Security Engineer
422 subscribers
88 photos
1 video
45 links
A diary of Security Engineerโ€˜s life. The good, the bad, the secure ๐Ÿ˜ฌ

Ping for cooperation @stansecure

My LinkedIn linkedin.com/in/stansecure/
Download Telegram
Your biggest vulnerability isn't your firewall โ€” It's the person sitting next to you.

95% of data breaches start with human error. Is your team the exception?

One click on a phishing link or one weak password can open the door for attackers. Thatโ€™s why I believe regular employee training is not optional - it is mission-critical.

Hereโ€™s what Iโ€™ve learned:
1๏ธโƒฃ Tailor Training to Each Role
โ†’ Developers, finance, and sales face different threats. Match content to their daily risks.

2๏ธโƒฃ Make It Interactive
โ†’ Use real scenarios and simulations. People remember what they do, not what they watch.

3๏ธโƒฃ Ask for Feedback
โ†’ Employees know what works. Use their input to improve future sessions.

4๏ธโƒฃ Test and Repeat
โ†’ Short quizzes and ongoing assessments help knowledge stick and show where to focus next.

A quick story: Early in my career, I saw a simple phishing email trick a smart, trusted team member. They felt bad, but our open culture turned it into a learning moment. We added more hands-on training and peer mentoring. The result? Fewer incidents, stronger teamwork.

Cyber threats keep changing. Our learning should too.

How do you keep your team ready?

Stay secure ๐Ÿ˜‘

__

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#EmployeeTraining #CyberAwareness
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘7๐Ÿคฏ1
#CyberMonday 7.3 Tbps DDoS in 45 seconds, do you really think your cloud is ready?

The largest DDoS attack ever seen hit 7.3 Tbps and dumped 37.4 TB of traffic in under a minute. #Cloudflare blocked it, but the message is clear:

Attackers are moving faster and hitting harder than ever.

๐Ÿ”ฅThis week's threat landscape:

1๏ธโƒฃ Off-hours Attacks Are Up
Hackers don't wait for business hours. They strike when teams are thin. If your SOC is not watching 24/7, you're giving attackers a head start.

2๏ธโƒฃ Insider Risk Is Real
A GCHQ (Government Communications Headquarters) intern took secret data home. Journalist accounts were hacked. Most breaches start with a person, not a tool.

3๏ธโƒฃ New Malware, New Tricks
Android malware like AntiDot is spreading using overlays and NFC theft. Trojanized GitHub repos are targeting devs and gamers.

4๏ธโƒฃ Big Events, Big Damages
Scattered Spider's attack on U.K. retailers caused up to $592M in losses. These are not small problems-they hit real people and real business.

๐Ÿซข Recent Critical & High Severity CVEs
โ†’ CVE-2023-0386 (#LinuxKernel #PublicExploit)
โ†’ CVE-2023-33538 (#TPLink #KnownExploited)

See full CVE lists for the last 7 and 30 days if you want more detail โ€” https://lnkd.in/dHN8u6nA

My take:
If your last DDoS test was "good enough," it's time to raise the bar.

โ†’ Run stress tests that match the scale of today's attacks
โ†’ Test your team's response outside office hours
โ†’ Patch high-severity CVEs before attackers do
โ†’ Build a culture where everyone knows their role during an incident

Security is about readiness, not luck. The next wave is already here.

__

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘6๐Ÿคฏ1
The cybersecurity "right skills shortage". SANS 2025 Workforce report.

Helen Patton, Cisco's CISO:
"My perspective is that we don't have a talent shortage in cybersecurity. The real issue lies in understanding the skill sets that are needed."


After taking a deep dive into SANS' latest Cybersecurity Workforce Research Report (3400+ respondents globally), I wanted to share some facts with the community.

Here is what stood out to me:

1๏ธโƒฃ "Right skills" set
โ†’ 52% of organizations say "not having the right staff" is a bigger problem than "not enough staff" (48%). It is essential to adapt and learn new skills to the specific requirements of your job or position.

2๏ธโƒฃ Training is non-negotiable
โ†’ 55% recognize having security teams is not enough; ongoing skills development is crucial.

3๏ธโƒฃ Certifications are a must
โ†’ 65% of jobs now require certifications for skill validation.

4๏ธโƒฃ Top Valued Skills: Teamwork, growth mindset, and adaptability.

