en
Feedback
Security Engineer

Security Engineer

Open in Telegram

A diary of Security Engineer‘s life. The good, the bad, the secure 😬 Ping for cooperation @stansecure My LinkedIn linkedin.com/in/stansecure/

Show more
379
Subscribers
No data24 hours
-37 days
-830 days
Posts Archive
#CyberMonday 7.3 Tbps DDoS in 45 seconds, do you really think your cloud is ready? The largest DDoS attack ever seen hit 7.3
#CyberMonday 7.3 Tbps DDoS in 45 seconds, do you really think your cloud is ready? The largest DDoS attack ever seen hit 7.3 Tbps and dumped 37.4 TB of traffic in under a minute. #Cloudflare blocked it, but the message is clear: Attackers are moving faster and hitting harder than ever. 🔥This week's threat landscape: 1️⃣ Off-hours Attacks Are Up Hackers don't wait for business hours. They strike when teams are thin. If your SOC is not watching 24/7, you're giving attackers a head start. 2️⃣ Insider Risk Is Real A GCHQ (Government Communications Headquarters) intern took secret data home. Journalist accounts were hacked. Most breaches start with a person, not a tool. 3️⃣ New Malware, New Tricks Android malware like AntiDot is spreading using overlays and NFC theft. Trojanized GitHub repos are targeting devs and gamers. 4️⃣ Big Events, Big Damages Scattered Spider's attack on U.K. retailers caused up to $592M in losses. These are not small problems-they hit real people and real business. 🫢 Recent Critical & High Severity CVEs → CVE-2023-0386 (#LinuxKernel #PublicExploit) → CVE-2023-33538 (#TPLink #KnownExploited) See full CVE lists for the last 7 and 30 days if you want more detail — https://lnkd.in/dHN8u6nA My take: If your last DDoS test was "good enough," it's time to raise the bar. → Run stress tests that match the scale of today's attacks → Test your team's response outside office hours → Patch high-severity CVEs before attackers do → Build a culture where everyone knows their role during an incident Security is about readiness, not luck. The next wave is already here. __ Enjoy this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn. #Cybersecurity #InfoSec #ThreatIntel

Your biggest vulnerability isn't your firewall — It's the person sitting next to you. 95% of data breaches start with human e
+7
Your biggest vulnerability isn't your firewall — It's the person sitting next to you. 95% of data breaches start with human error. Is your team the exception? One click on a phishing link or one weak password can open the door for attackers. That’s why I believe regular employee training is not optional - it is mission-critical. Here’s what I’ve learned: 1️⃣ Tailor Training to Each Role → Developers, finance, and sales face different threats. Match content to their daily risks. 2️⃣ Make It Interactive → Use real scenarios and simulations. People remember what they do, not what they watch. 3️⃣ Ask for Feedback → Employees know what works. Use their input to improve future sessions. 4️⃣ Test and Repeat → Short quizzes and ongoing assessments help knowledge stick and show where to focus next. A quick story: Early in my career, I saw a simple phishing email trick a smart, trusted team member. They felt bad, but our open culture turned it into a learning moment. We added more hands-on training and peer mentoring. The result? Fewer incidents, stronger teamwork. Cyber threats keep changing. Our learning should too. How do you keep your team ready? Stay secure 😑 __ Enjoy this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn. #EmployeeTraining #CyberAwareness

