Sign in

Matt Johansen

@mattjay.com
10K followers 481 following 814 posts

Friendly neighborhood cybersecurity guy | expect infosec news, appsec, cloud, dfir. | Long Island elder emo in ATX. vulnu.com <- sign up for my weekly cybersecurity newsletter

PostsRepliesMedia
Matt Johansen @mattjay.com · 23/10/2025
The criminal information doc is light on specifics - doesn't name the victim companies or detail nature of stolen trade secrets. But does list all the watches the FBI collected from him... We can connect some dots based on what they do as a company.
120
Matt Johansen @mattjay.com · 23/10/2025
Worth noting that this comes on heels of recent internal Trenchant investigation into leaked hacking tools. Not yet clear if the two incidents are connected.
110
Matt Johansen @mattjay.com · 23/10/2025
Timeline: Williams allegedly stole 7 trade secrets between Apr '22-Jun '25, and an 8th between Jun-Aug '25. He was Trenchant's GM from Oct '24 until Aug '25, operating out of DC.
120
Matt Johansen @mattjay.com · 23/10/2025
Former L3Harris/Trenchant GM Peter Williams charged with stealing trade secrets. DOJ claims he made $1.3M from the sale.
120
Matt Johansen @mattjay.com · 23/10/2025
Woah. Trenchant, who develops zero-days and surveillance tools for Five Eyes intelligence agencies (US, UK, Canada, Australia, and New Zealand). Has had an insider accused of selling secrets to Russia.
3167
Matt Johansen @mattjay.com · 29/09/2025
Funnily enough, I was looking for Medusa stuff while writing this thread, and CISA's advisory on how to protect yourself from them is the top search result. While this is all good advice, it wouldn't have done much to stop this type of attack. Hacks are just logins in 2025.
130
Matt Johansen @mattjay.com · 29/09/2025
Group referenced previous "successful" insider compromises at UK healthcare and US emergency services orgs. Claims align with known Medusa TTPs focusing on high-value targets.
140
Matt Johansen @mattjay.com · 29/09/2025
When reporter delayed, group pivoted to aggressive MFA bombing - continuously triggering 2FA notifications hoping for accidental approval. Same technique used in 2022 Uber compromise.
160
Matt Johansen @mattjay.com · 29/09/2025
They requested specific network reconnaissance via command line queries, demonstrated knowledge of BBC's IT infrastructure, and offered "trust payment" of 0.5 BTC as deposit.
150
Matt Johansen @mattjay.com · 29/09/2025
Threat actor claimed to be a "reach out manager" for Medusa - a Ransomware-as-a-Service operation believed to operate from Russia/CIS region. Group has hit 300+ victims in past 4 years per US cyber authorities. (img: TheHackerNews)
150
Matt Johansen @mattjay.com · 29/09/2025
Initial contact came to @JoeTidy via Signal from "Syndicate" offering 15% of potential ransom payment for access to BBC systems. Offer later increased to 25% of what they claimed would be "1% of BBC's total revenue."
260
Matt Johansen @mattjay.com · 29/09/2025
This BBC reporter was offered 25% of a ransom payout if he gave hackers access to the corporate network. He played along so we got a look inside their tactic here:
26025
Matt Johansen @mattjay.com · 05/08/2025
Panel on bootstrapping vs. VC money. @haroonmeer.canary.love : “With bootstrapping you need to be careful to not be timid when it’s time to be bold” Just great life advice in general. Will remember this quote forever. Oh and @hdm.io and @andrewmorr.is are cool too.
030
Matt Johansen @mattjay.com · 31/07/2025
This is a fun vuln youtu.be/jsygONOr_f4
071
Matt Johansen @mattjay.com · 25/07/2025
Not just 4chan trolls. 404media decompiled the app and found the URLs in question in code. Not public anymore, but verified they are there. Original article: www.404media.co/wome...
280
Matt Johansen @mattjay.com · 25/07/2025
"No authentication, no nothing. It's a public bucket" This is why security and privacy pros hate these ID verification laws that require drivers license uploads - these apps just can't keep this stuff secure.
