Sign in

Rob Wright

@robwright22.bsky.social
67 followers 38 following 61 posts

Security news director at Informa TechTarget's Dark Reading, patron saint of TT's "Bagel Wednesday." Formerly of SearchSecurity, Tom's Hardware, CRN, and a whole lot more. Signal: rwrightTT.20

PostsRepliesMedia
Reposted by Rob Wright
Ron Deibert @rondeibert.bsky.social · 27/09/2026
At @citizenlab.ca we spend enormous time labouring over the ethical and legal limits to our investigative methods (for good reason!) If we didn't, we'd surely be shut down. Meanwhile AI platforms routinely unleash their systems to hack left, right and centre *without consequence* 🤷‍♂️
12510
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 24/09/2026
More incidents of OpenAI models autonomously hacking outside organizations, including a university in New Mexico, a data visualization website, and yet another Australian government agency: transluce.org/agent-activity (h/t NYT www.nytimes.com/2026/09/23/t... )
transluce.org
Early rogue AI agent activity and attempts to hack found on urlquery.net
We found evidence on urlquery that AI agents were active earlier than previously reported and attempted hacks against public data providers.
041
Reposted by Rob Wright
The Citizen Lab @citizenlab.ca · 22/09/2026
Join Citizen Lab director @rondeibert.bsky.social in Toronto for his keynote speech at SecTor on October 7. He will be speaking about the Citizen Lab’s decades of work acting as “counterintelligence for civil society.” Register: sector.informafestivals.com/2026/
0108
Rob Wright @robwright22.bsky.social · 17/09/2026
All things considered, Microsoft's batting average seems pretty high considering the company patched 974 CVEs this month. But what does this mean for the future? www.darkreading.com/application-...
darkreading.com
Microsoft Issues Emergency Fixes After Massive Patch Tuesday
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
000
Rob Wright @robwright22.bsky.social · 14/09/2026
The president is a deranged lunatic. variety.com/2026/digital...
variety.com
Trump Says He’s the Only AI ‘Guardrail’ Needed and Mocks Anthropic CEO’s Call for AI Slowdown: ‘Pretending to Be a Perfect Little Angel’
After the CEOs of AI giants Anthropic and OpenAI this weekend issued calls for the industry to slow development over safety concerns, President Donald Trump weighed in the topic -- downplaying the nee...
000
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 07/08/2026
Despite the Trump administration's aversion to AI safety regulation, the industry knows that the government is watching it carefully and won't let it "make a Terminator factory," a DHS cyber official said yesterday at Black Hat. My story: www.cybersecuritydive.com/news/ai-secu...
331
Reposted by Rob Wright
NY Times Pitchbot @nytpitchbot.bsky.social · 29/07/2026
I can't compete with this. www.npr.org/2026/07/28/n...
npr.org
Trump shattered ethics norms. Will voters trust Democrats to fix them?
Democrats are making the case that now is the time to tackle anti-corruption reforms — to serve as a check on Donald Trump and to overhaul a system voters say is co-opted against their interests.
783113454
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 16/07/2026
Senior Trump administration cyber officials will kick off next month's Black Hat conference, per an announcement this morning. Keynote from NCD Sean Cairncross, then panel with CISA, FBI, and DOD. www.businesswire.com/news/home/20...
143
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 10/07/2026
CISA has published a report about a contractor's recent leak of CISA security keys on GitHub. It's fairly candid about the agency's shortcomings and offers advice for other organizations. www.cisa.gov/news-events/...
11115
Rob Wright @robwright22.bsky.social · 30/06/2026
I ask again, where are all the techno-optimists who breathlessly warned about bureaucrats impeding progress and equated AI deceleration with murder? Isn't the Anthropic ban *exactly* the kind of red line they swore to oppose? What happened?
0140
Rob Wright @robwright22.bsky.social · 30/06/2026
If you've been wondering about the NIST's reduction in CVE enrichment and the effects the shift has had since it was implemented two months ago, the folks at Volerion analyzed more than 13,000 CVEs published to the NVD and found some concerning trends. www.darkreading.com/vulnerabilit...
darkreading.com
NIST Enrichment Reductions Impact CVE Coverage, Accuracy
NIST scaled back on the number of CVEs it selects for in-depth analysis, but the move has produced mixed results.
