Reposted by Matt MullerChristophe Tafani-Dereeper @christophetd.fr · 24/09/2026Had lots of fun finding this vulnerability and writing an (hopefully) educational write-up! 022
Matt Muller @matt.buildingsecops.com · 21/09/2026It’s only a vulnerability problem if it’s in a network edge device, otherwise it’s a sparkling developer velocity problem. 000
Reposted by Matt MullerAnil Dash @anildash.com · 09/09/2026There are a lot of people who think their parents got their brains destroyed by Fox News, but somehow they’re not getting their brains destroyed by staying on Twitter. 333585708
Reposted by Matt Mullercje @cje.io · 01/09/2026"What is a bug worth" has always been *the* question: The Vulnpocalypse Is Repricing the Bug Bounty Economy www.darkreading.com/vulnerabilit...darkreading.comThe Vulnpocalypse Is Repricing the Bug Bounty EconomyThe surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers. 095
Reposted by Matt MullerKatie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 29/05/2026Not that ‘responsible’ disclosure shit again 🙄 No vendor uses that term unless they want to call someone irresponsible. Even if someone drops 0day, patch & move on. Going after a researcher is a great way to turn 1 bad relationship into many terrible relationships. 18831
Matt Muller @matt.buildingsecops.com · 13/06/2026As someone who has recently moved to NYC and takes the subway to work every day, this is possibly the most fragile masculinity, snowflake shit I have ever read. 020
Matt Muller @matt.buildingsecops.com · 12/06/2026Is it too cynical to say we should check Kalshi for insider gambling based on this? 000
Reposted by Matt MullerJohn Scott-Railton @jsrailton.bsky.social · 10/06/2026NEW: malware developers added nuclear & biological weapons text to to their spyware. Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner. Cleanest practical example I can think of for why over-indexing on first order "safety" is risky. 1/ 4533189
Reposted by Matt MullerNicholas Grossman @nicholasgrossman.bsky.social · 17/05/2026I don’t think DOJ should hand the president a multi-billion dollar slush fund he can divvy up between criminals he likes and his private bank account, nor that he should be able to buy stock then use taxpayer funds to boost that company. It’s corrupt. Sorry to get so partisan, but that’s how I feel. 602544514
Reposted by Matt MullerBill Kristol @billkristolbulwark.bsky.social · 16/05/2026Mamdani has proposed a balanced budget for next year, holding spending level while closing a $12 billion deficit. Trump's budget proposal increases the deficit year over year by about $300b, with a massive deficit next year of more than $2 trillion. Fiscal responsibility? Mamdani > Trump. 692565614
Reposted by Matt MullerSocket @socket.dev · 03/04/2026🚨 New Investigation: Attackers are hunting the maintainers behind Lodash, Fastify, buffer, Pino, mocha, Express, and #Nodejs core, because compromising one of them means write access to packages downloaded billions of times a week. socket.dev/blog/attacke...socket.devAttackers Are Hunting High-Impact Node.js Maintainers in a C...Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios. 12814
Reposted by Matt MullerWarren Wells, AICP @warrenjwells.bsky.social · 22/03/2026How can this go on for another 3 years? 197106813834
Reposted by Matt MullerJ Wolfgang Goerlich @jwgoerlich.bsky.social · 22/03/2026Cyber: Humans are the weakest link! Also cyber: Human-in-the-loop is the only way to make AI safe! 152
Reposted by Matt MullerCasey Newton @caseynewton.bsky.social · 18/03/2026Hmmm do you think this will happen more or less often after the company lays off 20 percent of its workforce 1227368
Reposted by Matt MullerMax Kennerly @maxkennerly.bsky.social · 14/03/2026Never fund DHS again. Abolish it completely. If someone wants to moan about "but but we have to ____" yeah fine we can discuss a new department, but *this* department has to go. 4742881385
Reposted by Matt MullerGreg Foss @gregfoss.com · 06/03/2026We recently partnered with Okta to ship new identity threat detections, alongside contributing to Okta's open source Security Detection Catalog, so the broader security community benefits. Big thanks to the Okta Cyber Defense team for the collaboration! sec.okta.com/articles/202...sec.okta.comDatadog and Okta Combine for New Customer DetectionsComprehensive monitoring of identity activity is crucial to the security of any organization. A compromised identity can lead to widespread data breaches and 031
Reposted by Matt MullerWhitney Merrill @wbm312.bsky.social · 04/03/2026Also if you work in sales at a company, do not call me. Email, fine. 0171
Matt Muller @matt.buildingsecops.com · 01/03/2026I love the Three Buddy Problem and listen to it religiously. My question for @ryanaraine.bsky.social @jags.bsky.social and @craiu.bsky.social - do you think the benefits of staying on Twitter outweigh the hazards? 201
