Node problem: Tracking recent npm package compromises | Red Canary
Recent npm supply chain attacks highlight why robust mitigation and response strategies are required for both developers and users.
Some helpful and topical content posted to @redcanaryco.bsky.social yesterday. Distilled some great guidance from @forensicitguy.bsky.social on securing npm packages + responding to a compromise: redcanary.com/blog/threat-...
24.09.2025 18:59 β π 0 π 0 π¬ 0 π 0
Understanding OAuth application attacks and defenses | Red Canary
Red Canaryβs Threat Hunting team recently uncovered a malicious OAuth application attack, demonstrating the need for specific defenses.
@redcanaryco.bsky.social's Threat Hunting team recently investigated an incident that illustrates how stealthy and patient an OAuth application attack can be. We breakdown the campaign (and how to defend against these attacks) in this blog:
05.09.2025 13:37 β π 0 π 0 π¬ 0 π 0
Front page ad for Prager in the NYT today π₯΄
31.08.2025 15:13 β π 0 π 0 π¬ 0 π 0
Deer Isle Oysters at Pilgrimβs Inn. Could eat a lot of these.
10.08.2025 16:47 β π 0 π 0 π¬ 0 π 0
Ugh, @noupside.bsky.social posted yesterday about this happening to her, too!
24.07.2025 18:01 β π 1 π 0 π¬ 0 π 0
10 Black Hat talks we want to see in 2025 | Red Canary
Talks on bypassing SOCs and initial accessβwe scoured this yearβs list of sessions at Black Hat to find 10 talks worth making time for.
Another new @redcanaryco.bsky.social β¬blog: I'm not going to @blackhatevents.bsky.social this year but if I were, these are the talks I'd try to attend. Lots of stories + intel for defenders: redcanary.com/blog/securit...
24.07.2025 14:42 β π 0 π 0 π¬ 0 π 0
Summercon Foundation
Hey, Summercon is streaming today: www.youtube.com/@SummerconFo...
11.07.2025 15:17 β π 1 π 0 π¬ 0 π 0
Understanding the threat landscape for MCP and AI workflows
We break down the cybersecurity landscape of Model Context Protocol (MCP) servers and agentic AI workflows, including monitoring advice
MCP servers allow developers to facilitate AI agents to execute code. MCP doesn't include security mechanisms howeverβthe onus is on developers to implement standard security best practices. @redcanaryco.bsky.social's Jesse Griggs navigates the MCP threat landscape: redcanary.com/blog/threat-...
11.07.2025 13:14 β π 0 π 0 π¬ 0 π 0
Appreciate what #HillFarmstead does for its Harvest Festival re: curated guest taps, almost like a mini-FW Invitational. I don't think I've been to one since 2011? Whenever you used to be able to camp there afterwards.
08.07.2025 13:18 β π 0 π 0 π¬ 0 π 0
Atomic Red Team
A community for all things related to the Atomic Red Team open source testing library. Use this space to share threat intelligence, suggest new tests, discuss testing priorities, and ask questions abo...
βοΈ Use Atomic Red Team to validate security controls? Test detection coverage? Emulate adversary behaviors? Share how you use the project, suggest new tests, and ask questions at our new subreddit! www.reddit.com/r/atomicredt...
11.06.2025 15:43 β π 0 π 0 π¬ 0 π 0
All about that baseline: Detecting anomalies with Surveyor | Red Canary
The Surveyor open source tool can help organizations establish a baseline of their environment, verify activity, and investigate anomalies.
π« @redcanaryco.bsky.social has a handful of helpful free, open-source tools, including Surveyor, which can help orgs establish a baseline of their environment and in turn, detect potential anomaliesβlike unsanctioned RMM tool usage that can be abused for initial access: redcanary.com/blog/threat-...
