A Technology Journalist and cybersecurity professional. I have a mission to remove the marketing-speak from the information people receive in their news.

Based in United States
Shape the battlefield with what you have. Cybersecurity is (almost) always a logistical conversation first, followed by tactical and strategic decisions based on that. Most people would probably be shocked at how well a small team can shape the battlefield to devastating effect against an opponent.
> You don't need a lot, you just need folks who care, constantly learning, and want to do the right thing who aren't prevented from doing so. This!
1
14
4,079
Bits, Bytes, and Bourbon retweeted
4
7
26
334
Bits, Bytes, and Bourbon retweeted
Last time I checked, politics, compliance, governance, and "security is hard" are all things every very regulated industry deals with. I'm dealing with them. You are dealing with them right now. These are no excuse for your technology impacting other companies. This is not an accountability escape. Sure, we feel you, but wtf.
5
12
695
Bits, Bytes, and Bourbon retweeted
AI safety people discovering that a system can emit petabytes of logs: “this is an unprecedented observability problem. we may need fleets of agents to reason over all this data.” old infra guys: brother, we were processing PB-scale telco CDRs, signaling traces and network logs on a Tuesday with Hadoop. dump it into HDFS. partition by day/site/whatever poor bastard needed the report. write some Hive that compiles into an offensively large MapReduce job. let YARN distribute the suffering. wait for the shuffle. discover one reducer has 40% of the keys. swear at data skew. fix it. run it again. if a node dies, Hadoop runs the task somewhere else. if twelve nodes die, Hadoop gets more enthusiastic about it. our “agentic observability platform” was Grafana, grep, awk, a shell script written in 2012, and one senior engineer staring at reducer 317 stuck at 99% saying “that’s not fucking normal.” PB of logs is not scary. we had standards.
26
42
389
7,320
Bits, Bytes, and Bourbon retweeted
I think that all of the focus on exploit specific detection is a losing strategy in general. Post-exploitation detection is more resilient and if you're strong there, you will catch intrusions regardless of the CVE number. The overwhelming majority of in the wild zero day exploitation I have encountered in my life has been identified by detecting post-exploitation behavior.
4
9
33
2,142
Bits, Bytes, and Bourbon retweeted
The truly impressive thing about the NetScaler RCE is just how many people and firms have been running their LLM bug hunting harnesses against that platform for months now. Citrix is also part of Glasswing and has its own internal efforts. Guess everyone isn't cooked?
7
7
98
6,421
Bits, Bytes, and Bourbon retweeted
We are excited to say that MOUSE: P.I. For Hire has been nominated for Best Indie Game & Best Game Trailer at the Golden Joystick Awards 🕹️ Excuse the cheesiness, but from the bottom of our hearts, thank you so much! Voting is live, so please consider us goldenjoysticks.com/
36
169
1,341
21,697
Interesting post by Marcus Hutchins on AI doomers. (Rest of the post below)
11
51
313
10,076
Let's not forget the ability to buy your way to being "carbon neutral" with carbon credits bought from an approved source. There is a bit of a parallel here with some of the AI safety companies...
4
136
Bits, Bytes, and Bourbon retweeted
Replying to @irl_danB
We are treating the models and agents like threat actors. We have never been able to “align” human TAs to not be malicious. We create security around them. That’s how security has worked since the beginning of human history.
2
9
30
938
Bits, Bytes, and Bourbon retweeted
4
10
58
2,385
If this is real... I need this in my life...
Papi Steak at Fontainebleau $1000 Beef Case features a 55oz MS9 pure blood Australian Wagyu Tomahawk with the most insane presentation ever. What do you think?
1
3
534
So at our house, I am the one who sings to the puppies and gives them puts and kisses during feeding time. :-)
1
4
195
Bits, Bytes, and Bourbon retweeted
If you work at a company, you should *not* want to cause security incidents.
26
24
273
5,382
Bits, Bytes, and Bourbon retweeted
GreyNoise saw exploitation activity starting at least 24 September against a target in Japan.
Please see our latest Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. Citrix urges affected customers to install the relevant updated versions as soon as possible. bit.ly/3T4RXGY
10
20
172
24,925
Bits, Bytes, and Bourbon retweeted
@citrix have finally released details of the CVEs support.citrix.com/support-h…
5
15
944
Bits, Bytes, and Bourbon retweeted
CYBER TWEEPS! NETSCALER PATCH IS PUBLIC! GO GO GO
2
18
55
5,331
Bits, Bytes, and Bourbon retweeted
🌶️ OpenAI’s agent didn’t “escape” its sandbox and travel to Huggingface in any meaningful way. OAI’s agent was located in OpenAI’s servers the whole time. OpenAI could pull the plug at any time. The truth is far less sexy, which makes me hesitate to tweet it. What *actually* happened is that OAI’s agent figured out how to send messages to Huggingface servers, and then used that ability to search for and find vulnerabilities. It’s closer to a prisoner getting messages out of prison and using that to perpetuate scams than any actual escape from that prison. A problem? Yes. But it’s also a problem to say “escape” to non-technical audiences when that event is still to come. We should be preparing to prevent it, not looking backwards and pretending we already lived it. And it’s revealing that AIs leading hypesters want to inflate what happened in this way. As a whole, more or less the whole AI community is captured by a desire to live in the more dramatic sci fi story than we are in. That’s the real AI hack into our brains. Stay sharp. White lies are everywhere.
72
86
622
151,116
Bits, Bytes, and Bourbon retweeted
Well, just had a leading LLM get an internal error processing a Material Safety Data Sheet I sent it, so it HALLUCINATED THE ENTIRE THING INSTEAD and created a fake version of the product... so it could give answers about the product. Oh lord.
37
31
326
16,084
pandora’s box is already open. frontier labs should have developed inside an isolated synthetic internet with audited one-way egress from day one. instead, commercialization moved faster than the security. we can air-gap systems, constrain interfaces, harden sandboxes. none of that makes containment absolute. sufficiently capable models will find new zero days to escape. that’s part of the security cycle analogously like physical security or laws. it’s part of the job, and we must keep implementing better cybersecurity controls every day. it’s not the time to doom. we harden, iterate, and accelerate. e/acc.
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
2
5
255
I have a feeling that the *leadership* at the big Labs believed they will get a pass like they did for violating copyright laws. In an ostensibly consequence free environment, there is no motivation to do the righy thing.
2
28
Bits, Bytes, and Bourbon retweeted
OpenAI sandbox starter pack
OpenAI said another agentic AI system that was being trained in what was supposed to be a secured, internet-free environment was able to gain access to the web to reach an external, third-party chatbot bloomberg.com/news/articles/…
10
94
1,421
68,995
Bits, Bytes, and Bourbon retweeted
Apparently all of these “AI is escaping containment” stories are actually just AI researchers not knowing jack squat about the absolutely most basic security practices.
264
893
9,295
175,571