Sign in

Matt Johansen

@mattjay.com
10K followers 481 following 814 posts

Friendly neighborhood cybersecurity guy | expect infosec news, appsec, cloud, dfir. | Long Island elder emo in ATX. vulnu.com <- sign up for my weekly cybersecurity newsletter

PostsRepliesMedia
Matt Johansen @mattjay.com · 23/10/2025
If you like this stuff, subscribe to my free weekly newsletter along with 32k other pros:
vulnu.com
Vulnerable U
Infosec's favorite weekly newsletter for news, tools, and tips with 32,000+ CISOs, founders, change-makers, and straight up hackers.
020
Matt Johansen @mattjay.com · 23/10/2025
Full article on TechCrunch -
techcrunch.com
U.S. government accuses former L3Harris cyber boss of stealing trade secrets | TechCrunch
The U.S. Department of Justice accused Peter Williams, former general manager of L3Harris’ hacking division Trenchant, of stealing trade secrets and selling them to a buyer in Russia.
250
Matt Johansen @mattjay.com · 23/10/2025
Arraignment/plea agreement hearing scheduled for Oct 29 in DC. Williams isn't currently in federal custody. His attorney John Rowley declined comment when contacted by TC.
120
Matt Johansen @mattjay.com · 23/10/2025
The criminal information doc is light on specifics - doesn't name the victim companies or detail nature of stolen trade secrets. But does list all the watches the FBI collected from him... We can connect some dots based on what they do as a company.
120
Matt Johansen @mattjay.com · 23/10/2025
Worth noting that this comes on heels of recent internal Trenchant investigation into leaked hacking tools. Not yet clear if the two incidents are connected.
110
Matt Johansen @mattjay.com · 23/10/2025
Timeline: Williams allegedly stole 7 trade secrets between Apr '22-Jun '25, and an 8th between Jun-Aug '25. He was Trenchant's GM from Oct '24 until Aug '25, operating out of DC.
120
Matt Johansen @mattjay.com · 23/10/2025
Former L3Harris/Trenchant GM Peter Williams charged with stealing trade secrets. DOJ claims he made $1.3M from the sale.
120
Matt Johansen @mattjay.com · 23/10/2025
Woah. Trenchant, who develops zero-days and surveillance tools for Five Eyes intelligence agencies (US, UK, Canada, Australia, and New Zealand). Has had an insider accused of selling secrets to Russia.
3167
Matt Johansen @mattjay.com · 29/09/2025
Dig this kind of news? Join over 30k pros who get my weekly newsletter for free:
vulnu.com
Vulnerable U
Infosec's favorite weekly newsletter for news, tools, and tips with 30,000+ CISOs, founders, change-makers, and straight up hackers.
040
Matt Johansen @mattjay.com · 29/09/2025
No vulnerabilities used. No lateral network movement. It's all just OAuth tokens all the way down. Read the whole story here:
bbc.com
'You'll never need to work again': Criminals offer reporter money to hack BBC
Reporter Joe Tidy was offered money if he would help cyber criminals access BBC systems.
2131
Matt Johansen @mattjay.com · 29/09/2025
Funnily enough, I was looking for Medusa stuff while writing this thread, and CISA's advisory on how to protect yourself from them is the top search result. While this is all good advice, it wouldn't have done much to stop this type of attack. Hacks are just logins in 2025.
130
Matt Johansen @mattjay.com · 29/09/2025
Worth noting actors maintained professional demeanor throughout most interactions. Only escalated to aggressive tactics (MFA bombing) after patience wore thin. Even apologized and said that was just them testing the login page.
130
Matt Johansen @mattjay.com · 29/09/2025
Group referenced previous "successful" insider compromises at UK healthcare and US emergency services orgs. Claims align with known Medusa TTPs focusing on high-value targets.
140
Matt Johansen @mattjay.com · 29/09/2025
When reporter delayed, group pivoted to aggressive MFA bombing - continuously triggering 2FA notifications hoping for accidental approval. Same technique used in 2022 Uber compromise.
160
Matt Johansen @mattjay.com · 29/09/2025
They requested specific network reconnaissance via command line queries, demonstrated knowledge of BBC's IT infrastructure, and offered "trust payment" of 0.5 BTC as deposit.
