Remote
Roger A. Grimes
@rogeragrimes@infosec.exchange
Roger A. Grimes, CPA, CISSP, CEH, MCSE, CISA, CISM, CNE, yada, yada, CISO Advisor for KnowBe4, Inc., is the author of 16 books and over 1600 articles on computer security, specializing in host security and preventing hacker and malware attacks. Roger is a frequent speaker at national computer security conferences and was the weekly security columnist at InfoWorld and CSO magazines between 2005 - 2019. He has worked at some of the world’s largest computer security companies, including, Foundstone, McAfee, and Microsoft. Roger is frequently interviewed and quoted in the media including Newsweek, CNN, NPR, and WSJ. His presentations are fast-paced and filled with useful facts and recommendations.
167 Followers
48 Following
29 Posts
Joined October 12, 2023
computer security:
phishing
hackers:
hacking
webinars:
presenting
data driven defense:
defense
malware:
windows
Science fact of the day: Every colored thing we see is the opposite of the color we are seeing. You only see color that the object doesn't absorb and reflects back instead. That red object. It's really every color but red. Now go live with that realization.
Open post
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
https://thehackernews.com/2026/06/new-gaslight-macos-malware-uses-prompt.html
This is a great example of how attacks TO AI are likely a bigger issue in the long run than attacks FROM AI.
0
0
0
0
Open post
Check out my latest article: First Case of Fully Autonomous AI Ransomware
https://www.linkedin.com/pulse/first-case-fully-autonomous-ai-ransomware-roger-grimes-jibwe
0
0
0
0
Open post
Zscaler finds autonomous agents succumb to IPI traps
https://www.csoonline.com/article/4193498/zscaler-finds-autonomous-agents-succumb-to-ipi-traps-2.html
If you use AI agents to help with your email, calendaring, or browsing, just be aware that there are "hidden" attacks that they may fall for
0
0
0
0
Open post
All new cars sold in the US and UK will have infrared cameras pointed at the driver's face to detect distracted drivers. If it detects a distracted driver, it will try to make them alert. It stores that data on the car. I wonder if it can be obtained by police and accident investigators?? Privacy groups are concerned.
https://risky.biz/risky-bulletin-all-new-cars-to-include-a-camera-aimed-at-the-drivers-face/
0
0
0
0
Open post
Wow! Nearly 5,000 Security Issues Identified Across 2,259 Public MCP Servers
https://cybersecuritynews.com/security-issues-mcp-servers/
Many of the flaws will allow access to the desktops, clouds, and applications that use them. Many of them had exposed logon credentials.
0
0
0
0
Open post
Husband deleted their invitation to Taylor Swift's wedding because he thought it was a phishing attempt. Haha. Lot of spouses would be mad.
https://www.huffpost.com/entry/tk_n_6a4d953ce4b094d71e70f5a5?origin=home-whats-happening-unit
0
0
0
0
Open post
Wiz announces the GhostApproval vulnerability in six of the top AI coding assistants: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. A malicious repository can trick the agent into accessing arbitrary files outside the workspace sandbox, potentially achieving remote code execution on the developer's machine.
https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants
0
0
0
0
Open post
Check out my latest article: Don’t Follow Post-Quantum Recommendations to Key 128-bit Keys and Hashes https://www.linkedin.com/pulse/dont-follow-post-quantum-recommendations-key-128-bit-keys-grimes-2k39e
0
0
0
0
Open post
CBS reporter Matt Gutman was almost scammed into withdrawing his entire bank account and giving it to fraudsters claiming to be with his bank's fraud investigation team. Be aware!
https://www.msn.com/en-us/money/news/cbs-news-matt-gutman-says-he-got-completely-scammed/ar-AA27KZPL
0
0
0
0
Open post
Check out my latest article: What is a Tensor?
https://www.linkedin.com/pulse/what-tensor-roger-grimes-tnvae
0
0
0
0
Open post
Interesting. X code to be open source
https://thenewstack.io/x-open-source-codebase/
0
0
0
0
Open post
Cool website showing AI (and AI-related) vendor's expenses versus revenues. Basically, only the chip manufacturers are close to being profitable: https://isaiprofitable.com/
0
0
0
0
Open post
OpenAI used stolen credentials and a 0-day to break into Hugging Face. Care to explain the stolen credentials more?
0
0
0
0
Open post
26-year-old Illinois man sentenced to 6 years in prison for hacking/social engineering Snapchat accounts of young women and stealing nude photos. On a related note, Northeastern University track was sentenced to 5 years for hiring the hacker to hack into female athlete accounts.
https://www.bleepingcomputer.com/news/security/man-gets-six-years-for-hacking-750-womens-snapchat-accounts/
0
0
0
0
Open post
Using Claude or any AI agent on the same computer where you do banking is just asking for trouble. Until the security gets figured out, you must isolate your AI agents or accept the risk that your could be compromised at will.
0
0
0
0
Open post
SIKE, RAINBOW, and now, HAWK, are your reminders that no PQC algorithm is provable secure. PQC is a (necessary) intermediate step toward truly secure quantum encryption
https://decrypt.co/374600/claude-mythos-cracked-post-quantum-cryptography
0
0
0
0
Open post
Be careful, hackers are exploiting hotel WiFi DNS to unknowingly redirect Microsoft O365 users to bogus logon websites. I suspect this is not widespread, but hotel WiFi's are notoriously insecure (often unpatched, default passwords, etc.). Watch those logon URLs.
https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/
0
0
0
0
Open post
Developers will die laughing reading this.
https://nesbitt.io/2026/06/26/incident-report-cve-2026-lgtm.html
0
0
0
0
Open post
You should care and focus on features 100% and what those features give you that you didn't have before, do they help your environment, and not care if those new features were given to you by AI or not.
0
0
0
0
Open post
25 Industry titan companies urge the White House and Congress not to restrict open weight AI models. Good call...not that making them illegal would have worked anyway.
https://www.secureworld.io/industry-news/open-weight-ai-models
0
0
0
0
Open post
AI is making cybersecurity fundamentals more important than ever (I'm quoted)
https://www.csoonline.com/article/4204101/ai-is-making-cybersecurity-fundamentals-more-important-than-ever.html
0
0
0
0
Open post
Technical Deep dive on how CrowdStrike Falcon works
https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/
0
0
0
0
Open post
This past May, a military exercise using GPS jamming made a medivac aircraft with two pilots and two nurses slam into a mountain.
https://www.wired.com/story/a-civilian-plane-crashed-in-new-mexico-was-the-militarys-tech-to-blame
0
0
3
0
Open post
Check out my latest article: Hunt for the Huntsman Spider
https://www.linkedin.com/pulse/hunt-huntsman-spider-roger-grimes-vahqe
0
0
0
0
Open post
I was pretty excited to read the new CISA memo about how they were going to improve the existing Common Vulnerabilities and Exposures (CVE) Program. But it's a big nothingburger. It says a lot of wonderful, nebulous things (likely written by AI) without actually saying what they will be doing that is net new. No details. Just a vision. I liked what I read...but where's the beef? I mean, why did they make this announcement?
https://www.cisa.gov/resources-tools/resources/cve-program-establishing-quality-era-framework
0
0
0
0
Open post
Replying to
@lmk@infosec.exchange That's like asking what color is a prism? It's what it is reflecting or transporting, which in general is all the colors our eyes really don't see. You can't see something if the color or photon is absorbed. We see what bounces off.
0
0
0
0


