening with @Antisy_Training Training and Black Hills Information Security! The next Anti-cast is on Prompt Engineering 201: The Context Stack w/ @BronwenAker Wed, Jun 24, 2026 12:00 PM EDT Register: events.zoom.us/ev/As1cQmMZui… BHIS Webcast: The next BHIS webcast is on Why You Should Care About SQL Injections in 2026 w/ Fernando Panizza Thu, Jun 25, 2026 1:00 PM EDT Register: events.zoom.us/ev/AsFLiIVYra…
2
5
1,480
The Hitchhiker's Guide to the Galaxy has this to say about software security: it's most effective when built in from the start, and most expensive bolted on after the ship has already launched. @shehackspurple has been making that argument, and winning it, for nearly 3 decades.
2
9
1,293
Check out Jacob Swinsinski's talk, "You Used to Call Me On My Shell Phone," from WWHF @ Mile High 2026! youtube.com/watch?v=hy4AmbzS… Be sure to get your tickets for WWHF - Deadwood 2026! wildwesthackinfest.com/wild-…
2
4
793