05.06.2025 15:20 β π 0 π 0 π¬ 0 π 0
Take a bad thing and make it worse
20.05.2025 18:02 β π 26 π 8 π¬ 3 π 0
We have two. The Hario Blue Bottle one which looks nice and fits easily in the fridge but doesn't make that much and the OXO, which we use more often but makes a bunch but takes up a bit of room on the counter.
08.05.2025 18:29 β π 0 π 0 π¬ 1 π 0
Haim industrial complex is working overtime this year.
28.04.2025 19:54 β π 0 π 0 π¬ 0 π 0
ATT&CK v17: New Platform (ESXi), Collection Optimization, & More Countermeasures
By: Amy Robertson and Adam Pennington
New ATT&CK @attack.mitre.org version (v7) includes ESXi + four new techniques designed for it, expanded cloud security + Linux coverage, new mobile techniques: medium.com/mitre-attack...
23.04.2025 13:10 β π 1 π 0 π¬ 0 π 0
Finally finished The Antidote. Fitting to end with a Land Lost Acknowledgement.
18.04.2025 02:12 β π 1 π 0 π¬ 0 π 0
YouTube video by Lana Del Rey
Lana Del Rey - Henry, come on (Audio)
New Lana song titled something I say literally everyday: www.youtube.com/watch?v=nDYY...
11.04.2025 18:39 β π 0 π 0 π¬ 0 π 0
The RSA Conference talks worth catching in 2025 | Red Canary
How AI agents can help purple teaming, inside the stolen credential ecosystem, and more: We read through the RSA agenda so you don't have to.
Did a deep dive on this year's #RSAC schedule (500+ sessions!) for Red Canary and found what I thought were some interesting talks on adversary emulation, detection engineering, and yes, AIβit's unavoidable! redcanary.com/blog/securit...
03.04.2025 17:45 β π 0 π 0 π¬ 0 π 0
As long as we got a dollar left, we eat good in this house. Words about baseball, board games, food, and more.
Securing data everywhere with Zero Trust + AI to protect your workforce, branches, and clouds.
Senior Intelligence Analyst at Red Canary, former DFIR at Mandiant. Psychology and history nerd. When I am not computering, I go outside and play!
Security without fear since 2018.
https://decipher.sc
https://www.youtube.com/@DecipherSec
24/7/365 threat detection and response across your cloud, identity, endpoints and everything in-between. We got you!
For more information visit: https://redcanary.com/
Principal Analyst @Forrester, covering #DataSecurity. All opinions are my own. She/Her
Community + Content @ Red Canary
Comms by day, craft beer by night. Other half of Gentile Brewing. Wisconsinite turned Masshole.
Researching conservative news and right-wing media. PhD in American Studies from NYU. I teach at but don't speak for the University of Alabama.
News on the Right (http://bit.ly/2YgUcZX).
Pre-order *Making the Liberal Media* (https://shorturl.at/e31nU)!
Former door-to-door knife salesman from Georgia. Current ne'er-do-well in South Philly
Writer. Boston Globe correspondent + words at Boston.com, Down East, Edible, GovTech, Different Leaf, etc. Stop sending alcohol pitches. :)
Herr Doktor Professor Deth Vegetable -- CULT OF THE DEAD COW -- .ooM
Hacker / Archaeologist / Gadabout / Professional Something-or-Other. Anti-fascist and Pro-science. As the old axiom says, reality has a liberal bias.
π§π»βπ»Communications & PR | Listens to Phish βοΈ | Philly native, Former Californian | I also DJ π§
Letβs count the rings around my eyes
Writer/Editor in Brooklyn. Talk to me about infosec, pop music, and black cats.
https://www.nytimes.com/2024/04/16/style/tiny-love-modern-love-stories-the-one-liners-kept-coming.html?smid=nytcore-ios-share&referringSource=articleShare
Sharing my super retro banner image but I look a lot older than this now.
PR elder, cybersecurity roadie, proud papa of 2 boys, accomplished wiseacre, Multiversal social entity.
Editor-in-Chief of Dark Reading, but most of my family & friends have no clue what I do.