Robert Pritchard

15.8K posts

Robert Pritchard banner
Robert Pritchard

Robert Pritchard

@TheCyberSecExp

Cyber security nerd. Former UK gov cyber security. Security consultant & capacity builder. RUSI Associate Fellow. Creator of Soothsayer

Beigetreten Ekim 2013
3K Folgt2.7K Follower
Robert Pritchard retweetet
Zack Korman
Zack Korman@ZackKorman·
NVIDIA Nemoclaw's security is worse than I expected. The AI can modify its own config to bypass security controls. I asked it to accept websocket connections from any origin and change its token to something trivial (123). Now any site I visit can give instructions to my bot.
Zack Korman tweet media
English
56
79
593
57.9K
Shashank Joshi
Shashank Joshi@shashj·
When I joined The Economist almost eight years ago, I submitted a sample article. It was on Strava revealing the location of US special forces bases and other sensitive sites. Every since then there has been at least one of these incidents each year. x.com/shashj/status/…
Shashank Joshi@shashj

'France says it’s taking “appropriate measures” after a naval officer’s use of the Strava exercise app inadvertently enabled journalists to geolocate the aircraft carrier Charles de Gaulle' washingtonpost.com/world/2026/03/…

English
5
30
283
18.4K
Shashank Joshi
Shashank Joshi@shashj·
'France says it’s taking “appropriate measures” after a naval officer’s use of the Strava exercise app inadvertently enabled journalists to geolocate the aircraft carrier Charles de Gaulle' washingtonpost.com/world/2026/03/…
English
24
61
427
82.7K
Robert Pritchard retweetet
MikeTalonNYC
MikeTalonNYC@MikeTalonNYC·
Heads up, DownDetector is reporting CloudFlare is barfing hard right now. Expect outages and other issues across most of the damn Internet for a while.
English
0
3
4
111
Zack Korman
Zack Korman@ZackKorman·
If you believe this you have zero clue how security works.
Zack Korman tweet media
English
84
55
747
24.7K
Robert Pritchard
Robert Pritchard@TheCyberSecExp·
@UK_Daniel_Card To painful to make it through all the six minutes. I am quite worried about these mega agents though
English
1
0
4
452
Robert Pritchard
Robert Pritchard@TheCyberSecExp·
@ZackKorman My feeling (and hence advice) on this was a) make sure you stay within the law (ie have done gdpr due diligence) and b) how forward leaning are you compared to your competitors, and hence how bad is it the AI provider gets pwned or misuses the data?
English
1
0
1
86
Zack Korman
Zack Korman@ZackKorman·
Of all the AI security risks, vendors training on your data is one of the least scary. It’s just the one CISOs focus on most because it’s the easiest to understand and solve.
English
13
7
89
6K
Robert Pritchard
Robert Pritchard@TheCyberSecExp·
@ZackKorman I think you even overstate it! 'There's a file on my machine which contains text which asks it not to do anything bad'
English
1
0
3
95
Zack Korman
Zack Korman@ZackKorman·
“I gave an AI agent the ability to read and write to any file on my machine, but don’t worry, there’s a file on my machine that stops it from doing anything bad.” Half of AI agent security is simply internalizing how dumb that is.
English
17
14
162
5.8K
Robert Pritchard
Robert Pritchard@TheCyberSecExp·
@GazTheJourno Send one over and I’ll take a look. Forward it as an attachment (you click the three little dots I think - can check when at my desk). Will pm email
English
0
0
0
37
Gareth Corfield
Gareth Corfield@GazTheJourno·
Infosec bods, help! My inbox is filling up with semi-targeted crud that feels very much like a threat actor. Hallmarks: Emails that look like press releases. Sender names that are always a female name and initial, e.g. Dani K URLs that are always three words... 1/x 🧵
English
2
0
0
992
Robert Pritchard
Robert Pritchard@TheCyberSecExp·
@AlexMartin Having read the story now it feels like a questionable prosecution given his mental state.
English
1
0
0
416
Alex Martin
Alex Martin@AlexMartin·
Chap's given himself an awfully unfortunate job title on LinkedIn.
Alex Martin tweet mediaAlex Martin tweet media
