Security101's Avatar

Security101

@security101.bsky.social

CISO enjoying every day of his profession.

24 Followers  |  79 Following  |  1 Posts  |  Joined: 16.11.2024  |  1.7519

Latest posts by security101.bsky.social on Bluesky

Ein Vorhängeschloss aus Metall liegt auf pink-violetten Leiterplatten. Darunter steht auf dunkelblauem Hintergrund in großer weißer Schrift: "Kryptographische Empfehlungen (TR-02102) aktualisiert". In kleinerer weißer Schrift darunter steht: "BSI empfiehl

Ein Vorhängeschloss aus Metall liegt auf pink-violetten Leiterplatten. Darunter steht auf dunkelblauem Hintergrund in großer weißer Schrift: "Kryptographische Empfehlungen (TR-02102) aktualisiert". In kleinerer weißer Schrift darunter steht: "BSI empfiehl

Wir empfehlen das Ende klassischer asymmetrischer Verschlüsselungsverfahren & sprechen uns in der jährlichen Aktualisierung unserer kryptographischen Empfehlungen (TR-02102) erstmals für ein Ablaufdatum dieser aus. Die Zukunft: #Post-Quanten-Kryptographie.

👉️ https://www.bsi.bund.de/dok/1192230

11.02.2026 11:30 — 👍 11    🔁 6    💬 0    📌 0
https://allthingsopen.org/wp-content/uploads/2025/06/helm-chart-scan-1024x778.png

https://allthingsopen.org/wp-content/uploads/2025/06/helm-chart-scan-1024x778.png

This article shows how to scan Helm charts for insecure RBAC, secret leaks, and malicious templates using tools like Trivy, GitHub Search, and OPA

➜ https://ku.bz/k4MpGVLyZ

11.02.2026 18:26 — 👍 0    🔁 1    💬 0    📌 0
https://miro.medium.com/v2/1*IG_Vh6FgW1jnOA1W2PKhNg.png

https://miro.medium.com/v2/1*IG_Vh6FgW1jnOA1W2PKhNg.png

This article explains the risks of using unmaintained Docker images and how to detect vulnerabilities with tools like Trivy, SBOM operator, and Dependency Track

➜ https://ku.bz/WJ75qXRbV

09.02.2026 18:51 — 👍 0    🔁 1    💬 0    📌 0
Preview
Everyone Says AI Is Insecure, So I Measured It | HackerNoon The uncomfortable but ultimately empowering truth is that a significant number of so-called AI "risks" are, in fact, old security problems wearing new language.

Everyone Says AI Is Insecure, So I Measured It #Technology #Cybersecurity #AIsecurity #CyberThreats #DataProtection

https://hackernoon.com/everyone-says-ai-is-insecure-so-i-measured-it?source=rss

08.02.2026 07:54 — 👍 0    🔁 1    💬 0    📌 0

https://github.com/PAPAMICA/waf-checker

07.02.2026 03:34 — 👍 0    🔁 1    💬 0    📌 0

https://github.com/marceloprates/prettymaps

06.02.2026 02:43 — 👍 0    🔁 1    💬 0    📌 0
Preview
AI Is Rewriting Compliance Controls and CISOs Must Take Notice AI agents are now executing regulated actions, reshaping how compliance controls actually work. Token Security explains why CISOs must rethink identity, access, and auditability as AI becomes a digital employee.

AI Is Rewriting Compliance Controls and CISOs Must Take Notice #cybersecurity #hacking #news #infosec #security #technology #privacy

29.01.2026 21:26 — 👍 0    🔁 1    💬 0    📌 0
ShinyHunters Claims Breach of Crunchbase, Betterment via Okta Vishing Attacks The ShinyHunters extortion group has claimed responsibility for breaching Crunchbase and Betterment by using voice phishing (vishing) to defeat Okta single sign-on (SSO) security.

Cybercrime group ShinyHunters claims to have breached Crunchbase & Betterment by using voice phishing (vishing) to bypass Okta SSO. 📞 The attack highlights the risk of non-phishing-resistant MFA. #Vishing #ShinyHunters #Okta #CyberSecurity

29.01.2026 21:34 — 👍 0    🔁 1    💬 0    📌 0
Preview
Federal Government Rescinds Software Supply Chain Mandates, ... The U.S. government is rolling back software supply chain mandates, shifting from mandatory SBOMs and attestations to a risk-based approach.

SBOMs are no longer mandatory for federal agencies. New guidance rescinds prior software supply chain mandates and shifts to agency-defined risk assessment.

Details → socket.dev/blog/federal... #Cybersecurity #GovTech

29.01.2026 03:15 — 👍 3    🔁 4    💬 0    📌 0
Preview
A Modern Guide to Vulnerability and Threat Management Learn how modern vulnerability and threat management moves beyond CVE lists to safe, automated remediation that fixes what other tools only flag.

