Brett Winterford

8.5K posts

Brett Winterford banner
Brett Winterford

Brett Winterford

@breditor

InfoSec, tweeting and tooting when time allows. Dipping toes in mastodon at [email protected] - Founding (former) editor of SRSLY RISKY BIZ newsletter.

Perth, Western Australia Присоединился Şubat 2009
3.5K Подписки5.3K Подписчики
Brett Winterford ретвитнул
Bad Packets by Okta
Bad Packets by Okta@bad_packets·
Anyone reusing credentials on their Fortinet device? Asking for a friend on AS17511 (219.75.254[.]166) who keeps failing to get their password right.
English
1
5
6
2.1K
Brett Winterford ретвитнул
Bad Packets by Okta
Bad Packets by Okta@bad_packets·
We analyzed over 300,000 rows of the January 2026 BreachForums database leak to find their users' anonymizers of choice. Join us in the cantina. 🧵
Bad Packets by Okta tweet media
English
1
6
7
2.9K
Brett Winterford ретвитнул
Todd McKinnon
Todd McKinnon@toddmckinnon·
I recently joined @reckless on @DecoderPod to discuss the “SaaSpocalypse,” the future of software, and why the identity layer for AI agents could become the biggest category in cyber. Really enjoyed this conversation: bit.ly/481Tema
English
1
1
6
484
Brett Winterford ретвитнул
Bad Packets by Okta
Bad Packets by Okta@bad_packets·
A browser extension promised security. In reality, it was a Trojan horse for your crypto. We tracked the extension, mapped the infrastructure and pulled the plug. Full breakdown of the takedown: bit.ly/40E9i9N
English
0
4
4
1.2K
Brett Winterford ретвитнул
Bad Packets by Okta
Bad Packets by Okta@bad_packets·
Your star hire might be a DPRK agent. 🇰🇵 @Okta reveals how state actors use stolen LinkedIn IDs, AI-generated faces, and forged git commits to bypass HR. Verify identities before they're on your payroll! #opentowork bit.ly/4quh8go
Bad Packets by Okta tweet media
English
0
3
8
1.7K
Brett Winterford ретвитнул
Bad Packets by Okta
Bad Packets by Okta@bad_packets·
Google disrupted IPIDEA, a major residential proxy network. Our data confirms a sharp drop in their active IPs following the action. 📉 Protect your Okta org today: block IPIDEA and residential proxies with dynamic network zones bit.ly/3OiZVJz
Bad Packets by Okta tweet media
English
0
6
28
13.5K
Brett Winterford ретвитнул
Bad Packets by Okta
Bad Packets by Okta@bad_packets·
Still tracking the bad packets, now powered by Okta log data! Top ASNs used in recent signup fraud attacks: • 212238 • 16276 • 44477 • 26548 • 200373 • 137409 • 214483 • 13213 • 397368
English
1
4
11
5.4K
Brett Winterford ретвитнул
Todd McKinnon
Todd McKinnon@toddmckinnon·
Cross App Access (XAA) is now the #MCP authorization extension: ‘Enterprise-Managed Authorization’. Proud @okta played a role in establishing this new protocol to secure AI. bit.ly/3Knjzm8
Todd McKinnon tweet media
English
1
2
8
1.4K
Brett Winterford ретвитнул
The Daily Show
The Daily Show@TheDailyShow·
Troy Iwata got hired for Trump's cabinet, but @jordanklepper wasn't?
English
12
175
988
149.1K
Brett Winterford ретвитнул
myGov
myGov@myGovau·
We’ve introduced passkeys as a simple and secure option for people to sign in to their myGov account. Your account will be most secure when you create a passkey and turn off your password as a sign in option. To find out more watch this video, or visit: my.gov.au/passkeys
English
7
4
13
5.3K
Brett Winterford ретвитнул
Okta
Okta@okta·
Check out our very own CPO, @clcsampaio, being interviewed on @riskybusiness about Identity and Fine Grained Authorization! 🎧 Listen to the full episode here: bit.ly/4bQezhQ
Okta tweet media
English
0
3
1
2.6K
Brett Winterford ретвитнул
Molly White
Molly White@molly0xFFF·
back in my day we called this spyware
Molly White tweet media
English
140
4.4K
20.2K
1.3M
Troy Braban
Troy Braban@hargobt·
I honestly don’t think we will ever see anything like this in our lifetime #damnlucky #messi
English
1
0
1
184
Brett Winterford
Brett Winterford@breditor·
@darrenpauli Unless you’re applying for a rental property. And they want EVERYTHING
English
1
0
1
28
darren
darren@darrenpauli·
You can't tell if security is great or awful at a given org, but you can often control what data you give them. Think if they really need your date of birth. It wouldn't help with Outabox, but many times it does. Let it be your fake alias that's spilled over the net in a breach.
English
1
0
0
147
darren
darren@darrenpauli·
Privacy Awareness Week next week has a bitter irony for consumers: your best efforts mean little when multiple orgs store your private info in systems that lack strict access controls, logging, deletion, and encryption. This failure is widespread. abc.net.au/news/2024-05-0…
English
1
1
3
322