Sign in

Matt Kapko

@mattkapko.com
494 followers 894 following 53 posts

Digital threats reporter @ CyberScoop • Grateful lifelong Californian • matt.49 on Signal • matt.kapko@cyberscoop.com • mattkapko.com

PostsRepliesMedia
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 16h
Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They expect more attacks to come. Read more by @mattkapko.com: cyberscoop.com/citrix-netsc...
043
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 28/08/2026
A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. www.youtube.com/watch?v=jQKb... More by @mattkapko.com: cyberscoop.com/grand-theft-...
youtube.com
The GTA VI leaks are breaking the internet. Security researchers have seen this before.
YouTube video by CyberScoop
001
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 26/08/2026
A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. Read more by @mattkapko.com: cyberscoop.com/grand-theft-...
022
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 19/08/2026
Clop, a prolific but calculated data theft extortion group that’s been active since 2020, began sending threatening emails to its alleged victims in mid-July, according to researchers. Read more by @mattkapko.com: cyberscoop.com/clop-zero-da...
032
Reposted by Matt Kapko
Tim Starks @timstarks.bsky.social · 13/08/2026
Deeper dive into all the questions stemming from the big new offensive cyber memo, with some unsparing words from critics and the case for it from supporters. cyberscoop.com/private-sect...
cyberscoop.com
A bold new strategy or a dangerous precedent? Experts are divided on Trump's memo.
A controversial new presidential memorandum aims to enlist private sector companies in federal hacking operations against cybercriminals, dividing cybersecurity experts over its legal, ethical, and op...
285
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 05/08/2026
TeamPCP, the threat actor behind an unrelenting flurry of attacks on open-source software this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop.  Read more by @mattkapko.com: cyberscoop.com/teampcp-long...
032
Matt Kapko @mattkapko.com · 10/07/2026
A former DigitalMint ransomware negotiator was sentenced to 70 months in jail for deceiving his clients and conspiring with ransomware affiliates to extort a combined $75.3 million from five U.S. companies he was entrusted to aid during their moments of extreme crisis. cyberscoop.com/digitalmint-...
cyberscoop.com
Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
Angelo Martino exploited his insider position and fed confidential information to ransomware co-conspirators to extort a combined $75.3 million from five U.S.-based victims.
000
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 03/07/2026
Peter Stokes boasted on social media about the luxurious globetrotting life he enjoyed while he was still a child. via @mattkapko.com cyberscoop.com/scattered-sp...
cyberscoop.com
Alleged longstanding member of Scattered Spider extradited to US
Alleged Scattered Spider hacker Peter Stokes, 19, has been extradited to the U.S. after flaunting a lavish lifestyle funded by $100M in cyber extortion.
021
Matt Kapko @mattkapko.com · 22/06/2026
Thank you, @pylos.co.
030
Matt Kapko @mattkapko.com · 18/06/2026
TeamPCP is on a rampage through open-source software, striking defensive vulnerabilities the software industry has known about for years. The open source trust model is broken and susceptible to sabotage. Yet, the software industry has not fixed this problem. cyberscoop.com/teampcp-brea...
cyberscoop.com
How software development's speed obsession enabled TeamPCP’s chaos crusade
The threat group’s remarkable success targeting open-source software was inevitable and fueled by the industry’s decision to prioritize code shipping over security.
010
Reposted by Matt Kapko
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 05/06/2026
More of my thoughts on the public vulnerability disclosure fight Microsoft picked with the researcher Nightmare Eclipse in this piece by @mattkapko.com for @cyberscoop.bsky.social . @andrewmorr.is of @greynoise.io Intelligence shares perspective too. cyberscoop.com/microsoft-co...
cyberscoop.com
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
When a researcher went public with Microsoft vulnerabilities, it laid bare a conflict that has never really been solved.
0146
Reposted by Matt Kapko
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 27/05/2026
Thanks for letting me comment @mattkapko.com! And…yea, I made an Arby’s joke 😂
cyberscoop.com
FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person
Silent Ransom Group isn’t prolific, but it's demonstrated a knack for attacking the legal services sector with an extraordinary dual use of social engineering and in-person visits to victims’ workstat...
