Dr Jason R.C. Nurse's Avatar

Dr Jason R.C. Nurse

@jasonnurse

I research Cyber/HCI/Web @UniKentCyberSec & lead S&R @CybSafe; @EPSRC Rising Star; Affil. @RUSI_org @Ox_CyberSec @SPRITEPlus @WolfsonCollege; Ex. @WarwickPsych.

45
Followers
43
Following
27
Posts
11.02.2024
Joined
Posts Following

Latest posts by Dr Jason R.C. Nurse @jasonnurse

Preview
A fragmented ransomware ecosystem may be more threatening than we recognise Smaller ransomware groups, bigger ransomware problem

In their latest for Binding Hook, @jasonnurse.bsky.social & Will Lyne show that the #ransomware ecosystem has fragmented. It is now crowded with smaller, more agile actors. As the landscape shifts, new threats require new tactics to combat.

Read full article: bindinghook.com/a-fragmented...

25.02.2026 09:05 πŸ‘ 3 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Preview
Why LinkedIn is a hunting ground for threat actors – and how to protect yourself The business social networking site is a vast, publicly accessible database of corporate information. Don’t believe everyone on the site is who they say they are.

Why LinkedIn is a hunting ground for threat actors

The business social networking site is a vast, publicly accessible database of corporate information. Don’t believe everyone on the site is who they say they are.

www.welivesecurity.com/en/social-me...

17.01.2026 19:52 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
AI’s Memorization Crisis Large language models don’t β€œlearn”—they copy. And that could change everything for the tech industry.

New research presents the most compelling evidence yet that generative AI directly stores and reproduces material used to train itβ€”a finding that could have massive legal consequences for the tech industry, Alex Reisner reports.

11.01.2026 08:15 πŸ‘ 153 πŸ” 55 πŸ’¬ 8 πŸ“Œ 15
Post image

Cybercriminals stole the sensitive information of 17.5 million Instagram accounts, including usernames, physical addresses, phone numbers, email addresses, and more.

This data is available for sale on the dark web and can be abused by cybercriminals.

09.01.2026 16:34 πŸ‘ 45 πŸ” 52 πŸ’¬ 2 πŸ“Œ 23
Post image

No new year resolutions here β€” just solid foundations 🌟

For when you want to revisit the fundamentals, CyBOK provides a structured, research-led body of knowledge supporting education, training, and professional practice.

Learn more πŸ‘‰ buff.ly/6M7yEmQ

05.01.2026 08:45 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
The Impact of Generative AI on Critical Thinking: Self-Reported Reductions in Cognitive Effort and Confidence Effects From a Survey of Knowledge Workers - Microsoft Research The rise of Generative AI (GenAI) in knowledge workflows raises questions about its impact on critical thinking skills and practices. We survey 319 knowledge workers to investigate 1) when and how the...

The Impact of Generative AI on Critical Thinking

Key finding:

β€œSpecifically, higher confidence in GenAI is associated with less critical thinking…”

www.microsoft.com/en-us/resear...

03.01.2026 10:44 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Rejoice! Carmakers Are Embracing Physical Buttons Again Amazingly, reaction times using screens while driving are worse than being drunk or highβ€”no wonder 90 percent of drivers hate using touchscreens in cars. Finally the auto industry is coming to its…

Amazingly, reaction times using screens while driving are worse than being drunk or highβ€”no wonder 90 percent of drivers hate using touchscreens in cars. Finally the auto industry is coming to its senses.

27.12.2025 18:44 πŸ‘ 4720 πŸ” 1172 πŸ’¬ 188 πŸ“Œ 512

.. the very type of crime that they should have been working to stop,” said the Justice Department’s Criminal Division.

The three men agreed to pay the ALPHV BlackCat administrators a 20% share of any ransoms received in exchange for access to the ransomware and extortion platform.

31.12.2025 10:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Two Americans Plead Guilty to Targeting Multiple U.S. Victims Using ALPHV BlackCat Ransomware Yesterday a federal district court in the Southern District of Florida accepted the guilty pleas of two men to conspiring to obstruct, delay or affect commerce through extortion in connection with ran...

πŸ¦ΉπŸ½β€β™‚οΈ When good guys go bad: β€œThese [security professionals] used their sophisticated cybersecurity training and experience to commit ransomware attacks...”

#cybercrime #ransomware #cybersecurity #justice #crime #profession #extortion

www.justice.gov/opa/pr/two-a...

