kanunicipher

31 Followers
140 Following
156 Posts
Working in Cyber Security, interested in DevSecOps, honeypots, emerging threats, IOT

While I cannot share the slides for the 5-hour lecture, I *can* share the sources and PDFs of the two guides I made for the security leaders taking my Data-Drive Security/Threat Intelligence module.

https://codeberg.org/hrbrmstr/cmu-ciso-dds-ddi has markdown+typst and compiled PDFs of "A Practical Guide to Cyber Threat Intelligence For Security Leaders" (kind of a quick terms ref) & "Operationalizing CTI: Considerations for Security Leaders"

They might be useful to others, hence getting them up on Codeberg.

cmu-ciso-dds-ddi

Data-Driven Threat Intelligence Resources

Codeberg.org
@reverseics Quick stab.

What happens when @malwarejake pokes a stick into AI during real-world situations and risk assessments. You may be surprised, and you’ll definitely be entertained:

SAINTCON 2025 - Jake Williams - Findings From Real-World AI Application Assessments
https://youtu.be/MyRIZZYFgiE

SAINTCON 2025 - Jake Williams - Findings From Real-World AI Application Assessments

YouTube

Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new Shai-Hulud supply-chain campaign.

https://www.bleepingcomputer.com/news/security/shai-hulud-malware-infects-500-npm-packages-leaks-secrets-on-github/

Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub

Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new Shai-Hulud supply-chain campaign.

BleepingComputer
Tidal is down at the moment. App does not load!

❤️ I LOVE THIS! Kudos to Checkout.com, which received a ransom demand from the ShinyHunters hacking group 👏

Not only did Checkout's CTO Mariano Albera say "sorry"how refreshing, a hacked company that actually apologises! - but it is also refusing to pay the ransom to the hackers and *instead* is donating the ransom amount to Carnegie Mellon University and the University of Oxford Cyber Security Centre "to support their research in the fight against cybercrime."

https://www.checkout.com/blog/protecting-our-merchants-standing-up-to-extortion

So the US recently forced the Dutch to remove a memorial to America's own Black soldiers that died liberating the Netherlands from the nazis? On brand. [Edit: the cemetery is US government controlled, and the US forced its own employees to remove the memorial plaques. The Dutch government had no opportunity to oppose the decision.]

Towards the end of WW2, the French were shocked when the US refused to let its own Black soldiers join the celebration of the liberation of Paris.

The 761st Tank Battalion was an all Black tank unit that served with distinction as part of Pattons 3rd army. They killed a lot of nazis, and liberated over 30 French towns, and much of the Netherlands.

If you saw their Black Panther logo? It was all over for you. Black Panther beats German Panzer.

These elite Black soldiers racked up victories.

But they weren't immortal, and they didn't have superior weapons to either the Germans or white American soldiers. They were just brave. Many Black soldiers died freeing Europe from the nazis.

Europeans were grateful.

Racist Americans? Not so much.

@mekkaokereke The French were indeed shocked by the overt racism of the Americans, but around the same time they massacred an unknown number (estimates up to 400) of their own Senegalese troops for refusing to disperse to their homes without the demobilisation pay to which they were entitled.

https://en.wikipedia.org/wiki/Thiaroye_massacre

Still being rehashed and reassessed in French political life: https://www.franceinfo.fr/culture/patrimoine/histoire/au-senegal-des-archeologues-exhument-les-corps-du-cimetiere-de-thiaroye-pour-elucider-le-massacre-des-tirailleurs_7580245.html

Thiaroye massacre - Wikipedia

RE: https://mastodon.social/@randahl/115513890753953838

This feels like it should be illegal.

I wrote up some notes on two new papers on prompt injection: Agents Rule of Two (from Meta AI) and The Attacker Moves Second (from Anthropic + OpenAI = DeepMind + others) https://simonwillison.net/2025/Nov/2/new-prompt-injection-papers/
New prompt injection papers: Agents Rule of Two and The Attacker Moves Second

Two interesting new papers regarding LLM security and prompt injection came to my attention this weekend. Agents Rule of Two: A Practical Approach to AI Agent Security The first is …

Simon Willison’s Weblog