Adrian Sanabria (@[email protected])

65.1K posts

Adrian Sanabria (@sawaba@infosec.exchange) banner
Adrian Sanabria (@sawaba@infosec.exchange)

Adrian Sanabria (@[email protected])

@sawaba

🏢 The Defenders Initiative, 🎙️ Enterprise @secweekly Podcast, 🤝 Founder @bsidesknoxville, 🗣️ Faculty @IANS_Security, 🍳 Cooking, 🏎️ F1, ⛰️ Hiking

Knoxville, TN Katılım Eylül 2008
2.2K Takip Edilen9.3K Takipçiler
Sabitlenmiş Tweet
Adrian Sanabria (@sawaba@infosec.exchange)
I've been working on a talk tentatively titled "Myths and Lies in InfoSec" Some of the research I'll be referencing in the talk was inspired by one particular stat: "60% of small businesses go out of business within 6 months of a data breach" How do we know a stat is fake? 🧵⏲️
Brett Callow@BrettCallow

Anybody know where this iffy stat came from? I’ve seen it attributed to several organizations, but its actual origin remains murky.

English
12
25
127
0
Adrian Sanabria (@sawaba@infosec.exchange)
@thedawgyg IIRC, it was $20k to find ONE bug, the one that crashed OpenBSD Maybe DoS is valuable to someone, but these bugs are just mostly wasting everyone’s time by forcing software updates for no tangible benefit. But what do I know - maybe Rocket League’s servers run on OpenBSD?
English
0
0
1
45
dawgyg - WoH
dawgyg - WoH@thedawgyg·
They spent $20k finding their bugs, while I spend less than $1000 on my fuzzing setup and found alot of the same bugs (several in their announcements i found and have in my 'to report' docs since they werent exploitable beyond DoS). i havent found 'thousands' but i have found nearly 1000 since December. And the VAST majority that have been found with AI and fuzzing are Null Ptr Derefs. and as mentioned, they are almost never exploitable on modern systems since memory at 0x0000000 cant be mapped to anything anymore. (it cant with like +8/16/32/64 offsets either, i forget what the first usable spot is but its not anywhere near a null ptr deref location). Mythos might be good at finding bugs, but it is not finding things that would set the internet on fire in most instances. im sure they found some nice bugs in their thousands, but most of them would be DoS impact at absolute most.
Ananay@ananayarora

Marcus Hutchins, the guy famous for stopping the WannaCry Ransomware, probably has the best take on Mythos doing vulnerability research

English
27
118
1K
122.1K
Adrian Sanabria (@[email protected]) retweetledi
SquareX
SquareX@getsquarex·
Why does security keep failing despite massive investments in tools and compliance? Adrian Sanabria (@sawaba), Principal Researcher at The Defenders Initiative and Main Host of Enterprise Security Weekly (@secweekly), explores this uncomfortable truth in our latest episode of the Be Fearless Podcast. Adrian discusses with @JohnCarse why checklist-focused security keeps defenders behind, how cyber insurance might force real change, and why AI has become the attacker's number one accomplice in 2025. Hear the conversation: open.spotify.com/episode/5FSLs2… #cybersecurity #browsersecurity #enterprisesecurity
English
0
2
4
256
dtathemes
dtathemes@dtathemes·
@Pebble Wait what? Was my favorite watch till the support for it stopped. I wore my OG pebble till it wouldn’t turn on anymore. Good old days!
English
1
0
7
2.9K
Adrian Sanabria (@[email protected]) retweetledi
SquareX
SquareX@getsquarex·
Why does security keep failing despite massive investments in tools and compliance frameworks? Adrian Sanabria (@sawaba), Principal Researcher at The Defenders Initiative and Main Host of Enterprise Security Weekly (@SecWeekly), explores this uncomfortable truth in our latest episode of the Be Fearless Podcast. Adrian discusses with @JohnCarse why focusing on checklists keeps defenders perpetually behind, how cyber insurance might force real change in security practices, and why AI has become the attacker's number one accomplice in 2025. He also covers prompt injection attacks as the next big problem, using frameworks correctly to guide decisions, and why CISOs must avoid the "hoarding" mindset. Watch now: youtu.be/n79YY-pqwBA #cybersecurity #browsersecurity #enterprisesecurity
YouTube video
YouTube
SquareX tweet media
English
0
2
2
226
Eric Migicovsky
Eric Migicovsky@ericmigi·
Would you pick rivian-blue or orangered?
Eric Migicovsky tweet mediaEric Migicovsky tweet media
English
82
13
318
11.9K
Adrian Sanabria (@sawaba@infosec.exchange)
@brysonbort All sizes nest and they all use the same size lid. Freeze & microwave in them, and they’re cheap enough that you can send someone home with leftovers and they don’t need to return the container.
English
0
0
1
38
Bryson 🦄
Bryson 🦄@brysonbort·
Y'all always complaining Cyber is hard. Have you organized Tupperware?
Bryson 🦄 tweet media
English
9
1
33
1.8K