Reposted by Matt MullerGlonzo the Bureaucrat 🇬🇱 🌹 @snarkranger.bsky.social · 28/02/2026Each one of those three missiles costs 33% more than the annual budget of the national park where I work. 5558941898
Matt Muller @matt.buildingsecops.com · 24/02/2026I do not want AI in @1password.bsky.social. So naturally my next renewal will be a price increase because they’re stuffing AI into @1password.bsky.social. 000
Reposted by Matt MullerKevin M. Kruse @kevinmkruse.bsky.social · 21/02/2026We should do everything we can to help Democratic politicians leave Twitter behind. Help the AG out! 352363594
Reposted by Matt MullerAsha Rangappa @asharangappa.bsky.social · 20/01/2026This is an excellent explainer. 👀 quote: “In rough terms, the workforce of CBP officers and Border Patrol agents commit crimes at an equal or even greater rate PER CAPITA than the population of undocumented immigrants do in the United States.” 181135447
Reposted by Matt MullerKevin Beaumont @doublepulsar.com · 26/12/2025patch ye MongoDB, there's an exploit for a vuln which has been in the product for over a decade that allows the remote, unauth read of any memory - which includes plaintext creds. Somebody posted an exploit on Christmas Day, Merry Christmas! doublepulsar.com/merry-christ...doublepulsar.comMerry Christmas Day! Have a MongoDB security incident.Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day. 310245
Matt Muller @matt.buildingsecops.com · 12/12/2025That feeling when @iverify.bsky.social tells you about an iOS update before Apple even issues a security bulletin 😍 000
Reposted by Matt MullerDatadog Security Labs @securitylabs.datadoghq.com · 04/12/2025CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js securitylabs.datadoghq.com/articles/cve... 164
Reposted by Matt MullerStephen or Steve "EMV" Cobb @scobb.net · 26/11/2025A man and a woman get in an elevator, which one is doing risk assessment?riskopia.substack.comLifting awareness of male supremacy: an elevator pitch with a twistThe source of much of what is wrong in the world today is male supremacy, awareness of which needs raising. Could one simple question do the trick? 012
Reposted by Matt MullerJessica Lyons @jessicalyons.bsky.social · 25/11/2025Afraid of connecting to public Wi-Fi? Terrified to turn your Bluetooth on? You may be falling for "hacklore." Dozens of CISOs and ex-CISA officials have launched an effort to dispel these myths and show you how not to get hacked for real.theregister.comEx-CISA officials, CISOs aim to stop the spread of hacklore: Don't believe everything you read 043
Reposted by Matt MullerIndivisible ❌👑 @indivisible.org · 11/11/2025After yesterday’s surrender, we’re launching the largest Democratic primary program that we’ve ever run. We will not back any Senate primary candidate unless they call for Schumer to step down as Minority Leader. If you’re as pissed as we are, join this campaign to rebuild the Democratic Party. 👇indivisible2026.orgDemocratic leaders have failed us again. It's time to get new leaders.After yet another capitulation by Chuck Schumer and Senate Democrats, it's clear we need new leadership capable of mounting a serious opposition to Trump's authoritarian regime. We're launching our la... 17262612082
Reposted by Matt Muller404 Media @404media.co · 04/11/2025When you book a flight through major travel sites, a data broker owned by U.S. airlines will sell details about your flight—your name, credit card used, and where you’re flying to the government. We found out how to opt-out of ARC selling your travel data. A guide: www.404media.co/how-to-opt-o...404media.coHow to Opt-Out of Airlines Selling Your Travel Data to the GovernmentThe Airlines Reporting Corporation (ARC), owned by major U.S. airlines, collects billions of ticketing records and sells them to the government to be searched without a warrant. I managed to opt-out… 281260795
Reposted by Matt MullerTom Joscelyn @tomjoscelyn.bsky.social · 02/11/2025“I’m a law-abiding citizen who never thought I’d be of such interest that the U.S. government would use my tax dollars & yours to try to send me to prison…[after being] manhandled by an Immigration and Customs Enforcement agent trying to remove my phone from my hand.” www.msnbc.com/opinion/msnb...msnbc.comOpinion | A jury of my peers agreed that the feds wrongly charged me for watching ICEI believe that filming what federal agents were doing that day counted as basic human decency. 131315495
Reposted by Matt Mullerevacide @evacide.bsky.social · 14/10/2025Truly, SS7 is the surveillance gift that keeps on giving: www.motherjones.com/politics/202...motherjones.comThe surveillance empire that tracked world leaders, a Vatican enemy, and maybe youInside the hidden world of First Wap, whose untraceable tech has targeted politicians, journalists, celebrities, and activists around the globe. 56537
