๐Ÿ’ก Security isnโ€™t a collective fear - itโ€™s a shared competence โœ…

๐ŸŽฏ ๐——๐—œ๐—š๐—œ๐—ง๐—”๐—Ÿ ๐—ฅ๐—œ๐—ฆ๐—ž๐—ฆ, ๐—ง๐—›๐—ฅ๐—˜๐—”๐—ง ๐— ๐—ข๐——๐—˜๐—Ÿ๐—ฆ, ๐—”๐—ก๐—— ๐—˜๐— ๐—ฃ๐—”๐—ง๐—›๐—ฌ: ๐—ง๐—ฅ๐—”๐—œ๐—ก๐—œ๐—ก๐—š๐—ฆ ๐—ง๐—›๐—”๐—ง ๐—˜๐— ๐—ฃ๐—ข๐—ช๐—˜๐—ฅ - ลukasz Krรณl โœจ๐Ÿ”ฅ

Digital and cyber risks donโ€™t always fit into standard risk assessment models. They use different language, involve complex causes, and depend on interlinked systems.

In this talk, ลukasz Krรณl shares how to make digital security feel real, relatable and doable, even for non-technical audiences. Heโ€™ll show how to compare digital risks to physical, financial, and legal threats using simple analogies, how to break down the myth of omnipresent surveillance, and how to use storytelling to make threat modelling feel less abstract.

With real examples heโ€™ll prove that empathy, clarity, and simple frameworks can turn fear into action.

ลukasz Krรณl https://pretalx.com/bsidesluxembourg-2026/speaker/NLVVCF/ is a digital security trainer at the ICRC Global Cyber Hub in Luxembourg. He has a background in politics, technology, and international relations. He is particularly interested in digital security pedagogies, selecting secure and sustainable digital tools, and effectively supporting at-risk groups and individuals.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg #DigitalSecurity #RiskAssessment #CyberTraining #OSINT #HackerLife #SecurityEducation

A few minutes ago on the live feed for #artemis I watched the astronaut with the tablet on his lap unlock it with a password of 3939. Hope they change it before the next flight.

#nasa #space #HackerLife #infosec

๐Ÿ•ต๏ธโ€โ™‚๏ธ Trust can break Anonymity โœ…๐Ÿ”

๐ŸŽฏ ๐—ฃ๐—›๐—œ๐—ก๐——๐—œ๐—ก๐—š ๐—” ๐—ฃ๐—›๐—œ๐—ฆ๐—›๐—˜๐—ฅ: ๐——๐—ข๐—กโ€™๐—ง ๐—Ÿ๐—˜๐—ง ๐—ฅ๐—˜๐—ฃ ๐—š๐—˜๐—ง ๐—ฌ๐—ข๐—จ ๐—ฅ๐—˜๐—ž๐—ง - ๐—˜๐—Ÿ๐—Ÿ๐—œ๐—ข๐—ง ๐—ฃ๐—”๐—ฅ๐—ฆ๐—ข๐—ก๐—ฆ โœจ๐Ÿ”ฅ

The โ€œas-a-service modelโ€ has become ubiquitous across the cybercrime ecosystem. Previously dominated by tight-knit, exclusive groups, cybercrime is now a distributed international marketplace of service providers and consumers. As a result, it is more resilient than ever, with the gaps left by law enforcement takedowns quickly filled by the next opportunistic teenager.

However, to operate effectively in this anonymous distributed economy, threat actors need to build a reputation to gain trust. Does this give us an opportunity?

In this presentation, Elliot Parsons discusses the importance of trust in the cybercrime ecosystem and walks through a real-world investigation involving a prominent phishing-as-a-service (PhaaS) provider. The case study illustrates that trust and OpSec do not mix, exposing threat actors to identification.

Elliot Parsons https://www.linkedin.com/in/elliot-parsons-4ba72140 is a cyber threat intelligence consultant at AmeXio. He is from New Zealand with a background in Financial Services, Technology Services and Government organisations. His expertise is in threat intelligence, threat hunting, reverse engineering, malware analysis, and incident response.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg #Phishing #CyberCrime #OSINT #ThreatIntelligence #PhaaS #HackerLife

Here is another BSides Luxembourg 2026 announcement!