150
Matt Johansen @mattjay.com · 29/09/2025
Threat actor claimed to be a "reach out manager" for Medusa - a Ransomware-as-a-Service operation believed to operate from Russia/CIS region. Group has hit 300+ victims in past 4 years per US cyber authorities. (img: TheHackerNews)
150
Matt Johansen @mattjay.com · 29/09/2025
Initial contact came to @JoeTidy via Signal from "Syndicate" offering 15% of potential ransom payment for access to BBC systems. Offer later increased to 25% of what they claimed would be "1% of BBC's total revenue."
260
Matt Johansen @mattjay.com · 29/09/2025
This BBC reporter was offered 25% of a ransom payout if he gave hackers access to the corporate network. He played along so we got a look inside their tactic here:
26025
Matt Johansen @mattjay.com · 12/08/2025
I think the separation of dev and prod is one of the most important things we need to solve in AI coding land. Keys. Secrets. Deployment. All that jazz. None of the tools help, if anything they make it super easy to do wrong.
170
Matt Johansen @mattjay.com · 05/08/2025
Panel on bootstrapping vs. VC money. @haroonmeer.canary.love : “With bootstrapping you need to be careful to not be timid when it’s time to be bold” Just great life advice in general. Will remember this quote forever. Oh and @hdm.io and @andrewmorr.is are cool too.
030
Matt Johansen @mattjay.com · 31/07/2025
This is a fun vuln youtu.be/jsygONOr_f4
071
Matt Johansen @mattjay.com · 25/07/2025
If you like following news like this checkout my weekly newsletter: Join over 30k pros: vulnu.com/subscribe
vulnu.com
Vulnerable U
Infosec's favorite weekly newsletter for news, tools, and tips with 28,000+ CISOs, founders, change-makers, and straight up hackers.
020
Matt Johansen @mattjay.com · 25/07/2025
Not just 4chan trolls. 404media decompiled the app and found the URLs in question in code. Not public anymore, but verified they are there. Original article: www.404media.co/wome...
280
Matt Johansen @mattjay.com · 25/07/2025
"No authentication, no nothing. It's a public bucket" This is why security and privacy pros hate these ID verification laws that require drivers license uploads - these apps just can't keep this stuff secure.
271
Matt Johansen @mattjay.com · 25/07/2025
They found the database exposed on Google's Firebase. The app is meant to be basically the "are we dating the same man?" Facebook group in a dating app. In order to verify that the users are women, they ask for photos and driver's licenses.
130
Matt Johansen @mattjay.com · 25/07/2025
That viral women's only dating app 'Tea' was hacked by some 4chan users. They didn't phish, social engineer, or use some crazy hacker technique either - the database was just public
4104
Matt Johansen @mattjay.com · 25/07/2025
Hey so… don’t do this.
0142
Matt Johansen @mattjay.com · 17/07/2025
Someone can buy this extension that is tied to tons of peole's salesforce account and just ...get access to all that info. (h/t @johntuckner.me)
182
Matt Johansen @mattjay.com · 15/07/2025
If I was a bad guy who was looking for memory vulns, I'd be ALL OVER these new hotness web browsers. (Comet, Arc, etc.) Market share is small but much more valuable targets. - Teams behind them way smaller than ...Google
2112
Matt Johansen @mattjay.com · 11/07/2025
Wild trend this week of legitimate apps and extensions turning into malware. youtu.be/o9XBXeX0_5E
032
Matt Johansen @mattjay.com · 10/07/2025
I just can't believe how successful ClickFix campaigns are right now. And now FileFix on top of it...
170
Matt Johansen @mattjay.com · 06/07/2025
Volume of vulns != In The Wild exploits. Super interesting post and data - aibaranov.github.io/windrivers/
aibaranov.github.io
Lift me up to Ring 0: what are the most vulnerable Windows drivers
Examining the statistics on the most frequently patched Windows drivers between January 2022 and May 2025
120
Matt Johansen @mattjay.com · 06/07/2025
Which Windows drivers keep Microsoft’s security engineers busiest - and which ones do attackers actually exploit? Artem Baranov did the dang math. He scraped every CVE bulletin from Jan 2022 through May 2025 and built a clean data set of kernel-mode driver patches.
1111
Matt Johansen @mattjay.com · 03/07/2025
If you like staying on top of this kind of news: Join over 30,000 cybersecurity pros who get my free weekly newsletter - vulnu.com/subscribe
vulnu.com
Vulnerable U
Infosec's favorite weekly newsletter for news, tools, and tips with 28,000+ CISOs, founders, change-makers, and straight up hackers.
