Security Engineer
422 subscribers
88 photos
1 video
45 links
A diary of Security Engineerโ€˜s life. The good, the bad, the secure ๐Ÿ˜ฌ

Ping for cooperation @stansecure

My LinkedIn linkedin.com/in/stansecure/
Download Telegram
The biggest telecom hack in history didnโ€™t start with malware.

It started with a person.
A compromised employee account.

On December 12, 2023, Kyivstar, Ukraineโ€™s largest telecom, was taken down
24 million people lost mobile service.
No phone. No internet. No air raid alerts.
The attackers didnโ€™t break in, they were already inside.

This wasnโ€™t just a breach. It was cyberwar, and a blueprint for whatโ€™s coming.

Here are 3 lessons I believe every security leader must act on now:

1๏ธโƒฃ The Myth of the Impenetrable Fortress is Dead
Attackers got in by targeting people, not tech.
They were inside for weeks before striking.

โœ”๏ธ Your biggest risk is not your firewall - itโ€™s your people.
โœ”๏ธ Assume breach. Build from the inside out.
โœ”๏ธ Security culture matters more than the latest tool.


2๏ธโƒฃ Resilience > Prevention

When the core was destroyed, prevention didnโ€™t matter.
Recovery did.

โœ”๏ธ Do your backups survive when the backups are targeted?
โœ”๏ธ Has your incident response actually been tested under fire?
โœ”๏ธ Can your business keep running under attack?

3๏ธโƒฃ Attacks Hit People, Not Just Servers

โ†’ ATMs down.
โ†’ Air Raid Alerts silenced.
โ†’ Lives disrupted.

This wasnโ€™t an IT problem.
It was a humanitarian one.

We defend networks, but what weโ€™re really protecting are communities, economies, and national resilience.

The Kyivstar attack wasnโ€™t just about code.
It was about culture, readiness, and people under pressure.

The real heroes? The engineers working through the night.
Their story matters just as much as the breach.

Stay secure. ๐Ÿ˜‘

__

Enjoying this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Resilience #Kyivstar
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘17๐Ÿคฏ2
#CyberMonday EchoLeak: Zero-click AI attacks now steal Microsoft 365 data with no user action needed.

A new threat called EchoLeak has appeared recently. Attackers can now pull sensitive data right out of Microsoft 365 Copilot - no clicks, no alerts, no warning. Zero-click means users do nothing, but data still leaves the building. ๐Ÿซข

EchoLeak uses prompt injection to break through Copilotโ€™s context and steal information. The bad actor does not need to trick you; AI becomes the way in.

This is part of a bigger trend:
More AI tools = more risk

๐Ÿ”ฅ Top News:

1๏ธโƒฃ Salesforce, over 20 configuration weaknesses found exposing sensitive data.

2๏ธโƒฃ Microsoft fixed 67 security flaws in Patch Tuesday (11 critical!).

3๏ธโƒฃ Apple patched a zero-click bug in Messages used for spying.

4๏ธโƒฃ Over 269,000 websites hit by JavaScript malware in one month.


๐Ÿซข Recent Critical & High Severity CVEs
โ†’ CVE-2025-24016 (Wazuh #KnownExploited)
โ†’ CVE-2025-32433 (Erlang #KnownExploited)
โ†’ CVE-2024-42009 (Webmail #KnownExploited)
โ†’ CVE-2025-33053 (WebDAV #PublicExploit)

See full CVE lists for the last 7 and 30 days if you want more detail โ€” https://lnkd.in/dHN8u6nA

Stay alert, patch fast, and treat AI like every other critical system. ๐Ÿ˜‘

Which threat worries you most right now?

__

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘3๐Ÿคฏ2
The world calls it "news." For us, it's Tuesday morning in Kyiv.

This isnโ€™t a movie set. Itโ€™s my neighborhood. My community. My reality.

As a cybersecurity professional, I see the same pattern here as in digital warfare: Deliberate targeting of civilian infrastructure. Accountability evasion. Global consequences when threats go unchecked.

They label it a "special military operation", but what kind of operation deliberately targets sleeping families?