172
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 20/05/2026
Fox Tempest, a financially-motivated threat group, allowed ransomware operators and other cybercriminals to slip malware-laced software past security controls. via @mattkapko.com cyberscoop.com/microsoft-di...
cyberscoop.com
Microsoft disrupts cybercrime service that abused software verification systems en masse
Fox Tempest, a financially-motivated threat group, allowed ransomware operators and other cybercriminals to slip malware-laced software past security controls.
041
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 11/05/2026
Researchers found artifacts in the code that proved AI was heavily involved. A prominent cybercrime group planned to exploit the zero-day en masse for financial gain. via @mattkapko.com www.youtube.com/watch?v=Rywb... | cyberscoop.com/google-threa...
youtube.com
Google spotted an AI-developed zero-day before attackers could use it
YouTube video by CyberScoop
011
Reposted by Matt Kapko
Robert Downen @robertdownen.bsky.social · 04/05/2026
My colleague Aaron Parsley just won a Pulitzer for this story, written days after he survived the July 4 floods that killed his nephew. It's one of the most gutwrenching and memorable things you'll ever read. Please do.
texasmonthly.com
“The River House Broke. We Rushed in the River.”
The July 4 Texas flooding ripped our Kerr County home from its pillars, pulling us into the water and into the night. Then morning came.
231022315
Reposted by Matt Kapko
Greg Otto @gregotto.bsky.social · 20/04/2026
"...the seeds of the attack were planted in February when a Context.ai employee’s computer was infected with Lumma Stealer malware after they searched for Roblox game exploits, a common vector for infostealer deployments." cyberscoop.com/vercel-secur...
cyberscoop.com
Vercel's security breach started with malware disguised as Roblox cheats
The attack, which originated at Context.ai, showcases the pitfalls of interconnected cloud applications and SaaS integrations with overly privileged permissions.
1174
Reposted by Matt Kapko
Tim Starks @timstarks.bsky.social · 09/04/2026
Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’: FBI cyber chief Brett Leatherman told CyberScoop the Russian GRU campaign was unique in how it could propagate from routers to beyond. cyberscoop.com/fbi-operatio...
cyberscoop.com
Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’
FBI Assistant Director Brett Leatherman reveals how "Operation Masquerade" dismantled a "virtually invisible" Russian GRU cyber campaign that hijacked 18,000 routers to spy on home and office traffic worldwide.
043
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 27/03/2026
A systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. Retired four-star military officials worry the worst day in cyber is yet to come. via @mattkapko.com www.youtube.com/watch?v=Kv-h... | cyberscoop.com/former-nsa-c...
youtube.com
Former NSA chiefs worry American offensive edge in cybersecurity is slipping
YouTube video by FedScoop
026
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 26/03/2026
A systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. Retired four-star military officials worry the worst day in cyber is yet to come. via @mattkapko.com cyberscoop.com/former-nsa-c...
cyberscoop.com
Former NSA chiefs worry American offensive edge in cybersecurity is slipping
A systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. Retired four-star military officials worry the worst day in cyber is yet to come.
022
Matt Kapko @mattkapko.com · 26/03/2026
Four former NSA chiefs worry that a systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. The retired four-star military officials worry the worst day in cyber is yet to come. cyberscoop.com/former-nsa-c...
cyberscoop.com
Former NSA chiefs worry American offensive edge in cybersecurity is slipping
A systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. Retired four-star military officials worry the worst day in cyber is yet to come.
022
Matt Kapko @mattkapko.com · 24/03/2026
Second drop from the RSA Conference in San Francisco.
121
Matt Kapko @mattkapko.com · 23/03/2026
My first drop from this week’s RSA conference is out. Leaders from various cybersecurity institutions were quick to defend and evangelize the administration’s strategic pivots in cyberspace, claiming the freshly-released document is already paying off. cyberscoop.com/cyber-strate...
cyberscoop.com
Experts insist Trump administration's cyber strategy is already paying off
Leaders from various cybersecurity institutions were quick to defend and evangelize the administration’s strategic pivots in cyberspace.