🫢 16 billion passwords just leaked. This is not old news - it's a new kind of threat. Researchers found 30 fresh datasets, 1
🫢 16 billion passwords just leaked. This is not old news - it's a new kind of threat. Researchers found 30 fresh datasets, 16 billion credentials. Not recycled. Not old. The data includes Apple, Google, Facebook, GitHub, Telegram, even government services. This is weaponizable intelligence. Threat actors now have a new playbook. Every leak follows a pattern: → Discovery → Dark web trading → Account takeovers → Business disruption But this scale? It changes the risk for everyone. Here’s what I see (and why I worry): 1️⃣ Password Reuse Epidemic One bad password = ten breached accounts. People still reuse passwords across work and personal logins. 2️⃣ MFA Gaps Many users trust passwords alone. MFA is not everywhere, especially on high-value accounts. 3️⃣ Detection Delays This breach was months in the making. Many companies never knew they were exposed. Uncomfortable truth: Your credentials are likely in this dataset. Here’s what security leaders must do NOW: ☑️ Audit MFA coverage (focus on privileged users) ☑️ Deploy credential monitoring tools ☑️ If Affected - Force password resets immediately ☑️ Start moving toward Zero-trust architecture My take: This breach is the wake-up call our industry needed. The question is not if your credentials are out there. The question is - what will you do about it? If you see "Password123" anywhere in your org, please reach out. I want to help. What’s your immediate response strategy? How are you handling this breach at your company? __ Enjoy this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn. #DataBreach #PasswordSecurity

The world calls it "news." For us, it's Tuesday morning in Kyiv. This isn’t a movie set. It’s my neighborhood. My community.
The world calls it "news." For us, it's Tuesday morning in Kyiv. This isn’t a movie set. It’s my neighborhood. My community. My reality. As a cybersecurity professional, I see the same pattern here as in digital warfare: Deliberate targeting of civilian infrastructure. Accountability evasion. Global consequences when threats go unchecked. They label it a "special military operation", but what kind of operation deliberately targets sleeping families? Here’s what leaders need to understand: → Civilian targeting isn’t "collateral damage" — it’s intentional strategy → Every attack carries command approval, just like cyber threat actors → "Neutrality" enables aggressors Our industry’s principles apply here: Threat analysis. Defense. Accountability. This morning, people didn’t get to say "good morning." How can we translate our skills into real-world protection for civilians? Convert your anger into contribution: https://send.monobank.ua/jar/A3Y5u1H5cL Eternal memory to those lost. Strength to the injured. Action > anger. __ Enjoy this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn. #CyberWarfare #StandWithUkraine

#CyberMonday EchoLeak: Zero-click AI attacks now steal Microsoft 365 data with no user action needed. A new threat called Ech
#CyberMonday EchoLeak: Zero-click AI attacks now steal Microsoft 365 data with no user action needed. A new threat called EchoLeak has appeared recently. Attackers can now pull sensitive data right out of Microsoft 365 Copilot - no clicks, no alerts, no warning. Zero-click means users do nothing, but data still leaves the building. 🫢 EchoLeak uses prompt injection to break through Copilot’s context and steal information. The bad actor does not need to trick you; AI becomes the way in. This is part of a bigger trend: More AI tools = more risk 🔥 Top News: 1️⃣ Salesforce, over 20 configuration weaknesses found exposing sensitive data. 2️⃣ Microsoft fixed 67 security flaws in Patch Tuesday (11 critical!). 3️⃣ Apple patched a zero-click bug in Messages used for spying. 4️⃣ Over 269,000 websites hit by JavaScript malware in one month. 🫢 Recent Critical & High Severity CVEs → CVE-2025-24016 (Wazuh #KnownExploited) → CVE-2025-32433 (Erlang #KnownExploited) → CVE-2024-42009 (Webmail #KnownExploited) → CVE-2025-33053 (WebDAV #PublicExploit) See full CVE lists for the last 7 and 30 days if you want more detail — https://lnkd.in/dHN8u6nA Stay alert, patch fast, and treat AI like every other critical system. 😑 Which threat worries you most right now? __ Enjoy this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn. #Cybersecurity #InfoSec #ThreatIntel

