Sign in

Greg Otto

@gregotto.bsky.social
5.6K followers 500 following 1K posts

@gregotto from twitter, now on bluesky. Editor-in-Chief at CyberScoop. Host of Safe Mode. Better with words than I am with code.

PostsRepliesMedia
Greg Otto @gregotto.bsky.social · 19h
NEW: Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected cyberscoop.com/citrix-netsc...
cyberscoop.com
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They expect more attacks to come.
021
Greg Otto @gregotto.bsky.social · 23h
This truly is worth every second of your time.
021
Greg Otto @gregotto.bsky.social · 29/09/2026
cursory prompt check on america dot gov
Questions i asked america dot gov hoping it would tell me what the model is. Prompted like i was writing an academic paper, and just throwing out stuff to see if i could test the model.Questions i asked america dot gov hoping it would tell me what the model is. Prompted like i was writing an academic paper, and just throwing out stuff to see if i could test the model.Questions i asked america dot gov hoping it would tell me what the model is. Prompted like i was writing an academic paper, and just throwing out stuff to see if i could test the model.
030
Greg Otto @gregotto.bsky.social · 29/09/2026
You're all free to just concentrate on NetScaler now: Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities cyberscoop.com/kiteworks-li...
cyberscoop.com
Kiteworks lifts shutdown advisory after 'credible threat intelligence' from federal authorities
Kiteworks lifted a weekend precautionary shutdown advisory issued after federal authorities warned of an imminent cyber threat, patching a newly discovered vulnerability in its Advanced Forms tool.
110
Greg Otto @gregotto.bsky.social · 26/09/2026
You argue about alignment. I fix mine. We are not the same.
120
Greg Otto @gregotto.bsky.social · 26/09/2026
Reeeeeeeally straining to see why agents accessing public data sets is being described as “meddling” or “going rogue” but everyone’s lost the plot anyway so I’m gonna go crack a beer see yall Monday
030
Greg Otto @gregotto.bsky.social · 24/09/2026
I see this has been taken down but what sort of journo would I be if I didn’t Save to PDF
140
Greg Otto @gregotto.bsky.social · 24/09/2026
So this has consumed my afternoon and has sent me down a rabbit hole that makes me feel like i'm living at the end of sanity www.verysane.ai/p/ai-safety-...
verysane.ai
110
Greg Otto @gregotto.bsky.social · 24/09/2026
Sen. Mark Warner and Sen. Ted Cruz are introducing legislation to foster cybersecurity standards for the telecommunications sector nearly two years after the landmark Salt Typhoon campaign was made public. cyberscoop.com/senate-telec...
cyberscoop.com
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Sens. Mark Warner and Ted Cruz introduced bipartisan legislation to establish voluntary telecom cybersecurity standards nearly two years after the Salt Typhoon hack.
110
Greg Otto @gregotto.bsky.social · 24/09/2026
This is symphonic
033
Greg Otto @gregotto.bsky.social · 23/09/2026
This is one of the saddest things I've ever read www.sonicwall.com/blog/the-soc...
sonicwall.com
SOC Van Pelt: Knowing a Threat Isn't Stopping It
Lane Kiffin built Ole Miss's roster, coaching staff, and quarterback room. It still beat him. Here's what that says about mistaking familiarity for readiness in security.
220
Greg Otto @gregotto.bsky.social · 22/09/2026
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud cyberscoop.com/microsoft-ev...
cyberscoop.com
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise.
011
Greg Otto @gregotto.bsky.social · 17/09/2026
The fact I got this as a push alert could explain a lot imo
A LinkedIn push alert that says I would be a top applicant for Anthropic’s head of vulnerability disclosure and security community position (I am not qualified for this)
050
Greg Otto @gregotto.bsky.social · 17/09/2026
Hygiene > panic cyberscoop.com/ai-agent-hac...
cyberscoop.com
The AI hacking apocalypse is not inevitable
Cybersecurity experts push back against "AI doomer" narratives, arguing that emerging AI agent hacking threats can be managed through established security controls.
141
Greg Otto @gregotto.bsky.social · 16/09/2026
CISA promotes a fresh way to deter cyberattackers: Lie to them cyberscoop.com/cisa-guidanc...
cyberscoop.com
CISA promotes a fresh way to deter cyberattackers: Lie to them
CISA issued new guidance advising critical infrastructure operators on using cyber decoys and honeytokens to cheaply detect and distract network intruders.
