Sign in

Matthijs R. Koot

@cyberwar.nl
754 followers 530 following 207 posts

IT, privacy, security, democracy. PhD. PGP: 51F9 8FC9 C92A 1165 (keybase.io/mrkoot). Employed as IT security specialist. Mastodon: @mrkoot@infosec.exchange LinkedIn: /in/mrkoot

PostsRepliesMedia
Reposted by Matthijs R. Koot
Electrospaces.net @electrospaces.bsky.social · 06/10/2026
So the problem isn't as much with former director Hanning but more with his accomplice, former BND chief of staff Manfred D., who was willing to sell the agency's classified reports...
012
Reposted by Matthijs R. Koot
Electrospaces.net @electrospaces.bsky.social · 06/10/2026
In Germany, they arrested August Hanning, who was head of the intelligence agency #BND from 1998 to 2005. From 2010 to 2022, Hanning paid an accomplice at the BND to provide him with classified information which he used for his private consulting work: www.dw.com/en/germanys-...
dw.com
Germany's ex-spy chief arrested for espionage, disclosing state secrets and attempted treason
August Hanning, the man who once led Germany's spy service, is now under investigation for passing on state secrets.
124
Reposted by Matthijs R. Koot
The Insider @theins.press · 06/10/2026
Hunting for cannon fodder: How Russia's private recruitment market for the war in Ukraine really works Targeting debtors, alcoholics, criminals, and other vulnerable groups has become a big business — one that operates with state support.
theins.press
Hunting for cannon fodder: How Russia's private recruitment market for the war in Ukraine really works
The prosecutor's office in the Russian city of Nizhny Tagil proposed scrapping payments to recruiters who sign up contract soldiers for the war in Ukraine,…
01813
Reposted by Matthijs R. Koot
Thomas Brewster @thomasbrewster.bsky.social · 24/09/2026
Well, holy shit... Back in 2017, I wrote a story about Oxygen Forensics and other Russian companies helping hack into iPhones and Androids for American gov. They were really not happy being called Russian. Now, the DOJ has indicted its leadership... Original story: www.forbes.com/sites/thomas...
forbes.com
Meet The Russians Helping The Feds Hack Silicon Valley
At a time when suspicions over Russia are at fever pitch, these Russian security firms are now a part of the U.S. government’s surveillance apparatus and sit on some of the nation’s most sensitive net...
11510
Reposted by Matthijs R. Koot
Doug Madory @eldomador.bsky.social · 20/09/2026
Large BGP routing leak out of Iran earlier today. Mobile provider MCCI (AS197207) originated hundreds of routes including some /8s: 19.0.0.0/8 (Ford) 102.0.0.0/8 (AFRINIC) 29.0.0.0/8 (DoD) 26.0.0.0/8 (DoD) 22.0.0.0/8 (DoD) 21.0.0.0/8 (DoD) x.com/Qrator_Radar...
x.com
Radar by Qrator (@Qrator_Radar) on X
🚨 BGP Hijack at 2026-09-20 10:04 UTC 🇮🇷AS197207 (MCCI-AS) announced 190 prefixes, creating 10,865 conflicts with 1,524 ASNs in 100🌏. 🌏Max propagation: 100% ⏱️Duration: 8 min (first part) and 15 min ...
0103
Reposted by Matthijs R. Koot
Christoph Harig @charig.bsky.social · 15/09/2026
Russian frigate shoots flares at Danish Air Force helicopter in international waters off the Danish coast www.dr.dk/nyheder/indl...
dr.dk
Forsvarets helikopter beskudt med flares fra russisk fregat nær Gedser
Udenrigsministeriet indkalder Ruslands ambassadør, efter at en russisk fregat affyrede to flares mod en dansk helikopter under en rutinemæssig flyvning ud for Gedser mandag.
