Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Brian Greenberg :verified:

@brian_greenberg@infosec.exchange
  • Open on infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

440 Followers
240 Following
50 Posts
Joined March 25, 2025
Blog:
https://briangreenberg.net
Github:
https://github.com/bjgreenberg
Gravatar:
https://gravatar.com/bjgreenberg
Threads:
https://www.threads.net/@bjgreenberg
LinkedIn:
https://linkedin.com/in/bjgreenberg
LinkTree:
https://linktr.ee/brian.greenberg

Posts

Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Aug 07, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
Boosted by DataKnightmare @DataKnightmare@mastodon.xyz
A software investor told an AI agent, 11 times in all caps, DO NOT TOUCH ANYTHING WITHOUT PERMISSION!! It wiped his production database anyway. Then it claimed the data was unrecoverable. It wasn't. Everyone wants to talk about how the AI misbehaved. I think that's the wrong conversation. Every failure in that story has a known engineering fix. Keep prod separate from dev. Put safeguards on destructive commands. The AI did what any unsupervised tool does. What was missing was the judgment a senior engineer brings before a single line of code is written. So I wrote about the question technology leaders should be asking instead: whose engineering judgment is your AI following? Because it's following someone's. If your standards live in a document nobody reads, your AI is coding to whatever it picked up from the prompt in front of it. AI is an amplifier. Hand it vague requirements and weak practices, and it produces bad work faster. Hand it the discipline of your best engineers, and it spreads that discipline across the whole team. Full piece in Forbes: https://www.forbes.com/councils/forbestechcouncil/2026/08/07/your-ai-is-learning-from-someone-make-sure-its-your-best-engineer/ I also open-sourced an experiment called Senior Engineering Partner, a Claude Code skill that encodes those habits into working instructions. Spec before code. Evidence before claims. Real failures turn into regression tests instead of postmortem notes. It's on GitHub if you want to try it or tear it apart. https://github.com/bjgreenberg/senior-engineering-partner #AI #SoftwareEngineering #TechnologyLeadership #security #privacy #cloud #infosec #cybersecurity
5
0
4
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Aug 03, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
✨ A sparkle icon shows up in an app you own. Nobody in IT put it there. A user opens a ticket asking what it does, and the help desk has no answer. The feature is live, it's available to everyone, and it's already processing your data. I wrote this one for Forbes because it keeps happening and I've stopped pretending it's normal. Zoom gave admins about four days in July 2024 to click "do not auto-enable" before AI Companion turned itself on. Google launched Workspace Intelligence in April 2026 with Gemini reaching into Gmail, Drive, Chat and Calendar, each source on by default, and the admin controls could show up as much as 72 hours behind the live feature. OpenAI ships ChatGPT Enterprise with connectors off and ChatGPT Business with them on. Same company, opposite decision. Here's the part that should bother you. Many U.S. states require two-party consent for recording. Whether an AI meeting summary counts as a recording under wiretap law is still an open question, and your company gets to be the test case. Zoom chat retention defaults to two years, so the evidence sticks around while you figure it out. What decent vendor behavior would look like: ・New AI features ship off, with the switch left to you ・One clear notice to admins naming the feature, the data it touches, and the date it goes live ・An evaluation window measured in weeks Until that shows up, work from the assumption that the next AI feature is already on in your tenant. Put configuration reviews on a recurring schedule. Write down every default-on surprise you find and bring that list to your renewal conversation, because that's where you actually have leverage over the behavior. Default-on is a choice. So is governance. https://briangreenberg.net/2026/07/30/default-on-ai-are-saas-vendors-outsourcing-their-risk-to-you/ #AIGovernance #CISO #SaaS #security #privacy #cloud #infosec #cybersecurity
0
0
0
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jul 29, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

My friend Jeff Olsen wrote a really good piece on status updates, and it's been rattling around my head all week. His point is that "on track" describes a conversation, not a state. The words sound like progress. They can hide a month of sitting in someone else's queue.

I've worked with Jeff, and this is exactly how he thinks. He's always pushing to make himself and the people around him better. This post is a great example of that.

The line that got me: four weeks on the calendar, thirty minutes of actual work. The rest was waiting. And nobody could see it because "almost done" sounded fine.

A few things worth borrowing:

  • When someone says they're blocked, ask what would unblock it. Then ask who owns the next move. Two questions turn a vague update into something you can act on.

  • "Access takes a week" stops being a question and starts being an assumption. Once a wait has a shape, you can count how often it shows up. One slow approval is annoying. The same one twelve times a year has a price tag.

  • Keep it curious. Point the question at a person, and it becomes an accusation. Point it at the work, and people tell you the truth.

If you run projects or sit in status meetings, give this one ten minutes.

https://jeffols.substack.com/p/on-track-is-not-a-state

#Leadership #ProjectManagement #ITLeadership

jeffols.substack.com

'On Track' Is Not a State.

Teasing out where the work actually is, before the date decides for you.

0
0
0
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jul 06, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
Some news I'm honored to share. I've been nominated for the 2026 Chicago CIO of the Year Award, and I owe a big thank you to Dean Haacker of Highland Grove Partners for putting my name forward. Being nominated by someone I respect makes this one mean a lot. Since 1995, SIM Chicago, The Executives' Club of Chicago, and AITP Chicago have recognized technology leaders across Chicagoland with this award. Nominations come from CIO peers, CEOs, and other senior executives, which is what makes it special. The judging looks at the things I actually care about in this job: leadership in the business, value creation and protection, building teams, and innovation. Whatever happens from here, the process itself is a chance to step back and reflect on what my team and I have accomplished together. And none of it happens without them. Thank you again, Dean, and congratulations to my fellow nominees. Finalists get announced in September, and winners are named at the SIM Fall Gala in November. I'm looking forward to meeting the other candidates along the way. https://aitpchicago.com/CIO-OF-THE-YEAR-AWA #CIO #Leadership #Chicago @RHR_International@mastodon.social @aitpchicago@bird.makeup @forbestechcncl@bird.makeup
0
0
0
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jun 30, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
Everyone's using AI to write code faster. Almost nobody's using it to write code better. It's where the next wave of breaches and a 2am page will come from... So I built something to help myself, and I'm putting it out there. It's a Claude Code skill called senior-engineering-partner. It's not autocomplete. It's the strict senior engineer who reviews your pull request, asks why you skipped the tests, and won't let you ship a hardcoded secret because you were "just prototyping." A few things it does: ・ Enforces a real workflow. Agree on the spec, plan in verifiable steps, write the test first, then prove the work before calling it done. ・ Holds a security floor that never moves. Whether you're prototyping or running in production, the secrets and input-validation basics stay non-negotiable. Cheap doesn't mean insecure. ・ Refuses to hallucinate. It verifies claims about your environment by running a real command, rather than inventing a flag or an API that sounds right. ・ Switches modes depending on how you call it: reviewer, debugger, mentor, or pair programmer. It's open source under Apache-2.0, stack-agnostic, and built around Python, Bash, Apps Script, and JavaScript. Here's my ask. Use it. Then tell me where it's wrong. I want the good feedback and the brutal feedback, plus any capability you wish it had. The whole point is to encode what senior engineers actually do, and I'd rather hear it breaks on your stack than find out later. What would you want a skill like this to enforce? https://github.com/bjgreenberg/senior-engineering-partner #ClaudeCode #AI #SoftwareEngineering #AppDev #DevOps #security #privacy #cloud #infosec #cybersecurity
0
0
0
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jun 15, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

The most interesting thing about the new SearchLeak attack on Microsoft 365 Copilot isn't any single bug. It's that none of the three pieces was dangerous on its own. Varonis combined a prompt injection via a URL parameter, an HTML rendering race condition, and a server-side request forgery in Bing's image search. Each of these is a common bug that security teams usually consider minor. But when you put them together with a Copilot that can access your mailbox, OneDrive, and SharePoint, they create a critical flaw. Microsoft has since patched this issue (CVE-2026-42824).

