Sign in

Ben Read

@benread.bsky.social
2K followers 135 following 148 posts

CTI ‪@wizsecurity.bsky.social‬ Adjuct at @jhu.edu - SAIS Nonresident Fellow at @atlanticcouncil.bsky.social - Cyber Statecraft Previously NSC44, Mandiant, Google Go Mammoths

PostsRepliesMedia
Reposted by Ben Read
Zack Whittaker @zackwhittaker.com · 27/09/2026
Citrix has a security post on its website that also confirms exploitation and has a bunch of remedation advice, which you might not know because the company set the page to "noindex," so it doesn't show up in search results. 🤦‍♂️
community.citrix.com
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, ...
0113
Reposted by Ben Read
Saher @saffronsec.bsky.social · 24/09/2026
Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
22215
Reposted by Ben Read
Eric Geller @ericjgeller.com · 24/09/2026
Wiz today announced a "Scan for Good" initiative to use AI to scan under-resourced critical infrastructure for vulnerabilities. It's already found problems in rail systems, hospitals, and vital online tech. www.wiz.io/blog/scan-fo...
071
Reposted by Ben Read
Saher @saffronsec.bsky.social · 23/09/2026
We're one month out from @what-is-sos.bsky.social in Brussels with a packed and stacked agenda on all things intel, espionage, sabotage, physical ops, and attribution - get your tickets asap!! www.stateofstatecraft.com/agenda
stateofstatecraft.com
Agenda - State of Statecraft
The purpose of SOS is to discuss state-sponsored operations and drive understanding of geopolitical risk and impact through study of the actors or systems that facilitate them.
033
Ben Read @benread.bsky.social · 23/09/2026
NYT top 10 TV shows
Mad Men
Chapelle's show
Rubicon
Industry 
The Bureau (fr)
The Righteous Gemstones
Shorsey
Chernobyl 
ZeroZeroZero
Bluey
010
Reposted by Ben Read
Patrick Meyers @pmeyers7.bsky.social · 21/09/2026
So interesting that they're dropping $30M on Sen. Brown, who isn't currently in the Senate, and not Susan Collins, who voted against their signature bill last week (and after they threatened to spend against non-supporters). Almost as if they're not actually "non-partisan" like they claim!
021
Reposted by Ben Read
halvarflake.bsky.social @halvarflake.bsky.social · 17/09/2026
I gave a talk at Bluehat Singapore today. The slides are here: thomasdullien.github.io/about/slides...
1219
Reposted by Ben Read
Melissa K. Griffith @melissakgriffith.bsky.social · 16/09/2026
Thrilled to be Arizona-bound to present my work on "Chips on the Move: Export Controls, Evasion, and the Race for Compute" at #LABScon. Hope to see you there! The fantastic two-day program can be found here: www.labscon.io/speakers/ #chips #compute #semiconductors #ai #geopolitics #natsec
061
Reposted by Ben Read
hakan @hatr.bsky.social · 14/09/2026
Some news on "incident 2", the one which had Anthropic "most concerned". Crucially, the malware was stopped within 18 minutes of being uploaded. A trusted security researcher from Austria, working in his spare time, quickly analyzed and then quaranted mlflow-ui www.derstandard.de/story/300000...
derstandard.de
Wie ein Wiener eine KI-Spionagesoftware von Anthropic stoppte
Künstliche Intelligenz lud Schadsoftware auf eine Plattform mit Millionen Nutzern. Ein Cybersicherheitsforscher aus Österreich verhinderte, dass sie sich weiter verbreiten konnte.
12413
Reposted by Ben Read
Richard Tofel @dicktofel.bsky.social · 14/09/2026
BREAKING @propublica.org: Trump Jr.’s wedding this May was heavily funded by a Russian oligarch close to Putin www.propublica.org/article/dona...
propublica.org
Donald Trump Jr.’s Wedding Bankrolled by Putin-Linked Russian Oligarch
The oligarch, Umar Kremlev, spent hundreds of thousands on expenses like renting out a private island. He appears to have met Trump Jr. only recently, but he attended the intimate wedding with a large...
1519381
Reposted by Ben Read
David Oxley @oxley.io · 13/09/2026
Career achievement unlocked: someone is impersonating me on Gmail! Please note, I do not send professional email from “freemail” email addresses. If you’re contacted by someone, please feel free to message me with the details here. Thanks!
021
Ben Read @benread.bsky.social · 11/09/2026
This report from Anthropic is really good and comes with a level of detail on atribution that is impressive. www.anthropic.com/threat-intel...
anthropic.com
Countering misuse of AI: September 2026 / Anthropic
Case studies from threat actors disrupted between December 2025 and August 2026 across seven areas of harm, from cyber operations to biological misuse.
