Ben Rothke
benrothke.bsky.social
Ben Rothke
@benrothke.bsky.social
I do information security, risk management and other tech stuff.
Co-author of new book: The Definitive Guide to PCI DSS Version 4: Documentation, Compliance, and Management.
https://amzn.to/3WhEfh1

How do you know if the call about vacations is a scam? If you get a call about a #vacation, #timeshare, or #cruise, it’s 100% a #scammer. Hang up & avoid the #scam. Even the Mexican drug cartel is now doing vacation #scams. Legit firms won’t call you.
brothke.medium.com/how-to-tell-...
How to tell if the telephone call you received about a vacation is a scam or not.
Vacation scams are a goldmine
brothke.medium.com
November 19, 2025 at 5:07 PM
Black Friday 2025 carries high risk of widespread fraud, ranging from hundreds of thousands of fake accounts to large-scale account takeovers. #AI threats becoming a significant risk. Much of e-commerce industry lacks basic #infosec controls.. api.cyfluencer.com/s/security-a...
api.cyfluencer.com
November 19, 2025 at 3:57 PM
Reposted by Ben Rothke
🔏𝗡𝗲𝘄 𝗥𝗲𝘃𝗶𝗲𝘄 𝗗𝗿𝗼𝗽 📖

Jeny Teheran discusses why Dr. Susan Landau’s 𝙇𝙞𝙨𝙩𝙚𝙣𝙞𝙣𝙜 𝙄𝙣 is a must-read exploration of privacy, encryption, and the ongoing struggle over government access to secure systems, recommending it for the CyberCanon Hall of Fame.

📝Review: cybercanon.org/listening-in...

(1/2..)
November 19, 2025 at 1:23 PM
Ferocious Kitten is a covert cyber-espionage actor active since 2015 focused on Persian-speaking targets inside #Iran, uses politically themed decoy documents to trick dissidents, activists & other individuals to opening weaponized files.
cybersec.picussecurity.com/s/ferocious-...
Ferocious Kitten APT Exposed: Inside the Iran-Focused Espionage Campaign
Discover how Ferocious Kitten’s MarkiRAT malware targets Persian-speaking users and learn how Picus helps defend against this cyber-espionage threat.
cybersec.picussecurity.com
November 11, 2025 at 5:20 PM
Reposted by Ben Rothke
👩‍💻𝗜𝘁'𝘀 𝗥𝗲𝘃𝗶𝗲𝘄 𝗗𝗮𝘆!🧠

This week, Kevin Magee provides a Hall of Fame recommendation for Sarah Armstrong-Smith’s 𝙐𝙣𝙙𝙚𝙧𝙨𝙩𝙖𝙣𝙙 𝙩𝙝𝙚 𝘾𝙮𝙗𝙚𝙧 𝘼𝙩𝙩𝙖𝙘𝙠𝙚𝙧 𝙈𝙞𝙣𝙙𝙨𝙚𝙩

Read why he believes it will help you "transform your response to threats" ➡️ tinyurl.com/56nzxp5z

#CISO #SecurityAwareness #ThreatIntelligence
November 4, 2025 at 3:31 PM
Reposted by Ben Rothke
🧠 New CyberCanon review!

Jeffrey Pierdomenico dives into Mark Bailey’s Unknowable Minds, exploring AI, ethics, and security.

“Putting humanity above all else” has never felt more urgent.

🔗 cybercanon.org/unknowable-minds

From: @imprintacademic.bsky.social

#AIsecurity #CybersecurityBooks
October 28, 2025 at 2:35 PM
#Zerodayx1 is a likely Lebanese hacktivist who positions themselves as Muslim & pro-Palestinian threat actor. It launched its own Ransomware-as-a-Service (#RaaS) operation. It shows how financial gain is integrated into hacktivist objectives. api.cyfluencer.com/s/zerodayx1-...
zerodayx1: Hacktivist groups turning to ransomware operations
Learn how hacktivist group zerodayx1 launched its own Ransomware-as-a-Service (RaaS) operation.
api.cyfluencer.com
September 29, 2025 at 9:53 PM
Interesting new framework from Pillar. Their SAIL (Secure AI Lifecycle) Framework is designed to manage AI-specific risks and build trustworthy AI systems.
The 11 risk categories detail the many threats and vulnerabilities inherent in AI deployments.

