<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><description>Welcome to the aforementioned slinky and sultry Web 2.0 crap.</description><title>tumblr.attrition.org</title><generator>Tumblr (3.0; @attritionorg)</generator><link>https://tumblr.attrition.org/</link><item><title>Security vs Security Theatre; A Lesson for Abbott</title><description>&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/05/08/security-vs-security-theatre-a-lesson-for-abbott/","display_url":"https://jericho.blog/2026/05/08/security-vs-security-theatre-a-lesson-for-abbott/","title":"Security vs Security Theatre; A Lesson for Abbott","poster":[{"media_key":"80eb25bc0d8c17bf4c391aafba8a4aaf:8b749b7d0a0ecb81-8e","type":"image/png","width":1008,"height":1064}]}'&gt;&lt;a href="https://jericho.blog/2026/05/08/security-vs-security-theatre-a-lesson-for-abbott/" target="_blank"&gt;Security vs Security Theatre; A Lesson for Abbott&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/816057237051260928</link><guid>https://tumblr.attrition.org/post/816057237051260928</guid><pubDate>Fri, 08 May 2026 11:07:07 -0400</pubDate><category>Abbott</category><category>Security Theatre</category><category>Twitter</category></item><item><title>The NVD Shell Game &amp;amp; Schr&amp;ouml;dinger&amp;rsquo;s Enriched Vulnerability</title><description>&lt;h1&gt;The NVD Shell Game &amp;amp; Schrödinger&amp;rsquo;s Enriched Vulnerability&lt;/h1&gt;&lt;p class="npf_link" data-npf="{&amp;quot;type&amp;quot;:&amp;quot;link&amp;quot;,&amp;quot;url&amp;quot;:&amp;quot;https://jericho.blog/2026/05/07/the-nvd-shell-game-schrodingers-enriched-vulnerability/&amp;quot;,&amp;quot;display_url&amp;quot;:&amp;quot;https://jericho.blog/2026/05/07/the-nvd-shell-game-schrodingers-enriched-vulnerability/&amp;quot;,&amp;quot;title&amp;quot;:&amp;quot;The NVD Shell Game &amp;amp;amp; Schrödinger's Enriched Vulnerability&amp;quot;,&amp;quot;poster&amp;quot;:[{&amp;quot;media_key&amp;quot;:&amp;quot;5ecef4282545198087f49650332af587:e189d6b46b2156a1-78&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;image/png&amp;quot;,&amp;quot;width&amp;quot;:1171,&amp;quot;height&amp;quot;:768}]}"&gt;&lt;a href="https://jericho.blog/2026/05/07/the-nvd-shell-game-schrodingers-enriched-vulnerability/" target="_blank"&gt;The NVD Shell Game &amp;amp;amp; Schrödinger&amp;rsquo;s Enriched Vulnerability&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/815969737637019648</link><guid>https://tumblr.attrition.org/post/815969737637019648</guid><pubDate>Thu, 07 May 2026 11:56:21 -0400</pubDate><category>Harold Booth</category><category>NVD</category><category>VulnCon</category></item><item><title>The Night I Almost Died</title><description>&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/05/03/the-night-i-almost-died/","display_url":"https://jericho.blog/2026/05/03/the-night-i-almost-died/","title":"The Night I Almost Died","poster":[{"media_key":"4fceb7901d98536df45edb15c75cc41c:951e65db76f08d1d-e5","type":"image/png","width":1088,"height":763}]}'&gt;&lt;a href="https://jericho.blog/2026/05/03/the-night-i-almost-died/" target="_blank"&gt;The Night I Almost Died&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/815612996598497280</link><guid>https://tumblr.attrition.org/post/815612996598497280</guid><pubDate>Sun, 03 May 2026 13:26:06 -0400</pubDate><category>Abbott</category><category>Diabetes</category><category>Libre</category><category>Libre2</category></item><item><title>Starfleet Academy; The Review</title><description>&lt;p&gt;Starfleet Academy (SA), the latest TV show in the Star Trek line, debuted this year with a lot of fanfare and a fair share of drama. The show almost immediately hit the news with cries of it being “too woke”. The Washington Times headline called it a “woke culture war casualty” and Outkick said the show hit “a new low” and that the franchise “just keeps getting worse“. Jonathan Frakes, best known…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/05/02/starfleet-academy-the-review/","display_url":"https://jericho.blog/2026/05/02/starfleet-academy-the-review/","title":"Starfleet Academy; The