271
Matt Johansen @mattjay.com · 25/07/2025
They found the database exposed on Google's Firebase. The app is meant to be basically the "are we dating the same man?" Facebook group in a dating app. In order to verify that the users are women, they ask for photos and driver's licenses.
130
Matt Johansen @mattjay.com · 25/07/2025
That viral women's only dating app 'Tea' was hacked by some 4chan users. They didn't phish, social engineer, or use some crazy hacker technique either - the database was just public
4104
Matt Johansen @mattjay.com · 25/07/2025
Hey so… don’t do this.
0142
Matt Johansen @mattjay.com · 17/07/2025
Someone can buy this extension that is tied to tons of peole's salesforce account and just ...get access to all that info. (h/t @johntuckner.me)
182
Matt Johansen @mattjay.com · 15/07/2025
If I was a bad guy who was looking for memory vulns, I'd be ALL OVER these new hotness web browsers. (Comet, Arc, etc.) Market share is small but much more valuable targets. - Teams behind them way smaller than ...Google
2112
Matt Johansen @mattjay.com · 11/07/2025
Wild trend this week of legitimate apps and extensions turning into malware. youtu.be/o9XBXeX0_5E
032
Matt Johansen @mattjay.com · 10/07/2025
I just can't believe how successful ClickFix campaigns are right now. And now FileFix on top of it...
170
Matt Johansen @mattjay.com · 06/07/2025
Which Windows drivers keep Microsoft’s security engineers busiest - and which ones do attackers actually exploit? Artem Baranov did the dang math. He scraped every CVE bulletin from Jan 2022 through May 2025 and built a clean data set of kernel-mode driver patches.
1111
Matt Johansen @mattjay.com · 03/07/2025
The data exfiltration: Keychain creds, browser data, Telegram chats, then push over WebSockets - encrypted channel, tricky for network sensors that ignore non-HTTP(S) traffic
110
Matt Johansen @mattjay.com · 03/07/2025
Nasty little persistence trick - malware revives itself when killed. It intercepts `SIGINT` / `SIGTERM`, then rewrites LaunchAgents on shutdown. "any user-initiated termination of the malware results in the deployment of the core components, making the code resilient to basic defensive actions."
110
Matt Johansen @mattjay.com · 03/07/2025
Stage-2 drops two binaries in /private/var/tmp • `a` (C++) - kicks off data-stealing chain • `installer` (Nim) - sets up persistence via signal handlers so killing the process re-installs the backdoor on reboot.
100
Matt Johansen @mattjay.com · 03/07/2025
That script (`zoom_sdk_support.scpt`) hides *10,000 blank lines* scroll forever, never see the payload. The last 3 lines fetch stage-2 from `support.us05web-zoom[.]forum` (notice the look-alike Zoom domain)
100
Matt Johansen @mattjay.com · 03/07/2025
The attacker pretends to be a trusted contact → DM on Telegram → Calendly invite → follow-up email with a Zoom link that tells victims to “run this update script.” It's been hyper successful and catching founders/devs off-guard
100
Matt Johansen @mattjay.com · 03/07/2025
🚨 New macOS backdoor alert: North-Korean hackers are disguising a Zoom update that drops malware built to hijack laptops and steal data & passwords. If you or your devs run macOS, keep scrolling.👇
286
Matt Johansen @mattjay.com · 02/07/2025
One of the wilder revelations in this report for me: They're hiring facilitators that are managing the scheme in the US. They also: - Create a bank account for the North Korean, or lend their own account to the worker - Purchase mobile phone numbers or SIM cards
100
Matt Johansen @mattjay.com · 02/07/2025
But they create a big digital footprint and work history. This helps with legitimacy and some light background checks. A bunch of them have GitHub profiles full of activity and badges.
100
Matt Johansen @mattjay.com · 02/07/2025
They've gotten real good at making fake profiles, pictures, resumes on LinkedIn and even boosting their resumes. This is the heaviest use of AI we've seen.
