Secure Ideas

Secure Ideas Secure Ideas is a security consulting firm focused on improving your security. Secure Ideas has focused on pe*******on testing and application security.

Secure Ideas was created by a group of security professionals working toward improving security within organizations. The company is made up of well-known security professionals that are focused on helping you improve your security posture. Secure Ideas' group of security researchers work toward improving security. They have spent years researching various exploits and vulnerabilities, building to

olsets and helping organizations secure their networks. From open-source projects such as SamuraiWTF and Weaponized Flash, to training classes such as Security 542 from SANS, Secure Ideas involves themselves in all facets of a security program. Secure Ideas can help you move your organization further into the future.

Seats close September 6. It's not too late to sign up!10 weeks, all 8 CISSP domains, pay-what-you-can pricing. Enroll on...
09/03/2026

Seats close September 6. It's not too late to sign up!

10 weeks, all 8 CISSP domains, pay-what-you-can pricing. Enroll once and you can rejoin any future session free. Don't wait on this one.

Enroll now: https://hubs.la/Q04tRmvP0

Seats are still available for the Professionally Evil CISSP Mentorship Program, and classes begin September 1.10 weeks o...
08/28/2026

Seats are still available for the Professionally Evil CISSP Mentorship Program, and classes begin September 1.

10 weeks of live, instructor-led mentorship covering all 8 CISSP domains. Tuesdays, 2โ€“4pm ET. Pay what you can, no minimum.

You'll get the official study guide, weekly live sessions, session recordings, a private Slack channel, and practice exams.

Enroll now: https://hubs.la/Q04tQppd0

Kevin Tackett is speaking at OWASP PhoenixTuesday, September 1 at 7:30 PM, Kevin will take the OWASP Phoenix Chapter thr...
08/25/2026

Kevin Tackett is speaking at OWASP Phoenix

Tuesday, September 1 at 7:30 PM, Kevin will take the OWASP Phoenix Chapter through the tangled ruins of modern application architecture in "Raiders of the Lost Architecture: Security Testing in Modern Applications."

In this talk, Kevin Tackett takes attendees on an expedition through the tangled ruins of modern application architecture. Drawing from real-world pe*******on testing engagements, he will share stories of uncovering forgotten API endpoints still connected to production data, third-party integrations that outlived their original purpose but retained their access, and AI components bolted onto legacy systems with little consideration for the attack surface they introduced. Like any good archaeologist, a security tester must piece together fragments of understanding while avoiding the traps left behind by those who built before them.

๐Ÿ“ HeatSync Labs, 108 W Main St, Mesa, AZ
๐Ÿ•ข 7:30 PM
Free and open to all

Details and registration: https://hubs.la/Q04vgTM20

Most CISSP courses are taught by people who teach for a living. Ours are taught by people who break things for a living....
08/25/2026

Most CISSP courses are taught by people who teach for a living. Ours are taught by people who break things for a living.

Our instructors have decades of hands-on, real-world security experience. You're learning from practitioners, not a textbook.

Enroll now: https://hubs.la/Q04tCV5G0

Scheduling an external pentest? The prep work matters just as much as the testing itself.Two things to nail down before ...
08/21/2026

Scheduling an external pentest? The prep work matters just as much as the testing itself.

Two things to nail down before your kickoff call:

Know your scope before the attacker does. Build an asset inventory of your public-facing IPs and think through your goals for the assessment. Not sure of your full scope? That's normal, but don't wait until the day before testing to figure it out. A finalized scope is needed at least a week out.

Designate a point of contact. Connection issues, critical findings that need immediate attention, someone needs to be reachable when it counts. No point of contact often means delays or shifted testing dates.

Our latest blog breaks down the pre-engagement essentials, the four phases of an external pentest (recon, discovery, validation and exploitation, reporting), and how to prioritize remediation once your report lands.

Read it here:

Prepare for an external pe*******on test by understanding scope, communication, and remediation to strengthen your organization's security posture.

Still telling yourself you'll start studying for the CISSP "next month"?The Professionally Evil CISSP Mentorship Program...
08/20/2026

Still telling yourself you'll start studying for the CISSP "next month"?

The Professionally Evil CISSP Mentorship Program is 10 weeks of live, instructor-led sessions covering all 8 CISSP domains. Starts September 1. No prior CISSP coursework required.

Enroll now: https://hubs.la/Q04tCYwM0

Robotic Process Automation and Low-Code/No-Code platforms are reshaping how businesses operate, letting teams automate w...
08/14/2026

Robotic Process Automation and Low-Code/No-Code platforms are reshaping how businesses operate, letting teams automate workflows faster and with less overhead. But what happens when the automation itself becomes the risk?

Jordan Bonagura, Senior Security Consultant at Secure Ideas, is speaking at the ISC2 Central Florida Chapter meeting hosted by Full Sail University.

When the Robots Start Acting Crazy: A Security Approach

Jordan will explore the intersection of automation and security, looking at real-world scenarios where RPA and LCNC tools go rogue, and the impact on data, infrastructure, and compliance when they do. The session covers how to recognize, mitigate, and recover from these risks before they turn into breaches.

๐Ÿ“ Full Sail University, Winter Park, FL
๐Ÿ—“๏ธ Monday, August 24th, 2026
๐Ÿ•• 6:00 PM - 9:00 PM
Hosted by ISC2 Central Florida

Register here: https://hubs.la/Q04t2R_J0

Proud to see our CEO Kevin Tackett quoted in HuffPost this week on the Zbtlink router backdoor story.Researchers at Vuln...
08/11/2026

Proud to see our CEO Kevin Tackett quoted in HuffPost this week on the Zbtlink router backdoor story.

Researchers at VulnCheck found that over 20 router models sold under the Zbtlink and Wiflyer brand names shipped with a hidden implant that phones home to servers in China every 35 seconds, giving an attacker full root access to the device. An estimated 100,000+ routers worldwide may be affected.

Kevin's take: this isn't a bug you patch, it's a trust problem. If your router's label says Zbtlink, ZBT, ZBTWiFi, or Wiflyer, the recommendation is simple: replace it.

Check the full article for how to identify affected models:

Your most sensitive information could be at risk. Hereโ€™s what you need to know.

Over the last few months we followed one droid from concept to convention floor: teaching it to see, building the body, ...
08/03/2026

Over the last few months we followed one droid from concept to convention floor: teaching it to see, building the body, and finally putting it in front of a real crowd at Orlando Maker Faire.

Doug just dropped Part 4: three days of kids waving, adults asking questions, and a droid that had to prove itself outside a controlled test. What worked, what broke, and where the build goes next.

Read the finale:

Three days at Orlando Maker Faire with an AI-powered Star Wars Pit Droid. What worked, what failed, and how the project evolves with Claude and Cowork.

Address

3412 Kori Road
Jacksonville, FL
32257

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Telephone

(866) 404-7837

Alerts

Be the first to know and let us send you an email when Secure Ideas posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Secure Ideas:

Shortcuts

Share