SANS is the most trusted and by far the largest source for information & cyber security training, certification and research in the world.

Worldwide
The case behind Netflix's A Toxic Love Story: a Deputy U.S. Marshal used VPNs, encrypted apps, and wiped devices to frame an innocent woman. At #DFIRSummit, Jason Higley will walk through the forensic evidence that caught him. 🗓️ Summit: Oct. 15–16 | 📍 Arlington, VA Save Your Spot: go.sans.org/TSSBBf
1
3
1,033
The Idaho murders suspect studied how investigators work and appeared to leave almost no digital footprint. At #DFIRSummit, Heather Barnhart will walk through the evidence that helped build the case anyway. In person only. 🗓️ Summit: Oct. 15–16 | 📍 Arlington, VA Save Your Spot: go.sans.org/TSSBBf
4
4
2,011
SANS Institute retweeted
We're screening for North Korean IT workers in the wrong place. Most of the advice on North Korean IT workers is about catching them in the interview. I think that's the wrong place to put most of our effort. The joint advisory four governments just put out is a good example. The hiring advice is almost entirely human: check the applicant's IP against where they say they live, call their phone number, drill the resume live, and ask about their hometown and hobbies. (Apparently "tell me about your hometown" is a security control now.) I'm not knocking any of it. Talking to a real person is still one of the better fraud checks we have. But it only works on applicants, and a laptop farm exists to beat the IP check anyway. None of it helps with the one who already passed, got the laptop, and built a normal work record. And I'd assume one already has. At @OneRSAC last year, @Mandiant's Charles Carmakal said nearly every Fortune 500 CISO he'd talked to about this problem admitted hiring at least one North Korean IT worker. I wouldn't bet on smaller shops doing better. (I'd love to be wrong on that.) The advisory does mention least privilege, in one line, next to revoking accounts once you suspect someone. Revoking only helps once somebody notices. I'd put least privilege at the center for new remote hires. Access should grow with tenure instead of arriving on day one, and you should have a tested answer for how fast you can pull it back. Pick your newest remote engineer. What could they reach, exfiltrate, administer, deploy, or monetize before anyone had a reason to wonder? I built the brand new FOR500: SANS Windows Forensic Analysis case with @HeatherMahalik Barnhart and @ovie Carroll around exactly that hire. Operation Crimson Ledger puts you on the Windows 11 laptop of a remote engineer who cleared the interview and looked normal for months: two remote-access tools, a consumer VPN, an AI coding agent with more screen time than Office, company files staged to a personal Google Drive, a mailbox exported through a second copy of Office, and a wiper run seven times in the two minutes around the upload. (Least privilege wouldn't have stopped all of it, but it would have made the trail a lot shorter.) Advisory: ic3.gov/CSA/2026/260918.pdf SecurityWeek: securityweek.com/japan-disma…
9
20
97
37,811
Ever wondered what it feels like to be the last line of defence for a power station? ⚡ This year's CyberThreat CTF puts you in charge of defending Kiron power station, built by @xzer0f and more brutal than ever. Hackable badges are back too. go.sans.org/TOqOEp #CyberThreat2026
2
2
1,996
At last year's ceremony, we asked SANS Difference Makers Award winners to describe the DMAs in one word.