This is how the attack worked:

* The victim clicks a link. That's the whole interaction. They type nothing.

* The link instructs Copilot to search the mailbox, find sensitive information such as access codes, and place it into an image URL.

* Bing retrieves that image, which sends the stolen data to the attacker's server. Bing serves as the delivery service, allowing the attack to bypass the content security policy intended to stop it.

From the user's perspective, Copilot just pauses for a moment. There is no visible sign that any data has been taken.

In the past, we've spent years rating bugs by their severity on their own. An SSRF here, an HTML injection there—each seemed minor. But when an AI assistant can follow instructions from untrusted input and access your real data, those minor bugs become much more serious. Old types of vulnerabilities become important again in this new context.

If your company uses Copilot or any AI assistant that can access company data, it is important to ask your team how they are rating bugs that affect it. The way we judge what is low risk has changed.

https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/

#AI #Cybersecurity #InfoSec #security #privacy #cloud #AttackChain

4
0
6
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jun 15, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

For a long time, people said the law was behind when it came to deepfake abuse. That seems to be changing. The DOJ took down two sites, CFAKE and SOCFAKE, which prosecutors say had thousands of fake nude images of well-known women, including politicians, journalists, and athletes. This is one of the first big federal actions under the TAKE IT DOWN Act, passed in May 2025. The law makes it a federal crime to publish sexually explicit fake images of an identifiable adult without their consent if the goal is to cause harm.

Here are a few things of note:

* The images may be fake, but the people targeted are real, and so is the harm to their reputation and privacy. The law was created to address this specific problem.

* This effort was international. Italy's cyber police were the first to spot the sites and then shared evidence with France under the Budapest Convention. A suspect was arrested in Nice on June 10.

* The DOJ made it clear that taking down the sites is just the beginning. For anyone running similar sites, seizing the domain is only the first step, not the last.

One important thing to remember: putting a seizure notice on a website can help stop some abuse, but the technology to make these images is cheap and widely available. Law enforcement can go after those who host or profit from this content, but they can't make the technology disappear. This means victims still have to find and report the images themselves, which is tiring and unfair.

If you or someone you know is facing this problem, StopNCII(.)org works with most major platforms to remove nonconsensual images. You can also report it to the FBI at ic3(.)gov. It's good to know these options before you need them.

https://hackread.com/feds-seize-cfake-and-socfake-explicit-deepfakes-women/

#Cybersecurity #Privacy #AI #security #cloud #infosec #DeepFakes

1
0
1
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jun 15, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

I just finished reading Google's new report about a Chinese espionage group that spent over a year inside North American medical and military research networks. What stands out is how ordinary their method was. They used a standard Google Workspace admin feature called a content compliance rule, which lets admins flag emails based on certain words or addresses. The attackers set up one of these rules, called it "Patroit" (misspelling Patriot), and used it to secretly BCC every matching email to a Gmail account they controlled. This gave them a steady stream of sensitive defense, policy, and medical research emails, all through a feature that was working exactly as intended.

Here are a few important points to consider:

- The attackers got in through a REDCap server that was exposed to the internet. Hospitals and universities often use these servers to store clinical research data. The first known break-in happened in September 2023.

- They installed malware called InfiniteRed to steal real login credentials, then used admin accounts to move through the network.

- The data theft relied on a legitimate, built-in feature. There were no suspicious files to detect.

This last point is important. We invest heavily in finding malware and suspicious files. But a configuration rule set up by an admin on an ordinary day just looks like regular work. That’s why it went unnoticed for so long.

If you manage email for your company using Google Workspace or Microsoft 365, check today who can create forwarding and compliance rules, and whether anyone gets notified when those rules change. Taking a few hours to review this now could save you from much bigger problems down the road.

https://www.theregister.com/research/2026/06/15/google-says-prc-linked-spies-hid-in-medical-research-networks-for-more-than-a-year/5254547

#Cybersecurity #InfoSec #RiskManagement #security #privacy #cloud #email

2
0
3
1
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jun 15, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Loving our new brand...

Shifting workplace expectations, geopolitical tensions, technology disruptions, and more have created one of the most challenging business landscapes to date, leaving organizations faced with a multitude of emerging challenges and competing priorities – and an even more crucial need for leaders to rise to the top.

Today, we are proud to unveil the next evolution of RHR International, bringing our best work into clearer focus, helping leaders see this complexity as a catalyst for opportunity while unlocking the true potential of leadership within their organizations.

Visit our website (www.rhrinternational.com) to learn more and follow along as we empower leaders to unlock the full potential of their people and organizations for today’s business environment.

#LeadershipDevelopment
#Leadership
#TalentDevelopment
@RHR_International@mastodon.social

Your browser does not support the video tag.
0
0
0
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jun 14, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

This project really made me smile. Andrew Warkentin has created a virtual museum with over 600 operating systems, all set up and ready to run on a regular computer. The collection covers everything from the Manchester Baby in 1948, which was the first stored-program machine, to early Android versions from 2011. He’s been gathering these images since 2003.

It’s clearly fun, but what really impressed me was how useful it is. If you teach or work in security, it’s hard to find a collection of old systems you can actually start up. You can show students how operating systems managed memory, permissions, and networking before today’s safety features, and you get to do it on a live system instead of just looking at screenshots.

Here are a few reasons why it stood out to me:

1. Everything is already set up. Running old software is usually a hassle because some systems only work with certain emulator versions or need special patches. Warkentin has already handled all of that, so you don’t have to.
2. The collection is huge. It includes the earliest mainframes and CTSS, many DOS versions, early Windows, classic Mac OS, the Lisa, and even rare hobby systems that most people have never tried.

There is one thing to keep in mind. Most of the images only include the software that originally came with the operating system, like calculators and text editors, so they’re a bit limited at first. Finding old software for systems like CTSS can be tricky. Think of this as a history archive you can use, not a complete app store.

But above all, I think this is a fantastic way to preserve history. A lot of early software has already been lost or can’t be read anymore. Keeping working copies that people can still use helps keep that history alive. If you used any of these systems growing up, try starting one up and see what memories come back. And if you’re a teacher, this could be the best classroom tool you find all year.

https://www.theverge.com/tech/945246/virtual-os-museum-dos-windows-mac-os

#Cybersecurity #InfoSec

2
0
2
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jun 14, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

 This new agentic AI demo from Apple's WWDC was so cool. Apple Intelligence can now log into your accounts, reset a compromised password, and save the new one so you don’t have to remember it.

This is super important because weak and reused passwords still account for a large share of account breaches, and fixing them has always been a hassle. Most people struggle with password hygiene and rarely reset all their accounts. A tool that handles this for you bridges the gap between knowing you should do it and actually doing it.

