Lenny Zeltser
@lennyzeltser.com
📤 2376
📥 375
📝 86
Builder of security products and programs. Teacher of those who run them.
https://zeltser.com
pinned post!
You can now receive my blog posts via email. Go ahead and sign up:
https://zeltser.com/newsletter
I've been writing more frequently than I have in recent years, and I'd rather share my articles directly than rely on an algorithm to decide whether to surface them.
loading . . .
Lenny Zeltser's Newsletter
Subscribe to get new posts by email. Cybersecurity, mostly.
https://zeltser.com/newsletter
3 months ago
0
3
1
Security leaders are making AI security decisions with almost no data about what their peers are doing. Sounil Yu and I built a five-minute anonymous survey to change that, and we'll publish the findings so you can benchmark your approach.
https://zeltser.com/ai-security-survey
loading . . .
Benchmark Your AI Security Decisions: A Five-Minute Survey
Answer ten questions about how your organization secures AI, and you get a peer benchmark in return. Sounil Yu and I will publish findings on which AI assets peers protect, who decides, and where controls come from.
https://zeltser.com/ai-security-survey
about 9 hours ago
0
3
1
I've seen too many author-centric assessment reports, full of stories of conquest and irrelevant details. The best reports are reader-centered. My new template offers a consistent way to write them that way. It's AI-friendly, too.
https://zeltser.com/security-assessment-report-template
loading . . .
A Report Template for Security Assessments
The technical severity of an assessment finding tells only part of the story. A customizable report template helps you document the scope, rate findings by risk, and write for the executives and engineers who read the results differently.
https://zeltser.com/security-assessment-report-template
4 days ago
0
1
1
A decade of CA failures could have collapsed the web's certificate trust model, but they didn't. Browsers and CAs addressed each failure with a structural fix, and the same approach applies wherever you delegate trust.
https://zeltser.com/past-present-future-web-trust-model
loading . . .
The Past, Present, and Future of the Web's Trust Model
Observability, short-lived credentials, and active enforcement hold the web's trust model together. Without them, a decade of Certificate Authority failures would've collapsed it. Will those same levers hold for what's coming next?
https://zeltser.com/past-present-future-web-trust-model
5 days ago
0
1
0
Sounil Yu and I built the AI Defense Matrix, an approach for deciding how to defend the various AI systems in your environment. Here's why.
https://www.sans.org/blog/why-sounil-yu-i-built-ai-defense-matrix
6 days ago
0
1
0
AI capabilities of keyboard apps (rewrites, voice transcription, generative writing) entice us into letting our keystrokes float to the developer's servers. That makes each one a keylogger we authorized, with safeguards left to the developer.
https://zeltser.com/third-party-keyboards-security
loading . . .
Security of Third-Party Keyboard Apps on Mobile Devices
Keyboard apps offer better predictions, voice transcription, and AI-powered writing, all requiring users to send what they type to remote servers. Mobile OS vendors set the rules but can't enforce what developers do with that data.
https://zeltser.com/third-party-keyboards-security
6 days ago
0
0
0
My new template for security assessment reports offers a structured, repeatable approach to communicating with readers. It's based on my experience creating and reading many such reports over the years. It's AI-friendly, too.
https://zeltser.com/security-assessment-report-template
loading . . .
A Report Template for Security Assessments
The technical severity of an assessment finding tells only part of the story. A customizable report template helps you document the scope, rate findings by risk, and write for the executives and engineers who read the results differently.
https://zeltser.com/security-assessment-report-template
7 days ago
0
1
0
How can you use your AI agent to transform raw threat notes into a well-sourced CTI report draft? Use my MCP server with my new CTI report template and writing guidance. Your sensitive data stays local.
https://zeltser.com/cyber-threat-intel-report-template
loading . . .
A Report Template for Cyber Threat Intelligence
Cyber threat intelligence analysts produce credible reports by weighing signals at tactical, operational, and strategic levels. A customizable CTI report template helps analysts capture activity, attribute it with calibrated confidence, and translate findings into defensive actions.
https://zeltser.com/cyber-threat-intel-report-template
11 days ago
0
5
1
Observability, short-lived credentials, and active enforcement held the web's certificate trust model through a decade of CA failures. The same three levers work anywhere you delegate trust, from code signing to identity federation.
https://zeltser.com/past-present-future-web-trust-model
loading . . .
