ZackKorman Profile Banner
Zack Korman Profile
Zack Korman

@ZackKorman

Followers
3K
Following
17K
Media
1K
Statuses
18K

CTO @ Pistachio. I build AI cybersecurity stuff.

Oslo, Norway
Joined January 2014
Don't wanna be here? Send us removal request.
@ZackKorman
Zack Korman
2 months
Microsoft isn’t disclosing this so: M365 Copilot allowed users to access files without producing an audit log. All you had to do was ask Copilot to not link to the file. You don’t even have to ask; it sometimes just happens. If your org uses Copilot your audit log is likely wrong
@ZackKorman
Zack Korman
2 months
Microsoft isn’t just not issuing a CVE, they’re actually not going to disclose this issue at all.
28
582
4K
@ZackKorman
Zack Korman
9 hours
Don’t worry SOC analysts, AI isn’t going to take your job just yet.
10
8
168
@ZackKorman
Zack Korman
19 hours
Every single person who replied “guide” to this should be permabanned to the shadow realm (LinkedIn)
@ankurnagpal
Ankur Nagpal
1 day
This is the most valuable resource I have ever created I wrote a brand new, extremely detailed Notion guide on every single strategy to save money on taxes The best of my content in a single place Want a free copy? - Like / RT this post - Reply with "GUIDE" and I'll DM you
2
0
15
@ZackKorman
Zack Korman
19 hours
Think you’re going to exfiltrate company data from the inside? This guy and a couple billion Gemini tokens are going to catch you.
6
0
35
@ZackKorman
Zack Korman
1 day
Apparently $1/user/month is considered a massive investment.
@Nitin_Dahiya_1
Nitin
1 day
Even after massive investments in cybersecurity training, social attacks still lead among all attacks. Technology evolves, but human still remains weakest link.
1
0
14
@ZackKorman
Zack Korman
1 day
If you don’t know how, it’s a button in Purview that always seems to move every time I look. Just go there and click around randomly until you find it.
2
1
19
@ZackKorman
Zack Korman
1 day
Please turn on automatic sensitivity labels for emails. The “cost” is that users will see a little orange shield in Outlook. The benefit is that your audit log becomes actually useful.
7
8
132
@ZackKorman
Zack Korman
2 days
Ngl, all the other parts of cybersecurity I’ve come across are lowkey easy. I thought it’d be the same for malware. It’s just code, and I know code. Turns out they don’t even give you the code!
5
0
39
@ZackKorman
Zack Korman
2 days
Dear @Fortinet post token use
0
1
2
@ZackKorman
Zack Korman
2 days
Hey @TrendMicro post token use
1
1
3
@ZackKorman
Zack Korman
2 days
I’ll go first. Today Presence used about 60m tokens so far. Not a lot, but enough to prove we’re doing a real thing given that we launched only a few days ago.
1
0
2
@ZackKorman
Zack Korman
2 days
Should I start tagging vendors to ask them to post token use?
2
0
8
@ZackKorman
Zack Korman
2 days
Any cybersecurity vendor claiming “AI threat detection” should have to post their token usage.
2
1
24
@ZackKorman
Zack Korman
3 days
Never make a joke about AI or they’ll ruin your feed with whatever the hell this is until you repent. I’m sorry @nikitabier I promise I won’t do it again I just want cybersecurity content back.
4
0
27
@ZackKorman
Zack Korman
4 days
Copilot in Excel is a global financial crisis waiting to happen.
462
4K
61K
@ZackKorman
Zack Korman
5 days
Went ahead and bought evilmcp[.]com so I can make an evil mcp server for fun.
@ZackKorman
Zack Korman
5 days
People are worried about protecting against prompt injections while using MCP tools. My brother in christ, MCP is a prompt injection.
5
1
35
@ZackKorman
Zack Korman
5 days
People are worried about protecting against prompt injections while using MCP tools. My brother in christ, MCP is a prompt injection.
5
6
58
@ZackKorman
Zack Korman
6 days
Way more companies than expected turned on the free trial, so it turns out finance team might be right.
@ZackKorman
Zack Korman
13 days
4 days until launch. Or as our finance team puts it: 4 days until Zack bankrupts us with Google Cloud.
7
2
57
@ZackKorman
Zack Korman
6 days
The design team has figured out that if they ask permission I’ll say no, but if they just do it I’ll appreciate it. (Mine has blue Powerade because that’s the only thing I drink)
1
0
10
@ZackKorman
Zack Korman
7 days
The end. I think of this every single Christmas now, and probably will for many years to come.
0
0
10
@ZackKorman
Zack Korman
7 days
After that, I put down some serious processes. One person takes lead. Another takes communication. Designated people who can report issues, to avoid the flood of chaos. We ran those processes dozens of times after, and never had an issue like this again.
1
0
14