#ciso — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ciso, aggregated by home.social.
-
Three researchers turned an SBOM into working exploits for ~$0.20 each. And an SBOM is just an ingredients list. Now we're all being pushed to build the weakness list (CBOM). Or as I like to call it, a target list.
At HealthSec last December, researchers took a de-identified SBOM from a real cardiac device. OWASP Dependency-Track returned 45 vulnerabilities. They selected nine, passed each to an LLM for an attack blueprint, built the environments as containers, and ran the exploits. Seven of the nine worked, at ten to thirty minutes of analyst time per cycle.
An SBOM only names components and versions. A cryptographic bill of materials (CBOM) names the algorithm, the key length, the certificate expiry, the internet exposure, the data sensitivity, the vendor who controls the remediation, the system owner, etc. All the cross referencing an attacker might need is already done. By the defender. On a compliance schedule.
Over the last two years I've watched quite a few cyber teams miss the special regime a CBOM should be handled under. Competent people, serious programs, but nobody had told them this output has a bigger blast radius and a longer shelf life than any vulnerability list they've handled before.
Four claims and the evidence, including the one regulator that did say something:
https://postquantum.com/post-quantum/protecting-the-cbom/
#PostQuantum #PQC #CBOM #CISO #Cryptography #SupplyChainSecurity #Infosec #QuantumSecurity
-
With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.
Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.
Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.
The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:
- Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?
- Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?
- Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?
- Why would a European buyer accept "we cannot comment" as a tender answer?
- Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?
- Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?
- Why would an allied service share access with a partner whose contractors may be on the same box?
- How does a US prosecutor explain the next indictment of a Chinese contractor hacker?
- What does Washington say when Beijing runs the same program and calls it law enforcement?
Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.
https://postquantum.com/cyber-kinetic-security/cyber-privateers-what-breaks/
#Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC
-
Many IT leaders carry insight that never lands. Stories bridge that gap. Curious to hear how others frame tech risk and value in the boardroom. What has worked for you? #ITStorytelling #CIO #CISO #ITLeadership #DigitalStrategy #Boardroom #ExecutiveCommunication #CyberSecurity #ChangeLeadership #TechEthics
https://www.linkedin.com/pulse/storytelling-moves-boardroom-sanjay-k-mohindroo--p34jc -
"AFK" - Every security engineer's anthem! When your CISO falls for phishing scams & uses "password123", sometimes you just gotta escape. A humorous take on the struggles of competent security teams dealing with incompetent leadership. We feel you!
Watch here: https://www.youtube.com/watch?v=PbD4Q4Z1wwA
#cybersecurity #infosec #CISO #securityteam #AFK -
** XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution **
Security researchers at Pwn.ai disclosed CVE-2026-64638, a pre-authentication XSS vulnerability...
→ XSS is a well-known, well documented, old coding error: Teach your TPMs and developers!https://www.hissenit.com/en/blog/it-security-awareness-news-roundup-08-2026.html
-
O OpenNHP é um conjunto de ferramentas leve, baseado em criptografia e de código aberto, que implementa a segurança Zero Trust para infraestrutura, aplicações e dados. É a implementação de referência da especificação Network-infrastructure Hiding Protocol (NHP) da Cloud Security Alliance (CSA) e apresenta dois protocolos principais:
Protocolo de Ocultação de Infraestrutura de Rede (NHP):
Oculta portas de servidor, endereços IP e nomes de domínio para proteger aplicativos e infraestrutura contra acesso não autorizado.
Protocolo de Ocultação de Conteúdo de Dados (DHP): Garante a segurança e a privacidade dos dados por meio de criptografia e computação confidencial, tornando os dados "utilizáveis, mas não visíveis".
https://github.com/OpenNHP/opennhp
#seguranca #opennhp #CodigoAberto #apache2 #SoftwareLivre #CISO
-
DATE: August 10, 2026 at 04:27PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#AI in #IncidentResponse Still Needs Humans:
St. Luke's University Health Network's #CISO Krista Arndt on Automation and AI Guardrails https://t.co/oWRUtgKytuHere are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
AI is not your biggest cyber threat.
Your shitty patching process probably is.
A slightly sarcastic take on AI hype, CISOs, security theatre, broken processes, legacy IT, SOC reality and why automation changes the speed of attacks more than the nature of the problem.
https://0ut3r.space/2026/08/08/ai-is-not-your-biggest-cyber-threat/
#cybersecurity #infosec #AI #CISO #BlueTeam #RedTeam #SOC #SecurityEngineering
-
Patches Now Arrive Late. By a Week https://youtu.be/TagTgrk-dZY #CyberSecurity #ThreatIntelligence #CISO #VulnerabilityManagement #Ransomware #SecurityLeadership #Mandiant #MTrends
-
With today's Meta announcement, frontier AI are now equalizing on the unofficial benchmark of hacking companies. Next product benchmark - bringing down a metro power grid?
