Oh, the irony.. CISA — the agency responsible for telling everyone else how to secure their infrastructure — reportedly had internal cloud credentials, deployment files, Terraform configs, and plaintext passwords exposed in a public GitHub repository:
covertaccessteam.substack.com/p/cisa-just-pu…
Most operators are comfortable when they have backup. Our SOLO course is about what happens when you don’t.
When you’re operating alone, every mistake belongs to you.
Next course: June 20-21, 2026 | Virtual | €1500 | 12-20 CEST
Learn more: covertaccessteam.com/strategic-oper…
Attackers are now using Microsoft Teams chats to socially engineer employees into infecting their own systems with malware.
This article breaks down:
— how the fake IT support chats work
— why Teams makes the attack feel legitimate
& more
Read here: covertaccessteam.substack.com/p/attackers-ar…
Most companies prepare for physical attacks as if someone's sneaking in a window at night.
But the most dangerous attacker is often the one everyone assumes belongs.
Let's break down why physical intrusions almost always evolve into insider threats:
covertaccessteam.substack.com/p/the-insider-…
We want people to leave our courses able to immediately apply what they learned in the real world.
One student in latest PACT course said: “I came away feeling much more confident and prepared.”
Overall, students rated it a 9.6/10!
Next course: covertaccessteam.com
John-André Bjørkhaug has been developing specialized physical pentesting equipment focused on real-world PACS attacks, RFID exploitation, tamper bypasses & Wiegand interception.
This article takes a look at some of John’s equipment: covertaccessteam.substack.com/p/john-andre-b…
Most physical pentest training assumes you have a team. What if you’re running solo?
Our SOLO course is built specifically for experienced black teamers who need to plan, execute, adapt & problem-solve entirely on their own in high-pressure environments: covertaccessteam.com/strategic-oper…
Federal prosecutors say a Chinese aerospace engineer spent years impersonating trusted U.S. researchers to obtain restricted NASA and military aerospace software.
Not through malware. Not through zero-days. Through trust. Learn more:
covertaccessteam.substack.com/p/chinese-engi… | #CyberSecurity
A local sports celebrity. A believable pretext. One social engineer inside a bank.
Patrick Laverty breaks down how OSINT, authority, and human behavior mattered far more than “breaking in” on this Covert Access Team Podcast episode: covertaccessteam.substack.com/p/interview-wi…
🚨 Last chance to join this weekend’s Physical Audit Certification Training (PACT) course.
We won’t have another PACT course until November, so now’s your chance.
Learn professional physical security audit methodology from experienced practitioners: covertaccessteam.com/physical-audit…
Ana Montes spied for Cuban intelligence for nearly two decades while working as a senior DIA analyst. She allegedly avoided many traditional data exfiltration indicators by using one of the oldest methods in espionage: Memory.
Full story: covertaccessteam.substack.com/p/could-you-sp…
Toronto Police just announced the first known SMS blaster case in Canada.
According to investigators, the attackers used mobile rogue cellular infrastructure to force nearby phones onto fake networks & push phishing texts directly into victims’ devices: covertaccessteam.substack.com/p/toronto-poli…
Spend this weekend getting certified to perform physical security audits 💪
There’s still time to join this weekend’s PACT course covering physical security assessments, covert entry, social engineering & real-world audit methodology.
Learn more:
covertaccessteam.com/physical-audit…
Brian sits down with Alex Cole, the creator of Fitted, a new physical security tool built around a problem every physical pen tester understands: finding repeatable ways to exploit real-world access control assumptions.
Listen on Youtube: youtu.be/tENt9DesK9E?si…
Most new physical pentesters want to jump right into physical pentests. For beginners, that’s usually a mistake. That’s why we built the Physical Audit Certification Training. Audits help you learn the fundamentals.
Join our next PACT course May 23-24: covertaccessteam.com/physical-audit…
Federal prosecutors say a crew in Michigan moved ~400 high-end vehicles worth around $40M through a coordinated theft and export pipeline.
Local theft → staging lots → shipping containers → rail/freight → overseas.
Read the full post: covertaccessteam.substack.com/p/gone-in-60-s…
🚨 Covert Access Team is offering free physical security penetration tests and audits to a limited number of European companies. 🚨
Interested? Email [email protected] to learn how your company can be considered.
#CyberSecurity#PenTesting#PhysicalSecurity
Most teams waste recon time. Not because they’re lazy—but because they don’t know what “done” looks like.