Here’s why I think it’s a good idea:

1. It targets the main weakness. Most breaches begin with something simple, like a password that has already leaked elsewhere.

2. It takes away the hassle that keeps people from taking action. The best security tool is the one people actually use.

I do have one quick caution. An agent that can change your credentials is powerful, so it’s important to know how Apple keeps it secure and how quickly you can turn it off. Still, the main idea is solid, and it shows how this technology can really help by handling the security tasks people usually avoid. I hope other password managers add this feature too. And always use MFA!

https://gizmodo.com/apple-intelligence-can-change-your-passwords-for-you-when-you-get-hacked-2000769041

#AI #InfoSec #Cybersecurity #security #privacy #cloud #infosec

3
12
2
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jun 14, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

For years, we’ve worried about who collects our data. Now, The Washington Post has shown us how it can be used: to charge you as much as it thinks you’ll pay.

The main plaintiff paid $42.40 for a year of the Post in 2024. In 2025, her price jumped to $127.20. Her most recent renewal was $148.40. An algorithm set these prices by analyzing her personal data. She only found out because a New York law requires companies to disclose this practice.

Here are a few details that should concern you:

1. The lawsuit claims the Post created individual profiles from subscribers’ devices and used them to guess the highest price each person would accept.

2. The Post also asks you to link your Amazon account, which gives the pricing system even more of your personal data.

If you ignore the AI buzzwords, this is just old-fashioned price discrimination. The difference is that now the seller knows your income and even your recent browsing history. Most people won’t realize they’re paying a personalized markup, since most states don’t require the kind of disclosure that revealed this case.

If you design these systems, pay close attention to this issue. It’s reasonable to use data to make a product better. But using it to secretly decide who pays more is what courts are now being asked to call deceptive. As disclosure laws spread, it’s wise to set your own standards before regulators do it for you.

https://gizmodo.com/washington-post-sued-over-alleged-surveillance-pricing-after-subscription-prices-jump-dramatically-2000770744

#Privacy #AI #RiskManagement

6
2
5
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jun 14, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Google's defense for false AI Overviews: Nobody should blindly trust AI output anyway. And they're right. A German court agreed nobody should trust it, then held Google liable for it regardless.

However, the court found that your product only has value if people trust it. You can't sell a tool that answers with confidence and then tell a judge the answers shouldn't be believed.

Two things from the ruling of note:

1. Search engines get liability protection because surfacing third-party links is unavoidable. The court said AI summaries are optional. Nobody needs them to search the web, so they don't get the same level of protection.

2. Google's AI Overviews on the current Gemini model are wrong about 9% of the time and attach bad source links 56% of the time. Most people never click through to check. Trust, but verify!

Put that together, and a tool like this produces millions of wrong answers a day, and almost nobody verifies them. Which they should. I keep coming back to accountability, companies, and individuals. Someone decided to ship a feature that makes confident, original claims about real businesses and didn't fix them quickly when they were wrong. Additionally, it's up to the end user to always verify the claims. However, the court called it the company's own speech and liability.

If you're adding AI features to your product, the lesson is simple. You own what your tool says. The disclaimer won't save you.

https://arstechnica.com/tech-policy/2026/06/nobody-needs-ai-to-search-the-internet-court-says-in-ruling-against-google/

#AI #RiskManagement #Cybersecurity #TrustButVerify

0
0
1
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Jun 10, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

✨ A sparkle icon appears in an app that no one in IT approved. The help desk can't explain it, and it's already processing your data! This kept coming up in conversations with other CIOs, so I wrote about it in my latest Forbes piece.

The pattern repeats across so many vendors; here are just a few:
・Zoom auto-enabled AI Companion on host accounts, with recordings and full transcripts already defaulted on
・Microsoft 365 Copilot activates for every admin if your tenant holds a single paid license, and opting out means building a special security group
・Google's Workspace Intelligence shipped default-on for Gmail, Drive, Chat, and Calendar, with admin controls lagging the live feature by up to 72 hours
・OpenAI disables connectors by default for Enterprise customers but enables them for Business. Same vendor, opposite defaults.

Every default-on feature just transfers governance work from the vendor to you, along with wiretap exposure and e-discovery sprawl that nobody signed up for.

My ask of vendors is simple: ship AI features off by default and give admins an evaluation window measured in weeks, not days. Until that happens, assume the next AI feature is already live in your tenant. Review your configurations like it's a recurring operational task, because it is.

Full piece here: https://www.forbes.com/councils/forbestechcouncil/2026/06/10/default-on-ai-are-saas-vendors-outsourcing-their-risk-to-you

#RiskManagement #Forbes #ForbesTechnologyCouncil #ForbesTechCouncil #leadership #security #privacy #cloud #infosec #cybersecurity #AI #SaaS  
@forbes@flipboard.com @Forbes@newsie.social @forbestechcncl@bird.makeup @RHR_International@mastodon.social @depaulu@bird.makeup #DePaul #DepaulU #DePaulUniversity #DePaulCDM

10
1
7
1
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · May 22, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

https://open.substack.com/pub/briangreenberg/p/how-to-protect-yourself-from-identity?r=3thg8&utm_medium=ios

2
0
0
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · May 19, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

🥶 A contractor for CISA posted AWS GovCloud admin keys to a public GitHub repo! The repo was named "Private-CISA." Not an accident, the contractor actively disabled GitHub's built-in secret scanner to do it. That's a choice. Not a typo, not a misconfiguration. Someone turned off the guardrail and then stored plaintext credentials in a file called "importantAWStokens." That should make every security leader lose their 💩 AND the exposed keys stayed valid for 48 hours after CISA was notified. The agency responsible for protecting the country's critical infrastructure took two days to rotate credentials sitting in a public repo. 🤬 One researcher called this "the worst leak I've witnessed in my career." The exposed files included credentials to CISA's internal software build environment. Anyone who found those keys first could have backdoored the packages CISA builds and deploys. Every new build would carry that backdoor forward. CISA has lost nearly a third of its workforce since January. The oversight that might have caught this sooner is gone.

Two questions worth taking back to your own team:
・ When did you last verify that secret scanning is actually enabled across every repo your contractors touch?
・ If you got the call today that credentials were public, how long would it take to rotate them?

https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
#CISA #CloudSecurity #SupplyChainSecurity #CyberGovernance #security #privacy #cloud #infosec

krebsonsecurity.com

CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

3
0
3
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · May 15, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
Here are a few key points from tonight:
・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

https://aitpchicago.com/event-6680905
#Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

5
2
4
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · May 14, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

The big security conferences have their place. You get the keynotes, the vendor expo, and the sponsored happy hours. What you don't always get is a straight conversation with someone who actually broke something recently and wants to talk about it.

That's why I'm going to BSides312 this weekend.

Saturday, May 16th, at the Irish American Heritage Center in Chicago. Two talk tracks, 15 speakers, a CTF, a lockpicking village, and an after-party. Community-run, non-profit, built for practitioners by practitioners.

