Mitch Herckis (@mherckis) 's Twitter Profile
Mitch Herckis

@mherckis

Public sector tech nerd through and through.

ID: 48359056

calendar_today18-06-2009 14:06:35

7,7K Tweet

961 Takipçi

1,1K Takip Edilen

Wiz (@wiz_io) 's Twitter Profile Photo

🎶 Our 'Winter Hacking Playlist' is here! We reached out to the biggest names in the industry to collect their fav tunes to listen to while hacking! John Hammond , Corey Quinn , chompie , Tanya Janca | Shehackspurple and many more... 🎵 'Hack-tivate' here: open.spotify.com/playlist/28b5H…

🎶 Our 'Winter Hacking Playlist' is here!

We reached out to the biggest names in the industry to collect their fav tunes to listen to while hacking! <a href="/_JohnHammond/">John Hammond</a> , <a href="/QuinnyPig/">Corey Quinn</a> , <a href="/chompie1337/">chompie</a> , <a href="/shehackspurple/">Tanya Janca | Shehackspurple</a> and many more...

🎵 'Hack-tivate' here: open.spotify.com/playlist/28b5H…
Wiz (@wiz_io) 's Twitter Profile Photo

🪄 HUGE NEWS: Welcome Fazal Merchant as our new CFO & President! Coming from leadership roles at DreamWorks and Tanium, Fazal joins us at an incredible time - as we hit our strongest quarter yet and approach our 5th birthday 🎂 45% of Fortune 100 companies trust us with their

Eric Geller (@ericgeller) 's Twitter Profile Photo

.White House Office of the National Cyber Director, the National Security Council, and the National Space Council have published a summary of the perspectives they heard from space industry participants during a series of space cyber workshops with domestic firms, foreign firms, and foreign govts: bit.ly/3DYdiK1

.<a href="/ONCD/">White House Office of the National Cyber Director</a>, the National Security Council, and the National Space Council have published a summary of the perspectives they heard from space industry participants during a series of space cyber workshops with domestic firms, foreign firms, and foreign govts: bit.ly/3DYdiK1
Nicholas Bagley (@nicholas_bagley) 's Twitter Profile Photo

Time for a periodic reminder that the vast majority of executive orders are nothing more than gussied up memos asking subordinates to do stuff. Most EOs lead with strong rhetoric, but close with a milquetoast instruction to act "as soon as practicable" or "as appropriate."

Life of a Philly Fan (@phillyfanlife) 's Twitter Profile Photo

LMAO this could be an episode in Its Always Sunny The Bayou in Manayunk was listed as a Commanders fan bar on the official Commanders site, without the Bayou even knowing about it

Nagli (@galnagli) 's Twitter Profile Photo

Critical vulnerabilities doesn't have to be complex or have a CVE - DeepSeek publicly exposed their internal ClickHouse database to the world, without any authentication at all, and leaked sensitive data. No one is safe from security mistakes, follow along to learn more 🧵

Critical vulnerabilities doesn't have to be complex or have a CVE - <a href="/deepseek_ai/">DeepSeek</a> publicly exposed their internal ClickHouse database to the world, without any authentication at all, and leaked sensitive data.

No one is safe from security mistakes, follow along to learn more 🧵
Victor Brandon Dover (@victordover) 's Twitter Profile Photo

R.I.P. Donald Shoup, 1938-2025. Prof. Shoup's influential 2005 book The High Cost of Free Parking confirmed our long-held suspicions: parking policies are wrecking cities. He emboldened us & thousands of other urbanists to call for undoing ridiculous minimum parking regulations.

R.I.P. Donald Shoup, 1938-2025. Prof. Shoup's influential 2005 book The High Cost of Free Parking confirmed our long-held suspicions: parking policies are wrecking cities. He emboldened us &amp; thousands of other urbanists to call for undoing ridiculous minimum parking regulations.
Nir Ohfeld (@nirohfeld) 's Twitter Profile Photo

Thrilled to finally share this—one of the coolest container escapes I’ve seen! 🔥 wiz.io/blog/nvidia-ai… A subtle logic bug that lets you break out to the host on ANY NVIDIA GPU-supported container 🤯 Can’t believe we had to sit on the technical details for so long! Incredible

Rami McCarthy (@ramimacisabird) 's Twitter Profile Photo

📰 EXTRA EXTRA New news on Github Actions security! We (the wiz research team) have followed up our work on the tj-actions/changed-files incident by discovering an additional compromised Action reviewdog/action-setup@v1 was malicious for 2 hours on March 11th

📰 EXTRA EXTRA

New news on Github Actions security! 

We (the <a href="/wiz/">wiz</a> research team) have followed up our work on the tj-actions/changed-files incident by discovering an additional compromised Action

reviewdog/action-setup@v1 was malicious for 2 hours on March 11th
Nir Ohfeld (@nirohfeld) 's Twitter Profile Photo

We (+sagitz Ronen Shustin Hillai Ben-Sasson) found a series of unauthenticated RCEs in core @KubernetesIO project "Ingress-NGINX". The impact? From zero permissions ➡️ to complete cluster takeover 🤯 This is the story of #IngressNightmare 🧵⬇️

We (+<a href="/sagitz_/">sagitz</a> <a href="/ronenshh/">Ronen Shustin</a> <a href="/hillai/">Hillai Ben-Sasson</a>) found a series of unauthenticated RCEs in core @KubernetesIO project "Ingress-NGINX".

The impact?

From zero permissions ➡️ to complete cluster takeover 🤯

This is the story of #IngressNightmare 🧵⬇️
Wiz (@wiz_io) 's Twitter Profile Photo

🎥 How is AI reshaping cybersecurity? 85% of Wiz customers already use #AI, yet many security teams still struggle to understand the risks. At #GTC, alon breaks down how AI Agents are changing the game. Big thanks to NVIDIA for hosting this critical conversation.

Rami McCarthy (@ramimacisabird) 's Twitter Profile Photo

In light of recent GitHub Actions incidents (Ultralytics, tj-actions...), I wrote up a practical guide to hardening for Wiz Covers permissions, secrets, 3rd-party Actions, ++ Use it to avoid learning these lessons the hard way: wiz.io/blog/github-ac…