Hereโ€™s what leaders need to understand:
โ†’ Civilian targeting isnโ€™t "collateral damage" โ€” itโ€™s intentional strategy
โ†’ Every attack carries command approval, just like cyber threat actors
โ†’ "Neutrality" enables aggressors

Our industryโ€™s principles apply here: Threat analysis. Defense. Accountability.

This morning, people didnโ€™t get to say "good morning."

How can we translate our skills into real-world protection for civilians? Convert your anger into contribution:

https://send.monobank.ua/jar/A3Y5u1H5cL

Eternal memory to those lost. Strength to the injured.

Action > anger.

__

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#CyberWarfare #StandWithUkraine
๐Ÿ‘7๐Ÿค”1๐Ÿคฏ1
๐Ÿซข 16 billion passwords just leaked. This is not old news - it's a new kind of threat.

Researchers found 30 fresh datasets, 16 billion credentials. Not recycled. Not old. The data includes Apple, Google, Facebook, GitHub, Telegram, even government services.

This is weaponizable intelligence. Threat actors now have a new playbook.

Every leak follows a pattern:
โ†’ Discovery
โ†’ Dark web trading
โ†’ Account takeovers
โ†’ Business disruption

But this scale? It changes the risk for everyone.

Hereโ€™s what I see (and why I worry):

1๏ธโƒฃ Password Reuse Epidemic
One bad password = ten breached accounts. People still reuse passwords across work and personal logins.

2๏ธโƒฃ MFA Gaps
Many users trust passwords alone. MFA is not everywhere, especially on high-value accounts.

3๏ธโƒฃ Detection Delays
This breach was months in the making. Many companies never knew they were exposed.

Uncomfortable truth:
Your credentials are likely in this dataset.

Hereโ€™s what security leaders must do NOW:
โ˜‘๏ธ Audit MFA coverage (focus on privileged users)
โ˜‘๏ธ Deploy credential monitoring tools
โ˜‘๏ธ If Affected - Force password resets immediately
โ˜‘๏ธ Start moving toward Zero-trust architecture

My take:
This breach is the wake-up call our industry needed. The question is not if your credentials are out there. The question is - what will you do about it?

If you see "Password123" anywhere in your org, please reach out. I want to help.

Whatโ€™s your immediate response strategy?
How are you handling this breach at your company?

__

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#DataBreach #PasswordSecurity
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘5๐Ÿคฏ3๐Ÿค”1
Your biggest vulnerability isn't your firewall โ€” It's the person sitting next to you.

95% of data breaches start with human error. Is your team the exception?

One click on a phishing link or one weak password can open the door for attackers. Thatโ€™s why I believe regular employee training is not optional - it is mission-critical.

Hereโ€™s what Iโ€™ve learned:
1๏ธโƒฃ Tailor Training to Each Role
โ†’ Developers, finance, and sales face different threats. Match content to their daily risks.

2๏ธโƒฃ Make It Interactive
โ†’ Use real scenarios and simulations. People remember what they do, not what they watch.

3๏ธโƒฃ Ask for Feedback
โ†’ Employees know what works. Use their input to improve future sessions.

4๏ธโƒฃ Test and Repeat
โ†’ Short quizzes and ongoing assessments help knowledge stick and show where to focus next.

A quick story: Early in my career, I saw a simple phishing email trick a smart, trusted team member. They felt bad, but our open culture turned it into a learning moment. We added more hands-on training and peer mentoring. The result? Fewer incidents, stronger teamwork.

Cyber threats keep changing. Our learning should too.

How do you keep your team ready?

Stay secure ๐Ÿ˜‘

__

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#EmployeeTraining #CyberAwareness
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘7๐Ÿคฏ1
#CyberMonday 7.3 Tbps DDoS in 45 seconds, do you really think your cloud is ready?

The largest DDoS attack ever seen hit 7.3 Tbps and dumped 37.4 TB of traffic in under a minute. #Cloudflare blocked it, but the message is clear:

Attackers are moving faster and hitting harder than ever.

๐Ÿ”ฅThis week's threat landscape:

1๏ธโƒฃ Off-hours Attacks Are Up
Hackers don't wait for business hours. They strike when teams are thin. If your SOC is not watching 24/7, you're giving attackers a head start.