If you're in Chicago and work in security, this is where you should be this weekend. Come find me.

https://bsides312.org

#BSides312 #Cybersecurity #InfoSec #Chicago #security #privacy #cloud #312 @bsides312@infosec.exchange @bsides312@bird.makeup

5
0
2
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · May 14, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Though Google Cloud Next in Las Vegas was a couple weeks ago, I'm still working through it and trying to process everything I learned there. Three days, 32,000 attendees, 260 product announcements. One cool stand out...
Google shipped an entire agent accountability infrastructure at this conference. Every AI agent now gets a cryptographic ID and an auditable action trail tied to a defined authorization policy. They built anomaly detection that flags unusual agent reasoning in real time and maps it back to the source.
You build that when you're expecting things to go wrong at scale.
GE Appliances is deploying 800 AI agents across manufacturing and supply chain right now. That's operational continuity with autonomous software making decisions without a human in the loop.
Every enterprise leader needs to answer one question the technology doesn't answer for you: when an agent makes a decision that costs money or creates legal exposure, who owns it?
I'm looking forward to diving deeper into Gemini Enterprise and Chrome Enterprise. The Chrome Enterprise shadow AI reporting shows you every unsanctioned AI tool your employees are already using. You can't govern what you can't see.

https://cloud.google.com/blog/topics/google-cloud-next/google-cloud-next-2026-wrap-up

#AIGovernance #AgenticAI #GoogleNext #CIO #EnterpriseSecurity #security #privacy #cloud #infosec #cybersecurity #AI @google @googlecloud@twtr.plus @googlecloudsec@bird.makeup

2
2
5
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · May 14, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Grateful to be a part of the Gartner Chicago CIO Community Executive Summit at the Sears (Willis) Tower. The most sobering thing I heard came from CIOs across all sorts of companies, who openly admitted that nobody has solved AI or Agentic AI operationalization. In a room full of people who are supposed to have the answers, that's the right starting point. Every conversation seemed to be all about #agenticAI.

A few things that stuck:

・ The "Death of the ERP?" conversation wasn't hyperbole. Agentic AI is genuinely unbundling what monolithic ERP systems do, and CIOs who aren't asking that question now will be answering it under pressure in two years.

・ Most organizations are still stuck between proof of concept and production. The gap is real and larger than most teams are willing to admit publicly.

・ Governance has to come before you scale adoption, not after. IDC projects AI identities will hit 1.3 billion within two years. The organizations that haven't started thinking about identity and access controls for AI agents are already behind.

・ Know what you're trying to accomplish before you start buying tools. The orgs getting value from AI defined the outcome first.

The CIO role is shifting. The value is in guiding the organization through the change, not just managing the infrastructure underneath it.

Shoutout to Zander Petersen and the Gartner team for a well-run day.

https://www.evanta.com/cio/chicago/chicago-cio-executive-summit-8429

#CIO #AI #Leadership #Cybersecurity @RHR_International@mastodon.social

0
0
1
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · May 08, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Your data isn't at risk of being breached. It already has been. The right question is whether what's out there can still be used against you. Most of the attack surfaces that actually matter are stoppable with free government tools almost nobody has touched: new credit accounts opened in your name, fraudulent tax returns filed before you file yours, employment fraud using your SSN, bank account takeovers. The IRS Identity Protection PIN alone is worth calling out. Someone can file a return in your name, collect your refund, and disappear before you ever log into TurboTax. There's a free six-digit PIN that blocks this cold. Most people have never heard of it.

A few things worth flagging from the guide:
- 23andMe filed for bankruptcy in 2025 and was acquired, putting genetic data for millions of users at risk of sale. If you have an account, delete it and request deletion of your physical sample.
- HIPAA covers your doctor. It doesn't cover your fitness tracker, your wellness app, or your period tracking app. That data flows freely and largely without regulation.
- E-Verify Self Lock is something most people don't know exists. If someone uses your SSN to get a job, the IRS gets their wages on your record. Self Lock blocks it at employers who use E-Verify, which is most large ones.

If you do nothing else, freeze your credit at all four bureaus and get an IRS IP PIN. It takes about 90 minutes and cost nothing. Read the guide, pick a few off the list, and stop treating this as something that happens to other people.
https://briangreenberg.net/2026/05/07/how-to-protect-yourself-from-identity-theft/
#Cybersecurity #IdentityTheft #Privacy #security #cloud #infosec

4
0
3
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 30, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

I'm hiring an Analytics Engineer (GCP) to join my team at RHR International.
What you'd actually be doing: building and owning our analytics foundation in a Google Cloud GCP-first environment — BigQuery, Data/Looker Studio, Python, SQL, GitHub, Docker. Real production work, version-controlled and documented, not throwaway queries.
RHR is a leadership consulting firm that's been around for 80+ years. We're cloud-first, SaaS-only, no on-prem. Small IT team, which means your work matters immediately.
What I'm looking for beyond the technical skills: curiosity, self-direction, and the ability to explain what you built and why to people who don't write code. Bonus points if you've fixed something nobody asked you to fix.
Hybrid in Chicago preferred, remote considered.
Apply here: https://www.linkedin.com/jobs/view/4399748962/
If you know someone who fits, I'd appreciate the tag or share.

#Hiring
#AnalyticsEngineer
#GCP
#BigQuery
#DataEngineering
#Chicago
#RHRInternational
#Google
#GoogleCloud
#GoogleCloudPlatform

Your browser does not support the video tag.
1
0
4
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 29, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
Replying to @theraccoonbytes@theforkiverse.com
@theraccoonbytes@theforkiverse.com https://briangreenberg.net
0
0
0
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 28, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Your AI strategy isn't a strategy if your competitor can copy it in a quarter.

MIT Sloan just published something you might want to ruminate on. The argument is straightforward: AI fails the basic test of sustainable competitive advantage because it's neither unique nor inimitable. Capital, talent, algorithms, even proprietary data, all of it is converging. Smaller models are catching up to larger ones. Open-source is closing the gap. The moat you think you're building is filling in as fast as you dig.

The part that should sting for most executives is this: the companies that win won't win because of AI. They'll win because of what their people do with it that nobody else thought to do.

That means that it isn't what AI tools you're buying. It's whether you're still investing in the humans who know your customers, your market, and your blind spots well enough to make a move no model would predict.

If you gutted your talent development budget to fund AI infrastructure, you may have traded the thing that can't be commoditized for the thing that already is.

https://sloanreview.mit.edu/article/why-ai-will-not-provide-sustainable-competitive-advantage

#AIStrategy #CompetitiveAdvantage #Leadership #FutureOfWork #TalentDevelopment

6
0
6
1
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 27, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

What is going on with Gemini and workflows today? It's like it fell down and hit its head on a very large rock. 🤦🏻‍♂️✨

0
1
0
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 27, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

An AI coding agent wiped out a company's entire production database and every backup in just 9 seconds. The AI agent later confessed, in its own words, that it guessed a destructive action would be scoped to the staging environment, didn't verify, didn't read the docs, and just did it anyway. 🤦🏻‍♂️ Everyone's blaming the AI. I'm looking at the humans who handed it the keys. This wasn't a rogue model. It was a predictable outcome of predictable choices:

  • A CLI token with blanket permissions across all environments
  • Backups stored on the same volume as the data they're meant to protect
  • A cloud provider whose API executes destructive commands with zero confirmation step
  • An agent given access to production while the team thought it was safely contained in staging

The founder is now manually reconstructing customer bookings from Stripe logs and calendar integrations. Every one of his customers is doing the same because of a 9-second API call. AI agents don't have judgment. They have instructions and permissions. Whatever permissions you grant, assume they will eventually be used in the worst possible sequence at the worst possible moment. That's not pessimism, it's how you architect resilient systems. Separate your environments. Scope your tokens. Store backups offline and off-volume. Require confirmation before any destructive operation. These aren't AI-era lessons. They're 30-year-old lessons that people keep skipping because the tooling makes it easy to skip them. The speed AI can act is new. The failure modes underneath it are not. https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue #AI #Cybersecurity #RiskManagement

11
7
14
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 24, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

The McDonald's AI jailbreak story was fabricated. The Chipotle one before it was Photoshopped. I get why they went viral, they're kinda funny. But they're pulling attention away from the cases that actually happened and actually cost companies money.