100
Matt Johansen @mattjay.com · 02/07/2025
"To evade detection, these workers use VPNs, virtual private servers (VPSs), and proxy services as well as RMM tools to connect to a device housed at a facilitator’s laptop farm located in the country of the job."
100
Matt Johansen @mattjay.com · 02/07/2025
Even the DoJ just put out how they're busting these laptop farms facilitating these remote workers access to US companies. 29 houses raided recently
100
Matt Johansen @mattjay.com · 02/07/2025
A lot of people are waiting for the "super AI malware hacking machine!" to drop, but really it's just how everyone is using AI. Either way, it's been hyper successful for them. Hundreds of companies have hired these spies unwittingly.
110
Matt Johansen @mattjay.com · 02/07/2025
Microsoft just put out a detailed threat intel report on North Korean threat actors who keep getting hired for remote jobs at US companies. They also outline how they're using AI to level up. Here's some highlights:
193
Matt Johansen @mattjay.com · 01/07/2025
Been reading more and more about governments hacking their own citizens with spyware. They seem to be finding any excuse - journalists. politically active people. social media posts. Whatever they want. Then they do it with zero click 0days silently. Wild. youtu.be/zqY2A112bAQ
1132
Matt Johansen @mattjay.com · 25/06/2025
I dove deeper into that AI Agent becoming #1 on the HackerOne leaderboard. youtu.be/lC2Ornloj24
110
Matt Johansen @mattjay.com · 24/06/2025
Are AI hacking agents happening?
250
Matt Johansen @mattjay.com · 22/06/2025
Sunday scaries big time when I’m leaving this to go back to reality.
2380
Matt Johansen @mattjay.com · 17/06/2025
Data at risk includes sensitive labor organizing info and union complaints. Over 50 House Democrats from Congressional Labor Caucus expressed concerns about worker data exposure risks.
133
Matt Johansen @mattjay.com · 17/06/2025
The alleged extraction code was hosted on Microsoft-owned GitHub. Rep. Lynch specifically wants details about attempts to "conceal activities, obstruct oversight, and shield from accountability."
144
Matt Johansen @mattjay.com · 17/06/2025
Key context: This follows whistleblower Daniel Berulis's disclosure about ~10GB of data exfiltrated from NLRB's NxGen system. DOGE engineer Jordan Wick's repo "NxGenBdoorExtract" was made private before investigation.
175
Matt Johansen @mattjay.com · 17/06/2025
Breaking: House Oversight's top Dem Rep. Lynch requests Microsoft provide info on DOGE staffer's GitHub repo. It allegedly contains code to extract data from the NLRB's case management system.
23412
Matt Johansen @mattjay.com · 13/06/2025
This fits a pattern: Major supply chain attacks hit Clorox (2023, $356M impact), Sysco (2024, data leak), JBS Foods (2021, $11M ransom). Targeting distributors maximizes downstream impact.
100
Matt Johansen @mattjay.com · 13/06/2025
Market impact: UNFI stock was down 9% after 8-K filing mentioned ongoing disruptions. Critical infrastructure implications too - UNFI serves hospitals, schools, SNAP retailers. (It's now down over 20% the last 5 days)
100
Matt Johansen @mattjay.com · 13/06/2025
Whole Foods already seeing impacts: Reports of empty freezers, delayed deliveries across multiple states. While they have regional DCs, most center-store items flow through UNFI. (Still nobody wants Keto bread...)
100
Matt Johansen @mattjay.com · 13/06/2025
UNFI is North America's largest grocery wholesaler ($31B in sales). Whole Foods represents >10% of their business. Manual operations now in place at distribution centers. Who remembers when DEFCON hotel got hacked and they had to break out the *cachunk* credit card carbon paper machines?
100
Matt Johansen @mattjay.com · 13/06/2025
UNFI (major distributor for Whole Foods + 30k grocery stores) hit with cyber incident. Critical systems offline since June 5. Significant supply chain disruptions ongoing. Heres what we know. 🧵
272