Founder/Chief Analyst, Cernivera Research. Cybersecurity industry analyst, researcher & consultant. Snark warning always in effect.

Joined January 2012
76 Photos and videos
A question I'd ask @FBIDirectorKash at his next presser: "The ShinyHunters cybercrime syndicate has now breached 1000s of orgs, extracted 10s of millions in ransom & caused billions in damage over 7.5 years. What is @FBI doing to bring them to justice?" cernivera.com/2026/free-exec…
35
It's good to be back. cernivera.com #analystlife
19
.@RSAConference USA is officially bigger than ever: #RSAC2025 final attendance is just under 44k (43,500 ), up from 41k attendees in 2024 & topping the previous all-time high of 42,500 in 2019. Also #RSAC2026 will be in calendar Q1, slated for March 23-26 in SF. #RSAC
2 May 2025
#RSAC™ Conference Wraps 34th Annual Flagship Event with Many Voices, One Community. Read more: spr.ly/60102LUt2
1
79
28 Apr 2025
As #RSAC2025 begins, here's a great snapshot of what adversaries are now focused on, and in turn what CISOs should be pivoting to detect & prevent.
We’re seeing a clear trend: attackers are bypassing the endpoint entirely. Not just avoiding traditional EDR-monitored systems by pivoting to embedded and edge devices, but now also operating purely in the cloud. No shell, no malware, no persistence on the endpoint. Just an OAuth token and full access to whatever’s in the victim’s Microsoft 365, Google Workspace, or AWS console. It’s a complete inversion of how things used to be. The endpoint, once the weakest link, is now usually the most monitored, most policy-enforced part of the infrastructure. You’ve got EDRs, SIEM integration, automation, threat hunting - the full stack. But attackers don’t need to touch it anymore. Instead, they go after the new soft spots: - Cloud platforms, where logging is limited, expensive, or off by default - Network devices and appliances, which are practically blind spots - obscure OSes, no EDRs, hard to monitor, hard to forensicate. - Embedded systems and IoT junk that no one really knows how to secure, but that sit in critical network paths. Cloud especially is a mess: - Logging tiers cost extra and the good stuff is behind paywalls. - Detection content is lacking, both from vendors and the community. - You don’t get memory dumps or full control like you do on endpoints. - You’re at the mercy of the provider when it comes to visibility and response. And that’s the shift: attackers aren’t hacking computers anymore. They’re hacking trust relationships, identities, and APIs. The whole idea of detection and response needs to evolve with that. Otherwise, we’re securing the hell out of endpoints while attackers happily fish through mailboxes and cloud shares from halfway across the planet.
37
25 Apr 2025
Best wishes to everyone attending #RSAC 2025 next week. I will be focusing on my new role, but will miss many friends, colleagues, and the buzz of the event. I will *not* miss making lap after lap in and around Moscone on foot!
41
16 Apr 2025
One of the scariest phishing attempts I’ve seen in a long time. Good that Google has agreed to fix the root vulnerability, but in the meantime, be careful.
Recently I was targeted by an extremely sophisticated phishing attack, and I want to highlight it here. It exploits a vulnerability in Google's infrastructure, and given their refusal to fix it, we're likely to see it a lot more. Here's the email I got:
32
Super cute marketing/training effort coming up next week from @immersivelabs "Christmas Tree-Son" Virtual Crisis Simulation: "Immerse yourself in a unique and engaging crisis scenario set against the backdrop of the North Pole." info.immersivelabs.com/chris…
41
Important new primary research: The app for your internet-connected litter box should NOT require your wifi network password for connectivity. (Manufacturers should ensure the device can connect directly and securely w/o an app. Software is always the weakest link!) #IoTsecurity
44
19 Nov 2024
Great quote from special guest Venus Williams, borrowed from Billie Jean King: “Pressure is a privilege… it means that you’re doing things and going places.” #opentextworld
2
102
19 Nov 2024
Barrenechea commits @OpenText to masking all of its data and eliminating passwords in favor of biometric authentication over the next two years. #OpenTextWorld
19 Nov 2024
Barrenechea on integration: "With enterprise security you need to compose a solution. No company can do it all. All the (technology) partners in your ecosystem throw off security events, so you have to do it in a composable way, connecting disconnected islands." #OpenTextWorld
1
118
19 Nov 2024
Barrenechea on integration: "With enterprise security you need to compose a solution. No company can do it all. All the (technology) partners in your ecosystem throw off security events, so you have to do it in a composable way, connecting disconnected islands." #OpenTextWorld
19 Nov 2024
Barrenechea on @OpenText security strategy: "We’re here to make security as important as anything we do... We think it’s no longer human vs machine, it’s machine vs machine." #OpenTextWorld
187
19 Nov 2024
Barrenechea on @OpenText security strategy: "We’re here to make security as important as anything we do... We think it’s no longer human vs machine, it’s machine vs machine." #OpenTextWorld
19 Nov 2024
It is notable that security is the dominant theme in the @OpenText multicloud integration strategy. #opentextworld
127
19 Nov 2024
It is notable that security is the dominant theme in the @OpenText multicloud integration strategy. #opentextworld
19 Nov 2024
The full quote for accuracy (had to cut too much for the X word limit):
95
19 Nov 2024
The full quote for accuracy (had to cut too much for the X word limit):
19 Nov 2024
Barrenechea on AI: “Agents are going to make decisions on your behalf. This is going to make us uneasy... would you let a piece of software do that? I think you will, and we’ll give you the tools to do it.” #OpenTextWorld
215
19 Nov 2024
Barrenechea on AI: “Agents are going to make decisions on your behalf. This is going to make us uneasy... would you let a piece of software do that? I think you will, and we’ll give you the tools to do it.” #OpenTextWorld
19 Nov 2024
Barrenechea: "We’re going to continue to extoll that security is job one… built all the way into the software, and it needs to work across multicloud." #OpenTextWorld
76
19 Nov 2024
Barrenechea: "We’re going to continue to extoll that security is job one… built all the way into the software, and it needs to work across multicloud." #OpenTextWorld
19 Nov 2024
I really like how @OpenText CEO/CTO Mark Barrenechea highlights the value of #AI in the enterprise in his opening keynote: "Every organization has two proprietary gifts: talent and data... AI transforms the value of both of those gifts." #OpenTextWorld
87
19 Nov 2024
I really like how @OpenText CEO/CTO Mark Barrenechea highlights the value of #AI in the enterprise in his opening keynote: "Every organization has two proprietary gifts: talent and data... AI transforms the value of both of those gifts." #OpenTextWorld
19 Nov 2024
Pleased to spend time with @OpenText & @OpenTextSec this week at #opentextworld Key Qs: Is this *really* a security company vs an information management co w/ security? Has the Micro Focus deal/integration been a force multiplier? @OmdiaCyber
101
19 Nov 2024
Pleased to spend time with @OpenText & @OpenTextSec this week at #opentextworld Key Qs: Is this *really* a security company vs an information management co w/ security? Has the Micro Focus deal/integration been a force multiplier? @OmdiaCyber
1
2
108
24 Oct 2024
Hot take: It's 2024. No one should be looking at comparative research on EPP to guide their endpoint security buying decisions. #EDR #XDR
35