Rob T. Lee @robtlee
Chief AI Officer, Chief of Research, @SANSInstitute | Cybersecurity Expert & Threat Hunter | Godfather of DFIR | Technical Advisor to US Govt robtlee73.substack.com Denver, CO Joined February 2008-
Tweets6K
-
Followers27K
-
Following1K
-
Likes2K
The executive order signed Tuesday asks AI developers to give the federal government up to 30 days with a frontier model before anyone else gets it. The draft floated 90. Security people wanted as much warning as they could get. The labs wanted less. At 30 days, nobody got what they asked for, which is usually how you know a compromise is real. (Both sides are now sufficiently disappointed. On schedule.) 30 days isn't a fix, though. It's a hurricane warning. You board the windows, you move the boat, and the storm still makes landfall. The buffer buys preparation, not prevention, and it only counts if you do something with it. The part nobody's arguing about: access to these capabilities is not equal, and it won't be. JPMorgan and Amazon will be fine. The order names rural hospitals, community banks, and local utilities as a concern, then leaves them a discretionary "where appropriate" while early access goes to trusted partners selected with the government. The hospital in Springfield sits at the back of that line. And closing your source code doesn't save you. Source code analysis is where Mythos is focused right now, which is why open source gets scanned first, but it does black box exploitation just as well. Nation-state teams have broken Microsoft, Apple, and Google for years without ever seeing their source. The vulnerabilities get found either way. (Adversaries don't wait for their tier assignment.) Under all of it is the oldest question in cyber defense: what is the government actually responsible for? The critical infrastructure everyone is worried about sits in private hands. The military can't defend a bank's network. The FBI takes the report after the breach. CISA runs real threat intelligence and coordination, but it doesn't have the authority to operate inside a private company and defend it. When Volt Typhoon and Salt Typhoon hit American infrastructure, they hit private companies, because that's where the front line is. (I came up through the military side. That gap still bothers me.) The order doesn't solve any of this. It documents the threat and starts the argument, and the risk now is that people read "signed" as "handled." The work is what the community builds during the buffer, which is why @gadievron, @rmogull, and I, with @cloudsa, @SANSInstitute, and [un]prompted, are running closed-door CISO sessions in DC (luma.com/jzr25473), New York (luma.com/kn2djk5v), and San Francisco. The people in the fight, writing the playbook before the vendors write it for us. If you're a senior security leader, you should apply to attend. Read the Mythos-ready security program paper: labs.cloudsecurityalliance.org/mythos-ciso CISOs: do you actually know where your organization sits in that access structure? If not, that's worth finding out this week.
@HALNine9sRel1k @anton_chuvakin This is awesome!!
Anthropic and roughly 50 partners used Claude Mythos Preview to find more than 10,000 high or critical severity vulnerabilities in the first month of Project Glasswing. Most partners found hundreds of high or critical issues in their own code. (One month. Let that sit for a second.) Of those 10,000-plus, 97 have been patched upstream as of May 22. That number is not a measure of how hard anyone tried. It is a measure of where the work now jams. The Glasswing update says it plainly: software security used to be limited by how fast you could find vulnerabilities, and now it is limited by how fast you can verify, disclose, and patch them. High and critical bugs are taking about two weeks each to patch. Several maintainers have already asked Anthropic to slow its disclosure rate, because they cannot keep up. Discovery is no longer the bottleneck. The humans in the pipeline are. The patch playbook itself, coordinated disclosure on a 90-day clock, monthly patch cycles, the quarterly review, was built for a world where finding a flaw was slow. That world is gone. The playbook is not strained. It is finished, and most of us have not said that out loud yet. (I would love to be wrong on this. Correct me, and tell me what planet still runs on a 90-day clock.) Rebuilding it is not a tooling purchase. It is a skills problem, and a specific one. Working at this volume means triaging AI-generated findings ten deep, judging which severity ratings hold up, and deciding what gets fixed in what order when the queue is a thousand items long. That is human judgment under machine-scale load, and almost nobody has trained for it, because the tools that create the problem are months old. You cannot hire your way out of this, because the talent pool does not exist yet. All of us are figuring it out at the same time. So the people who can help you most are already on your team. They are the ones who know your business, who have worked real incidents, who understand what a finding actually means in your environment. What they are missing is reps on AI tools under realistic pressure. The @SANSInstitute Find Evil! hackathon is one place to get those reps fast. Practitioners build autonomous incident response agents, run them against real case data, and watch where the AI is sharp and where it falls apart. That last part is the point. The skill that transfers is not the agent, it is the calibrated judgment of when to trust the machine and when to override it, and that is exactly the muscle the patch pipeline now needs. Find Evil! runs through June 15, with $22,000 in prizes, at findevil.devpost.com. If you manage defenders, here is the Monday version. Pick two people who know your environment cold. Give them protected time this month to put AI tools against your own findings backlog and report back on where the tools broke. That is the rewrite starting, in miniature, on your team. The Glasswing numbers should change what you do this week, not how well you sleep.
