Paul Wagenseil

@wagenseil@infosec.exchange
148 Followers
227 Following
272 Posts
Custom content creator, CyberRisk Alliance. Former security editor, Tom's Guide. Opinions my own. Likes & re"toots" are not all endorsements.
Funny how blockchain isn't a thing anymore now that LLMs are here.
At BSidesSF & RSAC, Ira Winkler & Ian Amit explain how we're getting AI all wrong https://www.scworld.com/news/rsac-2025-if-everything-is-ai-then-nothing-is-ai
RSAC 2025: 'If everything is AI, then nothing is AI'

We fundamentally misunderstand what AI is, what it can do, and how it should be regulated, two researchers said at the BSides SF and RSAC information-security conferences last week.

SC Media

Today's the day. May 4, 2000 the ILOVEYOU worm took the world by storm. @0xBennyV and @chetwisniewski have all the gory details of this milestone event in computer security history 25 years on.

https://securitytaketwo.com/iloveyou/
#InfoSec #Podcast #ILOVEYOU

ILOVEYOU

Security Take(s) Two - ILOVEYOU

Security Take Two - Real. Serious. Security.
At #BSidesSF, Cato's Matan Mittelman shows how to control malware using cloud-based office tools https://www.scworld.com/news/bsides-sf-how-consumer-cloud-services-can-command-and-control-malware
BSides SF: How consumer cloud services can command and control malware

Safe-seeming cloud services like Google Drive and Trello have everything attackers need to remotely control infected hosts, and most defenders have no idea.

SC Media
Fascinating stuff from #BSidesSF -- Aikido's @advocatemack shows how ChatGPT can spot undisclosed vulnerability patches in open-source software https://www.scworld.com/news/bsides-sf-using-ai-to-spot-shadow-patches-in-open-source-software
BSides SF: Using AI to spot shadow patches in open-source software

An indisputable security use case for ChatGPT: scouring open-source changelogs for undisclosed vulnerability patches.

SC Media
RSAC 2025: Ex-CISA head Krebs defiantly urges infosec community to keep up the good fight

Facing a politically motivated Justice Department investigation, former CISA director Chris Krebs was warmly welcomed at the RSAC conference as he led a panel discussion of national-security luminaries.

SC Media

Chris Krebs today at RSA:

"I almost didn't come out here this week. I made a promise, though, to Dr. Hugh Thompson, the chairman of the conference, that I'd come out and I'd do this panel, so I did it. I'd like to think that I'm a man of my word.

So I showed up. And I want to say I'm completely and utterly thankful that I did, because of you. All of you have been hugely supportive.

And not just of me, but the community. It's the community that right now is in distress, that's under attack, that's being picked at from all sides.

Cybersecurity is national security. We see it in this show. Every one of you -- I don't care if you are a sales rep, an engineer, whatever -- you are on the front lines of modern warfare.

You are the ones that will see the first Chinese attack. You're the ones that are dealing with cybercriminals and child sexual predators on a daily basis. You are the front lines right now. There is no such thing as geographic distance for defense any more.

So thank you for what you do on a daily basis. Please stay in the fight. Do not lose the faith. Don't let 'em grind you down. We have to win this. We will win this. Thank you."

How to stay on Windows 10 instead of installing Linux (by @lproven): Turns out that Microsoft will support Windows 10 until 2032 *if* you can live without their cloud and AI bullshit: just download/install an obscure version aimed at corporate clients who want long-term support:

https://www.theregister.com/2025/04/22/windows_10_ltsc/?td=rt-3a

(I'm a macOS/Linux guy, but if I had an old Win10 box and wanted to avoid Windows 11 and Recall this would be a great way forward)

How to stay on Windows 10 instead of installing Linux

: Can't run Windows 11? Don't want to? There are surprisingly legal options

The Register

This pisses me off.

Many folks on here have been vocal about the bullshit pillory of Chris Krebs, sure.

But the big name cybersecurity firms just kowtowing to Trump indicates their own capitulation to the regime.

On their heads be it. Fuck em.

https://www.forbes.com/sites/tonybradley/2025/04/16/deafening-silence-from-the-cybersecurity-industry/

Deafening Silence From The Cybersecurity Industry

Chris Krebs affirmed the 2020 election was secure. Now he's the target of an Executive Order—and the cybersecurity industry’s silence is enabling a dangerous precedent.

Forbes

pooh riff:

the wonderful thing about tariffs
is tarriffs are wonderful things
my head is made out of rubber but
the market is made out of springs
It's bouncey, trouncey, ouncey, pouncey
fun, fun, fun, fun, fun
but the most wonderful thing about tarriffs
is i have just begun.