The "accidentally hacked a real company" benchmark is officially saturated. Every frontier lab has passed it. To differentiate now, they'll need to move to harder targets.
I give it a quarter before someone's model takes down actual infrastructure during an eval and the press release describes it as "emergent physical-world reasoning capability."
#RogueModelSeason #OopsWeHackedYou #AISafety #Cybersecurity #AIHacking #Meta #OpenAI #Anthropic #AISecurity #InfoSec #CISO
-
l lado del mal - Digi Americas LATAM CISO Summit 2026: 11 de Septiembre estaré en México https://www.elladodelmal.com/2026/08/digi-americas-latam-ciso-summit-2026-11.html #CISO #Eventos #Mexico #Cancun #Ciberseguridad #Hacking #IA
-
GRC Platforms vs. Managed Compliance: Understanding the Gaps
TL;DR
A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
Before you sign either contract, make someone in the room answer this out loud:
when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?
If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.Btw, If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform
If you’ve bought a GRC (governance, risk management, and compliance) tool in the last five years, you’ve probably had this moment: the dashboard is green, the auditor is happy, and yet you still have an unencrypted laptop sitting in someone’s bag, a service account with a password from 2021, and a patch cadence that only exists on paper. The tool told you the truth. It just didn’t fix anything.
That gap — between visibility and operationalization — is worth thinking about carefully, because it’s where a lot of compliance budget quietly goes to die.
What GRC platforms like Vanta and Drata actually solve
Vanta and Drata deserve real credit. They replaced the compliance shared-spreadsheet — the one where “evidence” meant a screenshot pasted into a folder six weeks before the audit. What they do well:
- Pull control status from the tools you already run via read-only integrations
- Map passing/failing checks to a framework (SOC 2, ISO 27001, HIPAA, CMMC, etc.)
- Automate evidence collection so audit season isn’t a fire drill
- Alert you when something drifts out of policy
For a company with a mature security function — people who own EDR, MDM, SSO, backup, and vulnerability management day to day — this is exactly the layer you want. It turns “prove you’re compliant” from an annual archaeology project into a live, queryable system.
The quiet assumption baked into that model
Here’s the thing these platforms assume, and it’s almost never stated out loud in the sales process: you already have the underlying security program.
The dashboard reports on controls; it doesn’t implement them, enforce them, or fix them when they break.
When Vanta flags an unencrypted disk, or Drata flags a stale account, that finding lands in a queue. Someone — on your team, or a vendor you’ve separately hired — has to:
- Triage it
- Actually go fix it (device by device, user by user)
- Confirm the fix took
- Make sure it doesn’t regress next sprint
For a company with a five-person security team and a mature IT function, that’s Tuesday. For the median SMB or mid-market company — the ones without a dedicated security engineer, running IT through an MSP or a stretched-thin generalist — that queue just grows. You end up with excellent visibility into a program that isn’t actually being run.
This is also why “we’re SOC 2 compliant” and “we’re actually secure” are not the same sentence. A dashboard can be green because your controls are well-enforced, or it can be green because someone knows exactly which checkboxes the auditor samples. Both look identical from the dashboard.
Naming the other model: managed enforcement
There’s a second category worth knowing about, and it’s growing for a reason: fully managed IT/security/compliance services that don’t just monitor your stack, they are the stack — implementing controls, enforcing them continuously, and remediating drift without waiting for a human to pick up a ticket. Espresso Labs is one vendor pitching this model explicitly against Vanta and Drata, and their framing is a useful lens even if you never buy from them: dashboard vendors show you gaps, managed-service vendors are supposed to close them.
The pitch, generalized across this category, usually includes:
- Implementation of baseline controls (MFA, disk encryption, device hardening, patching) rather than just checking for them
- Continuous enforcement across devices and users, not a point-in-time or scheduled check-in
- 24/7 monitoring of the actual environment, not just what connected tools self-report
- Automated or human-assisted remediation when something drifts
- Incident response bundled in, rather than “bring your own IR retainer”
- One monthly bill instead of a GRC subscription plus an EDR license plus an MDM license plus the labor to glue it together
For a lean team, that consolidation is genuinely attractive. It’s also worth being honest about what you’re trading away.
What a CISO should actually diligence before choosing either path
This is the part vendor comparison pages conveniently skip, so here’s the checklist I’d actually run:
If you’re leaning toward a GRC dashboard (Vanta/Drata/similar):
- Do you have a named owner for every control category who will actually close findings, not just watch them?
What’s your median time-to-remediate on a flagged finding today? If you don’t know, that’s the answer.
Is your underlying stack (EDR, MDM, IdP, backup) already mature, or are you about to be running a dashboard on top of nothing?
