# cyber

Published articles for cyber.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## CrowdStrike SafeMind Uses Adversarial Co-Evolution to Improve AI-Powered Cybersecurity

DevFeed: [CrowdStrike SafeMind Uses Adversarial Co-Evolution to Improve AI-Powered Cybersecurity](<https://devfeed.tech/articles/crowdstrike-safemind-when-the-best-offense-builds-the-best-defense-42120.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/crowdstrike-safemind-best-offense-builds-best-defense/>)

Author: Ioana Croitoru - Sean Pagano - Keegan Hines - Alexander Nazarian - Chase Midler

Published: 2026-09-18T01:40:54.157408Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [scale](<https://devfeed.tech/tags/scale.md>), [securing-ai](<https://devfeed.tech/tags/securing-ai.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

CrowdStrike describes SafeMind, a closed-loop cybersecurity system in which offensive and defensive AI agents continuously test and improve one another. The system is designed to generate attacks, strengthen defenses, and automate detection creation at scale.

### Source excerpt

SafeMind is a closed-loop system where offense and defense continuously sharpen each other, resulting in a defense that's been forged against the best possible attacks. Learn more!

## China's Salt Typhoon backdoors Latin American orgs with new snooping malware

DevFeed: [China's Salt Typhoon backdoors Latin American orgs with new snooping malware](<https://devfeed.tech/articles/china-s-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware-42150.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286>)

Author: Jessica Lyons

Published: 2026-09-17T18:00:17Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [infosec](<https://devfeed.tech/topics/infosec.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [backdoor-malware](<https://devfeed.tech/tags/backdoor-malware.md>), [china](<https://devfeed.tech/tags/china.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [malware](<https://devfeed.tech/tags/malware.md>), [salt-typhoon](<https://devfeed.tech/tags/salt-typhoon.md>), [security](<https://devfeed.tech/tags/security.md>), [sparrowocky](<https://devfeed.tech/tags/sparrowocky.md>)

### AI overview

A news report about Salt Typhoon using new snooping backdoors and malware against organizations in Latin America.

### Source excerpt

Beware the SparroWocky, my son! The backdoor that bites...

## Welcoming the Sri Lankan Government to Have I Been Pwned

DevFeed: [Welcoming the Sri Lankan Government to Have I Been Pwned](<https://devfeed.tech/articles/welcoming-the-sri-lankan-government-to-have-i-been-pwned-41991.md>)

Original publisher: [Read original article](<https://www.troyhunt.com/welcoming-the-sri-lankan-government-to-have-i-been-pwned/>)

Author: Troy Hunt

Published: 2026-08-23T06:39:45Z

Content type: news

Language: en

Sources: [Troy Hunt](<https://devfeed.tech/sources/troy-hunt.md>)

Topics: [monitor](<https://devfeed.tech/topics/monitor.md>), [service](<https://devfeed.tech/topics/service.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [cyber](<https://devfeed.tech/tags/cyber.md>), [data](<https://devfeed.tech/tags/data.md>), [data-breaches](<https://devfeed.tech/tags/data-breaches.md>), [government](<https://devfeed.tech/tags/government.md>), [have-i-been-pwned](<https://devfeed.tech/tags/have-i-been-pwned.md>), [monitor](<https://devfeed.tech/tags/monitor.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [service](<https://devfeed.tech/tags/service.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

Have I Been Pwned has onboarded Sri Lanka as its 48th government customer for the free HIBP service. Sri Lanka CERT can monitor government domains for exposed accounts and respond to new data breaches.

### Source excerpt

Today, we welcome the 48th government onboarded to Have I Been Pwned's free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.