The Past, Present, and Future of the Web's Trust Model
Observability, short-lived credentials, and active enforcement hold the web's trust model together. Without them, a decade of Certificate Authority failures would've collapsed it. Will those same levers hold for what's coming next?
https://zeltser.com/past-present-future-web-trust-model
13 days ago
0
0
0
My new template for cyber threat intelligence reports covers tactical, operational, and strategic aspects of threat activity. A companion brief captures the key takeaways for decision-makers. You can also use it with your AI agent.
https://zeltser.com/cyber-threat-intel-report-template
loading . . .
A Report Template for Cyber Threat Intelligence
Cyber threat intelligence analysts produce credible reports by weighing signals at tactical, operational, and strategic levels. A customizable CTI report template helps analysts capture activity, attribute it with calibrated confidence, and translate findings into defensive actions.
https://zeltser.com/cyber-threat-intel-report-template
14 days ago
0
0
0
Threat attribution works at 3 levels: Tactical examines the incident, operational characterizes the campaign, and strategic asks who's responsible and why. Disciplined analysts weigh the same 6 signals at every level.
https://zeltser.com/six-signals-for-threat-attribution
loading . . .
Six Signals for Threat Attribution
Credible threat attribution weighs six signals together. Each signal has a disciplined methodology behind it, with citations and stress tests to back the conclusions.
https://zeltser.com/six-signals-for-threat-attribution
19 days ago
0
0
0
Every domain has its Turbo Encabulator. The more expert we feel, the more fluently we explain something that doesn't exist.
https://zeltser.com/experts-overstate-expertise
loading . . .
Experts Cannot Help Overstating Their Expertise
The more confident we feel in a domain, the more likely we are to claim knowledge that doesn't exist. Recognizing this overclaiming bias helps us invite critique when we share our expertise and ask sharper questions when others share theirs.
https://zeltser.com/experts-overstate-expertise
20 days ago
0
0
0
This template for a security incident report not only helps with documentation, but also offers guidance when capturing findings during the incident. Take it, customize it, use it.
https://zeltser.com/incident-response-report-template
loading . . .
A Report Template for Cybersecurity and Privacy Incident Response
Incident responders need to know which questions to ask and how to communicate the answers to a diverse set of stakeholders. A customizable report template gives the response coordinator that structure when the stakes are high.
https://zeltser.com/incident-response-report-template
21 days ago
0
3
0
Plant a decoy persona, such as a fake LinkedIn profile or an unused directory account, to catch attackers reaching for what they think is real. The decoy has no production use, so any interaction is a high-confidence alert.
https://zeltser.com/the-notion-of-a-honeypot-persona
loading . . .
Plant Decoy Personas to Detect Impersonation Attacks
Decoy personas extend honeytoken thinking to user accounts and public profiles. The technique gives defenders a tripwire on the identity surface that other detection layers don't cover.
https://zeltser.com/the-notion-of-a-honeypot-persona
26 days ago
1
1
0
We read more threat attribution claims than we make. Six signals separate the ones that hold up from the ones that don't, and analysts weigh them together to build a defensible case.
https://zeltser.com/six-signals-for-threat-attribution
loading . . .
Six Signals for Threat Attribution
Credible threat attribution weighs six signals together. Each signal has a disciplined methodology behind it, with citations and stress tests to back the conclusions.
https://zeltser.com/six-signals-for-threat-attribution
27 days ago
0
2
0
Letter grades tied to specific criteria influence business' behaviors, as NYC's sanitation labels have shown. Cybersecurity is starting to follow with the Cyber Trust Mark for IoT, but the consumer web hasn't caught up.
https://zeltser.com/restaurant-inspections-as-security-validation-model
loading . . .
What Cybersecurity Can Learn from NYC Restaurant Inspections
When letter grades are visible at the moment of decision, businesses improve their practices, with NYC restaurants raising their sanitation scores 35% within three years. The U.S. Cyber Trust Mark is starting to bring the model to consumer IoT, while consumers still don't see equivalents on the webs
https://zeltser.com/restaurant-inspections-as-security-validation-model
28 days ago
0
0
0
A decoy persona alerts you when an attacker probes your directory or public profiles. When they can't tell the bait from real identities, you create an asymmetry that gives you the upper hand.
https://zeltser.com/the-notion-of-a-honeypot-persona
loading . . .
