I manage information security at @Experian. Write articles & book reviews on security, privacy, risk management. Member of @CyberSecCanon.

USA
Got @PunchbowlNews @paperlesspost or @evite invite? Think twice before clicking. Scammers use digital invitations to steal passwords, hijack accounts & spread malware. Scary part is they look 100% legitimate. Your “invitation” may actually be an attack. brothke.medium.com/invitatio…
1
85
The @NFL & @MLB are in full swing & so is online gambling feeding frenzy. @FanDuel @CaesarsSports @BetMGM @bet365 & @DraftKings aren’t in business to make YOU rich. You can’t beat the house & that’s what they’re counting on. Don’t take any ‘free’ offers. brothke.medium.com/why-you-s…
161
Everyone wants to be validated. The @PicusSecurity Validation Summit ’26 free online event on Oct. 14/15, w/ a keynote by @mikko, focuses on how organizations can validate whether their defenses actually work against increasingly AI-powered attackers. cybersec.picussecurity.com/s… #AI
2
103
Shakespeare knew that the most dangerous threats come from within. Cute video from Eliana V., a cyber historian at @MiggoSecurity, on why strong #infosec tools matter to protect against Shadow #AI. Unknowns are the biggest #cybersecurity exposure. api.cyfluencer.com/s/shadow-…
1
107
The @owasp lists focus limited security attention where it matters most. #OWASP Top 10 for #AI #LLM applications reflects the growing consequences of giving LLM applications access to tools and enterprise systems. Prompt injection remains #1. HT @aembit_io go.aembit.io/s/the-owasp-top…
1
3
174
You can be on the real @X website & still get hacked. This #phishing attack looked so convincing I almost fell for it. Attackers don’t need your password. I show how the #scam works. If you dig a little, you can easily spot it before it’s too late: brothke.medium.com/youre-on-… #Scams
3
6
1,270
It’s not just healthcare data - it’s mental health data. Compromised medical records are bad enough. Exposure of someone’s mental health history, diagnoses, treatment, or therapy can have deeply personal, potentially life-changing consequences. api.cyfluencer.com/s/the-int… #infosec
4
193
Tortillas are delicious. But DarkTortilla #malware certainly leaves a bad taste in your mouth. #DarkTortilla is a highly configurable .NET crypter & multi-stage loader active since August 2015. Good overview how to protect against it from @PicusSecurity. cybersec.picussecurity.com/s…
3
300
Boards are all asking - If #AI is this good at writing code, why keep buying security tools? The answer is that a frontier model is a reasoning layer, not a replacement for #SAST, #SCA, secrets & supply-chain defense. Interesting insights from @EndorLabs. api.cyfluencer.com/s/ciso-s-…
1
2
650
Think a birthday invitation is harmless? Think again. Scammers are using fake @PunchbowlNews @paperlesspost& @evite party invitations to steal passwords, hijack accounts & spread malware. The scary part? They can look like they came from someone you know. brothke.medium.com/invitatio…
1
6,808
#DoppelCart is a automated fraud network of nearly 119k domains running fake online shops to steal credit card/banking details. Most domains are in the .SHOP top-level domain, accounting for 2.72% of all sites on the TLD. HT @billtoulas in @BleepinComputer bleepingcomputer.com/news/se…
124
#Passwordless authentication & #passkeys are quite popular but are in fact quite vulnerable accd. to @Unit42_Intel. The #pass-ta-key attack leverages synced passkey features of #Google #Chrome to successfully gain access to passkey-authenticated services. api.cyfluencer.com/s/what-pa…
2
202
Major news: Jacob Tsimerman of @UofT won the Fields Medal in June & is now leaving academia & redirecting his research toward solving problems in #AI safety. He starts a job in the safety department at @OpenAI later this month. HT @sioroberts in @NYTimes. nytimes.com/2026/09/08/scien…
164
Ben Rothke retweeted
𝗔𝗻 𝘂𝗻𝗮𝘂𝘁𝗵𝗲𝗻𝘁𝗶𝗰𝗮𝘁𝗲𝗱 𝗮𝘁𝘁𝗮𝗰𝗸𝗲𝗿 𝗰𝗼𝘂𝗹𝗱 𝘁𝘂𝗿𝗻 𝗮𝗻 𝗮𝗳𝗳𝗲𝗰𝘁𝗲𝗱 𝗚𝗿𝗮𝗳𝗮𝗻𝗮 𝗠𝗖𝗣 𝘀𝗲𝗿𝘃𝗲𝗿 𝗶𝗻𝘁𝗼 𝗮 𝗽𝗿𝗼𝘅𝘆 𝗳𝗼𝗿 𝗶𝗻𝘁𝗲𝗿𝗻𝗮𝗹 𝗻𝗲𝘁𝘄𝗼𝗿𝗸𝘀 𝗮𝗻𝗱 𝗰𝗹𝗼𝘂𝗱 𝗺𝗲𝘁𝗮𝗱𝗮𝘁𝗮 𝗲𝗻𝗱𝗽𝗼𝗶𝗻𝘁𝘀, 𝗽𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹𝗹𝘆 𝗿𝗲𝘁𝗿𝗶𝗲𝘃𝗶𝗻𝗴 𝗰𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹𝘀 𝘁𝗵𝗮𝘁 𝗲𝗻𝗮𝗯𝗹𝗲 𝗹𝗮𝘁𝗲𝗿𝗮𝗹 𝗺𝗼𝘃𝗲𝗺𝗲𝗻𝘁. The scale around it is significant: Grafana reports more than 1.5 million active installations and 25 million users worldwide, while its MCP server has surpassed 1.9 million Docker Hub downloads. Pillar Security researcher Ariel Fogel discovered two issues that combined into a critical kill chain: a missing inbound authentication boundary allowed anyone who could reach the server to invoke its tools, while an SSRF vulnerability let callers control the destination, method, headers, and body of outbound requests. 𝗧𝗵𝗲 𝗦𝗦𝗥𝗙 𝗶𝘀 𝘁𝗿𝗮𝗰𝗸𝗲𝗱 𝗮𝘀 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟭𝟵𝟱𝟭𝟲 (𝗖𝗪𝗘-𝟵𝟭𝟴), 𝘄𝗶𝘁𝗵 𝗮 𝗖𝗩𝗦𝗦 𝘀𝗰𝗼𝗿𝗲 𝗼𝗳 𝟵.𝟭. Credit to the Grafana team for shipping authentication protection within hours of triage and moving quickly to address the SSRF. 𝗥𝗲𝗮𝗱 𝘁𝗵𝗲 𝗳𝘂𝗹𝗹 𝘁𝗲𝗰𝗵𝗻𝗶𝗰𝗮𝗹 𝗯𝗿𝗲𝗮𝗸𝗱𝗼𝘄𝗻 𝗮𝗻𝗱 𝘄𝗮𝘁𝗰𝗵 𝘁𝗵𝗲 𝟵𝟬-𝘀𝗲𝗰𝗼𝗻𝗱 𝗱𝗲𝗺𝗼: pillar.security/blog/valid-b…
7
2
14
412
This piece details 6 #cybersecurity risks of agentic #AI traditional app security wasn’t built for: unbounded autonomy, tool-chain exposure, identity fluidity, cascading multi-agent compromise, persistent memory poisoning & supply chain integrity gaps. go.aembit.io/s/6-cybersecuri…
2
2
171