"A Modern Guide to Vulnerability and Threat Management" by Barak Klinghofer, CEO and Co-Founder of Reclaim Security from January 6, 2026 api.cyfluencer.com/s/a-modern-g...

29.01.2026 04:55 — 👍 5    🔁 4    💬 1    📌 0
GitGuardian Security Your Secrets with ggshield

GitGuardian Security Your Secrets with ggshield

Cheat Sheet Alert! "How To Use ggshield To Avoid Hardcoded Secrets" by Dwayne McDaniel from @gitguardian.com December 10, 2025. GitGuardian's ggshield can help you quickly find any secrets in your repos, local files, archives, and commits.
cybersec.gitguardian.com/s/how-to-use...

28.01.2026 16:15 — 👍 5    🔁 4    💬 0    📌 0
Post image

Cybercriminals are using 'rn' to mimic 'm' in domains, impersonating Microsoft & Marriott. Stay alert! #Phishing #CyberSecurity #OnlineSafety Link: thedailytechfeed.com/cybercrimina...

26.01.2026 17:52 — 👍 0    🔁 1    💬 0    📌 0
Post image

GitHub code→cloud traceability is here.
Triage alerts by what’s deployed.
Tag first: exposure, data, or prod?
github.blog/changelog/2...

#SupplyChainSecurity #Cybersecurity

26.01.2026 17:56 — 👍 0    🔁 1    💬 0    📌 0
Verge headline: It doesn't matter if Alex Pretty had a gun
by Sarah Jeong

Photo by Steven Garcia depicts several masked law enforcement agents soaked in red light at night

Verge headline: It doesn't matter if Alex Pretty had a gun by Sarah Jeong Photo by Steven Garcia depicts several masked law enforcement agents soaked in red light at night

"Why is it so normal for law enforcement — those who are supposed to be keepers of law and order — to kill Americans? And why is the only question at the end of the day how much their victims deserved to die?"

Read more from @sarahjeong.bsky.social: www.theverge.com/policy/86745...

25.01.2026 17:12 — 👍 9513    🔁 2920    💬 472    📌 162
Screenshot of a TikTok video with error message at top saying “your video is under review and can’t be shared right now.”

Screenshot of a TikTok video with error message at top saying “your video is under review and can’t be shared right now.”

This morning, I recorded a video on TikTok about why DHS’s arguments for the power to enter homes without judicial warrants in immigration cases are bunk.

Nine hours later, TikTok still says my video is “under review,” and can’t be shared.

Well, here’s a link:

georgetown.box.com/v/Vladeck-IC...

26.01.2026 02:00 — 👍 10221    🔁 4271    💬 468    📌 356
Preview
Proposed Israeli cyber law calls for cyber incident reporting in real time Russia is likely the source of wiper malware that targeted Poland's energy sector, Russian national pleads guilty to targeting 50 victims with ransomware, DPRK group Konni is targeting blockchain engi...

A lot happened over the weekend. Check out today's Metacurity for the most critical infosec developments you might have missed, including

--Proposed Israeli cyber law calls for cyber incident reporting in real time, 1/5
www.metacurity.com/proposed-isr...

26.01.2026 14:40 — 👍 5    🔁 5    💬 1    📌 0

https://github.com/mostafa-wahied/portracker

24.01.2026 00:17 — 👍 0    🔁 1    💬 0    📌 0

https://github.com/warp-tech/warpgate

23.01.2026 11:37 — 👍 0    🔁 1    💬 0    📌 0
Post image

The cloud complexity gap keeps growing.
Fortinet’s 2026 report highlights tool sprawl, weak visibility, and talent shortages slowing cloud threat response.

What’s your take?
#CloudSecurity #CyberSecurity #MultiCloud

21.01.2026 16:08 — 👍 0    🔁 1    💬 1    📌 0
Evelyn Stealer Malware Targets Software Developers via Visual Studio Code Extensions Evelyn Stealer targets software developers by delivering malware via malicious Visual Studio Code extensions to steal credentials and crypto data.

Full Article: www.technadu.com/evelyn-steal...

Are developer environments receiving enough security attention? Comment below.
#CyberSecurity #Malware #Developers #DevSecOps #SupplyChainRisk

20.01.2026 17:15 — 👍 1    🔁 1    💬 0    📌 0
Preview
ETSI releases world-leading standard for securing AI ETSI releases world-leading standard for securing AI

🇪🇺 ETSI releases world-leading AI security standard — New global standard aims to secure AI systems across the lifecycle, boosting trust, safety & resilience in AI deployment. A major step for interoperable, secure AI worldwide. #AI #CyberSecurity #Standardization

19.01.2026 09:42 — 👍 0    🔁 1    💬 0    📌 0
Preview
GCVE startet öffentliche Schwachstellen-Datenbank db.gcve.eu Die GCVE-Initiative launcht mit db.gcve.eu eine offene Schwachstellen-Datenbank. Die Plattform aggregiert Daten aus über 25 Quellen und bietet kostenfreien API-Zugang für Sicherheitsforscher.