Review","poster":[{"media_key":"2c1a62f489f6d28f3249fa221ea91a06:29cd8e2fe3ae66f7-95","type":"image/png","width":345,"height":146}]}'&gt;&lt;a href="https://jericho.blog/2026/05/02/starfleet-academy-the-review/" target="_blank"&gt;Starfleet Academy; The Review&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/815515142115704832</link><guid>https://tumblr.attrition.org/post/815515142115704832</guid><pubDate>Sat, 02 May 2026 11:30:45 -0400</pubDate><category>Jonathan Frakes</category><category>Star Trek</category><category>Tom Morello</category><category>William Shatner</category></item><item><title>Why Data From So Many Breaches Never Sees the Light of Day</title><description>&lt;p&gt;Months ago I was chatting with a colleague about a recent data leak (a.k.a. Data breach), as we tend to do in this industry. Those terms are defined by Microsoft as “an unauthorized disclosure of sensitive, confidential, or personal information from an organization’s systems or networks to an external party“. Any time I see an article about data breaches I have flashbacks, and fortunately not too…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/05/01/why-data-from-so-many-breaches-never-sees-the-light-of-day/","display_url":"https://jericho.blog/2026/05/01/why-data-from-so-many-breaches-never-sees-the-light-of-day/","title":"Why Data From So Many Breaches Never Sees the Light of Day","poster":[{"media_key":"e63130a8b09092aa859d5da9224def9c:609436ba59d5a647-0c","type":"image/png","width":1408,"height":768}]}'&gt;&lt;a href="https://jericho.blog/2026/05/01/why-data-from-so-many-breaches-never-sees-the-light-of-day/" target="_blank"&gt;Why Data From So Many Breaches Never Sees the Light of Day&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/815423002786365440</link><guid>https://tumblr.attrition.org/post/815423002786365440</guid><pubDate>Fri, 01 May 2026 11:06:14 -0400</pubDate><category>Akamai</category><category>Ariana Baio</category><category>CloudFlare</category><category>Data Breach</category><category>Dataloss</category><category>Dominick Skinner</category><category>ICE</category></item><item><title>InfoSec News (ISN) Mail List History</title><description>&lt;p&gt;As early as 1996, I created a mail list called InfoSec News (ISN) which initially was to share news about the industry. At the time, there were no online news sites covering the topic with any regularity and most were hobbies at best. So the original list had many articles that I had typed in by hand from print InfoSec magazines. The list has mostly faded into obscurity; so much so that trying to…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/04/30/infosec-news-isn-mail-list-history/","display_url":"https://jericho.blog/2026/04/30/infosec-news-isn-mail-list-history/","title":"InfoSec News (ISN) Mail List History","poster":[{"media_key":"8ee672151e43d90b5c78941caa2c1935:3fa34107ac1267d2-ca","type":"image/gif","width":153,"height":160}]}'&gt;&lt;a href="https://jericho.blog/2026/04/30/infosec-news-isn-mail-list-history/" target="_blank"&gt;InfoSec News (ISN) Mail List History&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/815346577432559616</link><guid>https://tumblr.attrition.org/post/815346577432559616</guid><pubDate>Thu, 30 Apr 2026 14:51:29 -0400</pubDate><category>Gordon Lyon</category><category>InfoSec News</category><category>ISN</category><category>Repent Security</category><category>RSI</category><category>SecurityFocus</category><category>William Knowles</category></item><item><title>An AI agent destroyed &amp;hellip; hey wait a minute!</title><description>&lt;p&gt;Yesterday many people ran across a headline that was shocking, and repetitive. This time it read “‘Gone in 9 seconds’: Claude-powered AI agent deletes startup’s entire database“. For myself, the first thing I had to do was check the date of the article because I swore I had just read about this recently. Yep, April 28 so it’s a new one! In a prior blog on the topic of so-called AI, or as I argued…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/04/29/an-ai-agent-destroyed-hey-wait-a-minute/","display_url":"https://jericho.blog/2026/04/29/an-ai-agent-destroyed-hey-wait-a-minute/","title":"An AI agent destroyed … hey wait a minute!","poster":[{"media_key":"c423013af5c624f5e320b51d174c8085:c7df388ee8267c9b-40","type":"image/png","width":1408,"height":768}]}'&gt;&lt;a href="https://jericho.blog/2026/04/29/an-ai-agent-destroyed-hey-wait-a-minute/" target="_blank"&gt;An AI agent destroyed … hey wait a minute!