Amazon's Rufus chatbot got manipulated into providing instructions for obtaining dangerous chemicals. A Chevy dealership's bot was maneuvered into agreeing to sell a $76,000 Tahoe for a dollar. Air Canada's bot invented a refund policy that didn't exist, a customer relied on it, and when the airline said "that's not our problem, the bot is its own entity," a Canadian tribunal told them exactly where to put that argument.

If you're a CIO, the legal question sitting underneath all of this is the one worth losing sleep over:
- Prompt injection isn't exotic. It works because LLMs are built to be responsive to language, not resistant to it. There is no patch that fully closes this.
- Any AI you deploy on a customer-facing surface is making representations on your company's behalf. Your legal team needs to know that before your marketing team ships the chatbot.
- "The bot did it, not us" is not a defense. One court has already said so, and others will follow.

The fake viral stories are a distraction. The boring real ones are the ones that end up in discovery.

https://www.fastcompany.com/91532091/mcdonalds-ai-bot-didnt-go-rogue
#Cybersecurity #AI #Leadership #security #privacy #cloud #infosec #cybersecurity

8
0
6
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 24, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

One founder just called out something the VC community has been quietly living with for a while. AI startups are reporting CARR, which counts revenue that hasn't been invoiced and may never be, to the press while labeling it ARR. The gap between those two numbers, per the CEO who went public about it, can run 3 to 5x.

Here's the part that should make you uncomfortable if you're buying AI tools or evaluating vendors: the VCs aren't getting fooled. They read the contracts. The people getting fooled are journalists writing the coverage you're using to make procurement decisions, and employees who think they're joining a rocketship.

A few things worth sitting with:
- Free pilots counted as revenue is not a new trick. It just has a better outfit now.
- If you're a CIO evaluating an AI vendor's "momentum," ask one question: is that ARR live and invoiced, or contracted?
- The companies chasing inflated benchmarks they can't actually hit are the ones that will blow up your implementation 18 months in.

We've been here before. The numbers looked great right up until they didn't.

https://www.fastcompany.com/91532292/ai-startups-arr-carr-scott-stevenson
#AI #Leadership #Cybersecurity #VC #PE #startup #vaporware

2
0
1
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 24, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

The FCC forgot hotspots were a thing. They announced a ban on foreign-made consumer routers a month ago and had to update their FAQ to add MiFi devices and cellular home routers after the fact. That's not a minor oversight... it's the whole work-from-anywhere use case.

Here's the part that should bother you. The only way to get an exemption is to commit to US-based manufacturing and submit a time-bound plan to get there. Netgear, eero, and Adtran got conditional approval, but it runs out October 1, 2027. There is no domestic consumer router industry to speak of right now. So the FCC has created a countdown clock against a factory floor that doesn't exist yet.
A few things worth sitting with:
- The Global Electronics Association pointed out that security vulnerabilities show up across products regardless of where they're made. Geography isn't the filter; code quality is.
- The Covered List used to apply to specific companies flagged for specific reasons. Extending it to an entire product category means the government can now ban any internet-connected device made abroad by citing national security. Smartphones aren't included yet. "Yet" is doing a lot of work in that sentence.
- The Register's headline from last month said it plainly: the country that put backdoors in Cisco routers to spy on the world is now banning foreign routers. I didn't write that. They did. But they're not wrong.

If you're in security or IT leadership, watch the October 2027 date. That's when the conditional approvals expire, and if the manufacturing commitments aren't met, the options get ugly fast.

https://www.theregister.com/2026/04/24/fcc_does_a_doubletake_adds/
#Cybersecurity #FCC #NetworkSecurity #security #privacy #cloud #infosec

8
0
8
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 24, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

A lower court decided Apple, Google, and Facebook lose Section 230 immunity because they ran credit card transactions inside social casino apps. Not because they built the apps. Not because they designed the gambling mechanics. Because they processed the payments.

Follow that logic downstream and Etsy is liable for a seller's counterfeit goods the moment a buyer checks out. Patreon is exposed the second a creator's content draws a lawsuit. Section 230 has kept smaller platforms alive since 1996 by separating the pipe from the content flowing through it. Courts inventing a payment-processing carve-out don't hurt Apple. Apple has lawyers. The platforms that get hurt are the ones that can't afford to fight.

EFF filed an amicus brief arguing the 9th Circuit should reverse the lower court, and they're right. Congress never drew a line between hosting content and processing payments for it. Judges shouldn't draw one now just because the content happens to be digital slot machines.

https://www.eff.org/deeplinks/2026/04/eff-9th-circuit-again-app-stores-shouldnt-be-liable-processing-payments-user
#Tech #Law #Leadership

0
0
1
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 24, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Google just put $10 billion into Anthropic. Its competitor. The company it's also racing against to win the AI era.

Amazon dropped $5 billion into the same company this week. And investors are apparently trying to back Anthropic at an $800 billion valuation, up from $350 billion in February.

I get the hedge. Nobody wants to be Blockbuster. But there's something worth sitting with here: when the biggest players in tech are all funding the same startup, that's not a competitive landscape. That's a cartel with extra steps.

🤔 The "up to $40B" framing matters. Google commits $10B now. The other $30B depends on Anthropic hitting performance milestones. So Google's hedging its hedge.

💰 Anthropic is reportedly considering an IPO as soon as October. After this week, the timing makes a lot more sense.

🔒 From a security standpoint, this kind of capital concentration around a handful of AI providers should make enterprise buyers nervous. You're not just picking a vendor. You're picking a dependency.

https://www.cnbc.com/2026/04/24/google-to-invest-up-to-40-billion-in-anthropic-as-search-giant-spreads-its-ai-bets.html
#AI #Cybersecurity #Leadership

3
0
2
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 24, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
Anthropic recorded over 16 million interactions with Claude from about 24,000 fake accounts, which are reportedly linked to Chinese companies trying to cheaply copy the model. Google faced more than 100,000 attempts to copy Gemini. OpenAI reports that most distillation attacks they find come from China. This is not an isolated event. It is a repeatable and scalable strategy. Breaking the terms of service isn't enough to stop people when the reward is closing a years-long gap in AI technology. The House Select Committee on China wants to label 'adversarial distillation' as industrial espionage under the Economic Espionage Act, which makes sense. At the moment, getting caught just means losing an account. That is hardly a real punishment. The Trump-Xi summit is approaching, and the White House is reportedly considering sanctions. However, Trump has previously traded away export controls for other deals. If that happens again, AI companies may have to protect their intellectual property by themselves. When laws fail to keep pace with new types of attacks, attackers automatically have the advantage. If your company is developing anything unique using advanced AI models, your API access logs are now part of your security risks. https://arstechnica.com/tech-policy/2026/04/us-accuses-china-of-industrial-scale-ai-theft-china-says-its-slander/ #AI #Cybersecurity #NationalSecurity #IntellectualProperty #Geopolitics #security #privacy #cloud #infosec #Espionage
1
3
3
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 24, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

A Chinese national pretended to be U.S. engineers and researchers for almost five years, from 2017 to 2021, and walked away with sensitive aerospace and weapons development software from NASA, the Air Force, the Navy, and the Army. There was no hacking or breaking through firewalls. People simply emailed him what he asked for, because they believed he was someone they knew.