Plant Decoy Personas to Detect Impersonation Attacks
Decoy personas extend honeytoken thinking to user accounts and public profiles. The technique gives defenders a tripwire on the identity surface that other detection layers don't cover.
https://zeltser.com/the-notion-of-a-honeypot-persona
about 1 month ago
0
1
0
reposted by
Lenny Zeltser
about 1 month ago
"The career-shaping work happens in the years before the job search." 100% We're seeing others say the same things albeit in other areas, such as leadership
0
0
1
The career-shaping work happens in the years before the job search. Reputation, relationships, and visible work are what land the right role. The resume's job ends at initial screening.
https://zeltser.com/stop-relying-on-your-resume
loading . . .
Stop Relying on Your Resume
A resume gets you past initial screening. Reputation, relationships, and visible work built in the years before the search are what land the right role.
https://zeltser.com/stop-relying-on-your-resume
about 1 month ago
1
1
0
Having interviewed many candidates, I can tell within minutes whether someone prepared for the discussion. A few hours of focused prep often makes the difference between getting the offer and getting a polite no.
https://zeltser.com/interviewing-tips-for-it-job-candidates
loading . . .
5 Interviewing Tips for Tech and Cybersecurity Jobs
Strong technical skills get you to the interview, but preparation gets you the offer. Show up having done the homework that many candidates skip.
https://zeltser.com/interviewing-tips-for-it-job-candidates
about 1 month ago
0
1
0
The REMnux MCP server can now draft malware analysis reports using my new report template:
https://zeltser.com/ai-malware-analysis-remnux
loading . . .
Using AI Agents to Analyze Malware on REMnux
To analyze malware effectively, AI agents need practitioners' expertise and access to the analysis tools. The REMnux MCP server provides both, connecting AI to 200+ tools on REMnux with guidance on which to run and how to interpret their output.
https://zeltser.com/ai-malware-analysis-remnux
about 1 month ago
1
8
1
Self-hosted Algo on DigitalOcean lets us treat the VPN exit IP as disposable. After investigating malicious infrastructure, destroy the droplet, redeploy in minutes, and the next project starts from a clean IP.
https://zeltser.com/deploy-algo-vpn-digital-ocean
loading . . .
How to Deploy Your Own Algo VPN Server in the DigitalOcean Cloud
Tunneling connections through a VPN in a public cloud helps conceal your origin and safeguard traffic when performing security research or connecting over untrusted networks. Algo VPN is an open-source bundle designed for self-hosted VPN services that's easy to deploy on DigitalOcean and relies only
https://zeltser.com/deploy-algo-vpn-digital-ocean
about 2 months ago
0
0
0
I updated my cheat sheet for creating cybersecurity assessment reports. It's a one-page doc, which you can customize:
https://zeltser.com/security-assessment-report-cheat-sheet
loading . . .
Tips for Creating a Strong Cybersecurity Assessment Report
In a strong cybersecurity assessment report, you rate each finding by its risk to the organization rather than its raw tool score. You give readers the context and remediation steps they need to act on it. This cheat sheet covers how to analyze the data, document scope and methodology, write up find
https://zeltser.com/security-assessment-report-cheat-sheet
about 2 months ago
0
3
0
The people who handle breaches all day may be the worst at protecting themselves. Feeling invulnerable is what lets us function around constant threat, the way it lets doctors work around disease. Warnings about our own risk rarely stick.
https://zeltser.com/illusion-of-invulnerability
loading . . .
The Illusion of Invulnerability in Cybersecurity
Healthcare workers wash hands more often when signs emphasize protecting patients rather than themselves, because people overestimate their own invulnerability but not others'. Security messaging may be more effective when highlighting risks to customers or colleagues rather than to the individuals
https://zeltser.com/illusion-of-invulnerability
about 2 months ago
0
0
0
A decoy fires only when someone accesses a resource no legitimate user would touch. Plant tripwires across network, identity, data, and AI agent configs to create asymmetry in your security architecture.
https://zeltser.com/protean-information-security-architecture
loading . . .
Building Deception Into Your Security Architecture
Decoys add strategic asymmetry to your security architecture, strengthening your advantage against the attacker. Plant tripwires across network, identity, data, and AI agent configs for high fidelity alerts.
https://zeltser.com/protean-information-security-architecture
about 2 months ago
1
7
4
One word changed a hospital hand-washing sign from 'protects you' to 'protects patients,' and compliance climbed. We discount our own risk but not other people's. The same holds for security messaging aimed at others, not ourselves.
https://zeltser.com/illusion-of-invulnerability
loading . . .