The biggest telecom hack in history didn’t start with malware. It started with a person. A compromised employee account. On D
+6
The biggest telecom hack in history didn’t start with malware. It started with a person. A compromised employee account. On December 12, 2023, Kyivstar, Ukraine’s largest telecom, was taken down 24 million people lost mobile service. No phone. No internet. No air raid alerts. The attackers didn’t break in, they were already inside. This wasn’t just a breach. It was cyberwar, and a blueprint for what’s coming. Here are 3 lessons I believe every security leader must act on now: 1️⃣ The Myth of the Impenetrable Fortress is Dead Attackers got in by targeting people, not tech. They were inside for weeks before striking. ✔️ Your biggest risk is not your firewall - it’s your people. ✔️ Assume breach. Build from the inside out. ✔️ Security culture matters more than the latest tool. 2️⃣ Resilience > Prevention When the core was destroyed, prevention didn’t matter. Recovery did. ✔️ Do your backups survive when the backups are targeted? ✔️ Has your incident response actually been tested under fire? ✔️ Can your business keep running under attack? 3️⃣ Attacks Hit People, Not Just Servers → ATMs down. → Air Raid Alerts silenced. → Lives disrupted. This wasn’t an IT problem. It was a humanitarian one. We defend networks, but what we’re really protecting are communities, economies, and national resilience. The Kyivstar attack wasn’t just about code. It was about culture, readiness, and people under pressure. The real heroes? The engineers working through the night. Their story matters just as much as the breach. Stay secure. 😑 __ Enjoying this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn. #Resilience #Kyivstar

Want free mentorship? Bring 3 friends who love cybersecurity! I know how hard it can feel to start in cybersecurity. When I b
Want free mentorship? Bring 3 friends who love cybersecurity! I know how hard it can feel to start in cybersecurity. When I began my journey, I had many questions and not enough answers. Today, I want to give back to the community that helped me learn and grow. Here’s how it works: 1️⃣ Invite 3 friends who are interested in cybersecurity 2️⃣ Comment below their names 3️⃣ I’ll set up a free 1:1 session with you!💡 What will we talk about? → How to start a career in cybersecurity → Real-world threat trends and how to defend against them → Building a risk-resilient mindset → Deep dive into technical security (AWS, Azure, best practices) Why bring friends? Cybersecurity is not a solo sport. The more voices we have, the stronger our community becomes. Together, we can build a safer digital world. 🌎 I’ve spent over 10 years leading security teams and building strong defenses, in the private sector and for the Armed Forces. I know that sharing knowledge moves us all forward. If you want to learn, connect, and grow, this is your sign. 🚀 Curious about what a session looks like? Ask me @stansecure Stay secure. 😑 __ Enjoying this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn. #Cybersecurity #Mentorship

I rarely ask for help, but today I must. 30,000 UAH could save real lives. As a military and cybersecurity professional, my w
I rarely ask for help, but today I must. 30,000 UAH could save real lives. As a military and cybersecurity professional, my work is usually about building defense, in the cloud and on the ground. Today, I am reaching out for something even more personal. The 3rd Assault Brigade (3 OShBr 🇺🇦) is in need of our help. → The goal is: 30,000 UAH. → The need is urgent: funds will support ‘Павук Допхіна’ ('Dolphin Spider'), a new multi-purpose platform built by the Brigade’s own engineers. → The impact is real: stronger tech means more lives protected and more missions completed. Supporting these engineers is not just about equipment. It is about empowering the kind of innovation that keeps people safe and gives us a real edge. Want to help? 1️⃣ Contribute here: https://send.monobank.ua/jar/A3Y5u1H5cL 2️⃣ If you can’t give, a simple repost can reach someone who can. From my own experience at the front and in cyber defense, I know every bit counts. I believe in these people, and in our victory. With faith in the #ZSU🫡 Glory to #Ukraine! 🇺🇦 #StandWithUkraine