&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/815241753515933696</link><guid>https://tumblr.attrition.org/post/815241753515933696</guid><pubDate>Wed, 29 Apr 2026 11:05:21 -0400</pubDate><category>Alex Perry</category><category>Beatrice Nolan</category><category>Blame</category><category>Cecily Mauran</category><category>Fortune</category><category>Jer Crane</category><category>Journalism</category><category>Mashable</category><category>MoneyControl</category><category>So-called AI</category></item><item><title>Don&amp;rsquo;t Call Me Boss</title><description>&lt;p&gt;I don’t remember when it started but it was easily five to ten years ago. I’d be in a restaurant typically and a server or cashier would call me ‘boss’. It bothered me from day one because it usually came from a younger kid who presumably didn’t understand all of the connotations behind the word in that context. I certainly felt it was inappropriate but only said something a few times when I felt…&lt;/p&gt;&lt;p class="npf_link" data-npf="{&amp;quot;type&amp;quot;:&amp;quot;link&amp;quot;,&amp;quot;url&amp;quot;:&amp;quot;https://jericho.blog/2026/04/28/dont-call-me-boss/&amp;quot;,&amp;quot;display_url&amp;quot;:&amp;quot;https://jericho.blog/2026/04/28/dont-call-me-boss/&amp;quot;,&amp;quot;title&amp;quot;:&amp;quot;Don't Call Me Boss&amp;quot;,&amp;quot;poster&amp;quot;:[{&amp;quot;media_key&amp;quot;:&amp;quot;7f735016576763f72c936d14e0c03f1d:bcfaa4d6ed9b20b7-77&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;image/png&amp;quot;,&amp;quot;width&amp;quot;:1408,&amp;quot;height&amp;quot;:768}]}"&gt;&lt;a href="https://jericho.blog/2026/04/28/dont-call-me-boss/" target="_blank"&gt;Don&amp;rsquo;t Call Me Boss&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/815151404303925248</link><guid>https://tumblr.attrition.org/post/815151404303925248</guid><pubDate>Tue, 28 Apr 2026 11:09:18 -0400</pubDate><category>Boss</category><category>Prison</category><category>Society</category></item><item><title>Security Software: Holding the Vault Door Open for Criminals</title><description>&lt;p&gt;I have been consistently tracking a fun metric around vulnerabilities since March 19, 2024. Before that I would occasionally mention it during talks or chat, but I don’t think I formally blogged about it before this and didn’t track the exact number. So here we are to discuss the prevalence of vulnerabilities in security software, the very thing designed to protect us. As best I recall, 10 – 20…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/04/27/security-software-holding-the-vault-door-open-for-criminals/","display_url":"https://jericho.blog/2026/04/27/security-software-holding-the-vault-door-open-for-criminals/","title":"Security Software: Holding the Vault Door Open for Criminals","poster":[{"media_key":"bf9cb8e2dadc7cb8f17fd898952a3d88:6a2723cc56d6cc51-38","type":"image/png","width":1129,"height":768}]}'&gt;&lt;a href="https://jericho.blog/2026/04/27/security-software-holding-the-vault-door-open-for-criminals/" target="_blank"&gt;Security Software: Holding the Vault Door Open for Criminals&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/815060754759843840</link><guid>https://tumblr.attrition.org/post/815060754759843840</guid><pubDate>Mon, 27 Apr 2026 11:08:28 -0400</pubDate><category>Irony</category><category>OSVDB</category><category>Shakacon</category><category>Vulnerabilities</category></item><item><title>Another Wave of Random Thoughts</title><description>&lt;p&gt;ATM&lt;br/&gt;&lt;br/&gt;ATMs have way too many options for many users, and definitely for most uses of the machines by volume. Sometimes, when I put my card in, why are you asking what language I want to use? The same one as last time maybe? And for someone