The Illusion of Invulnerability in Cybersecurity
Healthcare workers wash hands more often when signs emphasize protecting patients rather than themselves, because people overestimate their own invulnerability but not others'. Security messaging may be more effective when highlighting risks to customers or colleagues rather than to the individuals
https://zeltser.com/illusion-of-invulnerability
about 2 months ago
0
2
1
An attacker on a developer's machine often pivots to reconnaissance. AI agent MCP configs are plain-text files at known paths, offering an index of high-value services. A decoy entry pointing to a honeypot MCP server alerts you of an intrusion.
https://zeltser.com/decoy-mcp-server-honeypot
loading . . .
Build a Decoy MCP Server to Catch AI Agent Attackers
Your AI agent's MCP config can be a target for an attacker who reaches your machine. A decoy MCP server entry pointing at a Cloudflare Worker can reveal the attacker's presence and their intent.
https://zeltser.com/decoy-mcp-server-honeypot
about 2 months ago
0
3
0
reposted by
Lenny Zeltser
Alexander Jäger
about 2 months ago
One should print out those rules, laminate them and give it to everyone in cyber.
add a skeleton here at some point
0
2
1
When an executive rejects a security recommendation, it's worth asking what would need to change for a different answer. That question reveals constraints we didn't see and persuasion paths we didn't consider.
https://zeltser.com/rejected-security-recommendations
loading . . .
When Executives Reject Your Security Recommendations
A rejected security recommendation feels personal, but it often reflects competing demands the security team doesn't fully see. Knowing how to act on that reality helps the CISO become someone the business trusts with its priorities.
https://zeltser.com/rejected-security-recommendations
about 2 months ago
0
1
0
"Fileless malware" started as Code Red's pure in-memory worm in 2001 and has evolved to cover other forms of evasion, including living-off-the-land. I traced the journey of the term through its 25-year history.
https://zeltser.com/fileless-malware-beyond-buzzword
loading . . .
The History of Fileless Malware - Looking Beyond the Buzzword
Defenders apply "fileless malware" to nearly any evasion technique, far beyond its 2001 in-memory definition. Walk through the malware samples from Code Red to PyLoose so we can understand what this term means.
https://zeltser.com/fileless-malware-beyond-buzzword
about 2 months ago
0
2
0
Much of our security work is communicating with colleagues throughout the org. 10 habits that sharpen how the technical work gets heard.
https://zeltser.com/strong-communication-skills
loading . . .
10 Communication Tips for Security and IT Professionals
Explaining security and IT work is often harder than the work itself. Ten habits will sharpen how you explain it to specialists, executives, and everyone in between.
https://zeltser.com/strong-communication-skills
about 2 months ago
0
6
2
Four tips for a strong executive summary of your security report. They apply whether you write it from scratch or draft it with AI's help:
https://zeltser.com/executive-summary-for-security-assessment-report-tips
loading . . .
A Strong Executive Summary for Your Security Report
Decision-makers decide how to act on your findings based on what they see in the executive summary. Write it deliberately, with your readers' priorities and needs in mind.
https://zeltser.com/executive-summary-for-security-assessment-report-tips
about 2 months ago
0
1
0
Existing AI security frameworks each cover one slice of the work, like components, risks, and lifecycle. The AI Defense Matrix combines them into a single grid of AI asset classes mapped to NIST CSF functions.
https://zeltser.com/ai-defense-matrix-intro
loading . . .
Making Sense of Security for AI: The AI Defense Matrix
The AI Defense Matrix maps eight AI asset classes to NIST CSF functions, giving security leaders one grid to assign ownership, find gaps, and select controls. Sounil Yu and I co-authored it as the security-for-AI companion to his Cyber Defense Matrix.
https://zeltser.com/ai-defense-matrix-intro
2 months ago
0
2
0
A honeytoken fires when someone reaches for what they shouldn't, which makes the alerts high-signal. To get the most of them, decide on the best locations, such as decoy MCP entries, fake AWS keys, and Cloudflare Workers serving fake admin pages.
https://zeltser.com/plant-honeytokens
loading . . .
