Feng Xue

110 posts

Feng Xue

Feng Xue

@s0what

Founder of ThreatBook(CTI provider). ex Microsoft TwC, ex Amazon InfoSec.

Beijing,China Katılım Mart 2009
2.9K Takip Edilen1.4K Takipçiler
Feng Xue
Feng Xue@s0what·
+1
Howie Xu@H0wie_Xu

The hiring game has fundamentally changed, and most people haven't noticed. I've been thinking about what companies are really looking for in 2026. Everyone talks about AI skills, programming abilities, or technical expertise. But after observing multiple hiring cycles, I see a different pattern emerging. We're not just hiring specialists anymore. We're hiring mini-CEOs or founders for literally any position. The qualities we used to demand only from startup founders - self-drive, resilience, communication skills - are now table stakes for every role. Product managers, engineers, designers, marketers. Everyone needs founder-level qualities. This isn't theoretical. My own hiring criteria has shifted completely. When I work with recruiters, my first requirement is simple: "Show me candidates who have already founded a company." It doesn't matter what position I'm filling. I want to see entrepreneurial experience on that resume. Recently, I heard Ramp's CEO say exactly the same thing. He's specifically looking for people with founder backgrounds, regardless of the role they're hiring for. Rippling has 150 former YC founder types working in the company. Why is this happening? In an AI-accelerated world, technical skills become commoditized faster than ever. What can't be replicated is the founder mindset - the ability to own problems end-to-end, push through obstacles, and communicate vision clearly. Ten or twenty years ago, we only expected this from startup founders. Today, we need it from everyone. The implication is profound: we're not hiring employees anymore. We're assembling teams of internal entrepreneurs who can operate with founder-level autonomy and accountability. If you're job hunting, stop optimizing your technical resume. Start building evidence of entrepreneurial thinking and execution. The companies that embrace this hiring philosophy first will build unbeatable teams. #Hiring #Entrepreneurship #AI #Leadership #FutureOfWork #StartupMindset #TechCareers #Innovation #Management #TalentStrategy

QST
0
0
0
37
Feng Xue
Feng Xue@s0what·
Tencent researchers found a RCE vulnerability of Hermes agent, what’s more interesting is that they found the agent defended itself after few exploitation tries. Inspired by this accidental emergence, the team built something deliberate: an adaptive immune system for AI agents— in just a few dozen lines of code. For more details, read their post: mp-weixin-qq-com.translate.goog/s/R8r4WSi1eEh0…
English
0
0
3
106
Feng Xue
Feng Xue@s0what·
We actually found the Lazarus breach on a MacBook before realizing that there’s a Axios poisoning
ThreatBook@ThreatBookLabs

#Lazarus is behind the Axios npm supply chain attack. ThreatBook's analysis links the macOS payload to WAVESHAPER — a Lazarus backdoor disclosed by Mandiant in Feb 2026. Full attribution report + new IOCs → na2.hubs.ly/H04BWXP0

English
0
0
0
296
Feng Xue
Feng Xue@s0what·
@ZackKorman For AI agent security, seems it' still vague and there a lot of overlapping concept and solutions such as GuardRails, LLM Firewall, Agent Firewall, etc.
English
0
0
2
51
Zack Korman
Zack Korman@ZackKorman·
Thanks for all the responses. It turns out that my view of cybersecurity’s future is unpopular. But here it is: - New doesn’t replace old. All the stuff that exists keeps existing. BUT it will be effectively “legacy”. Everything below is about the new. - AI detection everywhere. Audit logs, endpoint, appsec, etc. We embrace non-deterministic vibe hunting. - The whole “use stupid rules to trigger alerts that we then hand to humans” flow (SOC) disappears because that was built for a world where intelligence was expensive. - Detection, investigation, and response become one thing. - AI agent security will be super hot and attract a lot of people not in cyber today (engineering and IT). - Attacks are way less homogenous, and orgs experience way higher volume of sophisticated and targeted attacks. - GRC keeps being GRC. - A lot of existing CISOs won’t make it. Most new CISOs won’t come from traditional cyber roles.
Zack Korman@ZackKorman

What’s cybersecurity going to look like five years from now? I know that’s a hard question, but I’ve been thinking about it a lot lately. Would be good to hear what others think. What roles won’t exist? What product categories disappear? What tech will be obsolete?

English
47
22
237
54.1K
Feng Xue retweetledi
ThreatBook
ThreatBook@ThreatBookLabs·
Threat Alert: #CharmingKitten: New C2 Hostname on Known Asset. IP: 185[.]132[.]176[.]27 New C2 Hostname: videozoom[.]ddns[.]net ThreatBook Intelligence: na2.hubs.ly/H01lHm90
ThreatBook tweet mediaThreatBook tweet media
English
1
7
16
2.3K
Feng Xue retweetledi
ThreatBook
ThreatBook@ThreatBookLabs·
Threat Alert: #donot — Info TLD Domains Registered for C2 Abuse. Newly registered .info domains likely reserved for C2/backdoor control. Domains: uptonox[.]info gilbertfix[.]info uptofixbi[.]info keeznoted[.]info servzkeeps[.]info ThreatBook Intelligence: na2.hubs.ly/H01lK1N0
ThreatBook tweet media
English
0
7
13
1.7K
Feng Xue retweetledi
ThreatBook
ThreatBook@ThreatBookLabs·
Threat Alert: #SideCopy: New Malware Sample Observed. Sample uses a typosquatted C2 Hash: 5d5ae0671130f0b8232e4e426d88fb4fa42f50e86b7a016a92b89c4181528ad3 C2 Domain: windowsdns[.]com ThreatBook Intelligence: na2.hubs.ly/H01lDPx0
ThreatBook tweet mediaThreatBook tweet media
English
0
4
12
2.8K
Feng Xue retweetledi
ThreatBook
ThreatBook@ThreatBookLabs·
🚀 We’re excited to announce the launch of ThreatBook ATI! With ThreatBook ATI, defenders gain tailored threat landscapes that connect adversary profiles, technical indicators, and real-world activity, helping SOC teams focus on what matters most. na2.hubs.ly/H01kvWN0
English
0
1
1
530
Feng Xue retweetledi
ThreatBook
ThreatBook@ThreatBookLabs·
What if you could build a customized threat landscape report in minutes? With ThreatBook ATI, you can. Here’s how: na2.hubs.ly/H01jSLY0
English
0
1
3
397
SecInterviewHub
SecInterviewHub@sec_hub93028·
VirusTotal shuts down. What are you using to triage and analyze suspicious files or URLs?
English
86
94
1.2K
122.2K
Feng Xue retweetledi
ThreatBook
ThreatBook@ThreatBookLabs·
We’re thrilled to be included in the 2025 Gartner® Magic Quadrant™ for Network Detection and Response (NDR)! ThreatBook’s edge? A global perspective on cyber threats, actionable context from deep research, and a platform designed to spot what others miss. Speak with us today!
ThreatBook tweet media
English
0
1
2
487