Roger A. Grimes

157 Followers
48 Following
1.8K Posts
Roger A. Grimes, CPA, CISSP, CEH, MCSE, CISA, CISM, CNE, yada, yada, Data-Driven Defense Evangelist for KnowBe4, Inc., is the author of 14 books and over 1400 articles on computer security, specializing in host security and preventing hacker and malware attacks. Roger is a frequent speaker at national computer security conferences and was the weekly security columnist at InfoWorld and CSO magazines between 2005 - 2019. He has worked at some of the world’s largest computer security companies, including, Foundstone, McAfee, and Microsoft. Roger is frequently interviewed and quoted in the media including Newsweek, CNN, NPR, and WSJ. His presentations are fast-paced and filled with useful facts and recommendations.
computer securityphishing
hackershacking
webinarspresenting
data driven defensedefense
malwarewindows
PolyKG Discovers Previously Unreported OilRig Samples Using Stolen Cert

Using PolyKG, PolySwarm analysts have identified previously unreported OilRig activity leveraging a stolen Entrust Extended Validation (EV) code signing certificate issued to Thai IT vendor MOSCII Corporation.

FBI Director Kash Patel's personal email was compromised by Iranian hackers and they publish his stuff online

https://www.msn.com/en-us/news/politics/iran-linked-hackers-breach-fbi-directors-personal-email-publish-excerpts-online/ar-AA1Zy0nq

MSN

Foreshadowing a growing trend

CERN scientists successfully transport universe-killing anti-matter in a truck. First one went swell. Cue any Tom Clancy novel for the next transport attempt.

https://www.msn.com/en-us/news/technology/physicists-successfully-deliver-first-bottle-of-cern-antimatter-from-the-antimatter-factory/ar-AA1ZoPj4

MSN

Hilarious. Guy created AI bot that interfaced with his text scammers...driving them crazy

This is huge Quantum news! Google moves their Q-Day date estimate to 2029. When is NIST going to update their 2030/2035 dates?? After RSA is broken??

https://arstechnica.com/security/2026/03/google-bumps-up-q-day-estimate-to-2029-far-sooner-than-previously-thought/

Google bumps up Q Day deadline to 2029, far sooner than previously thought

Company warns entire industry to move off RSA and EC more quickly.

Ars Technica

My colleague, Martin Kraemer, writes an awesome article summarizing how to securely implement AI agents, Best Practices for Implementing AI Agents. It's a GREAT summary article.

https://blog.knowbe4.com/best-practices-for-implementing-ai-agents

The only thing I would add is that all of his suggestions should begin and include an extensive threat model. It's implied. But if you aren't threat modeling your AI implementation, you should. Most aren't doing it. If you aren't doing it, stop what you are doing and create and implement a threat model...on all AI. And this really even applies if you are just a user of AI. Your AI can be used against you. Threat model. Threat model. Threat model.

Best Practices for Implementing AI Agents

One SQL Injection, Millions of Messages. On March 9th, Codewall.ai disclosed how it had hacked McKinsey & Company’s AI platform called Lilli...

Greek spyware maker, who only sold to government clients was sentenced to 126 in prison...is now ready to spill all on his government clients and politicians. Said he his being treated as the fall guy in a huge gov't spying scandal.

https://risky.biz/risky-bulletin-the-intellexa-ceo-is-pissed/

Risky Bulletin: The Intellexa CEO is pissed!!! - Risky Business Media

The CEO of a major spyware vendor says he is being scapegoated by the Greek government and is willing to testify and spill the beans on th [Read More]

I'm so excited!!!! Alex Honnold, super free solo climber, of El Captain and the 101-story Taipei 101 skyscraper fame, will be a keynote speaker at our May 12-14 KB4-CON 2026 at the Orlando World Center Marriott

https://www.knowbe4.com/kb4-con