5๏ธโƒฃ New rules (NIS 2 Directive, DORA, Cybersecurity Maturity Model Certification) are shaping how cybersecurity is hired and trained.

So, what do we learn from this?

For CISOs and hiring managers:

Look inside your team. Perhaps the Cybersecurity "star" you are looking for is already working for you and needs some development.

For career seekers:


Start with some entry certifications (CompTIA Security+, eJPT, and others) to get your foot into the first job.

Are you currently looking for a talent? How difficult is it to find a "highly skilled" professional?

Perhaps you are starting in cybersecurity. What problems are giving you the most pain when finding your first job?

Stay sharp, stay secure. ๐Ÿ˜‘

(SANS 2025 Workforce report in the comments below.)

__

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #SkillsGap #SANS
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘6๐Ÿคฏ1
#CyberMonday 7 Threats, 3 CVEs, 1 Death.

The death of one person has been linked to a ransomware attack on NHS England services at London hospitals.

King's College Hospital confirmed that one patient had "died unexpectedly" during the cyber attack on 3 June 2024, because of "a long wait for a blood test result".

This is what happens when cybersecurity fails.

And this week's risks weren't just techical, it touched lives.๐Ÿ‘‡


๐Ÿ”ฅ Top News:

1๏ธโƒฃ Ransomware + NHS = tragedy
โ†’ Delayed blood test results contributed to a patientโ€™s death.

2๏ธโƒฃ Facebook's new AI tool asks users to upload personal photos for "story ideas."

3๏ธโƒฃ LapDogs espionage: 1,000+ SOHO routers compromised in a China-linked campaign.

4๏ธโƒฃ Cisco ISE & ISE-PIC RCE flaws (CVE-2025-20281 & 20282).
โ†’ Unauthenticated API access โ†’ root privileges. Update now.

5๏ธโƒฃ Printer exploits led to real-world "Prishing" attacks via QR code bait.
โ†’ Review and act, harden your printer.

6๏ธโƒฃ Citrix Bleed 2.0 (CVE-2025-6543): Another NetScaler zero-day.

7๏ธโƒฃ GIFTEDCROOK malware evolved from browser stealer to full-blown intelligence tool.


๐Ÿซข New Critical CVEs:
โ†’ CVE-2024-54085 (#AMI Redfish API #KnownExploited)
โ†’ CVE-2024-0769 (#DLink #KnownExploited)


๐Ÿ“Œ Exploitability spike +50%:
โ†’ CVE-2015-5311 (#PowerDNS Server #DOS)


Let's be honest: cybersecurity isn't just about uptime anymore.
It's about protecting real people from real harm.

What stuck with you this week?

Stay secure ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘5๐Ÿคฏ2
Please help me to improve my Cybersecurity Blog.

I want all of you to write 3 things that you Like and 3 things that you Don't like about my Blog. ๐Ÿ‘‡

I am a humble person, and I believe there is always room for improvement.

Your feedback matters ๐Ÿ™‚

(The person with most valuable feedback will get a prise)

Stay secure ๐Ÿ˜‘
.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘8
My daily cybersecurity flow keeps me ahead of threats. Here's my 6-site routine:

Staying up to date in cybersecurity feels impossible. News breaks every hour. Threats move faster than most teams can react.

But I have found a daily system that works. I keep these 6 sites in my rotation for real-time alerts and deep dives.

โ†’ The Hacker News
Fast updates on new exploits, CVEs, and breaches. I keep this tab open all day. TG: @thehackernews

โ†’ Bleeping Computer
Trusted for alerts, malware analysis, and patch news. TG: @BleepingComputer

โ†’ tl;dr sec
7 minutes a week for the best tools and resources. Categories for tech, AI, infosec, and more.

โ†’ CISA
America's Cyber Defense Agency. I subscribe to their alerts for breaking news on threats.

โ†’ Sans Internet Storm Center
Daily "Stormcast" for threat trends, malware outbreaks, and vulnerability news.

โ†’ CVEdetails
Not just a CVE database. Advisories, exploits, and RSS feeds for vulnerability intelligence.

Each week, I scan these sites. I don't read every article. I focus on major trends and alerts. This habit keeps my team ready for what's next.

Cybersecurity is not about knowing everything. It's about having the right signals at the right time.

What am I missing? Which sites do You trust to stay ahead?

