Dave Kennedy

55K posts

Dave Kennedy banner
Dave Kennedy

Dave Kennedy

@HackingDave

Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhLyP. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.

Fairlawn, OH شامل ہوئے Temmuz 2009
6.1K فالونگ228.2K فالوورز
Dave Kennedy ری ٹویٹ کیا
Binary Defense
Binary Defense@Binary_Defense·
If your team has to “figure it out,” you’re already behind. NightBeaconAI removes the guesswork. It analyzes events, files, and emails in real time and tells you exactly what you’re looking at and what to do next. Clear answers. Backed by evidence. Humans still in control. Learn more about NightBeaconAI: binarydefense.com/resources/data…
Binary Defense tweet media
English
0
1
4
490
Dave Kennedy ری ٹویٹ کیا
TrustedSec
TrustedSec@TrustedSec·
AI is reshaping vulnerability research and exploit development, but what does that look like in practice? Tune in next week to the #SecurityNoise podcast as @Bandrel and @freefirex2 break down how #AI is changing the #CVE discovery process. Subscribe so you don't miss it!
TrustedSec tweet media
English
0
5
5
1K
Dave Kennedy
Dave Kennedy@HackingDave·
Happy to announce that I took a board position (thanks @edskoudis) to SANS Technology Institute (college degree programs). I'm truly excited here as it fits right in to my passion of helping the next generation of cybersecurity folks get into the industry. Amazing mission reaching our youth, and impacting the next generation of hackers. I'm also on the board of Paradigm Cyber Ventures which focuses on K-12 cybersecurity hands-on courses in the high school level and we sponsor and fund many high school cybersecurity programs. Make the world a better place. sans.edu/about/governan…
English
23
15
235
5.1K
Dave Kennedy
Dave Kennedy@HackingDave·
Car rides with my wife are such polar differences on temperature lol. Her side 78 with heat blaring, my side 62. Its like a wall of heat and cold battling each other in the car 😂
English
11
0
52
3.3K
Dave Kennedy ری ٹویٹ کیا
edskoudis
edskoudis@edskoudis·
@HackingDave We are so excited to have you on the sans.edu Board of Directors. Your input will be invaluable, my friend. So much exciting work to do for the community and our students!
edskoudis tweet media
English
2
4
22
860
Dave Kennedy
Dave Kennedy@HackingDave·
I couldn't make a military simulation with my airsoft buddies (daughters volleyball tournament) so one of my friends Ryan built this so I didn't have to miss it 🤣🤣🤣🤣
Dave Kennedy tweet media
English
14
1
61
2.5K
Dave Kennedy ری ٹویٹ کیا
can
can@marmaduke091·
🚨 100M TOKEN CONTEXT WITHOUT COLLAPSE > <9% degradation from 16K → 100M > beats RAG + rerank + SOTA pipelines > runs on just 2×A800 GPUs we could be back
can tweet media
艾略特@elliotchen100

论文来了。名字叫 MSA,Memory Sparse Attention。 一句话说清楚它是什么: 让大模型原生拥有超长记忆。不是外挂检索,不是暴力扩窗口,而是把「记忆」直接长进了注意力机制里,端到端训练。 过去的方案为什么不行? RAG 的本质是「开卷考试」。模型自己不记东西,全靠现场翻笔记。翻得准不准要看检索质量,翻得快不快要看数据量。一旦信息分散在几十份文档里、需要跨文档推理,就抓瞎了。 线性注意力和 KV 缓存的本质是「压缩记忆」。记是记了,但越压越糊,长了就丢。 MSA 的思路完全不同: → 不压缩,不外挂,而是让模型学会「挑重点看」 核心是一种可扩展的稀疏注意力架构,复杂度是线性的。记忆量翻 10 倍,计算成本不会指数爆炸。 → 模型知道「这段记忆来自哪、什么时候的」 用了一种叫 document-wise RoPE 的位置编码,让模型天然理解文档边界和时间顺序。 → 碎片化的信息也能串起来推理 Memory Interleaving 机制,让模型能在散落各处的记忆片段之间做多跳推理。不是只找到一条相关记录,而是把线索串成链。 结果呢? · 从 16K 扩到 1 亿 token,精度衰减不到 9% · 4B 参数的 MSA 模型,在长上下文 benchmark 上打赢 235B 级别的顶级 RAG 系统 · 2 张 A800 就能跑 1 亿 token 推理。这不是实验室专属,这是创业公司买得起的成本。 说白了,以前的大模型是一个极度聪明但只有金鱼记忆的天才。MSA 想做的事情是,让它真正「记住」。 我们放 github 上了,算法的同学不容易,可以点颗星星支持一下。🌟👀🙏 github.com/EverMind-AI/MSA

English
34
112
1.6K
182.1K
Dave Kennedy ری ٹویٹ کیا
Epic Clip Vault
Epic Clip Vault@EpicClipVault·
This is the kind of wealth people should aim for in life.
English
87
729
9.7K
1M
Dave Kennedy ری ٹویٹ کیا
Ryan
Ryan@ohryansbelt·
Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor
Ryan tweet media
erin griffith@eringriffith

A detailed and brutal look at the tactics of buzzy AI compliance startup Delve "Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite." substack.com/home/post/p-19…

English
336
597
7K
4.3M
Dave Kennedy
Dave Kennedy@HackingDave·
@DeanLo66 Erin has a heated bed so I can actually survive with cool bedrooms 😂 usually at 68-70
English
1
0
1
22
Grumpy Focker
Grumpy Focker@DeanLo66·
@HackingDave And what do you have the thermostats set at. 😂🤣😂🤣😂🤣
English
1
0
1
34
Timon S.
Timon S.@Timon_j_s·
@Binary_Defense Real shame this isn't offered as a product separately from the MDR service
English
1
0
0
34
Binary Defense
Binary Defense@Binary_Defense·
Yesterday we made NightBeacon official. This isn’t another AI announcement. It’s a new way to operate a modern SOC. Security teams today see an abundance of alerts while adversaries move faster than ever. NightBeacon was built to change that. It accelerates analysis, cuts through noise, and helps analysts move from investigation to decision faster than ever before. But the most important part? This isn’t AI replacing analysts. It’s AI amplifying them. NightBeacon learns from the people who defend our customers every day. Every investigation, every escalation, every decision makes the platform smarter. This is what happens when AI speed meets human expertise. The future of MDR just got a lot faster. binarydefense.com/nightbeacon
English
1
6
15
1.6K
Dave Kennedy ری ٹویٹ کیا
BSidesCharm
BSidesCharm@BSidesCharm·
We would like to send out a big THANK YOU to a NEW sponsor - @Binary_Defense - #BSidesCharm 2026 Gold sponsor!
BSidesCharm tweet media
English
0
2
6
1.3K
Dave Kennedy ری ٹویٹ کیا
Cyber Security News
Cyber Security News@The_Cyber_News·
⚠️ CISA Urges Securing Microsoft Intune Following Stryker Breach Source: cybersecuritynews.com/secure-microso… CISA has issued an urgent alert urging organizations to harden their endpoint management system configurations following a cyberattack on Stryker Corporation, a U.S.-based medical technology firm, on March 11, 2026. The cyberattack against Stryker Corporation highlights a growing trend of threat actors targeting endpoint management platforms, particularly Microsoft Intune, to gain privileged access across enterprise environments. In response to the breach, CISA is urging all organizations to implement Microsoft’s newly released best practices for securing Microsoft Intune. #cybersecuritynews
Cyber Security News tweet media
English
5
114
352
33.7K