vulnerability-research

16
May
Priority One: Insights into Submission and Payment Trends

Priority One: Insights into Submission and Payment Trends

2020: Chaos is a Ladder As 2020 comes to a close, I’ve started to see summaries of the year
3 min read
29
Mar
Hacking styles

Hacking styles

Broadly, there are two things that come into play when it comes to the style a person applies to hacking: The level of experience, and the overall wiring of the hacker.
1 min read
28
Mar
COVID-19/Coronavirus - What are the bad guys up to?

COVID-19/Coronavirus - What are the bad guys up to?

As expected, the covid19 pandemic has out brought some of the Internet’s worst. I’ve been working with several groups to information share and fight back on this stuff, including the COVID-19 CTI Group.
2 min read
02
Jan
Crowdsourcing physics

Crowdsourcing physics

Ok, time for some hard chats. I’m posting this following on from a series of conversations and reactions on
4 min read
31
Dec
The Future is Now: 2020 Cybersecurity Predictions

The Future is Now: 2020 Cybersecurity Predictions

How is it 2020 already? We’re in the last month of the decade, and the year that has long
3 min read
30
Aug

Vulnerability value modifiers

There are a few globally and truly external modifiers to the marketplace-defined value of a vulerability.
31
Jul

Practical prepping for Hacker Summer Camp

Here are some last-minute security and general “staying vertical” notes I shared with a few folks who are headed to
3 min read
25
Jun
What's in a name? Defining "hacker" in 2018

What's in a name? Defining "hacker" in 2018

If you do a Google Image Search against the word hacker, you’ll get images of scary-looking balaclava-clad cybercriminals hunched
2 min read
07
Mar

Thoughts on the vault7 CIA/Wikileaks disclosures

Wikileaks’ release of thousands of confidential CIA documents today is yet another demonstration of our just how vulnerable the cybersecurity
2 min read
22
Jul

disclose.io - Driving safety, simplicity, and standardization in vulnerability disclosure.

disclose.io is a collaborative and vendor-agnostic project to standardize best practices around safe harbour for good-faith security research. The
1 min read