A new initiative, hacklore.org, has been launched by former CISA advisor Bob Lord to address persistent cybersecurity myths and promote evidence-based security practices. The campaign, supported by an open letter signed by over 80 cybersecurity professionals, aims to shift public and organizational focus away from outdated advice—such as avoiding public Wi-Fi, never scanning QR codes, or frequently deleting cookies—and toward proven strategies like enabling multi-factor authentication, using strong passwords and passkeys, and keeping software up to date. The project also advocates for software companies to adopt "secure by design" and "secure by default" principles to improve overall digital safety.
The hacklore.org platform consolidates practical, fact-based cybersecurity guidance for individuals and small organizations, emphasizing actionable steps that genuinely enhance security. By challenging long-held superstitions and replacing fear-driven advice with accurate information, the initiative seeks to make digital safety advice more effective and accessible. The campaign has garnered support from cybersecurity leaders at major organizations, including Okta, Microsoft, and CISA, highlighting a broad consensus on the need to modernize cybersecurity education and awareness.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
A new public campaign, hacklore.org, launched to combat persistent cybersecurity misconceptions and promote practical guidance including strong passwords or passkeys, multi-factor authentication, social-engineering awareness, and secure-by-design software practices.
Former CISA advisor Bob Lord organized an open letter signed by more than 80 cybersecurity professionals calling for a shift away from outdated cybersecurity myths and toward evidence-based practices such as MFA, password managers, and software updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.