The AI vulnpocalypse isn't a real thing
Dennis
Wrote a couple books, started a couple things, met Shaq once.
It's been one year since we launched the revamped version of @Deciphersec@infosec.exchange, which is hard to believe. Lots more cool stuff is on the horizon!
https://decipher.sc/2026/09/02/one-year-of-decipher-relaunched/
ExploitGym: Nightmare CrossFit studio or AI benchmark? Why not both!
Talked to the great @cigitalgem@sigmoid.social on the @Deciphersec@infosec.exchange podcast this week about what's really happening with AI security, model escapes, etc.
https://youtu.be/M9uUuWnUb-A?si=OlyF_5EgcYpbSYt0
Aloha! New @Deciphersec@infosec.exchange podcast with @todb@infosec.exchange of @runZeroInc@infosec.exchange is available for your listening/viewing pleasure.
https://youtu.be/9WNJugOOqug?si=1uVXypF-w-9fIjBY
We have a secret weapon at @Deciphersec@infosec.exchange and it's @LindseyODWelch@infosec.exchange. Great video with @cigitalgem@sigmoid.social and @k8em0@infosec.exchange on the Claude Mythos non-release.
Fix the Dang Software: Claude Mythos and Vulnerability Research
I'm relatively certain some of y'all can read, so here's an excerpt of my @Deciphersec@infosec.exchange podcast with @todb@infosec.exchange in word form.
https://decipher.sc/2026/03/03/qa-tod-beardsley-on-how-to-use-cisas-kev-catalog/
Got the chance to talk to my pal @jags@infosec.exchange, famous podcast host, about the @SentinelLabs@infosec.exchange fast16 research and the expanding history of cyber espionage tools.
R2D2 IS A HACKER (sorry for yelling) and me and @rmogull@defcon.social and @wade@infosec.exchange talked about it!
Talked with the great @rmogull@defcon.social about the Cloudflare outage and platform fragility.
https://youtu.be/2118EJ4Gb5s?si=mJAKMr4hDUwl3Tw9
New @Deciphersec@infosec.exchange podcast, in which we talk about the Vercel intrusion and what in the world is happening with CISA these days.
https://open.spotify.com/episode/19N3VtIS1OU3PhnTnFKnzG?si=PO2CnB1_T8eUms3mLnesPw
Hey guess what! Me and @wendynather@infosec.exchange talked about The Martian and Mark Watney, space hacker, on a new @Deciphersec@infosec.exchange podcast!
Did you favorite vuln make the Mt. Rushmore of Branded Bugs? Only one way to find out!
https://decipher.sc/2026/04/30/a-copy-fail-faq/
Did I talk about CSI: Cyber and @0xcharlie@bird.makeup and @nudehaberdasher@bird.makeup on this @Deciphersec@infosec.exchange podcast? You bet your ass I did.
https://open.spotify.com/episode/2Zi84e5YP7buD3Zfz3mJyt?si=6da2feed1e054be5
🚨 New @Deciphersec@infosec.exchange podcast is up!
🪲 New Fortinet SSO auth bypass exploitation
🪲 Attacks on old WinRAR flaw
🖥️ Google disrupts IPIDEA proxy network
https://open.spotify.com/episode/5k9xpXyD7YSlJRkYqoCQde?si=K-CkeXMgRvGLHnpVpxNg1w
New @Deciphersec@infosec.exchange podcast with the great @tqbf@infosec.exchange on Claude Mythos and all things AI-assisted bug hunting.
https://open.spotify.com/episode/4EVod019ZbZMRJqtraka6i?si=d5fb611cef1e4a6e
Insert Fleetwood Mac supply chain joke here.
I got to talk to the great @catc0n@infosec.exchange for the @Deciphersec@infosec.exchange podcast. It was great because she's great.
Very fun new @Deciphersec@infosec.exchange podcast with my old friend Jeff Gothelf, talking about lean UX, collaboration for security teams, and lots of other stuff.
https://youtu.be/6kBvEmB4eCQ?si=xfGkwSm0n-tO6Zgl
I can't get over how this operation was handled.
https://decipher.sc/2026/04/05/the-285m-drift-protocol-heist-was-6-months-in-the-making/
Sleeping too well at night? Having pleasant dreams? I have the cure for that! Thanks to our pals at Material security.
In case you were actually living your life this weekend and missed it, things popped off with Citrix.
https://decipher.sc/2026/09/27/researchers-warn-of-citrix-netscaler-exploitation/
Old malware never dies, it just goes to live in OT networks.
Every day can be zero day if you try hard enough.
https://youtu.be/4M2ooW4IJfI?si=NO8ZMvcHNNqRtndu
Mondays are crap, but here's a new @Deciphersec@infosec.exchange podcast with Ryan Dewhurst from @watchtowrcyber@bird.makeup to brighten your day!
https://youtu.be/5WznmQpJnj4?si=bhnQ_Io_HM4wXSPX
Bulletproof hosting services are a BIG problem.
https://decipher.sc/2025/11/19/doj-sanctions-bulletproof-hosting-provider-used-by-ransomware-groups/
“We’ve got leverage now, our labor is still required and this is our time to strike. You and your creativity are the real frontier. I hope you never pace yourself. Don’t slow down.” @k8em0@infosec.exchange
https://decipher.sc/2026/09/21/we-have-enough-ai-realism-in-a-time-of-relentless-hype/
I talked to one of my absolute favorite people, @amirian@infosec.exchange, for a new @Deciphersec@infosec.exchange podcast about the scourge of trust-based scams and how to stop them. Full episode is up now!
Do you like webshells? No? Too bad! We talked to @watchtowrcyber@bird.makeup CEO Ben Harris about the weirdo Citrix zero day saga on the @Deciphersec@infosec.exchange podcast.
https://youtu.be/4M2ooW4IJfI?si=a3tPrlhfsDXK0c3b
Hey guess what!
If you think surveillance is getting more pervasive, you're not imagining it. We talked to @eff@mastodon.social Exec Director Nicole Ozer about this and much more on the @Deciphersec@infosec.exchange podcast this week.
What's happening with that whole Project Glasswing/Claude Mythos thing? Hard to say! But we gave it a try.
https://decipher.sc/2026/04/13/myths-and-mythos-an-ai-vulnerability-research-faq/
Bonus @Deciphersec@infosec.exchange podcast episode this week, with Will Dixon of @intel471inc@bird.makeup on the cybercrime ecosystem and how it continues to shift and reshape.
https://decipher.sc/podcasts/fighting-cybercrime-with-global-intelligence-will-dixon/
Fun new @Deciphersec@infosec.exchange podcast with Christine Gadsby of BlackBerry, who I've known for *many* years.
https://youtu.be/Vk-RJBr1jS8?si=wUQwWrW5bP5eDv3H
