Mark Carter's Avatar

Mark Carter

@markcarter.bsky.social

#CISO #startup founder #engineering #infosec #cloud #machinelearning #sre @vimeo previously: @salesforce @awscloud @tesla @google @paypal *Opinions my own

180 Followers  |  1,704 Following  |  30 Posts  |  Joined: 07.01.2024  |  1.7799

Latest posts by markcarter.bsky.social on Bluesky

For all of you who proudly served our nation ๐Ÿ‡บ๐Ÿ‡ธ thank you ๐Ÿ™ On this veteran day and every day #usa

11.11.2025 16:39 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Bank of America Discloses Data Breach After Customers' Documents Disappear, Says Names, Addresses, Account Information and Social Security Numbers Affected - The Daily Hodl Bank of America says efforts to locate sensitive documents containing personal information on an undisclosed number of customers have failed. The North Carolina-based bank says it is unable to recover...

๐Ÿ›ก๏ธ Bank of America Discloses Data Breach After Customersโ€™ Documents Disappear, Says Names, Addresses, Account Information and Social Security Numbers Affected dailyhodl.com/2025/04/12/b... #Infosec

13.04.2025 05:27 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Agent2Agent Protocol An open protocol enabling communication and interoperability between opaque agentic applications.

Great to see authentication and authorization finally integrated into agentic AI ๐Ÿ›ก๏ธ Very excited about Agent2Agent Protocol (A2A) ๐Ÿ‘ well written technical documentation. Recommended read google.github.io/A2A/#/docume... #MachineLearning #Infosec

10.04.2025 03:51 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿค” NIST Trustworthy and Responsible AI
NIST AI 100-2e2025 - Adversarial Machine Learning
A Taxonomy and Terminology of Attacks and Mitigations nvlpubs.nist.gov/nistpubs/ai/... #Infosec

27.03.2025 13:37 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Alphabet in Talks to Buy Cloud Security Firm Wiz for $33 Billion Alphabet Inc. is in talks to purchase cloud-security company Wiz Inc. for $33 billion, restarting discussions that were called off last summer after extended negotiations, according to people familiar...

๐Ÿคฏ Alphabet Inc. Said in Talks to Buy Cyber Firm Wiz for $33 Billion www.bloomberg.com/news/article... #Infosec #Google

18.03.2025 02:02 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
AI coding assistant refuses to write code, tells user to learn programming instead Cursor AI tells user, โ€œI cannot generate code for you, as that would be completing your work.โ€โ€ฆ

๐Ÿ˜œ An AI Coding Assistant Refused to Write Codeโ€”and Suggested the User Learn to Do It Himself arstechnica.com/ai/2025/03/a... #AI

15.03.2025 22:14 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
TELUS Digital Survey Reveals Enterprise Employees Are Entering Sensitive Data Into AI Assistants More Than You Think Nearly seven out of 10 (68%) enterprise employees who use generative AI (GenAI) at work say they access publicly available GenAI assistants such as Ch

๐Ÿค” 57% of enterprise employees admit to entering high-risk information into publicly available generative AI assistants, exposing critical security gaps in enterprise AI usage www.businesswire.com/news/home/20... #Infosec

26.02.2025 13:07 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
OmniParser V2: Turning Any LLM into a Computer Use Agent - Microsoft Research Yadong Lu, Senior Researcher; Thomas Dhome-Casanova, Software Engineer; Jianwei Yang, Principal Researcher; Ahmed Awadallah, Partner Research Manager Graphic User interface (GUI) automation requires a...

๐Ÿ‘ Microsoft Research OmniParser V2: Turning Any LLM into a Computer Use Agent www.microsoft.com/en-us/resear... #MachineLearning

16.02.2025 12:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Amazon Q Developer now supports upgrade to Java 21 - AWS Discover more about what's new at AWS with Amazon Q Developer now supports upgrade to Java 21

๐Ÿ‘ Amazon Q Developer now supports upgrade to Java 21. In just a few steps, update applications to the latest supported Java versions, gain performance benefits, and remove vulnerabilities in unsupported versions. aws.amazon.com/about-aws/wh... #aWS #Infosec

15.02.2025 01:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Benefits of the M&A Frenzy in Fraud Solutions As cybercriminals exploit AI-generated deepfake scams and synthetic identity fraud, financial institutions are investing heavily in fraud detection, anti-money

๐Ÿค” The Benefits of the M&A Frenzy in Fraud Solutions - Emerging Vendors, Consolidation Drive Innovation in Fraud, AML, Scam Prevention. The Global Anti-Scam Alliance reported that scammers stole $1.03 trillion in 2024. www.bankinfosecurity.com/benefits-ma-...

