In Appreciation: Dr. Eric Cole
Dr. Eric Cole's cybersecurity accomplishments are legendary, but his willingness to speak openly about burnout is something that particularly resonated with me, as it is something many of us struggle to avoid.
Dr. Eric Cole's cybersecurity accomplishments are legendary, but his willingness to speak openly about burnout is something that particularly resonated with me, as it is something many of us struggle to avoid.
AI may be making deception easier, but Dustin "Wirefall" Dykes argues that human connection -- not technology -- is the most effective defense against a future where reality itself becomes increasingly difficult to verify.
Thirty years after Sean Marley died, I realize that my focus on mental health in cybersecurity started with him. This is a belated thank you to him for helping me strive for something better. He wasn't a hacker. But he sure as hell was one of us.
A voice phishing call compromised one identity. Millions of records followed. The Charter breach is the latest evidence that the gap between identity security and SaaS governance isn't a gap enterprises can afford to keep ignoring.
Among the topics: Cognitive warfare and medical device mayhem.
Sean Satterlee’s CYBR.HAK.CON. presentation used the deadly Therac-25 radiation overdoses to expose how modern connected medical devices still repeat many of the same dangerous cybersecurity and safety failures.
Stephen Cravey’s “A Brief Introduction to Cognitive Warfare” explores how modern influence operations exploit human psychology, identity, emotion, and social dynamics much like attackers exploit vulnerabilities in technical systems.
NIST releases its first concrete OT recovery playbook and it looks nothing like an IT runbook. The document is formally aimed at manufacturing, but the problem it addresses is structural across every operational technology environment where stopping production has physical consequences.
A replica of WOPR, built for HouSecCon 2015's WarGames theme, has become a fan favorite at CYBR.SEC.Community events -- a fixture that taps into the hacker nostalgia and cautionary spirit of the 1983 film.
Built by the team behind HOU.SEC.CON. (now CYBR.SEC.CON.) and partnered with renowned penetration tester Phil Wylie, CYBR.HAK.CON. aims to reconnect cybersecurity conferences with their grassroots hacker culture through hands-on training, community collaboration, and practitioner-first experiences.
AI security scanners promise to reduce AppSec workload, but Contrast Labs' testing shows they systematically multiply it, turning a $315 API fee into an estimated $128,000 triage burden, before fixing a single vulnerability.
But first: About CYBR.SEC.Media 2.0!
An 18-year-old heap overflow in NGINX's rewrite engine is now under active exploitation. Patches exist, but attackers moved faster than most organizations can respond.
The new version of CYBR.SEC.Media puts community voices, practitioner insight, podcasts, videos, and visual storytelling front and center.
Information overload, cognitive warfare, and nonstop digital noise are turning human attention into a vulnerable attack surface.
Organizations spend real money on penetration testing and too often walk away afterwards with the same vulnerabilities they started with. The test happened. The report landed. The checkbox got checked. Nothing significant has changed.