001
Matt Kapko @mattkapko.com · 22/03/2026
Thank you, @ransomwaresommelier.com! That’s very kind of you.
111
Reposted by Matt Kapko
Zach Edwards @thezedwards.bsky.social · 20/03/2026
Good morning to everyone but botnet admins! Great piece from @mattkapko.com, appreciate having a few of my comments in it! 🖖🌩️⚖️ cyberscoop.com/botnet-disru...
cyberscoop.com
Justice Department disrupts botnet networks that hijacked 3 million devices
The Aisuru, Kimwolf, JackSkid and Mossad botnets enabled cybercriminals to initiate thousands of attacks. A crackdown targeting large-scale botnets continues amid growing challenges.
122
Reposted by Matt Kapko
Ryan Mac 🙃 @rmac.bsky.social · 18/03/2026
A difficult but necessary story. www.nytimes.com/2026/03/18/u...
nytimes.com
Cesar Chavez, a Civil Rights Icon, Is Accused of Abusing Girls for Years
2324
Matt Kapko @mattkapko.com · 16/03/2026
Maybe a criminal convicted of computer fraud and aggravated identity theft shouldn't have access to a computer while they're in prison for those crimes? Am I missing something here? cyberscoop.com/nba-nfl-athl...
cyberscoop.com
Zero lessons learned: Convicted scammer allegedly ran another athlete-focused phishing scam from federal prison
Kwamaine Jerell Ford allegedly impersonated an adult film star and tricked his high-profile victims into sharing their iCloud credentials and MFA codes under false pretenses.
031
Reposted by Matt Kapko
Tim Starks @timstarks.bsky.social · 16/03/2026
Nice one from @lindseywilkinson.bsky.social! (I lent a hand.)
085
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 12/03/2026
Angelo Martino is accused of playing both sides — committing attacks and conducting ransomware negotiations on some of the same cases on behalf of his former employer. www.youtube.com/watch?v=MlK6... | cyberscoop.com/digitalmint-...
youtube.com
Feds say another DigitalMint negotiator ran ransomware attacks and helped extort $75 million
YouTube video by CyberScoop
012
Matt Kapko @mattkapko.com · 12/03/2026
Some stories are so strange and so wild, they defy imagination. My latest digs into how a cybersecurity professional allegedly moonlighted as a cybercriminal -- committing attacks and conducting ransomware negotiations for his employer on some of the same cases. cyberscoop.com/digitalmint-...
cyberscoop.com
Feds say another DigitalMint negotiator ran ransomware attacks and extorted $75 million
Federal prosecutors have unsealed charges against Angelo John Martino III, a Florida ransomware negotiator accused of playing "both sides" by orchestrating attacks on his own clients.
021
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 06/03/2026
The administration also released an executive order on cybercrime and fraud. via @timstarks.bsky.social cyberscoop.com/trump-cybers...
cyberscoop.com
The long-awaited Trump cyber strategy has arrived
President Donald Trump released his administration's cyber strategy Friday, promoting offense operations in cyberspace, securing federal networks and critical infrastructure, streamlining regulations,...
056
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 02/03/2026
In this episode of Safe Mode, @gregotto.bsky.social dives in with @timstarks.bsky.social to unpack what’s happened inside CISA—and what it could mean for the country’s ability to withstand the next major cyber crisis. www.youtube.com/watch?v=ZUDX... | cyberscoop.com/cisa-personn...
youtube.com
The operational impact of worforce reductions at CISA
YouTube video by CyberScoop
046
Reposted by Matt Kapko
Kim Zetter @kimzetter.bsky.social · 27/02/2026
Seeing the lengthy list of changes/cutbacks to CISA catalogued in this one piece makes it clear there is little left of it. The agency is less than a decade old and struggled for years to find its footing before it started to make progress. But all advances it made have been gutted in last 12 months
cyberscoop.com
Across party lines and industry, the verdict is the same: CISA is in trouble
One year into the second Trump administration, CISA faces a 33% loss in personnel and shuttered divisions. Experts warn of "decimated" capabilities and a leadership vacuum as the agency struggles to m...
