Advertisement · 728 × 90

Posts by Jennifer Wood

Video

If you missed last week’s runZero Hour with Caroline Wong, author of The AI Cybersecurity Handbook, here’s a peek at what you missed.

Watch the full episode now for more AI insights, CVE program updates, AI trivia, and notable vulns from the month.

Full episode: www.runzero.com/resources/ru...

1 day ago 1 1 0 0
Preview
Dispatch from VulnCon: AI, CVEs, & cooperation todb shares his key VulnCon 2026 takeaways, covers the rise of AI in vuln research, the role of CISA’s Vulnrichment, and the future of the CVE program.

Recently back from VulnCon 2026, runZero's @todb.hugesuccess.org shares his insights on AI's dual role in vuln discovery & defense, CVE ecosystem updates, and a cautiously optimistic outlook for the future of vuln disclosure and remediation.

Read his blog today! 👇️
www.runzero.com/blog/vulncon...

2 days ago 3 2 0 1
Post image

Are you attending the DoW MPE Summit in Ft. Lauderdale this week?

Be sure to connect with our team onsite to learn how runZero provides a single source of truth for exposure management across the total attack surface—without the friction of agents.

👉️ More details: www.ncsi.com/event/mpe/ag...

1 week ago 1 1 0 0
Post image

Need some downtime today during #BSidesSF 2026? Escape to the runZero sponsored Bar & Chill Out Space (inside) or Lounge (outside) from 9 AM-5:30 PM PT.

Stop by, say hello, and snag some swag! 👉 Remember, two complimentary drink tickets were provided at registration!

1 month ago 1 1 0 0
Post image

Tomorrow on the runZero Hour: Deep dive into OT retroencabulation

Join @todb.hugesuccess.org, Rob King, & Ulises Fuentes Venado from GuidePoint Security for an in-depth discussion on the evolving security challenges facing OT.

📅 March 18 | 1 PM ET / 10 AM PT
www.runzero.com/research/run...

1 month ago 2 1 0 0
Preview
OpenAI strikes deal with Pentagon after Trump orders government to stop using Anthropic On X, Defense Secretary Pete Hegseth said he had moved to label Anthropic as a "supply chain risk" and cancel Defense business with the company.

One way to read the AI/Pentagon news from last night (I covered it but didn't skeet) is that the Department of Defense wants AI to automate weapons and/or spy on Americans and that Anthropic would have the best AI to do that, but OpenAI is at least the second-best so they'll just use that instead.

1 month ago 141 64 11 7

If everything is a priority, nothing is.

@todb.hugesuccess.org helped build CISA KEV and his new runZero research finally makes it actionable.

He sat down with Casey Ellis on @riskybusiness to talk about what KEV actually is and how to use it right.

🎧 www.runzero.com/resources/ri...

1 month ago 3 2 0 0
Advertisement
Preview
DOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunch The former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am...

NEW: U.S. prosecutors say the hacking tools that Peter "Doogie" Williams stole from defense contractor L3Harris Trenchant could have been used against "millions of computers and devices" worldwide.

Williams said he didn't know the tools could end up in the hands of Russia or other governments.

2 months ago 9 7 1 2
Preview
DOJ says Trenchant boss sold exploits to Russian broker capable of accessing 'millions of computers and devices' | TechCrunch The former boss of the L3Harris-owned hacking and surveillance tools maker Trenchant faces nine years in prison for selling several exploits to a Russian broker, which counts the Russian government am...

Prosecutors have confirmed for the first time that Peter Williams, who ran L3Harris' Trenchant unit (which makes hacking tools for the U.S. govermment and its allies), sold the company's exploits to a Russian broker that were capable of accessing "millions of computers and devices" around the world.

2 months ago 20 22 2 2
Video

🚨 New report + tool: CISA KEV analysis by former Section Chief @todb.hugesuccess.org + KEV Collider to help prioritize real exploits over noise.

📄 Report: www.runzero.com/resources/ke...
🧪 Tool: www.runzero.com/kev-collider/
✍️ Blog: www.runzero.com/blog/making-...

Ready to make KEV actionable?

2 months ago 4 2 0 0

Joseph Menn has been writing about cybersecurity since well before most journalists even understood it as a beat. Big loss for the Post and its readers, but also for the industry and the wider public, who will be less informed - and less safe - as a result.

2 months ago 141 45 3 0

Why are pubs laying off talented journalists? We need reporters who understand security to continue covering it. It is disheartening to see this happening over and over again.

2 months ago 0 0 0 0
Preview
Open-source AI models vulnerable to criminal misuse, researchers warn Hackers and other criminals can easily commandeer computers operating open-source large language models outside the guardrails and constraints of the major artificial-intelligence platforms, creating ...

Good stuff here, folks! When you have a few minutes, read the article and the research (links below). #LLMsecurity

Story: www.reuters.com/technology/o...

Research: www.sentinelone.com/labs/silent-...

2 months ago 0 0 0 0
Preview
FAA ignored warnings from controllers before DCA crash, federal investigators say Families hope the nearly year-long probe by the National Transportation Safety Board will promote aviation safety changes.

The Federal Aviation Administration ignored warnings about a dangerous level of air traffic at Reagan National Airport before the midair collision between a commercial jet and U.S. Army helicopter that took 67 lives, federal investigators said.

