I will light the way by the bridges I burn. Retired Senior SANS Instructor IANS Faculty Black Hills Information Security Active Countermeasures

Spearfish, SD
strandjs - strandjs@bsky.social retweeted
The classics never go out of style, they just get an AI upgrade. Learn the 11 core security concepts with John Strand, Nov 10–11 (8am MST)! learning.antisyphontraining.…
1
1
364
strandjs - strandjs@bsky.social retweeted
Red Siege is heading back to @WWHackinFest Deadwood! Training. Talks. Workshops. Vishing CTF. Swag. And a whole crew of Red Siegers. See everything we’ve got planned for WWHF 🔗 redsiege.com/deadwood-guide2…
1
6
527
Coolest vendor at GoSec. Check out Mokn.
3
1,487
strandjs - strandjs@bsky.social retweeted
Ready to take your pentesting skills further? Join Red Siege CEO @TimMedin for Penetration Testing: Beyond the Basics at @WWHackinFest Deadwood, Oct. 6–7. Go beyond the fundamentals and add new techniques to your toolkit. There's still time to register! 🔗👇
1
2
5
645
Cyber hot take, delivered somewhere on a mountain bike trail. No packets were harmed. Same can't be said for my quads...
9
5
45
5,844
strandjs - strandjs@bsky.social retweeted
Hunting CVE-2026-85706 in GitLab logs? A 400 saying "branch is required" is not a failed attempt. It means the file was read. We proved it by planting files with known contents and watching the error change. activesoc.blackhillsinfosec.…
1
6
16
3,111
strandjs - strandjs@bsky.social retweeted
oh wait... its @eric_capuano! how cool.. great read on the GitLab vuln.
Hunting CVE-2026-85706 in GitLab logs? A 400 saying "branch is required" is not a failed attempt. It means the file was read. We proved it by planting files with known contents and watching the error change. activesoc.blackhillsinfosec.…
1
10
1,250
Got a hot take on cyber today, brought to you by a guy currently doing zero cyber...
5
4
55
3,167
Quick thoughts on the Anthropic report that bad people are using AI. I guess I am shocked that people are shocked.
1
2
18
1,711
strandjs - strandjs@bsky.social retweeted
Hacking back is now (partially..) legal for U.S. companies. Our founder John Strand breaks down what Trump's new memo actually allows and the big questions still unresolved. cybrsecmedia.com/trumps-hack…
2
7
1,522
NSA, FBI, CISA, DOE, and EPA just went public with AI-assisted attacks on Siemens PLCs hitting critical infrastructure. When the NSA says something like this, people listen, and I weighed in on what it means in this article. scworld.com/news/unspecified…
5
45
181
21,248
Live from Black Hat, I was invited to sit down with G Mark Hardy on the CISO Tradecraft podcast. Thanks for having me on. We had wide-ranging conversation about the future of AI, cybersecurity careers, penetration testing, automation, and the skills that will actually matter next. Go check it out! piped.video/watch?v=8KJcXoHf…
1
3
2,197
The Goons at this years Defcon are amazing. Helpful and very kind. Hats off to the whole group. Backdoors and breaches at Defcon Groups is still going very strong.
1
2
24
1,861
Backdoors and Breaches tournament in effect! Come play a round with me in the defcon groups room.
1
25
2,069
strandjs - strandjs@bsky.social retweeted
AI is already here in cybersecurity. Join the FREE Infosec: Age of AI Summit for real lessons, risks, and honest talks. Less hype, more security. Register now! learning.antisyphontraining.…
1
1
542
strandjs - strandjs@bsky.social retweeted
And that's not all! Join our FREE 6-hour Infosec: Age of AI Summit on August 14th for real-world AI cybersecurity insights from experts. Register free and boost your skills! learning.antisyphontraining.…
1
2
510
strandjs - strandjs@bsky.social retweeted
Hey folks, John Strand (@strandjs) returns to Black Hills Information Security 's weekly webcast! There has been a lot of discussion lately about AI and what it means for penetration testing. Depending on who you talk to, AI is either going to replace every pentester on the planet or completely revolutionize the way we work. Join John for a candid discussion about what Black Hills Information Security is actually seeing in the field. Where AI is helping, where it’s hurting, what we’re doing at BHIS, & why he believes there is still plenty of opportunity ahead for security professionals willing to adapt. Thu, Jul 16, 2026 1:00 PM EDT Register: events.zoom.us/ev/Al_Jad5ZPg… P.S. On August 14, 2026, @Antisy_Training and BHIS are hosting the free virtual Infosec: Age of AI Summit! Explore how AI is impacting the industry — antisyphontraining.com/event…
2
4
1,466
strandjs - strandjs@bsky.social retweeted
"As new vulnerabilities emerge, the race to identify and mitigate them begins. But how do we, the guardians of the digital realm, rapidly pinpoint these threats as they become public?" Read more: blackhillsinfosec.com/how-to… How to Identify and Exploit New Vulnerabilities by: Matthew Eidelberg Published (in blog format): 05/13/2026
3
15
2,064
Apparently AI has already replaced every pentester, hacked every government, writes flawless malware, cured cancer, and probably folded your laundry before breakfast. Let's separate the hype from reality. We'll dig into the AI arms race, the NSA rumors, what's actually changing in cybersecurity, and where AI helps... and where it confidently makes a complete mess. If you’re looking for a practical discussion with a healthy dose of skepticism, some historical context, and a few stories about what we’ve learned the hard way, join us. events.zoom.us/ev/As7GlHatqc…
3
9
1,370
strandjs - strandjs@bsky.social retweeted
A huge thank you to @CorelliumHQ for supporting the class, Practical iOS Application Security Testing with Cameron Cartier and Dave Blandford, at WWHF - Deadwood 2026 and providing licenses at no cost to students! wildwesthackinfest.com/https…
2
2
714