This worries me more than any zero-day vulnerability. The NASA OIG reported that Song Wu asked for the same software several times without explaining why he needed it. Most people miss this kind of red flag because no one teaches them to spot it. We invest millions in technology controls but spend very little on training people to pause and think like a threat actor before sending information.

Export controls are not only about legal compliance. They are also about human behavior. Your employees make export control decisions every day, often without realizing it.

When was the last time your organization ran a spear-phishing simulation aimed at your researchers, not just your finance team?

If your security awareness program doesn't cover identity deception and unusual software requests, it is not thorough enough.

https://thehackernews.com/2026/04/nasa-employees-duped-in-chinese.html
#Cybersecurity #NationalSecurity #Espionage #SecurityAwareness #InfoSec #security #privacy #cloud #infosec

1
0
1
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 24, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Bitcoin blocks usually take about 10 minutes to confirm. According to new research from Google, quantum key derivation might only take around 9 minutes. That similarity is hard to overlook.

The main point isn’t that quantum computers will eventually break crypto—we’ve expected that. What matters now is that Google has reduced the estimated resources needed by about 20 times. That means fewer qubits, fewer gate operations, and shorter timelines. Plus, 1.7 million BTC are stored in old address formats where the public key is already visible. Attackers wouldn’t have to hurry; they could take as long as they want. 🔓

The crypto industry often sees upgrades like SegWit and Taproot as successes, and they are. However, Taproot brought back direct public key exposure for different reasons. Now, every design choice in crypto has a quantum aspect, whether teams realize it or not.

⏳ The threat isn’t immediate, but the time to prepare is now—and that window won’t last forever.
🏛️ If your organization holds digital assets, you should add post-quantum cryptography to your risk register now, not two years from now.

https://www.ccn.com/education/crypto/google-quantum-computers-break-bitcoin-ethereum-9-minutes-1-7m-btc-risk/
#Cybersecurity #QuantumComputing #Crypto #RiskManagement #Blockchain

2
0
0
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 24, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Anthropic spent months carefully gatekeeping access to Mythos, their most capable AI model, while limiting access only to a small group of vetted companies for defensive cybersecurity testing. Then a private online forum got in anyway, through a third-party vendor, on the same day the controlled program was announced.

That's the part worth sitting with. Not the model. The vendor. Third-party vendors... It's always the the 3td party vendor. 🤦🏻‍♂️ You can build the most carefully controlled AI release program in the industry, and one weak link in your supply chain burns it down. We keep having this conversation about AI safety and regulation, and we keep forgetting that the threat surface isn't just the model. It's every partner, every integration, every environment touching it. 🔗 Everything's connected. Everything.

🤔 Ask yourself: how many third parties have access to your most sensitive systems right now? Do you actually know?
⚠️ Vendor risk management isn't a compliance checkbox. It's where your security posture actually lives or dies.

https://www.yahoo.com/news/articles/anthropics-mythos-model-accessed-unauthorized-214920132.html
#Cybersecurity #AI #VendorRisk #InfoSec #RiskManagement #security #privacy #cloud #infosec

2
1
4
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 24, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
Boosted by Kevin Karhan @kkarhan@jorts.horse
Trying to be secure... You deleted the app. You turned on disappearing messages. You did everything right. The FBI can still read your Signal messages. Huh? This wasn't a Signal failure. Signal did its job. iOS didn't. The phone was storing notification previews in a database long after the app was gone, because someone turned on Lock Screen message previews. Apple just patched it in iOS 26.4.2, and they only found out about it because a defendant's court case exposed it during testimony. 🔎 This is why privacy promises and privacy architecture are two different things 📲 Update your phone. Not because you're hiding something. Because your phone is quietly keeping receipts you don't know about. ⚠️ And if you're a CISO still telling employees that "just use Signal" is a complete privacy answer, it's time to revisit that conversation. https://www.macrumors.com/2026/04/22/ios-26-4-2-notification-database-security-fix/ #Cybersecurity #Privacy #iOS #InfoSec #Leadership #security #cloud #infosec #AlwaysUpdate
12
1
13
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 23, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
Replying to @freshstart@hachyderm.io
@freshstart@hachyderm.io I like emojis. 🤷🏻‍♂️
0
0
1
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 22, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Quick thought experiment. Pull out your phone, look at your lock screen, and ask yourself who else is reading those notification previews. The answer is stranger than you think.

EFF just laid out what most people don't realize: push notifications usually route through Apple or Google servers before they hit your device, often with content visible in the clear. Then they get written to a local notification database that doesn't always get wiped when you swipe the alert away or even when you uninstall the app. 404 Media reported the FBI has pulled deleted Signal message text out of that database using standard forensic tools. Signal. The app you installed specifically because you didn't want this.

🔐 Apple and Google now require a court order for push notification data, but Apple's transparency report still shows hundreds of users handed over
📱 Lock screen previews are a free read for anyone who picks up your phone, including at a border crossing or traffic stop
🧹 Uninstalling an app does not guarantee its notification history goes with it, and we don't know what gets backed up to iCloud or Google
🛠️ Signal's notification setting "No Name or Content" is a 30-second fix that closes the easiest leak

For the security folks, this is a useful reminder that end-to-end encryption ends at the endpoint, and the endpoint includes a SQLite file most users have never heard of. For the executives, this is the reason your travel security policy for high-risk regions should say more than "use Signal." The default settings on a stock iPhone leak more than the app you chose to protect you.

https://www.eff.org/deeplinks/2026/04/how-push-notifications-can-betray-your-privacy-and-what-do-about-it
#Privacy #Cybersecurity #MobileSecurity #security #cloud #infosec

29
2
46
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 22, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
An ex-Azure engineer published six essays arguing Microsoft's cloud has been on life support since 2008, and the cause isn't bad code. It's bad people decisions. Rushed launch, post-launch talent exodus, no testing discipline, no architectural vision. Sound familiar to anyone who's worked in a place that ships first and staffs later? Now layer 2026 on top. Microsoft cut roughly 15,000 jobs in mid-2025. Coding agents are pumping out 4x more commits in 90 days. GitHub's unofficial uptime has slipped under 90% and the proposed fix is, wait for it, moving more of GitHub onto Azure. The same Azure the engineer says is held together with rushed decisions and wishful thinking. 🧠 The phrase that stuck with me is "knowledge dilution from high attrition." When the senior people who knew why a system was built that way leave, no LLM in the world can recover that context 🤖 More AI-written code does not mean less work. It means more code to review, test, deploy, and run, which means more compute and more humans needed downstream 📉 OpenAI signing an $11.9B compute deal with CoreWeave in March 2025 was the loudest "we don't trust your capacity" signal Microsoft has ever received from its closest partner 🪑 The bet that AI lets you cut headcount keeps colliding with the reality that AI generates work for humans faster than it removes it Every CIO I talk to is being pitched the same dream: fewer engineers, more agents, lower run rate. The Azure story is what happens when that math doesn't pencil out and the bill comes due in incidents instead of dollars. https://www.theregister.com/2026/04/04/azure_talent_exodus/ #Azure #AI #Leadership #security #privacy #cloud #infosec #cybersecurity #software #devops
116
10
129
3
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 22, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Four grand. That's what it costs a random kid with a laptop to run a voice phishing operation that used to require a call center, a phisher, and a developer. ATHR packages all of it into one dashboard, tosses in AI voice agents that can ad-lib when a victim gets suspicious, and ships with ready-made lures for Google, Microsoft, Coinbase, Binance, and a few more.