api.cyfluencer.com/s/build-your...
SAIL Framework: A Practical Guide for AI Security
The SAIL Framework, co-developed with industry leaders, is a process-oriented guide to build your AI security roadmap, aligned with standards like NIST, ISO & OWASP.
api.cyfluencer.com
September 9, 2025 at 4:02 PM
Bots are spelling the demise of @X. Massive amounts of misinformation, stock fraud, scams & more. Latest #scam is a Twitter reply directing one to a supposed financial expert. Which they're clearly not. They are just automated bots looking to bankrupt you. brothke.medium.com/bots-are-spe...
Bots are spelling the demise of X
Bots from scammers and fraudsters are contaminating the platform.
brothke.medium.com
September 9, 2025 at 3:02 PM
I wrote this piece about #Boardsi over 9 months ago, how even those on the Boardsi testimonials page did not find value with them. In those 9 months, not a single person has told me that I was wrong, and that they, in fact, did obtain a board position.
brothke.medium.com/get-on-a-boa...
Get on a board — but maybe not with Boardsi
Can Boardsi really get you a six-figure board and advisory positions like they claim?
brothke.medium.com
August 26, 2025 at 7:37 PM
If there’s a correlation between antisemitism & bad #infosec controls & @Columbia is the poster child. They did zero as #Jewish & #Zionist students were attacked by #Hamas supporters, & their cybersecurity failure is of historic proportion.
api.cyfluencer.com/s/columbia-u...
Columbia University’s Costly Lesson in Data Security
Learn about the Columbia University security breach and its implications for data protection in academic institutions today.
api.cyfluencer.com
August 26, 2025 at 7:32 PM
Hardly a day goes by without an article about ‘millions’ of open information security jobs. But the notion of millions of #infosec jobs is preposterous. How can you know how many #cybersecurity jobs there are if there’s no real statistical data available?
brothke.medium.com/the-big-lie-...
November 28, 2023 at 10:59 PM
Many communication breakdowns when it comes to #infosec. 10 really good tips from @XMCyber_ to get security/non-security teams on the same page. This one may go the farthest: Give kudos when other teams accomplish goals & make sure management knows, too. cybersec.xmcyber.com/s/10-tips-to...
August 30, 2023 at 8:12 PM
Hey @facebook: the 'look who died' & ‘just passed away’ scams have been spreading like wildfire on #Facebook. I’d estimate it would take a programmer an hour & 100 lines of code to block these #phishing #scams to your billions of users. It’s a really easy #infosec fix. Thoughts?
August 30, 2023 at 7:22 PM
Have you gotten a wrong number text? Someone’s contact list doesn’t need updating. It's from well-organized & sophisticated international scam operations. They want you to invest in #cryptocurrency & promise massive profits. But you’ll have 1 massive loss.
Wrong number texts — a brilliant yet simple attack vector
In the world of information security, there are many cutting-edge attacks. Like the one out of Israel, researchers from Ben-Gurion…
brothke.medium.com
July 21, 2023 at 4:57 PM
Reposted by Ben Rothke
Give back to the #InfoSec community by writing a review of a book, fiction or non-fiction, that you think every #cybersecurity professional should read! 🤓

Learn more about writing a book review for the Cybersecurity Canon here📚
https://icdt.osu.edu/news/2020/08/want-submit-review
July 21, 2023 at 4:41 PM
It’s the end of an era with the demise of #CentOS. Lior Ben Dayan of @VulcanCyber details what the death of @CentOS means for security. Everything you need to know, including the measures you can take. https://cybersec.vulcan.io/s/what-the-death-of-centos-means-for-security-9580 #infosec
July 5, 2023 at 7:16 PM
Check out a new book I cowrote: The Definitive Guide to PCI DSS Version 4: Documentation, Compliance, and Management. Hopefully it can help people here on their PCI journey.  #PCI #DSS https://amzn.to/3WhEfh1
July 4, 2023 at 1:50 AM