021
Ben Read @benread.bsky.social · 10/09/2026
Get excited folks. This is a great con to go to and present at, always top notch. I have it on good authority that there will be some fun surprises this year.
041
Reposted by Ben Read
Wiz io @wiz.io · 10/09/2026
We built a Cyber Arena to find out how good AI really is at hacking. 🧪 We tested AI like an attacker would (For science) with over 300 real-world offensive AI challenges! 🤖 This gives defenders real data & a clearer view of what AI can do today. www.wiz.io/cyber-model-...
wiz.io
Cyber Model Arena | Wiz
Evaluating AI agents across real-world security challenges
011
Reposted by Ben Read
Mark Kelly @mkyo.bsky.social · 09/09/2026
🚨🌙 Today we are releasing a new @threatinsight blog on BlueMoon, an exploit kit that chained “patch-gap” Chrome zero-days with a Windows zero-day and had indicators of AI-assisted development. It was used by at least four espionage-motivated threat actors since late August.
175
Reposted by Ben Read
No Escalators @noescalators.bsky.social · 06/09/2026
Everyone in these pictures thought they won
8711189
Ben Read @benread.bsky.social · 02/09/2026
We're looking for a couple people to join my strategic threat intel team here at Wiz Sr. Threat Researcher - www.wiz.io/careers/job/... Threat Intel Analyst - www.wiz.io/careers/job/... More details below, but we're looking to hire quickly, so if you're interested, apply now.
wiz.io
Threat Intelligence Researcher (Cloud) | Wiz Careers
Join the Battle for Cloud Security
112
Reposted by Ben Read
Kevin M. Kruse @kevinmkruse.bsky.social · 02/09/2026
Students who nod and smile during lecture when we try to make a point? Heroes
872464162
Reposted by Ben Read
Rob Delaney @robdelaney.bsky.social · 17/07/2026
I’m a card carrying socialist & union member & all that and/but this book fucking torpedoed for me the myth that Democrats & Republicans are “the same.” The massive, fundamental differences btwn D & R administrations in regard to disabled ppl’s lives is INSANE.👩🏻‍🦼‍➡️❤️ judithheumann.com/being-heumann/
judithheumann.com
Being Heumann | Personal Story & Fighting Education | Judithheumann
One of the most influential disability rights activists in US history tells her personal story of fighting for the right to receive education
231283230
Reposted by Ben Read
Timothy Burke @bubbaprog.xyz · 01/09/2026
"don't you have something better to be doing wi..." NO I DON'T I HAD TO DO IT
16918258
Ben Read @benread.bsky.social · 20/08/2026
New (susp) DPRK supply chain operation affecting the arrayref Rust crate: www.wiz.io/blog/rust-su...
wiz.io
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns | Wiz Blog
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios...
020
Reposted by Ben Read
Patrick Meyers @pmeyers7.bsky.social · 12/08/2026
Oh what the actual FUCK? How on earth is this good for anyone? It’s just reducing corporate transparency and putting anyone who does due diligence or AML work in an impossible position! This is genuinely outrageous and totally flying under the radar.
home.treasury.gov
FinCEN Permanently Ends Beneficial Ownership Reporting Requirements for Millions of Small Business Owners
Will Delete Information Previously Reported by U.S. PersonsWASHINGTON––Today, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) is issuing a final rule that permanently removes the requirement for U.S. companies and U.S. persons to report beneficial ownership information to FinCEN under the Corporate Transparency Act.  The final rule is effective on its publication in the Federal Register. FinCEN today also announced that it will delete previously reported information by U.S. persons—now exempt from the reporting requirements—from the beneficial ownership information database. “Today’s action is a victory for common sense and American small businesses,” said Secretary of the Treasury Scott Bessent. “President Trump promised to cut red tape, and this final rule delivers. Treasury is eliminating a burdensome reporting requirement for millions of law-abiding business owners without compromising our national security.” The final rule:adopts the exemptions set out in the interim final rule issued in March 2025, making the rollback of beneficial ownership reporting by U.S. companies permanent;exempts U.S. persons who have obtained FinCEN IDs from any obligation to update or correct the information they originally provided to FinCEN to obtain their FinCEN IDs;eliminates the requirement for foreign companies to report U.S. person “company applicants” (i.e., the individuals who helped those foreign companies register to do business in the United States);exempts foreign pooled investment vehicles registered in the United States from reporting the beneficial ownership information of a U.S person in control of the investment vehicle; andconfirms that FinCEN will delete information about any individuals—company applicants, beneficial owners, or recipients of a FinCEN ID—that FinCEN reasonably believes is a U.S. person (e.g., the information is linked to a U.S. passport or U.S. driver’s license).Under the final rule, foreign entities that are reporting companies will still be required to report beneficial ownership information for foreign individuals. In addition to the final rule, FinCEN has issued Frequently Asked Questions, and will be updating guidance on FinCEN.gov to reflect the final rule. ###
184
Reposted by Ben Read
Aaron Fritschner @fritschner.bsky.social · 11/08/2026
Video of an ICE agent pulling a gun on a wife and mother, who is a US citizen born and raised in the area, near Bailey's Crossroads in Northern Virginia yesterday. Chillingly, they claimed she “almost ran them over” until she told them she had video proving that was a lie.