Reposted by Matt MullerJohn Scott-Railton @jsrailton.bsky.social · 09/10/2025NEW: cost to 'poison' an LLM and insert backdoors is relatively constant. Even as models grow. Implication: security doesn't scale with LLMs. Super interesting: Prior work had suggested that as model sizes grew, it would make them cost-prohibitive to poison. 1/ arxiv.org/pdf/2510.07192 15922
Reposted by Matt MullerPatton Oswalt @pattonoswalt.bsky.social · 08/10/2025🎶Thicker than A deep dish pie Joints are sore Blood pressure high Pudding, flan And crème brûlée None are safe From the Green Beignets🎶 3313317583
Reposted by Matt MullerZohran Kwame Mamdani @zohrankmamdani.bsky.social · 25/09/2025Sickening behavior by this agent. The fact that Mayor Adams has rolled out the red carpet for ICE is a stain on our city. 1208221735591
Reposted by Matt MullerTProphet @tprophet.org · 23/09/20251/ Hi, I'm TProphet. I write the Telecom Informer for @2600.com. A lot of people have been asking me about www.nbcnews.com/politics/nat... given that I'm somewhat knowledgeable in the area. Here's my take: I'm kind of astonished that this is public, and it isn't normal that it would ever be.nbcnews.comSecret Service agents dismantle network that could shut down New York cellphone systemAgents discovered electronic devices in five locations in and around the city that could be used to disable cellphone towers. The system could also be used for criminal activities. 10363178
Reposted by Matt MullerMark Harris @markharris.bsky.social · 21/09/2025Be sure you take a moment today to remember Charlie Kirk for exactly who he was. 812388765
Matt Muller @matt.buildingsecops.com · 20/09/2025Nothing infuriates me more than cybercriminals that target small businesses, so it's time to spend a Saturday burning down the infrastructure of the ones who targeted a contractor I've worked with. 000
Reposted by Matt MullerMax Kennerly @maxkennerly.bsky.social · 18/09/2025It's bullshit that I agree with David Frum. Things shouldn't have sunk so low that we've reached our level of agreement! We should be in the realm where we disagree on every issue in the news! 622669424
Reposted by Matt MullerMatt Novak @paleofuture.bsky.social · 18/09/2025I watched Kimmel's three most recent monologues, convinced I had missed the thing MAGA was outraged about. But it looks like this is it. It has to be more than this, right? There's just no way this is it. 651111263
Reposted by Matt MullerChris Hayes @chrislhayes.bsky.social · 18/07/2025Not really an overstatement to say that the test of a free society is whether or not comedians can make fun of the country's leader on TV without repurcussions. 14567315618650
Matt Muller @matt.buildingsecops.com · 16/09/2025I am genuinely curious what other type of content AWS thinks I’d be submitting through their “Report Phishing” form…? 000
Reposted by Matt MullerJake Williams @malwarejake.bsky.social · 12/09/2025It is a bit wild to me that Snowflake got dragged through the mud because threat actors abused a bunch of one-off credentials in stealer logs, but somehow Salesforce has escaped scrutiny when all the impacted customers came from a single integration. 1305
Reposted by Matt MullerTaggart @taggart-tech.com · 09/09/2025An incredible firsthand glimpse into threat actor operations from Huntress:huntress.comAn Attacker’s Blunder Gave Us a Look Into Their Operations | HuntressAn attacker installed Huntress onto their operating machine, giving us a detailed look at how they’re using AI to build workflows, searching for tools like Evilginx, and researching targets like software development companies. 052
Matt Muller @matt.buildingsecops.com · 07/09/2025This talk was excellent - super practical advice and a refreshing antidote to all the “AI will fix everything” nonsense out there. 081
Matt Muller @matt.buildingsecops.com · 06/09/2025Let the @blueteamcon.com festivities commence! Looking forward to a great day of talks. 011
Matt Muller @matt.buildingsecops.com · 26/08/2025Sorry guys, Taylor Swift’s own instagram post is wrong, Google’s multi billion dollar AI says so. 000
Reposted by Matt MullerCSOonline @csoonline.bsky.social · 26/08/2025“I’ve never heard of the kind of pervasive bribery that this incident showed us, with the long-term focus and the amounts involved,” Philip Martin, CSO of Coinbase, tells CSO. “It was, to me, an evolution in attacker behavior.” www.csoonline.com/article/4042...csoonline.comBehind the Coinbase breach: Bribery emerges as enterprise threatCoinbase’s breach shows how bribery schemes — long used for SIM swaps — can be a potent enterprise attack vector. Experts urge security leaders to add bribery training and red-teaming to their cyber d... 012