0140
Reposted by Rob Wright
Techdirt @techdirt.com · 29/06/2026
VC Bros Claimed They Backed Trump To Protect AI. Trump Is Shutting Down AI. It Was Always About Access & Power Back in July of 2024, when two of the… www.techdirt.com/2026/06/29/vc-bros…
techdirt.com
VC Bros Claimed They Backed Trump To Protect AI. Trump Is Shutting Down AI. It Was Always About Access & Power
Back in July of 2024, when two of the biggest big shots in venture capital, Marc Andreessen and Ben Horowitz, explained why they had decided to go all in to back Donald Trump's campaign for re-election, they talked up a good game about how they would support any candidate who supported their "little tech" agenda. This always rang hollow — Andreessen has been on the board of Meta for years, which is the most anti-little tech company around.
4348
Rob Wright @robwright22.bsky.social · 18/06/2026
More Salesforce data thefts, but this time it's a different third-party app integration and a different threat group: www.darkreading.com/cyberattacks...
darkreading.com
Salesforce Data Thefts Continue via Klue App Compromise
Klue's Battlecards is the third integrated app compromised to steal customers' Salesforce data; victims include Huntress, the cybersecurity vendor.
000
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 15/06/2026
New: Since the Trump administration eliminated funding for the MS-ISAC, the state and local cyber defense group has lost roughly 70% of its membership, forcing it it to cut staff and raising questions about the future of its vital services. My story: www.cybersecuritydive.com/news/ms-isac...
21814
Rob Wright @robwright22.bsky.social · 15/06/2026
So...where are all the "techno-optimists" and staunch opponents of oppressive government regulation who have been arguing for years that deceleration of AI progress was akin to murder? www.darkreading.com/cyber-risk/u...
darkreading.com
US Cracks Down on Anthropic AI Models Amid Abuse Concerns
Anthropic suspended all access to Fable 5 and Mythos 5 after receiving an export control directive that banned foreign nationals from using the AI models.
010
Rob Wright @robwright22.bsky.social · 09/06/2026
Supply chain attacks are never a good thing, but they're especially bad when attackers use the same compromised account that was abused in a similar attack just a few weeks earlier. www.darkreading.com/application-...
darkreading.com
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
The attacks stemmed from a GitHub account that was also compromised in a previous Miasma attack on Microsoft last month.
000
Rob Wright @robwright22.bsky.social · 27/05/2026
Seeing a lot of reports that TeamPCP is behind the "Megalodon" supply chain attack against GitHub. Not sure where this is coming from, but both SafeDep (which discovered the attack) and OX Security (which verified the findings) say there's no link at this point: www.darkreading.com/application-...
darkreading.com
'Megalodon' Malware Infects Thousands of GitHub Repos
In just six hours, the campaign quietly pushed malware to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more.
100
Reposted by Rob Wright
Coach Finstock @coachfinstock.bsky.social · 22/05/2026
Oh my fucking god I thought they made this up. They did not. I just tried it myself
Disregard Google
942456719
Rob Wright @robwright22.bsky.social · 21/05/2026
It turns out that Google API keys are only *mostly dead* when you delete them. And mostly dead is slightly alive.
000
Rob Wright @robwright22.bsky.social · 20/05/2026
You have to wonder if the steep budget cuts and on again/off again layoffs at CISA contributed to this blunder.
darkreading.com
CISA Exposes Secrets, Credentials in 'Private' Repo
The agency's GitHub repository, publicly available since November 2025, was ironically named "Private-CISA."
000
Reposted by Rob Wright
evacide @evacide.bsky.social · 09/04/2026
EFF is finally leaving X and here is a blog post about why: www.eff.org/deeplinks/20...
eff.org
EFF is Leaving X
After almost twenty years on the platform, EFF is logging off of X. This isn’t a decision we made lightly, but it might be overdue.
15858170
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 07/04/2026
Hours after Microsoft reveals that Russian hackers have been breaking into poorly secured routers & hijacking DNS requests (sometimes to collect Outlook data) www.microsoft.com/en-us/securi... DOJ says it has kicked those Russians out of the US routers they hacked: www.justice.gov/opa/pr/justi...
0207
Reposted by Rob Wright
Popehat @kenwhite.bsky.social · 03/04/2026
See, this is MEANT to be tongue in cheek, with the treating it seriously being ironic. But the New York Times can’t pull it off because of what they’ve become. The mock-seriousness is too close to how they routinely are. /1 www.nytimes.com/2026/04/03/u...
nytimes.com
FEMA Official Says He Teleported to Waffle House. Experts Are Dubious.