#CyberMonday PathWiper wiped Ukrainian infrastructure in 2025. Cyber threats are not waiting for us to catch up. The PathWipe
#CyberMonday PathWiper wiped Ukrainian infrastructure in 2025. Cyber threats are not waiting for us to catch up. The PathWiper attack on Ukrainian critical infrastructure is a warning. Malware is now able to hit fast and giving defenders very little time to react. 🔥Top News: 1️⃣ Misconfigured HMIs exposed US water systems — hundreds of control dashboards sat open on the internet, some with NO passwords. 2️⃣ Voice phishing attacks are now targeting cloud systems for data extortion. 3️⃣ A critical Cisco ISE flaw (CVSS 9.9) was patched, but proof-of-concept exploit code is already out there. 4️⃣ Chrome extensions leaked user data by sending info over HTTP and hard-coding secrets. 🫢 Recent Critical & High Severity CVEs → CVE-2021-32030/39780 (Asus Router #PotentialExpoit) → CVE-2024-56145 (Craft CMS #PublicExpoit) → CVE-2025-3935 (ScreenConnect #RemoteAccess) → CVE-2025-21479/21480 (Qualcome #MemoryLeak) → CVE-2025-5419 (Chrome #OutOfBounds) See full CVE lists for the last 7 and 30 days if you want more detail — https://www.cvedetails.com/ Staying proactive is the only way forward. My take: Security is not about fear, it is about staying ready. Simple checks can stop big leaks before they start. Have you checked your extensions lately? 😑 __ Enjoy this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn. #Cybersecurity #DataProtection #ThreatIntel

🧠 5 Blind Spots That Held Me Back as a Security Leader (Until My Mentor Called Me Out) For years, I thought being a strong s
+6
🧠 5 Blind Spots That Held Me Back as a Security Leader (Until My Mentor Called Me Out) For years, I thought being a strong security leader meant fixing every problem. I jumped into tool implementation, led audits, and stayed deep in the technical weeds. I believed doing more was leading more. Then, I asked for honest feedback from the manager I trust. What I heard was not easy, but it changed my path. Here are the 5 blind spots that stalled my growth: 1️⃣ Overinvolvement in Execution I thought being hands-on was the way to lead. But by taking every task myself, I blocked my team from growing. I learned: leadership means empowering others, not doing it all. 2️⃣ Under-communicating Wins & Lessons I believed results would speak for themselves. They don’t. If you do not share your team’s impact and what you learn (even from mistakes), your work stays hidden. Now, I make it a habit to share short updates about impact, not just activity. 3️⃣ Perfect Messaging Over Timely Connection I spent too long trying to say things perfectly. This made me miss moments to connect and build trust. Now, I focus on being real, not perfect. Authentic words build stronger teams. 4️⃣ Defaulting to Technical Depth I thought technical skill was my main tool. But leadership is not about solving every ticket; it is about shaping team culture, budgets, and the big picture. I ask myself: am I leading with my expertise, or with my vision? 5️⃣ Waiting to Feel ‘Ready’ to Share I waited too long to share my journey. I told myself, “I’ll post after something big.” But real growth happens in public, by sharing small wins, struggles, and lessons as they come. Every leader has blind spots. These were mine. Facing them with real feedback helped me become not just a better engineer, but a better leader. What is one leadership blind spot you have seen in yourself or others? How did you work through it? Stay sharp, stay secure. __ Enjoy this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn #Leadership #InfoSec #GrowthMindset

How valuable my weekly #CyberMonday threat and CVE updates?
Anonymous voting

After 2 weeks of #CyberMonday threat intel and CVE updates, I want to hear from YOU. Every Monday, I share the latest threats, key CVEs, and Cybersecurity news to help you stay ahead. My goal? Make your week safer and save you hours of research. But I know every team has different needs. Here’s what I want to know: → Are these weekly updates helping you spot risks faster? → Do you use them to brief your team, patch systems, or guide your strategy? → What would make these updates even more useful for you? Your feedback shapes what I share next. I want #CyberMonday to be your go-to for: 1️⃣ Actionable Threat Intel 2️⃣ Fast CVE Highlights 3️⃣ Simple, clear takeaways you can use right away Help me deliver the best #Cybersecurity content for YOU 🙂