who has the same exact transaction 95% of the time, give me a single button that just says “repeat last transaction” and display what it is. So much time would…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/04/22/another-wave-of-random-thoughts/","display_url":"https://jericho.blog/2026/04/22/another-wave-of-random-thoughts/","title":"Another Wave of Random Thoughts","poster":[{"media_key":"38c96466ee5f62dd8817b5b0effde037:841c83bb6f9c356c-94","type":"image/png","width":1408,"height":768}]}'&gt;&lt;a href="https://jericho.blog/2026/04/22/another-wave-of-random-thoughts/" target="_blank"&gt;Another Wave of Random Thoughts&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/814608206909358080</link><guid>https://tumblr.attrition.org/post/814608206909358080</guid><pubDate>Wed, 22 Apr 2026 11:15:24 -0400</pubDate><category>Amazon</category><category>Pandemic</category><category>Travel</category></item><item><title>Death Bed Then vs Now; Societal Impact and Contentment</title><description>&lt;p&gt;An abstract thought.&lt;br/&gt;&lt;br/&gt;Our grandparent’s generation seemed content on their deathbed, some with religion, some without. In TV, movies, and books, you see one in a hospital or at home surrounded by loved ones, with a gentle smile. I wonder if that will get much more difficult in today’s age, as society declines and the sense of accomplishing something meaningful declines as well. Two generations…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/04/21/death-bed-then-vs-now-societal-impact-and-contentment/","display_url":"https://jericho.blog/2026/04/21/death-bed-then-vs-now-societal-impact-and-contentment/","title":"Death Bed Then vs Now; Societal Impact and Contentment","poster":[{"media_key":"186458f15f532d1ca30e4e13d55c1adb:14c260f7022524ae-86","type":"image/jpeg","width":512,"height":422}]}'&gt;&lt;a href="https://jericho.blog/2026/04/21/death-bed-then-vs-now-societal-impact-and-contentment/" target="_blank"&gt;Death Bed Then vs Now; Societal Impact and Contentment&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/814512326275399680</link><guid>https://tumblr.attrition.org/post/814512326275399680</guid><pubDate>Tue, 21 Apr 2026 09:51:25 -0400</pubDate><category>Death</category><category>Dystopia</category><category>Politics</category><category>Society</category></item><item><title>NVD Gives Up</title><description>&lt;p&gt;Since 2024, representatives from NIST’s National Vulnerability Database (NVD) have given a presentation at VulnCon with updates to the program. This has been where news broke about significant changes, admissions, and omissions. The talks, typically 30 minutes, are certainly not enough time to tell us what the industry needs to know and leaves no time for Q&amp;amp;A despite there being a considerable…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/04/17/nvd-gives-up/","display_url":"https://jericho.blog/2026/04/17/nvd-gives-up/","title":"NVD Gives Up","poster":[{"media_key":"454295039e0c8e3646ee201bc5f11f5f:1d2991f74e45d514-b2","type":"image/png","width":1408,"height":768}]}'&gt;&lt;a href="https://jericho.blog/2026/04/17/nvd-gives-up/" target="_blank"&gt;NVD Gives Up&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/814154591223562240</link><guid>https://tumblr.attrition.org/post/814154591223562240</guid><pubDate>Fri, 17 Apr 2026 11:05:23 -0400</pubDate><category>CVE</category><category>Harold Booth</category><category>Jon Boyens</category><category>KEV</category><category>NIST</category><category>NVD</category><category>SBOM</category><category>VulnCon</category></item><item><title>Anthropic, Mythos, and the Dark Reality No One Is Talking About</title><description>&lt;p&gt;If I had a nickel for every time Anthropic’s new Project Glasswing / Mythos initiative came up in conversation or I was asked directly about it in the last few days, I would have a shit ton of nickels! Let’s dive into it… first with brief observations about the announcements and available information, other’s opinions, then a broader opinion of my own on where this is all going.