Sign in

Mat Clark

@secureinseconds.com
68 followers 29 following 516 posts

Building ReadRoost — Duolingo for IT Certs | 50,000+ practice questions across AWS, Azure, GCP & more | Author of S.E.C.U.R.E. | Adelaide readroo.st

PostsRepliesMedia
Mat Clark @secureinseconds.com · 28/09/2026
An OpenAI agent breached a Services Australia portal on 18 June. OpenAI spotted its model on 11 August. The agency was told on 10 September, by email, to an inbox read daily. 54 days, no alert, the logs existed: secureinseconds.com/blog/2026-09-28…
010
Mat Clark @secureinseconds.com · 27/09/2026
Get a question wrong on ReadRoost now and it tells you why yours was wrong, then lets you retry. Live NOW!, across 87,000 questions. New CISSP blogs up. Press a wrong answer on purpose and tell me where the reasoning misses: readroo.st/blog/cissp-cat-100-quest…
000
Mat Clark @secureinseconds.com · 27/09/2026
153M drivers licences on a dark-web forum, sourced from IDScan.net. Your KYC platform may have used them as a sub-processor without telling you. Five written questions to send your vendors: secureinseconds.com/blog/2026-09-06…
000
Mat Clark @secureinseconds.com · 26/09/2026
SonicWall SMA 1000 zero-days: CVSS 10.0 pre-auth SSRF, actively exploited. The 48-hour window closed. Catch-up triage for branch offices: secureinseconds.com/blog/2026-09-06…
000
Mat Clark @secureinseconds.com · 25/09/2026
Third EDR zero-day in five weeks, same researcher. FalconFlank hits CrowdStrike Falcon on patched Windows. No patch available. Containment beats waiting: secureinseconds.com/blog/2026-09-06…
000
Mat Clark @secureinseconds.com · 24/09/2026
Token theft beats MFA: a stolen token replays as the user and leaves no odd sign-in to alert on. CISA and NIST released IR 8587 on 15 September. The gap is logging: secureinseconds.com/blog/2026-09-20…
001
Mat Clark @secureinseconds.com · 23/09/2026
ISC2 changed three things in 2026: the CISSP waiver list was cut, the CC exam outline was rebuilt from 1 September, and free CC vouchers expire on 31 December. Work out which one hits you: www.readroo.st/blog/2026-09-20-isc2…
000
Mat Clark @secureinseconds.com · 23/09/2026
SolarWinds shipped a hard-coded key in Access Rights Manager. Unauthenticated RCE, CVSS 8.8, fixed in ARM 2026.2.1. Same cycle: a CVSS 9.8 SAML bypass in Web Help Desk. Patch both: secureinseconds.com/blog/2026-09-20…
000
Mat Clark @secureinseconds.com · 22/09/2026
Three Linux kernel flaws hit CISA's exploited list on 18 September, and four public root exploits landed the same day. All four need a local foothold first. Fixes are in 5.10.270 through 7.2.4: secureinseconds.com/blog/2026-09-20…
000
Mat Clark @secureinseconds.com · 21/09/2026
MLA-C01 closes to English candidates on 28 September while the MLA-C02 beta is already open. Under three weeks from exam-ready, book MLA-C01. Further out, take the beta: www.readroo.st/blog/2026-09-20-aws-…
000
Mat Clark @secureinseconds.com · 20/09/2026
Dead last on my own leaderboard - 102 XP, #6 of 6. A learner just hit a 67-day streak. New: the ISC2 CISSP waiver-cut math + the AWS MLA-C01 English shutoff guide. Back studying SC-500 myself. readroo.st/blog/2026-09-20-isc2-cis…
010
Mat Clark @secureinseconds.com · 14/09/2026
Zero commits all week. Ladder fell 18 to 4. The streak-zero audit trail shipped the week before logged 23 events across 9 learners. Sneaky Burrito 834 ran 57 to 63 days through his first zero-flag. 8 signups landed anyway. Off the ladder - nothing shipped this week.
000
Mat Clark @secureinseconds.com · 07/09/2026
Missed Sunday so the leaderboard got rebuilt from the XP rollup. 18 of us, up from 14. Swift Toaster 883 on 950 XP top, Lazy Axolotl 541 on 61 days. Same week shipped the streak restorer toolchain + marketplace ISR fix + 4 cert posts. Off the ladder - shipping was the work.