## Weekly Update 517: Cyber Ransoms

DevFeed: [Weekly Update 517: Cyber Ransoms](<https://devfeed.tech/articles/weekly-update-517-cyber-ransoms-41985.md>)

Original publisher: [Read original article](<https://www.troyhunt.com/weekly-update-517/>)

Author: Troy Hunt

Published: 2026-08-18T03:44:58Z

Content type: opinion

Language: en

Sources: [Troy Hunt](<https://devfeed.tech/sources/troy-hunt.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [breach](<https://devfeed.tech/tags/breach.md>), [class](<https://devfeed.tech/tags/class.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [weekly-update](<https://devfeed.tech/tags/weekly-update.md>)

### AI overview

The article comments on ransomware as extortion, the financial motives of attackers, and the legal and communication pressures faced by breached companies.

### Source excerpt

The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn't even involve "ware", it's just extortion) is carried out by kids who successfully make a truckload of money but can't spend it without

## Digital Policy in the Coalition Agreement: AI, Cybersecurity and Digital Autonomy

DevFeed: [Digital Policy in the Coalition Agreement: AI, Cybersecurity and Digital Autonomy](<https://devfeed.tech/articles/digitaal-zoet-en-zuur-in-het-coalitieakkoord-36355.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/digitaal-zoet-zuur-coalitie-akkoord/>)

Published: 2026-02-02T11:00:00Z

Content type: opinion

Language: nl

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [overheid](<https://devfeed.tech/tags/overheid.md>)

### AI overview

This opinion article reviews digital policy in the coalition agreement, highlighting enthusiasm for AI, proposed government IT centralization, efforts to reduce reliance on American cloud providers, and measures related to cybersecurity and digital autonomy.

### Source excerpt

Het coalitieakkoord heeft een boel woorden die raken aan digitalisering, digitale autonomie en cybersecurity. Veel van de plannen komen niet uit de lucht vallen, en zijn gebaseerd op bijeenkomsten, gesprekken en documenten van de afgelopen jaren. Het is goed te zien dat men gebruik heeft gemaakt van dit eerdere werk (zoals het stuk Wolken aan de horizon, en Ons Digitaal Fundament). Specifiek moet het initiatief van de digitale club van D66 om samen te werken met de digitale zuster-afdelingen van CDA, GroenLinks-PvdA en VVD genoemd worden, waar een gezamenlijk document met input uit is gekomen.

## "Cyber Special Operations": China-linked influence planning

DevFeed: ["Cyber Special Operations": China-linked influence planning](<https://devfeed.tech/articles/cyber-special-operations-china-linked-influence-planning-41318.md>)

Original publisher: [Read original article](<https://openai.com/index/disrupting-malicious-uses-of-ai-cyber-special-operations>)

Published: 2026-02-01T00:00:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [case-study](<https://devfeed.tech/tags/case-study.md>), [china](<https://devfeed.tech/tags/china.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [fake-accounts](<https://devfeed.tech/tags/fake-accounts.md>), [influence](<https://devfeed.tech/tags/influence.md>), [japan](<https://devfeed.tech/tags/japan.md>), [openai](<https://devfeed.tech/tags/openai.md>), [report](<https://devfeed.tech/tags/report.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [safety](<https://devfeed.tech/tags/safety.md>), [social-media](<https://devfeed.tech/tags/social-media.md>)

### AI overview

OpenAI describes banning a ChatGPT account linked to an individual associated with Chinese law enforcement after the account was used to plan covert influence activity, harassment, and online operations targeting the Japanese prime minister and other adversaries. The article says the model refused to assist with the influence-operation planning but was asked to edit and polish status reports. Open-source investigation linked the reported activity to a broader alleged Chinese law-enforcement strategy involving fake accounts, AI models, and multiple online tactics.

### Source excerpt

OpenAI banned an account linked to an individual associated with Chinese law enforcement, using AI to plan influence activity, harassment, and online operations.