#CyberMonday 5 CVEs jumped 50%+ in exploitability in 7 days. Are you chasing the wrong threats? Another week, another reminde
#CyberMonday 5 CVEs jumped 50%+ in exploitability in 7 days. Are you chasing the wrong threats? Another week, another reminder that cybersecurity never sleeps. Here’s what caught my eye. 🔥Top News: 1️⃣ Linux flaws in Ubuntu, RHEL, Fedora → password hash theft via core dumps. Not flashy, but deadly if missed. 2️⃣ U.S. DoJ took down 4 “crypting service” domains. Attackers keep innovating, law enforcement is catching up. 3️⃣ EDDIESTEALER malware broke Chrome’s latest encryption. Even browser security is a moving target. 4️⃣ China-linked APTs went after SQL Server, expanding attack vectors across Asia and Brazil. 5️⃣ Microsoft OneDrive File Picker bug → possible exposure of whole cloud storage, not just the file you pick. ESSP score check: CVE-2024-9916 went from low risk to 80.49% exploitability — up 79.40 points. That’s a warning to look at. More at cvedetails.com Here’s what I’ve learned: → The “boring” stuff — core dump handlers, file pickers, config basics — gets ignored until attackers show us why it matters. → 80% of cloud breaches start with simple misconfigurations, not zero-days. Remember Capital One’s $1.8M lesson? → Attackers target what we trust most: “invisible” things that hold our systems together. My take: Security leaders who audit the basics win the long game. Fancy tools matter, but discipline around the fundamentals saves millions. Are you focusing on the right risks? Or is your team missing what’s hiding in plain sight? Stay secure out there. 😑 __ Enjoy this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn #Cybersecurity #InfoSec #ThreatIntel

My Path Into Cybersecurity Started With a Choice That Changed Everything. I was top of my Computer Science class at Military
My Path Into Cybersecurity Started With a Choice That Changed Everything. I was top of my Computer Science class at Military Institute of Telecommunications and Information Technologies (MITIT) with multiple career paths ahead of me. Then, I heard about a brand-new cybersecurity unit being formed in 2015. Most classmates chose traditional tech roles. Military Intelligence looked prestigious. Telecommunications seemed stable. But something about defending critical infrastructure from invisible enemies sparked something in me I didn't know existed. 𝙏𝙝𝙚 𝙈𝙤𝙢𝙚𝙣𝙩 𝙀𝙫𝙚𝙧𝙮𝙩𝙝𝙞𝙣𝙜 𝘾𝙡𝙞𝙘𝙠𝙚𝙙 Picture this: 2015, Ukraine. Cyber warfare wasn't theoretical — it was happening in real-time. I walked into that newly formed cybersecurity unit as a fresh graduate with book knowledge. I walked out every day knowing I was part of something bigger than code and algorithms. We weren't just IT professionals. We were digital defenders.🛡 𝗪𝗵𝗮𝘁 𝗡𝗼𝗯𝗼𝗱𝘆 𝗧𝗲𝗹𝗹𝘀 𝗬𝗼𝘂 𝗔𝗯𝗼𝘂𝘁 𝗠𝗶𝗹𝗶𝘁𝗮𝗿𝘆 𝗖𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 Working in AFU's cybersecurity division taught me lessons no classroom ever could: → Stakes are real - When defending critical infrastructure, there's no "test environment." → Teamwork saves lives - Cyber defense isn't solo when national security is on the line. → Adaptability is survival - Threat actors don't follow textbooks. → Purpose fuels performance - Protecting your country changes how you approach problems. 𝗧𝗵𝗲 𝗧𝗲𝗮𝗰𝗵𝗲𝗿𝘀 𝗪𝗵𝗼 𝗖𝗵𝗮𝗻𝗴𝗲𝗱 𝗠𝘆 𝗧𝗿𝗮𝗷𝗲𝗰𝘁𝗼𝗿𝘆 My MITIT teacher who saw potential in cybersecurity before it was mainstream. My AFU manager, who believed in developing talent, not just using it. These people showed me what it means to serve something bigger than yourself. 𝗙𝗿𝗼𝗺 𝗦𝗢𝗖 𝗔𝗻𝗮𝗹𝘆𝘀𝘁 𝘁𝗼 𝗗𝗶𝘃𝗶𝘀𝗶𝗼𝗻 𝗖𝗵𝗶𝗲𝗳 Starting in that unit in 2015, I never imagined I'd grow into SOC Division Chief. Here's what I learned: 1. Technical skills get you in the door 2. Leadership skills keep critical systems protected 3. People skills turn individual defenders into unified teams 4. Strategic thinking transforms reactive responses into proactive defense 𝗧𝗵𝗲 𝗥𝗲𝗮𝗹 𝗦𝗲𝗰𝗿𝗲𝘁 𝘁𝗼 𝗖𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗦𝘂𝗰𝗰𝗲𝘀𝘀 It's not about being the smartest person in the room. It's about caring deeply enough to never stop learning, defending, and improving. 𝗬𝗼𝘂𝗿 𝗧𝘂𝗿𝗻 What moment made cybersecurity "click" for you? Was it: A personal experience? A mentor who opened your eyes? A realization about how much depends on digital security? A desire to serve and protect? Share your story below. Every journey is unique, but they all share one thing: the drive to protect what matters. __ Enjoy this? 🔄 Repost it to your network and follow @securediary for more. Join me on LinkedIn #CyberSecurity #InfoSec #CyberWarfare

