Haroon Meer
@haroonmeer.canary.love
đ€ 1698
đ„ 443
đ 140
Security Geek. We build Thinkst Canary -
https://canary.tools
reposted by
Haroon Meer
Steven
8 days ago
Canary tokens are incredible, bravo
@thinkstcanary.canary.tools
1
7
2
reposted by
Haroon Meer
ThinkstCanary
10 days ago
Leighton & Sharukh just snuck a quick update into
canarytokens.org
to allow you to easily manage all the tokens you've previously created. Still just $0.00 Still one of the best things you can do to detect attackers before they dig in...
loading . . .
0
7
2
Itâs so disingenuous to keep pushing Palestinian liberation further down the the road.. The âdoing X now only hampers long term successâ argument canât be used after decades of failure.. Weâve tried the alternative - letâs try ending the occupation?
13 days ago
0
7
0
Rome takes their FLOSS licenses seriously..
14 days ago
1
3
1
reposted by
Haroon Meer
ThinkstCanary
19 days ago
Today we released our new (free) AWS Infrastructure Canarytoken on
canarytokens.org
. It catches attackers in your AWS account by putting tempting assets in their way and alerting you if they get probed. (1 of 3)
loading . . .
1
6
6
This talk by Ollie Whitehouse is worth watching for Cybersecurity vendors, startups and purchasers. 0 hype, with a bunch of plain-talk current and future challenges (and opportunities). Vendors: do better.. Buyers: demand better..
youtu.be/UVNMozEgYtY?...
loading . . .
The Wicked Problems and Opportunities of Cyber - Ollie Whitehouse
YouTube video by BSides Bournemouth
https://youtu.be/UVNMozEgYtY?si=pzHo8F9d1tsBGGuD
28 days ago
1
12
4
reposted by
Haroon Meer
ThinkstCanary
about 1 month ago
Most of the company is in CapeTown this week for our annual ThinkstCon. This means lots of green stuff, and lots of padel. đȘđ
1
4
1
reposted by
Haroon Meer
ThinkstCanary
about 1 month ago
It's our birthday, so we created a tiny skunk(worksy) game for you to play.. Complete all 7 continents, and we will send you a limited-edition, 10-year t-shirt. Have fun!! (but watch out for the Canaries)
canary.tools/10-year
loading . . .
0
8
3
reposted by
Haroon Meer
ThinkstCanary
about 1 month ago
In April this year,
@grafana.bsky.social
had a security incident due to an insecure GitHub Action. The attackers even tried covering their tracks. How were they discovered? Canarytokens.. Check out their postÂč on how they use our tokens at scale.. __ Âč
grafana.com/blog/2025/08...
loading . . .
Canary tokens: Learn all about the unsung heroes of security at Grafana Labs | Grafana Labs
Learn why the use of canary tokens let us spot a recent intrusion and swarm quickly in response, and find out why you should be using canary tokens to prevent serious security incidents in the future.
https://grafana.com/blog/2025/08/25/canary-tokens-learn-all-about-the-unsung-heroes-of-security-at-grafana-labs/
0
5
2
reposted by
Haroon Meer
Mostafa Moradian
about 1 month ago
How do you know you're compromised? Read my newest article to see how we used canary tokens to detect an attack on our infrastructure.
grafana.com/blog/2025/08...
loading . . .
Canary tokens: Learn all about the unsung heroes of security at Grafana Labs | Grafana Labs
Learn why the use of canary tokens let us spot a recent intrusion and swarm quickly in response, and find out why you should be using canary tokens to prevent serious security incidents in the future.
https://grafana.com/blog/2025/08/25/canary-tokens-learn-all-about-the-unsung-heroes-of-security-at-grafana-labs/
0
6
5
I know academic papers usually prefer to do vendor neutral studies, but it would be fun to see an empirical study of security-vendor-X through the ages. âRarely is the question asked: Is our cÌ”hÌ”iÌ”lÌ”dÌ”rÌ”eÌ”nÌ” vendors learning?â
about 1 month ago
0
2
0
At BlackHat this year we paid a student to walk the business hall (for both days) to collect as much swag as possible. We wondered if we would learn anything useful from it. Prelim. findings are not particularly interesting đ€·ââïž
about 1 month ago
2
9
1
-=[ PHRACK PROPHILE ON Gera ]=-
phrack.org/issues/72/2#...
Thatâs the whole postâŠ
loading . . .
.:: Phrack Magazine ::.