It’s 1 pm ET / 10 am PT, Fri. 22 May 2026, and there's no LIVE show. Replay #CXOTalk ep. 910 w guests: @RobTLee, #CAIO, @SANSInstitute + Co-host David Bray, PhD., @StimsonCenter talking about the #AI attack lifecycle in an age of intelligent threats. cxotalk.com/episode/the-ai… #DFIR #AIsecurity #CSO #CSIO #CIO
Builders and skeptics wanted to judge the FIND EVIL! Hackathon. DFIR, Al, cybersecurity, and open-source reviewers who can separate useful autonomous response tools from polished demos. Favor - this has a goal of a far-reaching community impact - could you please SHARE this in your personal feeds? Apply here: findjudges-9kvkxt6m.manus.space Takes two minutes. More than 3,500 entrants. Building autonomous Al agents on the SANS SIFT Workstation (200+ incident response tools on a single platform, 18 years of community development, 60K+ annual downloads). If you have expertise in these areas, I want to hear from you: Digital Forensics & Incident Response (DFIR) Al/ML engineering Agentic frameworks (Claude Code, LangGraph, AutoGen, CrewAl) Cybersecurity (offensive/defensive) Open-source development This is not a hackathon where you vote for your favorite demo. Judges review runnable open-source submissions, check required materials, and score evidence-backed autonomous incident response work. Winning entries released back to the community. Submissions close June 15. Judging runs June 19 through July 3. Decide who earned the $22,000 in prizes.
One in ten of you reading this have kids whose data is in the dump supposedly burned when Instructure paid the ShinyHunters ransom to avoid the liability of millions of minors' data hitting the field. 275 million records across 8,800 institutions in 50 countries, from kindergarten to Ivy League. Hard to trust that the data is destroyed when the hackers broke in a second time to post a ransom note across every school's Canvas login during the negotiation. First time that families saw a ransomware threat. I have twin teenagers. This just got personal. Criminals known for sophisticated social engineering are now capable of stitching the most credible spear-phishing ever assembled (student names and emails, schools and teachers, real message threads) onto WormGPT-class phishing at 93% success and SIM farms running thousands of numbers. You don't need to be a nation-state to run a convincing impersonation of a teacher, or to create illicit content and threaten to post to their social media accounts. You need a target list and a couple of hours. (And if it doesn't keep you up at night yet, ShinyHunters was responsible for the ADT breach and the AT&T breach, among many more in recent years.) What I would do now: 1. Freeze each kid's credit at all three bureaus. Block the long-tail identity attack that hits when the kid turns 18 and first applies for credit. Few parents have done this for their kids. 2. Set up a new email account for your kid's social media. Don't use that email address anywhere else. 3. Move 2FA off SMS and onto an authenticator app. If they didn't get contact numbers in this breach, ShinyHunters already had phone numbers from the AT&T breach. A SIM swap takes one social-engineered call. Google Authenticator and other apps are tied to the device, not the number. 4. Pick a family safe word. Make it weird, memorable, specific. Drill them often. Voice and video can be faked now, cheaply and fast. The word can't be faked unless the attacker is also at our dinner table. We told them AI was cheating at school. They are about to learn what it means to have AI used against them. We owe them a different conversation now.
The @Google Threat Intelligence Group report released today (11 May) identified a cyber crime group with a zero-day almost certainly built with AI: a 2FA bypass in a popular open-source admin tool. (I am not sure whether to be relieved GTIG caught this one or worried about the ones they did not.) The flaw was not memory corruption or input sanitization. It was a hardcoded trust assumption the developer left in the logic, the kind of dormant semantic gap fuzzers and static analyzers are not built to catch. We train people to recognize known patterns: known malware, known signatures, known bad behavior. You cannot pattern-match a logic gap that did not exist as a pattern until an AI reasoned its way to it. Defending against this requires humans who can run the same reasoning the attacker's AI did, which means operators who actually understand AI tools, know how to point them at the right data, interpret the output, and action on it. The @SANSInstitute 2026 Workforce Research Report @jameslyne and I presented at RSAC in March tells us whether those operators exist. 60% of organizations now say their bigger problem is skills, not headcount. That skills-versus-bodies differential was 4 points in 2025. It is 20 points now. 27% report breaches they trace directly to skills gaps. (Workforce report, case studies: sans.org/mlp/2026-evolv…) The bad news: This is not a "buy more AI" problem. It is a "we do not have the people to operate the AI we already have" problem. Two Fortune 500 companies can buy the same defensive AI tool. One team finds the threat in 10,000 tokens. The other burns 10 million and finds nothing. So defenders end up new to the tools, pointing AI at the wrong data with the wrong prompts, losing the cost war on top of the time war. The BAD bad news: There is no "AI security workforce" to hire from. It is a job category we are still inventing. The tool is not the bottleneck. The operator is. Without trained people, the budget burns and the threat still gets through. Train the team you have.
