Elizabeth Wharton
@lawyerliz.bsky.social
📤 2946
📥 354
📝 194
Adviser, lawyer, and sometimes cybersecurity circus ringmaster - my monkeys fly.
reposted by
Elizabeth Wharton
TechCrunch
about 23 hours ago
The European Commission said on Friday that it has preliminarily found that both companies are not complying with rules of the Digital Services Act (DSA) that mandate them to give researchers adequate access to public data.
loading . . .
EC finds Meta and TikTok breached transparency rules under DSA | TechCrunch
The European Commission said on Friday that it has preliminarily found that both companies are not complying with rules of the Digital Services Act (DSA) that mandate them to give researchers adequate access to public data.
https://techcrunch.com/2025/10/24/ec-finds-meta-and-tiktok-breached-transparency-rules-under-dsa/
0
30
10
reposted by
Elizabeth Wharton
Electronic Frontier Foundation
18 days ago
Happy Amazon Prime Day! Amazon collects mountains of data about how you use the service, but there is a setting you can change to make it harder for the company to use that data to sell you more things.
#OptOutOctober
www.eff.org/deeplinks/2...
26
740
386
reposted by
Elizabeth Wharton
Jason Kikta
about 23 hours ago
It did not. The reporter took the date on my original email about the planned malware release and assumed that the graphic was begun at the same time. I sketched out a rough version of that with the PAO in like 15 minutes of brainstorming on a whiteboard. She then sent it to the graphic contractor.
add a skeleton here at some point
2
64
17
Sir Toby has questions. Same here, same.
23 days ago
0
4
0
Trust but verify - yes, you should check the citations in your work before submitting it. Period. $10k is getting off lightly.
add a skeleton here at some point
about 1 month ago
1
4
0
reposted by
Elizabeth Wharton
Zack Whittaker
about 1 month ago
For TechCrunch, I wrote about Unit 221B, a cybersecurity company that's recently made a name for itself by tracking today's top English-speaking hacking groups, including Scattered Spider, and helping to disrupt their operations. Now the company has raised $5 million to focus on the threat.
loading . . .
Unit 221B raises $5 million to help track and disrupt today’s top hacking groups | TechCrunch
The seed funding raise will help Unit 221B expand its threat intelligence platform, which tracks the English-speaking youth hacking phenomenon.
https://techcrunch.com/2025/09/22/unit-221b-raises-5-million-to-help-track-and-disrupt-todays-top-hacking-groups/
1
30
14
reposted by
Elizabeth Wharton
TechCrunch
about 1 month ago
Travelers at major European airports including Heathrow, Brussels, and Berlin faced significant delays this weekend following what Collins Aerospace described as a “cyber-related incident.”
loading . . .
Hundreds of flights delayed at Heathrow and other airports after apparent cyberattack | TechCrunch
Travelers at major European airports including Heathrow, Brussels, and Berlin faced significant delays this weekend following what Collins Aerospace described as a “cyber-related incident.”
https://techcrunch.com/2025/09/21/hundreds-of-flights-delayed-at-heathrow-and-other-airports-after-apparent-cyberattack/
1
17
7
reposted by
Elizabeth Wharton
Randall Munroe
about 1 month ago
Biology Department
xkcd.com/3140/
33
5007
721
reposted by
Elizabeth Wharton
Eileen Clancy 🧿
about 2 months ago
This
@consumerreports.org
article by
@yaelwrites.com
compares the different services that scrub your name off data brokers' lists. To cut to the chase –the most expensive service is ~$249/year. You can get the same result with EasyOptOuts for $19.99.
easyoptouts.com
add a skeleton here at some point
0
20
7
reposted by
Elizabeth Wharton
darth™️
about 2 months ago
there is good in this world u just have to know where to look
add a skeleton here at some point
10
1377
155
reposted by
Elizabeth Wharton
Shiv Ramdas Mens Rice Activist
about 2 months ago
Robocop is one of the greatest films ever made and on the short list of contenders for single best dystopian satire Hollywood has produced in the last 40 years
add a skeleton here at some point
37
729
108
reposted by
Elizabeth Wharton
Max Kennerly
about 2 months ago
Nice schadenfreude here, Reuters dug up Bill Pulte's father & stepmother claiming two houses as their primary residence, and when Reuters asked Michigan about it, Michigan yanked their homestead exemption.
add a skeleton here at some point
31
1547
452
reposted by
Elizabeth Wharton
One of the methods that I used for a fun project that I presented at
#Labscon
a couple of years ago - tracking which law firms worked with Russian oligarchs based on patterns in legal filings and demand letters.
about 2 months ago
1
2
1
Yep. Follow this kind of law firm + client copy/paste (comms, filings, letters) for all kinds of data points to run through LLM agent analysis -
add a skeleton here at some point
about 2 months ago
2
2
0
reposted by
Elizabeth Wharton
TechCrunch
about 2 months ago
X's new encrypted messaging feature, XChat, has some red flags.
loading . . .
