Tag: hacktivism

  • What’s New in Cybersecurity This Week: Projects, Videos, Articles & Podcasts I’m Following – 10/27/25

    What’s New in Cybersecurity This Week: Projects, Videos, Articles & Podcasts I’m Following – 10/27/25

    Welcome to my weekly cybersecurity roundup! Here, I share updates on the projects I’m currently working on, along with the most insightful cybersecurity videos I watched, articles I found valuable, and podcasts I tuned into this week.

    Featured Analysis

    Featured article analysis: You have one week to opt out or become fodder for LinkedIn AI training

    LinkedIn’s updated data use policy, effective November 3, 2025, marks a significant expansion in its program of scraping user data for AI model training. Crucially, this policy change eliminates previous geographic exemptions, extending the practice to members in the UK, the European Union (EU), the European Economic Area (EEA), Switzerland, Canada, and Hong Kong. For professionals in these regions, virtually all publicly available data—including profile details and posts—is now fair game for harvesting. This move places LinkedIn squarely within a major global trend where tech giants are re-engineering terms of service to fuel their generative AI ventures, often raising the ire of members who explicitly provided their professional data for networking, not for mass training of commercial machine learning tools.

    Beyond personal privacy, this policy shift introduces complex challenges for corporate governance, compliance, and legal teams. By sharing scraped data with affiliates, specifically Microsoft, LinkedIn is blurring the lines between its professional network data and the broader commercial interests of its parent company. The article notes that this data will be used to show more personalized ads, which may include sensitive insights gleaned from professional activity. Furthermore, the mandatory “opt-out” mechanism—instead of an “opt-in” model—is likely to face intense scrutiny in regions with stringent privacy legislation like the GDPR. The default setting of allowing data use creates a regulatory risk, potentially positioning LinkedIn for future legal challenges regarding the lack of explicit, freely given consent.

    The analysis serves as a clear call to action, emphasizing that professionals in the newly included regions have a narrow window to safeguard their data. The process is a two-step affair: first, opting out of AI training under the Settings > Data Privacy menu, and second, adjusting the relevant preferences under the Advertising Data category to prevent data sharing with Microsoft affiliates for ad purposes. For a LinkedIn audience—whose primary asset is their meticulously curated professional identity—understanding and executing these opt-out steps is an urgent necessity. Failure to act defaults their professional biographies and content into the engine that powers the next generation of AI tools, permanently changing the intended use and ownership of their digital profile.

    Projects

    • TryHackMe – CyberChef: The Basics – In Progress

    Videos

    Articles

  • What’s New in Cybersecurity This Week: Projects, Videos, Articles & Podcasts I’m Following – 9/15/25

    What’s New in Cybersecurity This Week: Projects, Videos, Articles & Podcasts I’m Following – 9/15/25

    Welcome to my weekly cybersecurity roundup! Here, I share updates on the projects I’m currently working on, along with the most insightful cybersecurity videos I watched, articles I found valuable, and podcasts I tuned into this week.

    Featured Analysis

    Featured article analysis: Former FinWise employee may have accessed nearly 700K customer records

    The data breach at FinWise Bank, which affected nearly 700,000 customer records, highlights the significant and often prolonged risk posed by former employees. A former staff member was able to potentially access sensitive information for over a year after their employment ended, demonstrating a critical failure in the company’s offboarding and access control protocols. While FinWise Bank has taken standard corrective measures, such as hiring cybersecurity professionals and offering free credit monitoring to the 689,000 affected customers, the incident underscores the severe consequences of a breach that goes undetected for a lengthy period.

    This incident is not isolated and falls into a growing pattern of insider-related data breaches. The article cites similar, high-profile cases at companies like Coinbase and Rippling, where former or current employees were found to have maliciously accessed or stolen data. The problem extends beyond malicious intent to include accidental breaches, such as misdirected emails. The recurring nature of these events, including a statistic about student-caused cyberattacks in schools, points to a systemic vulnerability in how organizations manage and secure internal access to sensitive information.

    Experts suggest that a more strategic approach to personnel security is needed to counter these risks effectively. The analysis from Paul Martin of RUSI points out the “lacking strategic thinking” in the field and recommends proactive measures rather than reactive ones. He advocates for a stronger internal security culture, built on trust, and the creation of a dedicated working group to aggregate and analyze data that could indicate insider malfeasance. By improving these internal processes, organizations like FinWise could better protect themselves from the risks posed by both current and former employees, thus preventing future incidents of this scale.

    Projects

    • TryHackMe – Log Fundamentals – In Progress

    Papers

    Articles

  • Book Review: “Cult of the Dead Cow” – Inside the World of the Original Hacking Supergroup

    Book Review: “Cult of the Dead Cow” – Inside the World of the Original Hacking Supergroup

    • Author: Joseph Menn
    • Fiction: Non-Fiction
    • Genres: Technology, Cyber Security
    • Rating: 3.5 Stars
    • Date Finished: 3/6/25

    The Book in 3 Sentences

    The book explores the history and influence of the legendary hacking collective known as cDc, which pioneered hacktivism and shaped modern cybersecurity. The book delves into the group’s groundbreaking contributions, such as exposing software vulnerabilities, promoting ethical hacking, and influencing figures like Beto O’Rourke. Menn also highlights the evolving cyber threat landscape, emphasizing the ongoing battle between hackers, corporations, and governments over privacy and security.

    Impressions

    How I Discovered It

    I’m reading through all the information security books that my local library has. I’m also try to get them to include more books from this subject.

    Who Should Read It?

    Cult of the Dead Cow is ideal for cybersecurity professionals, ethical hackers, and tech enthusiasts interested in the origins of hacktivism and its impact on modern security. It’s also a great read for policymakers, journalists, and privacy advocates who want to understand the ethical dilemmas and power struggles shaping the digital world. Additionally, anyone curious about the intersection of technology, activism, and government surveillance will find this book insightful and thought-provoking.

    How the Book Changed Me

    • Expanded Perspective on Hacktivism – It shifted your view of hackers to individuals who use their skills for social good, advocating for privacy, security, and accountability.
    • Strengthened Awareness of Cybersecurity Risks – It revalidated by view of digital vulnerabilities, how governments and corporations handle (or mishandle) cybersecurity, and the importance of protecting personal data.
    • Inspiration for Ethical Advocacy – The book motivated me to push for stronger digital rights.

    My Top 3 Quotes

    • “Hacking is not inherently bad. It’s about figuring out how things work and making them better.”
    • “The greatest threat to cybersecurity is not hackers—it’s apathy.”
    • “Privacy is not about having something to hide; it’s about having control over your own life.”

    Summary

    Cult of the Dead Cow by Joseph Menn chronicles the rise and influence of one of the most legendary and impactful hacking groups in history. The book explores how the cDc pioneered hacktivism, exposing software vulnerabilities, advocating for digital privacy, and shaping cybersecurity policies. Menn highlights their role in pushing companies and governments to take security more seriously while also delving into their ethical dilemmas and controversial tactics. The book also reveals the surprising connection of some members to mainstream politics and business, illustrating how hacking culture has evolved from the underground to the halls of power. Ultimately, Cult of the Dead Cow is a compelling look at the battle for control over the internet, security, and personal freedoms in the digital age.