“We have startups today that are 4 people large that are reaching $10 million valuation,” says @robtlee, Chief AI Officer and Chief of Research at the @SANSInstitute, in a recent fireside chat with XBOW CEO @oegerikus. “If you’re able to do business that way, why can’t you similarly create an attack team?” Watch more of their conversation: bit.ly/422eZPo
Nearly 3,000 people are spending two months teaching AI agents to FIND EVIL in real DFIR data. Now we need judges willing to tell them how they actually did. Apply at sansurl.com/find-evil-judge Both kinds welcome: the true believers who think AI-augmented incident response is going to rewrite how we do DFIR, and the skeptics who have been waiting two years for someone to show them something that doesn't hallucinate its way to a conclusion. (Either way, you're going to see things in these submissions you didn't expect. I'll leave it at that.) The judging rubric was built for serious evaluation. Six equally weighted criteria: 1. Autonomous execution quality 2. IR accuracy 3. Analysis depth 4. Constraint implementation 5. Audit trail quality 6. Usability Every finding has to trace back to a specific tool execution. Hallucinations caught and flagged count. Confident-sounding wrong answers do not get partial credit. (This is not a hackathon where you vote for your favorite demo. Real forensic data. Real agent execution logs. Real consequences for the community toolset that winning code goes back into.) Submissions close June 15. Judging runs June 19 through July 3. $22,000 in prizes. Come see what the community built. Apply at sansurl.com/find-evil-judge Judges will have their pictures on the findevil website. We are looking for judges with real DFIR and AI experience. Skeptics. Proponents. Everyone. (Front-row seat to watch autonomous AI agents work through real incident response cases. Whether that excites you or makes you deeply curious about where it breaks, you belong in this room.)
Data poisoning = someone did it to you. Data pollution = you did it to yourself. You can't poison what isn't clean to begin with. Is a fired employee still listed as active, informing an automated decision? Conflating poisoning and pollution is how orgs end up building defenses against adversaries when their actual threat is their own data mess. The approval process and AI-assisted cleanup aren't governance theater. They're how we get to a state where poisoning is even a relevant threat model. We have to earn the right to worry about poisoning by solving hygiene first. This is important enough to need a leader. Security has the most to lose if it doesn't get one. We aren't going to do this cleanup manually. (We weren't going to do it before AI either, which is why we're all here.) I've released a LinkedIn Learning course talking about a model for how business units can work with security to get AI tool approvals for the cleanup in front of you. Parts 1-4 are live now: (free, ungated) gettoolapproved.ai Thanks to Cynthia Brumfield @CSOonline for including my and @chrishvm's POV. Important topic (and killer title): Poisoned truth: The quiet security threat inside enterprise AI: csoonline.com/article/416617… @SANSInstitute
“I spend all day, every day, looking at folks who misuse our models and our products. I want to walk through all of you what I've been seeing on the ground and how this has changed in the past year.” - Jacob Klein, @AnthropicAI's head of threat intel at the @SANSInstitute AI Summit. And then came the heartburn line: “Almost everything I’m walking through can be used by a defender as well.” He’s right. Defenders can point AI at endpoints at scale, code at scale, vulnerabilities, and SOC signals. Every serious defender already knows the list. The hard part is the operating reality: usable data, investigations that don’t depend on manual glue work, remediation that moves fast enough, and AI you can actually trust. What makes this a tougher sell is the reliability of the tools in our hands right now and our own skill gaps. And consider: we still get to watch some of this play out in the open. That window closes as attackers move to their own private tooling and infrastructure. The only way we get ready is by starting now: working on our own skill gaps, building muscle with the tools we have, stress-testing them in real environments, forcing the workflow changes that make AI for defense operational. Work on this directly with us: Find Evil! is live. Protocol SIFT is what happens when you wire an AI agent into a forensic workstation full of trusted tools and tell it to behave. It's an early capability with real outputs, failure mode. Join our community effort to make it something defenders can deploy. 42 days to enter. An incredible 2,500+ builders and teams are in as of today. $22K in cash prizes. Sponsored by SANS Institute. findevil.devpost.com (You'll have to hear Jacob's full talk and the fireside chat with Bruce Schneier and Anne Neuberger: Are tech companies the new SOC? Check it out on the SANS Institute YouTube page.) Curious what you think. (And if you've entered in the hackathon?) #AIsecurity #cybersecurity #vulnops