2๏ธโƒฃ Insider Risk Is Real
A GCHQ (Government Communications Headquarters) intern took secret data home. Journalist accounts were hacked. Most breaches start with a person, not a tool.

3๏ธโƒฃ New Malware, New Tricks
Android malware like AntiDot is spreading using overlays and NFC theft. Trojanized GitHub repos are targeting devs and gamers.

4๏ธโƒฃ Big Events, Big Damages
Scattered Spider's attack on U.K. retailers caused up to $592M in losses. These are not small problems-they hit real people and real business.

๐Ÿซข Recent Critical & High Severity CVEs
โ†’ CVE-2023-0386 (#LinuxKernel #PublicExploit)
โ†’ CVE-2023-33538 (#TPLink #KnownExploited)

See full CVE lists for the last 7 and 30 days if you want more detail โ€” https://lnkd.in/dHN8u6nA

My take:
If your last DDoS test was "good enough," it's time to raise the bar.

โ†’ Run stress tests that match the scale of today's attacks
โ†’ Test your team's response outside office hours
โ†’ Patch high-severity CVEs before attackers do
โ†’ Build a culture where everyone knows their role during an incident

Security is about readiness, not luck. The next wave is already here.

__

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘6๐Ÿคฏ1
The cybersecurity "right skills shortage". SANS 2025 Workforce report.

Helen Patton, Cisco's CISO:
"My perspective is that we don't have a talent shortage in cybersecurity. The real issue lies in understanding the skill sets that are needed."


After taking a deep dive into SANS' latest Cybersecurity Workforce Research Report (3400+ respondents globally), I wanted to share some facts with the community.

Here is what stood out to me:

1๏ธโƒฃ "Right skills" set
โ†’ 52% of organizations say "not having the right staff" is a bigger problem than "not enough staff" (48%). It is essential to adapt and learn new skills to the specific requirements of your job or position.

2๏ธโƒฃ Training is non-negotiable
โ†’ 55% recognize having security teams is not enough; ongoing skills development is crucial.

3๏ธโƒฃ Certifications are a must
โ†’ 65% of jobs now require certifications for skill validation.

4๏ธโƒฃ Top Valued Skills: Teamwork, growth mindset, and adaptability.

5๏ธโƒฃ New rules (NIS 2 Directive, DORA, Cybersecurity Maturity Model Certification) are shaping how cybersecurity is hired and trained.

So, what do we learn from this?

For CISOs and hiring managers:

Look inside your team. Perhaps the Cybersecurity "star" you are looking for is already working for you and needs some development.

For career seekers:


Start with some entry certifications (CompTIA Security+, eJPT, and others) to get your foot into the first job.

Are you currently looking for a talent? How difficult is it to find a "highly skilled" professional?

Perhaps you are starting in cybersecurity. What problems are giving you the most pain when finding your first job?

Stay sharp, stay secure. ๐Ÿ˜‘

(SANS 2025 Workforce report in the comments below.)

__

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #SkillsGap #SANS
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘6๐Ÿคฏ1
#CyberMonday 7 Threats, 3 CVEs, 1 Death.

The death of one person has been linked to a ransomware attack on NHS England services at London hospitals.

King's College Hospital confirmed that one patient had "died unexpectedly" during the cyber attack on 3 June 2024, because of "a long wait for a blood test result".

This is what happens when cybersecurity fails.

And this week's risks weren't just techical, it touched lives.๐Ÿ‘‡


๐Ÿ”ฅ Top News:

1๏ธโƒฃ Ransomware + NHS = tragedy
โ†’ Delayed blood test results contributed to a patientโ€™s death.

2๏ธโƒฃ Facebook's new AI tool asks users to upload personal photos for "story ideas."

3๏ธโƒฃ LapDogs espionage: 1,000+ SOHO routers compromised in a China-linked campaign.

4๏ธโƒฃ Cisco ISE & ISE-PIC RCE flaws (CVE-2025-20281 & 20282).
โ†’ Unauthenticated API access โ†’ root privileges. Update now.

5๏ธโƒฃ Printer exploits led to real-world "Prishing" attacks via QR code bait.
โ†’ Review and act, harden your printer.

6๏ธโƒฃ Citrix Bleed 2.0 (CVE-2025-6543): Another NetScaler zero-day.