1814214078940
Reposted by Ben Read
Aaron Reichlin-Melnick @reichlinmelnick.bsky.social · 11/08/2026
This is absolutely WILD. Here's the dashboard video posted by @fritschner.bsky.social. Fast forward to about 1 minute. An ICE officer jumps out of a van and pulls a gun on this woman immediately before lying and claiming she "almost ran us over." *profanity warning if watching in public.
35857632703
Ben Read @benread.bsky.social · 04/08/2026
New supply chain operation compromising keyv and cacheable. Some similarities to TeamPCP, but we're still investigating: www.wiz.io/blog/keyv-an...
wiz.io
keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.
000
Reposted by Ben Read
Jeff Moss @thedarktangent.defcon.social.ap.brid.gy · 25/07/2026
Great new feature in the latest Signal app. If you enable disappearing messages the meta data of calls and missed calls gets deleted as well. I know this was a long standing goal for them, but the engineering behind it took time. #Privacy @signalapp
421693
Reposted by Ben Read
Saher @saffronsec.bsky.social · 23/07/2026
Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...
proofpoint.com
TA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint US
Proofpoint is releasing this report in coordination with NSA and FBI’s JSAC reporting about TA488/Void Blizzard, which can be found here. This is part 1 of a 2-part blog series Proofpoint is
21815
Reposted by Ben Read
Dustin Volz @dustinvolz.bsky.social · 17/07/2026
Mullin just parroted an Iranian disinformation operation from 2020.
20437168
Reposted by Ben Read
Raphael Satter @raphae.li · 08/07/2026
omg this Brian Krebs story: krebsonsecurity.com/2026/07/felo...
krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most...
33418
Ben Read @benread.bsky.social · 07/07/2026
Poland appears to have Kinder Eggs, but for cats?
An egg shaped plastic container with the words "Joy & Toy" and the picture of a cat.
110
Reposted by Ben Read
Dustin Volz @dustinvolz.bsky.social · 18/06/2026
Great story here by my former colleague @bobmcmillan.bsky.social on built-in backdoors in consumer devices that allow nation-state hackers to create huge residential proxy networks. Bob spent months talking my ear off about this. This story is worth your time. www.wsj.com/tech/cyberse...
wsj.com
Exclusive | How Hackers Found a Back Door Into the American Living Room
Nation-state cyberattackers are increasingly using residential proxy networks to mask their traffic, turning everyday electronics into a massive global threat.
0119
Ben Read @benread.bsky.social · 27/05/2026
New from me and the @wizsecurity.bsky.social CIRT team. A novel suspected DPRK crypto targeting cluster. Their tactics are familiar (compromise via supply chain, job interviews) but their malware and infrastructure is different. www.wiz.io/blog/threat-...
wiz.io
Threat Actor Targets Crypto Organizations | Wiz Blog | Wiz Blog
Threat actor, JINX-0164, uses LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target crypto organizations.
040
Reposted by Ben Read
Tom Pepinsky @tompepinsky.com · 25/05/2026
This is nothing short of a bombshell. One of the most trusted media groups in Indonesia has released a report on Russian and Chinese influence operations in Indonesian social media, which blamed local protests on deliberate U.S. meddling. 🧵 1/
23220
Reposted by Ben Read
Oleg Shakirov @shakirov2036.bsky.social · 22/05/2026
Russia and China consider new steps to expand their digital cooperation including on software development and satellite Internet and declare adherence to cyber norms. In this post, I review the relevant sections of the recent joint statement from Beijing fromcyberia.substack.com/p/putin-and-...
fromcyberia.substack.com
Putin and Xi Plan for Co(de)dependence
Russia and China consider expanding their digital cooperation per the joint statement following recent talks in Beijing.