## Cyber Security: A Pre-War Reality Check

DevFeed: [Cyber Security: A Pre-War Reality Check](<https://devfeed.tech/articles/cyber-security-a-pre-war-reality-check-36332.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/cyber-security-pre-war-reality-check/>)

Published: 2024-05-14T18:48:26Z

Content type: opinion

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [autonomy](<https://devfeed.tech/tags/autonomy.md>), [conference](<https://devfeed.tech/tags/conference.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [presentation](<https://devfeed.tech/tags/presentation.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [speech](<https://devfeed.tech/tags/speech.md>)

### AI overview

A lightly edited transcript of a presentation arguing that cybersecurity should be understood not only as protecting secrets and systems from hackers or ransomware, but also in the context of war and broader societal security risks. The speaker calls for a more realistic assessment of the current security environment.

### Source excerpt

This is a lightly edited transcript of my presentation today at the ACCSS/NCSC/Surf seminar 'Cyber Security and Society'. I want to thank the organizers for inviting me to their conference & giving me a great opportunity to talk about something I worry about a lot. Here are the original slides with notes, which may be useful to view together with the text below. In the notes there are also additional URLs that back up the claims I make in what follows.

## Cybersecurity Is Like Food Safety: Digital HACCP

DevFeed: [Cybersecurity Is Like Food Safety: Digital HACCP](<https://devfeed.tech/articles/cybersecurity-is-like-food-safety-digital-haccp-36333.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/cybersecurity-is-like-food-safety/>)

Published: 2021-02-18T08:31:12Z

Content type: opinion

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [cyber](<https://devfeed.tech/tags/cyber.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [digital](<https://devfeed.tech/tags/digital.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that cybersecurity is more like food safety than a product that can be purchased. Effective protection depends on understanding risks, consistently following appropriate practices, measuring compliance, and maintaining vigilance across the supply chain. It introduces HACCP as a potential source of ideas for cybersecurity.

### Source excerpt

There are lots of calls to invest in improving cybersecurity. But it struck me that it doesn't work like that. Not getting hacked is not so much a question of buying the right stuff. It is a question of doing the right things and understanding what you are doing. It is easy to demand that people 'invest' in something. You can even supply them with the money to do so.

## Sociotechnical Approach to Cyber Security

DevFeed: [Sociotechnical Approach to Cyber Security](<https://devfeed.tech/articles/sociotechnical-approach-to-cyber-security-36975.md>)

Original publisher: [Read original article](<https://shostack.org/blog/sociotechnical-approach-to-cyber-security/>)

Author: Adam

Published: 2020-07-24T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [context](<https://devfeed.tech/topics/context.md>)

Tags: [approach](<https://devfeed.tech/tags/approach.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [post](<https://devfeed.tech/tags/post.md>), [security](<https://devfeed.tech/tags/security.md>), [technical](<https://devfeed.tech/tags/technical.md>), [uk](<https://devfeed.tech/tags/uk.md>)

### AI overview

This post highlights a recent UK NCSC article by Helen L. on sociotechnical approaches to cybersecurity, including the context of these approaches, the RISCS Institute, and a related problem book.

### Source excerpt

A recent post from Helen L. of the UK's NCSC, A sociotechnical approach to cyber security, shares the context of socio-technical approaches.

## Worthwhile Books (Q1 2020)

DevFeed: [Worthwhile Books (Q1 2020)](<https://devfeed.tech/articles/worthwhile-books-q1-2020-37126.md>)

Original publisher: [Read original article](<https://shostack.org/blog/worthwhile-books-q1-2020/>)

Author: Adam

Published: 2020-04-14T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [books](<https://devfeed.tech/tags/books.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [history](<https://devfeed.tech/tags/history.md>)

### AI overview

The author recommends books read in the first quarter of 2020, including works about cybersecurity, the NotPetya worm, online harassment, weather science, Tolkien, Theranos, and synthetic intellects. The article highlights lessons about observation, knowledge-sharing, loyalty, and cybersecurity.

### Source excerpt

These are the books I read in the first quarter (and forgot to mention last quarter) that I think are worth your time.