An insightful question about AI and LLM security 🤔 𝗤: So, how could organizations defend themselves against AI injections?
An insightful question about AI and LLM security 🤔 𝗤: So, how could organizations defend themselves against AI injections? Or is it more about the developers of LLMs, not the users? 𝗔: Great question — and it’s both, really 🙂 ➡️ LLM providers (Devs) need to harden their models against prompt injection by improving context handling, sandboxing actions, and applying prompt input filters. ➡️ But orgs using LLMs also have responsibilities: → Avoid blindly integrating AI into sensitive workflows (Do the security check first!) → Sanitize and validate user inputs before sending them to the model. → Log and audit AI activity — treat it like any critical system. I see both misconfigurations and poor input handling open the door to attackers. Don’t let your guard down. #CyberSecurity #LLM #AI #DataProtection @securediary

#CyberMonday This Week in Cybersecurity — May 26 Big week for cyber news! Here’s what caught my eye — and what I think matter
#CyberMonday This Week in Cybersecurity — May 26 Big week for cyber news! Here’s what caught my eye — and what I think matters most 👇 1️⃣ Windows Server 2025 dMSA Vulnerability → A new flaw lets attackers gain privilege and compromise any user in Active Directory. → If you run AD, review your delegated Managed Service Accounts. Patch as soon as updates drop! 2️⃣ TikTok Malware via ClickFix → Hackers use TikTok videos to spread Vidar and StealC malware. → The “ClickFix” trick gets people to download malware fast. → Training users to spot these tricks is key. Social media is now a top threat vector. 3️⃣ GitLab Duo AI Prompt Injection → Attackers can hijack AI responses and steal source code using hidden prompts. → AI-powered tools save time, but always check for new risks — especially indirect prompt injection. 4️⃣ Europol Strikes Ransomware Networks → 300 servers and €3.5M seized, 650 domains neutralized, 20 arrest warrants issued. → Law enforcement is stepping up. Global teamwork works! 5️⃣ SafeLine WAF — Open Source Web App Firewall → New open-source WAF with zero-day detection and bot protection. → If you run web apps, try SafeLine for better defense. 🫢 Recent Critical & High Severity CVEs → CVE-2025-4632 (Samsung MagicINFO 9 Server) → CVE-2025-27920 (Output Messenger) → CVE-2025-4428/4427 (Ivanti Endpoint Manager) → CVE-2023-38950 (ZKTeco BioTime) See full CVE lists for the last 7 and 30 days if you want more detail — https://www.cvedetails.com/ My take: Cybersecurity is not slowing down. Every week brings new threats, new tools, and new wins for defenders. Staying informed is part of defense. Keeping teams trained and systems patched is how we win. Want more? Check the links for CVE details and threat feeds. Let’s keep our networks safe — together. 🔒 What’s the most important cyber risk you saw last week? 👇 #CyberSecurity #InfoSec #CloudSecurity #ThreatIntel @securediary

