Justin Elze

61.3K posts

Justin Elze banner
Justin Elze

Justin Elze

@HackingLZ

CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars

/tmp/.a 参加日 Nisan 2008
4.6K フォロー中68.8K フォロワー
Justin Elze がリツイート
Chris Bakke
Chris Bakke@ChrisJBakke·
One of my weird, silly little hobbies is that I absolutely love testifying before grand juries in fraud trials. That’s why I try to invest early in as many Forbes 30 Under 30 founders as I can.
English
6
5
162
8.2K
Justin Elze
Justin Elze@HackingLZ·
@IceSolst Ironically the landscape has slightly improved at major cloud providers because CISOs were leaning on them 😂
English
0
0
1
66
Justin Elze がリツイート
Alek Asaduryan
Alek Asaduryan@Ldnbox·
SaaS founder realizes they may have accidentally built the backbone for a drug trafficking operation. 😜
Alek Asaduryan tweet media
English
92
102
4.6K
523K
Justin Elze がリツイート
watchTowr
watchTowr@watchtowrcyber·
speak next week friends
watchTowr tweet media
English
1
4
21
1.3K
Justin Elze がリツイート
National Security Division, U.S. Dept of Justice
Three Charged with Conspiring to Unlawfully Divert Cutting Edge U.S. Artificial Intelligence Technology to China “The indictment unsealed today details alleged efforts to evade U.S. export laws through false documents, staged dummy servers to mislead inspectors, and convoluted transshipment schemes, in order to obfuscate the true destination of restricted AI technology—China,” said John A. Eisenberg, Assistant Attorney General for National Security. “These chips are the product of American ingenuity, and NSD will continue to enforce our export-control laws to protect that advantage.” 🔗: justice.gov/opa/pr/three-c…
National Security Division, U.S. Dept of Justice tweet media
English
183
1K
3.3K
2.5M
Justin Elze
Justin Elze@HackingLZ·
Wild 🤯
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
2
0
15
3.4K
Justin Elze がリツイート
erin griffith
erin griffith@eringriffith·
A detailed and brutal look at the tactics of buzzy AI compliance startup Delve "Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite." substack.com/home/post/p-19…
English
97
93
1.4K
1.2M
Joe Rozner
Joe Rozner@jrozner·
@HackingLZ I was having it reverse something for me recently. It got surprisingly far fairly quickly and then basically got stuck for 2 days burning tokens. Gonna work on giving it some better tools and skills and see if that helps when I give it another shot
English
1
0
0
28
Justin Elze
Justin Elze@HackingLZ·
"Research-grade hard" Thanks Opus
Justin Elze tweet media
English
2
0
29
1.9K
Justin Elze
Justin Elze@HackingLZ·
@jrozner I need to check on it the whole thing was more just letting Claude grind on it and see what happens.
English
1
0
0
22
Justin Elze がリツイート
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
Last year in Feb I was playing around with some hardware. I got this tp-link AC1200 which was the most purchased router at the time IIRC. I was cleaning up my place and I wanted to dust off and complete my old research before throwing it out. Pre-auth RCE, latest firmware 👀
b33f | 🇺🇦✊ tweet mediab33f | 🇺🇦✊ tweet media
English
3
2
56
4.3K
Justin Elze
Justin Elze@HackingLZ·
@da5ch0 I mainly care from the perspective of industry agreed upon terms randomly get shaken up by marketing people for no reason which makes client sales calls confusing.
English
1
0
3
107
Justin Elze
Justin Elze@HackingLZ·
Prior to the recent “pentest agent” wave on GitHub, app testing hadn’t really been framed as “pentesting” in a long time.
English
2
3
25
1.9K
Jarrod
Jarrod@Jr0dR87·
If you use a mic for YouTube or streaming, what brands or mic do you recommend?
English
12
0
10
777
Justin Elze
Justin Elze@HackingLZ·
Spam emails generated by programs already exceed human written emails
R A W S A L E R T S@rawsalerts

🚨#BREAKING: According to Tech Sciencest they report that AI bot traffic is projected to surpass human internet traffic by 2027

English
2
4
24
2.3K