Sign in

John Hultquist

@hultquist.bsky.social
9.8K followers 310 following 230 posts

Mandiant Intelligence at Google. CYBERWARCON and SLEUTHCON founder. Johns Hopkins professor. Army vet.

PostsRepliesMedia
John Hultquist @hultquist.bsky.social · 13/05/2026
If you've been laid off from a cyber threat intel position and would like to come to @SLEUTHCON this year, please reach out.
1129
John Hultquist @hultquist.bsky.social · 11/05/2026
Google Threat Intelligence Group is dropping our latest AI Threat Tracker report today, which covers several threats we are watching through a variety of means. The report includes some details of the first 0day exploit we've found developed with AI. 1/x cloud.google.com/blog/topics/...
cloud.google.com
Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access | Google Cloud Blog
Explore GTIG's 2026 report on how adversaries leverage AI for zero-day exploits, autonomous malware, and industrial-scale cyber operations.
21311
Reposted by John Hultquist
Dustin Volz @dustinvolz.bsky.social · 11/05/2026
Google finds evidence a criminal hackers attempted a widespread campaign that relied on a 0day built by artificial intelligence. “It’s a taste of what’s to come,” @hultquist.bsky.social says. www.nytimes.com/2026/05/11/u...
nytimes.com
Google Says Criminal Hackers Used A.I. to Find a Major Software Flaw
56326
Reposted by John Hultquist
Frank Bajak @fbajak.bsky.social · 11/05/2026
Google disrupts hackers who used AI to identify a “zero day” vulnerability in popular online system administration tool (that it would not name). “It’s here,” said @hultquist.bsky.social “The era of AI-driven vulnerability and exploitation is already here.” apnews.com/article/goog...
apnews.com
Google disrupts hackers using AI to exploit an unknown weakness in a company's digital defense
Google said Monday that it had disrupted a criminal group’s attempt to use artificial intelligence to exploit another company’s previously unknown digital vulnerability, adding to heightened worries a...
014
Reposted by John Hultquist
SLEUTHCON @sleuthcon.bsky.social · 23/04/2026
The speaker lineup is here! 🐍 SLEUTHCON 2026 is six weeks away, and the lineup is stacked. Check it out and grab your tickets today! Happening June 5th, 2026, in Arlington, VA + virtually! www.sleuthcon.com #SLEUTHCON #CybersecurityEvents
054
John Hultquist @hultquist.bsky.social · 17/04/2026
Getting ready to read these @sleuthcon.bsky.social talk proposals! Last day sleuths! IT’S CRIME TIME!
media.tenor.com
a man in a purple and black jacket with a ravens logo on the front
ALT: a man in a purple and black jacket with a ravens logo on the front
011
Reposted by John Hultquist
John Hultquist @hultquist.bsky.social · 06/04/2026
The @SLEUTHCON CFP closes next week. Don’t waste valuable time doing your taxes. Submit! Submit! Submit!
174
John Hultquist @hultquist.bsky.social · 06/04/2026
The @SLEUTHCON CFP closes next week. Don’t waste valuable time doing your taxes. Submit! Submit! Submit!
174
John Hultquist @hultquist.bsky.social · 31/03/2026
We are still looking at the axios supply chain compromise, but we’ve attributed it to UNC1069, a suspected DPRK actor, who we covered in a blog this February. They are financially-motivated and historically DPRK uses these incidents to target crypto. cloud.google.com/blog/topics/...
cloud.google.com
UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering | Google Cloud Blog
North Korean threat actors target the cryptocurrency industry using AI-enabled social engineering such as deepfakes, and ClickFix.
0107
Reposted by John Hultquist
Ben Read @benread.bsky.social · 18/03/2026
Get your tickets (and CFPs) now! This conference is always a great time and you learn a lot.