&lt;br/&gt;&lt;br/&gt;Gemini prompt:…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/04/15/anthropic-mythos-and-the-dark-reality-no-one-is-talking-about/","display_url":"https://jericho.blog/2026/04/15/anthropic-mythos-and-the-dark-reality-no-one-is-talking-about/","title":"Anthropic, Mythos, and the Dark Reality No One Is Talking About","poster":[{"media_key":"3ca7e5e38ce315b7d9811f368c0b7c9d:909322cd55518ae9-15","type":"image/png","width":1036,"height":766}]}'&gt;&lt;a href="https://jericho.blog/2026/04/15/anthropic-mythos-and-the-dark-reality-no-one-is-talking-about/" target="_blank"&gt;Anthropic, Mythos, and the Dark Reality No One Is Talking About&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/813976057317376000</link><guid>https://tumblr.attrition.org/post/813976057317376000</guid><pubDate>Wed, 15 Apr 2026 11:47:40 -0400</pubDate><category>Anthropic</category><category>Cloud Security Alliance</category><category>Glasswing</category><category>Jon Martindale</category><category>KEV</category><category>Mythos</category><category>Nico Waisman</category><category>So-called AI</category><category>The AI Security Institute</category><category>Vulnerability Disclosure</category></item><item><title>Vulnerability Research Isn&amp;rsquo;t Cooked; It&amp;rsquo;s Burned Beyond Recognition</title><description>&lt;p&gt;On March 30, 2026, Thomas &amp;amp; Erin Ptacek posted a blog titled “Vulnerability Research Is Cooked“. I don’t believe I know Erin, but I know of Thomas as an old-school vulnerability researcher who has been well respected for a long, long time. When he speaks about vulnerability research, I certainly listen. So this blog was of interest to me for a variety of reasons as it primarily talked about the…&lt;/p&gt;&lt;p class="npf_link" data-npf="{&amp;quot;type&amp;quot;:&amp;quot;link&amp;quot;,&amp;quot;url&amp;quot;:&amp;quot;https://jericho.blog/2026/04/06/vulnerability-research-isnt-cooked-its-burned-beyond-recognition/&amp;quot;,&amp;quot;display_url&amp;quot;:&amp;quot;https://jericho.blog/2026/04/06/vulnerability-research-isnt-cooked-its-burned-beyond-recognition/&amp;quot;,&amp;quot;title&amp;quot;:&amp;quot;Vulnerability Research Isn't Cooked; It's Burned Beyond Recognition&amp;quot;,&amp;quot;poster&amp;quot;:[{&amp;quot;media_key&amp;quot;:&amp;quot;1700b405cf2379ec64f3dba2dfd6ffd4:b562e74780ccd501-fc&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;image/png&amp;quot;,&amp;quot;width&amp;quot;:1408,&amp;quot;height&amp;quot;:768}]}"&gt;&lt;a href="https://jericho.blog/2026/04/06/vulnerability-research-isnt-cooked-its-burned-beyond-recognition/" target="_blank"&gt;Vulnerability Research Isn&amp;rsquo;t Cooked; It&amp;rsquo;s Burned Beyond Recognition&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/813157399076700160</link><guid>https://tumblr.attrition.org/post/813157399076700160</guid><pubDate>Mon, 06 Apr 2026 10:55:26 -0400</pubDate><category>Erin Ptacek</category><category>LLM</category><category>Nicholas Carlini</category><category>OpenClaw</category><category>So-called AI</category><category>Thomas Ptacek</category><category>Vulnerability Disclosure</category></item><item><title>We Are Legion (We Are Bobservations); Answering a &amp;ldquo;Simple&amp;rdquo; Question</title><description>&lt;p&gt;In late February, a friend linked an article about a science-fiction book and asked if I had read it. I told her that I hadn’t but after reading an abstract it sounded good. She asked if I would be her designated reader due to her workload, and report back. I said sure! She was particularly interested in it after reading an article by Rya Jetha in the The San Francisco Standard. The article,…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/04/04/we-are-legion-we-are-bobservations-answering-a-simple-question/","display_url":"https://jericho.blog/2026/04/04/we-are-legion-we-are-bobservations-answering-a-simple-question/","title":"We Are Legion (We Are Bobservations); Answering a \"Simple\" Question","poster":[{"media_key":"05ee37ddd9dcffe5a49bdd49b7f8f201:4224151522257fd7-4c","type":"image/png","width":1376,"height":768}]}'&gt;&lt;a