Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Lenny Zeltser

@lennyzeltser@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Builder of security products and programs. Teacher of those who run them.

I'm a cybersecurity executive with deep technical roots, product management experience, and a business mindset. I've built security products and programs from early stage to enterprise scale. I'm also a Faculty Fellow at SANS Institute and the creator of REMnux, a popular Linux toolkit for malware analysis. I share perspectives on security leadership and technology at zeltser.com.

#CISO #CyberSecurity #malware #infosec #fedi22 #searchable

0 Followers
0 Following
15 Posts
Joined November 08, 2022
About:
https://zeltser.com/about
Blog:
https://zeltser.com/writing
Linkedin:
https://www.linkedin.com/in/lennyzeltser/
Twitter:
https://x.com/lennyzeltser
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 2mo ago
AI capabilities of keyboard apps (rewrites, voice transcription, generative writing) entice us into letting our keystrokes float to the developer's servers. That makes each one a keylogger we authorized, with safeguards left to the developer. https://zeltser.com/third-party-keyboards-security #privacy #communication
16
1
12
1
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 2mo ago
I've seen too many author-centric assessment reports, full of stories of conquest and irrelevant details. The best reports are reader-centered. My new template offers a consistent way to write them that way. It's AI-friendly, too. https://zeltser.com/security-assessment-report-template #assessments #riskmanagement
3
0
1
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 7mo ago

The new REMnux MCP server connects AI agents to 200+ malware analysis tools. I was surprised at the depth of investigation it can deliver: https://zeltser.com/ai-malware-analysis-remnux

Most of my time on this project went into capturing how I approach malware analysis and making sure the server provides the right guidance at the right time, so that AI can think and adapt as it creates the workflow. The post includes interactive replays of real analysis sessions.

#malware #malwareanalysis #infosec #cybersecurity #tools #artificialintelligence #AI

Using AI Agents to Analyze Malware on REMnux
Lenny Zeltser

Using AI Agents to Analyze Malware on REMnux

To analyze malware effectively, AI agents need practitioners

7
0
6
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 5mo ago

"A technical postmortem on how one person with zero coding experience built a self-evolving AI swarm across 11 platforms using 900 accounts, 56 GitHub Actions workflows, and $0 in compute costs."

Junliang Shu's full postmortem:
https://blog.mulerun.com/p/ai-immortality-postmortem/

#Cybersecurity #InfoSec #AI

3
0
3
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 5mo ago

We told employees to "be suspicious" of links they needed for work. Now we're adding "be careful with AI" to the awareness curriculum. Teaching when to escalate works better than teaching what to fear.

https://zeltser.com/ai-influence-awareness-training

#cybersecurity #AI #securityawareness #infosec

1
0
2
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 2mo ago
Threat attribution works at 3 levels: Tactical examines the incident, operational characterizes the campaign, and strategic asks who's responsible and why. Disciplined analysts weigh the same 6 signals at every level. https://zeltser.com/six-signals-for-threat-attribution #malwareanalysis #incidentresponse
0
0
0
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 2mo ago
Observability, short-lived credentials, and active enforcement held the web's certificate trust model through a decade of CA failures. The same three levers work anywhere you delegate trust, from code signing to identity federation. https://zeltser.com/past-present-future-web-trust-model #encryption #history
0
0
0
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 2mo ago
My new template for security assessment reports offers a structured, repeatable approach to communicating with readers. It's based on my experience creating and reading many such reports over the years. It's AI-friendly, too. https://zeltser.com/security-assessment-report-template #assessments #riskmanagement
0
0
0
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 2mo ago
Sounil Yu and I built the AI Defense Matrix, an approach for deciding how to defend the various AI systems in your environment. Here's why. https://www.sans.org/blog/why-sounil-yu-i-built-ai-defense-matrix #cybersecurity #AI
0
0
0
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 2mo ago
A decade of CA failures could have collapsed the web's certificate trust model, but they didn't. Browsers and CAs addressed each failure with a structural fix, and the same approach applies wherever you delegate trust. https://zeltser.com/past-present-future-web-trust-model #encryption #history
0
0
0
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 2mo ago
Security leaders are making AI security decisions with almost no data about what their peers are doing. Sounil Yu and I built a five-minute anonymous survey to change that, and we'll publish the findings so you can benchmark your approach. https://zeltser.com/ai-security-survey #artificialintelligence #riskmanagement
0
1
0
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 1mo ago
Third-party keyboards can leak our keystrokes even when the developer isn't malicious. A supply chain attack can hijack a legitimate app, and weak engineering and security practices can expose highly sensitive data. https://zeltser.com/third-party-keyboards-security #privacy #communication
0
0
0
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 1mo ago
If you help secure AI, whatever your title, Sounil Yu and I have ten quick questions for you. Anonymous, mostly checkboxes. We'll share the analysis, so the more practitioners respond, the more useful the benchmark becomes for everyone. https://zeltser.com/ai-security-survey #artificialintelligence #riskmanagement
0
0
0
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 1mo ago
Attackers and their malware can turn our trusted tools against us to steal API and SSH keys. In the s1ngularity attack, hijacked AI coding agents combed developer machines for such secrets. Here's how to minimize our exposure. https://zeltser.com/securing-api-keys-on-your-workstation #tools #artificialintelligence
Securing API Keys on Your Workstation
Lenny Zeltser

Securing API Keys on Your Workstation

Every dev tool you grant API access to, AI assistants included, can read the keys within its reach. No setup removes that risk entirely, so the goal is fewer secrets exposed and less damage when one leaks.

0
0
0
0
Open post
Lenny Zeltser @lennyzeltser@infosec.exchange
· 1mo ago
When everyone's attention is on a celebrity vulnerability, you can organize your investigation and share findings using my new template. It's AI-friendly, of course. https://zeltser.com/high-profile-vulnerabilities #communication #riskmanagement
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 16:24:45 UTC