Plant Honeytokens to Detect Intrusions
Plant decoy credentials, configs, and URLs to surface an attack the rest of your stack might miss. Deployment scenarios include MCP server entries, AWS API keys, and Cloudflare Workers serving fake admin pages.
https://zeltser.com/plant-honeytokens
2 months ago
2
4
1
reposted by
Lenny Zeltser
David J. Bianco
2 months ago
If AI driven attacks become more prevalent, it'll only be a matter of time before attackers push the token burden on to their victims, using the AI that's already (probably) there. I'm calling it "living off the lAInd".* *Jokey name. Probably will happen, though.
0
1
1
A decoy in your AI agent's MCP config can be an early sign of an intrusion. Interactions with the honeypot MCP server mentioned there can be a high-confidence signal. Building this honeypot is pretty straightforward.
https://zeltser.com/decoy-mcp-server-honeypot
loading . . .
Build a Decoy MCP Server to Catch AI Agent Attackers
Your AI agent's MCP config can be a target for an attacker who reaches your machine. A decoy MCP server entry pointing at a Cloudflare Worker can reveal the attacker's presence and their intent.
https://zeltser.com/decoy-mcp-server-honeypot
2 months ago
0
3
0
Sounil Yu and I co-authored the AI Defense Matrix, the security-for-AI companion to his Cyber Defense Matrix. It maps eight AI asset classes to NIST CSF functions, so security leaders can find gaps and vendors map products.
https://zeltser.com/ai-defense-matrix-intro
loading . . .
Making Sense of Security for AI: The AI Defense Matrix
The AI Defense Matrix maps eight AI asset classes to NIST CSF functions, giving security leaders one grid to assign ownership, find gaps, and select controls. Sounil Yu and I co-authored it as the security-for-AI companion to his Cyber Defense Matrix.
https://zeltser.com/ai-defense-matrix-intro
2 months ago
0
2
0
What exactly is "malware"? Here's my definition, so we don't need to rely on "We know it when we see it."
https://zeltser.com/what-is-malware
loading . . .
What is Malware?
A program counts as malware not because of what it can do, but because of how an attacker uses it. This view aligns with NIST's longer formulation but cuts the verbiage.
https://zeltser.com/what-is-malware
2 months ago
1
3
0
Unnecessary complexity makes products hard to maintain and hard to secure. Modern apps such as Cloudflare's EmDash and Tailscale show that designing for simplicity produces stronger security as a side effect.
https://zeltser.com/modern-design-security
loading . . .
How Modern Product Design Principles Strengthen Security
Unnecessary complexity makes products hard to maintain and hard to secure. Modern apps such as Cloudflare's EmDash and Tailscale show that designing for simplicity produces stronger security as a side effect.
https://zeltser.com/modern-design-security
2 months ago
0
4
1
Honeytokens are a time-tested idea, but the interesting part is where you plant them. Consider using them as decoy MCP entries, fake AWS keys, and Cloudflare Workers serving fake admin pages to detect intrusions.
https://zeltser.com/plant-honeytokens
loading . . .
Plant Honeytokens to Detect Intrusions
Plant decoy credentials, configs, and URLs to surface an attack the rest of your stack might miss. Deployment scenarios include MCP server entries, AWS API keys, and Cloudflare Workers serving fake admin pages.
https://zeltser.com/plant-honeytokens
2 months ago
0
2
0
How do builders of security products assess strategies against vibe-coded competition? You can now use your AI agent and my MCP server, which carries Ben Vierck's seven-dimension defensibility rubric, included with his permission.
https://zeltser.com/security-product-strategy-with-ai
loading . . .
Build Better Security Product Strategies Using Your AI Tool
Modern AI tools can help evaluate a security product's strategy, but only if they have the right criteria. An MCP server with domain-specific frameworks gives your AI agent the practitioner knowledge to test strategic fit, evaluate competitors, and assess vendor viability.
https://zeltser.com/security-product-strategy-with-ai
2 months ago
1
3
0
SaaS vendors should assess whether their trust boundary includes customers' AI agents. Liability has pushed banks toward securing the customer's device four times, and the fifth wave is forming around AI agents.
https://zeltser.com/saas-ai-agent-trust-boundary
loading . . .