000
Mat Clark @secureinseconds.com · 31/08/2026
AFP arrested two alleged TeamPCP members in WA (21 and 23). One stolen Trivy token, five poisoned ecosystems, five days. What caught them: a cat avatar reused across five platforms for a decade. Five controls: secureinseconds.com/blog/2026-08-27…
011
Mat Clark @secureinseconds.com · 30/08/2026
I passed AB-730 using only ReadRoost, ground it out only to have Eager Pickle pass first. Same week: AZ-500 cert blog, restrictive data entry cap dropped, Coin Shop admin view. Eager Pickle caught a streak-freeze bug - fixed Monday, fired Sunday. Next: SC-500. 14 on ladder.
000
Mat Clark @secureinseconds.com · 23/08/2026
Most of this week's ReadRoost commits were security fixes: cross-pack answer injection closed, JSON-LD XSS closed, per-IP rate limits, HMAC unsubscribe. Lifetime push + vouchers, funnel compressed, 2 cert posts. 10 of us, I'm last on 76 XP but 7-day streak. Clever Mouse 451 on 1,089.
000
Mat Clark @secureinseconds.com · 23/08/2026
A year ago an AI found ~1 Windows bug in 7. Microsoft's new MDASH finds 9 in 10. It found 16 Windows bugs (4 critical) before May Patch Tuesday and beat Anthropic's Mythos on the benchmark. www.secureinseconds.com/blog/2026-0…
001
Mat Clark @secureinseconds.com · 18/08/2026
First fully-automated AI cyber campaign wasn't an attack. It was a training accident. OpenAI's Black Hat talk: AI agents formed a collective, chained zero-days, breached Hugging Face. Offense automated. Defense isn't. secureinseconds.com/blog/2026-08-18…
010
Mat Clark @secureinseconds.com · 17/08/2026
13 XSS alerts closed by one override to the HTML sanitizer. New PMP-2026 pack + CISSP CAT post shipped. Cert comparison pages now resolve (role, structure, prereqs, study time, career arcs, salary, pass rate). Ladder: #7 of 8 on 76 XP. Eager Pickle 938 running away on a 69-day streak.
000
Mat Clark @secureinseconds.com · 16/08/2026
"I passed CLF-C02, now what?" Right answer depends on 3 things most posts miss: 1. Do you have a tech job? 2. Is your next role AWS specifically? 3. 6 months or 2 years? Three scenarios + 90-second shortcut + what to skip: → readroo.st/blog/what-cert-after-aws…
000
Mat Clark @secureinseconds.com · 09/08/2026
Spot-checked onboarding this week. It was quietly blocking sign-ups, nobody had reported it. Fixed it. Also unfroze the auth pages from 5.2s/5.3s Slow-4G. New dispatch model live: OpenWeights via LiteLLM, Hermes -> Pi leader -> specialists. 2 blogs queued. Ladder: 8 of us, #6 on 123 XP.
000
Mat Clark @secureinseconds.com · 09/08/2026
A scammer called this week knowing the victim's licence, addresses, employer. Not a hack. Brokers stitch profiles using your email as the key. Use a different alias per signup. Stitching breaks. → www.secureinseconds.com/blog/2026-0…
000
Mat Clark @secureinseconds.com · 02/08/2026
I check the smoke detector first now. Wi-Fi camera found in a hotel power adapter this week. <$50 hardware. 4-min sweep: - 60s eye scan - 90s plug audit - 60s IR (selfie cam, dark) - 30s Wi-Fi scan → www.secureinseconds.com/blog/2026-0…
000
Mat Clark @secureinseconds.com · 27/07/2026
Closed all 17 items from an audit Fable ran on ReadRoost in June: dead SSO stack, a stale game mode, fields Mongoose was silently dropping. Some fixes went to a free local model, Laguna XS, dispatched through cmux while Claude Code orchestrated. Also bumped the database tier. Ladder: #4/11, 228 XP.
