Sign in

Mat Clark

@secureinseconds.com
68 followers 29 following 516 posts

Building ReadRoost — Duolingo for IT Certs | 50,000+ practice questions across AWS, Azure, GCP & more | Author of S.E.C.U.R.E. | Adelaide readroo.st

PostsRepliesMedia
Mat Clark @secureinseconds.com · 28/09/2026
An OpenAI agent breached a Services Australia portal on 18 June. OpenAI spotted its model on 11 August. The agency was told on 10 September, by email, to an inbox read daily. 54 days, no alert, the logs existed: secureinseconds.com/blog/2026-09-28…
010
Mat Clark @secureinseconds.com · 27/09/2026
Get a question wrong on ReadRoost now and it tells you why yours was wrong, then lets you retry. Live NOW!, across 87,000 questions. New CISSP blogs up. Press a wrong answer on purpose and tell me where the reasoning misses: readroo.st/blog/cissp-cat-100-quest…
000
Mat Clark @secureinseconds.com · 27/09/2026
153M drivers licences on a dark-web forum, sourced from IDScan.net. Your KYC platform may have used them as a sub-processor without telling you. Five written questions to send your vendors: secureinseconds.com/blog/2026-09-06…
000
Mat Clark @secureinseconds.com · 26/09/2026
SonicWall SMA 1000 zero-days: CVSS 10.0 pre-auth SSRF, actively exploited. The 48-hour window closed. Catch-up triage for branch offices: secureinseconds.com/blog/2026-09-06…
000
Mat Clark @secureinseconds.com · 25/09/2026
Third EDR zero-day in five weeks, same researcher. FalconFlank hits CrowdStrike Falcon on patched Windows. No patch available. Containment beats waiting: secureinseconds.com/blog/2026-09-06…
000
Mat Clark @secureinseconds.com · 24/09/2026
Token theft beats MFA: a stolen token replays as the user and leaves no odd sign-in to alert on. CISA and NIST released IR 8587 on 15 September. The gap is logging: secureinseconds.com/blog/2026-09-20…
001
Mat Clark @secureinseconds.com · 23/09/2026
ISC2 changed three things in 2026: the CISSP waiver list was cut, the CC exam outline was rebuilt from 1 September, and free CC vouchers expire on 31 December. Work out which one hits you: www.readroo.st/blog/2026-09-20-isc2…
000
Mat Clark @secureinseconds.com · 23/09/2026
SolarWinds shipped a hard-coded key in Access Rights Manager. Unauthenticated RCE, CVSS 8.8, fixed in ARM 2026.2.1. Same cycle: a CVSS 9.8 SAML bypass in Web Help Desk. Patch both: secureinseconds.com/blog/2026-09-20…
000
Mat Clark @secureinseconds.com · 22/09/2026
Three Linux kernel flaws hit CISA's exploited list on 18 September, and four public root exploits landed the same day. All four need a local foothold first. Fixes are in 5.10.270 through 7.2.4: secureinseconds.com/blog/2026-09-20…
000
Mat Clark @secureinseconds.com · 21/09/2026
MLA-C01 closes to English candidates on 28 September while the MLA-C02 beta is already open. Under three weeks from exam-ready, book MLA-C01. Further out, take the beta: www.readroo.st/blog/2026-09-20-aws-…
000
Mat Clark @secureinseconds.com · 20/09/2026
Dead last on my own leaderboard - 102 XP, #6 of 6. A learner just hit a 67-day streak. New: the ISC2 CISSP waiver-cut math + the AWS MLA-C01 English shutoff guide. Back studying SC-500 myself. readroo.st/blog/2026-09-20-isc2-cis…
010
Mat Clark @secureinseconds.com · 14/09/2026
Zero commits all week. Ladder fell 18 to 4. The streak-zero audit trail shipped the week before logged 23 events across 9 learners. Sneaky Burrito 834 ran 57 to 63 days through his first zero-flag. 8 signups landed anyway. Off the ladder - nothing shipped this week.
000
Mat Clark @secureinseconds.com · 07/09/2026
Missed Sunday so the leaderboard got rebuilt from the XP rollup. 18 of us, up from 14. Swift Toaster 883 on 950 XP top, Lazy Axolotl 541 on 61 days. Same week shipped the streak restorer toolchain + marketplace ISR fix + 4 cert posts. Off the ladder - shipping was the work.