Phrack staff website.
https://phrack.org/issues/72/2#article
about 2 months ago
1
15
4
reposted by
Haroon Meer
ThinkstCanary
about 2 months ago
"We had good success with your canaries at ..." "I would like to intro my (new) team at ...." 10 years in && we still do 0 outbound sales. We've had the best customers since day-1! đȘđ
0
2
2
I thought Ezra Klein came across badly when he & Ta-Nehisi talked Israel/PalestineÂč - but he did the same discussing âGenocideâ with Phillipe SandsÂČ. Sands: itâs not complex, splitting hairs is a distraction Klein: letâs split some hairs __ Âč
youtu.be/Tg77CiqQSYk?...
ÂČ
youtu.be/RrhBypHFYPY?...
loading . . .
Ta-Nehisi Coates on Israel: âI Felt Lied To.â
YouTube video by The Ezra Klein Show
https://youtu.be/Tg77CiqQSYk?si=6QmnCMzVrEUoKUlN
about 2 months ago
0
3
0
reposted by
Haroon Meer
ThinkstCanary
about 2 months ago
A friendly reminder from your Canary Console that if you are in the Northern Hemisphere, you can probably check out the Perseid meteor shower this week.. đȘđđ«
loading . . .
1
12
2
reposted by
Haroon Meer
ThinkstCanary
about 2 months ago
BlackHat boothing was great. We got to hang-out with customers & chat Canary with a bunch of new folks.. Our booth has changed, our tech has levelled up (by orders of magnitude) but it's the same priceÂč as always, & still "just works!" __ Âč Still never increased prices since year-1
0
8
1
1) I totally think that LLMs are amazing; 2) The BlackHat showroom floor was embarrassingly covered in AI/Agentic/*
about 2 months ago
1
5
0
So long Vegas. Was leet meeting customers and old friends, but Iâm out early.
about 2 months ago
0
3
0
reposted by
Haroon Meer
ThinkstCanary
about 2 months ago
The 2025, Q2 edition of ThinkstScapes is now available for downloadÂč at
thinkst.com/ts
If you are in Vegas for BlackHat, swing by our booth for a hard copy. This edition tracks "over 1,450 talks & papers & almost 1,400 blog posts" __ Âč As always, completely free
0
3
1
It is mildly obscene how many times i've been to Las Vegas.
2 months ago
3
4
0
The momentum that Chromebooks (as a secure enterprise desktop) had a few years back seems to have waned.. Anyone still have faith?
2 months ago
2
4
0
Iâm not sure what it means, but I think I see more âon my way to BlackHatâ posts on my LinkedIn feed than on my Twitter timeline..
2 months ago
1
1
0
This Christine Amanpour interview with leaders of B'Tselem & 'Physicians for Human Rights Israel' is worth watching. It is insane that conscientious Israelis (inside Israel) are now calling this a genocide, while ppl outside are relying on played out tropes.
youtu.be/kNJbNCCejvg?...
loading . . .
Israeli rights groups accuse government of genocide: 'We are doing it with a heavy heart'
YouTube video by CNN
https://youtu.be/kNJbNCCejvg?si=Hedd-3bPuLVjurBf
2 months ago
0
5
2
2 months ago
0
10
0
Totally didnât think it worked like thatâŠ
2 months ago
1
5
3
I don't think i've ever had an MS Teams call without a deep pit of stomach worry that the call setup will fail first time.. For me, it remains impressively bad..
2 months ago
3
5
0
Perplexity launched their own browser (Perplexity Comet) which reinforces the ânext Googleâ vibe.. When Goog did Chrome, they had the best sec team on the planet, & part of their pitch was security, tab isolation, etc. It bodes badly that sec doesnât get a mention now at all..
3 months ago
2
7
2
The AI boom has turned several SV maxims on their head: - Researchers donât build companies; - You donât make money selling developer tools; - You earn the big money being a founder (instead of deep tech researcher). Everything holds till it doesnât
3 months ago
0
0
0
If you listened to Tesla-fans, youâd almost believe that Waymoâs werenât using AI to drive..
3 months ago
0
3
0
Itâs hard to miss that WHOOP is currently everywhere. Hard to catch a podcast/sport clip without seeing one. I wonder if people have gotten a little weary of notifications/a screen on their wrist.
4 months ago
1
1
0
It's kinda funny that as more hardware and software uses AI to "touch up" faces, it will get more difficult to tell real from fake, but in the other direction... Fun times...
4 months ago
1
3
0
New startup marketing playbook just dropped
loading . . .
4 months ago
2
37
22
On the other hand.. Mars is probably looking a lot more attractive all of a sudden..