Let's break down how we structure recon across OSINT, long range, short range, and embedded—and what you should accomplish before moving closer: covertaccessteam.substack.com/p/recon-playbo…
778 Followers 5K FollowingPENTESTER#CybserSecurity research in #Automotive #IoT #WirelessComm #SourceCodeAudit #AppSec noob and actively learning #AIML in CyberSecurity domain.
79 Followers 2K FollowingA caring female entrepreneur and charity agent. Focusing on women's health care and maintenance, Estee Lauder partner agent, Sephora partner agent.
15 Followers 2K FollowingOperations and Technology professional, passionate about helping companies solve their most pressing problems and implement state-of-the-art solutions.
119 Followers 1K FollowingCrypto / US equity Trading
#Letterology #GematriaClub #cuelifetime | studying under OM (WD Gann)
Bridge between the seen and the unseen worlds
165 Followers 1K FollowingGenerative AI Security Testing and AI Enthusiast | Experienced in Offensive Security Consulting | Red Teaming | Penetration testing | Cloud Security
949 Followers 1K FollowingVintage IT guy with passion for cyber and physical security, games, long distance swimmer. BTW, my tweets are wrote by superior AI out of my control…
350K Followers 15K FollowingMulti-award winning 🏆 Online Media House of the Year ’25 + Most Informative Publication ’24. Independent nonprofit. People-driven news. Tip-offs: 082 766 9991
215K Followers 76 FollowingOne guy. Global cybercrime. Tracked so you don't have to. Ransomware, data breaches, dark web activity, darknet markets, IOCs & emerging threats. Stay informed!
204K Followers 0 FollowingWe make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!
3.5M Followers 2K FollowingSubscribe to American Swiper Series👇. Guerrilla Journalist. CEO of O’Keefe Media Group, Founder, Project Veritas (CEO ‘09-‘22) SIGNAL: 9144919395
337K Followers 3K FollowingHackerOne makes security continuous.
We unite AI and human insight through a unified platform to expose risk and eliminate it.
329K Followers 118 FollowingEmpowering the world to fight cyber threats with indispensable cybersecurity skills and resources.
Support queries: https://t.co/HtFpqjjlRZ
199K Followers 6K FollowingThe leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
124K Followers 3K FollowingRapid7 is a leader in AI-powered managed cybersecurity operations. 11,500+ customers utilize Rapid7 to disrupt attackers and advance their cyber resilience.
253K Followers 182 FollowingOfficial account of the Metasploit Project, part of the @rapid7 family.
Mastodon: @[email protected]
Slack: https://t.co/ZOLPDG2O2s
216K Followers 525 FollowingWe improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
78K Followers 763 FollowingEnd-to-end Cybersecurity consulting team leading the industry, supporting organizations, and giving back. #Hacktheplanet
Blogs, news, webinars, and tools!
9K Followers 293 FollowingI hack, I think, I question, I offend. Follow @internetofdongs for my other project and @murdoch_monkey for lulz. https://t.co/7BVh73fARQ
10.2M Followers 105 FollowingThe first word in business news | Watch Live: https://t.co/nHEpHOAfg3 | Newsletters: https://t.co/nWaCxHTiks | Podcasts: https://t.co/096e9xMJF7
57K Followers 874 FollowingBuilding communities one event at a time. Thirteen years, over eight hundred events, and we're just getting started.
@[email protected]
6K Followers 235 FollowingNCC Group North America security consulting. Find our Corporate Global Account here: @NCCGroupPLC and our everything tech account here: @NCCGroupInfosec
45K Followers 985 FollowingStalwart defender of Oxford commas, two spaces after a period, and ellipses. When they ask how I died, tell them... still happy.
(he/they)
408K Followers 0 FollowingDenne profil er ikke længere aktiv. Vi henviser til POLITI UPDATE på https://t.co/qklU76EwnY og politiets hjemmeside på https://t.co/whCQJUyNKy.
21.5M Followers 1K FollowingSign up for our newsletters and alerts: https://t.co/QevH0DLQi8 | Got a tip? https://t.co/iXIigdPjEZ | For WSJ customer support: https://t.co/DZgH9n53qg
198K Followers 14K FollowingWe help professionals acquire the skills, knowledge and certificates by teaching defense through offense to advance their careers in cybersecurity.