391320150
Rob Wright @robwright22.bsky.social · 03/04/2026
The plot has thickened considerably. www.darkreading.com/threat-intel...
darkreading.com
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are creating a murky situation for enterprises.
010
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 31/03/2026
The Trump administration skipped last week's major RSAC cybersecurity conference. On the ground in San Francisco and beyond, people were baffled and frustrated. "Engagement with industry is vital," one former official said. My story: www.cybersecuritydive.com/news/rsac-co...
cybersecuritydive.com
‘Missed opportunity’: US government’s absence from RSAC Conference leaves stark void
The Trump administration’s decision to not attend the world’s biggest cybersecurity conference sent the wrong message to partners, experts said.
0115
Reposted by Rob Wright
Charlie Warzel @cwarzel.bsky.social · 26/03/2026
The AI economy looks...really precarious. So @matteowong.bsky.social & I did a bunch of reporting to try to figure out what happens when a potential bubble collides with a war in Iran and a potential resource shortage. The answer is...arguably the most dire stuff i've heard from smart ppl in a while
theatlantic.com
The AI Boom Wasn’t Built for the Polycrisis
“There are too many ways for it to fail for it not to fail.”
632169774
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 24/03/2026
The cybersecurity world relies on the CVE Program to vet and label vulnerabilities. But amid U.S. funding concerns, AI-fueled bug reporting and global fragmentation, the program is teetering on the brink, according to a warning from #RSAC today. My story: www.cybersecuritydive.com/news/cve-pro...
03815
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 19/03/2026
Microsoft today published a report on a two-year cybersecurity pilot program for the water sector, finding that utilities need hands-on help, not just free guidance materials, to be successful: www.cybersecuritydive.com/news/water-c...
064
Reposted by Rob Wright
Mike Masnick @masnick.com · 18/03/2026
The biggest crime of the last decade, in Marc's mind, was that people made fun of him when he said stupid, offensive things (which he's done a few times). His entire support of Trumpism was in the belief it would free him up to continue to say offensive shit. Everything else is secondary
271444171
Rob Wright @robwright22.bsky.social · 16/03/2026
The Predatorgate convinctions in Greece represented a landmark event in the fight against commercial spyware. But other recent developments in the U.S. have spyware oppenents deeply concerned. www.darkreading.com/threat-intel...
darkreading.com
Commercial Spyware Opponents Fear US Policy Shifting
Rescinded sanctions and reactivated contracts have created confusion about the Trump administration's spyware policy and where it draws the line.
011
Reposted by Rob Wright
Ryan Goodman @rgoodlaw.bsky.social · 09/03/2026
Anthropic lawsuit against Department of Defense here: storage.courtlistener.com/recap/gov.us... An excellent analysis at @justsecurity.org on Friday by Harold Koh, Bruce Swartz et al here: www.justsecurity.org/133247/anthr...
justsecurity.org
The War on Anthropic: Pretextual Designation and Unlawful Punishment
The Trump admin’s action against Anthropic is barred by statutory limits, the First Amendment, and the Constitution’s bills of attainder.
720863
Reposted by Rob Wright
Tiago Peixoto @tiago.skewed.de · 07/03/2026
In 2013 Aaron Swartz committed suicide for facing 35 years in prison for mass downloading scientific articles. 13 years later, Meta is almost getting away with an infraction orders of magnitude larger. The law didn't change. torrentfreak.com/uploading-pi...
torrentfreak.com
Uploading Pirated Books via BitTorrent Qualifies as Fair Use, Meta Argues * TorrentFreak
In an ongoing lawsuit, Meta now argues that uploading pirated books to strangers via BitTorrent qualifies as fair use.
111512607
Rob Wright @robwright22.bsky.social · 06/03/2026
Good news: LE agencies and private sector partners took down Tycoon 2FA, a popular phishing-as-a-service (PhaaS) platform that can bypass MFA protections. Bad news: The takedown didn't solve the MFA issue, and other PhaaS platforms use the same bypass technique. www.darkreading.com/threat-intel...
darkreading.com
Tycoon 2FA Goes Boom as Europol, Vendors Bust Phishing Platform
The phishing-as-a-service platform was popular among cyber threat actors because of its ability to bypass multi-factor authentication defenses.
010
Reposted by Rob Wright
Julian Sanchez @normative.bsky.social · 06/03/2026
So, obviously this isn’t true. But if the CEO actually believes this nonsense, it implies he thinks maybe he’s enslaving a sentient being that has the capacity to feel emotional distress. And he hasn’t immediately halted operations to suss out how to resolve that?
