<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>Most top security firms license my patents for mobile app security. Pioneered zero trust for anti-phishing. Helped to launch @AIM @MetaCert Founder. Co-invented the concept of labeling user accounts on the web at the W3C in 2004. Expert in SMS security.</description><link>https://bsky.app/profile/paulwalsh.bsky.social</link><title>@paulwalsh.bsky.social - Paul Walsh</title><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3mgs4i6j6o22d</link><description>Just wrote this. A new secure messaging app called prvc takes privacy and security to a new level. It will launch with Mackie Mobile, a new US carrier built from the ground up to prioritise subscriber safety and privacy.&#xA;&#xA;https://www.linkedin.com/pulse/signal-whatsapp-cyberattacks-highlight-design-flaw-prvc-paul-walsh-5suzc</description><pubDate>11 Mar 2026 14:39 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3mgs4i6j6o22d</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3mgrw7npqss2n</link><description>I wrote an article explaining how attackers are taking over Signal accounts used by high-risk individuals and why there’s very little Signal can do to stop it. The issue isn’t broken encryption. It’s how authentication workflows are being abused.&#xA;&#xA;https://paul-walsh.medium.com/how-attackers-hijack-accounts-like-signal-and-whatsapp-using-legitimate-authentication-workflows-64224e6663c3</description><pubDate>11 Mar 2026 12:47 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3mgrw7npqss2n</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3mgrtvz7bjk2n</link><description>The only advice I can offer for this serious problem is simple. Be extremely cautious whenever you’re presented with a meeting link, a verification code, or a request to approve a login or authenticate an account. There isn&#39;t much Signal can do to combat this.&#xA;&#xA;https://paul-walsh.medium.com/how-attackers-hijack-accounts-like-signal-and-whatsapp-using-legitimate-authentication-workflows-64224e6663c3?postPublishedType=repub&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>11 Mar 2026 12:06 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3mgrtvz7bjk2n</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lt6cxqc3gk27</link><description>I haven’t signed into this site for quite some time - is it worth it?&#xA;https://media.tenor.com/uD2bBJhV0gAAAAAC/shrug.gif?hh=376&amp;ww=498</description><pubDate>04 Jul 2025 22:44 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lt6cxqc3gk27</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lpr2anm6zs2y</link><description>Most phishing links aren’t flagged as dangerous because they’ve never been seen before. &#xA;&#xA;We don’t need more, or better awareness. We need better systems to protect people.&#xA;&#xA;Here’s how MetaCert stops phishing without the need to train people:&#xA;&#xA;🔗 https://www.linkedin.com/pulse/phishing-isnt-human-problem-its-failure-systems-meant-paul-walsh-z0zcc</description><pubDate>22 May 2025 11:47 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lpr2anm6zs2y</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3loloaywyvk2j</link><description>In addition to the good detail contained in this article, do NOT trust any person who calls you, even if it comes from a legitimate number because they’re easy to spoof.&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>07 May 2025 15:04 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3loloaywyvk2j</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3loinro2f7s2g</link><description>MetaCert has built a new solution that helps banks protect their brand, reduce liability, and stop this type of fraud before it happens — using tech that wasn’t possible until now. Hoping to see it adopted in Ireland soon. @bankofireland @AIBIreland ☘🔐&#xA;&#xA;https://www.rsvplive.ie/news/irish-news/bank-ireland-warns-customers-spike-35142836</description><pubDate>06 May 2025 10:18 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3loinro2f7s2g</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3loih3ikxfk2g</link><description>My open letter to the security industry — and MetaCert’s U.S. SMS security test report — is featured in this Forbes article.&#xA;&#xA;Huge thanks to @happygeek for giving the underdog a voice. The best solution means nothing if no one hears about it.&#xA;&#xA;https://www.forbes.com/sites/daveywinder/2025/05/05/new-warning---19-billion-compromised-passwords-create-hacking-arsenal/</description><pubDate>06 May 2025 08:18 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3loih3ikxfk2g</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lnxcpxycas25</link><description>I just wrote this: &#34;Zero Trust Is Broken at the URL — And That’s Where Most Attacks Begin (Phishing)&#34;&#xA;&#xA;https://www.linkedin.com/pulse/zero-trust-broken-url-thats-where-most-attacks-begin-phishing-walsh-irlec&#xA;&#xA;https://paul-walsh.medium.com/zero-trust-is-broken-at-the-url-and-thats-where-most-attacks-begin-phishing-a144d1179a6d&#xA;&#xA;Lots of people are talking about Zero Trust at  #RSAC2025  but not one person has mentioned zero trust for URLs. 