๐Ÿ’ป ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—œ๐—ง๐—ฌ ๐—œ๐— ๐—ฃ๐—ฅ๐—˜๐—ฆ๐—ฆ ๐—ž๐—”๐—ฅ๐—”๐—ข๐—ž๐—˜๐ŸŽฏ๐Ÿ”ฅโœจ - Kirils Solovjovs ( @k )

Think you can bluff your way through a security talk with zero prep? Now is your chance! At Security Impress Karaoke, you'll be handed a totally random, security-themed slide deck youโ€™ve never seen before and have just 3 minutes to present it like a pro. This is all about having fun, thinking fast, and impressing the crowd with your creativity and/or chaos. Come take the podium and letโ€™s see what youโ€™ve got!

Kirils Solovjovs https://www.linkedin.com/in/kirilssolovjovs/ is Latviaโ€™s top white-hat hacker and IT policy activist with 10+ years in offensive security and command-line mastery.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg #SecurityKaraoke #CyberHumor #PublicSpeaking #HackerLife

That time when we gather around the tableโ€ฆ
โ€ฆand fix the printer, reset the router, and explain 2FA.
Happy Friends & Family Tech Support Day to all who celebrate!
May your Wi-Fi be strong and your patience stronger.
#CkC #TechSupportDay #infosec #hackerlife #thanksgiving

Okay I know I could simply repair the keyboard with the intermittent keyboard problem impacting a couple of keys by taking apart my HP Dev One and cleaning/fixing/replacing things which will fix the problem, but am I doing that?

Of course not. Instead I'm of course thinking about just upgrading the laptop and I am trying to use this scenario as an excuse to try and justify a new fancy laptop purchase.

#infosec #HackerLife #hacker #firstworldproblems

If you run Sendmail for a domain and are under regular attack by APT actors, then boy oh boy I have a fun blog post for you! What? Just me?

Ah well, you might find it interesting nonetheless as it is a monitoring problem I needed solving, and managed to actually meet my own needs.

https://www.markloveless.net/blog/2025/11/13/apt-and-sendmail-monitoring

#infosec #security #HackerLife #apt

APT and Sendmail Monitoring โ€” Mark Loveless

Instead of simply discarding incoming phishing emails from APT actors, I decided to make sure it was loud and clear in mail logs that I discarded them - with attribution.

Mark Loveless

A flaw led to more, then equipment upgrades and then things accelerated. What critical systems were impacted? Well, my own. Yup, massive techno-drama on the #homelab front.

https://www.markloveless.net/blog/2025/10/29/network-updates

#infosec #HackerLife

Network Updates โ€” Mark Loveless

Everything on the network is finally done. Oh who am I kidding? Things change constantly between software and hardware updates and upgrades. This just documents a small part of it.

Mark Loveless

Itโ€™s not a good rack rewiring day unless you scrape off some skin. But things are _slightly_ more secure.

#homelab #infosec #hacker #HackerLife

I do appreciate the fact that many people are thrilled and excited to talk about the movie Hackers like they are. But when asked about it, they are typically shocked that I hated the film.

Yes it was in part that by comparison to the 1992 film Sneakers (and of course reality itself) it was wildly inaccurate, but as someone who remembers Eternal September* the film Hackers became its own version of that with a massive influx of newbies on security and hacker mailing lists and USENET channels saying "Teach me how to hack" who wanted instant results and would not respond well to pointers to papers and whatnot filled with technical details. "But I want to hack, not do homework!" was a reply I remember seeing that summed up a common feeling amongst newbs. Trying to explain that the film exaggerated and was fiction simply fell on deaf ears for many.

And that is why I hate the movie Hackers. Just remembering the film Sneakers that starred Robert Redford (RIP).

* https://en.wikipedia.org/wiki/Eternal_September

#hacker #HackerLife #infosec #sneakers #robertredford #rip

Eternal September - Wikipedia