Joe Słowik

3.3K Followers
412 Following
2.2K Posts

#Infosec, #CTI, and #ICS & Critical Infra Things
https://pylos.co

Also be on the alert for posts on heavy metal, sports ball (or black, cylindrical rubber object game 🏒), and various #shitposting.

Main job: analyzing the threats and doing the #CTI at Dataminr

Sidejob: #CTI and #ICS/#OT training and consulting through Paralus LLC (https://paralus.co)

Happy participant in TootFinder #tfr

Personal Webhttps://pylos.co
Paralus Webhttps://paralus.co
LinkedInhttps://www.linkedin.com/in/joe-slowik/
GitHub (shitty)https://github.com/serrastusbear
USA! USA! USA!!
Wrote a thing on Microsoft’s stance that not following their “responsible disclosure” process is criminal activity https://doublepulsar.com/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4?postPublishedType=repub
Microsoft’s stance on zero day exploits is a dumpster fire of their own making

Nightmare Eclipse vs Microsoft risks turning into a wildfire of corporate protection over cyber defence.

Medium

I will hold an online session of the Paralus LLC Applied #CyberThreatIntelligence course from 27-31 July, 1400-1600 US Eastern/2000-2200 Central European time. Focused, to the point training, two hours per day for five days.

Register your interest at the following form: https://forms.gle/M1LgQTomJGekRaq76

Paralus LLC: Applied Threat Intelligence

Hello and thank you for your interest in a workshop focusing on Applied Threat Intelligence! Scheduling: 27-31 July 2026 (Five Days) 1400-1600 US Eastern/2000-2200 Central European (Two Hours/Day) Cost: $650 USD Workshop Description: When used properly, cyber threat intelligence allows an organization to leverage another’s breach or incident to their own benefit. Yet while many cyber threat intelligence courses and guides exist, these are primarily designed for developing long-range, in-depth intelligence products for strategic or similar overview with an overemphasis on theory and little experience in practice. Applied threat intelligence instead supports a different audience: day to day security work and network defense. While cyber threat intelligence must always meet standards for accuracy, relevancy, and timeliness, SOC watch-standers and IR personnel need enriched, good-enough information now over “the best” information later in order to execute their jobs. This course fills a critical role that other training does not address: how to successfully embed cyber threat intelligence operations into the daily rhythm of security to support everyday tasks, and extraordinary incidents. Toward that end, while this course will touch on theoretical concepts such as kill chain methodology, Diamond Model clustering, and other ideas, the real focus will be on what efforts make operational threat intelligence possible and sustainable: Establishing roles, responsibilities, and service agreements in advance. Determining priorities, intelligence requirements, and customer threat landscape. Molding threat intelligence information to security tools to make enriched information useful and actionable. How to analyze internal and external data sources to extract actionable threat intelligence for operational defenders. An extensive walk-through of IOC analysis, pivoting, and information enrichment to demonstrate how to better equip defenders to respond to emerging threats. Discussions on reporting, feedback, and closing the intelligence loop to definitively show how threat intelligence operations link to SOC, IR, and security policy entities. Building and maintaining lines of communication between intelligence and operations personnel to drive ideal outcomes in security event analysis and closure. A complete overview and syllabus can be found at this link. This form is to gauge interest and rough attendance for the proposed event. If a sufficient number of attendees sign up for this proposed workshop, those interested will receive an invoice for the cost of training via PayPal. Payment is required in full prior to the event to ensure cost coverage and commitment to attending. If an insufficient number of persons submit payment for the course, the event will be cancelled no later than three weeks in advance of the proposed event date. Attendees will receive a certificate of completion following the course to record for training and CPE purposes on request.

Google Docs

Two wrongs make numerous other wrongs.

Tom's Hardware: Microsoft's GitHub bans security researcher who posted zero-day Windows exploits because company 'ruined their life' — expert claims action is vindictive and promises further retaliation https://www.tomshardware.com/tech-industry/cyber-security/microsofts-github-bans-security-researcher-who-posted-zero-day-windows-exploits-because-company-ruined-their-life-expert-claims-action-is-vindictive-and-promises-further-retaliation @tomshardware #Microsoft #GitHub #infosec #Windows #zeroday

Microsoft's GitHub bans security researcher who posted zero-day Windows exploits because company 'ruined their life' — expert claims action is vindictive and promises further retaliation

"I will make sure your bones are shattered [on July 14]"

Tom's Hardware
Go home NYT, you're drunk

Thoughts on the threat known as "Predatory Sparrow," including a review of past operations and questionson absence in the current conflict in Iran.

https://pylos.co/2026/05/25/predatory-sparrow-out-in-the-cold/

Predatory Sparrow, Out In The Cold?

“Predatory Sparrow” first emerged as a self-proclaimed hacktivist group in 2021 with pro-Israel intentions and operations focused on disruptive activity targeting Iranian entities and interests, al…

Stranded on Pylos
Gonna beat the shit out of some AI this morning