1
1
5,211
This year's ceremony is coming up during SANS Cyber Defense Initiative in December, livestreamed for the whole community. #SANSDMA
1
440
Watch what past winners said and learn more about the DMAs here: go.sans.org/UypMD0
1
381
SANS Institute CEO James Lyne reviewed the incident reports behind this summer's "rogue AI" stories. His take: they're "technically incoherent" and show "a pretty profound unfamiliarity with the subject." aol.com/articles/no-ai-not-g…
2
7
4,514
⏳ The countdown has started. CyberThreat 26 is coming. @xzer0f has the details 👇 Awesome speaker lineup, real practitioner insight, and the Kiron Nuclear Power Station CTF returns with new realms to explore. Register → go.sans.org/TOqOEp #CyberThreat2026
2
3,891
SANS Institute retweeted
At the first @unpromptedconf, we planned for 200 people. Two weeks before the conference, our sponsors made it possible to move venues so we could grow to 650 in-person attendees, allowing us to let hundreds of people off the waiting list. We also added a virtual conference that welcomed an additional ~1000 attendees. Almost all talks were released following the event resulting in ~750,000 online views post conference! [un]prompted was born, and is now recognized as the highest impact AI security and safety community. Sponsors made this convening possible! In the seven months after the first con, the field has changed enough that the community needs to gather again. Sponsors do not receive an attendee list, a talk, control of the content, or the usual conference marketing deal. They chose to support [un]prompted anyway. A remarkable commitment to this community and its cause. Anchor Sponsors: @knosticai, @TachTech, @censysio, @Ent_Security, @WorkOS, @DecibelVC Partner Sponsors: @WhiteRabbitGrp, @zenitysec, @runsybil, @AISLE_Inc Community Partners: @SANSInstitute, @cloudsa, @OneRSAC, @FIRST In 39 days at [un]prompted II, find them, thank them, shake their hands. Help us celebrate the leaders who put mission first. @unpromptedconf, where the security community convenes. Back in San Francisco and online, October 27–29.
1
6
18
2,854
"Effective security starts with understanding people." Dr. Hassan Abutair, Founder & CEO of DIGISEC, on what's changing in security awareness programs. From the SANS Security Awareness Report 2026: go.sans.org/imaYcs #SecurityAwareness #HumanRisk
1
2,032
Choose your challenge, build your future. SANS Cyber Quest CTF, Powered by @RBC gives Greater Vancouver's next generation of defenders 72 hours of gamified, hands-on challenges, free to join. Full announcement: go.sans.org/Ony3kW #CTF #Cybersecurity #RBC #SANSTraining
2
1,930
SANS Institute retweeted
Six people who've spent months disagreeing in public about how bad AI gets for vulnerability discovery and cyber defense are sharing one stage, Nov. 2-3. They have been challenging all of our thinking (and each other) in public: Ciaran Martin: “Are you sure?” @k8em0 says “brace yourself.” @gadievron says “the AI vulnerability cataclysm is coming.” Marcus Hutchins: “marketing BS.” @jeremiahg says AI vulnerability research “doesn’t make an internal service externally reachable.” @EppSecurity says “offense has the cheapest verifier.” (I've watched this argument run in public for months and I still don't have a side, which is exactly why I want it on a stage instead of in my replies.) This isn't a hot take panel. Moussouris built the vulnerability disclosure programs most companies now run by default. Martin led the UK's national cyber defense. Hutchins stopped WannaCry. Evron has founded security companies and lived inside this fight for years. Grossman and Epp have both been testing the actual systems this argument is about, not narrating from the sidelines. (The debate you actually want, not the one you get on X.) We are 44 days away from "Autonomous AI Hacking: How Big Is the Threat?" Day 2 of the @SANSInstitute AI Cybersecurity Summit, moderated by Ciaran Martin (who has earned it, given how many times he's pushed back on me directly). Registration includes virtual access to @unpromptedconf II: go.sans.org/x0xA1Y
3
9
35
3,535
New keynotes and panelists announced for SANS AI Cybersecurity Summit Fall 2026. This November, voices from across cybersecurity, AI, technology risk, public policy, and security leadership are coming together to dig into the questions security teams are working through now: → How AI is changing security operations → What happens as agents take on more responsibility → Where new attack surfaces are emerging → How teams balance autonomy with human oversight And the agenda is still growing, with more speakers and sessions to come. 🗓️ Nov. 2–3 📍 Arlington, VA | All-Access + Workshops 🌐 Live Online | Summit Talks Explore the growing agenda: go.sans.org/AAslWm #AISummit #AISecurity #CyberSecurity
1
3
2,267
SANS just launched LinkedIn and X channels for our North America community. Expect insights on what security teams here face, stories about why this work matters, and real voices from practitioners. Follow @SANSAmerica.
1
8
3,064
SANS Institute retweeted
Welcome to SANS North America on X. This region deserves a space of its own, so expect insights on what security teams here face, stories about why this work matters, and real voices from practitioners.
1
2
2
847
Does your employer offer tuition assistance? 💼 You're likely eligible to use those benefits toward a cybersecurity degree or certificate @SANS_EDU. Learn how: go.sans.edu/eSwkR5
2
1
9
2,875