7๏ธโƒฃ GIFTEDCROOK malware evolved from browser stealer to full-blown intelligence tool.


๐Ÿซข New Critical CVEs:
โ†’ CVE-2024-54085 (#AMI Redfish API #KnownExploited)
โ†’ CVE-2024-0769 (#DLink #KnownExploited)


๐Ÿ“Œ Exploitability spike +50%:
โ†’ CVE-2015-5311 (#PowerDNS Server #DOS)


Let's be honest: cybersecurity isn't just about uptime anymore.
It's about protecting real people from real harm.

What stuck with you this week?

Stay secure ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘5๐Ÿคฏ2
Please help me to improve my Cybersecurity Blog.

I want all of you to write 3 things that you Like and 3 things that you Don't like about my Blog. ๐Ÿ‘‡

I am a humble person, and I believe there is always room for improvement.

Your feedback matters ๐Ÿ™‚

(The person with most valuable feedback will get a prise)

Stay secure ๐Ÿ˜‘
.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘8
My daily cybersecurity flow keeps me ahead of threats. Here's my 6-site routine:

Staying up to date in cybersecurity feels impossible. News breaks every hour. Threats move faster than most teams can react.

But I have found a daily system that works. I keep these 6 sites in my rotation for real-time alerts and deep dives.

โ†’ The Hacker News
Fast updates on new exploits, CVEs, and breaches. I keep this tab open all day. TG: @thehackernews

โ†’ Bleeping Computer
Trusted for alerts, malware analysis, and patch news. TG: @BleepingComputer

โ†’ tl;dr sec
7 minutes a week for the best tools and resources. Categories for tech, AI, infosec, and more.

โ†’ CISA
America's Cyber Defense Agency. I subscribe to their alerts for breaking news on threats.

โ†’ Sans Internet Storm Center
Daily "Stormcast" for threat trends, malware outbreaks, and vulnerability news.

โ†’ CVEdetails
Not just a CVE database. Advisories, exploits, and RSS feeds for vulnerability intelligence.

Each week, I scan these sites. I don't read every article. I focus on major trends and alerts. This habit keeps my team ready for what's next.

Cybersecurity is not about knowing everything. It's about having the right signals at the right time.

What am I missing? Which sites do You trust to stay ahead?

Share, save, and stay secure. ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘14๐Ÿคฏ1
#CyberMonday Hackers breached a Norwegian dam and opened the floodgates.

Norvay Critical infrastructure is under attack. Unidentified hackers have breached the systems of a Norwegian dam and opened its water valve at full capacity.

Single breach can impact communities, economies, and daily life.

Cyber risk = real-world consequences.


๐Ÿ”ฅTop News:

โ†’ Taiwan's National Security Bureau warned about apps like TikTok and Weibo. Too much data collection. Data flowing where it shouldn't.

โ†’ Exposed JDWP interfaces let attackers mine crypto and launch DDoS on your servers.

โ†’ A new APT, NightEagle, is using zero-days to target Microsoft Exchange.

โ†’ Two new Sudo flaws on Linux. Local users can get root access. Major distros affected Ubuntu, RHEL, Fedora.

โ†’ Google faces a $314M fine for passive Adroid cellular data misuse.

โ†’ Over 40 Firefox extensions are stealing crypto wallet secrets.

โ†’ Glasgow City Council is offline after an attack. City services, disrupted.


๐Ÿซข New Critical CVEs:
โ†’ CVE-2025-6554 (#Chrome #KnownExploited)
โ†’ CVE-2025-6543 (#Citrix #KnownExploited)


๐Ÿ“Œ Exploitability spike +50%:
โ†’ CVE-2024-5247 (#Netgear #RCE)
โ†’ CVE-2002-1623 (#IKE #UserEnumaration)


Stay sharp, because these threats are not stopping.

Stay secure ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘8๐Ÿคฏ2
Explaining cyber risk: ๐™ƒ๐™ค๐™ฌ ๐™„ ๐™ฉ๐™๐™ž๐™ฃ๐™  ๐™„ ๐™ก๐™ค๐™ค๐™  ๐™ซ๐™จ. ๐™ƒ๐™ค๐™ฌ ๐™„ ๐™–๐™˜๐™ฉ๐™ช๐™–๐™ก๐™ก๐™ฎ ๐™ก๐™ค๐™ค๐™ 

Everyone been there. You walk into the boardroom with slides, ready to talk risk. Picture yourself as Einstein-clear, smart, in control.

