Sign in

Danny Moore

@moore.bsky.social
6.5K followers 284 following 258 posts

Cyber-warfare | PhD from KCL | Author of 'Offensive Cyber Operations' | Security @ Meta

PostsRepliesMedia
Danny Moore @moore.bsky.social · 14/08/2026
These kinds of attacks, which are loud, aggressive, and have limited real-world effects, are basically a form of psychological terrorism. It's much more about fear and pressure than it is casualties.
2197
Reposted by Danny Moore
404 Media @404media.co · 23/07/2026
It is rare for the public to see such a large list of ICE’s technology capabilities in a single document. 404 Media has published the whole document, called “ICE Wide Analytical Tools," here: www.404media.co/leaked-docum... @josephcox.bsky.social reports:
6380211
Danny Moore @moore.bsky.social · 17/06/2026
No one is immune. As a side note the auth/trust model for most online services was already vulnerable to social engineering, and AI lowers the barrier to making compelling lures.
010
Danny Moore @moore.bsky.social · 12/05/2026
Even though I lived under constant rocket fire, I can't imagine what it must be like to live under the threat of scaled cheap drone warfare. Production scales up to millions-per-year now, this would've been pure fantasy a decade ago.
110
Danny Moore @moore.bsky.social · 30/04/2026
Chatting about this with friends earlier, but I miss the mid 2010s when all of cyber sec was on a flawed but functional Twitter. What I loved most about it was that we intersectdd with journalists, academics, policy makers, lawyers, band anyone else who had skin in the game.
1210
Danny Moore @moore.bsky.social · 23/06/2025
One of our biggest issues as a cybersecurity community and industry is that we inflicted dozens of partly overlapping cryptonyms on the world and just expect them to deal with it because we can't.
1100
Danny Moore @moore.bsky.social · 23/06/2025
Still consistently the best cyber-related podcast out there
0142
Danny Moore @moore.bsky.social · 21/06/2025
Considering that one of Israel's overt goals for the war is to destabilize the Iranian government, a nation-wide shutdown of public internet access plays well into Israel's hands. And it may not even stop further attacks.
042
Reposted by Danny Moore
Catalin Cimpanu @campuscodi.risky.biz · 19/06/2025
Predatory Sparrow has dumped the Nobitex crytpo platform source code on Telegram They previously stole $90mil worth of assets in a hack yesterday t.me/gonjeshkdara...
072
Danny Moore @moore.bsky.social · 13/06/2025
My hot take is that it isn't a lack of strategy, Israel has many viable, ambitious strategies. It's a constant failure of political will, unity, and patience to enact a strategy.
0252
Danny Moore @moore.bsky.social · 29/05/2025
Interesting! In my book, Offensive Cyber Operations, I talk a lot about the convergence of tactical offensive cyber and electronic warfare. The resources, approach and desired outcomes are deeply connected. The UK's move is in line with trends seen elsewhere. Will dive more into it all later.
0150
Danny Moore @moore.bsky.social · 26/05/2025
The most interesting bit here is that the best Western gov cyber outfits overhauled their operational approach after the mid-10s to focus more on avoiding detection. The era of the "factory ops" was too risky with the rise of threat intel. Harder to reliably spot 2025's Regin, Careto, Flame, etc
1215
Danny Moore @moore.bsky.social · 20/05/2025
"the technical team's analysis indicates that the attacker's methods and related technical proficiency were relatively low-level." Nothing in the article to explain what makes this "cyber warfare".
041
Reposted by Danny Moore
John Hultquist @hultquist.bsky.social · 20/05/2025
If you’ve been laid off from a cyber intel position, please reach out if you’d like to come to @sleuthcon.bsky.social.
36747
Reposted by Danny Moore
Greg Otto @gregotto.bsky.social · 15/05/2025
NEW: Hundreds of victims are surfacing across the world from zero-day cyberattacks on SAP, in a campaign that one leading cyber expert is comparing to the vast Chinese government-linked Salt Typhoon and Volt Typhoon breaches. cyberscoop.com/sap-cyberatt...
cyberscoop.com
SAP cyberattack widens, drawing Salt Typhoon and Volt Typhoon comparisons
Hundreds of victims are surfacing across the world from zero-day cyberattacks on Europe’s biggest software manufacturer and company.