X is now offering me end-to-end encrypted chat. You probably shouldn't trust it yet. | TechCrunch
X's new encrypted messaging feature, XChat, has some red flags.
https://techcrunch.com/2025/09/05/x-is-now-offering-me-end-to-end-encrypted-chat-you-probably-shouldnt-trust-it-yet/
8
27
19
reposted by
Elizabeth Wharton
Viktor Winetrout
about 2 months ago
Life is short and the hour of our death is a mystery, so no, I will not rate my transaction
14
1492
330
Puppy love. Sir Toby has stolen my heart. That’s all. Carry on.
2 months ago
1
5
0
reposted by
Elizabeth Wharton
Zack Whittaker
2 months ago
NEW: Earlier this month, two hackers published their findings in Phrack magazine after earlier breaking into the computer of a North Korean government hacker. Now, in speaking with
@lorenzofb.bsky.social
, the two hackers explain why they went public — even though their breach was probably illegal.
loading . . .
Hackers who exposed North Korean government hacker explain why they did it | TechCrunch
The two self-described hacktivists said they had access to the North Korean spy’s computer for around four months before deciding what they had found should be made public.
https://techcrunch.com/2025/08/21/hackers-who-exposed-north-korean-government-hacker-explain-why-they-did-it/
3
38
27
reposted by
Elizabeth Wharton
Darth Putin
2 months ago
We refuse to allow Ukraine to interfere in its own internal affairs.
add a skeleton here at some point
30
656
138
reposted by
Elizabeth Wharton
Gareth L. Powell
2 months ago
In the bookshop this morning: PARENTS: “Okay, we’re leaving now.” CHILD: *pulls another book from the shelf and sits down * CHILD: “Then I guess this is goodbye.”
184
10227
1302
Highlights some of the 🛰️ security challenges that the
@aerospacevillage.bsky.social
spotlighted at
#defcon33
and beyond…
apnews.com/article/spac...
loading . . .
Hijacked satellites and orbiting space weapons: In the 21st century, space is the new battlefield
Outer space has emerged as the world's next battlefield, demonstrated by recent cyberattacks on satellites blamed on Russia.
https://apnews.com/article/space-weapons-trump-satellites-russia-0fdd31a1e3d350a54823e8a3d228fc17
2 months ago
0
4
0
reposted by
Elizabeth Wharton
Allan “Ransomware Sommelier” Liska
2 months ago
I love being able to post cybersecurity wins, something I can’t do too often :( via
@reuters.com
loading . . .
Poland foiled cyberattack on big city's water supply, deputy PM says
A large Polish city could have had its water supply cut off on Wednesday as a result of a cyberattack, a deputy prime minister said after the intrusion was foiled.
https://www.reuters.com/en/poland-foiled-cyberattack-big-citys-water-supply-deputy-pm-says-2025-08-14/
0
30
9
reposted by
Elizabeth Wharton
Marcus Hutchins
2 months ago
Going live is approx 30 mins
www.youtube.com/watch?v=lRlC...
loading . . .
Patch Analysis & Exploit Dev - Featuring Chompie1337
YouTube video by Marcus Hutchins
https://www.youtube.com/watch?v=lRlCrYiqmWQ
1
38
9
reposted by
Elizabeth Wharton
J. L. Westover
2 months ago
freak flag
7
1558
214
reposted by
Elizabeth Wharton
Phrack Zine
2 months ago
Heeey NYC! Come celebrate 40 years of Phrack with
@vacci.ne
@guitmz.bsky.social
@hackerschoice.bsky.social
! We'll be at
@2600.com
's HOPE Conference tomorrow at 17:00!
#phrack72
#phrackat40
schedule.hope.net/hope16/talk/...
loading . . .
Phrack Magazine #72 - 40th Anniversary Release Party HOPE_16
Celebrate 40 years of legendary hacking with Phrack Magazine! Netspooky and TMZ will be dropping a special hardcopy release of their magazine, packed with cutting-edge research, underground insights, ...
https://schedule.hope.net/hope16/talk/CGVSAM/
0
26
13
reposted by
Elizabeth Wharton
Eric Capuano
2 months ago
If you’re interested in tinkering with LLMs to assist with incident triage, check out this demo I did with
@limacharlie.io
using Claude Code and the LC MCP:
youtu.be/dSCmLIBkTdo?...
I open sourced the Claude configs and context files for anyone that wants to try it out:
github.com/Digital-Defe...
loading . . .