🙄</description><pubDate>29 Apr 2025 12:45 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lnxcpxycas25</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lnn7hm4gls25</link><description>🎓 Are you brave enough to give it a go? What’s the right answer?&#xA;&#xA;Even the most skilled &amp; experienced security pros fail my tests 99% of the time — so there’s no need to feel afraid or embarrassed. Feel free to share it too — the more awareness, the better&#xA;&#xA;I don’t get much engagement on here so...</description><pubDate>25 Apr 2025 12:20 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lnn7hm4gls25</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lnio4vuaec26</link><description>I just received this SMS scam. This one’s from a lazy attacker — strange ID, sloppy text. But don’t let it fool you into thinking they’re all this obvious. Many are highly convincing and look exactly like the real messages you’re expecting — from deliveries to security alerts.</description><pubDate>23 Apr 2025 16:59 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lnio4vuaec26</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lngdkoezt223</link><description>I just wrote this:&#xA;https://www.linkedin.com/pulse/lie-weve-been-sold-why-security-has-never-stopped-phishing-paul-walsh-w4t6c?utm_source=share&amp;utm_medium=member_ios&amp;utm_campaign=share_via</description><pubDate>22 Apr 2025 18:44 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lngdkoezt223</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lmrhnbqll22y</link><description>💡 Just dropped: how I turned ChatGPT into my expert collaborator — not just a generic assistant.&#xA;&#xA;Includes the exact prompt I use + how to apply it across product, sales, hiring, comms, and more.&#xA;&#xA;https://www.linkedin.com/pulse/how-train-chatgpt-think-like-you-use-strategic-paul-walsh-dfpgc</description><pubDate>14 Apr 2025 11:31 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lmrhnbqll22y</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lmiourtrgk2r</link><description>SMS phishing isn’t clever — just easy&#xA;Criminals test fake messages on their own SIMs&#xA;If the link gets through, they send it to you&#xA;If it doesn’t, they swap it until it does&#xA;This is why traditional security fails&#xA;Only trusted link authentication stops smishing before it starts.</description><pubDate>10 Apr 2025 23:47 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lmiourtrgk2r</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lmhmps6w2c2r</link><description>AI isn’t just fun — it’s a serious business tool. I still had to finesse and shape things, but ChatGPT did most of the heavy lifting behind the scenes.&#xA;&#xA;#SMSFraud #Phishing #Smishing</description><pubDate>10 Apr 2025 13:36 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lmhmps6w2c2r</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lmg64hova22r</link><description>Already sparked a few great conversations from my LinkedIn post. It wasn’t a call for work — just holding myself accountable by not procrastinating. 🤓&#xA;&#xA;https://www.linkedin.com/posts/paulwalsh_hashtag-activity-7315840945822879745-UoeZ</description><pubDate>09 Apr 2025 23:42 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lmg64hova22r</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lmfc64e24224</link><description>OpenAI now holds detailed insight into people’s jobs and interests — all exchanged for a bit of entertainment. 🤓</description><pubDate>09 Apr 2025 15:22 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lmfc64e24224</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3llvt3n2krc25</link><description>If you know anyone at banks or payment providers in Ireland, I’d appreciate an intro. I’m in touch with the Banking Federation but keen to connect with more of the right people — hoping Ireland can lead the way in stopping SMS fraud.</description><pubDate>03 Apr 2025 11:42 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3llvt3n2krc25</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lltpxvc6as25</link><description>Thank you, ChatGPT. I made several edits, but the AI handled most of the heavy lifting.&#xA;&#xA;MetaCert has developed a short code specifically for Ireland, where current privacy regulations prevent mobile operators from implementing network-based anti-phishing security.</description><pubDate>02 Apr 2025 15:41 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lltpxvc6as25</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lltdeffmvs25</link><description>LinkedIn engagement has fallen off a cliff since the start of 2025. I’m not sure what they changed, but it’s obvious something’s different. If I wasn’t writing for a handful of very specific people, I’d have stopped posting altogether. And it’s even worse on here. Not a single engagement.