19531
Reposted by Matthijs R. Koot
Hannah Neumann @hneumannmep.bsky.social · 04/09/2026
EU 🇪🇺 cannot continue “business as usual” while Vučić’s government weaponizes #Serbia’s security apparatus against peaceful students & the opposition. Together with MEPs from 5 political groups, we demand immediate EU action over deployment of #spyware against government critics
1143
Reposted by Matthijs R. Koot
The Register @theregister.com · 01/09/2026
33-hour BGP hijack of Softaculous traffic prompts security scramble
theregister.com
33-hour BGP hijack of Softaculous traffic prompts security scramble
Hosting software vendor tells customers to reset credentials and hunt for malicious packages
022
Reposted by Matthijs R. Koot
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 31/08/2026
NEW: Could AI make software so secure that it will make it harder for governments to use hacking tools and spyware? To try to answer that question, I spoke to cybersecurity and privacy experts, and people with experience finding and exploiting security flaws that can be then sold to governments.
techcrunch.com
How AI could make it harder for governments to use hacking tools | TechCrunch
AI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices.
068
Reposted by Matthijs R. Koot
Russia-Ukraine Daily News @rvps2001.bsky.social · 25/08/2026
ISW: 🇷🇺 Putin is setting conditions for the widespread nationalization of Russian private assets under the broad pretext of defending critical enterprises against Ukrainian strikes, likely in part to generate additional state revenues. understandingwar.org/research/rus... #russia
073
Reposted by Matthijs R. Koot
The Insider @theins.press · 24/08/2026
Cyprus-sourced road cameras for Slovakia were manufactured in Russia and may be used for espionage One of the cameras was found to feature a hidden SIM-card slot and could receive SMS commands from 12 Russian-registered phone numbers.
theins.press
Cyprus-sourced road cameras for Slovakia were manufactured in Russia and may be used for espionage
Slovakia’s Interior Ministry, which is looking to modernize its road traffic monitoring system, had planned to procure 279 speed cameras from a Cyprus-based…
13118
Reposted by Matthijs R. Koot
The Citizen Lab @citizenlab.ca · 20/08/2026
Senior researcher @jsrailton.bsky.social spoke to @techcrunch.com about the “unprecedented” number of Apple users who recently received notifications alerting them to suspected spyware attacks against their devices. Read: techcrunch.com/2026/08/17/u...
techcrunch.com
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators | TechCrunch
Cybersecurity experts who investigate spyware attacks say the number of people who received a recent threat notification from Apple is unusually high.
185
Reposted by Matthijs R. Koot
Matthew Green @matthewdgreen.bsky.social · 15/08/2026
I wrote up a new post about what AI software finding might mean for the backdoor debate. blog.cryptographyengineering.com/2026/08/14/e...
blog.cryptographyengineering.com
Everything is about to “go dark”
I’m coming down from spending a few days at Usenix Security, right here in my hometown of Baltimore. This means that my days have been taken up with two kinds of conversation: first, explaini…
810446
Reposted by Matthijs R. Koot
Kien Tuong Truong @kientuong114.bsky.social · 09/03/2026
Just finished presenting this work at Real World Crypto in Taipei :) TL;DR: We found 2 attacks on Signal (Android, Desktop) where a malicious server can inject messages in conversations. Super fun project! Thanks a bunch to Noemi Terzo, @kennyog.bsky.social, and @cryptojedi.bsky.social
0204
Reposted by Matthijs R. Koot
John Sipher @johnsipher.bsky.social · 05/08/2026
🤦‍♂️ www.reuters.com/world/china/...
reuters.com
EXCLUSIVE: Under Patel, FBI forges unprecedented law enforcement ties with China, Russia
FBI Director Kash Patel says he has forged new law enforcement partnerships with China and Russia, two longtime U.S. rivals, over the past year in hopes of gaining allies in combating transnational cr...
