CompTIA SecurityAI+ certified. AI security, threat modeling, and cert prep. Free study resources below. 📺 https://t.co/2lj0H4sMg9secaiplus.comJoined March 2026
Three ISO numbers, free exam points:
27001 — information security management
27701 — privacy management
42001 — AI management
SecAI+ will happily offer all three as answer choices on one question. Don't donate the points.
Evasion ≠ poisoning.
Poisoning: corrupt the model before deployment (training time).
Evasion: fool the model after deployment (inference time).
One breaks the tool. The other sneaks past it. Different timeline, different controls.
You wouldn't run an unsigned binary from a forum.
A pretrained model off a public hub is an unsigned binary — with weights nobody can eyeball.
Provenance, hashes, scanning before load. Same hygiene, new file type.
"Human in the loop" is doing a lot of work in AI governance docs.
A human who reviews 400 AI decisions an hour isn't in the loop. They're in the blast radius.
If the review is a formality, the control doesn't exist.
An analyst who trusts every AI verdict is a rubber stamp.
An analyst who trusts none of them is doing two jobs.
Domain 3 of SecAI+ is about the space between — when to let automation act, and when a human stays in the loop.
Sitting SecAI+ this fall? 20% off the full prep stack — study guide, 3 timed practice exams, 150-card Anki deck — through Labor Day. Code LABORDAY20 →
secaiplus.gumroad.com/l/everything-b…
Your SOC lives in MITRE ATT&CK.
ATLAS is its sibling for AI systems — same structure, different attack surface: poisoning, extraction, evasion, prompt injection.
If you can read ATT&CK, you can read ATLAS. Most teams just haven't opened it.
Shadow AI is just shadow IT with better marketing.
Proprietary code into a public chatbot. Customer data through an unapproved model. You don't firewall it away — you give people a sanctioned tool that's actually good.
CompTIA SecAI+ is now ANAB-accredited.
Translation: "is this new cert even legit?" just got an official answer.
I passed it in the February cohort. What it actually tests:
youtu.be/tKiFVGtEZIk
Data poisoning ≠ model poisoning.
Poison the data: corrupt the training set.
Poison the model: tamper with the weights directly.
Same goal, different entry point, different controls. Know it cold.
Healthcare diagnostic AI under the EU AI Act is High risk — not Unacceptable.
High risk = heavily regulated.
Unacceptable = banned (social scoring, mass biometric surveillance).
Picking "unacceptable" for healthcare is the classic trap answer.
Stop losing these points:
NIST CSF → Identify, Protect, Detect, Respond, Recover
NIST AI RMF → Map, Measure, Manage, Govern
The exam swaps them on purpose.
I passed the CompTIA SecurityAI+ in February — one of the first cohorts.
Everyone asks the same two things: what's on it, and how to prep.
Just answered both in my first video. YouTube: @SecAIPlus
Your RAG knowledge base is attack surface.
Poison one retrieved document and the model follows the instructions hidden inside it — without the attacker ever touching your prompt.
That's indirect prompt injection. Validate inputs. Filter retrieved content.
Prompt injection ≠ jailbreaking.
Injection: crafted input overrides the system prompt (SQL injection, but for language).
Jailbreak: you talk the model out of its own safety rules.
Different attack. Different fix. SecAI+ tests whether you know which is which.
Output validation is the control layer most teams skip. The model generates, the app ships it, nobody checked in between.
That gap is the new perimeter.
Your IR plan assumes you can find what changed and when.
A model poisoned during training, six months before it misbehaves, breaks that assumption completely.
15 Followers 334 Followinghttps://t.co/GzdCg7wRH8 Consultoría & Asesoría en Seguridad de la Información
Information Security InfoSec ISO 27001 ISO 27002 ISO 22301
1K Followers 2K Following2x YC founder. CEO of @Posh_Energy(YC W22). Stanford grad. Daydreaming about American dynamism. Opinions are mostly my own, occasionally ChatGPT’s
38 Followers 134 FollowingFrom theory to terminal 🛠️ Hands-on cloud/DevOps cert prep — real browser labs, an AI coach & a free readiness diagnostic. Pay once · 14-day guarantee.
1K Followers 159 FollowingChief Technology Evangelist @CompTIA, working and speaking in #cybersecurity, emerging tech, open source, #IoT, and hands-on IT education worldwide.
233K Followers 6K FollowingFounder @Binary_Defense @TrustedSec Co-Owner https://t.co/NUvgPUifL0. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
32K Followers 2K FollowingExecutive AI Strategist to Fortune 500 leaders. Career strategist for high performers that are ready to turn performance into leverage. ✨
255K Followers 1K FollowingFounder & CEO of @haveibeenpwned, the most trusted name in data breach intelligence. Speaker, blogger, Microsoft Regional Director. Gold Coast, Australia.
578K Followers 53 FollowingThe Gemini app turns research into reality, bringing frontier AI experiences like Omni, Deep Think, Nano Banana, and more to hundreds of millions of people.
2.7M Followers 47 FollowingThe official handle for NVIDIA. Blog: https://t.co/JAn5eKOTBT Support: https://t.co/6ln5FVnA2o All our social media: https://t.co/Uc56dL57Dh
606K Followers 59K FollowingThe automated life | San Francisco/Silicon Valley AI, robotics, BCIs | Ex-Microsoft, Rackspace, Fast Company | Wrote eight books about the future.
245K Followers 7K FollowingOG GenAI Skeptic; spoke at US Senate. Warned about hallucinations in 2001. Advocating world models & neurosymbolic AI ever since. Author, Marcus on AI & 6 books
3K Followers 852 FollowingThe latest news about AI and ML Security, Robustness, Safety, Privacy, Trustworthiness, Ethics and Bias by https://t.co/wZlrmYRyzL
303K Followers 71 FollowingPart of @CISAgov, we respond to major incidents, analyze threats, and exchange critical cybersecurity information with partners around the world.
333K Followers 2K FollowingIndependent investigative journalist. Author of 'Spam Nation,' a NYT bestseller. Former Washington Post reporter. Mastodon: https://t.co/fTKNavlMwp
252K Followers 857 FollowingThe only magazine dedicated to the strategy and technology of information security, delivering critical business and technical information for IT professionals.
357K Followers 49 FollowingOne of the most widely read and trusted cybersecurity news sites, providing IT security professionals informed insights into the latest news and trends.
137K Followers 457 FollowingFree and open source tool for network discovery, admin, and security auditing. Our tweetmaster is Gordon "Fyodor" Lyon. We're also on FB: https://t.co/RVkxWNikvW
126K Followers 3K FollowingRapid7 is a leader in AI-powered managed cybersecurity operations. 11,500+ customers utilize Rapid7 to disrupt attackers and advance their cyber resilience.
312K Followers 91 FollowingKaspersky is the world’s largest privately held vendor of Internet security solutions for businesses and consumers. For support https://t.co/enRPRUIwcm
95K Followers 6K Followinghow hackers start their afternoons. where 50k+ technologists publish blog posts for 4M+ monthly readers. write your story 👉https://t.co/PGmtSCSd5V
119K Followers 514 FollowingMITRE ATT&CK® - A knowledge base for describing the behavior of adversaries. Replying/Following/Re-tweeting ≠ endorsement. @ https://t.co/wt46ArkZVt
331K Followers 117 FollowingEmpowering the world to fight cyber threats with indispensable cybersecurity skills and resources.
Support queries: https://t.co/HtFpqjjlRZ
262K Followers 10 FollowingWe’ll help you make it like nobody’s business. Multimodal media generation and editing tools to get your idea to production. Self-deploy? 👍 Need a partner? 🤝