I created a blog post based on my talk in #Disobey2026:
vasenius.fi/beyond-the-p...
#CyberSecurity #DataSecurity #Honeytokens
I created a blog post based on my talk in #Disobey2026:
vasenius.fi/beyond-the-p...
#CyberSecurity #DataSecurity #Honeytokens
We analyze novel attack vectors where malicious JavaScript is dynamically generated at runtime. This process leverages client-side API calls to trusted LLM services, initiated from an initially benign webpage (hiding malicious code in a text prompt). Read the threat brief here: bit.ly/4qQW0Cp
We have a new badge competition starting ...now! Create a game or (mini)app for the badge! Join and win awesome (disclaimer: with relative degrees of "awesome") prizes at Disobey 2026! To find out more, visit: disobey.fi/2026/competi...
Our research has identified a characteristic within Azure Private Endpoint deployments that could expose Azure resources to denial of service conditions. This finding pertains to the Azure Private Link mechanism: bit.ly/4r1nzZd
#MongoBleed vulnerability CVE-2025-14847 can expose sensitive data from heap memory. This includes cleartext credentials, API keys, session tokens and PII. Read our latest Threat Brief for details: bit.ly/4qVOkOM
Vibe Coding and Vulnerability: Why Security Canβt Keep Up
The promise of AI-assisted development, or βvibe coding,β is undeniable: unprecedented speed and productivity for development teams.
unit42.paloaltonetworks.com/securing-vib...
#VibeCoding #AISecurity #RiskManagement #Unit42
I wrote a new blog post based on my talk on #CloudBrew2025.
vasenius.fi/how-to-secur...
Russia Hits Critical Orgs Via Misconfigured Edge Devices - www.darkreading.com/endpoint-sec...
Starting the new week strong! π
We are excited to announce the sessions for our #Security track! And what a power house of speakers and sessions! π€©
Get your tickets here:
π« cloudtechtallinn.com
ποΈ cloudtechtallinn.com/agenda
#VisitTallinn #CTTT26
6 Predictions for the AI Economy:
2026's New Rules of Cybersecurity
www.paloaltonetworks.com/perspectives...
Microsoft is increasing prices for many of its products due to changes in its Enterprise Agreement (EA) volume licensing, effective November 1, 2025. The company is eliminating tiered discounts. This change will result in a cost increase of 6% to 12% for many.
www.microsoft.com/en-us/licens...
Struggling to manage it all at work? 5 ways to delegate like a pro - and lighten your load
Leading isn't easy. Five business leaders share how to hand off responsibility, build trust, and focus on long-term success.
#hackernews #news
If you want to learn more about how to use the #entraid advanced features for your blue team, check out my talk on Thursday at 11.45 AM! #iam #CyberSecurity #tallinn
Amazon Outage is Waking People up Regarding Our Slavery to the Internet - U.S. Government Failing in Defense Against Cyberattacks
medicalkidnap.com/2025/10/23/a...
A foreign actor infiltrated the National Nuclear Security Administrationβs Kansas City National Security Campus through vulnerabilities in Microsoftβs SharePoint browser-based app, raising questions about the need to solidify further federal security protections. www.csoonline.com/article/4074...
ConnectWise fixes Automate bug allowing AiTM update attacks
ConnectWise released a security update to address vulnerabilities, one of them with critical severity, in Automate product that could expose sensitive communications to interception and modification. [...]
#hackernews #news
China accuses US of cyberattack: Beijing says sensitive info stolen; what is National TimeΒ Center?
Representative image (AI) China on Sunday accused the US National Security Agency (NSA) of carrying out cyberattacks on its National Time Service Center. It further warned that any damage to theβ¦
Just shared a new blog post on how Microsoft Azureβs Security Suite gets even stronger with Palo Alto Networksβ tech and Unit 42βs intelligence.
Itβs about collaboration, visibility, and resilience across every layer of defense.
Read here π
vasenius.fi/enhancing-mi...
NDSS 2025 β Keynote 2: Towards Resilient Systems In An Increasingly Hostile World
Author, Creator & Presenter: Dr. Kathleen Fisher PhD, Director, Information Innovation Office (I2O), US Defense Advanced Research Projects Agency (DARPA)
Our thanks to the Network and Distributed β¦
#hackernews #news
Financial, Other Industries Urged to Prepare for Quantum Computers
PoC Exploit Unveiled for Lenovo Code Execution Vulnerability Enabling Privilege Escalation
Excited to be part of the new Evo Finland podcast episode on Security x AI ποΈ
We dive into when to build vs. buy AI tools, the newest AI-native threats, and why human oversight still matters.
π§ Listen here: open.spotify.com/episode/5JbU...
#AI #CyberSecurity #EvoFinland
Rolling out Microsoft Purview just got easier. This friendly deployment guide turns the latest models and the lightweight blueprint into a simple good, better, best path. Start fast, protect data, grow with confidence. Read more: vasenius.fi/how-to-choos... #MicrosoftPurview #DataSec
Anatomy of a Billion-Download NPM Supply-Chain Attack
open.substack.com/pub/jdstaerk...
Unify SecOps with Sentinel Data Lake and Defender XDR. Learn RBAC hardening, onboarding, incident correlation, Purview audit logging, and cost aware retention.
vasenius.fi/microsoft-pu...
#MicrosoftSecurity #SecOps #SecurityOperations #MicrosoftSentinel #MicrosoftPurview
Russian APT28 Deploys "NotDoor" Outlook Backdoor Against Companies in NATO Countries thehackernews.com/2025/09/russ...
Cloud sovereignty = ensuring data stays under local laws while benefiting from cloud scale + innovation.
Learn more:
πΉ Azure: learn.microsoft.com/en-us/indust...
πΉ AWS: aws.amazon.com/compliance/d...
πΉ Gaia-X: gaia-x.eu
#CloudSovereignty #DataControl
This MVP Award kit is so cool! Hope to get some more disks into this in future. #MVPBuzz