Sign in

metlstorm

@metlstorm.risky.biz
1.6K followers 74 following 36 posts

Unix berserker, retired hacker-con organiser (Kiwicon!) and now technology-editor-slash-sysadmin-janitor at Risky.biz. Was @metlstorm on Twitter, am metlstorm@infosec.exchange on Masto.

PostsRepliesMedia
Reposted by metlstorm
Kawaiicon @kawaiicon.bsky.social · 04/05/2026
Kawaiicon is back for 2026 and while we get a lot done with volunteer help, Wellington City Council don't accept venue payment in high fives 🙏. The 2026 Kawaiicon Call for Sponsors is open! If you want a copy of our sponsor pack, throw us an email at kiwicon@kiwicon.org.
01618
Reposted by metlstorm
Joe Tidy BBC News @joetidy.bsky.social · 22/01/2026
With my book launching in the US + Canada I joined @patrick.risky.biz & @metlstorm.risky.biz on the RiskyBiz pod. I've listened to these guys for 8yrs so it was an honour to chat through cyber news and explain why I decided to write a book about teenage hackers and the Vastaamo case. risky.biz
1112
metlstorm @metlstorm.risky.biz · 03/11/2025
I am mad about @jags.bsky.social 's cat on the pod. Why does't Riskybiz have a pod-kitty?! 😾
381
metlstorm @metlstorm.risky.biz · 12/09/2025
Lol its been a whlie since I last hit the "please write your card name, number, expiry and cvv in this pdf and email it back" ecommerce checkout flow. Such PCI! Very DSS. 🤦 Paging a QSA and an acquiring bank, cleanup aisle my card data
0110
Reposted by metlstorm
Patrick Gray @patrick.risky.biz · 20/08/2025
MAGA be like...
2385
Reposted by metlstorm
Chris Satterfield @compgeke.com · 31/07/2025
99318
Reposted by metlstorm
Patrick Gray @patrick.risky.biz · 04/07/2025
Well, yeah. We're going to let our "kernel bug" description of Crowdstrike's mass murder of Windows systems stand
0151
Reposted by metlstorm
Patrick Gray @patrick.risky.biz · 04/07/2025
Maybe we should stagger newsletter releases in ringed deployments so we can catch these egregious errors... you know, like they should have done with their shitty content update that wiped out 8.5m boxes!
3491
Reposted by metlstorm
Patrick Gray @patrick.risky.biz · 04/07/2025
A Crowdstrike PR exec has written to us (twice) to demand we change some phrasing in one of our newsletters. We said a bug in their kernel driver caused their meltdown when it was actually a bad update file that caused a kernel panic. Huge mistake!
5251
Reposted by metlstorm
Kawaiicon @kawaiicon.bsky.social · 19/06/2025
It is that time! Call for Participation (CFP) time! Got a talk in mind? Done some cool research? Want to do something for hallway con? Want to be able to summon sparkle pots on cue? Submit to our CFP! Closes eventually, so just get your submission in now! kawaiicon.org/cfp/
media.tenor.com
a cartoon panda bear is holding a notebook and a pencil .
Alt: a cartoon panda bear is holding a notebook and a pencil .
0138
metlstorm @metlstorm.risky.biz · 12/06/2025
Omg, how is the webdav CVE-2025-33053 so dumb?! You make a .url shortcut file to run a local binary, with working-dir set to a webdav path, and if the binary happens to fork out to another bin without an absolute path, cwd is first in the search path... oh no? Is it.. is the bug really that stupid?!
2210
Reposted by metlstorm
Patrick Gray @patrick.risky.biz · 01/05/2025
35914
Reposted by metlstorm
Patrick Gray @patrick.risky.biz · 22/04/2025
The most recent episode of Wide World of Cyber w @thekrebscycle.bsky.social and @stamos.org is back in our podcast feed... it was offline for a week(ish) due to the recent unpleasantness So yeah, it's back. If you missed it, here it is VIDEO: www.youtube.com/watch?v=JPYt... AUDIO: risky.biz/WWC8/
youtube.com
Wide World of Cyber: How the Trump admin is changing the cybersecurity landscape
YouTube video by Risky Business Media
1284
Reposted by metlstorm
Patrick Gray @patrick.risky.biz · 11/04/2025
I have cancelled our planned trip to the RSA Conference in San Francisco later this month. @metlstorm.risky.biz and I were headed over to record some live shows and see everyone. Unfortunately I have received advice that crossing the border into the United States right now would be a bad idea.
1615329
Reposted by metlstorm
Patrick Gray @patrick.risky.biz · 11/04/2025
I've pulled down the most recent episode of Wide World of Cyber with Chris Krebs and Alex Stamos at the request of their employer SentinelOne, the sponsor of the series. I will say more about this in next week's Risky Business, but I want to make one thing clear: SentinelOne is not the bad guy here
7716
Reposted by metlstorm
brsn @br-sn.bsky.social · 10/04/2025
@metlstorm.risky.biz @patrick.risky.biz looks like rapid7 found a nice exploit strategy for that Ivanti BOF you discussed in the recent ep: attackerkb.com/topics/0ybGQ...
attackerkb.com
CVE-2025-22457 | AttackerKB
On April 3, 2025, Ivanti published an advisory for CVE-2025-22457, an unauthenticated remote code execution vulnerability due to a stack based buffer overflow.…
041
metlstorm @metlstorm.risky.biz · 26/03/2025
If you've ever run into your ios exploit dev mate at the pub after work and they seem a lil crazy-eyed, you can kinda see why: googleprojectzero.blogspot.com/2025/03/blas...
googleprojectzero.blogspot.com
Blasting Past Webp
An analysis of the NSO BLASTPASS iMessage exploit Posted by Ian Beer, Google Project Zero On September 7, 2023 Apple issued  an out-...
191
metlstorm @metlstorm.risky.biz · 26/03/2025
This is real handy to have in the pocket when some family/acquaintance asks about a service or platform you yourself don't use. "Just click about and see if anyone has logged in as you" makes sense to us nerds, but for normies, this is helpful as! Thanks Lorenzo!
0163
Reposted by metlstorm
Patrick Gray @patrick.risky.biz · 21/03/2025
We’re stoked to say Amberleigh Jack has joined Risky Biz full time as a producer and editor. Amberleigh has mountains of experience as a journalist and editor and she’s already such an important part of the team. She also has a deep connection to security via her (sadly departed) brother Barnaby
3533
metlstorm @metlstorm.risky.biz · 28/02/2025
Jesus, I think rather than being booted outta FVEY, Canada’s spooks are gonna be more like
media.tenor.com
two men standing next to each other with the words lea may i be excused on the bottom
ALT: two men standing next to each other with the words lea may i be excused on the bottom
080
metlstorm @metlstorm.risky.biz · 19/02/2025
Why you gotta be like this Cisco? Quote the url to get your "entitlement to a free upgrade" for a CVSS 10/10 bug in your product? Really? Thats where we're at with product security in 2025AD? SMDH. 🖕🌉🖕
3325