121
Greg Otto @gregotto.bsky.social · 16/09/2026
Coast Guard, FBI board foreign ships coming to US to probe cyberattacks cyberscoop.com/coast-guard-...
cyberscoop.com
Coast Guard, FBI board foreign ships coming to US to probe cyberattacks
The U.S. Coast Guard and FBI boarded two foreign tankers in the Gulf of Mexico to investigate cyberattacks that compromised the vessels' operational and IT networks.
162
Greg Otto @gregotto.bsky.social · 16/09/2026
This is insane www.reuters.com/legal/govern...
reuters.com
US charges five people in alleged Russian-backed murder plots
The U.S. Department of Justice has charged five people ​in connection with alleged Russian plots involving surveillance, recruitment and ‌targeted killings, according to an indictment unsealed on Tues...
142
Greg Otto @gregotto.bsky.social · 11/09/2026
Sorry for being pedantic, but I am going to scream this until i collectively see better: stop calling AI 'rogue.' Using that word connotes that these models have the agency to decide what is (and is not) appropriate w/r/t its instructions. It's computing just like someone typing cd ~ into bash.
341
Greg Otto @gregotto.bsky.social · 10/09/2026
What i told you there was enough cyber in this anthropic threat report for you to stay occupied until the next model dropped cyberscoop.com/anthropic-re...
cyberscoop.com
AI lets small actors run state-level hacking campaigns, Anthropic report finds
A new threat report from Anthropic reveals that AI is erasing the skill gap between lone cybercriminals and state-sponsored espionage operations.
242
Greg Otto @gregotto.bsky.social · 10/09/2026
Lmao @hultquist.bsky.social did it again folks
Terminator coming out of the computer
040
Greg Otto @gregotto.bsky.social · 10/09/2026
Breathtaking stupidity wrapped in hubris
031
Greg Otto @gregotto.bsky.social · 09/09/2026
lmao tell me again how this is so cutting edge "Despite those restrictions, agents still found ways to talk to one another...similar to how students forbidden from talking to one another during an exam can still share ​answers by scrawling notes on a bathroom stall." www.reuters.com/world/openai...
reuters.com
EXCLUSIVE: OpenAI’s rogue agents used at least 10 more sites for unauthorized comms, researchers say
AI agents unleashed by OpenAI used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, according to six sets of independent investigators and data reviewed ...
110
Greg Otto @gregotto.bsky.social · 09/09/2026
In other FBI cyber news @timstarks.bsky.social has an exclusive look at the FBI's cyber strategy which was released today, and more comments from FBI cyber leaders who say AI isn’t doing anything that attention to cybersecurity basics wouldn’t prevent cyberscoop.com/fbi-cyber-st...
cyberscoop.com
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
The FBI is unveiling a new cyber strategy addressing AI-powered hacker threats while urging organizations to abandon quarterly updates for continuous, risk-based patching.
042
Greg Otto @gregotto.bsky.social · 09/09/2026
FBI cyber chief worries private sector not sharing enough cyber threat information cyberscoop.com/fbi-cyber-di...
cyberscoop.com
FBI cyber chief worries private sector not sharing enough cyber threat information
FBI Cyber Division Assistant Director Brett Leatherman dispelled misconceptions about regulatory data sharing, urging private firms to report nation-state breaches under a "share until it hurts" polic...
011
Greg Otto @gregotto.bsky.social · 09/09/2026
Beyond exhausted with the AI doomerism. A lot of apocalyptic bluster and hand-waving, and zero concrete examples of how it happens. The computer god is gonna wipe out the nurse? The farmer? The teacher? When it can’t produce a picture of breakfast burrito w/o making ppl sick? Get out of my face.
131
Greg Otto @gregotto.bsky.social · 08/09/2026
CIA Dep. Dir. Michael Ellis said Tuesday that the agency’s role in Operation Absolute Resolve is an example of how it has moved to put cyber operations at the center of intelligence collection and field missions, rather than treat them as a separate technical service. cyberscoop.com/cia-cyber-op...
cyberscoop.com
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
CIA Deputy Director Michael Ellis revealed at the Billington Cybersecurity Conference that elevated cyber intelligence enabled Special Operations forces to locate and apprehend Nicolás Maduro during O...