English
1
7
27
7.3K
Robert Pritchard
Robert Pritchard@TheCyberSecExp·
@IceSolst @georgiaweidman I know of one incidence where it worked and the target went out and bought the apple vouchers or whatever they were.
English
0
0
1
14
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
@georgiaweidman There’s a super common scam where they pose as the CEO (scraped from LinkedIn) and reach out to folks “hey do you have a minute”, and for the vast majority of people, this is a psa, since they don’t typically interact
English
2
0
5
281
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
Your CEO is NOT reaching out to your goofy ass on WhatsApp/text/email, it’s a scam, and they keep doing it because it works
English
36
15
289
14.6K
alicia 👩🏻‍💻
alicia 👩🏻‍💻@lishadawn·
@TheCyberSecExp @sweetdelightss Yeah, I think you’re right. I think most of us care too much. I need to find the balance between beating myself up and realizing that cybersecurity is a field where mistakes are going to happen. But ugh, they suck
English
1
0
2
34
Stacey✨
Stacey✨@sweetdelightss·
The most painful part of security is getting something wrong and still having the wherewithal to get over your embarrassment and learn from it and still deliver. I swear some people don’t seem to have this issue and recover instantaneously. …weirdos
English
5
0
43
3.7K
Robert Pritchard
Robert Pritchard@TheCyberSecExp·
@lishadawn @sweetdelightss I think the number of people who really just let stuff roll off is fairly small (I hope anyway!). But you need to find a way not to beat yourself up constantly. For me I tell myself there’s literally nothing to be done other than making sure I don’t do whatever it was again.
English
1
0
2
55
alicia 👩🏻‍💻
alicia 👩🏻‍💻@lishadawn·
@sweetdelightss I had a miss about a month ago that I’m still feeling like shit about. I don’t know how people just let it roll off them. I wish I could
English
1
0
2
42
Robert Pritchard
Robert Pritchard@TheCyberSecExp·
@sweetdelightss It’s not easy but all you can do is learn from it and promise yourself you won’t make that mistake again.
English
0
0
1
27
Robert Pritchard
Robert Pritchard@TheCyberSecExp·
@ZackKorman @IceSolst Compliance has become a thing for its own sake, with divergent goals from actually being secure. No one accepts any of the 'standards' but you still have to have one of them anyway, and then as Zac says you get more questions anyway which achieve equally nothing
English
1
0
3
32
Zack Korman
Zack Korman@ZackKorman·
@IceSolst This is the core problem. People say SOC2 or ISO27001 mean nothing and then try to run their own mini audit that…. Is SOC2 or ISO27001 but worse. These standards are bad because the problem of verifying security is difficult. So “roll your own vendor review” isn’t solving it
English
10
0
48
1.5K
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
SOC2 is a massive waste of time. Theater, a self-assessment of your own policies. If you hand me a SOC2 report, it means nothing to me. So companies get around by sending you their own 200-line questionnaire… making it an even bigger waste of time. Kill all auditing.
English
65
18
331
18.7K
Robert Pritchard
Robert Pritchard@TheCyberSecExp·
@ZackKorman @techspence @dasgrog I've been trying to be a bit more present on there because I think it is useful, but I do agree. You can just say anything and people will cheer you on.
English
0
0
2
15
Zack Korman
Zack Korman@ZackKorman·
@techspence @dasgrog I genuinely mean it, the quality of posts on LinkedIn is so bad. And even if you call it out it doesn’t matter. People just keep on liking the trash
English
4
0
12
255
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
8
11
193
3.3K
Robert Pritchard retweetet
Darth Putin
Darth Putin@DarthPutinKGB·
OTD in 2015 Boris Nemtsov shot himself in the back 4 times by the CIA a few hundred yards from the Kremlin. In unrelated events, he had just written a detailed report about how Russia had invaded Ukraine & said we would make them enemies forever...
English
10
279
1.6K
23.1K