Share, save, and stay secure. ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘14๐Ÿคฏ1
#CyberMonday Hackers breached a Norwegian dam and opened the floodgates.

Norvay Critical infrastructure is under attack. Unidentified hackers have breached the systems of a Norwegian dam and opened its water valve at full capacity.

Single breach can impact communities, economies, and daily life.

Cyber risk = real-world consequences.


๐Ÿ”ฅTop News:

โ†’ Taiwan's National Security Bureau warned about apps like TikTok and Weibo. Too much data collection. Data flowing where it shouldn't.

โ†’ Exposed JDWP interfaces let attackers mine crypto and launch DDoS on your servers.

โ†’ A new APT, NightEagle, is using zero-days to target Microsoft Exchange.

โ†’ Two new Sudo flaws on Linux. Local users can get root access. Major distros affected Ubuntu, RHEL, Fedora.

โ†’ Google faces a $314M fine for passive Adroid cellular data misuse.

โ†’ Over 40 Firefox extensions are stealing crypto wallet secrets.

โ†’ Glasgow City Council is offline after an attack. City services, disrupted.


๐Ÿซข New Critical CVEs:
โ†’ CVE-2025-6554 (#Chrome #KnownExploited)
โ†’ CVE-2025-6543 (#Citrix #KnownExploited)


๐Ÿ“Œ Exploitability spike +50%:
โ†’ CVE-2024-5247 (#Netgear #RCE)
โ†’ CVE-2002-1623 (#IKE #UserEnumaration)


Stay sharp, because these threats are not stopping.

Stay secure ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘8๐Ÿคฏ2
Explaining cyber risk: ๐™ƒ๐™ค๐™ฌ ๐™„ ๐™ฉ๐™๐™ž๐™ฃ๐™  ๐™„ ๐™ก๐™ค๐™ค๐™  ๐™ซ๐™จ. ๐™ƒ๐™ค๐™ฌ ๐™„ ๐™–๐™˜๐™ฉ๐™ช๐™–๐™ก๐™ก๐™ฎ ๐™ก๐™ค๐™ค๐™ 

Everyone been there. You walk into the boardroom with slides, ready to talk risk. Picture yourself as Einstein-clear, smart, in control.

But two minutes in?

Drawing messy lines, talking about threats, and compliance.
Eyes glaze over.
Did I lose them? (Probably.)

Here's what worked for me:

โ†’ ๐—ฆ๐—ต๐—ผ๐˜„ ๐˜๐—ต๐—ฒ ๐—ป๐˜‚๐—บ๐—ฏ๐—ฒ๐—ฟ ๐Ÿค‘
"$2M at risk if things go wrong"
Beats "Here's how many vulnerabilities we have."

โ†’ ๐—จ๐˜€๐—ฒ ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐˜„๐—ผ๐—ฟ๐—ฑ๐˜€
"Business risks," not "attack vectors."
"Disruptions," not "threat actors"

โ†’ ๐—ฆ๐—ต๐—ฎ๐—ฟ๐—ฒ ๐˜€๐˜๐—ผ๐—ฟ๐—ถ๐—ฒ๐˜€
"Our competitor lost $50M last year to ransomware."
People connect with real events, not long reports.

โ†’ ๐—–๐—ฎ๐—น๐—น ๐—ผ๐˜‚๐˜ ๐˜ƒ๐—ฎ๐—น๐˜‚๐—ฒ ๐Ÿš€
Security helps us move faster, not slower.

Clarity builds trust.
That's where true security starts.

Got a better way to explain risk to non-technical leaders?
I want to hear your best tip.๐Ÿ‘‡

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#InfoSec #SecurityLeadership
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘13๐Ÿคฏ1
AI is rewriting the rules of cybersecurity. And not everyone is ready. Join live panel on July 10!

โ†’ Hear Dr. Oleh Polihenko, Anastasiia Voitova, and Taras Loboda dive into how AI is changing threat detection, response, and prevention.

โ†’ Learn how to use AI securely - without adding risk

โ†’ Live Q&A + networking at SKELAR Office, Kyiv (๐—ฎ๐—ป๐—ฑ ๐—ผ๐—ป๐—น๐—ถ๐—ป๐—ฒ!)

I see big shifts in both the field and on the frontline. (The pace is real.)