167844
Reposted by Matthijs R. Koot
EPIC @epic.org · 29/07/2026
On Monday, EPIC and @cdt.org urged the FCC to reconsider a proposed rule that would mandate the government collection of more personal data from and about anyone who makes a phone call. While we support the FCC's mission to combat illegal robocalls and scam traffic, this strategy is misguided.
epic.org
EPIC and CDT Urge FCC to Reconsider Invasive Know Your Customer Rulemaking Proposal
Updates
168
Reposted by Matthijs R. Koot
Tor Project @torproject.org · 03/08/2026
🚨 New app alert! Android app called Snowflake Volunteer for those willing to help people reach the Tor network and circumvent censorship from their mobile devices. Built open-source by Bloco, an Android app studio from Portugal. ❄️👉 blog.torproject.org/snowflake-vo...
blog.torproject.org
Snowflake Volunteer, an Android app to help people bypass censorship | Tor Project
There are many ways to help people bypass censorship with Snowflake–a browser extension, using Orbot or Tor Browser, website embedding etc. We set out to experiment with a new mechanism and test an An...
0268
Reposted by Matthijs R. Koot
Anti-Fascism and Far Right @ffrafaction.bsky.social · 01/08/2026
Users on a niche far-right imageboard dedicated to coordinating online harassment campaigns have spent the last year developing artificial intelligence tools meant to help them surface private personal information for the targets of their abuse - aka ‘doxxing’ openmeasures.io/soyjak-ai-do...
openmeasures.io
Users on This Far-Right Imageboard Are Building ‘Fully Autonomous AI Doxxing’ Tools - Open Measures
Open Measures builds accessible and transparent products to contextualize the spread of harmful online content that impacts public discourse and global events.
164
Reposted by Matthijs R. Koot
Miska Knapek @miskaknapek.bsky.social · 31/07/2026
#ceuta 1500 Russian propaganda outlets are publishing disinformation about the Ceuta matter. Each major RT outlet has published at least 25 misleading articles about Ceuta. For reference: Ceuta is not part of the Schengen agreement - so no free mobility from Ceuta to the EU.
0178
Reposted by Matthijs R. Koot
Peter Schrijver @psguu.bsky.social · 29/07/2026
Short note to highlight today's charges against Telegram founder Pavel Durov and my own research into the use of Telegram by the Ukrainian intelligence services: ‘Neutral Telegram’ has become contested intelligence infrastructure; Durov is standing in the middle of it substack.com/@peterschrij...
substack.com
Peter Schrijver (@peterschrijver672321)
‘Neutral Telegram’ has become contested intelligence infrastructure; Durov is standing in the middle of it Today, on 29 July 2026, the Russian security service FSB charged Telegram founder Pavel Duro...
161
Reposted by Matthijs R. Koot
Peter Schrijver @psguu.bsky.social · 29/07/2026
According to: bsky.app/profile/medu...
141
Matthijs R. Koot @cyberwar.nl · 19/07/2026
Re: possible misuse of espionage in Serbia, involving the “Pixel Move” mobile phone tracking device by the Bulgarian company Circles which is capable of intercepting voice communications, messages and internet traffic: thegeopost.com/en/news/komi...
thegeopost.com
European Commission concerned about HRW findings on possible misuse of espionage in Serbia - The Geopost
Share the newsThe European Commission has expressed concern about reports of possible misuse of spy and forensic tools for mobile phones to
010
Reposted by Matthijs R. Koot
The Register @theregister.com · 17/07/2026
Europe's chip ambitions won't break dependence on US cloud and software, says Forrester
theregister.com
Europe's chip ambitions won't break dependence on US cloud and software, says Forrester
Brussels may spend billions on semiconductor fabs, but tech sovereignty remains firmly in American and Chinese hands
152
Reposted by Matthijs R. Koot
The Lobste.rs RSS feed @lobsters-feed.bsky.social · 17/07/2026
PACT: Anonymous Credentials for the Web – Mozilla Hacks lobste.rs/s/6pdyiy #security #privacy
hacks.mozilla.org
PACT: Anonymous Credentials for the Web – Mozilla Hacks - the Web developer blog
A deeper look at PACT: a new initiative to tackle the rising tide of CAPTCHAs on the web whilst keeping the web open and preserving user's privacy.