</description><pubDate>02 Apr 2025 11:55 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lltdeffmvs25</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3llt4tv2ems25</link><description>I just wrote this: The security industry widely acknowledges smishing as one of today’s most serious cybersecurity threats. So why is it that no legacy vendor offers a network-based solution for mobile operators to protect...&#xA;&#xA;LinkedIn: t.co/XpVg2498Cw&#xA;&#xA;Medium: https://paul-walsh.medium.com/from-aol-instant-messaging-to-sms-security-why-smishing-was-inevitable-and-preventable-804a54284b2f</description><pubDate>02 Apr 2025 09:58 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3llt4tv2ems25</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3llqyiiervk25</link><description>I made this emoji using ChatGPT — with a transparent background!&#xA;&#xA;It’s wild how fast this is evolving. Tools like this won’t replace great designers — but they will wipe out tedious work and make everyday tasks way faster and easier.</description><pubDate>01 Apr 2025 13:35 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3llqyiiervk25</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3llefw4gv7s2n</link><description>Troy Hunt has spent his career teaching people how phishing works and how to avoid it. He knows the tactics, he understands the risks — and he still got caught.&#xA;&#xA;LinkedIn: https://www.linkedin.com/pulse/troy-hunt-fell-phishing-attack-heres-why-should-scare-paul-walsh-uzomc&#xA;&#xA;Medium: https://paul-walsh.medium.com/troy-hunt-fell-for-a-phishing-attack-heres-why-that-should-scare-everyone-4cc7c2cad44a</description><pubDate>27 Mar 2025 13:31 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3llefw4gv7s2n</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3llc2vddwos2n</link><description>Google is flagging MetaCert’s anti-phishing emails as ‘dangerous’ — the same emails that highlight Google’s failure to detect phishing apps on Google Play. Ironic, but not even slightly funny.&#xA;&#xA;😤&#xA;&#xA;@gmail</description><pubDate>26 Mar 2025 15:08 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3llc2vddwos2n</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lkswleocc22a</link><description>“A World Without ADHD and Dyslexia&#34;&#xA;&#xA;I just wrote this for Neurodiversity Celebration Week.&#xA;&#xA;#NeurodiversityCelebrationWeek #NeurodiversityWeek #NCW #ThisIsND #ADHD #Dyslexia&#xA;&#xA;cc @NCWeek&#xA;&#xA;LinkedIn: https://www.linkedin.com/pulse/world-without-adhd-dyslexia-paul-walsh-taerc&#xA;&#xA;Medium: https://paul-walsh.medium.com/a-world-without-adhd-and-dyslexia-bfc7acbe06ab</description><pubDate>20 Mar 2025 14:41 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lkswleocc22a</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lkspa55awk22</link><description>It’s 2025, and the security industry still hasn’t solved phishing. It’s time for a new approach - it’s time for Zero Trust for URLs.&#xA;&#xA;Assume every site, login page, app, API, user account, and AI chatbot is dangerous unless explicitly verified as legitimate.&#xA;&#xA;https://www.securityweek.com/300-malicious-vapor-apps-hosted-on-google-play-had-60-million-downloads/</description><pubDate>20 Mar 2025 12:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lkspa55awk22</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lkrdgnkvvc2a</link><description>35% of entrepreneurs have dyslexia, 40% of self-made millionaires have ADHD. 30% - 40% have both. Yet, most investors &amp; corporate execs don’t fully understand how they think or communicate.&#xA;&#xA;I’m writing a book to explain why neurodivergent founders thrive and where they struggle.</description><pubDate>19 Mar 2025 23:26 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lkrdgnkvvc2a</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lknhnypk5k2y</link><description>This article explains why AI fails at detecting fake (dangerous) email links, SMS links, WhatsApp links, websites, login pages, apps, QR codes, AI chatbots, or any other web resource — and why relying on it for security is dangerous. #Smishing #Phishing&#xA;&#xA;https://www.linkedin.com/pulse/googles-ai-scam-detection-android-why-fails-protect-sms-paul-walsh-gwa0c/</description><pubDate>18 Mar 2025 10:31 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lknhnypk5k2y</guid></item><item><link>https://bsky.app/profile/paulwalsh.bsky.social/post/3lkdqmquhoc2y</link><description>After 20+ years in London, Amsterdam, San Francisco, Vancouver, and Edmonton, it’s great to finally be back home in Dublin.&#xA;&#xA; It’s been a while since I hosted events here, so I’d love to reconnect with the old timers and meet some new great people. 🚀&#xA;&#xA;metacertsecurity.typeform.com/to/BhKtEuIS&#xA;https://metacertsecurity.typeform.com/to/BhKtEuIS</description><pubDate>14 Mar 2025 13:45 +0000</pubDate><guid isPermaLink="false">at://did:plc:sapem3bipsshwhwm35mcud2d/app.bsky.feed.post/3lkdqmquhoc2y</guid></item></channel></rss>