## Books Worth Your Time (Q4)

DevFeed: [Books Worth Your Time (Q4)](<https://devfeed.tech/articles/books-worth-your-time-q4-36710.md>)

Original publisher: [Read original article](<https://shostack.org/blog/books-worth-your-time-q4/>)

Author: Adam

Published: 2019-12-01T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [huawei](<https://devfeed.tech/topics/huawei.md>), [C](<https://devfeed.tech/topics/c.md>), [Finance](<https://devfeed.tech/topics/finance.md>)

Tags: [books](<https://devfeed.tech/tags/books.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [energy](<https://devfeed.tech/tags/energy.md>), [game](<https://devfeed.tech/tags/game.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [huawei](<https://devfeed.tech/tags/huawei.md>), [review](<https://devfeed.tech/tags/review.md>), [space](<https://devfeed.tech/tags/space.md>)

### AI overview

A quarterly reading list reviews books about cybersecurity and hacking, including Huawei-related trust risks and the history of the hacking scene, alongside nonfiction about solar energy, spaceflight, and cooperative game design.

### Source excerpt

Just what the title says...

## DNS Security

DevFeed: [DNS Security](<https://devfeed.tech/articles/dns-security-36761.md>)

Original publisher: [Read original article](<https://shostack.org/blog/dns-security/>)

Author: Adam

Published: 2019-06-13T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [DNS security](<https://devfeed.tech/topics/dns-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cyber](<https://devfeed.tech/tags/cyber.md>), [deploy](<https://devfeed.tech/tags/deploy.md>), [dns](<https://devfeed.tech/tags/dns.md>), [dns-security](<https://devfeed.tech/tags/dns-security.md>), [easy](<https://devfeed.tech/tags/easy.md>), [effective](<https://devfeed.tech/tags/effective.md>), [report](<https://devfeed.tech/tags/report.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

The Global Cyber Alliance published research by Jay Jacobs, Wade Baker, and the author on the value of DNS security. The article says DNS providers using threat intelligence to block malicious sites can be effective and easy to deploy, citing a report that says DNS security can mitigate one-third of cyber incidents.

### Source excerpt

I'm happy to say that some new research by Jay Jacobs, Wade Baker, and myself is now available, thanks to the Global Cyber Alliance.

## When security goes off the rails

DevFeed: [When security goes off the rails](<https://devfeed.tech/articles/when-security-goes-off-the-rails-37120.md>)

Original publisher: [Read original article](<https://shostack.org/blog/when-security-goes-off-the-rails/>)

Author: Adam

Published: 2019-06-07T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [investigations](<https://devfeed.tech/tags/investigations.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A brief commentary points to a Dark Reading post about regulation in cybersecurity and argues that cyber can learn from the impartial analysis used in the highly regulated rail industry. It references conflicting accounts of a Baltimore ransomware attack and calls for an investigative capability that can establish the facts.

### Source excerpt

My newest post over at Dark Reading ponders regulation.

## Best Cyber News Blogs, thanks!

DevFeed: [Best Cyber News Blogs, thanks!](<https://devfeed.tech/articles/best-cyber-news-blogs-thanks-36695.md>)

Original publisher: [Read original article](<https://shostack.org/blog/best-cyber-news-blogs-thanks/>)

Author: Adam

Published: 2018-04-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>)

Tags: [blogs](<https://devfeed.tech/tags/blogs.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [news](<https://devfeed.tech/tags/news.md>)

### AI overview

The author thanks CyberDB for including Shostack + Friends Blog in its list of Best Cyber Security News Blogs 2018.

### Source excerpt

[no description provided]

## SEC Fines Yahoo $35 Million Over Disclosure of Russian Hacking

DevFeed: [SEC Fines Yahoo $35 Million Over Disclosure of Russian Hacking](<https://devfeed.tech/articles/35m-for-covering-up-a-breach-36648.md>)

Original publisher: [Read original article](<https://shostack.org/blog/35m-for-covering-up-a-breach/>)

Author: Adam

Published: 2018-04-24T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>)

Tags: [breach](<https://devfeed.tech/tags/breach.md>), [company](<https://devfeed.tech/tags/company.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [disclosure](<https://devfeed.tech/tags/disclosure.md>)

### AI overview

The article discusses the SEC's $35 million fine against Yahoo for failing to disclose a Russian hacking incident to investors. It highlights the SEC's view that the company's response warranted enforcement action.