Will you join us?
Event info & registration๐Ÿ‘‡
https://meetup.skelar.tech/skelar-meetup-ai-in-security-10-07

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#AI #CyberResilience
๐Ÿ‘7๐Ÿคฏ1
AI-Cybersecurity Reality Check

Yesterday I joined a live panel with some of the sharpest minds in the field.
We talked about how AI is changing cybersecurity fast.


๐Ÿ”ฅHere are key takeaways:

1๏ธโƒฃ "Privacy is already abused." (Taras Loboda)
Our phones, our apps, even AI tools-they know us better than we think. Privacy is not what it was. We need to accept this and make smarter choices about what we share, which tools we trust, and how we protect our data.

2๏ธโƒฃ "Cybersecurity should not prohibit but enable." (Anastasiia Voitova)
Security does not mean stopping progress. Good security guides people. It helps everyone use new tools, like AI, safely.

3๏ธโƒฃ "Don't blindly trust AIs, check your data." (Dr. Oleh Polihenko)
AI makes mistakes. Sometimes it gives wrong or even risky advice. Our experience and critical thinking are more important than ever. Always check, always verify.


What can we do now?

โ†’ Use AI for boring tasks-emails, reports, compliance checklists. Let machines do the heavy lifting.

โ†’ For sensitive data, use local LLMs that you control.

โ†’ When using online AI tools like ChatGPT or Gemini, always anonymize or pseudonymize your data.

โ†’ Only allow corporate and licensed AI tools. Block everything else.

These lessons feel urgent. In both private sector and military defense, I see how fast the rules change.

Adapting is not optional.


P.S. Thank you, Andrii Popovych and SKELAR, for organizing such a great event! We need more events like this.

Thank you Anastasiia Voitova for merch from Cossacks Labs, love it.

Stay secure ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#AI #DataProtection #CyberResilience
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘17๐Ÿคฏ1
#CyberMonday Office RCEs. Bluetooth car hacks. Four teens arrested after cyberattacks.

The National Crime Agency arrested three young men and one woman-ages 17 to 20-used, who used social engineering to breach two of the UKโ€™s biggest retailer stores (M&S and Co-op).


๐Ÿ”ฅTop News:

โ†’ Patch Tuesday: Microsoft Office RCEs

โ†’ PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution

โ†’ An Iranian-backed ransomware-as-a-service (RaaS) named Pay2Key has resurfaced in the wake of the Israel-Iran-U.S. conflict last month

โ†’ Fortinet's critical SQL injection flaw affecting FortiWeb

โ†’ Wing FTP Server vulnerability actively exploited


๐Ÿซข New Critical/High CVEs:
โ†’ CVE-2016-10033 (#PHPMailer #PublicExploit)
โ†’ CVE-2019-9621 (#Zimbra #PublicExploit)
โ†’ CVE-2019-5418 (#ActionView #PublicExploit)
โ†’ CVE-2025-5777 (#NetScaler #KnownExploited)
โ†’ CVE-2014-3931 (#MRLG #KnownExploited)


As always, share new CVEs and your thoughts in comments. ๐Ÿ‘‡

Stay secure ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘4๐Ÿคฏ1
How to Improve my Cybersecurity Blog.

I asked for your feedback and response was incredible.
A huge thank you to everyone who shared their thoughts! The quality and quantity of the feedback was humbling. I truly appreciate it.

What you like

โœ… Consistency & Quality
The predictable #CyberMonday posts, sharp insights, and quality visuals all a hit.

โœ… Clarity & Accessibility
You appreciate that the content is easy to understand, even for beginners, and provides a clear message.

โœ… Value
Getting relevant news summaries without having to search the internet is something you find valuable.

Now to the exciting part: the improvements. I've gathered all your suggestions into a few key themes.

Here are the top recommendations

1๏ธโƒฃ Real-World Stories & Case Studies
This was the most requested topic. You want to hear about real cases (mine or others), the biggest hacks and failures. The focus would be on how problems were actually solved, not just what happened.
(Inspired by Oleksandr, Vasyl, Anton, @leleka_marabou)

2๏ธโƒฃ Career Growth & A Day in the Life
Many of you, especially those looking to enter or switch to cybersecurity, want to know what the job is really like. This could include my present struggles, career paths, and how I look for new opportunities and certifications.
(Inspired by Anna Ovsepian, @OleksTpk, @rdbstrd)

3๏ธโƒฃ Deep Dives & Niche Research:
A call for more technical content, including reviews of promising tools, deep dives into infosec research, and analysis of bug bounty reports.
(Inspired by Dawid Czarnecki, @TuPa_Ded, @rdbstrd)

4๏ธโƒฃ More Fun
Injecting more personality, some funny stories or jokes related to the field.
(Inspired by Abel, Anna Ovsepian, @rdbstrd)

As I promissed I've choosen a winner for most valuable comment. The winner is @rdbstrd!