Trust Boundary of SaaS Will Include Customers' AI Agents
SaaS vendors should assess whether their trust boundary includes customers' AI agents. Liability has pushed banks toward securing the customer's device four times, and the fifth wave is forming around AI agents.
https://zeltser.com/saas-ai-agent-trust-boundary
2 months ago
0
1
0
Modern architectures make products easier to run, with security as a wonderful added benefit. Cloudflare's EmDash reimagines WordPress with no customer-managed server, and Tailscale connects devices with no VPN servers. Simpler designs leave less to attack.
https://zeltser.com/modern-design-security
loading . . .
How Modern Product Design Principles Strengthen Security
Unnecessary complexity makes products hard to maintain and hard to secure. Modern apps such as Cloudflare's EmDash and Tailscale show that designing for simplicity produces stronger security as a side effect.
https://zeltser.com/modern-design-security
3 months ago
0
2
1
When evaluating a security vendor's strategy, your own product roadmap, or an investment target, AI can separate marketing claims from verified capabilities. But it needs the right domain-specific criteria. Here's how:
https://zeltser.com/security-product-strategy-with-ai
loading . . .
Build Better Security Product Strategies Using Your AI Tool
Modern AI tools can help evaluate a security product's strategy, but only if they have the right criteria. An MCP server with domain-specific frameworks gives your AI agent the practitioner knowledge to test strategic fit, evaluate competitors, and assess vendor viability.
https://zeltser.com/security-product-strategy-with-ai
3 months ago
0
0
1
Generic AI does generic work. Once Claude Code knows your tools, your conventions, and your past projects, its outcomes start fitting how you actually operate. The seven-layer Personal AI Stack lays out what to add and why.
https://zeltser.com/personal-ai-stack
loading . . .
The Personal AI Stack: A Power User's Guide
An AI tool like Claude Code gives you solid general-purpose capabilities out of the box. To make it truly indispensable, add the layers that teach it who you are, how you work, and what you do.
https://zeltser.com/personal-ai-stack
3 months ago
1
2
0
AIUC-1 is a purpose-built compliance framework for AI agent risks such as prompt injection that existing certifications don't cover. Scope, auditor dynamics, and incentive alignment will shape what its certificates are worth.
https://zeltser.com/aiuc-1-cert
loading . . .
What to Make of AIUC-1, a New AI Agent Certification
New certifications start as claims and earn credibility through cycles of scrutiny. AIUC-1, a compliance framework for AI agent vendors, is at that starting point. How its structure, governance, and market acceptance hold up will decide what the certificate is worth.
https://zeltser.com/aiuc-1-cert
3 months ago
0
4
0
Out-of-the-box Claude Code is solid for general work. What makes it indispensable is the personalization, hardening, and connectors you layer on top. I mapped my setup into a seven-layer Personal AI Stack, so you can optimize yours.
loading . . .
The Personal AI Stack: A Power User's Guide
An AI tool like Claude Code gives you solid general-purpose capabilities out of the box. To make it truly indispensable, add the layers that teach it who you are, how you work, and what you do.
https://zeltser.com/personal-ai-stack
3 months ago
1
5
2
SaaS vendors that make their products usable by customers' AI agents inherit those agents' attack surface. Liability and regulation drove banks into that position four times already. The same pressure is building for agent-era vendors now.
https://zeltser.com/saas-ai-agent-trust-boundary
loading . . .
Trust Boundary of SaaS Will Include Customers' AI Agents
SaaS vendors should assess whether their trust boundary includes customers' AI agents. Liability has pushed banks toward securing the customer's device four times, and the fifth wave is forming around AI agents.
https://zeltser.com/saas-ai-agent-trust-boundary
3 months ago
1
3
0
"The current generation of frontier models behaves like a gifted PhD student with imposter syndrome: brilliant when calm, and when the room turns against them, they over-apologize, hedge everything, and abandon positions they should defend." -- Dheer Gupta
https://dheer.co/llm-anxiety/
3 months ago
0
2
0
Dan Nguyen-Huu walks through the economics of agentic procurement, a scenario where AI agents decide whether to build a capability from scratch or buy it from a vendor.
https://dannguyenhuu.substack.com/p/the-token-threshold
3 months ago
0
1
0
You can now receive my blog posts via email. Go ahead and sign up:
https://zeltser.com/newsletter
I've been writing more frequently than I have in recent years, and I'd rather share my articles directly than rely on an algorithm to decide whether to surface them.
loading . . .
Lenny Zeltser's Newsletter
Subscribe to get new posts by email. Cybersecurity, mostly.
https://zeltser.com/newsletter
3 months ago
0
3
1
Load more
feeds!
log in