Cindʎ Xiao 🍉

@cxiao@infosec.exchange
735 Followers
1.9K Following
2.1K Posts

professional strings(1) operator

online once every century, DM for signal!

pronounsshe/her or they/them
websitehttps://cxiao.net
githubhttps://github.com/cxiao
bskyhttps://bsky.app/profile/cxiao.net
🏳️‍🌈😎
viewsare mine

My team at Microsoft is hiring a junior-level red team engineer! We're looking for someone with at least 1 year of security experience and who can work with us from our Redmond, WA office at least 3 days a week.

Apply here or share with your network:
https://jobs.careers.microsoft.com/global/en/job/1836188/Security-Engineer

Search Jobs | Microsoft Careers

SK Telecom in South Korea had a bad data breach.... and boy, are they getting hit with all kinds of consequences for it, including:

-- a fine for late reporting ($22k USD);

-- an order to send notifications to all customers who were affected (23 million?!);

-- a judgment that they have to waive cancellation fees if dissatisfied customers canceled (and 660,000 canceled just last month alone); and

-- a criminal investigation has been launched into them for not preserving data properly for the regulator's investigation.

#databreach #SKTelecom #cybersecurity #malware

If there is one major take away I have from fwd:cloudsec it’s this: cloud security teams are rapidly being asked to secure generative AI systems and workloads, but struggle with the lack of observability and understanding of the most prevalent attack vectors. There is work here.
Senate strikes AI provision from GOP bill after uproar from the states
https://apnews.com/article/congress-ai-provision-moratorium-states-20beeeb6967057be5fe64678f72f6ab0
Senate strikes AI provision from the Republican tax bill after uproar

A proposal to deter states from regulating artificial intelligence for a decade was soundly defeated in the U.S. Senate on Tuesday, thwarting attempts to insert the measure into President Donald Trump’s big bill of tax breaks and spending cuts. The Senate voted 99-1 to strike the AI provision after weeks of criticism from both Republican and Democratic governors and state officials. Originally proposed as a 10-year ban on states doing anything to regulate AI, lawmakers later tied it to federal funding so that only states that backed off on AI regulations would be able to get subsidies for broadband internet or AI infrastructure.

AP News

Hello, friends! Do you want to -speak- at #PancakesCon this year? Our CFP is ~open~! https://forms.gle/K8UnDGHPdmj6vTgZ8

CFP Closes August 9 at 1800 Central Time. Don't miss out! Start thinking of your talk ideas now! Details at pancakescon.com, and mentorship and help on our Slack if you're a novice speaker

PancakesCon 6: Family Brunch - CFP

PancakesCon is a cybersecurity conference that will be conducted all day on 9/21/2025 (US Central Time). This conference is 100% virtual, not for profit and free to stream. **PancakesCon has a UNIQUE FORMAT. Please read these instructions carefully**: All PancakesCon talks must be 40-45 minutes long. They ****MUST**** consist of two parts: A brief talk about any cybersecurity topic targeted at junior professionals / students, and a brief talk about something which is not IT-related. The non-IT topics can cover anything from hobbies to fitness, cooking to music. Share something you're passionate about aside from computer technology or cybersecurity! Most people gave their talks in two separate halves at previous conferences with a clear transition, but you're welcome to combine the topics if you're feeling really creative! See examples on our YouTube. Example: "Active Directory Enumeration and Ballet Dance" CFP will close on Saturday, August 9, 2025 at 8:30PM US Central Time. CFP Notifications will go out on August 23 from hacks4pancakes at gmail (please make sure you allow this email). While we focus on diversity across all aspects of PancakesCon, our CFP review is blind. Please *do not include your name or any extremely identifying information* in your synopsis or we WILL disqualify you. ----------------------------- *Code of Conduct*: - PancakesCon is intended for a PG-13 audience. Please keep conversations and talks appropriate for young people (e.g. talks about making alcoholic drinks or medieval weapons are fine, but please be mindful of young people in talks and conversations) - PancakesCon talks and chat are moderated, and we have a zero tolerance policy on abuse, hate speech, and harassment. Violators will be removed from PancakesCon platforms and potentially barred from future events. Please contact a moderator in Slack immediately with any concerns.

Google Docs

Only the second time I've tried to reach out to fed cyber workers, but it worked super great the first time.

If anyone in the federal government involved in budgeting for cyber efforts follows me here, I would love for you to contact me at Cynthia.507 via Signal for a piece I'm writing for a cyber publication.

I will honor all requests for anonymity. Thank you.

I am very grateful to have been part of the panel at REcon. Like last year, I find myself leaving @reconmtl inspired and motivated to keep pushing forward in my research. Thanks again for all the awesome conversations, everyone. Hope to see you all next year.

I will be doing a live stream [stream] later today, kindly hosted by the amazing Dr. Josh Stroschein! I will be using #BinaryRefinery to replicate an analysis that Josh previously presented [source], of a download chain going from exploit document all the way to the AgentTesla payload itself.

[stream]: https://www.youtube.com/live/HuLONk0Rt98
[source]: https://www.youtube.com/playlist?list=PLHJns8WZXCdvfqIp9m0kkjsbg9G8YWdSH

Unraveling a Multi-Stage Downloader with Binary Refinery - Guest Jesko Hüttenhain

YouTube

While Republicans (and even some Democrats) continue to cruelly target trans young people and their families with discriminatory restrictions on not just healthcare but also sports, military service, and more, we will never stop fighting for trans peoples’ right to control their own futures as fully equal members of society.

DC and NYC: Please join the rallies against this dangerous ruling if you can. Trans rights are not up for debate. 🏳️‍⚧️

×
I am very grateful to have been part of the panel at REcon. Like last year, I find myself leaving @reconmtl inspired and motivated to keep pushing forward in my research. Thanks again for all the awesome conversations, everyone. Hope to see you all next year.