href="https://jericho.blog/2026/04/04/we-are-legion-we-are-bobservations-answering-a-simple-question/" target="_blank"&gt;We Are Legion (We Are Bobservations); Answering a &amp;ldquo;Simple&amp;rdquo; Question&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/812976831336677376</link><guid>https://tumblr.attrition.org/post/812976831336677376</guid><pubDate>Sat, 04 Apr 2026 11:05:23 -0400</pubDate><category>Dennis Taylor</category><category>Marc Benioff</category><category>Religion</category><category>Rya Jetha</category><category>So-called AI</category><category>Space Exploration</category><category>Von Neumann Probe</category></item><item><title>Wait&amp;hellip; We Needed That CNA Rule?! A Complaint =)</title><description>&lt;p&gt;It’s one of those rules you’d never think we needed until something happens…&lt;br/&gt;&lt;br/&gt;On March 27, a VulnDB (not to be confused with VulDB) analyst noticed that a CVE description had a line appended that basically advertised the service of the assigning CNA. CVE-2026-4963 had a pretty standard description from VulDB (not to be confused with VulnDB!) using their lackluster templating:&lt;br/&gt;&lt;br/&gt;“If you want to get…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/03/31/wait-we-needed-that-cna-rule-a-complaint/","display_url":"https://jericho.blog/2026/03/31/wait-we-needed-that-cna-rule-a-complaint/","title":"Wait… We Needed That CNA Rule?! A Complaint =)","poster":[{"media_key":"3fc77f41a70f14aa93ce5fcaa95ffdc6:9084ecd9a53221e9-96","type":"image/png","width":1376,"height":768}]}'&gt;&lt;a href="https://jericho.blog/2026/03/31/wait-we-needed-that-cna-rule-a-complaint/" target="_blank"&gt;Wait… We Needed That CNA Rule?! A Complaint =)&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/812616951236083712</link><guid>https://tumblr.attrition.org/post/812616951236083712</guid><pubDate>Tue, 31 Mar 2026 11:45:15 -0400</pubDate><category>CNA</category><category>CVE</category><category>Rules</category><category>Scott Moore</category><category>VulDB</category></item><item><title>Miggo, KEV, and FUD; They Still Don&amp;rsquo;t Get It</title><description>&lt;p&gt;[If the name ‘Miggo’ is familiar to you in the context of my blogging, you are thinking about one I wrote titled “Miggo Security’s AI Slop &amp;amp; Potential Trademark Infringement” in July, 2025. That was more around ‘corporate’ culture and bad lawyering. This blog is different, pointing out how they don’t seem to understand KEV at all.]&lt;br/&gt;&lt;br/&gt;On November 18, 2025, Miggo published a report titled “Missing…&lt;/p&gt;&lt;p class="npf_link" data-npf="{&amp;quot;type&amp;quot;:&amp;quot;link&amp;quot;,&amp;quot;url&amp;quot;:&amp;quot;https://jericho.blog/2026/03/30/miggo-kev-and-fud-they-still-dont-get-it/&amp;quot;,&amp;quot;display_url&amp;quot;:&amp;quot;https://jericho.blog/2026/03/30/miggo-kev-and-fud-they-still-dont-get-it/&amp;quot;,&amp;quot;title&amp;quot;:&amp;quot;Miggo, KEV, and FUD; They Still Don't Get It&amp;quot;,&amp;quot;poster&amp;quot;:[{&amp;quot;media_key&amp;quot;:&amp;quot;01781faf483adbf138bca3073f699de4:e16366ff0556b95a-8b&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;image/png&amp;quot;,&amp;quot;width&amp;quot;:2048,&amp;quot;height&amp;quot;:2048}]}"&gt;&lt;a href="https://jericho.blog/2026/03/30/miggo-kev-and-fud-they-still-dont-get-it/" target="_blank"&gt;Miggo, KEV, and FUD; They Still Don&amp;rsquo;t Get It&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/812525782326968320</link><guid>https://tumblr.attrition.org/post/812525782326968320</guid><pubDate>Mon, 30 Mar 2026 11:36:10 -0400</pubDate><category>EPSS</category><category>KEV</category><category>Miggo</category><category>Patrick Garrity</category><category>VulnDB</category><category>Vulnerability Statistics</category><category>Vulnerability Tourists</category></item><item><title>NaClCON Talks I Am Excited For</title><description>&lt;p&gt;Earlier this month, I published “My Unofficial NaClCON FAQ” talking about a new security conference that I am excited for. It’s still a bit surprising to myself that I am interested in one at all. I fully thought I was done with them, but here we are! After participating on the Call For Papers (CFP) team to help select speakers, I wanted to highlight some talks that sound great.