15.02.2025 00:44 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
MGM agrees to pay $45 million to victims of 2019 data breach and 2023 ransomware attack MGM Resorts International agreed to pay $45 million to settle multiple class action lawsuits related to a data breach in 2019 and a ransomware attack the company experienced in 2023.

๐Ÿค” MGM agrees to pay $45 million to victims of 2019 data breach and 2023 ransomware attack therecord.media/mgm-agrees-4... #Infosec #Law

29.01.2025 01:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
What Is Chinaโ€™s DeepSeek and Why Is It Freaking Out the AI World? (Bloomberg) -- DeepSeek, a Chinese AI startup thatโ€™s just over a year old, has stirred awe and consternation in Silicon Valley after demonstrating breakthrough artificial-intelligence models that offe...

What Is Chinaโ€™s DeepSeek and Why Is It Freaking Out the AI World? www.yahoo.com/news/china-d... #MachineLearning

27.01.2025 13:27 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Towards System 2 Reasoning in LLMs: Learning How to Think With Meta Chain-of-Thought We propose a novel framework, Meta Chain-of-Thought (Meta-CoT), which extends traditional Chain-of-Thought (CoT) by explicitly modeling the underlying reasoning required to arrive at a particular CoT....

Interesting read ๐Ÿค” Towards System 2 Reasoning in LLMs: Learning How to Think With Meta Chain-of-Thought arxiv.org/abs/2501.04682 #MachineLearning

10.01.2025 13:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Information Technology (IT) Sector-Specific Goals (SSGs) | CISA

Excellent set of Metrics ๐Ÿ›ก๏ธ CISA Issues New Goals to Strengthen IT Cybersecurity www.cisa.gov/resources-to... #Infosec

08.01.2025 04:29 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
RICTOR Unveils the World's First Amphibious Passenger Flying Motorcycle, Equipped with Automatic Route Planning and Takeoff/Landing System /PRNewswire/ -- In recent years, the rapid advancement of technology and the growing demand for diversified travel options have brought eVTOL technology into...

๐Ÿ˜ฎ RICTOR Unveils the World's First Amphibious Passenger Flying Motorcycle, Equipped with Automatic Route Planning and Takeoff/Landing System www.prnewswire.com/news-release...

08.01.2025 01:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Bad Tenable plugin updates take down Nessus agents worldwide Tenable says customers must manually upgrade their software to revive Nessus vulnerability scanner agents taken offline on December 31st due to buggy differential plugin updates.

Bad Tenable plugin updates take down Nessus agents worldwide ๐Ÿค” fixing the issue requires manually upgrading www.bleepingcomputer.com/news/securit... #Infosec

04.01.2025 00:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
The SSO Wall of Shame A list of vendors that treat single sign-on as a luxury feature, not a core security requirement.

The SSO Wall of Shame ๐Ÿค” A list of vendors that treat single sign-on as a luxury feature, not a core security requirement. sso.tax #Infosec

04.01.2025 00:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Wishing an amazing 2025 to everyone ๐ŸŽ‡ happy new year ๐Ÿฅณ๐Ÿ’ƒ๐Ÿ‘ฏโ€โ™‚๏ธ

01.01.2025 03:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
China-backed hackers breached US Treasury workstations | CNN Business The US Treasury Department notified lawmakers on Monday that a China state-sponsored actor infiltrated Treasury workstations in what officials are describing as a โ€œmajor incident.โ€

๐Ÿ›ก๏ธ โ€˜Major incidentโ€™: China-backed hackers breached US Treasury workstations www.cnn.com/2024/12/30/i... #Infosec

30.12.2024 21:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Principal Engineer Roles Framework I have worked on Amazon S3 for ~12 years and if there is one thing that I have learned, it is that when you run complex systems at scale, you must think deeply about how teams work. Itโ€™s not enough to...

Good read ๐Ÿค” #AWS Principal Engineer Roles Framework. In Amazon, a Principal Engineer is a very senior engineer who set direction on the evolution of your code, shape the culture of your engineering and operations, and improve your product roadmap. www.linkedin.com/pulse/princi...