The unopinionated AI advantage: Building AI-powered SecOps on your terms
YouTube video by LimaCharlie
https://youtu.be/dSCmLIBkTdo?t=1477&si=PSeo-rkasfzZifDl
0
12
8
reposted by
Elizabeth Wharton
Benjamin Ahr Harrison
2 months ago
My son walked into the room and said “I’m a Tyrannosaurus Cow!” And then roared a moo at me, so I drew this.
29
1459
231
reposted by
Elizabeth Wharton
Zack Whittaker
2 months ago
NEW, by me: Last week we reported TeaOnHer, a gossip dating app for men that rocketed to the top of Apple's App Store, was exposing users' data and driver's licenses, which users had to upload to sign up. The bugs now seem fixed. This is how we found the data-exposing flaws in less than 10 minutes.
loading . . .
How we found TeaOnHer spilling users' driver's licenses in less than 10 minutes | TechCrunch
Exclusive: A dating gossip app for men exposed thousands of users' personal data, including scans of driver's licenses. The app's developer, Xavier Lampkin, won't say if he plans to notify affected us...
https://techcrunch.com/2025/08/13/how-we-found-teaonher-spilling-users-drivers-licenses-in-less-than-10-minutes
4
52
36
reposted by
Elizabeth Wharton
Micah Lee
2 months ago
I just added a copy of my slides for my "We are currently clean on OPSEC" DEFCON talk here, in case you're interested
micahflee.com/we-are-curre...
loading . . .
"We are currently clean on OPSEC": The Signalgate Saga
I just gave my first solo main stage DEFCON talk, about Signalgate, and I think it was a resounding success! The room was packed – apparently people were waiting outside to get in. I got tons of posit...
https://micahflee.com/we-are-currently-clean-on-opsec-the-signalgate-saga/
0
58
24
When the theme is
#cybersecurity
in
#aviation
+
#space
& its
@defcon.bsky.social
, of course you dress accordingly. Great fun w/
@blueteamvillage.bsky.social
+
@aerospacevillage.bsky.social
TTX (thx to fellow panelists for keeping it entertaining)
3 months ago
0
12
2
reposted by
Elizabeth Wharton
NPR
3 months ago
When Dana's son was hospitalized last year, it led her to a path of discovery about predatory online networks that groom children into harming themselves and others. Their reach is global and growing.
loading . . .
Nihilistic online networks groom minors to commit harm. Her son was one of them
When Dana's son was hospitalized last year, it led her to a path of discovery about predatory online networks that groom children into harming themselves and others. Their reach is global and growing.
https://n.pr/45scGGu
21
304
139
reposted by
Elizabeth Wharton
Zack Whittaker
3 months ago
And my newsletter is out, featuring coverage, research and cool stuff from Black Hat and Def Con, plus stories on the data breaches at Google, Cisco, and Air France, the US courts system getting hacked (again), alarm over a new Exchange flaw, and lots more. 📩
this.weekinsecurity.com
/ read online:
loading . . .
~this week in security~ august 10 edition
Plus: CISA warns of new Exchange bug, encrypted messaging apps spilled messages, TeaOnHer app exposed users' data, and more.
https://mailchi.mp/weekinsecurity/this-week-in-security-august-10-2025-edition
0
5
3
reposted by
Elizabeth Wharton
NPR
3 months ago
Hundreds of United Airlines flights have been disrupted “due to a technology issue,” the airline said in a statement.
loading . . .
United Airlines flights grounded nationwide because of computer problems
Hundreds of United Airlines flights were disrupted on Wednesday evening as the carrier grappled with a major computer system outage. The airline requested ground stops at its major hubs in the U.S.
https://n.pr/4lhJsQC
27
347
111
reposted by
Elizabeth Wharton
Catalin Cimpanu
3 months ago
Breach at two airlines: KLM and Air France
nieuws.klm.com/klm-informee...
1
39
17
reposted by
Elizabeth Wharton
Allison Nixon
3 months ago
My BSidesLV keynote is here. It touches on several difficult topics in our industry. Topics best discussed in person. As our industry spends this week in Vegas, please share this talk with your peers and discuss in person.
www.youtube.com/watch?v=4CD9...
loading . . .
BsidesLV 2025 - Breaking Ground - Monday
YouTube video by BSidesLV
https://www.youtube.com/watch?v=4CD95pnIBKY&t=10362s
0
21
7
reposted by
Elizabeth Wharton
Klaus Agnoletti
3 months ago
Allright. You should see my talk at 5 pm Tuesday then 😊
bsideslv.org/talks#HVRLVM
loading . . .
Talks - BSides Las Vegas
BSides Las Vegas is a nonprofit organization formed to stimulate the Information Security industry and community.
https://bsideslv.org/talks#HVRLVM
1
2
1
Heading to Def Con? Catch me & our panel hosted by Blue Team Village + Aerospace Village:
btv-dc33.sessionize.com/session/966550
loading . . .
