Paul Walsh's Avatar

Paul Walsh

@paulwalsh.bsky.social

Most top security firms license my patents for mobile app security. Pioneered zero trust for anti-phishing. Helped to launch @AIM @MetaCert Founder. Co-invented the concept of labeling user accounts on the web at the W3C in 2004. Expert in SMS security.

145 Followers  |  28 Following  |  98 Posts  |  Joined: 20.04.2023  |  1.8894

Latest posts by paulwalsh.bsky.social on Bluesky

Preview
Password Hack Warning As New Threat Jumps From Your Laptop To Phone As if by magic, this password hack jumps from your laptop to your smartphone โ€” but it's you who waves the wand.

This article @forbes.com has now been updated with an interesting counterpoint from @paulwalsh.bsky.social.

#Infosec

www.forbes.com/sites/daveyw...

22.07.2025 12:46 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Number spoofing: are scam filters doing enough to catch dodgy texts? - Which? While hundreds of millions of dodgy texts are blocked, scammers continue to find ways to get them through

Hey Matt, I have detailed reports you might be interested in, that explains *why* SMS surpassed email as the number 1 vector on mobile for phishing and why phishing is still the main entry point for almost all fraud and attacks. Itโ€™s not sophisticated. www.which.co.uk/news/article...

11.08.2025 10:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
elmo from sesame street says " worth a shot " ALT: elmo from sesame street says " worth a shot "

I havenโ€™t signed into this site for quite some time - is it worth it?

04.07.2025 22:44 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Phishing isnโ€™t a human problem. Itโ€™s a failure of the systems meant to protect us. Would you trust the SMS link above? Look closely. The honest answer is, you canโ€™t know without opening it.

Most phishing links arenโ€™t flagged as dangerous because theyโ€™ve never been seen before.

We donโ€™t need more, or better awareness. We need better systems to protect people.

Hereโ€™s how MetaCert stops phishing without the need to train people:

๐Ÿ”— www.linkedin.com/pulse/phishi...

22.05.2025 11:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

In addition to the good detail contained in this article, do NOT trust any person who calls you, even if it comes from a legitimate number because theyโ€™re easy to spoof.

07.05.2025 15:04 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Bank of Ireland warns customers of spike in new scam to steal personal information The bank have warned their customers that there's a new scam doing the rounds in which fraudsters will send texts urging people to call phone numbers, where they will attempt to steal financial inform...

MetaCert has built a new solution that helps banks protect their brand, reduce liability, and stop this type of fraud before it happens โ€” using tech that wasnโ€™t possible until now. Hoping to see it adopted in Ireland soon. @bankofireland @AIBIreland โ˜˜๐Ÿ”

www.rsvplive.ie/news/irish-n...

06.05.2025 10:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Confirmed โ€” 19 Billion Compromised Passwords Published Online You must take action now, as security experts confirm 19 billion compromised passwords available to cybercriminals for use in account hacking attacks.

My open letter to the security industry โ€” and MetaCertโ€™s U.S. SMS security test report โ€” is featured in this Forbes article.

Huge thanks to @happygeek for giving the underdog a voice. The best solution means nothing if no one hears about it.

www.forbes.com/sites/daveyw...

06.05.2025 08:18 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 3
Post image

I just wrote this: "Zero Trust Is Broken at the URL โ€” And Thatโ€™s Where Most Attacks Begin (Phishing)"

www.linkedin.com/pulse/zero-t...

paul-walsh.medium.com/zero-trust-i...

Lots of people are talking about Zero Trust at #RSAC2025 but not one person has mentioned zero trust for URLs. ๐Ÿ™„

29.04.2025 12:45 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Itโ€™s just basic phishing. Time to ask the question: โ€œWhy hasnโ€™t the security world tried a different approach in the past 20 years?โ€ Itโ€™s time to move away from threat โ€œintelligenceโ€ as it doesnโ€™t work - period. Time to move to zero trust for URLs/web links.

25.04.2025 12:23 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐ŸŽ“ Are you brave enough to give it a go? Whatโ€™s the right answer?

Even the most skilled & experienced security pros fail my tests 99% of the time โ€” so thereโ€™s no need to feel afraid or embarrassed. Feel free to share it too โ€” the more awareness, the better

I donโ€™t get much engagement on here so...

25.04.2025 12:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

I just received this SMS scam. This oneโ€™s from a lazy attacker โ€” strange ID, sloppy text. But donโ€™t let it fool you into thinking theyโ€™re all this obvious. Many are highly convincing and look exactly like the real messages youโ€™re expecting โ€” from deliveries to security alerts.

23.04.2025 16:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Lie Weโ€™ve Been Sold: Why Security Has Never Stopped Phishing โ€” and Wonโ€™t Start with SMS Phishing Isnโ€™t New โ€” It Just Keeps Changing Channels In the 1990s, I worked at AOL during the early days of the internet, when phishing first emerged in chat rooms, email, and instant messages. I didn...

I just wrote this:
www.linkedin.com/pulse/lie-we...

22.04.2025 18:44 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
How to Train ChatGPT to Think Like You โ€” And Use It as a Strategic Collaborator For Anyone Using ChatGPT at Work: This Is How to Take It to the Next Level If youโ€™re already using ChatGPT at work โ€” for writing, planning, or creative thinking โ€” but want more consistent, higher-qual...

๐Ÿ’ก Just dropped: how I turned ChatGPT into my expert collaborator โ€” not just a generic assistant.

Includes the exact prompt I use + how to apply it across product, sales, hiring, comms, and more.

www.linkedin.com/pulse/how-tr...