02213
Reposted by Matt Kapko
Greg Otto @gregotto.bsky.social · 27/02/2026
Gottumukkala out, Andersen in as acting CISA director cyberscoop.com/cisa-leaders...
cyberscoop.com
Gottumukkala out, Andersen in as acting CISA director
Madhu Gottumukkala steps down as acting director of CISA, replaced by Nick Andersen. The move follows criticism of agency performance and leadership shifts at DHS.
021
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 26/02/2026
The global campaign marks the second series of multiple actively exploited zero-day vulnerabilities in Cisco edge technology since last spring. The similarities don’t end there. via @mattkapko.com cyberscoop.com/cisco-zero-d...
cyberscoop.com
Governments issue warning over Cisco zero-day attacks dating back to 2023
Hackers exploited zero-day flaws in Cisco network devices for three years undetected. CISA issued an emergency directive as the global campaign continues.
034
Matt Kapko @mattkapko.com · 25/02/2026
Tim dug up all the dirt on CISA. His reporting captures the agency's decline and serves stark warnings about the messes that could unravel when the next major crisis hits.
032
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 27/01/2026
Cybercrime groups, including one that identifies as ShinyHunters, are targeting single sign-on services to gain access to victim networks and steal data. via @mattkapko.com cyberscoop.com/shinyhunters...
cyberscoop.com
A new wave of 'vishing' attacks is breaking into SSO accounts in real time
Cybercrime groups, including one that identifies as ShinyHunters, are targeting single sign-on services to gain access to victim networks and steal data.
043
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 25/01/2026
Ransomware negotiators dish on being in a ‘moral gray zone,’ unrestricted by accountability or industrywide rules of engagement. @mattkapko.com @gregotto.bsky.social www.youtube.com/watch?v=iAMe... | cyberscoop.com/ransomware-n...
youtube.com
The thin line between saving a company and funding a crime
YouTube video by CyberScoop
024
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 21/01/2026
Ransomware negotiators dish on being in a ‘moral gray zone,’ unrestricted by accountability or industrywide rules of engagement. via @mattkapko.com cyberscoop.com/ransomware-n...
cyberscoop.com
The thin line between saving a company and funding a crime
Ransomware negotiators dish on being in a ‘moral gray zone,’ unrestricted by accountability or industrywide rules of engagement.
012
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 18/12/2025
Attacker interest in the vulnerability is magnified by an unparalleled number of publicly available exploits, earning the defect the highest verified public exploit count of any CVE ever. via @mattkapko.com cyberscoop.com/react2shell-...
cyberscoop.com
React2Shell fallout spreads to sensitive targets as public exploits hit all-time high
Attacker interest in the vulnerability is magnified by an unparalleled number of publicly available exploits, earning the defect the highest verified public exploit count of any CVE ever.
022
Reposted by Matt Kapko
Tim Starks @timstarks.bsky.social · 12/12/2025
Hey everybody @lindseywilkinson.bsky.social has joined the FedScoop team (and Bluesky)! Give her a follow
032
Matt Kapko @mattkapko.com · 05/12/2025
Attackers of different origins and motivations swiftly exploited a critical vulnerability dubbed React2Shell, affecting one of the most extensively used application frameworks. Unit 42 has confirmed more than 30 organizations across various sectors are impacted. cyberscoop.com/attackers-ex...
cyberscoop.com
Attackers hit React defect as researchers quibble over proof
A debate over actual exploitation is muddying response efforts. Multiple researchers say they’ve observed working proof of concepts while others assert evidence of attacks is lacking.