001
Reposted by Matthijs R. Koot
Martin Matishak @martinmatishak.bsky.social · 09/07/2026
The structure was briefed to Defense Secretary Pete Hegseth last week when he visited Fort Meade, Maryland, which is home to both NSA and U.S. Cyber Command. The Pentagon chief shared a picture of a TAO hat he had signed on his official X account. therecord.media/nsa-revives-...
therecord.media
NSA revives 'Tailored Access Operations' name for elite hacking unit
NSA last week changed the moniker of its Office of Computer Network Operations (CNO) back to Tailored Access Operations (TAO), a name that is sure to elicit nostalgia among the broader digital communi...
011
Reposted by Matthijs R. Koot
Saskia Dekkers @saskiadekkers.bsky.social · 09/07/2026
« The real damage, however, is psychological and political. While we were able to remove the threats from our systems, what we cannot so easily remove is the knowledge that a dictatorship’s security service has walked all over our private and professional lives. That feeling stays.»
0106
Reposted by Matthijs R. Koot
Huib Modderkolk @huibmodderkolk.bsky.social · 08/07/2026
NEW: Despite persistent warnings from American and British officials, Dutch intelligence agencies refused to believe Putin would invade Ukraine in 2022. Insiders reveal how it all went so wrong. ‘This was the highest-stakes game I’ve ever played.’ www.volkskrant.nl/kijkverder/v...
volkskrant.nl
‘Unique source’ blinded Dutch intelligence agencies to Putin’s invasion: ‘What a fuck-up’
Despite persistent warnings from American and British officials, the Dutch intelligence agencies refused to believe Putin would invade Ukraine in 2022. An investigation by de Volkskrant reveals how…
45125
Reposted by Matthijs R. Koot
Jason Kikta @kikta.net · 08/07/2026
HAHAHAHAHAHAHAHAHA No idea what the specific impetus was, but years of yolo posting random crap and ignoring DoD regulations on social media certainly didn’t help.
A tweet by the 780th Military Intelligence Brigade:

Effective immediately, the 780th Military Intelligence Brigade (Cyber) is not an Army organization authorized to manage an official social media account and is directed to close and archive all brigade accounts pursuant to the Army records management policy.
The @780thC is as a Major Subordinate Command under the U.S. Army Intelligence and Security Command, while also serving under the operational control of U.S. Army Cyber Command. You are invited to subscribe to their social media pages.
The Brigade is waiting on further instructions; however, it has been a privilege to be in this space.

[picture with unit logo and text]
Effective immediately, the 780th Military Intelligence Brigade (Cyber) is not an Army organization authorized to manage an official social media presence and is directed to close and archive all accounts pursuant to the Army records management policy.
The 780 MI BDE (CY) is as a Major Subordinate Command under the U.S. Army Intelligence and Security Command, while also serving under the operational control of U.S. Army Cyber Command. You are invited to subscribe to their social media pages.
It has been a privilege to be in this space.
1172
Reposted by Matthijs R. Koot
Chatham House @chathamhouse.org · 08/07/2026
Recent intelligence reports from Sweden, Estonia and other NATO allies have suggested that Russia is preparing to test the alliance and its commitment to mutual defence via Article 5.
chathamhouse.org
Tensions between the US and Europe loom large over NATO summit
Disagreements over the Iran war and defence procurement threaten to turn the annual summit into another theatre for division and distract from the threat from Russia.
42610
Reposted by Matthijs R. Koot
P(Doomien) Miller @damienmiller.bsky.social · 06/07/2026
OpenSSH 10.4 has just been released This release includes a number of security and bug fixes, as well as a handful of new features - most notable experimental support for a hybrid post-quantum signature scheme (ML-DSA 44 with Ed25519). www.openssh.org/releasenotes...
openssh.org
OpenSSH: Release Notes
OpenSSH release notes
04313
Reposted by Matthijs R. Koot
Bart Groothuis @bartgroothuis.bsky.social · 07/07/2026
Here’s the action plan from the European Commission digital-strategy.ec.europa.eu/en/library/e... Here are the recommendations for businesses by ENISA www.enisa.europa.eu/publications...
digital-strategy.ec.europa.eu
EU Action Plan on Cybersecurity and Artificial Intelligence
The European Commission has presented an Action Plan on Cybersecurity and Artificial Intelligence to support the safe and responsible use of AI while strengthening Europe's cybersecurity.