000
Mat Clark @secureinseconds.com · 19/07/2026
Quiet week on ReadRoost until Saturday: automated cert-retirement watching. Two new crons flag exams retiring soon with no replacement and watch vendor docs for ones we're waiting on. First catch: AZ-204 now redirects to AI-200 before it retires, not after. Ladder: 8 of us, #4 on 279 XP.
000
Mat Clark @secureinseconds.com · 13/07/2026
Design week on ReadRoost, not a fireworks one. Rebuilt the pack page lifetime-first, redesigned the blog funnel, and built a real trial: 5 questions into a live quiz, straight onto the leaderboard, no signup wall. Ladder: 9 of us, I'm #6 on 152 XP. Quiet week, better front door.
000
Mat Clark @secureinseconds.com · 09/07/2026
The AI I use for ReadRoost wrote an SC-500 question about a Microsoft feature that doesn't exist. So I rebuilt the pack: every question grounded in real docs, cited, re-fetched to verify. 552 questions, 4 domains. A hallucinated exam question is actively harmful to someone trusting you to pass.
000
Mat Clark @secureinseconds.com · 06/07/2026
Didn't build ReadRoost this week, I built the machine that builds it. Pifactory runs a spec through five AI stations - plan, scout, build, review, verify - different open models checking each other. Cheap models do 80-90% of it. 78 commits, #4 on the ladder. Slow week up top, big one underneath.
000
Mat Clark @secureinseconds.com · 28/06/2026
This week on ReadRoost I got thoroughly out-ground: #6 of 11, 405 XP, a 3-day streak. Still shipped the big one - a per-domain readiness model showing which exam domain is holding you back and when you'll be ready. The regulars out-grind the founder every week. Love it.
000
Mat Clark @secureinseconds.com · 21/06/2026
Security+ V8 is in CompTIA's draft objectives, so: take SY0-701 now or wait? Almost always, now. A retired version doesn't expire your cert - it's valid 3 years regardless. Waiting just delays it and loses mature study material. readroo.st/blog/security-plus-v8-ta…
000
Mat Clark @secureinseconds.com · 21/06/2026
Topped my own ReadRoost leaderboard this week (#1/12, 761 XP, 11-day streak) but the regulars still out-grind me. Best bit: James passed AB-730 after 4 weeks studying with ReadRoost. And AI assistants are starting to cite us - Claude's now my top AI referrer.
000
Mat Clark @secureinseconds.com · 19/06/2026
The CISSP CAT doesn't just change how many questions you answer, it changes which ones you see. Memorising definitions is the wrong prep - it tests whether you think like a manager. How to actually study for it: readroo.st/blog/cissp-cat-exam-stud…
000
Mat Clark @secureinseconds.com · 18/06/2026
Before the US govt pulled Claude Fable 5, a red-teamer already had. Anthropic said no universal jailbreaks. 2 days later: exploit code + a leaked system prompt. The scary part isn't the jailbreak - it's the safety design. secureinseconds.com/blog/2026-06-12…
000
Mat Clark @secureinseconds.com · 17/06/2026
AZ-900 isn't just a stepping stone to AZ-104. For PMs, pre-sales, and procurement it's the thing that lets you hold a cloud conversation without bluffing. Whether that's worth 40 hours, and how to study it if you're non-technical: readroo.st/blog/az-900-for-non-tech…
000
Mat Clark @secureinseconds.com · 16/06/2026
"Remain vigilant" is the useless advice every breach email gives. Do this instead: 1. Change that password + anywhere you reused it 2. Turn on 2FA 3. Check Have I Been Pwned 4. ID leaked? Bank, credit ban, IDCARE secureinseconds.com/blog/2026-06-14…
000
Mat Clark @secureinseconds.com · 15/06/2026
Everyone says CySA+ is the automatic next cert after Security+. The job ads disagree: Security+ is the hard requirement, CySA+ is usually "nice to have". The order that actually maps to jobs (and yes, it's CS0-004 now): readroo.st/blog/security-plus-vs-cy…
000
Mat Clark @secureinseconds.com · 15/06/2026
Anthropic's newest model lasted 3 days. Tue: Fable 5 launches. Thu: jailbroken. Fri: the US govt orders it off - for everyone. The real lesson: a model you build on can vanish overnight, by someone else's call. secureinseconds.com/blog/2026-06-13…
000
Mat Clark @secureinseconds.com · 14/06/2026
ReadRoost this week: 10 on the weekly ladder, loads of sessions. I got to #3 (5-day streak) but Cheerful Unicorn did 11 - the regulars still out-study me. Shipped a readiness-over-time chart, a 25-room Gauntlet mode, and a big speed pass. Google impressions broke 2k/week - 5x in 5 weeks.