Space Camp 33: An Orbital Incident Response Odyssey
Join Blue Team Village and Aerospace Village for a high-stakes, interactive tabletop exercise that launches cybersecurity into orbit — literally. In Space Camp 33, participants will respond to a casca...
https://btv-dc33.sessionize.com/session/966550
3 months ago
1
3
0
reposted by
Elizabeth Wharton
Catalin Cimpanu
3 months ago
CISA has published a report from a "proactive hunt" at an unnamed US critical infrastructure operator. It's a headache-inducing report, and I'm being generous on the findings.
www.cisa.gov/news-events/...
2
22
9
Here we go again, hacker summer camp. See y’all soon.
3 months ago
2
50
0
reposted by
Elizabeth Wharton
Zack Whittaker
3 months ago
NEW, by me: Hackers breached U.S. insurance giant Allianz Life in July and stole the "majority" of its customers' personal information. The company confirmed the breach to TechCrunch, but wouldn't provide an accurate number of affected customers. Its parent company, Allianz, has 125 million members.
loading . . .
Allianz Life says 'majority' of customers' personal data stolen in cyberattack | TechCrunch
Exclusive: Allianz Life said the "majority" of its customers and employees had data stolen in the June cyberattack. The insurance giant has more than 125 million customers worldwide.
https://techcrunch.com/2025/07/26/allianz-life-says-majority-of-customers-personal-data-stolen-in-cyberattack/
4
38
29
Delta flight attendant understands the assignment: he keeps bringing me extra snacks from the basket & laughs as I squirrel them away for later.
3 months ago
1
5
0
reposted by
Elizabeth Wharton
Rowdy
3 months ago
So you've decided to piss off every career intelligence officer and analyst
add a skeleton here at some point
5
44
9
reposted by
Elizabeth Wharton
Eric Geller
3 months ago
I missed this last week, but the Coast Guard's cybersecurity regulations for U.S.-flagged vessels and facilities took effect on July 16.
www.news.uscg.mil/maritime-com...
www.federalregister.gov/documents/20...
1
1
1
reposted by
Elizabeth Wharton
A. D. Vigilante (Author/Artist)
3 months ago
Editor, those are my emotional support "--" and "..." 😭
#writersky
11
422
181
reposted by
Elizabeth Wharton
InfoSteph
3 months ago
✨ new substack just dropped ✨ i’ve been quiet for a minute, but i’m back with a new format, an epiphany, and a gentle promise to stop giving all my energy to things that don’t give back. Also, I'm on a biweekly schedule now! 📝 read here:
open.substack.com/pub/justasec...
💛 comment if it resonates
loading . . .
July Newsletter: The Energy Audit
Allow me to reintroduce myself...and this wonderful newsletter that I've neglected. I'm back, baby! New epiphanies, new updates, new commitment to consistency!
https://open.substack.com/pub/justasecwithsteph/p/july-newsletter-the-energy-audit?r=ft53r&utm_campaign=post&utm_medium=web&showWelcomeOnShare=true
1
8
2
reposted by
Elizabeth Wharton
Adam Shostack
3 months ago
Hot take: Threat modeling ≠ risk management Threat = possible problem Risk = quantified threat Threat modeling finds issues → we engineer them away (TLS, MFA, etc.) Risk management = when threats can't be easily fixed Most execs care more about customer impact than CVSS scores 🤷♂️ Full:
is.gd/5QEfVJ
0
6
1
reposted by
Elizabeth Wharton
Zack Whittaker
3 months ago
Per
@ellenwapo.bsky.social
&
@joemenn.bsky.social
et al, U.S. state and federal government agencies have already been breached by the SharePoint zero-day bug. Commercial sector also affected. Tens of thousands of SharePoint self-hosted servers around the world at risk.
loading . . .
Global hack on Microsoft product hits U.S., state agencies, researchers say
Unknown attackers exploited a “significant vulnerability” in Microsoft’s SharePoint collaboration software, hitting targets around the world.
https://www.washingtonpost.com/technology/2025/07/20/microsoft-sharepoint-hack/
0
6
9
reposted by
Elizabeth Wharton
TechCrunch
3 months ago
A surveillance vendor was caught exploiting a new SS7 attack to track people’s phone locations
loading . . .
A surveillance vendor was caught exploiting a new SS7 attack to track people's phone locations | TechCrunch
The new SS7 bypass-attack tricks phone operators into disclosing a cell subscriber's location, in some cases down to a few hundred meters.
https://techcrunch.com/2025/07/18/a-surveillance-vendor-was-caught-exploiting-a-new-ss7-attack-to-track-peoples-phone-locations/?utm_campaign=social&utm_source=bluesky&utm_medium=organic
1
16
9
Load more
feeds!
log in