021
Reposted by Ben Read
Andy Greenberg @agreenberg.bsky.social · 21/05/2026
After this week's Github breach, we checked in on hacker group TeamPCP's victim count: their supply chain attacks have tainted more than 500 pieces of software (a thousand-plus different version) and breached hundreds of companies. This is out of control. www.wired.com/story/teampc...
wired.com
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
310645
Reposted by Ben Read
Monica Kello @monicakello.bsky.social · 21/05/2026
Why do some states routinely target civilian systems and commit operational errors, risking escalation, while others pursue highly restrained and carefully calibrated cyber operations, investing enormous amounts of time and resource? www.tandfonline.com/doi/full/10....
tandfonline.com
Fear of the (Un)known: How to Think About Risk and Threat Cultures in Cyber Conflict
The question of how states make operational decisions in cyber conflict is under-theorised. Much of existing scholarship has answered it within general frameworks of materialist and rationalist the...
242
Ben Read @benread.bsky.social · 19/05/2026
New TeamPCP operation targeting Durable Task SDK for Python via PyPl. www.wiz.io/blog/durable...
wiz.io
durabletask: TeamPCP's Latest PyPi Compromise | Wiz Blog
Discover the latest on malicious versions of the pypi package durabletask, matching TeamPCP tactics.
010
Reposted by Ben Read
David Oxley @oxley.io · 01/05/2026
Shame on the government of Zambia for buckling under Chinese government pressure over Taiwan and canceling this year’s @rightscon.org. www.rightscon.org/rc26-stateme...
rightscon.org
A statement to our community about why RightsCon 2026 will not take place in Zambia
Our official statement to the digital rights community about why RightsCon 2026 will not take place in Zambia
041
Ben Read @benread.bsky.social · 01/05/2026
Amherst/Weslyan/Williams
Tina Fey, Timmothy Chalamet and Kyle Jenner at a Nicks Game
020
Ben Read @benread.bsky.social · 24/04/2026
I laundered my Amherst College contribution through the only 5-college team on the list (UMASS), but I had to do my part. #GoMammoths @edsbs.bsky.social @newap-georgia.bsky.social @hollyanderson.bsky.social
$520 donation to UMASS recognizing the ACXC 2007 Women's national title
060
Reposted by Ben Read
Oleg Shakirov @shakirov2036.bsky.social · 23/04/2026
Lotus Wiper was likely used to attack PDVSA One important thing that the Kaspersky report omits is that pdvsa[.]com is hardcoded into OhSyncNow.bat, a file that triggers the wiping operation (HT @benread.bsky.social). This is used to limit the attack to the specified domain 1/11
152
Reposted by Ben Read
Barack Obama @barackobama.bsky.social · 22/04/2026
Congratulations, Virginia! Republicans are trying to tilt the midterm elections in their favor, but they haven’t done it yet. Thanks for showing us what it looks like to stand up for our democracy and fight back.
618433577891
Ben Read @benread.bsky.social · 19/04/2026
Awful to see Jorgenson crash like that. Gutted for him, I hope it's not as bad as it looked. #AGR26
010
Reposted by Ben Read
Ciaran Martin @ciaranm.bsky.social · 14/04/2026
This paper represents a small but deeply impressive and genuinely important achievement by the much maligned British state in what is probably the most important global issue of our era. Hear me out ( 🧵) 1/ www.aisi.gov.uk/blog/our-eva...
aisi.gov.uk
Our evaluation of Claude Mythos Preview’s cyber capabilities | AISI Work
We conducted cyber evaluations of Anthropic’s Claude Mythos Preview and found continued improvement in capture-the-flag (CTF) challenges and significant improvement on multi-step cyber-attack simulati...
4228135
Ben Read @benread.bsky.social · 14/04/2026
I'm live with the @huntress.com folks for Tradecraft Tuesday on axios and DPRK if you want to hang out: events.zoom.us/ejl/AnrTlSR3...
events.zoom.us
All-in-one virtual event platform | Zoom Webinars & Events
020
Ben Read @benread.bsky.social · 12/04/2026
WOUT!!
000
Reposted by Ben Read
Wiz io @wiz.io · 06/04/2026
🚨 500+ malicious PRs. One campaign. Wiz Research traced 6 waves of prt-scan starting 3 weeks earlier. AI-powered, automated attacks exploiting pull_request_target. Low success rate—but real npm + cloud creds hit. Full story: www.wiz.io/blog/six-acc...
wiz.io
prt-scan: AI-Powered GitHub Actions Supply Chain Attack | Wiz Blog
Wiz Research traces six waves of pull_request_target exploitation to one actor, starting three weeks before public disclosure. 500+ malicious PRs, 10% success.
031