074
Reposted by John Hultquist
SLEUTHCON @sleuthcon.bsky.social · 18/03/2026
SLEUTHCON 2026 is coming! 🐍🐻🌲 Registration is open and our CFP is live! We're back on June 5th, in-person in Arlington, VA and virtually. CFP closes April 17th + tickets will sell out! sleuthcon.com #SLEUTHCON #SLEUTHCON2026 #Cybercrime
02216
Reposted by John Hultquist
Danny Palmer @dannypalmer.bsky.social · 02/03/2026
Today I went to RUSI and @hultquist.bsky.social told me his thoughts about what to expect from Iranian cyber operations in the near future... Essentially, while tactics won't suddenly change, he believes the attacks will have a much wider scope... www.infosecurity-magazine.com/news/iran-cy...
infosecurity-magazine.com
Expect Iran to Launch Cyber-Attacks Globally, Warns Google
John Hultquist suggests “aggressive” Iranian cyber attackers will target the US and its Gulf allies with plausibly deniable ransomware attacks, hacktivist campaigns and more
176
John Hultquist @hultquist.bsky.social · 25/02/2026
Google Threat Intelligence Group took down a massive, longterm intrusion campaign into global telcos and government. This PRC-nexus actor built a vast surveillance tool across 42 confirmed countries and another 20 suspected countries. 1/x
47623
John Hultquist @hultquist.bsky.social · 05/02/2026
The conditions are absolutely ripe for cyberattacks on the Winter Games. In addition to historic precedent like Sandworm’s attempted disruption of the Pyeongchang opening ceremonies, Russian sabotage and cyberattack in Europe right now is reaching fever pitch. 1/x
161
John Hultquist @hultquist.bsky.social · 02/02/2026
Notepad++ compromised in supply chain attack from June to December 2025 by “likely Chinese state-sponsored actor”. notepad-plus-plus.org/news/hijacke...
notepad-plus-plus.org
Notepad++ Hijacked by State-Sponsored Hackers | Notepad++
2188
Reposted by John Hultquist
Eric Geller @ericjgeller.com · 30/01/2026
"The actor Poland has identified is notable for a lengthy history of digging into global critical infrastructure while holding back on actual attacks," @hultquist.bsky.social says. "If they have finally pulled the trigger, that would be a major departure from over a decade of restraint."
021
John Hultquist @hultquist.bsky.social · 30/01/2026
Poland releases details on December’s cyberattack on their energy infrastructure, noting similarities to prior FSB activity. The wiper has been attributed by others to Sandworm (GRU). Attribution is definitely not super clear yet. 1/x cert.pl/uploads/docs...
cert.pl
294
Reposted by John Hultquist
The Vertex Project @vertexproject.bsky.social · 06/11/2025
Ready to put your analysis skills to the test? Join us on Nov 18 (pre-CYBERWARCON) for a Synapse challenge using a real-world scenario. There will be snacks and limited-edition challenge coins! vertex.link/events/cyber...
095
Reposted by John Hultquist
CYBERWARCON @cyberwarcon.bsky.social · 30/10/2025
Meet our speaker: Kevin Hoganson! He leverages a broad skill set across cyber threat intelligence, digital forensics & incident response. His talk highlights commercial spyware actors' cleanup of forensic artifacts which prevents meaningful analysis of mobile device infections. www.cyberwarcon.com
051
Reposted by John Hultquist
CYBERWARCON @cyberwarcon.bsky.social · 30/10/2025
Tickets are almost sold out. Nerds. www.cyberwarcon.com
1115
Reposted by John Hultquist
CYBERWARCON @cyberwarcon.bsky.social · 24/10/2025
Meet our speaker Dlshad Othman! He has fifteen+ years of experience in threat intelligence, and has built a career at the intersection of cybersecurity and geopolitics. He will be joining David Magnotti for their talk "Ping First, Boom Second", which will focus on Iranian cyber threat groups.
0104
John Hultquist @hultquist.bsky.social · 23/10/2025
If you’ve been laid off from a cyber threat intel position, and you want a ticket to CYBERWARCON, please reach out.
