Attention Adventurers!
KEYNOTES ARE LIVE ON THE SITE!
@caseyjohnellis
@PhillipWylie
Come hang out around the campfire w these storied experts as they delve through their lore, legends, and long-winded explanations of how to pronounce gif
| Verified by | https://fedified.com |
| Web | https://cje.io |
| https://twitter.com/caseyjohnellis | |
| https://linkedin.com/in/caseyjohnellis | |
| Bluesky | caseyjohnellis.bsky.social |
Attention Adventurers!
KEYNOTES ARE LIVE ON THE SITE!
@caseyjohnellis
@PhillipWylie
Come hang out around the campfire w these storied experts as they delve through their lore, legends, and long-winded explanations of how to pronounce gif
NEW: A bug in a student admissions website exposed the personal information of parents and their children, including their names, dates of birth, home addresses, pictures, and details about their school.
The bug, now fixed, was a sequential IDOR. At least 1.63 million student records were exposed.

Ravenna Hub, which lets parents apply and track the status of their kids' applications across thousands of schools, allowed any logged-in user to access the personally identifiable data associated with any other user, including their children.
Junkyard was an absolute pleasure to host again, it was awesome to see it take off... we even had a Roller Coaster Tycoon exploit this year!
In case you missed the show, @caseyjohnellis gave a great writeup of the EOL targets and exploits shared: https://cje.io/2026/02/07/for-the-love-of-the-game-districtcons-year-1-junkyard/

Getting ahead of the grapevine a little: Last Saturday Jan 31 was my last day "inside the tent" at Bugcrowd. I've been slowly stepping back from the company since my heart surgery in '24, and it was the right time to go both-feet out. I'm still a founding shareholder, massive
An American social media influencer said he was paid $100 by a pro-Kremlin propagandist to post a fake video of Haitian immigrants claiming to vote in the US presidential election. The payment was one of several the man said he received from the propagandist- a registered Russian agent - to post on social media in the run-up to the election.
Now live: the discussion I had with Chris Hughes and @caseyjohnellis on systemic issues in #cybersecurity:
https://www.resilientcyber.io/p/resilient-cyber-w-wendy-nather-and
In which I pulled a “Legally Blonde” on Casey; see if you can catch it 😉
In this episode of Resilient Cyber Chris Hughes chats with Cyber industry veterans and long-time leaders Wendy Nather and Casey Ellis about systemic cyber struggles, issues that still plague us over the years, and some of the economic incentives at play (or not) when it comes to cybersecurity.
👏👏👏
Doubling Down on Trusted Partnerships: Our Commitment to Researchers | @ONCD | The @White House https://www.whitehouse.gov/oncd/briefing-room/2024/10/22/doubling-down-on-trusted-partnerships-our-commitment-to-researchers/
TLP:🌈
October 22, 2024 By National Cyber Director Harry Coker, Jr. The cybersecurity threat environment is constantly evolving. It is more complex than ever before. Keeping ahead of the bad actors requires collective effort, built on trusted partnership. Partnership means the government shares what we know to help entities defend themselves and their customers. But we…
OpenAI’s October “Influence and cyber operations: an update” just dropped 👀