010
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 04/12/2025
The attacks, which have impacted dozens of organizations, date back at least three years, lasting an average of 393 days. And that’s just what’s been uncovered in the last four months. via @mattkapko.com cyberscoop.com/china-bricks...
cyberscoop.com
Officials warn about expansive, ongoing China espionage threat riding on Brickstorm malware
The attacks, which have impacted dozens of organizations, date back at least three years, lasting an average of 393 days. And that’s just what’s been uncovered in the last four months.
034
Reposted by Matt Kapko
Greg Otto @gregotto.bsky.social · 04/12/2025
SCOOP: Sean Plankey's nomination to lead CISA is seemingly over, after DHS partially terminated a Coast Guard contract with Florida-based Eastern Shipbuilding Group. Plankey had been an adviser to CG. Sen. Rick Scott became a hurdle to Plankey's confirmation. cyberscoop.com/sean-plankey...
cyberscoop.com
Sean Plankey nomination to lead CISA appears to be over after Thursday vote
Sean Plankey’s nomination to lead the Cybersecurity and Infrastructure Security Agency looks to be over following his exclusion from a Senate vote Thursday on a panel of Trump administration picks.
135
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 03/12/2025
The open-source code library is one of the most extensively used application frameworks. Wiz found vulnerable versions in around 39% of cloud environments. via @mattkapko.com cyberscoop.com/react-server...
cyberscoop.com
Developers scramble as critical React flaw threatens major apps
The open-source code library is one of the most extensively used application frameworks. Wiz found vulnerable versions in around 39% of cloud environments.
075
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 25/11/2025
Details about the attack are scattered, and discrepancies remain about the number of companies impacted and the extent to which they are compromised. via @mattkapko.com cyberscoop.com/gainsight-ce...
cyberscoop.com
Gainsight CEO downplays impact of attack that spread to Salesforce environments
Details about the attack are scattered, and discrepancies remain about the number of companies impacted and the extent to which they are compromised.
023
Matt Kapko @mattkapko.com · 14/11/2025
China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work by @derekbjohnson.bsky.social at @cyberscoop.bsky.social. cyberscoop.com/anthropic-ai...
cyberscoop.com
China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work
Anthropic and AI security experts told CyberScoop that behind the hype, effective AI-driven cyberattacks still require skilled humans, with the attack possibly done to send a message as what’s possibl...
092
Reposted by Matt Kapko
Tim Starks @timstarks.bsky.social · 12/11/2025
I took a look at how Trump officials' comments on cyber deterrence contrast with the man himself, and what it means or reflects for the global scene. cyberscoop.com/trump-cyber-...
cyberscoop.com
While White House demands deterrence, Trump shrugs
U.S. cyber officials have pushed for strong action against foreign hacking, while President Trump has downplayed threats, creating mixed signals on cyber defense policy.
025
Reposted by Matt Kapko
Ken Mingis @kmingis.bsky.social · 29/10/2025
An incredibly sad loss for Computerworld, the larger tech journalism community, and for me personally....
computerworld.com
In Memoriam: Lucas Mearian, 1962-2025
Computerworld Senior Reporter Lucas Mearian passed away suddenly last week. Here’s a look at his professional career and his life.
011
Reposted by Matt Kapko
CyberScoop @cyberscoop.bsky.social · 02/10/2025
The emails, which are littered with broken English, aim to instill fear, apply pressure, threaten public exposure and seek negotiation for a ransom payment. via @mattkapko.com cyberscoop.com/extortion-em...
cyberscoop.com
Here is the email Clop attackers sent to Oracle customers
The emails, which are littered with broken English, aim to instill fear, apply pressure, threaten public exposure and seek negotiation for a ransom payment.
021
Reposted by Matt Kapko
Greg Otto @gregotto.bsky.social · 02/10/2025
CYBERSCOOP AFTER DARK: Attackers appearing to be aligned with the Clop ransomware group have sent emails to Oracle customers seeking extortion payments, claiming they stole data from the tech giant’s E-Business Suite. Early signs point to it being legit cyberscoop.com/clop-claims-...
cyberscoop.com
Oracle customers being bombarded with emails claiming widespread data theft
Researchers tell CyberScoop that notorious ransomware group Clop may be behind the email barrage.
062