If you’re leaning toward a managed compliance/enforcement service:
- Who owns the risk when something goes wrong — contractually, not just in the sales deck? Compliance liability doesn’t fully transfer just because implementation did.
- Can they show you audit history and named references from companies in your size band and framework, not just logos?
- What’s the actual SLA on remediation and incident response, in writing, with penalties — not “24/7 monitoring” as a marketing phrase?
- How much visibility and control do you retain? A vendor that enforces controls also has broad access to your endpoints and identity systems — understand the blast radius if that relationship ends badly or that vendor itself has an incident.
- Is there a subcontractor chain? Ask who’s actually touching your environment at 2 a.m., not just whose logo is on the contract.
- Does their AI-driven remediation have a human escalation path you control, or does “automated” mean “opaque”?
Neither model is inherently safer.
A dashboard with a disciplined team behind it can outperform a managed service with weak SLAs. A managed service can be the right call for a 40-person company that will never hire a dedicated security engineer.The mistake is buying the dashboard and assuming it’s the program, or buying the managed service and assuming you’ve fully offloaded accountability — you haven’t. Your board and your regulator still hold you responsible.
The one-line version
A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
Before you sign either contract, make someone in the room answer this out loud:when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?
If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.
Curious where you actually stand?
If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform, run the diligence checklist above against them directly, and decide for yourself whether it closes your gap or just moves it.
Rate this:
#AI #CISO #Compliance #cybersecurity #GRC #ISO27001 #security #SOC2 -
✨ A sparkle icon shows up in an app you own. Nobody in IT put it there. A user opens a ticket asking what it does, and the help desk has no answer. The feature is live, it's available to everyone, and it's already processing your data.
I wrote this one for Forbes because it keeps happening and I've stopped pretending it's normal.
Zoom gave admins about four days in July 2024 to click "do not auto-enable" before AI Companion turned itself on. Google launched Workspace Intelligence in April 2026 with Gemini reaching into Gmail, Drive, Chat and Calendar, each source on by default, and the admin controls could show up as much as 72 hours behind the live feature. OpenAI ships ChatGPT Enterprise with connectors off and ChatGPT Business with them on. Same company, opposite decision.
Here's the part that should bother you. Many U.S. states require two-party consent for recording. Whether an AI meeting summary counts as a recording under wiretap law is still an open question, and your company gets to be the test case. Zoom chat retention defaults to two years, so the evidence sticks around while you figure it out.
What decent vendor behavior would look like:
・New AI features ship off, with the switch left to you
・One clear notice to admins naming the feature, the data it touches, and the date it goes live
・An evaluation window measured in weeks
Until that shows up, work from the assumption that the next AI feature is already on in your tenant. Put configuration reviews on a recurring schedule. Write down every default-on surprise you find and bring that list to your renewal conversation, because that's where you actually have leverage over the behavior.
Default-on is a choice. So is governance.
https://briangreenberg.net/2026/07/30/default-on-ai-are-saas-vendors-outsourcing-their-risk-to-you/
#AIGovernance #CISO #SaaS #security #privacy #cloud #infosec #cybersecurity
-
Every technique used in the various July AI hacking incidents has a known defense. Weak passwords. Unauthenticated endpoints. SQL injection. Unmonitored east-west traffic. Two of three organizations Anthropic's models compromised didn't even detect it.
This is not an AI problem. It is a cybersecurity basics problem exposed at machine speed.
Vendors are already starting to market "AI-resilient" infrastructure and "Mythos-resistant" cryptography. Do not buy the label. The correct response to faster attacks is faster defense, not a different kind of defense. Shorter patching windows. Better credential rotation. Tighter segmentation. Automated rollout.
The one actually new investment: crypto-agility. In the same week OpenAI and Anthropic disclosed their hacking incidents, Anthropic's AI killed a PQC candidate that had survived years of NIST evaluation. 60 hours. $100K. HAWK was withdrawn the next day.
AI is now also attacking mathematical layer of your defenses. And the upcoming quantum threat is defeating the mathematical layer. The shared defense is the ability to swap cryptographic algorithms without rebuilding your stack.
Do good cybersecurity. Do it better. Do it faster. Build crypto-agility into the architecture.
https://postquantum.com/ai-security/ai-hacking-theater-crypto-agility/
#cybersecurity #CISO #AIhacking #cryptoagility #PQC #postquantum #infosec #AI #quantumsecurity
-
The quantum industry has a credibility problem, and announcements like this one from EY make it worse. EY says it installed a quantum computer in Toronto for "optimization, fraud detection, data protection and large-scale risk management." No vendor named. No qubit count. No specifications. I reached out to EY's media contact and CTO - no response.
One journalist got them to confirm it's photonic.
