security_craig Profile Banner
Craig Profile
Craig

@security_craig

Followers
8K
Following
6K
Media
688
Statuses
10K

Head of Threat Intelligence Engineering @ Amazon | Former Director Talos | Distinguished Speaker Hall of Fame | Reformed Podcaster | Bug Hunter | My Opinions

ヽ(`Д´)ノ
Joined April 2013
Don't wanna be here? Send us removal request.
@security_craig
Craig
4 months
Someone is excited to hear about the latest email bugs @CYBERWARCON 🦎
0
4
10
@security_craig
Craig
7 months
Getting the team ready for @SLEUTHCON again!
1
2
8
@security_craig
Craig
10 months
Now Hiring: Senior SDE (Level 5) in Austin! Join Amazon's Cyber Threat Intelligence team building mission-critical systems to protect Amazon's global infrastructure & customers. Scale, architecture, security - all the good stuff Apply:
0
1
5
@security_craig
Craig
11 months
Join the Amazon Threat Intelligence Team. We are hiring a Software Development Engineer (SDE) to support our engineering platforms. We build threat intelligence tools for all of Amazon. Made a difference at scale. Details - https://t.co/iTtc1x6bGm
0
1
4
@security_craig
Craig
1 year
🎄🤖🥳
@RGB_Lights
Rob Joyce
1 year
Christmas Robot was easily the favorite song in our holiday light show this year. It's an earworm!
0
0
1
@security_craig
Craig
1 year
Always interesting to see old techniques cross streams with modern technology
@androidmalware2
Mobile Hacker
1 year
Unusual Android malware distribution vector - physical analog letter ✉️ Fake letters were sent to people at their home addresses to download "Severe Weather Warning App" via the attached QR code. #Coper AKA #Octo2 banking malware is downloaded instead https://t.co/kRpPGA9sLu
0
0
0
@security_craig
Craig
1 year
Join Amazon's Threat Intelligence Team as an SDE. Build platforms using diverse tech to support security missions. Work with analysts, understand customer needs, and contribute to Amazon's security culture. Help protect our customers. https://t.co/uWECnY3bxl
0
1
1
@security_craig
Craig
1 year
My personal view is that it depends. If the machines are broadly vulnerable they are already targeted. The trick is most of the time in order to be effective across a baddie campaign this must be done @ scale. That's really where gov assistance and industry partnerships can shine
@RGB_Lights
Rob Joyce
1 year
I hear hack back as a solution to intrusions, and disagree. Compromised machines in friendly/ neutral countries will be targeted, risking harm to innocents. The diplomatic implications are already severe. Hack back is inherently a governmental function. Cyber doesn’t stop cyber.
0
0
0
@security_craig
Craig
1 year
There is no fix or parental control to stop this at this point. I just have to remove it from their device or take it. Seems like it should be a pretty easy fix ¯\_(ツ)_/¯
0
0
5
@security_craig
Craig
1 year
Katie's 3rd bug - If you set an apple device's date into the future or past (ancient 1980s) screen time breaks and they can play roblox until their eyes bleed. Apple assures me this isn't a security issue since screen time is not intended to protect against device manipulation.
1
5
24
@security_craig
Craig
1 year
Join Amazon's Threat Intelligence team! We're hiring an SDE to build platforms that power security missions, understand customer needs, and enhance Amazon's security culture. Leverage open-source, AWS, and vendor tech to protect customers. Apply now!
0
1
2
@security_craig
Craig
1 year
Is there a god of uptime?
1
0
0
@security_craig
Craig
1 year
My precious wagyu was never at risk, temp was actually in the zone
0
0
2
@security_craig
Craig
1 year
I use a computer to control my smoker when I sleep, somehow the memory got fairly corrupted. Alarms went off saying my cook hit 200k f. Is it weird I wonder if someone's heap spray broke before it occurred to me my ram is going bad.
3
0
11
@security_craig
Craig
1 year
Join the Amazon threat intelligence team. Help us build epic automation and data pipelines to make our tools more effective in hunting threats and adversaries. https://t.co/uWECnY3JmT
0
3
7
@security_craig
Craig
1 year
Spoiler - screen time is not intended to protect against device manipulation and thus this isn’t a security issue
@security_craig
Craig
1 year
My 11 year old found yet another full screen time bypass. I submitted it for her. Anyone know if they give a bounty or a shout out for these? The previous one was known by the time I submitted it for her.
0
0
0
@security_craig
Craig
1 year
My 11 year old found yet another full screen time bypass. I submitted it for her. Anyone know if they give a bounty or a shout out for these? The previous one was known by the time I submitted it for her.
0
2
9
@RGB_Lights
Rob Joyce
1 year
Always great to be on the Risky Business podcast! YouTube: https://t.co/sBJlDpu03k Podcast: https://t.co/uZJvZBf5Ql
2
10
62
@security_craig
Craig
1 year
My kid figured out another screen time bypass. The time setting is not a protected option. At 10pm you can set it to 7am and unlock the device 🙄
0
0
7