Please send me a DM, and we'll sort out how to send you a book! ๐Ÿ™‚

Thank you again to everyone who contributed, including Oleksandr Zaliubovskyi, Vladyslav Panchenko, Dawid Czarnecki, Vasyl Kuzyk, Pavlo Somko, Abel Hailu, Anton Kalakutskyi, Anna Ovsepian, Anastasia Mieshkova, @letsencryptssl, @TuPa_Ded, @OleksTpk, @leleka_marabou, and @rdbstrd.

Let's build a better blog together.

As always, stay secure๐Ÿ˜‘.

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #CyberSec
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘11
#CyberMonday Microsoft let engineers in China touch US DoD data.

Last week, a ProPublica investigation revealed that Microsoft subcontractors in China helped maintain US Defense Department systems-with little oversight from US staff.

Sensitive data. Minimal control = Maximum risk.

๐Ÿ”ฅTop News:

โ†’ Salt Typhoon (China-backed APT) quietly compromised the US Army National Guard for nearly a year.

โ†’ Massistant, a new surveillance tool in China โ€“ can silently extract SMS, GPS, and images from confiscated phones.

โ†’ Ivanti Zero-Days Exploited

โ†’ CERT-UA Discovers LAMEHUG Malware Linked to APT28, Using LLM for Phishing Campaign


๐Ÿซข New Critical CVEs:
โ†’ CVE-2025-53770 (#SharePoint #KnownExploited)
โ†’ CVE-2025-25257 (#FortiWeb #KnownExploited)
โ†’ CVE-2025-47812 (#WingFTP #PublicExploit)

Share new CVEs and your thoughts in comments. ๐Ÿ‘‡

Stay secure ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘6
Cybersecurity in Development - Online Webinar.

I am joining PM Coffee Time with Mykola Kalakutskyi and Kateryna Mandryka for their 40th anniversary session on July 30th. We'll talk about cybersecurity in development-and why you must keep security at the center of every project.

Here's what you can expect ๐Ÿ‘‡

โ†’ How secure development process protects your project
โ†’ Why every person in organization (not just security teams) is responsible for strong cyber defense
โ†’ Practical steps to make security part of your SDLC
โ†’ How can cybersecurity be an enabler for your business

Good security is not something you add at the end. You build it in from day one.

The session is open to everyone - new PMs, senior leaders, and anyone who cares about quality and resilience.

๐Ÿ“… July 30th

๐Ÿ”— Free to join: https://lnkd.in/dgSWvhrQ

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ProjectManagement
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘8๐Ÿคฏ1
#CyberMonday SharePoint at risk even after updates.

Attackers are using ToolShell to target unpatched SharePoint servers on-premises.

They install web shell backdoors and steal Machine Keys. That means even after you patch, attackers can stick around, move deeper, and deploy ransomware.

Read more on CVE-2025-53770.

Rapid-response checklist:

โ†’ Isolate vulnerable servers from your network
โ†’ Apply all available SharePoint updates
โ†’ Rotate Machine Keys
โ†’ Ensure anti-malware scanning is enabled
โ†’ Reset all credentials that touched those servers
โ†’ Scan for indicators of compromise


๐Ÿ”ฅTop News:

โ†’ CrushFTP Critical Flaw Exploited (CVE-2025-54309)

โ†’ UK Plans Ransomware Payment Ban and Reporting Requirements

โ†’ Cyber Espionage Campaign Hits Russian Aerospace Sector Using EAGLET Backdoor


๐Ÿซข New Critical/High CVEs:
โ†’ CVE-2025-2775/2776 (#SysAid #XXE)
โ†’ CVE-2025-6558 (#Chrome #SandboxEscape)


What grabbed your attention this week? Share in comments.

Stay safe ๐Ÿ˜‘

___

Enjoy this? ๐Ÿ”„ Repost it to your network and follow @securediary for more.

Join me on LinkedIn.

#Cybersecurity #InfoSec #ThreatIntel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘5๐Ÿค”1