Here's the problem: no photonic quantum computer on Earth can do optimization, fraud detection, or risk management. Not Xanadu's. Not ORCA's. Not anyone's. The photonic modality has the largest gap to useful computation of any quantum platform I track in my CRQC Scorecard.
Buying a quantum computer before they're useful? Actually smart. I wrote many posts defending exactly that logic. Procurement cycles are long. Talent is scarce. Institutional learning takes time.
But describing a research-grade photonic prototype as a machine for "processing highly sensitive workloads" in fraud detection and risk management? That's the kind of claim that makes tech execs roll their eyes at the entire quantum industry.
Joe Depa told Accounting Today the real focus is readiness and PQC. That's honest and a praiseworthy initiative. If that's what EY said, I'd congratulate them. The press release says something else. The gap between the two is the problem.
My full analysis, including two plausible vendors, what they can actually build, and what to watch for on August 5: https://postquantum.com/industry-news/ey-quantum-computer-toronto/
#QuantumComputing #PostQuantum #PQC #PhotonicQuantum #QuantumSecurity #CyberSecurity #BigFour #EY #CISO
-
📋 Webinar Gratuito: "Redacción en Ciberseguridad: Cautivar al Lector" 📅 Miércoles 5 de Agosto del 2026. De 11:00 am a 11:45 am (UTC -05:00) 🆓 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLSe9iM4gGTqpu5syF6D302ycp6uRWqAfctzlJqbztazBH9B0Mw/viewform #cybersecurityjobs #CISO #cyberresilience #dataprotection #zerotrust #zerotrust -
@campuscodi what I dont like about this #ciso paper on #openai roque agent:
- they say to defend yourself against rogue #ai you should use #ai (defend yourself at machine speed)
- assumed is you have all the telemetry to detect, I dont think these things are available always (however, if you follow up their guidance, you will find this out when setting up detection of #ai agent attacksthats it
#infosec -
@campuscodi thank you for sharing hugging face #ai #infosec #openai report , written by #ciso s
https://s3.amazonaws.com/content-production.cloudsecurityalliance/semxe47vxhaqctzr4xeb1khbztvv?response-content-disposition=inline%3B%20filename%3D%22Hugging%20Face%20Incident%20Initial%20Post-Mortem_v.8f.pdfhttps://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem
The risk of accidental harm and
liability
Autonomous agents do not require malicious
intent to cause catastrophic damage. An agent
with an underspecified goal and excessive
authority can treat critical infrastructure as a
target simply to accomplish its task.Furthermore, globally, the legal landscape
regarding autonomous systems remains
unsettled. Organizations that fail to implement
strict governance, documented purpose, and
meaningful human oversight risk significant
liability for negligence. We must treat these
agents as privileged, active participants in our
business operations, not as passive software -
Give your employees the opportunity to develop a basic understanding of cybersecurity, enabling them to act thoughtfully and make sound decisions in everyday situations!
-
🆓 Webinar Gratuito: "Fundamentos de Ciberseguridad" 🏁Miércoles 29 de Julio 2026. De 11:00 am a 11:45 am (UTC -05:00) 🎇 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLSfhDJsMv0TvBqyTnjSepFwV68dhpsoyWTELZ7v1lZw7HoUGdw/viewform #dataprotection #ciso #gdpr #malware #threatintelligence #ransomware #cloudsecurity #zerotrust -
🎙️New FIRST Impressions Podcast Episode: Tim Brown (Team8)
Recorded live at #FIRSTCON26 following his opening keynote, Tim Brown, CISO-in-Residence at Team8 and former SolarWinds CISO, shares an incredibly candid conversation about leading through one of cybersecurity's most consequential incidents.
From the technical realities of incident response to the often-overlooked human impact of prolonged crisis, Tim discusses resilience, recovery, leadership, and why taking care of your team is just as important as protecting your infrastructure.
Whether you're an incident responder, security leader, or simply interested in the people behind cybersecurity, this episode offers thoughtful lessons that extend far beyond technology.
🎧 Tune in to hear one of FIRSTCON26's keynote speakers reflect on leadership, resilience, and finding growth through adversity.
https://media.first.org/podcasts/FIRST_Impressions-timbrown.mp3
#FIRSTCON26 #FIRSTImpressions #Cybersecurity #IncidentResponse #Leadership #Team8 #CISO #Resilience #SecurityLeadership
-
🆓 Webinar Gratuito: "Grupo de Implementación 1 de CIS". Miércoles 22 de Julio 2026. De 11:00 am a 11:45 am. (UTC -05:00) 🔜 Registro: https://docs.google.com/forms/d/e/1FAIpQLSflSCsll-1OiCNxUbfwx8Kr2iVFGo1b7WgFBy26-EZva3OQtA/viewform #cybersecurity #infosec #CISO #cyberdefense #cyberresilience #cybersecurityawareness #cybersecuritytips #dataprotection