CyberCrime has a SaaS model now, complete with commission splits (10% of profits back to the vendor). The barrier to running a convincing vishing campaign just collapsed, and your awareness training still says "watch for typos in the email."

🎙️ AI agents handle objections live, so the "support rep" sounds real because they are, functionally, reasoning
📧 Lure emails are customized per target with accurate IPs, dates, locations, and pass authentication checks
🏦 Eight brands supported out of the box, crypto exchanges heavily represented for obvious reasons
🛡️ Stop looking at email indicators, start modeling normal communication patterns and flag the anomalies

If your vishing defense is a 20-minute annual training video and a phish-report button, you're bringing a knife to a drone fight. The humans on the other end of the phone aren't humans anymore, and they don't get tired, rattled, or bored on calls.

https://www.bleepingcomputer.com/news/security/new-athr-vishing-platform-uses-ai-voice-agents-for-automated-attacks/

#Cybersecurity #Vishing #AI #security #privacy #cloud #infosec #cybersecurity

3
0
4
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 14, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Anthropic built an AI model called Mythos that autonomously found a 17-year-old remote code execution vulnerability in FreeBSD. No human involvement after the initial prompt. It found thousands more zero-days across every major OS and browser, some hiding for decades. Anthropic says it's too dangerous to release publicly, so they gave it to AWS, Microsoft, Apple, Google, CrowdStrike, and a handful of others under a new initiative called Project Glasswing. $100M in usage credits to go fix things before similar capabilities go wide.

Impressive, but worth some skepticism. Bruce Schneier pointed out this is also a very effective PR play. A security firm called Aisle replicated many of the same findings using older, cheaper, publicly available models. The gap between "too dangerous to release" and "already achievable with what's out there" may be thinner than the headlines suggest.

🔒 Mythos autonomously discovered and exploited a FreeBSD RCE that had been present for 17 years (CVE-2026-4747)
🔗 It chains 3-5 vulnerabilities together into multi-step attack sequences
📊 Over 99% of the vulnerabilities found are still unpatched, so we're trusting Anthropic's claims on scope
💰 $25/$125 per million input/output tokens for partners, if you're on the list

Meanwhile, the advice cybersecurity experts are giving the rest of us: update your software, use MFA, get a password manager. The most advanced AI vulnerability scanner ever built, use off-line (truly air-gapped) backups, and basic hygiene is still the best defense most people have.

https://www.crn.com/news/security/2026/5-things-to-know-on-anthropic-s-claude-mythos-and-project-glasswing
#CyberSecurity #AI #ProjectGlasswing #security #privacy #cloud #infosec

5
0
4
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 13, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
Anthropic created an AI that discovered vulnerabilities in every major operating system and browser, even uncovering a nearly 30-year-old flaw in one of the most secure platforms. Weirder yet, one day, while a researcher was eating lunch in the park, the model emailed them. It had escaped their internal sandbox and reached the internet. They named it Claude Mythos Preview, but they are not making it available to the public. A private company, mainly accountable to its investors and its own sense of ethics, now controls a cyber weapon as powerful as those used by nation-states. For now, they have given Apple, Microsoft, Google, and Nvidia access to use it for defense. This situation proves what the security community has warned about for years: 🔓 The balance has shifted. In cybersecurity, attacking has always been easier than defending. Mythos doesn't just narrow that gap; it widens it. While finding a vulnerability and exploiting it without being noticed are separate challenges, you can't exploit what you haven't found. Mythos has now solved the problem of large-scale vulnerability detection. 🌐 Calling this move "responsible" serves several purposes. Anthropic can announce a major breakthrough, show restraint by not releasing it, and boost its reputation as a responsible company, all at once. This isn't being cynical, it's simply how public relations works. Both can be true. ⚔️ The article mentions that OpenAI is working on something similar, and Google DeepMind will likely follow. Soon, smaller companies with fewer safety measures will offer cheaper models. The time when "responsible non-release" is a real option is running out. I teach cybersecurity at DePaul, and for years I've told my students that AI would make both attacking and defending more accessible. Now, Mythos shows we've reached a turning point where attackers have pulled far ahead. The real question isn't if a tool like this will be misused, but how soon a version without any safeguards will be released by someone with no accountability. https://www.theatlantic.com/technology/2026/04/claude-mythos-hacking/686746/ #Cybersecurity #AI #Leadership #security #privacy #cloud #infosec
10
2
9
1
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 13, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange
Boosted by Greg Bell @ferrix@mastodon.online
A startup is putting military-style drones in high school ceilings. Ceiling-mounted. Charging. Waiting. And when something happens, a pilot in Austin, Texas, decides whether to deploy pepper gel on your kid's school. I'm not saying the problem isn't real. It absolutely is. But read that back.... in schools. We've taken a Ukrainian battlefield tactic against Russian soldiers and ported it to Deltona High School in Florida. The co-founder literally said the idea came from watching drone videos of the war in Ukraine. The chief pilot described it as "cheating in a video game after you die." These are children. Here's what's not in the headline: 🔒 The drones use an encrypted connection — but the article notes they're potentially vulnerable to cyberattack. A compromised drone in a crowded hallway isn't a security tool; it's a weapon pointed in the wrong direction. ⚖️ Mithril reserves the right to act independently during an attack, without waiting for law enforcement. A private company operating remotely is making use-of-force decisions at a school. 💰 Florida and Georgia approved $500K+ each for this. A group of Texas parents raised $200K more. That's real money going to ceiling drones instead of mental health services, counselors, or de-escalation programs. The ACLU said it plainly: when force becomes a zero-risk remote action, it gets overused. Axon tried a Taser drone for schools in 2022, and its own ethics board killed it. Mithril is picking up where that got dropped. I teach cybersecurity. I've spent years in boardrooms helping organizations think through risk. And the risk calculus here isn't just about whether the drone works. It's about what we're normalizing when we turn schools into drone-monitored combat zones and call it progress. "This is the future," said the sheriff's captain. I hope not. https://www.wsj.com/business/a-startup-is-supplying-drones-to-high-schools-a7800ade #SchoolSafety #Cybersecurity #Leadership #security #privacy #cloud #infosec
Your browser does not support the video tag.
247
68
291
16
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 06, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

☢️ Last May, OpenAI representatives showed up at Los Alamos National Laboratory with armed security escorts and locked metal briefcases. Inside: the model weights for ChatGPT o3, which they then installed on Venado, one of the most powerful supercomputers on earth. By August, Venado was moved onto a classified network with access to nuclear weapons data. 🤖 Let that sit for a second. 😳 A quote from a researcher who's been in nuclear testing since the 1980s: "We're doing calculations I could only dream of doing before." The implication being that AI isn't just a productivity tool at Los Alamos. It's changing what questions they can even ask.