@robtlee @anton_chuvakin @OpenAI @AnthropicAI At Aisle, we were able to find the same things cheaper and we documented it. aisle.com/blog/system-ov…
So excited to announce: Find Evil!, the first autonomous AI hackathon for incident response is live. More than 1,400 solo builders and teams registered as of this morning. IR professionals, AI engineers, developers, students. Most of what's on our feeds and agendas is how two frontier AI labs told the world that their own models are dangerous enough to need emergency defensive programs, and basically to go figure it out. Let's do something about it. Grab your team and sign up. Especially grab peers who keep saying "Why are you so obsessed with Claude Code?" (You cannot convince people with a deck. They have to put their hands on the tools and watch an AI agent reason through 200+ forensic tools in real time.) The hackathon is a two-month competition ($22K in prizes) to take Protocol SIFT, the proof-of-concept connecting AI agents to the SIFT Workstation’s 200+ open source forensic tools through MCP and to make it production-ready. You don't need to be an incident response expert. The SIFT Workstation handles the domain tooling. You need curiosity and building skills. Details and registration: findevil.devpost.com Sponsored by @SANSInstitute
What is the frontline of cybersecurity today? @robtlee, Chief AI Officer and Chief of Research at the @SANSInstitute, shares his thoughts in a fireside chat with XBOW CEO @oegerikus below. Watch more of their conversation. bit.ly/422eZPo
So @OpenAI basically took its latest model (not even a Frontier one) and re-released it after effectively removing guardrails. They are likely trying to enhance researchers' ability to find code vulnerabilities. But neither OpenAI nor @AnthropicAI is telling the cybersecurity community how to even accomplish this. We have heard from multiple folks with Mythos that they don't even know what specifically they're supposed to do with it. Point it at applications and say "find vulnerabilities" or what? It's not like it comes with a how-to manual or a man page. This is nothing more than one vendor trying to one-up another. We need to start benchmarking how one AI model is able to find code vulnerabilities over another and how quickly they are doing it. There are real risks at stake here. Is the solution to this problem that people should do code analysis and vulnerability discovery through models without additional security? For the majority of defenders out there that do not have the offensive training for fuzzing or vulnerability discovery, what are they supposed to do in the meantime? How are they going to validate the individuals (and people at enterprises) asking for access? While we can applaud that all these models are released to defenders first, the real issue is: is everyone fully aware of what to do with them once they get their hands on them?
We’re expanding Trusted Access for Cyber with additional tiers for authenticated cybersecurity defenders. Customers in the highest tiers can request access to GPT-5.4-Cyber, a version of GPT-5.4 fine-tuned for cybersecurity use cases, enabling more advanced defensive workflows.
AI is discovering vulnerabilities faster than defenders can patch them. This isn't a future risk — it's today's reality. Our new Mythos CISO briefing, "The AI Vulnerability Storm," gives security leaders a concrete playbook to respond. Authored by @gadievron, @rmogull, and @robtlee.
Florian Roth ⚡️ @cyb3rops
220K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Jake Williams @MalwareJake
149K Followers 2K Following Breaker of software | VP R&D @hunterstrategy | CTI/DFIR | @ians_security faculty | Bookings: jake at malwarejake dot com | GSE #150 | He/him
Dave Kennedy @HackingDave
231K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
SANS DFIR @sansforensics
111K Followers 104 Following The world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
Chris Sanders 🔎 �... @chrissanders88
35K Followers 487 Following Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM
Mick Douglas 🇺🇦... @bettersafetynet
32K Followers 575 Following Consultant for InfoSec Innovations | @SANSInstitute Principal Instructor | @IANS_Security Faculty | I like information security. How about you?
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
strandjs - strandjs@b... @strandjs
46K Followers 2K Following I will light the way by the bridges I burn. Retired Senior SANS Instructor IANS Faculty Black Hills Information Security Active Countermeasures
edskoudis @edskoudis
62K Followers 322 Following President SANS Technology Institute College. SANS Fellow. CEO @CounterHackSec. @RSAConference Keynoter. IANS Faculty. BoD @manasquanbank & https://t.co/WD7vkoH5lH.
Chad Tilbury @chadtilbury
22K Followers 599 Following Digital forensics and incident response. Ex-AFOSI, Mandiant, and CrowdStrike. SANS Institute Fellow and co-author of #FOR500 and #FOR508 courses.
Justin Elze @HackingLZ
70K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Heather Mahalik Barnh... @HeatherMahalik
23K Followers 1K Following DFIR, Faculty Fellow & author, #FOR585 #FOR500, wife, mama, researcher, USAF. Trust but validate. Thoughts are mine.