14.04.2025 11:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

SMS phishing isnโ€™t clever โ€” just easy
Criminals test fake messages on their own SIMs
If the link gets through, they send it to you
If it doesnโ€™t, they swap it until it does
This is why traditional security fails
Only trusted link authentication stops smishing before it starts.

10.04.2025 23:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

AI isnโ€™t just fun โ€” itโ€™s a serious business tool. I still had to finesse and shape things, but ChatGPT did most of the heavy lifting behind the scenes.

#SMSFraud #Phishing #Smishing

10.04.2025 13:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
#hashtag | Paul Walsh Making myself available โ€” selectively โ€” for board seats and advisory roles for the first time in a while. Iโ€™m particularly interested in tech companies and digital agencies where I can add strategic v...

Already sparked a few great conversations from my LinkedIn post. It wasnโ€™t a call for work โ€” just holding myself accountable by not procrastinating. ๐Ÿค“

www.linkedin.com/posts/paulwa...

09.04.2025 23:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

OpenAI now holds detailed insight into peopleโ€™s jobs and interests โ€” all exchanged for a bit of entertainment. ๐Ÿค“

09.04.2025 15:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

If you know anyone at banks or payment providers in Ireland, Iโ€™d appreciate an intro. Iโ€™m in touch with the Banking Federation but keen to connect with more of the right people โ€” hoping Ireland can lead the way in stopping SMS fraud.

03.04.2025 11:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

All we need now is anti-phishing protection. ๐Ÿค”

02.04.2025 16:11 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Thank you, ChatGPT. I made several edits, but the AI handled most of the heavy lifting.

MetaCert has developed a short code specifically for Ireland, where current privacy regulations prevent mobile operators from implementing network-based anti-phishing security.

02.04.2025 15:41 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

LinkedIn engagement has fallen off a cliff since the start of 2025. Iโ€™m not sure what they changed, but itโ€™s obvious somethingโ€™s different. If I wasnโ€™t writing for a handful of very specific people, Iโ€™d have stopped posting altogether. And itโ€™s even worse on here. Not a single engagement.

02.04.2025 11:55 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

I just wrote this: The security industry widely acknowledges smishing as one of todayโ€™s most serious cybersecurity threats. So why is it that no legacy vendor offers a network-based solution for mobile operators to protect...

LinkedIn: t.co/XpVg2498Cw

Medium: paul-walsh.medium.com/from-aol-ins...

02.04.2025 09:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

I made this emoji using ChatGPT โ€” with a transparent background!

Itโ€™s wild how fast this is evolving. Tools like this wonโ€™t replace great designers โ€” but they will wipe out tedious work and make everyday tasks way faster and easier.

01.04.2025 13:35 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Troy Hunt Fell for a Phishing Attackโ€Šโ€”โ€ŠHereโ€™s Why That Should Scare Everyone Troy Huntโ€Šโ€”โ€Šone of the worldโ€™s most respected security professionals and founder of Have I Been Pwnedโ€Šโ€”โ€Šjust admitted to falling for aโ€ฆ

Troy Hunt has spent his career teaching people how phishing works and how to avoid it. He knows the tactics, he understands the risks โ€” and he still got caught.

LinkedIn: www.linkedin.com/pulse/troy-h...

Medium: paul-walsh.medium.com/troy-hunt-fe...

27.03.2025 13:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Google is flagging MetaCertโ€™s anti-phishing emails as โ€˜dangerousโ€™ โ€” the same emails that highlight Googleโ€™s failure to detect phishing apps on Google Play. Ironic, but not even slightly funny.

๐Ÿ˜ค

@gmail

26.03.2025 15:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

โ€œA World Without ADHD and Dyslexia"

I just wrote this for Neurodiversity Celebration Week.

#NeurodiversityCelebrationWeek #NeurodiversityWeek #NCW #ThisIsND #ADHD #Dyslexia

cc @NCWeek

LinkedIn: www.linkedin.com/pulse/world-...

Medium: paul-walsh.medium.com/a-world-with...

20.03.2025 14:41 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
300 Malicious 'Vapor' Apps Hosted on Google Play Had 60 Million Downloads 300 malicious applications displaying intrusive full-screen interstitial video ads amassed more than 60 million downloads on Google Play.

Itโ€™s 2025, and the security industry still hasnโ€™t solved phishing. Itโ€™s time for a new approach - itโ€™s time for Zero Trust for URLs.

Assume every site, login page, app, API, user account, and AI chatbot is dangerous unless explicitly verified as legitimate.

www.securityweek.com/300-maliciou...

20.03.2025 12:30 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

35% of entrepreneurs have dyslexia, 40% of self-made millionaires have ADHD. 30% - 40% have both. Yet, most investors & corporate execs donโ€™t fully understand how they think or communicate.

Iโ€™m writing a book to explain why neurodivergent founders thrive and where they struggle.

19.03.2025 23:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Googleโ€™s AI โ€œScam Detectionโ€ for Android: Why It Fails to Protect SMS, RCS, and iMessage Googleโ€™s recently announced AI-powered scam detection feature for Android has generated buzz, suggesting a big leap forward in safeguarding Android users and their mobile communications. However, bene...

This article explains why AI fails at detecting fake (dangerous) email links, SMS links, WhatsApp links, websites, login pages, apps, QR codes, AI chatbots, or any other web resource โ€” and why relying on it for security is dangerous. #Smishing #Phishing

www.linkedin.com/pulse/google...

18.03.2025 10:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

I asked ChatGPT to generate an image for my Dublin tech networking event, and of course, I got lots of white people holding pints of Guinness. At least it didnโ€™t throw in a leprechaun pitching a blockchain idea. Progress. ๐Ÿ˜‚

14.03.2025 13:56 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@paulwalsh is following 20 prominent accounts