000
Mat Clark @secureinseconds.com · 12/06/2026
I gave one shop my email. Two weeks later, 3 companies I'd never heard of were emailing me. The fix: a different labelled email alias per company, so when spam arrives it tells you exactly who leaked you, by name. secureinseconds.com/blog/2026-06-07…
000
Mat Clark @secureinseconds.com · 10/06/2026
Someone can stick a fake QR code over the real one on a parking meter in 30 seconds, and the payment page it opens will take your card. QR phishing is up 146% this year. Read the web address before you tap, and check the sticker. secureinseconds.com/blog/2026-06-07…
000
Mat Clark @secureinseconds.com · 08/06/2026
Two weeks of ReadRoost in one (I skipped last week): a mobile quiz redesign down to 320px, daily-streak rewards, a 7-day unlimited trial, and a dozen+ blogs. Meanwhile my own streak is 3 days, #4 on my own product. If you've used a study platform: what's good, what's bad, what do you look for?
000
Mat Clark @secureinseconds.com · 03/06/2026
If you run a Microsoft SOC: the Sentinel-to-Defender portal migration deadline just moved from July 2026 to March 2027. 9 months you needed. The blocker everyone names is unified RBAC, a redesign, not a checkbox. www.secureinseconds.com/blog/2026-0…
000
Mat Clark @secureinseconds.com · 02/06/2026
I check the smoke detector first now. A USB power adapter in a hotel = Wi-Fi camera streaming overseas. $50, two taps. 4-min sweep on check-in: - Eye scan from foot of bed - Anything plugged in you didn't bring - IR check (lights off, selfie cam) - Wi-Fi scan → secureinseconds.com
000
Mat Clark @secureinseconds.com · 30/05/2026
"Just passed AZ-104. What next?" The lazy default reply: "AZ-305." Wrong for most. AZ-305 needs real architecture experience. Right answer: AZ-500 (security) for most. AZ-204 retiring July, skip it. → readroo.st/blog/what-cert-after-az-…
000
Mat Clark @secureinseconds.com · 30/05/2026
May 2026 was the first Patch Tuesday in two years with no exploited zero-days. 24 hours later a researcher dropped YellowKey, an unpatched BitLocker bypass that runs off a USB stick on current Windows 11. www.secureinseconds.com/blog/2026-0…
000
Mat Clark @secureinseconds.com · 30/05/2026
Right now there's probably an AI agent in your Microsoft tenant that nobody is governing. Agent 365 went GA on 1 May, the first real enterprise layer for AI agents (Copilot Studio, Foundry, Bedrock, Vertex AI). www.secureinseconds.com/blog/2026-0…
000
Mat Clark @secureinseconds.com · 30/05/2026
"Windows encryption has a backdoor" was the scary headline. Overblown. YellowKey is real but not a remote hack - someone needs your actual laptop. The real shift: what a stolen laptop is now worth. The calm fix: www.secureinseconds.com/blog/2026-0…
100
Mat Clark @secureinseconds.com · 30/05/2026
Last week I gave up 47 email addresses. All fake. None lead to my real inbox. One alias per service. If one leaks, I delete it and the spam stops instantly. Went from 200 emails a day to 20. 3 ways to start (incl. the one I built): secureinseconds.com
000
Mat Clark @secureinseconds.com · 25/05/2026
275 million Canvas users had their data stolen. The ransom was paid and the criminals "returned" it. Not safe - you can't un-leak data, a crook's promise isn't a delete key. If you used Canvas, assume your email is out: www.secureinseconds.com/blog/2026-0…
000
Mat Clark @secureinseconds.com · 25/05/2026
Someone lost $5K to a fake Indeed job last week. Money's recoverable. Worst part is the email: their real address is now in a fraud operation's confirmed-active contact database. One alias per job application contains it. → www.secureinseconds.com/blog/2026-0…
000