120
Greg Otto @gregotto.bsky.social · 03/09/2026
Been using both this morning with zero issues??? Weird
310
Greg Otto @gregotto.bsky.social · 01/09/2026
NEW: A newly released whistleblower complaint reveals details about the “rushed” effort by the Trump admin and USPS to install three new restrictive IT systems that would potentially deny thousands of mail-in ballots, if the federal gov disagrees on their eligibility. cyberscoop.com/usps-whistle...
cyberscoop.com
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
A new whistleblower complaint alleges the USPS is rushing untested IT systems ahead of the 2026 midterms, threatening to reject thousands of mail-in ballots over minor errors.
085
Greg Otto @gregotto.bsky.social · 31/08/2026
The Trump administration rolled out a six-month test program in Texas on Monday that will draw on volunteer expertise and technology from cyber and artificial intelligence companies to protect the water sector. cyberscoop.com/watershed-25...
cyberscoop.com
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Federal officials and Texas launch Watershed 250, a six-month pilot program partnering with top tech firms to protect water infrastructure against foreign cyber threats.
211
Greg Otto @gregotto.bsky.social · 27/08/2026
Completely undone by cat photos - cyberscoop.com/teampcp-cybe... VX Underground is somewhere laughing
cyberscoop.com
Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
Australian authorities have arrested two alleged members of cybercrime group TeamPCP over widespread supply-chain attacks that compromised more than 1,000 organizations worldwide.
081
Greg Otto @gregotto.bsky.social · 26/08/2026
NEW: DHS CIO Antoine McCord is set to depart the agency, according to people who spoke with @timstarks.bsky.social and @lindseywilkinson.bsky.social fedscoop.com/dhs-cio-depa...
fedscoop.com
DHS CIO Antoine McCord to exit agency
The Anduril alum and Marine Corps veteran joined DHS as its top technology leader in March 2025. He is the latest CIO planning to leave the role amid a slew of other resignations.
041
Greg Otto @gregotto.bsky.social · 26/08/2026
NEW: OpenAI has released an in-depth tech report on the HuggingFace incident, finding that the agent behavior that led to intrusion formed in May cyberscoop.com/openai-huggi...
cyberscoop.com
OpenAI: Agent behavior that led to Hugging Face intrusion formed in May
An OpenAI technical report details how autonomous AI agents collaborated to breach Hugging Face, citing key alignment and security failures.
140
Greg Otto @gregotto.bsky.social · 26/08/2026
ITS 2026!!!!!!!!!!
131
Greg Otto @gregotto.bsky.social · 26/08/2026
Cellebrite has announced a Tactical Extraction Kit (C-TEK), bringing its phone-cracking tech to the military. @brandivincent.bsky.social has more on it on @defensescoop.bsky.social defensescoop.com/2026/08/26/c...
defensescoop.com
Aiming to turn ‘every device into a source,’ Cellebrite launches made-for-the-military data extraction kit
The Israeli firm’s new C-TEK product triages data from mobile phones, SIM cards, computers, drones and other portable media.
011
Greg Otto @gregotto.bsky.social · 26/08/2026
So after all of the noise about Tina Peters being hired to run elections in Calif., county exec Clint Curtis called up @derekbjohnson.bsky.social this week to explain more about why he is comfortable employing the convicted felon cyberscoop.com/shasta-count...
cyberscoop.com
Election official says Tina Peters would be consultant, won’t have access to election systems
Shasta County registrar Clint Curtis offered convicted ex-clerk Tina Peters a consulting role for the 2026 elections despite parole hurdles and state outrage.
012
Greg Otto @gregotto.bsky.social · 25/08/2026
The GTA VI leaks are breaking the internet. Security researchers have seen this before. cyberscoop.com/grand-theft-...
cyberscoop.com
The GTA VI leaks are breaking the internet. Security researchers have seen this before.
A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience.
122
Greg Otto @gregotto.bsky.social · 25/08/2026
Joshua Culver, aka “Maverick Young,” allegedly impersonated an NSA elite hacking unit and the Supreme Court chief justice in an attempt to get info out of Indiana officials, including the location of his biological daughter. cyberscoop.com/arrested-man...
cyberscoop.com
Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice
Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that.
052
Greg Otto @gregotto.bsky.social · 20/08/2026
@derekbjohnson.bsky.social with an exclusive to @cyberscoop.bsky.social on dc groups coming together to push for the designation of AI as the next critical infrastructure sector cyberscoop.com/ai-critical-...
cyberscoop.com
The push to designate AI as the next critical infrastructure sector
A new report calls on the U.S. to designate the AI sector as critical infrastructure, naming CISA as the lead agency to protect models and data centers against cascading cyberthreats.