2 months ago 51 31 4 3
Advertisement
Preview
ShinyHunters claims Okta customer breaches, leaks data : 'A lot more' victims to come, we're told

ShinyHunters has claimed responsibility for an Okta voice-phishing campaign during which the extortionist crew allegedly gained access to Crunchbase and Betterment.

2 months ago 2 1 0 0
Preview
Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects' laptops: reports | TechCrunch The FBI served Microsoft a warrant requesting encryption recovery keys to decrypt the hard drives of people involved in an alleged fraud case in Guam.

NEW: Microsoft handed the FBI the recovery keys to decrypt the hard drives of three laptops encrypted with BitLocker.

BitLocker is enabled by default in modern Windows laptops, but Microsoft also prompts users to upload the recovery keys to the company's cloud, which opens up this possibility.

2 months ago 24 22 3 6
Preview
Under Armour says it's 'aware' of data breach claims after 72M customer records were posted online | TechCrunch TechCrunch obtained a sample of the stolen data, which contained names, email addresses, dates of birth, and the user's approximate geographic location. Under Armour confirmed some sensitive informati...

New, by me: Under Armour says it’s aware of data breach claims after 72M customer records were posted online.

A spox. told me a "small percentage" of customers had sensitive information compromised but wouldn't say what it considers "sensitive," nor provide an accurate figure of affected customers.

3 months ago 17 11 2 2
Preview
Threat Advisory: GPS Attacks [SA-26-01] The dramatic increase in credible reports of GPS attacks, combined with geographic spread and the decreasing cost of hardware for the attack, indicate a change in the threat landscape. If your company...

GPS attacks are increasing, relatively cheap to implement, spreading geographically, and present a significant threat to people's safety and the economy. If your org uses GPS data, it's time to update your threat models. Learn more: shostack.org/26-01

3 months ago 0 1 0 0
Post image

Today is the day…#LABScon2025 is live from Phoenix, AZ. Get ready for two days of unique research and excellent speakers.

7 months ago 0 0 0 0
Preview
Data breach at French telecom giant Bouygues affects millions of customers | TechCrunch This is the latest cyberattack to hit a French cellular carrier in recent weeks, following an attack on Orange Telecom in July.

New: French phone giant Bouygues confirmed a data breach affects the personal information of 6.4 million customers.

Bouygues disclosed the breach on a dedicated web page; however, the page is currently deliberately excluded from search engines using "noindex" code, making it more difficult to find.

8 months ago 42 19 2 2
Post image
8 months ago 0 0 1 0

Enjoying the #threebuddyproblem podcast live from BH /Vegas!

8 months ago 1 0 1 0

If all goes to plan, I’ll be in Vegas for #BlackHat this week. DM me if you would like to meet. See y’all soon and safe travels to all!

8 months ago 1 0 0 0
Advertisement

Update: Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. Customers should apply these updates immediately.

Full guidance and detection details: msft.it/6010sDzSE.

9 months ago 37 30 2 1
Preview
Microsoft Patches 'ToolShell' Zero-Days Exploited to Hack SharePoint Servers Microsoft has started releasing updates to fix the exploited SharePoint zero-days tracked as CVE-2025-53770 and CVE-2025-53771.

Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers - www.securityweek.com/microsoft-pa...

9 months ago 0 0 0 0
Preview
A Startup is Selling Data Hacked from Peoples’ Computers to Debt Collectors Infostealer data can include passwords, email and billing addresses, and the embarrassing websites you use. Farnsworth Intelligence is selling to to divorce lawyers and other industries.

New from 404 Media: a startup is selling data hacked from peoples' computers to debt collectors, divorce lawyers, more. People already hacked, now being re-vicitmized by startup. I used the tool, found peoples' personal addresses.

“This is so gross and predatory.”

www.404media.co/a-startup-is...

9 months ago 760 366 18 29
Preview
Microsoft Confirms Ongoing Mass SharePoint Attack — No Patch Available Microsoft has confirmed that SharePoint Server is under mass attack and no patch is yet available — here’s what you need to know and how to mitigate the threat.

No patch but here’s the suggested mitigations from MSFT:
Configure Antimalware Scan Interface integration in SharePoint and deploy Defender AV on all SharePoint servers, and/or consider disconnecting your server from the internet until a security update is available.

www.forbes.com/sites/daveyw...

9 months ago 0 0 0 0
Preview
Home Office anti-encryption site pushes payday loan scheme : Company at center of findings blamed SEO on outsourcer

A website developed for the UK Home Office's 2022 "flop" anti-encryption campaign has seemingly been hijacked to push a payday loan scheme.
www.theregister.com/2025/06/25/h...

9 months ago 7 8 0 0
Post image

Iran's APT42 (Charming Kitten) hacker team is now conducting targeted spearphishing attacks on high-profile Israeli national security journalists and cybersecurity researchers, according to Check Point. blog.checkpoint.com/security/edu...

9 months ago 12 4 0 0
Preview
Dear friends, former colleagues, and extended network: | Jennifer (Jen) Wood Dear friends, former colleagues, and extended network: After nearly five incredible years at Luta Security, I’ll be moving on at the end of the month and looking for a new senior communications leade...

After five incredible years at
@lutasecurity.bsky.social I’ll be moving on at the end of the month and looking for a new senior communications leadership role within the cybersecurity industry. For more info about my background, please read: tinyurl.com/yeyw4xb6. Thanks!

9 months ago 7 1 0 2