Shecky - Third Wheel

958 Followers
221 Following
3.6K Posts
Dad, Security Engineer, Burbsec North Organizer, KQL nerd, BlueTeam, N9HAK, Padawan, Theatre Actor/Tech Man, Train Hobbyist, "Dammit Shecky" Opinions and more, GCIH, CISSP
Bloghttps://siliconshecky.com
Verificationhttps://twittodon.com/share.php?t=siliconshecky&[email protected]
Blueskyhttps://bsky.app/profile/siliconshecky.bsky.social
Decentralized servers (like we have on the Fediverse) are often seen as a new, radical concept but that was *the entire point of creating internets in the first place*. 😖
Two Git Commands Fooled Claude Into Merging Malicious Code https://packetstorm.news/news/view/41219 #news
Two Git Commands Fooled Claude Into Merging Malicious Code - Manifold Security

Coding agents are on your endpoints. Do you know what they're doing? Manifold gives security teams runtime visibility into autonomous AI agents.

Laser-based hardware attacks are only for nation-state actors with million-dollar labs. Right?
Wrong.
At BSides312, Larry Trowell and Sam Beaumont (PANTH13R) from NetSPI built affordable laser tools using an open-source microscope and consumer-grade lasers to detect hardware malware and supply chain chip swaps.
Hackers go pew pew.
May 16th. Chicago.
🎟️ https://bsides312.org
#BSides312 #InfoSec #HardwareHacking #SupplyChainSecurity #CyberSecurity #Chicago #BSides #THOTCON
AI and its hallucinations look to be the new boy who cried wolf for SOC/IR. This is why we still need boots on the ground and not automated decisions without human validation.
https://cyberscoop.com/ai-generated-breach-narratives-ghost-threat-vector-op-ed/
Ghost breaches: How AI-mediated narratives have become a new threat vector

Think your company is secure? A "ghost breach" says otherwise. Discover how AI-mediated narratives are fabricating realistic data leaks, forcing firms into high-stakes crisis responses for incidents that never happened.

CyberScoop

Tomorrow morning I'm keynoting the Southeast Cybersecurity Summit. Can't wait to see you there!

I'll also be talking on a panel about AI in security later in the day. I'll be around most of the day. Track me down - I'd love to talk!
https://www.secybersecurity.com/

Southeast Cybersecurity Summit 2026 | April 15 - 16, 2026

The purpose of the Summit is to strengthen and promote the internet security profession in the southeastern United States region.

Most clients struggling with AI governance are struggling because they haven't fully defined their enterprise data governance requirements.

You can't code "people will use their judgment" into coherent AI governance, as much as you might want to.

I had a chat with Paul McCarty about his project Open Source Malware

Paul has a ton of great insight into what's happening with the massive influx of malware into our open source ecosystems

https://opensourcesecurity.io/2026/2026-04-open-source-malware-paul-mccarty/

Open Source Malware with Paul McCarty

Josh talks to Paul McCarty of Open Source Malware about … open source malware. Paul explains why there aren’t many good open source malware datasets. We discuss why the existing data is lacking for many use cases. We of course touch on AI and the malware in skills problems and challenges. It’s a fun discussion with a lot of new and interesting problems we all have to deal with. Episode Links Paul McCarty Open Source Malware Open Source Malware Blog This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.

Open Source Security
Redid my website siliconshecky.com so it looked newer when I wrote new blogs. Damn if I ain't wrote shit. Damn if I can't come up with something to write. Opinion pieces are a dime a dozen and I want substance which is tough for me.
Shouldn’t have taken this long for the market to turn on Palantir
Yesterday my #push4progress included a major test for the stability of my right knee. No brace on a slackline. Yes I had a crutch above but am proud of the advancement I made.