0119
Reposted by Danny Moore
zeynep tufekci @zey.bsky.social · 15/05/2025
Drama over at X/xAI. Whatever you ask Grok, it pivots to “white genocide” in South Africa. The last panel is what Grok claims was a “verbatim” system prompt that caused the behavior. Jury out. It’s now fixed but they haven’t yet bothered explaining. This, not those AGI fantastical scenarios.
24386106
Reposted by Danny Moore
Joseph Cox @josephcox.bsky.social · 04/05/2025
New from 404 Media: the Signal clone the Trump administration uses was just hacked. TeleMessage makes a modified version of Signal that archives messages for government agencies, Waltz used it. A hacker got some users' messages, group chats. Hugely significant breach www.404media.co/the-signal-c...
404media.co
The Signal Clone the Trump Admin Uses Was Hacked
TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked.
15459942731
Danny Moore @moore.bsky.social · 15/04/2025
The literal birth of my firstborn child was less anxiety inducing than a full week of driving and parking in Tel Aviv.
010
Danny Moore @moore.bsky.social · 13/04/2025
New tech class, new vulnerability class
281
Reposted by Danny Moore
Raphael Satter @raphae.li · 11/04/2025
THREAD: When @thekrebscycle.bsky.social and his workplace, @sentinelone.com, were singled out by Donald Trump on Wednesday, I thought it was an opportunity to weigh the cybersecurity industry's rhetoric against their real world actions.
512871
Danny Moore @moore.bsky.social · 11/04/2025
Cybersecurity is built on trust, I can only imagine how CISA staff must be feeling.
0100
Reposted by Danny Moore
Eric Geller @ericjgeller.com · 10/04/2025
👀 China reportedly acknowledged to outgoing Biden officials in December that it was responsible for the Volt Typhoon critical infrastructure intrusions, linking them to "increasing U.S. policy support for Taiwan." www.wsj.com/politics/nat...
25021
Reposted by Danny Moore
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 09/04/2025
I was there. It was meant literally. “JD Work — now on the US NSC — shocked some by warning that the US would take lethal action against malicious actors in commercial cyber operations. Participants who heard [it said] they were unsure if it was meant literally or figuratively”
58028
Reposted by Danny Moore
Ulrike Franke @rikefranke.eu · 27/03/2025
The Swiss population doesn’t want to buy the F35 anymore, given everything that’s going on in Trump’s US. In 2020, a 50,1% majority had voted for the acquisition in a referendum. www.watson.ch/schweiz/wirt...
1327371
Reposted by Danny Moore
Kim Zetter @kimzetter.bsky.social · 11/03/2025
Why is the headline on all X outage stories about Musk blaming Ukraine for the DDoS? Why aren't media outlets putting the emphasis on the security lapse that allowed script kiddies (or whoever) to launch the attack against X as well as the lack of any evidence that the traffic came from Ukraine IPs?
117827
Danny Moore @moore.bsky.social · 10/03/2025
DDoS attacks frequently use compromised or otherwise co-opted IP addresses. The global distribution helps avoid geofencing defenses. Public high-confidence attribution takes time and effort. So take any quickfire claims with healthy skepticism.
080
Danny Moore @moore.bsky.social · 05/03/2025
Great coverage by @kimzetter.bsky.social. In this ecosystem we need to be doubly suspicious of major claims even if published by reputable sources. Considering the denials it's hard to pin down the truth. That said if things continue we may still see a gradual derisking of Russia by the US.
071
Danny Moore @moore.bsky.social · 01/03/2025
That's genuinely lovely but if we are to establish soft power diplomatic momentum that isn't dependent on the US establishment maybe do it on a network that isn't Elon's X.
0186
Danny Moore @moore.bsky.social · 28/02/2025
Madness
0165
Reposted by Danny Moore
Joseph Cox @josephcox.bsky.social · 14/02/2025
New from 404 Media: anyone can push updates to the Doge.gov site. Two sources independently found the issue, one made their own decision to deface the site. "THESE 'EXPERTS' LEFT THEIR DATABASE OPEN." www.404media.co/anyone-can-p...