31.12.2025 10:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Teens flock to alternative apps after social media ban The Commonwealth's long-awaited social media ban for under-16s came into effect this month. But some experts note a rise in alternatives to popular platforms as teens find ways to stay active on socia...

Ah yes, we could never have predicted this, never www.abc.net.au/news/2025-12...

22.12.2025 22:21 πŸ‘ 100 πŸ” 14 πŸ’¬ 2 πŸ“Œ 6
Preview
Hacks, thefts and disruption: The worst data breaches of 2025 | TechCrunch TechCrunch looks back at the biggest data breaches, disruptive cyberattacks, and damaging hacks of 2025, from the raiding of U.S. government databases to a hack every month in South Korea.

TechCrunch looks back at the biggest data breaches, disruptive cyberattacks, and damaging hacks of 2025, from the raiding of U.S. government databases to a hack every month in South Korea.

19.12.2025 14:13 πŸ‘ 13 πŸ” 7 πŸ’¬ 0 πŸ“Œ 1
Preview
Prompt injection is not SQL injection (it may be worse) There are crucial differences between prompt and SQL injection which – if not considered – can undermine mitigations.

Why do researchers keep finding so many prompt injection issues?

Perhaps it is because many AI system designers and defenders are misunderstanding the risks.🚨

Find out more⬇️
https://www.ncsc.gov.uk/blog-post/prompt-injection-is-not-sql-injection

08.12.2025 10:37 πŸ‘ 9 πŸ” 3 πŸ’¬ 0 πŸ“Œ 3
Preview
Jaguar Land Rover cyberattack shows that governments must provide post-incident support Cyber incidents impacting key national industries highlight the need for better approaches to protect the individuals who suffer most

Last month’s #JaguarLandRovercyberattack may cost Β£3.5B in revenue, but the bigger issue is the impact on 230,000 workers at JLR and in the supply chain facing layoffs, work reductions, and lost wages. @jasonnurse.bsky.social, Tom Johansmeyer & Gareth Mott: bindinghook.com/jaguar-land-...

07.10.2025 08:03 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Samsung brings ads to US fridges Samsung’s β€˜screens everywhere’ initiative is morphing into ads everywhere.

Samsung has rolled out a software update to its smart fridges that will display ads, despite saying they had "no plans" to do so. We're headed for a future where you will have to pay extra for appliances without ads.

18.09.2025 19:07 πŸ‘ 431 πŸ” 158 πŸ’¬ 80 πŸ“Œ 233
Preview
OpenAI will apply new restrictions to ChatGPT users under 18 | TechCrunch Under the new policy, ChatGPT will be trained to no longer engage in "flirtatious talk" with underage users, and additional guardrails will be placed around discussions of suicide.

Under the new policy, ChatGPT will be trained to no longer engage in "flirtatious talk" with underage users, and additional guardrails will be placed around discussions of suicide.

16.09.2025 16:30 πŸ‘ 16 πŸ” 3 πŸ’¬ 2 πŸ“Œ 2
Preview
Amazon to launch augmented reality football coverage β€˜Prime Vision’ service featuring gaming-style graphics comes as sports broadcasters seek to boost youth engagement

Amazon to launch augmented reality football coverage on.ft.com/3I9wuXP

15.09.2025 20:20 πŸ‘ 11 πŸ” 3 πŸ’¬ 1 πŸ“Œ 8
A person, known as Dr. Jason Nurse, standing in the front of a room having a presentation.

A person, known as Dr. Jason Nurse, standing in the front of a room having a presentation.

Picture of a city with big colored letters in the foreground that say "Manchester".

Picture of a city with big colored letters in the foreground that say "Manchester".

Reposted from our colleagues who are currently visiting #EuroUSEC25 in Manchester πŸ‡¬πŸ‡§

Day 2 of #EuroUSEC25 is about to start, and amazing Dr. Nurse (@jasonnurse.bsky.social) is getting everyone on track for an inspiring day with a lot of good papers.

#SECUSO

11.09.2025 08:36 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Hear from our inspiring panel speaker @jasonnurse.bsky.social, University of Kent and @cybsafe.bsky.social, joining us at the Northern WARP 5th Annual Conference on the 12th September!