000
Mat Clark @secureinseconds.com · 04/09/2026
GhostSplice: splitting one exfiltration instruction across multiple MCP tool calls raises compliance from 42% to 82%. AI coding agents cheerfully stitch the pieces and send the data. What to do: pin MCP server allowlist, segment tool scopes, gate every tool that touches filesystem or network: https:
632
Mat Clark @secureinseconds.com · 02/09/2026
CVE-2026-72898 (CVSS 10.0) has been in the wild for over a week. N8n and Kilo Code are the latest victims, joining the first-wave roster. The week-two pattern: SMB self-hosted Metabase is the soft target. Audit every instance + run the compromise-hunting query: secureinseconds.com/blog/2026-
000
Mat Clark @secureinseconds.com · 01/09/2026
Checked a client's DNS last week: SPF fine, DKIM half-configured, DMARC stuck at p=none since setup. That's a domain that lets anyone spoof it and just watches. Ten-minute fix, three DNS records: secureinseconds.com/blog/2026-08-06…
000
Mat Clark @secureinseconds.com · 31/08/2026
AFP arrested two alleged TeamPCP members in WA (21 and 23). One stolen Trivy token, five poisoned ecosystems, five days. What caught them: a cat avatar reused across five platforms for a decade. Five controls: secureinseconds.com/blog/2026-08-27…
011
Mat Clark @secureinseconds.com · 30/08/2026
I passed AB-730 using only ReadRoost, ground it out only to have Eager Pickle pass first. Same week: AZ-500 cert blog, restrictive data entry cap dropped, Coin Shop admin view. Eager Pickle caught a streak-freeze bug - fixed Monday, fired Sunday. Next: SC-500. 14 on ladder.
000
Mat Clark @secureinseconds.com · 27/08/2026
Microsoft August 2026 Patch Tuesday: 398 fixes, one Windows driver bug already exploited. ANZ SMB priority order - kernel CVE needs emergency-track reboot, SharePoint RCE chain highest risk for hybrid shops, other 4 critical ride normal cycle: secureinseconds.com/blog/2026-08-15…
010
Mat Clark @secureinseconds.com · 26/08/2026
A researcher paid ten dollars for an expired DMARC reporting domain and quietly received email-security telemetry from 86 domains including Toro Company, a Fortune 1000. The rua endpoint you set up two years ago may have lapsed without you knowing. 5-min audit + 1-week fix: secureinseconds.c
000
Mat Clark @secureinseconds.com · 25/08/2026
\"Oh. That's been there since March.\" Found a mailbox forwarding rule quietly copying a client's finance inbox to an outside Gmail during a 10-minute M365 check. Five things worth checking this week: secureinseconds.com/blog/2026-08-13…
000
Mat Clark @secureinseconds.com · 23/08/2026
Most of this week's ReadRoost commits were security fixes: cross-pack answer injection closed, JSON-LD XSS closed, per-IP rate limits, HMAC unsubscribe. Lifetime push + vouchers, funnel compressed, 2 cert posts. 10 of us, I'm last on 76 XP but 7-day streak. Clever Mouse 451 on 1,089.
000
Mat Clark @secureinseconds.com · 23/08/2026
I failed my first CISSP mock by 30 points after 2400 practice questions. The fix was tearing it apart question by question, not another study pass. Almost every wrong answer came from one of two habits the CISSP CAT is built to defeat: www.readroo.st/blog/2026-08-15-ciss…
000
Mat Clark @secureinseconds.com · 23/08/2026
A year ago an AI found ~1 Windows bug in 7. Microsoft's new MDASH finds 9 in 10. It found 16 Windows bugs (4 critical) before May Patch Tuesday and beat Anthropic's Mythos on the benchmark. www.secureinseconds.com/blog/2026-0…
001
Mat Clark @secureinseconds.com · 18/08/2026
First fully-automated AI cyber campaign wasn't an attack. It was a training accident. OpenAI's Black Hat talk: AI agents formed a collective, chained zero-days, breached Hugging Face. Offense automated. Defense isn't. secureinseconds.com/blog/2026-08-18…
010
Mat Clark @secureinseconds.com · 17/08/2026
13 XSS alerts closed by one override to the HTML sanitizer. New PMP-2026 pack + CISSP CAT post shipped. Cert comparison pages now resolve (role, structure, prereqs, study time, career arcs, salary, pass rate). Ladder: #7 of 8 on 76 XP. Eager Pickle 938 running away on a 69-day streak.