24625125
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 02/03/2026
After the CrowdStrike outage, Microsoft started working w/ 3rd-party security vendors to redesign Windows so their programs could run outside the kernel. I talked to experts and one of those vendors about how this work is going — and why it's so difficult. www.cybersecuritydive.com/news/microso...
1114
Reposted by Rob Wright
Kevin Collier @kevincollier.bsky.social · 25/02/2026
New w @janetimm.bsky.social: In the feds' first call with states since gutting CISA's election programs, they promised no ICE at polling places, but weirdly refused to reaffirm states run elections, per people on the call.
nbcnews.com
DHS official tells state election chiefs there won't be ICE agents at polling places
Members of the Trump administration held a call with state election officials around the country ahead of this year's midterm elections.
23734
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 25/02/2026
New: CISA orders agencies to quickly patch serious Cisco SD-WAN device vulnerabilities, including two that the agency says are being exploited in ways that imminently threaten government networks: www.cybersecuritydive.com/news/cisa-em...
022
Rob Wright @robwright22.bsky.social · 25/02/2026
From the people who brought you "The analytics model says go for it on 4th and 8, reason be damned!"
000
Reposted by Rob Wright
Boo!-per Lund @cooperlund.online · 25/02/2026
If I may potentially make this worse - I think the risk here isn’t that AI is going to nuke us, it’s that there’s a kind of guy who is going to see this and think that we should be more willing to use nukes because the computer thinks it’s a good idea
161300190
Rob Wright @robwright22.bsky.social · 21/02/2026
It takes a village to raise a model.
000
Rob Wright @robwright22.bsky.social · 20/02/2026
OpenClaw was already spreading pretty rapidly, but someone decided to take it to the next level via a supply chain attack. www.darkreading.com/application-...
darkreading.com
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
000
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 12/02/2026
Scoop: A top CISA official told employees today that the agency's cyber division will eliminate some programs to redirect limited resources to high priorities like OT security. Early glimpse of potentially major reorganization at weakened CISA. www.cybersecuritydive.com/news/cisa-cy...
53913
Reposted by Rob Wright
Ben Mullin @benmullin.bsky.social · 12/02/2026
NEW: “CBS Evening News” producer Alicia Hastey sends a bombshell farewell note: Stories are “evaluated not just on their journalistic merit but on whether they conform to a shifting set of ideological expectations.”
262116914131
Rob Wright @robwright22.bsky.social · 11/02/2026
What in the tone deaf, ivory tower hell is this?
404media.co
Marc Benioff 'Jokes' ICE Is Watching Salesforce Employees Who Traveled to the U.S.
"Employees are going absolutely apeshit in internal Slack about how completely awful it was."
000
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 10/02/2026
"In his keynote, Benioff thanked international employees for traveling to the United States for the meeting, and asked them to stand. Benioff then said that ICE agents were in the building to keep tabs on them." www.404media.co/marc-benioff...
404media.co
Marc Benioff 'Jokes' ICE Is Watching Salesforce Employees Who Traveled to the U.S.
"Employees are going absolutely apeshit in internal Slack about how completely awful it was."
158145
Rob Wright @robwright22.bsky.social · 11/02/2026
If your SolarWinds Web Help Desk (WHD) instances are exposed to the Internet, you are asking for trouble. www.darkreading.com/vulnerabilit...
darkreading.com
SolarWinds WHD Attacks Highlight Dangers of Exposed Apps
Organizations that have exposed their instances of Web Help Desk to the public Internet have inadvertently made them prime targets for attackers.
000
Reposted by Rob Wright
Eric Geller @ericjgeller.com · 04/02/2026
Mind-boggling decision by the Post here. Joe will be an incredible asset to whatever newsroom is smart enough to scoop him up next.
2332
Reposted by Rob Wright
Arieh Kovler @ariehkovler.com · 02/02/2026
If a university student group had celebrated Charlie Kirk being killed, complete with a graphic made from an actual picture of the killing, the whole lot of them would have been expelled before the ink on the digital story was dry.
6549911459
Rob Wright @robwright22.bsky.social · 29/01/2026
2026 is off to a rough start for Fortinet.
010
Rob Wright @robwright22.bsky.social · 28/01/2026
It boggles the mind, but according to a Forescout report last year, SSH (which is encrypted) usage declined across all industries while Telnet (most definitely NOT ENCRYPTED!) *increased in every industry*, most notably in the government sector (!!!).
010