12623
John Hultquist @hultquist.bsky.social · 22/10/2025
An opinion piece I wrote for Cipher Brief on the next wave of AI threats. The speed and scale of this activity will change the nature of cybersecurity. In order to compete with adversary use of this technology we must adopt it wholeheartedly into defense. www.thecipherbrief.com/ai-cyberatta...
thecipherbrief.com
AI-Powered Adversaries Require AI-Driven Defenses
OPINION — The use of artificial intelligence by adversaries has been the subject of exhaustive speculation. No one doubts that the technology will be abused by criminals and state actors, but it can b...
0117
Reposted by John Hultquist
CYBERWARCON @cyberwarcon.bsky.social · 22/10/2025
Meet our speaker Caleb Marquis! His work played a central role in the landmark indictment of North Korean hacker Rim Jong Hyok. He has received the FBI Medal of Excellence and the Department of Justice Attorney General Award for Distinguished Service.
132
Reposted by John Hultquist
CYBERWARCON @cyberwarcon.bsky.social · 22/10/2025
We're excited to have Eric Kerr join us at CYBERWARCON! His talk, "From Hacker to Help Desk: The Surprising Story of a North Korean Cyber Operator", will cover the activities of Andariel, a North Korean hacking group that steals military & nuclear technology from US & South Korean defense networks.
152
Reposted by John Hultquist
CYBERWARCON @cyberwarcon.bsky.social · 17/10/2025
We're proud to announce Ruarigh Thornton is joining us this year at CYBERWARCON! Head of Research and Disruption at PGI, with experience in threats including counter espionage, hostile state information operations + more. He has led 100+ digital investigations. www.cyberwarcon.com
012
Reposted by John Hultquist
Wesley Shields @wxs.bsky.social · 08/10/2025
I won’t be at CYBERWARCON this year so I need someone to give @hultquist.bsky.social a hard time for me. I don’t yet know why he deserves this, but I’m sure a reason will present itself between now and then. The man never disappoints in the shenanigans and tomfoolery department.
151
Reposted by John Hultquist
Horkos @wylienewmark.bsky.social · 08/10/2025
Have you ever wanted to see two terminally online nerds really (and I mean *really*) get into the SVR deep lore while continuing the eternal goal of making 2016 last forever? Gosh does @cyberwarcon.bsky.social have a talk for you!
cyberwarcon.com
Oil Into The Fire — CYBERWARCON
2448
John Hultquist @hultquist.bsky.social · 08/10/2025
CYBERWARCON is gooooooooo! This year’s agenda is live! Thank you submitters.
1135
Reposted by John Hultquist
CYBERWARCON @cyberwarcon.bsky.social · 08/10/2025
Announcing this year's CYBERWARCON speaker lineup and agenda! We've got some fantastic talks this year, and more will be announced soon. Don't miss your chance to register now! Thank you everyone who submitted to the CFP. The selection was a truly grueling process!
0105
Reposted by John Hultquist
Greg Otto @gregotto.bsky.social · 24/09/2025
🚨🚨🚨 Google released a report on "Brickstorm" this morning — a next-level, suspected China-linked campaign targeting U.S. firms. Ultra-stealthy, 400+ day dwell times, focus on stealing IP, finding zero-days, and focused on long-term cyberespionage. cyberscoop.com/chinese-cybe...
cyberscoop.com
Brickstorm malware powering ‘next-level’ Chinese cyberespionage campaign
Mandiant and Google have identified “Brickstorm,” a sophisticated, suspected China-linked hacking campaign targeting U.S. tech firms, legal organizations, and BPOs. The operation often goes undetected...
86646
John Hultquist @hultquist.bsky.social · 24/09/2025
We are expecting several organizations who use this tool and actively hunt for this threat will find that this actor has been active in their networks for some time.
1256
John Hultquist @hultquist.bsky.social · 24/09/2025
We are releasing details on BRICKSTORM malware activity, a China-based threat hitting US tech to potentially target downstream customers and hunt for data on vulnerabilities in products. This actor is stealthy, and we've provided a tool to hunt for them. cloud.google.com/blog/topics/...
cloud.google.com
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors | Google Cloud Blog
BRICKSTORM is a stealthy backdoor used by suspected China-nexus actors for long-term espionage.