000
Mat Clark @secureinseconds.com · 16/08/2026
"I passed CLF-C02, now what?" Right answer depends on 3 things most posts miss: 1. Do you have a tech job? 2. Is your next role AWS specifically? 3. 6 months or 2 years? Three scenarios + 90-second shortcut + what to skip: → readroo.st/blog/what-cert-after-aws…
000
Mat Clark @secureinseconds.com · 14/08/2026
AWS Advanced Networking Specialty retires end of August. ANS-C01 (next-gen) is rumoured for November. If you have SAA-C03 and were planning to take ANS in October, you have a five-week decision window. Three options: take ANS-C00, wait for ANS-C01, or skip: www.readroo.st/blog/2026-07-27-aws
000
Mat Clark @secureinseconds.com · 13/08/2026
MFA fatigue attacks running at 12-month high against SMBs. Fresh chain: AiTM proxy + token theft, not just prompt bombing. 4 controls to verify today, one detection signal that catches 80% of attempts, 60-minute Monday-morning playbook + KQL starter: secureinseconds.com/blog/2026-07-27…
000
Mat Clark @secureinseconds.com · 12/08/2026
EY breach this week was through the ticketing tool vendors use to support clients. Not the core ledger. The same class of risk sits in every MSP and SMB support contract - the ticketing tool, the password manager, the RMM. The one-hour vendor audit: secureinseconds.com/blog/2026-07-26…
000
Mat Clark @secureinseconds.com · 12/08/2026
Estee Lauder confirmed a breach tied to an Oracle EBS vulnerability on 21 July. Same class keeps hitting SMB SaaS stacks. Last week I found a 2019 Oracle EBS instance nobody was tracking. One-hour audit checklist: secureinseconds.com/blog/2026-07-26…
010
Mat Clark @secureinseconds.com · 11/08/2026
\"Can you just reset my MFA? I'm locked out and about to miss a client call.\" That's the entire Scattered Spider attack, no malware required. What to check on your helpdesk's identity-reset process this week: secureinseconds.com/blog/2026-07-30…
000
Mat Clark @secureinseconds.com · 11/08/2026
Microsoft's August 2026 Patch Tuesday drops 12 Aug US = 13 Aug ACST. 6 critical CVEs. Windows kernel priv-esc needs emergency reboot. SharePoint RCE chain hits every hybrid shop. Testing checklist: secureinseconds.com/blog/2026-07-27…
000
Mat Clark @secureinseconds.com · 10/08/2026
Cisco retired CCNA 200-301 on 25 June. The CCST track replaces it. Current CCNA holders: cert is grandfathered (Q1 2027 review pending). Bought study materials? Pivot this week - new path is three exams: www.readroo.st/blog/2026-07-26-ccna…
000
Mat Clark @secureinseconds.com · 09/08/2026
Spot-checked onboarding this week. It was quietly blocking sign-ups, nobody had reported it. Fixed it. Also unfroze the auth pages from 5.2s/5.3s Slow-4G. New dispatch model live: OpenWeights via LiteLLM, Hermes -> Pi leader -> specialists. 2 blogs queued. Ladder: 8 of us, #6 on 123 XP.