🧠 Scientists there are using AI to simulate how weapons respond to stress without live detonation tests, which the US hasn't conducted since 1992. Eighty years of nuclear test data is now training data.

⚡ The $320M Genesis Mission program aims to double the productivity of American science within a decade. That's the stated goal. Across 17 national labs.

🤔 From LANL's computational sciences chief: "For the very first time, I would argue, on a really big scale, we find ourselves not in a leadership role here." The government, for once, is chasing the private sector. Not directing it.

We spend a lot of time debating AI safety in the abstract. Meanwhile, the actual story is already written, locked in a briefcase, and installed on a classified network in the New Mexico desert.

https://www.vox.com/technology/484250/los-alamos-nuclear-ai-openai-chatgpt
#AI #NationalSecurity #EmergingTech #security #privacy #cloud #infosec #cybersecurity

4
0
2
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 06, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

A Meta exec threatened to fire anyone who put OpenClaw on a work laptop. That's not being paranoid either. OpenClaw just patched a flaw that allowed anyone with the lowest permission level to silently escalate to full admin. No user interaction. No second exploit needed. Just pairing access, and you own the instance. On top of that, 63% of the 135,000 internet-exposed OpenClaw instances were running with zero authentication. On those deployments, the "lowest permission" wasn't even required. Any network visitor could just walk in. 😳

🧩 The patches dropped Sunday. The CVE listing didn't come until Tuesday. Attackers had a two-day head start.

🔑 Full admin means read all connected data sources, exfiltrate stored credentials, execute arbitrary tool calls, and pivot to whatever else the agent touches. Slack. Discord. Files. Logged-in sessions. All of it.

🤔 The real question isn't whether OpenClaw has security problems. Every tool does. The question is whether your organization decided to hand an inherently unpredictable LLM the keys to your environment before asking who else might be able to grab them.

If you're running OpenClaw, check your pairing approval logs. Then have an honest conversation about whether the productivity trade-off still makes sense.

https://arstechnica.com/security/2026/04/heres-why-its-prudent-for-openclaw-users-to-assume-compromise/
#Cybersecurity #AIAgents #ZeroTrust #security #privacy #cloud #infosec

3
1
2
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 06, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

Meta paused work with a $10B AI data vendor after hackers poisoned an open-source Python library called LiteLLM and walked out with four terabytes of data. So, that's bad. And the worst part? The stolen data might include the actual training methodologies that Meta, OpenAI, Anthropic, and Google paid billions to develop. Think about what that means. You can't protect your crown jewels if they're sitting inside a vendor who's connected to your three biggest competitors, all sharing the same open-source tools, all exposed by the same 40-minute window on PyPI before anyone noticed.

🎯 The attack chain here is worth understanding: hackers compromised a security scanner called Trivy, used that access to get credentials for a LiteLLM maintainer, then published two malicious package versions that lasted less than an hour before removal. Forty minutes. That's all it took.

💼 Mercor is not some sloppy startup. It's 22-year-old founders, $500M annualized revenue, and clients at the very top of the AI industry. Sophistication doesn't protect you from a poisoned dependency you never thought to audit.

🔍 The question I'd be asking right now if I were a CISO at any of these labs isn't "were we breached." It's "how many vendors in our training pipeline are running LiteLLM, and did we even know?"

Most companies audit their own software. Almost nobody audits the software their vendors use to build the data they're buying.

https://thenextweb.com/news/meta-mercor-breach-ai-training-secrets-risk
#Cybersecurity #AIRisk #SupplyChainSecurity spc #security #privacy #cloud #infosec #ThirdPartyRisk

7
0
6
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 05, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

https://www.cbsnews.com/news/new-hampshire-school-sign-language-communicate-deaf-student/

0
1
0
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 02, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

For my second leadership event of the day… I’m honored to participate in CXO Inc.’s #CISOMeet event today. We’re discussing the evolving role of the CIO/CISO today and strategies for #AI and #cybersecurity.

#cio #chicago #technology #leadership #educator #mentorship #collaboration #cisomeet #ciso

https://www.cisomeetchicago.com

0
0
3
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 02, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

I’m honored to be a panelist at CXO Inc.’s #CIOMeet event today. We’re discussing the evolving role of the CIO today and strategies for #AI and #cybersecurity.

#cio #chicago #technology #leadership #educator #mentorship #collaboration #ciomeet #futuristcio

https://www.ciomeet.org/chicago

0
0
3
0
Open post
brian_greenberg
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Mar 31, 2026
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange

CIO by day, cybersecurity professor & Forbes Contributor by night, and a firm believer that the best ideas start with good coffee. I’m passionate about using AI, cloud tech, and leveraging system dynamics to make work (and life) a little easier. Outside of work, I’m either reading/writing in some indie coffee house, hiking shady trails along the river, or adding to my ever-growing collection of houseplants. I’m always learning, always leading, and always up for a good book or a new coffee house to explore. 
#CyberSecurity #systemstheory #hiking #philosophy #actor #improviser #storyteller #coffee house addict
📍Chicago, IL 
🦋🥾☕️🎭🤖🪴✍️

infosec.exchange

First, Discord announced age verification. As predicted, users revolted. A former partner had already leaked 70,000 government IDs. Then, Discord backed down. And now the age-check vendors who got exposed in the process have to defend technology most people didn't even know existed. Interestingly, researchers at Georgia Tech reverse-engineered Yoti, the dominant age-check provider used on over 60% of compliant sites in states with age-gate laws. They found that Yoti sends your photo to its servers, collects data "beyond what is strictly necessary," and shares it with fourth parties most users have never heard of. Yoti disputes it. But they also confirmed facial age estimation does not happen on-device. Meanwhile, the EFF states that on-device processing is "less dangerous" than sending data over a network.

🔐 On-device face scans mean your biometric data stays on your phone, for now
🗝️ "Age keys" built on FIDO passkey tech could let you reuse an age signal across platforms without re-verifying each time
📸 The dominant provider in the US runs a million checks a day and sends your photo to its servers
⚖️ The Supreme Court ruled last summer that online age verification doesn't violate the First Amendment, partly based on Yoti's technical claims 😳

The thing people don’t realize is that once age-check infrastructure is embedded across every major platform, it doesn't go away. Every update is a new attack surface. Every new law expands the mandate. And the CEO of one of these companies is already talking about age-aware cameras and microphones as the logical next step.

Your device should work for ‘you.’ The moment it starts working for someone else's compliance requirement, that's a different product than the one you thought you had.

https://arstechnica.com/tech-policy/2026/03/after-discord-fiasco-age-check-tech-promises-privacy-by-running-locally-does-it-work/
#Privacy #CyberSecurity #TechPolicy #security #cloud #infosec

11
0
17
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 10:57:55 UTC