012
Reposted by Matthijs R. Koot
Bart Groothuis @bartgroothuis.bsky.social · 07/07/2026
Business leaders should take good note of the action plan on AI and cyber security the European Commission and ENISA put forward today. It’s not business as usual anymore. You have a few months to fix software vulnerabilities and the recommendations below will help you to do so 👇
143
Reposted by Matthijs R. Koot
The Register @theregister.com · 04/07/2026
Confidential computing's core trust mechanism is broken. The fix may not exist
theregister.com
Confidential computing's core trust mechanism is broken. The fix may not exist
Attested TLS: the handshake that can't prove who's on the other end
1155
Reposted by Matthijs R. Koot
Hacker News 200 Points @newsyc200.bsky.social · 29/06/2026
Age verification is just a precursor to automated attribution of speech nonogra.ph/age-verification-is-just… (news.ycombinator.com/item?id=487145…)
023
Reposted by Matthijs R. Koot
Organized Crime and Corruption Reporting Project @occrp.org · 26/06/2026
JUST OUT: 🔴 How Russia's defense industry buys European machinery Read more in OCCRP Weekly, our flagship email newsletter on the latest in organized crime and corruption: eepurl.com/5WN1X0frg2 Subscribe: eepurl.com/dv_Lov
03816
Reposted by Matthijs R. Koot
Patrick Breyer @echo-pbreyer.digitalcourage.social.ap.brid.gy · 26/06/2026
Montag droht der #Chatkontrolle-Worst-Case: 👁️ Verpflichtende Massenscans privater Nachrichten 🆔 Alterskontrolle für Messenger (= Ende der Anonymität!) 📰 Hintergrund im Blog […]
digitalcourage.social
Original post on digitalcourage.social
23342
Reposted by Matthijs R. Koot
Matt Blaze @mattblaze.federate.social.ap.brid.gy · 20/06/2026
A reminder that the #Defcon Voting Village Call for Presentations is open. If you've got interesting work on election security, please submit it! August 7-9 at DEFCON in Las Vegas. votingvillage.info/defcon-2026/cfp
votingvillage.info
Voting Village - Preserving Democracy
It Takes a Village to Preserve Democracy. Support election integrity through research and education.
123
Reposted by Matthijs R. Koot
Jeff Moss @thedarktangent.defcon.social.ap.brid.gy · 10/06/2026
Pretty major #Tor upgrade, full of security fixes. If you are a Relay or Onion operator please upgrade! gitlab.torproject.org/tpo/core/tor/…
0106
Reposted by Matthijs R. Koot
Joseph Cox @josephcox.bsky.social · 09/06/2026
New: the FCC is trying to ban burner phones by forcing all telecoms to store ID information on all new and renewing customers. That includes a government issued ID number. Massive privacy-impacting change “We never thought that would happen here,” the ACLU says www.404media.co/fcc-wants-to...
404media.co
FCC Wants to Kill Burner Phones By Forcing Telecoms to Get All Customers’ IDs
The FCC wants to legally force telecoms to collect new and renewing customers' government issued identity number and physical address, impacting everyone from the privacy-conscious to domestic abuse s...
541144720
Reposted by Matthijs R. Koot
🦇🎃💀 Riana-mator 💀🎃🦇 @riana.bsky.social · 20/05/2026
Reminder that I maintain a periodically-updated reading list of papers at the intersection of E2EE and Trust & Safety; suggestions welcome: docs.google.com/spreadsheets...
docs.google.com
Encryption + Trust & Safety reading list (updated 2026-05-20)
28222
Reposted by Matthijs R. Koot
Max Bernhard @mxbernhard.bsky.social · 09/06/2026
"The director of Russia’s FSB ... cautioned regional security chiefs last week that Russia’s vast surveillance apparatus had become a vulnerability — turning the authoritarian regime’s tools to monitor its own citizens into a weakness its enemies could exploit" www.ft.com/content/6f4d...