02113
John Hultquist @hultquist.bsky.social · 23/09/2025
Last week to get your @CYBERWARCON submissions in! Don’t miss out!
011
John Hultquist @hultquist.bsky.social · 18/09/2025
We've got some good submissions flowing into the @CYBERWARCON CFP, but there's still time for more. If you have good content, and you're worried the honorarium won't cover your travel, please submit, and we'll work it out. We do this because we believe this research matters.
053
John Hultquist @hultquist.bsky.social · 17/09/2025
Finland is so small that I once visited and Mikko found me in a bookstore.
1120
Reposted by John Hultquist
DPRK CERT @dprkcert.bsky.social · 16/09/2025
PAPERS PLEASE! #BSidesPyongyang2025 🇰🇵 Submit your CFP now: forms.gle/y6QRMeYuJPYXZi1k9
picture
021
Reposted by John Hultquist
Hampus Flink 🐷💢 @hampus.bsky.social · 05/09/2025
Tech startup idea: instead of starting your car with your key, you get in, turn on the display panel, enter your password, get your phone out, open the authenticator app, enter your pin, enter the timed passcode, then open the start menu, then helpdesk, then "request engine start", then submit a tic
49801132
Reposted by John Hultquist
Chris Sistrunk @chrissistrunk.bsky.social · 29/08/2025
Yo! #CYBERWARCON CFP & Reg is LIVE! You know what to do. AI can't do it for you...or wear these socks. @hultquist.bsky.social @cyberwarcon.bsky.social
013
John Hultquist @hultquist.bsky.social · 29/08/2025
Major Update: We now believe this incident impacts other Salesloft Drift integrations, not just Salesforce. We’re advising Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially compromised.
01511
John Hultquist @hultquist.bsky.social · 29/08/2025
Wait til they see the socks!
050
Reposted by John Hultquist
Greg Otto @gregotto.bsky.social · 28/08/2025
NEW: Google's Threat Intelligence Group has found the Salesloft issue impacting Salesforce actually impacts *all* Salesloft integrations, including those with Google Workspace. @mattkapko.com has it all (and will have more as this is developing) cyberscoop.com/salesloft-dr...
cyberscoop.com
Salesloft Drift compromised en masse, impacting all third-party integrations
Researchers said Google Workspace customers were hit, and noted other platforms are impacted as well. Fresh evidence proves impact was not limited to Salesforce, as Salesloft previously claimed.
054
Reposted by John Hultquist
Mick Baccio @nohackme.thruntcon.com · 28/08/2025
it's that time!!! @cyberwarcon.bsky.social tickets are on sale!! Get one before they sell out!! www.cyberwarcon.com/registration #CYBERWARCON #sockarmy
042
Reposted by John Hultquist
CYBERWARCON @cyberwarcon.bsky.social · 28/08/2025
CYBERWARCON is coming!!! Registration and CFP are now open for this year's #CYBERWARCON! This year's keynote speaker will be @dmitri.silverado.org!! We are back in Arlington, VA this year on November 19th. www.cyberwarcon.com
cyberwarcon.com
CYBERWARCON
12822
John Hultquist @hultquist.bsky.social · 26/08/2025
An actor we are tracking as UNC6395 is targeting Salesforce customer instances through compromised OAuth tokens associated with the Salesloft Drift third-party application. This is ongoing and widespread. cloud.google.com/blog/topics/...
cloud.google.com
Widespread Data Theft Targets Salesforce Instances via Salesloft Drift | Google Cloud Blog
A widespread data theft campaign targeting Salesforce instances via the Salesloft Drift third-party application.
2175
Reposted by John Hultquist
Jibblescribbits @jibblescribbits.bsky.social · 23/08/2025
Famous Dave's BBQ mascot. Pig cooking ribs
1425