Chuck Davis
banner
ckd3.net
Chuck Davis
@ckd3.net
Cybersecurity executive helping bridge technology, public policy, and critical infrastructure resilience. Author, inventor, educator, speaker, and founder of NetBOM
25 years ago today, I was working from home as an IT security architect for IBM when I heard the tone of the morning news anchors suddenly change.

I remember the shock, sadness and anger. I wanted to help. Ten days later, I was given a small opportunity to do exactly that.

betweenthehacks.com/...
September 11, 2026 at 8:56 PM
A fake $499.99 PayPal charge appeared on my son’s calendar exactly one year after I drafted an article about the same attack.

Was his account breached? Probably not.

Here is how calendar invite phishing works and what to do when one appears:

betweenthehacks.com/...
August 20, 2026 at 4:18 PM
What if your next cyberattack didn't begin with a phishing email or an unpatched server?

What if it started with a job application?

AI is making fake identities more convincing, which means hiring has become part of every organization's security perimeter.

betweenthehacks.com/...
August 6, 2026 at 6:43 PM
August 6, 2026 at 6:32 PM
AI didn't escape.

It started testing the fence.

That's the lesson I took from the OpenAI/Hugging Face incident. The important question isn't whether AI is malicious, it's whether our security controls still work when AI begins testing them.
betweenthehacks.com/...
July 28, 2026 at 2:30 PM
The best cybersecurity professional I ever hired had no college degree.

They had curiosity.

That mattered more.

Here’s why, plus the career advice I wish someone had given me.

betweenthehacks.com/...
July 16, 2026 at 8:42 PM
I thought I was just reading an article.

Instead, I found a ClickFix attack.

After reproducing it across multiple browsers and researching further, I realized the real story wasn’t the malware.

It's how attackers are impersonating security itself.

betweenthehacks.com/...
July 8, 2026 at 3:30 PM
We’ve spent decades securing identities.

AI governance extends those ideas to AI agents, and that’s the right direction.

But identity and governance answer only two questions.

I think the next challenge is understanding what influences AI behavior.

betweenthehacks.com/...
July 2, 2026 at 2:35 PM
Enjoyed joining @hackersonthehill.org in Washington, DC.

Cybersecurity isn’t just a technology challenge. It’s also about governance, public policy, and collaboration. Thanks @beauwoods.com and everyone who organized the event.

What cybersecurity policy issue deserves more attention from Congress?
June 25, 2026 at 5:15 PM
We keep talking about passwordless.

Attackers are still using passwords.

bth.news/2026wpd
#Cybersecurity #WorldPasswordDay #InfoSec #Security
May 7, 2026 at 2:40 PM
If your vulnerability program is driven entirely by CVSS scores, you are probably missing real risk. This post outlines a high-level approach to prioritizing remediation based on exposure, KEV data, and attacker behavior.
Link 👇
betweenthehacks.com/...
#VulnerabilityManagement
February 10, 2026 at 7:38 PM
Venmo makes your payments public by default.
Who you paid. When. And why.
This is a privacy problem with an easy, 30 second fix!
🔗 betweenthehacks.com/...
#Venmo #PrivacyMatters #CyberSecurity #VenmoPrivacy #AppSecurity #DataProtection #DigitalSafety #FixItFast
October 28, 2025 at 3:01 PM
Did you know National Internet Safety Month started in 2005?
It began as a campaign to protect kids online—now it’s a reminder for everyone to tighten up digital hygiene.

Read the history: bth.news/safety
#Cybersecurity #InternetSafety #Infosec
June 12, 2025 at 8:54 PM
Need a quick win this weekend?

Check out my 10-minute security checklist: updates, MFA, router tweaks, password scan, and more.

No fluff, no fear—just real-world security tips anyone can follow. 🔗 betweenthehacks.com/...

#cybersecurity #weekendproject #infosec
June 1, 2025 at 8:16 PM
If “The Spy Who Applied to Code” grabbed your attention, check out @smashingsecurity.com Ep. 407. It covers human trafficking behind tech scams in Myanmar. Dark stuff—important to know. www.smashingsecurity.com/407-hps-hold... #Cybersecurity #HumanRights
May 9, 2025 at 3:25 PM
He said he liked food.
He couldn’t name a restaurant.
He claimed to live in Houston.
He didn’t know what Halloween was.
Turns out, he was a North Korean spy.
Here’s what happened when Kraken interviewed him:
👉 www.betweenthehacks.com/blog/the-spy...
North Korean Hackers Are Applying for Remote Jobs: How to Spot the Fakes — Between The Hacks
A North Korean operative posing as a remote software engineer nearly infiltrated a U.S. company. Here’s what happened—and how to avoid falling for these increasingly sophisticated scams.
www.betweenthehacks.com
May 5, 2025 at 3:41 PM
A fake resume. A fake location. A real threat.

Kraken’s hiring team spotted the red flags—and uncovered a North Korean spy posing as a dev.

Here’s how it unfolded:
👉 betweenthehacks.com/...

#Cybersecurity #RemoteWork #Infosec
May 5, 2025 at 3:06 PM
It’s World Password Day!
Still clinging to qwerty and your dog’s birthday? No judgment—just backup and fix it.
New on Between The Hacks:
betweenthehacks.com/...
#Passwords #WorldPasswordDay #CyberSecurity
May 1, 2025 at 3:20 PM
Your laptop is your command center. Don’t make it an easy target.
Here are 10 smart, simple ways to lock it down in 2025. 🔒
👉 betweenthehacks.com/...
April 28, 2025 at 3:36 PM
New post on Between The Hacks:
Quishing: Phishing Got a Glow-Up
QR codes are sneaky little traps. This post explains how attackers use them to phish for creds, how it works, and how to stay safe.
bth.news/quishing
#quishing #cybersecurity #infosec
April 24, 2025 at 3:14 PM
DEF CON 33 talk submitted:
What SBOMs Forgot About the Network

NetBOM defines where devices should connect, then helps your firewall block the rest.

It’s time to stop trusting by default.
netbom.net
#NetBOM #Cybersecurity #DEFCON33
April 22, 2025 at 2:37 PM
Reposted by Chuck Davis
Just when we thought cyber security wasn’t difficult enough
BREAKING.

From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
April 15, 2025 at 7:41 PM
My thermostat wouldn’t work without full Internet access.
I tried to restrict it. Support said: “Put it in the DMZ.”
Nope. I built NetBOM instead.
It’s like SBOM—but for network behavior.
Read the blog: betweenthehacks.com/...
White Paper: netbom.net
#NetBOM #Cybersecurity #IoTSecurity
April 14, 2025 at 2:15 PM
Ransomware is no joke—but the time ransom notes started printing on lobby printers? Still kind of hilarious.
New on Between The Hacks: what it is, how it works, and how to stay protected.
👉 betweenthehacks.com/...
#Ransomware #InfosecHumor
April 9, 2025 at 2:10 PM
Hey friends, we’ve updated our main URL! The new default is betweenthehacks.com. Same content, just a new domain. Check it out: betweenthehacks.com/...
April 5, 2025 at 6:54 PM