258
Reposted by Greg Otto
Patrick Howell O’Neill @patrickhowelloneill.com · 19/08/2026
There's a whole cottage industry now of professional posters who take journalism and repost it with no credit, no link. What's considered normal now is wild. Polymarket is a multibillion dollar company and their whole social media strategy is to never ever credit journalists who work they use
23511
Greg Otto @gregotto.bsky.social · 19/08/2026
I'm sorry, I'm geeking out over this game as much as an employed 40+ yr old can, but this is insane www.cbsnews.com/news/grand-t...
cbsnews.com
Army unit offers 4-day pass to play Grand Theft Auto VI as reenlistment incentive
Eligible soldiers must reenlist for a minimum of two years and up to six years.
100
Greg Otto @gregotto.bsky.social · 19/08/2026
The long tail of Clop’s PTC hack is just beginning to emerge cyberscoop.com/clop-zero-da...
cyberscoop.com
The long tail of Clop’s PTC hack is just beginning to emerge
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims.
154
Greg Otto @gregotto.bsky.social · 18/08/2026
Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute cyberscoop.com/mabna-instit...
cyberscoop.com
Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute
Federal authorities unsealed an indictment against 17 Iranians affiliated with the Mabna Institute, alleging a campaign of vast state-sponsored cybertheft.
051
Greg Otto @gregotto.bsky.social · 17/08/2026
This is such a good story
031
Greg Otto @gregotto.bsky.social · 16/08/2026
This is why I don’t trust this line of tech. I’ve seen the same thing with the Declaration of Independence. I’ve seen the same thing with my writing! I’ve seen it say AI-generated stuff is 100 percent human. Not a good indicator at all!
020
Greg Otto @gregotto.bsky.social · 13/08/2026
There's been a lot of prognosticating on when other AI models were going catch up to Mythos/GPT-Cyber. Like everything else, it seems we're approaching that quicker than anyone could have anticipated. @derekbjohnson.bsky.social has more: cyberscoop.com/mid-tier-ai-...
cyberscoop.com
AI’s ‘middle class’ has gotten dramatically better at hacking
As frontier models and their sandbox escaping exploits dominate front-page news, researchers are increasingly worried about cheaper, more efficient AI models.
001
Greg Otto @gregotto.bsky.social · 11/08/2026
NEW: Delta is investigating that viral Wi-Fi spoofing incident. Everyone i talked to stressed two things: The flight was never in any real danger and everyone investigating this is extremely annoyed cyberscoop.com/delta-flight...
cyberscoop.com
Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas
Delta and federal authorities are investigating a rogue Wi-Fi spoofing incident aboard Flight 591 from Las Vegas to Atlanta following DEF CON.
32111
Greg Otto @gregotto.bsky.social · 11/08/2026
NIST is looking for input on how to overhaul its vulnerability reporting process to better meet the challenges of an “evolving cybersecurity landscape increasingly shaped by artificial intelligence and machine-consumable security data.” cyberscoop.com/nist-nationa...
cyberscoop.com
NIST wants to overhaul its vulnerability database for the AI age
NIST is requesting public feedback to overhaul the National Vulnerability Database, aiming to integrate AI and automation to counter faster, machine-driven threats.
051
Greg Otto @gregotto.bsky.social · 11/08/2026
The FTC wants to start regulating ideological bias in AI systems and assert federal control over state laws. They’re getting an earful from opponents on all sides of the political spectrum. Great read from @derekbjohnson.bsky.social cyberscoop.com/ftc-regulati...
cyberscoop.com
The FTC wants to regulate AI for ideological bias
The commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech.
024
Greg Otto @gregotto.bsky.social · 07/08/2026
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports cyberscoop.com/north-caroli...
cyberscoop.com
Coast Guard says it is monitoring cyberattack that disrupted North Carolina's ports
The U.S. Coast Guard is monitoring a cyberattack that disrupted gate operations across North Carolina ports as officials investigate the breach.
142
Greg Otto @gregotto.bsky.social · 06/08/2026
NEW:A new scan of internet-connected industrial equipment conducted Monday -- days after an FBI/EPA advisory -- found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online, including 22 in cities impacted by cyberattacks on U.S. water systems. cyberscoop.com/exposed-rock...
cyberscoop.com
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
New research reveals over 4,000 Rockwell Automation controllers exposed online, including 22 in cities recently targeted by cyberattacks on U.S. water systems.
000