Lina @d0rkph0enix
39K Followers 10K Following Infosec dork, boxer, poker player, dog owner/operator, spiller of things. Cars, vidya games, and cooking are my jam. #ChiefsKingdom and Royals fanatic. #SecKC
Thomas Roccia 🤘 @fr0gger_
35K Followers 2K Following AI Security x Threat Intel · Threat Researcher · Creator of #Unprotect & #NOVA · Malware Warlock · Python 🧡 · Prev @Microsoft @McAfee_Labs
Nicole Beckwith @NicoleBeckwith
42K Followers 7K Following Sr. Director, Security Engineering and Operations @cribl_io
SANS Institute @SANSInstitute
193K Followers 413 Following SANS is the most trusted and by far the largest source for information & cyber security training, certification and research in the world.
Eric Capuano - Bsky: ... @eric_capuano
11K Followers 3K Following Co-Founder @recon_infosec | SANS DFIR Instructor | IANS Faculty | https://t.co/yUXCSu2Yso | ⬡ ❤ @shortxstack
Ryan "Chaps" Chapman @rj_chap
8K Followers 3K Following Threat Hunter. DFIR & Malware Analyst. @sansforensics Author (FOR528) & Instructor (FOR610). Husband & father. Retro gamer too! Comments = own.
Frank McGovern - INAC... @FrankMcG
15K Followers 216 Following No longer active. Find me on LinkedIn and https://t.co/sNKTRQOIWi. Follow @BlueTeamCon. See pinned post. See you around. Touch grass. Be empathetic.
InfoSecSherpa 🏔️ @InfoSecSherpa
51K Followers 4K Following Your Guide Up a Mountain of Information! #Librarian 📚 ➡️ #InfoSec 🤖 #Philly 💚🏡 Nil satis nisi optimum ⚽ #Toffees
Dr. Josh C. Simmons @drjoshcsimmons
1K Followers 389 Following FOLLOW ME TO BE ON THE GOVERNMENT WATCHLIST. yes, im that one (just joined x)
Founder Engineer @founderengineer
108 Followers 562 Following Seek first His Kingdom and His righteousness and all of these things will be added to you. Working on the LLM for high-risk industries: @abliteration_ai
X @X6z4d
1 Followers 86 Following
Garin Pace @Garin_Pace
360 Followers 850 Following I like figuring out how things work. I work in the infosec & privacy (cyber) insurance space as an underwriter. Views are my own and not my employer’s.
goutham0164 @goutham0164
2 Followers 408 Following
Ziggy Ziggurat @ZigguratZi
10 Followers 379 Following
Max @Max33307
0 Followers 28 Following
CyberX @CyberXlx9q
52 Followers 671 Following 𝗖𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗡𝗲𝘄𝘀 | 𝗗𝗮𝘁𝗮 𝗟𝗲𝗮𝗸𝘀 | 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 | 𝗗𝗮𝗿𝗸 𝗪𝗲𝗯 Tracking breaches, threats & underground intel
marco @marco97392446
0 Followers 264 Following
Lurkt 🇺🇸 @Lurkt
3K Followers 5K Following wife, mama, mimi | Retired AI innovator | MS NatSec CI | opinionated but open-minded | anti-communist | my reposts mean sh!t | what sarcasm? | poet philosopher
smthor @smthor1
0 Followers 123 Following
Bill O'Hanlon @BillOHanlo56591
1 Followers 84 Following
Armando Vaca @Armando57154121
1 Followers 26 Following
Wilson Cruz @wilsoncruz
203 Followers 2K Following I´m Wilson Cruz from Sao Paulo, BR - Web Security, Scalability and Performance Addicted ** I´m #NOT the Wilson Cruz Actor!
everestk @everestkasa
136 Followers 5K Following
yue bei @lazhangao
8 Followers 525 Following
Rahul Banerji @rahulbanerji
349 Followers 2K Following Financial Services, Fintech Professional with varied interests including Guitar, Music and Squash
craiglawson @craiglawson
2K Followers 4K Following Cyber security guy, chugging along one tweet at a time. Buy local, use cash, make 1984 fiction again. #NoBackDoors
hls4 @hlsbaker4
0 Followers 30 Following
perseus @pers3_u5
1 Followers 50 Following
Ramesh @Ramesh278220
0 Followers 188 Following
Remi Afon @RemiAfon
2K Followers 707 Following AI/ML Security, MLSecOps. DevSecAI. Founder @lynsecofficial https://t.co/y2THmEgMYX @penayde https://t.co/XmC1mysTba @golegitofficial https://t.co/pIIwReNfEn
