Zoë Rose
banner
rosesec.bsky.social
Zoë Rose
@rosesec.bsky.social
#mumSec
One day, you’re braving the cold Canadian winters in a little black dress…

The next, you’ve acclimatised to European weather, and walking around the house in two sets of trousers, and it’s not even December yet… 🧊
November 13, 2025 at 11:43 AM
Had a fabulous time speaking and attending #MSPG25 ! Thanks to the organisers, attendees, vendors, and other speakers.
October 23, 2025 at 3:11 PM
On my way to MSP Global to chat all things #security! #MSPG25 If you’re around say hi, and if interested, my talks are below.
October 23, 2025 at 6:21 AM
Tech Field Day Exclusive with Microsoft Security - Tech Field Day
techfieldday.com
October 9, 2025 at 3:15 PM
Reposted by Zoë Rose
Turn off your phone’s “advertising ID” to make it harder for location data brokers to track you. (2/4)
October 2, 2025 at 11:13 PM
Reposted by Zoë Rose
As its cyber sec awareness month 🤣
October 1, 2025 at 4:49 PM
Reposted by Zoë Rose
Most of the apps on your phone are talking to a server somewhere - sending and receiving data through messages sent through APIs.

And here's the problem - hackers have determined that the APIs of mobile apps, when left visible and exploitable, can be a goldmine.
Your Favourite Phone Apps Might be Leaking Your Company's Secrets
Securing APIs isn't just about protecting servers, it's also about protecting the apps that use them.
www.fortra.com
October 1, 2025 at 8:48 PM
Reposted by Zoë Rose
Main character mostly completed, background creeping in.
#イラスト #art #illustration #winnipeg #canada #noAI #pencils #steampunk #cyborg #goth
October 2, 2025 at 1:46 AM
Reposted by Zoë Rose
What a delight it was to have @rosesec.bsky.social join the "Smashing Security" podcast this week, as we discussed how ransomware can silence burglar alarms, allowing thieves to help themselves to €600,000 worth of gold in a daring late-night heist.

open.spotify.com/episode/7Ewr...

#ransomware
The €600,000 gold heist, powered by ransomware
open.spotify.com
September 25, 2025 at 4:34 PM
Reposted by Zoë Rose
Reposted by Zoë Rose
I wrote a plea to cybersecurity curriculum developers about what I would like to see covered in OT cybersecurity coursework. tisiphone.net/2025/09/10/t...
The Top 10 Things I’d Like to See in University OT Cybersecurity Curriculum (2025 Edition)
Most of you who have been following me for a while know that I have a very strange and unusual job in cybersecurity. I’m one of maybe a hundred or so people on earth who does full time incide…
tisiphone.net
September 11, 2025 at 3:12 AM
Reposted by Zoë Rose
Now comes the knock-off: TeaOnHer. Same idea, but flipped - men rating women. And in a twist of poetic incompetence, it hasn’t just copied Tea’s concept… it has copied its shoddy approach to security too.

Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
TeaOnHer copies everything from Tea - including the data breaches
Tea, the woman-only dating advice app where users can anonymously rate and review men, has made quite a name for itself in recent weeks.
www.bitdefender.com
August 8, 2025 at 9:12 AM
Reposted by Zoë Rose
The Tea app - where women anonymously rate men - has had quite the month.

First, it was slammed for enabling digital vigilantism with zero fact-checking or right of reply. Then, it leaked sensitive user data, including private images and messages. Despite that, it rocketed up the app store charts 🙄
TeaOnHer copies everything from Tea - including the data breaches
Tea, the woman-only dating advice app where users can anonymously rate and review men, has made quite a name for itself in recent weeks.
www.bitdefender.com
August 8, 2025 at 9:12 AM
Reposted by Zoë Rose
We've had more feedback from this episode of the "Smashing Securit" podcast than any that we've put out for years. When you listen to it, you'll know why...

Have a handkerchief ready... 😢
The women-only dating safety app Tea leaks over 70,000 private images, ID docs, private DMs, and a dash of 4chan creepiness. Yikes.

Plus, Carole takes us down memory lane as she hangs up her co-host mic after 428 glorious episodes. Expect tea, tears, and Tom Lehrer

open.spotify.com/episode/0HnH...
Red flags, leaked chats, and a final farewell
Smashing Security · Episode
open.spotify.com
August 2, 2025 at 10:29 AM
Reposted by Zoë Rose
Dragos just opened 21 positions in Australia, UK, and US/Canada. Not my team, not the hiring manager, but there is an array of roles
Dragos
job-boards.greenhouse.io
July 31, 2025 at 2:06 AM
Reposted by Zoë Rose
New from 404 Media: a second data breach at Tea has exposed more than a million direct messages between users that we obtained. Discussions of abortions, cheating. The other data was older. This is as recent as *last week*. Hard to overstate how sensitive this data is www.404media.co/a-second-tea...
A Second Tea Breach Reveals Users’ DMs About Abortions and Cheating
The more than one million messages obtained by 404 Media are as recent as last week, discuss incredibly sensitive topics, and make it trivial to unmask some anonymous Tea users.
www.404media.co
July 28, 2025 at 5:05 PM
Reposted by Zoë Rose
72,000 images, including sensitive ID verification photos that were supposed to be deleted immediately, have been accessed.

Adding to the controversy, an additional 59,000 images, which included posts, comments, and direct messages, were also breached.

More info: www.bbc.co.uk/news/article...
Tea app hacked: Images stolen from women's dating safety app that vets men
Thousands of women registered with Tea have had their images illegally accessed, the US firm says.
www.bbc.co.uk
July 27, 2025 at 8:11 AM
Reposted by Zoë Rose
This is painfully ironic. A woman's dating app designed to enhance safety and vet potential dating partners has itself fallen victim to hackers.

The Tea Dating Advice app, used by women to do background checks on men, identify catfishers and scammers, and share "red flags", has been breached.
July 27, 2025 at 8:11 AM
Heyo #infoSec / #Cyber friends, @errbufferoverfl.bsky.social is doing some research for a talk.

Please help them out: cryptpad.fr/form/#/2/for...

It takes a few moments and would be lovely for your insights to be included.
Encrypted Form
CryptPad: end-to-end encrypted collaboration suite
cryptpad.fr
July 23, 2025 at 2:56 PM
Reposted by Zoë Rose
Bye forever, WeTransfer.
July 14, 2025 at 11:57 PM
Spontaneity as a single:

- Person: hmm, I think I’ll do $thing.
- Parent: in 1 week, let’s do $thing.

Yet, single parent situation is even more stressful 😅 #mumSec
July 15, 2025 at 7:50 AM