4 months ago
0
4
0
Alex Carp is straight outa central casting.. The problem is that itâs not completely clear what genre of movie this is yet..
4 months ago
0
0
0
reposted by
Haroon Meer
ThinkstCanary
4 months ago
We published an internal postÂč that our
@marcoslaviero.bsky.social
recently wrote "on caring". It's worth a read, because as he writes. caring about what is built is surprisingly fragile (and shockingly absent). __ Âč
blog.thinkst.com/2025/06/on-c...
0
3
1
reposted by
Haroon Meer
Geoff Belknap
4 months ago
I â€ïž Thinkst - When you ask real (aka salty) security people what security companies they respect - Thinkst is always on the list. Great work
@haroonmeer.canary.love
1
6
2
reposted by
Haroon Meer
TechCrunch
4 months ago
A decade in, bootstrapped Thinkst Canary reaches $20M in ARR without VC funding
loading . . .
A decade in, bootstrapped Thinkst Canary reaches $20M in ARR without VC funding | TechCrunch
Reflecting on 10 years since its launch, the honeypot maker explains why the company did not take on any VC funding.
https://techcrunch.com/2025/05/29/a-decade-in-bootstrapped-thinkst-canary-reaches-20m-in-arr-without-vc-funding/?utm_campaign=social&utm_source=bluesky&utm_medium=organic
1
20
5
reposted by
Haroon Meer
Patrick Gray
4 months ago
This wkâs show is up, w
@dmitri.silverado.org
,
@metlstorm.risky.biz
and
@haroonmeer.canary.love
We took an exclusive look at how a scattered spider-style crew is hijacking MX records, then taking over entire networks in minutes. We also explore the age old question: Bro, do you even waterboard?
loading . . .
3
25
1
reposted by
Haroon Meer
ThinkstCanary
4 months ago
When we first built
@thinkstcanary.canary.tools
we were proud that it took less than 4 minutes to be useful when bought. Now it takes less than two... Catching attackers is the game the whole family can play...
0
24
2
Turns out AI was to become the whistleblowers we were waiting forâŠ
4 months ago
0
3
0
Watching Dyson release this new vacuum cleaner is totally delightful.â© You see the pride in the details they believe matter, you see the determination to solve the right problems and mostly, you see a dedication to the craft..â© 10/10 - no notes.. â©
www.youtube.com/watch?v=ve6J...
loading . . .
The Dyson PencilVac Fluffyconesâą cleaner | Global Premiere
YouTube video by Dyson
https://www.youtube.com/watch?v=ve6JuJV17FQ
4 months ago
3
3
1
(It's probably unfair because i'm pretty into the Apple eco-system, but) I watch Apple keynotes/WWDC and expect to be using the products within a bit.. I almost never watch Google/IO expecting to bump into the tech they talk about in any version of "soon"...
5 months ago
1
1
0
Props to the North Koreans who took all the âunfilled jobs in infosecâ and turned it into an advantage.. Waiting for their âthe obstacle is the wayâ best-seller to drop..
5 months ago
1
7
1
Re: the Coinbase hack: "Hackers had paid multiple contractors and employees working in support roles outside the U.S. to collect information" In our 2016 TROOPERS talk we mentioned how most orgs ignore the power of support/helpdesks: __ 1) Apologies for "guys"; 2)
www.youtube.com/watch?v=rarp...
loading . . .
[TROOPERS15] Haroon Meer - Keynote
YouTube video by TROOPERS IT Security Conference
https://www.youtube.com/watch?v=rarpym8JJXQ
5 months ago
0
5
0
At some point, i decided it was unfair to judge people who quoted Ayn Rand/Atlas Shrugged without actually having read it.. Having now endured some 50 hours of it on Audible (with about 12 to go), my judgement is actually more severe.. Really impressively bad..
5 months ago
4
11
3
Iâm consistently surprised by company CEOs who tell me that âthe product doesnât matterâ. They generally spout some anachronistic platitudes about how $other.thing is what actually matters. Kinda amusingly - they are usually saying this while lamenting their lack of sales.
5 months ago
1
4
0
Internal release naming is totally becoming serious business at
@thinkstcanary.canary.tools
5 months ago
0
4
1
With all the comments on live goats being used as a booth attraction at
#RSAC
, you have to feel sorry for the marketing team at OpenText. They had a huuuge booth & banners _also_ using goats as the central theme. Folks in marketing worked a bunch & got kinda out-goated..
5 months ago
0
1
0
Load more
feeds!
log in