020
Matt Johansen @mattjay.com · 03/07/2025
[1]: www.sentinelone.com/... "macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware | SentinelOne" [2]: www.securityweek.com... "North Korean Hackers Use Fake Zoom Updates to Install macOS Malware - SecurityWeek"
sentinelone.com
macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware
NimDoor reflects a leap in DPRK’s offensive toolkit, mixing compile-time trickery with native scripting to complicate and deter analysis.
120
Matt Johansen @mattjay.com · 03/07/2025
macOS isn’t safe just because of Gatekeeper social-engineering + obscure languages (Nim) = new blind spots. Patch, monitor WebSocket egress, & warn employees: *no legit Zoom update arrives as an AppleScript!* RT to keep teams safe.
120
Matt Johansen @mattjay.com · 03/07/2025
The data exfiltration: Keychain creds, browser data, Telegram chats, then push over WebSockets - encrypted channel, tricky for network sensors that ignore non-HTTP(S) traffic
110
Matt Johansen @mattjay.com · 03/07/2025
Nasty little persistence trick - malware revives itself when killed. It intercepts `SIGINT` / `SIGTERM`, then rewrites LaunchAgents on shutdown. "any user-initiated termination of the malware results in the deployment of the core components, making the code resilient to basic defensive actions."
110
Matt Johansen @mattjay.com · 03/07/2025
Stage-2 drops two binaries in /private/var/tmp • `a` (C++) - kicks off data-stealing chain • `installer` (Nim) - sets up persistence via signal handlers so killing the process re-installs the backdoor on reboot.
100
Matt Johansen @mattjay.com · 03/07/2025
That script (`zoom_sdk_support.scpt`) hides *10,000 blank lines* scroll forever, never see the payload. The last 3 lines fetch stage-2 from `support.us05web-zoom[.]forum` (notice the look-alike Zoom domain)
100
Matt Johansen @mattjay.com · 03/07/2025
The attacker pretends to be a trusted contact → DM on Telegram → Calendly invite → follow-up email with a Zoom link that tells victims to “run this update script.” It's been hyper successful and catching founders/devs off-guard
100
Matt Johansen @mattjay.com · 03/07/2025
🚨 New macOS backdoor alert: North-Korean hackers are disguising a Zoom update that drops malware built to hijack laptops and steal data & passwords. If you or your devs run macOS, keep scrolling.👇
286
Matt Johansen @mattjay.com · 02/07/2025
If you like this kind of news - join over 30,000 pros who get my free weekly cybersecurity newsletter: vulnu.com/subscribe
vulnu.com
Vulnerable U
Infosec's favorite weekly newsletter for news, tools, and tips with 28,000+ CISOs, founders, change-makers, and straight up hackers.
010
Matt Johansen @mattjay.com · 02/07/2025
Check the whole report for more things to watch out for and how to protect yourself: www.microsoft.com/en...
microsoft.com
Jasper Sleet: North Korean remote IT workers’ evolving tactics to infiltrate organizations | Microsoft Security Blog
Since 2024, Microsoft Threat Intelligence has observed remote IT workers deployed by North Korea leveraging AI to improve the scale and sophistication of their operations, steal data, and generate revenue for the North Korean government.
331
Matt Johansen @mattjay.com · 02/07/2025
One of the wilder revelations in this report for me: They're hiring facilitators that are managing the scheme in the US. They also: - Create a bank account for the North Korean, or lend their own account to the worker - Purchase mobile phone numbers or SIM cards
100
Matt Johansen @mattjay.com · 02/07/2025
But they create a big digital footprint and work history. This helps with legitimacy and some light background checks. A bunch of them have GitHub profiles full of activity and badges.
100
Matt Johansen @mattjay.com · 02/07/2025
They've gotten real good at making fake profiles, pictures, resumes on LinkedIn and even boosting their resumes. This is the heaviest use of AI we've seen.
100
Matt Johansen @mattjay.com · 02/07/2025
"To evade detection, these workers use VPNs, virtual private servers (VPSs), and proxy services as well as RMM tools to connect to a device housed at a facilitator’s laptop farm located in the country of the job."
100
Matt Johansen @mattjay.com · 02/07/2025
Even the DoJ just put out how they're busting these laptop farms facilitating these remote workers access to US companies. 29 houses raided recently
100
Matt Johansen @mattjay.com · 02/07/2025
A lot of people are waiting for the "super AI malware hacking machine!" to drop, but really it's just how everyone is using AI. Either way, it's been hyper successful for them. Hundreds of companies have hired these spies unwittingly.
110