Most companies fear cyberattacks. But misconfigurations are the real silent killer. 🫨 Cloud misconfigurations are everywhere
+8
Most companies fear cyberattacks. But misconfigurations are the real silent killer. 🫨 Cloud misconfigurations are everywhere. They hide in small mistakes, missed settings, or rushed rollouts. Capital One lost $1.8M because of a single overlooked setting. 💰 (No, it was not a fancy hack. It was a tiny checkbox left open.) Here’s what I learned: → 80% of cloud breaches start with simple misconfigurations. → Old security tools miss these gaps. → The biggest risks are often the ones no one sees. Want to know where to look first? Here are the Top 5 cloud misconfigurations I check every time: 1. Publicly open storage buckets (easy target!) 2. Weak access controls (too many people with keys) 3. Missing encryption (data left in plain sight) 4. Default passwords still active (yes, it happens) 5. Unmonitored services (no alerts, no eyes) How do I prevent these? I use a simple playbook: → Review cloud settings often → Set alerts for changes → Limit access to what people need → Remove unused accounts fast → Train teams on what to watch for Cloud security does not need to be hard. But it does need care. One small mistake can cost a lot. Have you seen a cloud misconfiguration at work? How did you fix it? Your story could help save someone else’s data. 👇 #CloudSecurity #CyberSecurity #ThreatFridays @securediary

I've been writing for 7 years, and this post just reminded me why I still struggle. (original author post link) I saw this li
I've been writing for 7 years, and this post just reminded me why I still struggle. (original author post link) I saw this line and had to pause: “The 'write like you talk ' principle completely changed my game. I used to write like I was submitting a college paper – formal, stiff, trying to sound smart. Now I write like I'm texting my best friend about something I'm genuinely excited about. Game changer.” That hit home for me. In my early days, I tried to sound 'clean.' Every sentence felt heavy. Every word had to be perfect. I thought smart writing meant big words and long sentences. But my writing was not fun. Not all people were connected with it. When I learned to write like I talk, things changed💡. My ideas felt more real. People started to reply and share their own stories. I felt like I had found my voice. But I still have one big struggle: 𝙖𝙙𝙫𝙚𝙧𝙗𝙨. I want to cut them, but they sneak in when I am not watching.😅 From this list of 7 writing rules, that’s my weak spot. Curious if anyone else feels the same. Here is one more tip I would add as #8: → Read your work out loud before you share it. You catch the parts that sound wrong, the words that do not flow, and you hear where your voice is missing. (Trust me, it works!) Also, I do not fully agree with the 'never be formal ' rule. Sometimes a little formality helps. It can show respect or match your reader’s style. After 7 years, I am still learning. Writing is always about finding your real voice, but also being open to new ideas. If you're curious, here’s the link to my personal blog I started back in 2018: https://t.me/dreamerdiary 🌱 Which principle changed your writing most? Is there a rule you think does not fit your style? 👇 #WritingTips #Copywriting #Storytelling #PersonalBranding @securediary

What cybersecurity topics would you like to see MORE of here?
Anonymous voting

What best describes your current role or experience in cybersecurity?
Anonymous voting