Jacob Krell

3K posts

Jacob Krell banner
Jacob Krell

Jacob Krell

@hackerfren

Cybersec/AI expert | Hacker | Pilot | Lifter | OSCE3, CISSP, CCNP, CSIE | Top 20 Hack the Box | CTF Reviews and Writeups | meme magic 🐸

NC, United States Katılım Eylül 2023
730 Takip Edilen2.4K Takipçiler
Sabitlenmiş Tweet
Jacob Krell
Jacob Krell@hackerfren·
I Broke top 20 globally on Hack the Box, just in time for them to change the ranking system it seems. The new ranking system seems to include retired machines as well, and since I'm approaching 400 ( the most of anyone in the top 20) I'm guessing I'm pretty close to the top ranked in the new system as well.
Jacob Krell tweet media
English
3
0
36
1.6K
Jacob Krell
Jacob Krell@hackerfren·
I'm excited to be speaking tomorrow at @CybrSecCon convention in Plano TX, CYBR.HAK.CON, about how Agentic AI has impacted CTFs and competitive hacking!
Jacob Krell tweet media
English
0
0
3
61
Jacob Krell
Jacob Krell@hackerfren·
@rekdt The average exploit timeline is negative 7 days. On average patching isn’t even helping based on real world IR data….. The issue is the dwell times. We need ai threat hunting……
English
0
0
1
25
rekdt
rekdt@rekdt·
It’s really funny watching companies learn things like patching at high velocity isn’t a cybersecurity silver bullet The state of cybersecurity is so bad in tech today, they’re recreating defense in depth from first principles
Cloudflare@Cloudflare

Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. cfl.re/49BRUqW

English
15
43
369
43.3K
vx-underground
vx-underground@vxunderground·
GitHub, a company owned by Microsoft, was compromised. A GitHub employee browsing the VS Code marketplace, an asset owned and operated by Microsoft, inadvertently donated a malicious VS Code extension, which Microsoft offers guidance and best practices on to avoid
vx-underground tweet media
GitHub@github

1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.

English
59
452
4.8K
366K
Jacob Krell
Jacob Krell@hackerfren·
@yacineMTB The hard part is selling. With ai dev, bro, you can make an entire enterprise product in like a week if you know what your making.
English
0
0
0
88
kache
kache@yacineMTB·
your job as a researcher, developer is to help your salesperson sell things. build something that is easy to sell. build something that people actually need
thoughtlesslabs@thoughtlesslabs

@yacineMTB Absolutely. Having marketed bad products and good products, it is insane how much easier it is to market good products because they deliver on the promises you get to make.

English
18
24
454
24.1K
Jacob Krell
Jacob Krell@hackerfren·
@HackingLZ Who needs to evade detection when you are just hijacking the supply chain
English
0
0
0
33
Jacob Krell
Jacob Krell@hackerfren·
@UK_Daniel_Card Nice! St. Peter’s is unreal. Awesome in the truest sense of the word in my experience.
English
0
0
1
50
mRr3b00t
mRr3b00t@UK_Daniel_Card·
Off on another adventure again today! ❤️🇮🇹
mRr3b00t tweet mediamRr3b00t tweet mediamRr3b00t tweet media
English
4
1
53
1.3K
Jacob Krell
Jacob Krell@hackerfren·
I was quoted in Forbes, that's pretty cool! Microsoft does not seem to be having a good 2026 so far security wise, with Exchange being the most recent issue in the crosshairs: ...“attackers study mitigation guidance the same way defenders do,” meaning that such vulnerabilities can be turned into working exploits “much faster than most organizations can validate exposure.”'... forbes.com/sites/daveywin…
English
1
1
4
206
Justin Elze
Justin Elze@HackingLZ·
Here is your Mythos InfoSec strategy.
Justin Elze tweet mediaJustin Elze tweet mediaJustin Elze tweet mediaJustin Elze tweet media
English
10
17
153
11.1K
Jacob Krell
Jacob Krell@hackerfren·
Threat actors are security researchers in charge of revenue
GIF
English
0
0
4
226
Timothy McKenzie
Timothy McKenzie@timboloman·
I get that part, and I understand the volume (average) has shifted considerably. But, the term zero-day has always meant that the exploitation occurred before a patch was available. We don’t need negative day, as we already have an industry accepted term for the behavior. The current issue is not the behavior (zero days, as we have had those forever), but rather the issue is that the volume of zero-days has increased. The term negative day does not articulate well that the volume of zero days is increasing.
English
1
0
1
16
Suzu Labs
Suzu Labs@SuzuLabs·
We said it first. Now Mandiant just confirmed it. 👉 Mean Time to Exploit is now negative. Not shortened. Not faster. Negative. Attackers are exploiting vulnerabilities before organizations can even respond. That changes everything. This isn’t about patching faster or scanning more. It’s a timing problem, and most security strategies are already behind. At Suzu Labs, we’re seeing the same thing Jacob Krell just outlined in our latest research: 👉 If you’re reacting, you’re too late 👉 If you’re waiting for alerts, you’ve already missed it 👉 If you’re relying on point-in-time testing, you’re exposed The only way forward? Simulate attacks before attackers do. Continuously validate what actually breaks. Because in a world of negative exploit timelines… you don’t get a head start anymore. 📖 Read the full breakdown: na2.hubs.ly/H05hMNP0 🔗 See how we help teams stay ahead: na2.hubs.ly/H05hNvb0
Suzu Labs tweet media
English
2
3
46
1.3M
kache
kache@yacineMTB·
build robots
kache tweet media
English
12
8
184
6.5K
Jacob Krell
Jacob Krell@hackerfren·
@sec_hub93028 heres hoping that this isnt over the line and I get the FBI showing up at my home someday for making and publishing this. Im gonna need to disclaimer the heck out of it when I push it live hahaha
English
0
0
1
137