351184420
Danny Moore @moore.bsky.social · 10/02/2025
I'm sorry but that's the most unhinged paragraph I ever read
110
Danny Moore @moore.bsky.social · 06/02/2025
Meeting my past self: 2025 Danny: "So yeah that's when DOGE Big Balls took over the gov database" 2015 Danny: "oh no" 2025 Danny: "don't worry we can still buy Melania coin" 2015 Danny: "please stop, what happened to you" 2025 Danny: "to all of us past Danny, to all of us"
181
Danny Moore @moore.bsky.social · 24/01/2025
crawl_depth=5
020
Danny Moore @moore.bsky.social · 22/01/2025
Yeah, I really don't need the Nazi-account-empowering, Nazi-party-supporting, Nazi-conspiracy-espousing, Nazi-salute-making guy to actually say "gosh I'm a Nazi"
0174
Danny Moore @moore.bsky.social · 20/01/2025
This and also - we never signed up for social media as this grand attempt at societal discourse. We wanted to reach out with our ideas and content, find connections that we otherwise wouldn't, and consume content we find interesting. We don't owe troll engagement as a mandatory tax.
170
Danny Moore @moore.bsky.social · 20/01/2025
I like this and will add one bit - LLM outputs must be verified, always. Follow sources, double-check claims, scrutinize cited data. LLMs create an information bootstrap, but their fundamental limitations mean they may use their training data to fabricate or modify facts.
020
Danny Moore @moore.bsky.social · 12/01/2025
The Google reviews for the GCHQ Bude location are amazing
030
Reposted by Danny Moore
Gearóid O'Connor @goconnor.bsky.social · 05/01/2025
New Year. Newly renewed commitment to reading long form on topics. First up, Offensive #Cyber Operations by @moore.bsky.social
Photgraph of the book cover of Offensive Cyber Operations by Daniel Moore
042
Danny Moore @moore.bsky.social · 02/01/2025
Stop this, media. Be better. He did this specifically to bait all of you to write the exact headlines you then handed him.
0130
Danny Moore @moore.bsky.social · 30/12/2024
Telecoms are golden targets. Poorly defended, they give adversaries access to metadata, geolocation, content, ISP customers & infra, and billing personal info for millions of people, including sensitive targets. Of COURSE they're top on the list for many groups.
0296
Danny Moore @moore.bsky.social · 27/12/2024
Cyber ops, criminal or state-backed, often take the path of least resistance. Good security controls & practices force adversaries to take riskier and costlier approaches, or seek other targets. That's good! Especially if you're an incidental target rather than high on someone's shitlist.
0216
Danny Moore @moore.bsky.social · 26/12/2024
The United States is already one of the most globally aggressive, methodical, and pervasive threat actors in cyber.
55012
Danny Moore @moore.bsky.social · 17/12/2024
I'm on board, I always hated that term. It's weirdly violent/graphic, does nothing to describe the type of scam, and portrays victims poorly.
163
Danny Moore @moore.bsky.social · 02/12/2024
It's okay to admit that many folks want centralized verification as a way to easily distinguish who they should take more seriously on a given topic, even if that is obviously not great. We're human, looking for heuristics to simplify an overloaded information environment is normal.
330
Reposted by Danny Moore
Raphael Satter @raphae.li · 27/11/2024
This is a story a lot of reporters have been chasing: Starting in 2015, a massive cyberespionage campaign targeted some of America's most prominent environmentalists. Now, we can reveal that the FBI has been probing whether a longtime Exxon lobbyist was involved. www.reuters.com/business/ene...
reuters.com
Exclusive: Exxon lobbyist investigated over hack-and-leak of environmentalist emails, sources say
The FBI has been investigating a longtime Exxon Mobil consultant over the contractor's alleged role in a hack-and-leak operation that targeted hundreds of the oil company’s biggest critics, according to three people familiar with the matter.
311715857
Danny Moore @moore.bsky.social · 27/11/2024
For every repo retraction, there's a hundred more. unstoppable without a lot of internal Bluesky resources dedicated to anti-scraping. I'm enjoying myself here and I hate to be this guy. But the frictionless borderline utopian vibe we have here is the product of a platform in its honeymoon period.
191
Reposted by Danny Moore
Max Smeets @maxwsmeets.bsky.social · 26/11/2024
A big day: Virtual Routes launches! This is a major milestone for our team and mission. Really excited to see what lies ahead!
1123
Danny Moore @moore.bsky.social · 26/11/2024
8 a day is still incredibly low, and I have no idea how they scale operations to meet global legal and regulatory requirements without drastically changing their revenue model.
050
Danny Moore @moore.bsky.social · 26/11/2024
One reason I'm cautiously excited that we reached critical mass here is that Bluesky finally has the same intersection of people I cared about on Twitter - natsec, infosec, academia, and journos.
3786