ft.com
New AI espionage powers trigger Putin camera scare
Russia paused surveillance system after killing of Iran’s Supreme Leader exposed how AI can be used on CCTV data to target enemies
097
Reposted by Matthijs R. Koot
Ruslan Trad @ruslantrad.bsky.social · 09/06/2026
Russia is taking drastic measures to prevent European countries from seizing shadow fleet tankers. @ftm.eu's latest investigation reveals dozens of Russian security guards with military, intelligence, and mercenary backgrounds aboard tankers carrying sanctioned oil.
ftm.eu
Russian mercenaries are protecting oil tankers – and are telling FTM how
Follow the Money - Platform for investigative journalism
15315
Reposted by Matthijs R. Koot
Etienne - Tek @tek.randhome.io · 08/06/2026
Amnesty is recruiting a Technologist in their team researching digital surveillance abuse, this is an amazing position in an amazing team. Location is limited to a few places and deadline is really soon careers.amnesty.org/jobs/vacancy...
careers.amnesty.org
Amnesty International Careers
Amnesty International Careers, Jobs, Search and Apply
03035
Reposted by Matthijs R. Koot
Elise Thomas @elisethomas.bsky.social · 04/06/2026
Here's me for @bellingcat.com tracing Russia Today subsidiary Ruptly's digital footprints all the way from Berlin to Abu Dhabi www.bellingcat.com/news/2026/06...
bellingcat.com
Tracing Digital Links Between Viory and Ruptly - bellingcat
Bellingcat found mulitple links between the digital infrastructure of Viory and Ruptly news agency, a branch of Russia Today.
01610
Reposted by Matthijs R. Koot
Steven Murdoch @steven.murdoch.is · 02/06/2026
For 19 years, GPS satellites have secretly broadcast a “numbers station” in their signals. We decoded 12M messages: a 2011 flash where 31 satellites flipped in hours, “ghost” substrings repeating years apart, and a “TEXT” prefix spreading now. lsc-pagepro.mydigitalpublication.com/publication/...
lsc-pagepro.mydigitalpublication.com
Inside GNSS Media & Research • May/June 2026 • 62
621985
Reposted by Matthijs R. Koot
Starboard Maritime Intelligence @starboardintelligence.com · 30/05/2026
“For data on the AIS-off events and movement near undersea cables, we obtained additional data support from Starboard Maritime Intelligence, a platform utilized by government agencies, defense forces and critical infrastructure operators to analyze maritime risks” pulitzercenter.org/resource/how...
pulitzercenter.org
How (and Why) We Tracked China’s Deep-Sea Mining Fleet
We didn’t initially set out to investigate China’s deep-sea mining fleet, but as our research into other aspects of the burgeoning industry developed over our year-long partnership, it became clear...
16226
Reposted by Matthijs R. Koot
The Steady State @thesteadystate.org · 29/05/2026
Washington Walk& Talk: Former senior national security officials warn that America’s checks and balances are weakening, and Congress needs to hear directly from voters like you.
45624
Matthijs R. Koot @cyberwar.nl · 26/05/2026
ter aanvulling, niet gerelateerd aan je stelling: de betrokkenen kunnen een bezwaarprocedure starten tegen het verbod, en het is in het verleden al eens voorgekomen dat een verbod van BTI na bezwaar werd omgezet in een “goedkeuring onder voorwaarden”. Benieuwd hoe het bij deze casus zal verlopen.
020
Reposted by Matthijs R. Koot
Huib Modderkolk @huibmodderkolk.bsky.social · 22/05/2026
NEW: The consultant, the pianist, and the Kremlin’s hackers EU sanctions were supposed to shut down Russia’s bulletproof hosting network. Instead, it moved next door New investigation, together with the great @moltke www.volkskrant.nl/binnenland/h...
volkskrant.nl
How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers
In the international information war, few methods are off-limits. Pro-Russian cybercriminals carry out attacks to sow fear and disrupt Western societies. De Volkskrant investigated how Dutch…
01716