Ziyad Mehdawi @ziyad_mehdawii
181 Followers 327 Following {قَالَ كَلَّا ۖ إِنَّ مَعِيَ رَبِّي سَيَهْدِينِ} DFIR.
Omar Zaman @OZBeta
1 Followers 46 Following
KΞllhus @zer0proof
521 Followers 4K Following
Jerry Saperstein @JerrySaperstein
24 Followers 247 Following
Sattyam Jain @Sattyamjjain
69 Followers 316 Following GenAI Tech Lead @ https://t.co/59kZRyggQn | pyAGI (acquired) | 15+ production AI agents | Security, memory, governance Book a call: https://t.co/ZxkNhS7Oub
لمسات للتصم... @RoseReynolds16
49 Followers 158 Following عضو في فريق #لمسات_لتصميم سيره ذاتيه طريقك الى التميز يبدأ بشغفنا 🌟 #لوقو #شعار #هوية_تجارية * * * * https://t.co/C1d38MW5AT
Quantum2xLtd @Quantum2xLtd
3 Followers 75 Following Quantum 2x | AI Security Architecture • Zero-trust AI agents & workflows • Launching Model Package Protocol (MPP) — secure, signed, sandboxed AI tools
Abhi @ImAbhiImAbhi
88 Followers 941 Following My interests include music, science, justice, animals, shapes, feelings (as well as cycling, software, and Wisconsin sports). Vegan 🌱
Ig(#) @Ig23_L_A
0 Followers 38 Following
Jonathan Heese @HeeseJonathan
28 Followers 261 Following
Constantine @Al_Bufli
0 Followers 222 Following
@TheOctoSwat #NAFO #m... @TheOctoSwat
5K Followers 7K Following #Fella 🇺🇦 #NAFO Joyful Bastard/ Raconteur/Good Time Haver/Eclectic AF/Live Fire Cook 🔥/ very unlikely to DM / Fellowship of Coffee Sippers #smokefleet
Yehia Serrieh @JustYehia
244 Followers 132 Following
Caitlin Condon @catc0n
4K Followers 3K Following Adventurer. Takes a lot of photos, calls many places home. Research VP @VulnCheckAI. Previous research director @Rapid7 / @metasploit. Opinions mine. She/her.
Nunzio Capon @NunzioCapon1
3 Followers 197 Following
Christopher Linden @lcl_beignet
110 Followers 1K Following Infosec, network architecture, sports, and politics, and not nearly in that order. PGP fingerprint: https://t.co/H73MJM6A9t
b0bbyt @b0bbyt
19 Followers 380 Following
Florian Roth ⚡️ @cyb3rops
220K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Jake Williams @MalwareJake
149K Followers 2K Following Breaker of software | VP R&D @hunterstrategy | CTI/DFIR | @ians_security faculty | Bookings: jake at malwarejake dot com | GSE #150 | He/him
Dave Kennedy @HackingDave
231K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
SANS DFIR @sansforensics
111K Followers 104 Following The world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
Chris Sanders 🔎 �... @chrissanders88
35K Followers 487 Following Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM
Mick Douglas 🇺🇦... @bettersafetynet
32K Followers 575 Following Consultant for InfoSec Innovations | @SANSInstitute Principal Instructor | @IANS_Security Faculty | I like information security. How about you?
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
strandjs - strandjs@b... @strandjs
46K Followers 2K Following I will light the way by the bridges I burn. Retired Senior SANS Instructor IANS Faculty Black Hills Information Security Active Countermeasures
edskoudis @edskoudis
62K Followers 322 Following President SANS Technology Institute College. SANS Fellow. CEO @CounterHackSec. @RSAConference Keynoter. IANS Faculty. BoD @manasquanbank & https://t.co/WD7vkoH5lH.
Chad Tilbury @chadtilbury
22K Followers 599 Following Digital forensics and incident response. Ex-AFOSI, Mandiant, and CrowdStrike. SANS Institute Fellow and co-author of #FOR500 and #FOR508 courses.
Heather Mahalik Barnh... @HeatherMahalik
23K Followers 1K Following DFIR, Faculty Fellow & author, #FOR585 #FOR500, wife, mama, researcher, USAF. Trust but validate. Thoughts are mine.
SANS Institute @SANSInstitute
193K Followers 413 Following SANS is the most trusted and by far the largest source for information & cyber security training, certification and research in the world.
Tim Medin @TimMedin
18K Followers 594 Following Kerberoast Guy • @RedSiege CEO • IANS Faculty • Former SANS SEC560 Author, Senior Instructor • Packers Owner #GoPackGo • Work Req: https://t.co/ALJldLMDfZ
Eric Capuano - Bsky: ... @eric_capuano
11K Followers 3K Following Co-Founder @recon_infosec | SANS DFIR Instructor | IANS Faculty | https://t.co/yUXCSu2Yso | ⬡ ❤ @shortxstack
ARCHIVED: Jen Easterl... @CISAJen
61K Followers 48 Following Archived: Director, CISA—America’s Cyber Defense Agency. Combat Veteran. Proud Mom. Rubik’s Cuber. Aspiring Electric 🎸. ❤️/RT ≠ endorsement
Ryan "Chaps" Chapman @rj_chap
8K Followers 3K Following Threat Hunter. DFIR & Malware Analyst. @sansforensics Author (FOR528) & Instructor (FOR610). Husband & father. Retro gamer too! Comments = own.
