Rik Ferguson
banner
rikferguson.com
Rik Ferguson
@rikferguson.com
Immigrant. VP Security Intelligence @Forescout, Co-founder @RespectInSec. Board @vaultree, Cybersecurity Futurist, Researcher, Award-winning writer/producer. He/Him. Pussy in bio.
Substack - Ferguson.ink

Slava Ukraini 🇺🇦
Zero trust is no longer a nice to have security architecture. It is the only credible way to respond to attacks that target trust in all its forms: users, authentication, vendors, infrastructure and more.
December 11, 2025 at 12:21 PM
These sit in privileged network positions, are unavoidably exposed to hostiles, and make excellent pivot points for reconnaissance and lateral movement. At the same time, they are often significantly less visible in the traditional security stack, making compromise even more valuable to an attacker.
December 11, 2025 at 12:21 PM
What really concerns me is not simply the volume, but where these zero days are landing. We are seeing a continued rise in zero days affecting exposed edge devices, especially networking and security appliances (~20% of the 2025 total).
December 11, 2025 at 12:21 PM
Contractors? Have they not even *seen* Slow Horses?
November 21, 2025 at 3:59 PM
Thank you!
November 17, 2025 at 9:39 PM
Remember? It’s still happening.

Not sure if it’s a Xi-phoon or a Xi-clone though, difficult to tell them apart, they all rely on Xiploits.
October 30, 2025 at 9:16 PM
October 23, 2025 at 5:56 PM
I used to have the same problem back when I was doing PGP technical support, “I’ve lost my private key can you decrypt to my data for me?”
October 22, 2025 at 2:27 PM
And possibly also because many (?) of them are eventually reunited with their owners.
October 22, 2025 at 2:19 PM
Facetime and regular calls are about the only things that work in Lost Mode. No notifications, no apple pay and device is locked (duh).
October 22, 2025 at 2:06 PM
You can “Mark as lost” using Find My, which disables it until found.
October 22, 2025 at 2:06 PM