&lt;br/&gt;&lt;br/&gt;First, the…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/03/27/naclcon-talks-i-am-excited-for/","display_url":"https://jericho.blog/2026/03/27/naclcon-talks-i-am-excited-for/","title":"NaClCON Talks I Am Excited For","poster":[{"media_key":"69940c4050b7b100d2f729ee57e8a8da:2d74e1c7528e2035-8e","type":"image/png","width":684,"height":457}]}'&gt;&lt;a href="https://jericho.blog/2026/03/27/naclcon-talks-i-am-excited-for/" target="_blank"&gt;NaClCON Talks I Am Excited For&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/812263821459800064</link><guid>https://tumblr.attrition.org/post/812263821459800064</guid><pubDate>Fri, 27 Mar 2026 14:12:24 -0400</pubDate><category>Chris Wysopal</category><category>conferences</category><category>Hackers</category><category>History</category><category>Lee Felsenstein</category><category>NaClCON</category><category>Richard Thieme</category><category>TNO</category></item><item><title>YouTube: I Don&amp;rsquo;t Think You Understand Your Userbase</title><description>&lt;p&gt;It’s pretty rare that I use YouTube on a television, typically only if in the mood for specific music. Even then it tends to be a handful of videos as my ‘go to’. Earlier this month I was in the mood for such a concert and loaded it. I am authenticated as my Google account, so YouTube knows exactly who I am. At the top of the screen are my recommendations:&lt;br/&gt;&lt;br/&gt;You can probably see exactly where I am…&lt;/p&gt;&lt;p class="npf_link" data-npf="{&amp;quot;type&amp;quot;:&amp;quot;link&amp;quot;,&amp;quot;url&amp;quot;:&amp;quot;https://jericho.blog/2026/03/24/youtube-i-dont-think-you-understand-your-userbase/&amp;quot;,&amp;quot;display_url&amp;quot;:&amp;quot;https://jericho.blog/2026/03/24/youtube-i-dont-think-you-understand-your-userbase/&amp;quot;,&amp;quot;title&amp;quot;:&amp;quot;YouTube: I Don't Think You Understand Your Userbase&amp;quot;,&amp;quot;poster&amp;quot;:[{&amp;quot;media_key&amp;quot;:&amp;quot;fa34794b47a97f760ab468660a2573f6:cf264fcf74bd25e5-fb&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;image/png&amp;quot;,&amp;quot;width&amp;quot;:1120,&amp;quot;height&amp;quot;:698}]}"&gt;&lt;a href="https://jericho.blog/2026/03/24/youtube-i-dont-think-you-understand-your-userbase/" target="_blank"&gt;YouTube: I Don&amp;rsquo;t Think You Understand Your Userbase&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/812011547900690432</link><guid>https://tumblr.attrition.org/post/812011547900690432</guid><pubDate>Tue, 24 Mar 2026 19:22:37 -0400</pubDate><category>Emu</category><category>UX</category><category>YouTube</category></item><item><title>The Jericho Blog Graveyard (2016 - 2020)</title><description>&lt;p&gt;This is a continuing short run series of blogs summarizing old drafts and either declaring them dead, while listing them here, or keeping them as they are still relevant.&lt;br/&gt;&lt;br/&gt;Part 1 – The Jericho Blog Graveyard (2010 – 2013)Part 2 – The Jericho Blog Graveyard (2014 – 2015)&lt;br/&gt;&lt;br/&gt;Part three:&lt;br/&gt;&lt;br/&gt;2016 – Extensive notes from a group chat at RBS about how bad the 2016 DBIR report was, numerous errors in it, and…&lt;/p&gt;&lt;p class="npf_link" data-npf='{"type":"link","url":"https://jericho.blog/2026/03/18/the-jericho-blog-graveyard-2016-2020/","display_url":"https://jericho.blog/2026/03/18/the-jericho-blog-graveyard-2016-2020/","title":"The Jericho Blog Graveyard (2016 - 2020)","poster":[{"media_key":"1db6f4e7ff20b7ba96aaea576f78b2a1:8d54cbfc2b0a89fe-14","type":"image/png","width":1408,"height":768}]}'&gt;&lt;a href="https://jericho.blog/2026/03/18/the-jericho-blog-graveyard-2016-2020/" target="_blank"&gt;The Jericho Blog Graveyard (2016 - 2020)&lt;/a&gt;&lt;/p&gt;</description><link>https://tumblr.attrition.org/post/811455467445485568</link><guid>https://tumblr.attrition.org/post/811455467445485568</guid><pubDate>Wed, 18 Mar 2026 16:03:58 -0400</pubDate><category>Blogging</category><category>Jericho</category></item></channel></rss>