Bryson 🦄 @brysonbort
20K Followers 499 Following 🦄 @scythe_io @grimmcyber, Sr Advisor @IST_Org & NatSec Sr Fellow, Co-Fdr @ICS_Village, @c2_matrix co-creator, USMA Science Board, Angel Investor, US Army Offcr
Kevin 🤖🕵️🍺 @KevinPagano3
4K Followers 583 Following 🕵🏼♂️ @stark4n6 🎴 Shiny cardboard collector 🍺 Resident beer drinker
Lesley Carhart @hacks4pancakes
155K Followers 7K Following ICS DFIR @dragosinc, martial artist, marksman, humanist, Lvl14 Neutral Good rogue, USAF Ret. Tweet *very serious* things about infosec. Thoughts mine. They/them
Joshua Wright @joswr1ght
27K Followers 563 Following Hacker for @counterhacksec and SANS Faculty Fellow. Pirata informático. Photography at https://t.co/Qbh3jsSKAJ. He/him.
Sean Lyngaas @snlyngaas
14K Followers 5K Following @CNN cybersecurity reporter | Tips: Signal 202-355-8471 or SNLyng.11 | [email protected] | [email protected]| @DukeU/@FletcherSchool alum | Proud Dad | @LFC
jon greig @jgreigj
3K Followers 5K Following @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
Martin Matishak @martinmatishak
8K Followers 967 Following Senior Cybersecurity Reporter for @TheRecord_Media. Send tips to [email protected]. Signal: mmatishak.80
Dustin Volz @dnvolz
35K Followers 2K Following @nytimes Washington correspondent reporting on hackers and spies. Priors w/ @WSJ, @Reuters and @nationaljournal.
Tim Keary @tim_keary
1K Followers 72 Following Freelance technology reporter. Covering AI and cybersecurity. Feel free to send news tips to [email protected]
XBOW @Xbow
12K Followers 13 Following Bringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. https://t.co/D5Mco1tAKe
Sandra Joyce @JumpforJoyce
2K Followers 196 Following VP, Google Threat Intelligence @ Google. Board Member. Mom/Wife. Veteran. PhD Student
Claude @claudeai
1.4M Followers 2 Following Claude is an AI assistant built by @anthropicai to be safe, accurate, and secure. Talk to Claude on https://t.co/ZhTwG8d1e5 or download the app.
AI Security Institute @AISecurityInst
16K Followers 30 Following We conduct scientific research to understand AI’s most serious risks and develop and test mitigations.
CloudSecurityAlliance @cloudsa
19K Followers 268 Following We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.
Phil Venables @philvenables
14K Followers 590 Following All about cyber, resilience, risk, AI - at scale. Partner - Ballistic Ventures / 4 x CISO / Board Director / Chief Risk Officer
Jacob Klein @JacobKleinx
560 Followers 92 Following Trust & Safety @AnthropicAI | Currently building @NANEXLABS | Former @coinbase @Google | Views are my own
White House Office of... @ONCD
28K Followers 65 Following ONCD’s mission is to advance national security, economic prosperity, and technological innovation through cybersecurity policy leadership.
Maggie Miller @magmill95
6K Followers 1K Following Cybersecurity reporter for @politico, Austin, TX native, history nerd, TexMex snob. Follow Instagram @maggiemiller_reports. Tips? Send to [email protected]
John Sakellariadis @johnnysaks130
3K Followers 3K Following Cybersecurity and Intelligence Reporter at @politico. Reach me at [email protected] or johnnysak.21 on Signal.
Sam Sabin @samsabin923
5K Followers 2K Following @axios cybersecurity reporter, taking it day by day ✨ | 📩: sam.sabin@axios dot com, signal: SamSabin.01 (no pitches!)
Yotam Perkal @pyotam2
603 Followers 915 Following Security research lead @pluto_security | @pyconil Organization Committee | Sharing Cyber Security, ML & Startup Culture Insights | Always Learning!
Daniel Bardenstein @bardenstein
421 Followers 358 Following CTO, co-founder @ManifestCyber. Former @CISAGov, @DefenseDigital. Fellow @AspenPolicyHub. Leading @0x4Sight. Hack the Planet. Views are my own.