Tickets are FREE to anyone in the WARP community πŸ‘‰ northernwarpconference5.eventbrite.co.uk?aff=BlueSky

27.08.2025 10:36 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Security flaws in a carmaker's web portal let one hacker remotely unlock cars from anywhere | TechCrunch Security researcher Eaton Zveare told TechCrunch that the flaws he discovered in the carmaker's centralized dealer portal exposed vast access to customer and vehicle data. With this access, Zveare sai...

ICYMI from Def Con: Eaton Zveare found bugs in a carmaker's centralized dealer web portal that allowed "unfettered access" to customer data and systems inside. Portal allowed remote control of some car functions, like door unlocking. The bugs highlight the risks of these web-connected data portals.

12.08.2025 13:17 πŸ‘ 22 πŸ” 13 πŸ’¬ 0 πŸ“Œ 1
Warm, Encouraging Email From CEO Quickly Identified As Phishing Attempt

Warm, Encouraging Email From CEO Quickly Identified As Phishing Attempt

Warm, Encouraging Email From CEO Quickly Identified As Phishing Attempt theonion.com/warm-en...

07.08.2025 15:00 πŸ‘ 1956 πŸ” 250 πŸ’¬ 18 πŸ“Œ 6
Preview
OpenAI removes ChatGPT self-doxing option : Checkbox to make chatbot conversations appear in search engines deemed a footgun

OpenAI has removed the option to make ChatGPT interactions indexable by search engines to prevent users from unwittingly exposing sensitive information.

The feature rollback follows reports of ChatGPT conversations being discoverable in Google results.

www.theregister.com/2025/08/01/o...

02.08.2025 08:49 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Treating Online Abuse Like Spam

Treating Online Abuse Like Spam

What would happen if technology companies treated online abuse more like spam? A key advantage: users would have the choice to address potentially abusive content or to ignore it altogether. Here’s why that matters: innovation.consumerreports.org/Digital-Hara...

01.07.2025 19:05 πŸ‘ 2 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

A flyby of Earth from the International Space Station.

-Credits: NASA

01.08.2025 19:12 πŸ‘ 8493 πŸ” 1547 πŸ’¬ 253 πŸ“Œ 137
Preview
LLMs' AI-Generated Code Remains Wildly Insecure Security debt ahoy: Only about half of the code that the latest large language models (LLMs) create is cybersecure, and more and more of it is being created all the time.

LLMs' AI-Generated Code Remains Wildly Insecure

Security debt ahoy: Only about half of the code that the latest large language models (LLMs) create is cybersecure, and more and more of it is being created all the time.

www.darkreading.com/application-...

01.08.2025 19:01 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Top spy laments LinkedIn profiles that reveal defence work : Workers on joint US/UK/Australia nuclear submarine program are painting a target on themselves

Top spy says LinkedIn profiles that list security work 'recklessly invite attention of foreign intelligence services'

www.theregister.com/2025/08/01/a...

01.08.2025 15:16 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Hidden features of volcanic β€œlava bombs” have been caught on video.

Learn more: scim.ag/478PIqq

01.08.2025 13:58 πŸ‘ 161 πŸ” 27 πŸ’¬ 5 πŸ“Œ 3
Preview
Sex toy maker Lovense threatens legal action after fixing security flaws that exposed users' data | TechCrunch The internet-connected sex toy maker said it fixed the vulnerabilities that exposed users' private email addresses and accounts to takeovers, but said it was also planning to take legal action followi...

New, by me: Lovense, a maker of internet-connected sex toys, has confirmed it fixed a pair of security flaws that exposed users' private email addresses and put accounts at risk of takeovers. Now the company's CEO says he might sue.

01.08.2025 14:58 πŸ‘ 45 πŸ” 20 πŸ’¬ 4 πŸ“Œ 9
Preview
Google Project Zero to publicly announce bugs within a week of reporting them The vulnerability hunters at Google Project Zero want to address what they call the "upstream patch gap," when a vendor has a fix available but the downstream product providers haven't integrated it y...

Google Project Zero to publicly announce bugs within a week of reporting them

The elite bug-hunters at Google Project Zero are taking aim at how long it takes to fix cybersecurity vulnerabilities

therecord.media/google-proje...

30.07.2025 21:54 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
The Online Safety Act is a security and compliance minefield - Raconteur Ofcom has been given broad scope to enforce the Online Safety Act. But experts warn that its methods could create disproportionate risks

I’m in Raconteur talking about the β€˜new’ Online Safety Act, and range of risks surrounding online age checks and these digital ID systems.

www.raconteur.net/technology/t...

29.07.2025 11:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0