GCVE startet öffentliche Schwachstellen-Datenbank
Die Global Cybersecurity Vulnerability Enumeration Initiative hat mit db.gcve.eu eine neue zentrale Anlaufstelle für Schwachstelleninformationen geschaffen.
www.all-about-security.de/gcve-startet...
#cybersecurity #cve #schwachstellen

18.01.2026 10:41 — 👍 0    🔁 1    💬 0    📌 0
Preview
Reprompt attack hijacked Microsoft Copilot sessions for data theft Researchers identified an attack method dubbed "Reprompt" that could allow attackers to infiltrate a user's Microsoft Copilot session and issue commands to exfiltrate sensitive data.

Apparently #CoPilot can open links, and will parse anything after a "q" parameter in the URL as a query.

Headline: #Reprompt attack hijacked #Microsoft Copilot sessions for data theft

Link: www.bleepingcomputer.com/news/securit...

#Privacy #Security #CyberSecurity

16.01.2026 23:57 — 👍 0    🔁 2    💬 0    📌 0
Preview
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks A critical misconfiguration in Amazon Web Services (AWS) CodeBuild could have allowed complete takeover of the cloud service provider's own GitHub repositories, including its AWS JavaScript SDK, putting every AWS environment at risk. The vulnerability has been codenamed CodeBreach by cloud security company Wiz. The issue was fixed by AWS in September 2025 following responsible disclosure on
15.01.2026 19:31 — 👍 0    🔁 1    💬 0    📌 0

An engineer leaves your company. Access revoked. Laptop returned.

But their commits are still across dozens of repos.

For compliance audits, you need to know: which code was authored by former employees? 🧵

15.01.2026 15:15 — 👍 1    🔁 1    💬 1    📌 0
Preview
Multi-Agent Platform with A2A, Python, Strands & AWS AgentCore A single RAG agent is easy to ship. But the moment you need multiple domains (HR, IT, …), different...

Multi-Agent Platform with A2A, Python, Strands & AWS AgentCore https://cstu.io/9ee36c #cybersecurity #india #techno

14.01.2026 08:56 — 👍 0    🔁 1    💬 0    📌 0
Preview
Allianz Risk Barometer 2026: Cyberrisiken führen das Ranking an, KI rückt auf Platz zwei vor Das Allianz Risk Barometer 2026 zeigt Cyberrisiken weiterhin als größtes Geschäftsrisiko weltweit. Künstliche Intelligenz steigt stark auf und gewinnt auch in Deutschland an Bedeutung.

Allianz Risk Barometer 2026: Cyberrisiken führen das Ranking an, KI rückt auf Platz zwei vor - In Deutschland verschieben sich die Risikoschwerpunkte zusätzlich durch regulatorische Veränderungen.
www.all-about-security.de/allianz-risk...
#cybersecurity #KI #ransomware

14.01.2026 10:28 — 👍 1    🔁 2    💬 0    📌 0
Preview
CISO Assistant: Open-source cybersecurity management and GRC - Help Net Security CISO Assistant is an open-source governance, risk, and compliance (GRC) platform designed to help security teams document risks, controls, and framework

CISO Assistant: Open-source cybersecurity management and GRC

📖 Read more: www.helpnetsecurity.com/2026/01/14/c...

#cybersecurity #cybersecuritynews #CISO #GRC #opensource

14.01.2026 11:41 — 👍 1    🔁 1    💬 0    📌 0
Preview
CISO Succession Crisis Highlights How Turnover Amplifies Risks When cybersecurity leadership turns over too fast, risk does not reset. It compounds.

CISO Succession Crisis Highlights How Turnover Amplifies Security Risks #cybersecurity #hacking #news #infosec #security #technology #privacy

14.01.2026 13:08 — 👍 0    🔁 1    💬 0    📌 0
Preview
'Most Severe AI Vulnerability to Date' Hits ServiceNow ServiceNow tacked agentic AI onto a largely unguarded legacy chatbot, exposing customers' data and connected systems.

'Most Severe AI Vulnerability to Date' Hits ServiceNow #cybersecurity #hacking #news #infosec #security #technology #privacy

14.01.2026 14:55 — 👍 0    🔁 1    💬 0    📌 0

@security101 is following 20 prominent accounts