Anne Neuberger @AnneNeuberger
467 Followers 247 Following National Security & Technology Leader | Strategic Advisor @a16z | Lecturer @Stanford | Board Member @CNASdc | Fellow @RUSI_org
Pliny the Liberator �... @elder_plinius
177K Followers 1K Following ⊰•-•⦑ latent space steward ❦ prompt incanter 𓃹 hacker of matrices ⊞ breaker of markov chains ☣︎ ai danger researcher ⚔︎ bt6 ⚕︎ architect-healer ⦒•-•⊱
Palmer Luckey @PalmerLuckey
817K Followers 2K Following I am a technology enthusiast, writer, and modder. Founder of @ModRetro, @Oculus VR, and @Anduriltech. Keeping American superheroes safe with autonomous systems.
dragosr @dragosr
23K Followers 9K Following Stop, Think, Pwn! (see also @[email protected], https://t.co/BjclXYWQ9R for alternate)
Julie Michelle Morris @juliemichellemo
696 Followers 2K Following Thought leadership trainer. Cyber curious.
Gadi Evron @gadievron
7K Followers 2K Following CEO & Founder, Knostic. CISO-in-Residence for AI, Cloud Security Alliance. Founder @Cymmetria (acquired). Scifi geek, dance teacher. Opinions my own.
Peter Girnus 🦅 @gothburz
191K Followers 588 Following The Cyber Populist | Hacker. Writer. Heretic. | Reverse engineering narratives, systems, and power. Holding the pen.
CXOTALK @cxotalk
5K Followers 250 Following Live conversations on innovation and disruption. Hosted by @mkrigsman. Complete schedule: https://t.co/GduG6dq1fo #cxotalk
Helen Oakley @e2hln
2K Followers 1K Following Shaping the Future of Cyber & AI🚀 Core team https://t.co/iPZLPwWMmA🛡️ Creator of https://t.co/LZkfuHfVeU & https://t.co/aSFGy6tNbw🤖 CoFounder of @LadiesCyber 👩🎤
Mayank Vora @aiwithmayank
10K Followers 192 Following AI doesn’t have to be complicated - I’m here to show you how to actually use it and break down the latest trends in AI and Tech.
Joseph Cox @josephfcox
91K Followers 3K Following Hacking/crime/privacy journalist. Author of DARK WIRE. Co-founder of @404mediaco. Signal: joseph.404 Email: [email protected]
WSJ Pro Cybersecurity @WSJCyber
5K Followers 88 Following The official Twitter account for WSJ Pro's team of editors and reporters covering all things cybersecurity.
TeamYouTube @TeamYouTube
2.1M Followers 2K Following updates & answers from the team that brings you YouTube, helping in: english, español, português, français, 日本語, 한국어
CyberScoop - @cybersc... @CyberScoopNews
23K Followers 1K Following CyberScoop, a @ScoopNewsGroup property, reports on news and events impacting technology and security.
Aatish Nayak @nayakkayak
3K Followers 856 Following luck is predictable -- partner @kleinerperkins, prev vp product @harvey @scale_ai @shieldaitech @CarnegieMellon
Michael J.J. Tiffany @kubla
3K Followers 3K Following priv/acc Hacker: @ninjanetworks Cofounder: @SecureWithHUMAN (infosec unicorn) Cofounder: @FulcraDynamics (personal data sovereignty) I have magnificent friends
Rob Pegoraro @robpegoraro
17K Followers 1K Following Journalist covering/vexed by computers, gadgets, other things that beep. He/him. Read: @pcmag, @fastcompany, etc. Write: [email protected].
derekbjohnson.bsky.so... @DerekDoesTech
2K Followers 2K Following Reporter and knowledge broker @CyberScoopNews, covering elections, privacy and more. Priors @fcwnow and @scmagazine. Catch me at [email protected].
Aspen Digital @AspenDigital
6K Followers 2K Following We connect and spark policy action among those crucial to making our interconnected world accessible, safe, and inclusive — both online and off. @AspenInstitute
Paul Mauro @PaulDMauro
93K Followers 1K Following Fox News Contributor focusing on law enforcement, legal, and intel issues. Attorney. Ex-NYPD. Founder of https://t.co/ceMziOLzac. My latest podcasts and articles there.
Hailey | Sassenach Hi... @hailey_beaupre
6K Followers 621 Following Sassenach Historian Tours | Where Scottish dreams become reality✨🏴 | Reach out to book a tour! 🏰🏔️
Anime NYC @animenyc
66K Followers 2K Following August 20-23 2026. New York City’s anime convention 🍎🗽A showcase of the best of Japanese pop culture in the biggest city in America! 🇺🇸🇯🇵 #AnimeNYC
stewart @stewart9395
14K Followers 4K Following i never thought a tv program would bring so many wonderful people into my life. that program is outlander. A program my cath and i watch together. scottish 100%
Laura Rispoli 🎨 @LauraRispoliArt
8K Followers 6K Following Illustrator that does original handmade paintings and custom artwork. Please see my links! https://t.co/m4i0MaA2z7 💚Outlander & MPC⛰🌲
