### Source excerpt

[no description provided]

## An accessible explanation of the Spectre and Meltdown CPU vulnerabilities

DevFeed: [An accessible explanation of the Spectre and Meltdown CPU vulnerabilities](<https://devfeed.tech/articles/spectre-meltdown-tapping-into-the-cpu-s-subconscious-thoughts-36545.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/spectre-meltdown/>)

Published: 2018-01-06T09:34:05Z

Content type: article

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [cpu](<https://devfeed.tech/topics/cpu.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [accessible](<https://devfeed.tech/tags/accessible.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [processor](<https://devfeed.tech/tags/processor.md>), [programming](<https://devfeed.tech/tags/programming.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An accessible explanation of the Spectre and Meltdown vulnerabilities, including how CPU out-of-order execution improves processing speed while remaining hidden from executing programs.

### Source excerpt

Comments are very welcome on bert@hubertnet.nl or @bert_hu_bert. Update: several constructive remarks have been used to improve this text. Thanks! In this post I will attempt to fully explain the Spectre and Meltdown vulnerabilities in an accessible way. I decided to write it up after I realised it took me more than a day to figure it out, even though I've been doing security related stuff on CPUs for 20 years.

## Worthwhile Books, Q3

DevFeed: [Worthwhile Books, Q3](<https://devfeed.tech/articles/worthwhile-books-q3-37132.md>)

Original publisher: [Read original article](<https://shostack.org/blog/worthwhile-books-q3-2017/>)

Author: Adam

Published: 2017-10-11T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [Internet](<https://devfeed.tech/topics/internet.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [books](<https://devfeed.tech/tags/books.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [iot](<https://devfeed.tech/tags/iot.md>), [physics](<https://devfeed.tech/tags/physics.md>), [reading](<https://devfeed.tech/tags/reading.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A quarterly list of books the author recommends, covering cybersecurity and the Internet of Things, nonfiction about activism and learning from mistakes, modern physics, and science fiction.

### Source excerpt

Some of what I've read over the past quarter and want to recommend as worthy of your time.

## Breach Vouchers & Equifax 2017 Breach Links

DevFeed: [Breach Vouchers & Equifax 2017 Breach Links](<https://devfeed.tech/articles/breach-vouchers-equifax-2017-breach-links-36713.md>)

Original publisher: [Read original article](<https://shostack.org/blog/breach-vouchers-equifax-2017-breach-links/>)

Author: Adam

Published: 2017-09-07T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>)

Tags: [2017](<https://devfeed.tech/tags/2017.md>), [breach](<https://devfeed.tech/tags/breach.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [data-breaches](<https://devfeed.tech/tags/data-breaches.md>), [identity-theft](<https://devfeed.tech/tags/identity-theft.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that Equifax should not provide its own breach-response services after the 2017 data breach. It proposes that the FTC require vouchers so affected consumers can choose independent identity-theft protection and credit-monitoring providers.

### Source excerpt

[no description provided]

## Cyber Grand Shellphish

DevFeed: [Cyber Grand Shellphish](<https://devfeed.tech/articles/cyber-grand-shellphish-36747.md>)

Original publisher: [Read original article](<https://shostack.org/blog/cyber-grand-shellphish/>)

Author: Adam

Published: 2017-04-24T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Software](<https://devfeed.tech/topics/software.md>), [Algorithm](<https://devfeed.tech/topics/algorithm.md>)

Tags: [algorithm](<https://devfeed.tech/tags/algorithm.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

The article discusses Team Shellphish's participation in the Cyber Grand Challenge and highlights how a hypothetical team that stopped playing could have scored highly under the contest's scoring system. It argues that the result illustrates the difficulty of designing robust scoring systems.

### Source excerpt

[no description provided]