But two minutes in?

Drawing messy lines, talking about threats, and compliance.
Eyes glaze over.
Did I lose them? (Probably.)

Here's what worked for me:

โ†’ ๐—ฆ๐—ต๐—ผ๐˜„ ๐˜๐—ต๐—ฒ ๐—ป๐˜‚๐—บ๐—ฏ๐—ฒ๐—ฟ ๐Ÿค‘
"$2M at risk if things go wrong"
Beats "Here's how many vulnerabilities we have."

โ†’ ๐—จ๐˜€๐—ฒ ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐˜„๐—ผ๐—ฟ๐—ฑ๐˜€
"Business risks," not "attack vectors."
"Disruptions," not "threat actors"

โ†’ ๐—ฆ๐—ต๐—ฎ๐—ฟ๐—ฒ ๐˜€๐˜๐—ผ๐—ฟ๐—ถ๐—ฒ๐˜€
"Our competitor lost $50M last year to ransomware."
People connect with real events, not long reports.

โ†’ ๐—–๐—ฎ๐—น๐—น ๐—ผ๐˜‚๐˜ ๐˜ƒ๐—ฎ๐—น๐˜‚๐—ฒ ๐Ÿš€
Security helps us move faster, not slower.

Clarity builds trust.
That's where true security starts.

Got a better way to explain risk to non-technical leaders?
I want to hear your best tip.๐Ÿ‘‡

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#InfoSec #SecurityLeadership
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘13๐Ÿคฏ1
AI is rewriting the rules of cybersecurity. And not everyone is ready. Join live panel on July 10!

โ†’ Hear Dr. Oleh Polihenko, Anastasiia Voitova, and Taras Loboda dive into how AI is changing threat detection, response, and prevention.

โ†’ Learn how to use AI securely - without adding risk

โ†’ Live Q&A + networking at SKELAR Office, Kyiv (๐—ฎ๐—ป๐—ฑ ๐—ผ๐—ป๐—น๐—ถ๐—ป๐—ฒ!)

I see big shifts in both the field and on the frontline. (The pace is real.)

Will you join us?
Event info & registration๐Ÿ‘‡
https://meetup.skelar.tech/skelar-meetup-ai-in-security-10-07

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#AI #CyberResilience
๐Ÿ‘7๐Ÿคฏ1
AI-Cybersecurity Reality Check

Yesterday I joined a live panel with some of the sharpest minds in the field.
We talked about how AI is changing cybersecurity fast.


๐Ÿ”ฅHere are key takeaways:

1๏ธโƒฃ "Privacy is already abused." (Taras Loboda)
Our phones, our apps, even AI tools-they know us better than we think. Privacy is not what it was. We need to accept this and make smarter choices about what we share, which tools we trust, and how we protect our data.

2๏ธโƒฃ "Cybersecurity should not prohibit but enable." (Anastasiia Voitova)
Security does not mean stopping progress. Good security guides people. It helps everyone use new tools, like AI, safely.

3๏ธโƒฃ "Don't blindly trust AIs, check your data." (Dr. Oleh Polihenko)
AI makes mistakes. Sometimes it gives wrong or even risky advice. Our experience and critical thinking are more important than ever. Always check, always verify.


What can we do now?

โ†’ Use AI for boring tasks-emails, reports, compliance checklists. Let machines do the heavy lifting.

โ†’ For sensitive data, use local LLMs that you control.

โ†’ When using online AI tools like ChatGPT or Gemini, always anonymize or pseudonymize your data.

โ†’ Only allow corporate and licensed AI tools. Block everything else.

These lessons feel urgent. In both private sector and military defense, I see how fast the rules change.

Adapting is not optional.


P.S. Thank you, Andrii Popovych and SKELAR, for organizing such a great event! We need more events like this.

Thank you Anastasiia Voitova for merch from Cossacks Labs, love it.

Stay secure ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#AI #DataProtection #CyberResilience
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘17๐Ÿคฏ1