23.12.2024 18:15 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Convincing a billion users to love passkeys: UX design insights from Microsoft to boost adoption and security | Microsoft Security Blog Passkeys offer faster, safer sign-ins than passwords. Read Microsoft tips for encouraging users to adopt passkeys for improved security.

The era of passwords is ending ๐Ÿ‘ Convincing a billion users to love passkeys: UX design insights from #Microsoft to boost adoption. At Microsoft, we block 7,000 attacks on passwords per secondโ€”almost double from a year ago www.microsoft.com/en-us/securi... #Infosec

15.12.2024 07:04 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
I just saw the future of the web โ€” Google's new Deep Research tool unleashes swarms of AI agents to do in-depth research for you A Gemini feature that has to be seen to be believed

๐Ÿ‘ I just saw the future of the web โ€” Google's new Deep Research tool unleashes swarms of AI agents to do in-depth research for you www.tomsguide.com/ai/google-ge... #AI

12.12.2024 01:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
White House: Salt Typhoon hacked telcos in dozens of countries โ€‹Chinese state hackers, known as Salt Typhoon, have breached telecommunications companies in dozens of countries, President Biden's deputy national security adviser Anne Neuberger said today.

๐Ÿ›ก๏ธ Chinese state hackers have breached telecommunications companies in dozens of countries including 8 in #USA President Biden's deputy national security adviser Anne Neuberger said today www.bleepingcomputer.com/news/securit... #Infosec #China

05.12.2024 02:40 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Thinkst Thoughts Writing about our experiences and research findings

TL;DR Our credit card Canarytokens are out of beta. We love these tokens because they provide a novel way to alert on a strong signal of badness blog.thinkst.com #Infosec

04.12.2024 05:36 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Google sues Indian employee over alleged leaks 'See you in court', defendant posts

๐Ÿง‘โ€โš–๏ธ #Google sues Pixel engineer who allegedly posted trade secrets online www.theregister.com/2024/11/28/g... #Infosec #Legal

01.12.2024 02:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Insurance Companies Face $11.3 Million in Fines Due to Cybersecurity Failures | JD Supra In yet another example of the importance of a robust cybersecurity and data protection system, New York Attorney General (OAG) and the New York State...

nY AG and NYDFS collectively fined the insurance companies GEICO and The Travelers Indemnity Company $11.3 million due to a series of data breaches that accessed customer data www.jdsupra.com/legalnews/in... #Infosec

29.11.2024 22:03 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
Insurance Companies Face $11.3 Million in Fines Due to Cybersecurity Failures | JD Supra In yet another example of the importance of a robust cybersecurity and data protection system, New York Attorney General (OAG) and the New York State...

๐Ÿ›ก๏ธ nY AG and NYDFS fined the insurance companies GEICO and The Travelers Indemnity Company $11.3 million due to a series of data breaches that accessed customer data https://www.jdsupra.com/legalnews/insurance-companies-face-11-3-million-3432732/ #Infosec

29.11.2024 22:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I have created a starter pack to shine light on organizations that make notable contributions back to the #infosec community in the form of generous free tiers, valuable webinars, trainings, resources, etc.

I am sure there are others, just DM or reply with any suggestions!

go.bsky.app/NMbiTUL

27.11.2024 16:39 โ€” ๐Ÿ‘ 106    ๐Ÿ” 27    ๐Ÿ’ฌ 13    ๐Ÿ“Œ 1

You've probably seen this great thread around by now bu just want to add pedantic legal point to the ethical discussion. Personal data released publicly in EU/UK does NOT lose its protection under GDPR. That's a US privacy concept. What protection u get may vary but it's not on/off.

27.11.2024 18:53 โ€” ๐Ÿ‘ 29    ๐Ÿ” 18    ๐Ÿ’ฌ 4    ๐Ÿ“Œ 0
Preview
Data broker leaves 600K+ sensitive files exposed online Researcher spotted open database before criminals โ€ฆ we hope

EXCLUSIVE: I spoke with security researcher and discoverer of open databases Jeremiah Fowler about finding 600k+ sensitive files containing thousands of people's criminal histories, background checks, vehicle and property records exposed to the internet in a non-password protected S3 bucket.

27.11.2024 19:02 โ€” ๐Ÿ‘ 20    ๐Ÿ” 10    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 3

@markcarter is following 20 prominent accounts