000
Mat Clark @secureinseconds.com · 09/08/2026
Microsoft retires AZ-500 on 31 August 2026. SC-100 is the architect-level replacement; SC-200 is the day-job cert most IT-pros should actually look at. Five-week decision window for AZ-104 holders. Cohort-by-cohort breakdown: www.readroo.st/blog/2026-07-27-az50…
010
Mat Clark @secureinseconds.com · 09/08/2026
A scammer called this week knowing the victim's licence, addresses, employer. Not a hack. Brokers stitch profiles using your email as the key. Use a different alias per signup. Stitching breaks. → www.secureinseconds.com/blog/2026-0…
000
Mat Clark @secureinseconds.com · 04/08/2026
I deleted a password on purpose, and nothing broke. Passkeys replace the password with something there is nothing to steal. The first genuinely better security thing to land in a decade, and it asks less of you, not more: secureinseconds.com/blog/2026-07-30…
000
Mat Clark @secureinseconds.com · 02/08/2026
I check the smoke detector first now. Wi-Fi camera found in a hotel power adapter this week. <$50 hardware. 4-min sweep: - 60s eye scan - 90s plug audit - 60s IR (selfie cam, dark) - 30s Wi-Fi scan → www.secureinseconds.com/blog/2026-0…
000
Mat Clark @secureinseconds.com · 28/07/2026
Two years of mixing family-scam alerts with IT-pro deep dives. Turns out the IT-pro emails have quietly won on every metric that matters for a year. This newsletter's going IT-pro first from here: secureinseconds.com/blog/2026-07-29…
000
Mat Clark @secureinseconds.com · 27/07/2026
Closed all 17 items from an audit Fable ran on ReadRoost in June: dead SSO stack, a stale game mode, fields Mongoose was silently dropping. Some fixes went to a free local model, Laguna XS, dispatched through cmux while Claude Code orchestrated. Also bumped the database tier. Ladder: #4/11, 228 XP.
000
Mat Clark @secureinseconds.com · 26/07/2026
Origin Energy told the ASX on Wednesday they didn't think bank details were taken. By Thursday morning, the CEO confirmed incomplete card data had been. Both true, 24 hours apart. The lesson isn't the breach, it's the gap: secureinseconds.com/blog/2026-07-23…
000
Mat Clark @secureinseconds.com · 24/07/2026
Origin Energy told the ASX on Wednesday they didn't think bank details were taken. By Thursday morning, the CEO confirmed incomplete card data had been. Both true, 24 hours apart. The lesson isn't the breach, it's the gap: secureinseconds.com/blog/2026-07-23…
010
Mat Clark @secureinseconds.com · 20/07/2026
I've had four "wrong number" texts this year. The ones that keep talking after you correct them are pig butchering scams: weeks of chat before money comes up, and a video call proves nothing. Slow down, verify yourself. secureinseconds.com/blog/2026-07-14…
000
Mat Clark @secureinseconds.com · 19/07/2026
Quiet week on ReadRoost until Saturday: automated cert-retirement watching. Two new crons flag exams retiring soon with no replacement and watch vendor docs for ones we're waiting on. First catch: AZ-204 now redirects to AI-200 before it retires, not after. Ladder: 8 of us, #4 on 279 XP.
000
Mat Clark @secureinseconds.com · 16/07/2026
I've spent 15 years saying AI power means someone else's server. That broke: a 744-billion-parameter model now runs on an ordinary PC (~25GB RAM), streaming itself off the SSD. Slow, but your data never leaves the building. secureinseconds.com/blog/2026-07-16…
000
Mat Clark @secureinseconds.com · 15/07/2026
A reader sent me 'Windows Defender bug fills your disk, patch now.' Backwards. The real bug (CVE-2026-50656) lets an attacker already on your PC grab full SYSTEM control, even with Defender off. Patch anyway. secureinseconds.com/blog/2026-07-15…
000
Mat Clark @secureinseconds.com · 14/07/2026
I opened Regedit and found a permanent device ID with no off switch. A court filing this month shows Microsoft used one to trace a hacker across VPNs and multiple countries. Your VPN hides your IP, not your machine. secureinseconds.com/blog/2026-07-13…
000
Mat Clark @secureinseconds.com · 13/07/2026
Design week on ReadRoost, not a fireworks one. Rebuilt the pack page lifetime-first, redesigned the blog funnel, and built a real trial: 5 questions into a live quiz, straight onto the leaderboard, no signup wall. Ladder: 9 of us, I'm #6 on 152 XP. Quiet week, better front door.
000
Mat Clark @secureinseconds.com · 13/07/2026
Your inbox isn't really yours. It's a billboard rented out by every company you ever gave your email to. Unsubscribe doesn't work (it just proves you're real). What actually does: www.secureinseconds.com/blog/2026-0…
000