Jack Poller

@poller@infosec.exchange
39 Followers
66 Following
523 Posts
Founder & Principal Analyst, Paradigm Technica, covering Security, Cloud, and AI; former marketer, SW & HW Eng; Firearms Instructor & FFL, photographer, auto racer
Twitterhttps://twitter.com/poller
LinkedInwww.linkedin.com/in/jackpoller
Enterprise Strategy Grouphttps://www.esg-global.com/analysts/jack-poller
Twittodonhttps://twittodon.com/share.php?t=poller&m=poller@infosec.exchange
Identity fraudsters found the weak spot: attack the chip, disable digital verification, claim it got damaged in my pocket.
HINT's solution is almost too simple: make the chip visible. Attacks leave cracks, burns, blisters anyone can see.
Low-tech answer to high-tech threat. https://securityboulevard.com/2025/12/can-a-transparent-piece-of-plastic-win-the-invisible-war-on-your-identity/
Can a Transparent Piece of Plastic Win the Invisible War on Your Identity?

Identity systems hold modern life together, yet we barely notice them until they fail. Every time someone starts a new job, crosses a border, or walks

Security Boulevard
Attackers exploit new vulnerabilities in 5 days. Your monthly patch cycle takes 30.
The math doesn't work anymore. Traditional vulnerability management is broken.
Continuous exposure management isn't optional—it's survival.
https://paradigmtechnica.com/2025/12/16/when-five-days-decides-everything-the-structural-reset-in-vulnerability-management/
When Five Days Decides Everything: The Structural Reset in Vulnerability Management – Paradigm Technica

New Op-Ed: The $10B Blind Spot—How OWASP's Top 10 Legitimizes Agent Insecurity
MCP's optional auth is quicksand for AI agents.
Attribution gaps? Token bombs? We need to burn it down & build mandatory Zero Trust identities

Read: https://paradigmtechnica.com/2025/12/11/the-10-billion-blind-spot-how-owasp-just-legitimized-agent-insecurity/
#AISecurity #OWASP #CyberSec

The $10 Billion Blind Spot: How OWASP Just Legitimized Agent Insecurity – Paradigm Technica

🚨 New Op-ed: Gartner's AI Browser Ban: Rearranging Deck Chairs on the Titanic
Banning AI browsers won't work—agentic AI is already in Microsoft 365, Slack & Zoom. The threat isn't the browser, it's the agents. You can't ban the future. Secure it.
https://securityboulevard.com/2025/12/gartners-ai-browser-ban-rearranging-deck-chairs-on-the-titanic

RE: https://floss.social/@gisgeek/115679063672736382

@gisgeek brings up some interesting and salient points about FOSS.

Check it out!

A brief post inspired by a recent @poller post, about FOSS at a dead end for security.

https://lovergine.com/too-many-eyes-or-too-few-efforts.html

#foss #security #governance #dev

Too many eyes or too few efforts? — frankie-tales

AI safety ≠ AI security, and confusing them leaves you vulnerable on multiple fronts.
Safety = keeping your model ethical
Security = protecting systems from attackers
Your AI can be "safe" yet catastrophically insecure (or vice-versa).

Learn more: https://paradigmtechnica.com/2025/12/04/beyond-the-buzzwords-what-ai-safety-and-security-actually-mean-and-why-it-matters/

Beyond the Buzzwords: What AI Safety and Security Actually Mean (And Why It Matters) – Paradigm Technica

The "many eyes" myth is dead. Shai-Hulud, S1ngularity, and other attacks prove open source needs dedicated security teams, not just volunteers. AI-powered attackers are winning. Time to build something better.
Read my take here:
https://paradigmtechnica.com/2025/12/03/the-open-source-security-myth-why-many-eyes-arent-enough-anymore/
#opensource #security

🔐 In the AI Era, Resilience Determines Who Leads and Who Falls Behind

AI amplifies everything, including failure.

My latest article explores why AI resilience is different and what it takes to turn your greatest risk into sustainable advantage.

https://www.linkedin.com/pulse/building-ai-resilience-turning-your-greatest-risk-advantage-poller-odjwe

#CommvaultShift

Building AI Resilience: Turning Your Greatest Risk into Sustainable Advantage

In the AI Era, Resilience Determines Who Leads and Who Falls Behind In the AI era, resilience isn’t about avoiding failure—it’s about ensuring failure never becomes catastrophic. As organizations deploy AI at unprecedented scale, the question isn’t if disruption will occur, but how quickly you’ll re

Tycoon 2FA proves legacy MFA is dead!

The fix isn't harder passwords. It's hardware-backed cryptographic auth: no phishing or proxies.

Move beyond "something you know" to "something attackers can never steal."
🔐 Full analysis:
https://securityboulevard.com/2025/11/the-death-of-legacy-mfa-and-what-must-rise-in-its-place/
#Cybersecurity #MFA #FIDO2 #ZeroTrust #InfoSec

The Death of Legacy MFA and What Must Rise in Its Place

Tycoon 2FA proves that the old promises of “strong MFA” came with fine print all along: when an attacker sits invisibly in the middle, your codes, pushes,

Security Boulevard