Sign in

Chris Wysopal

@weld.bsky.social
6.6K followers 299 following 404 posts

Gray haired gray hat. Co-founder Veracode. Former L0pht security researcher. Builds tools to find and fix vulnerabilities in code at scale.

PostsRepliesMedia
Chris Wysopal @weld.bsky.social · 31/08/2026
It's the last day for early bird tickets for the PoC year of Boston's MINUTECON. I will be keynoting!
011
Chris Wysopal @weld.bsky.social · 13/08/2026
This is a pretty big shift in US cyber policy. The White House is setting up a program that would let private cybersecurity companies conduct gov-authorized operations against foreign cybercriminal groups, inc surveillance & disruption of their infrastructure www.whitehouse.gov/presidential...
whitehouse.gov
Expanding Capabilities to Combat Transnational Cyber-Enabled Crime
MEMORANDUM FOR THE VICE PRESIDENT THE SECRETARY OF STATE THE SECRETARY OF THE TREASURY THE SECRETARY OF WAR THE ATTORNEY GENERAL THE SECRETARY OF COMMERCE
53125
Chris Wysopal @weld.bsky.social · 11/08/2026
License-plate readers are evolving into device trackers, linking cars with nearby phones, wearables and wireless devices to build an “electronic fingerprint.” theconversation.com/new-tech-add...
theconversation.com
New tech adds phone tracking to license plate readers, associating devices with identifiable cars
License plate readers are widely used in the US. A new product marketed to police departments promises to add the ability to sense phones and other devices in passing cars.
144
Chris Wysopal @weld.bsky.social · 11/08/2026
"The most severe activity known to date involved Georgia, where cyber activity against Clayton County reportedly caused a water pressure drop and forced the agency to issue a boil water advisory." www.darkreading.com/ics-ot-secur...
darkreading.com
Multistate Water System Attacks Widen, Iran Suspected
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
000
Chris Wysopal @weld.bsky.social · 04/08/2026
Unsupported connected devices are becoming a global security risk, but public policy has not kept pace. At BSides LV, Paul Roberts and Silas Cutler will discuss emerging state legislation requiring clear end-of-life disclosures, minimum support transparency, and responsible vendor exit plans.
140
Chris Wysopal @weld.bsky.social · 31/07/2026
Victim blaming in cyber is so 2000 and late.
050
Chris Wysopal @weld.bsky.social · 31/07/2026
Wow! This is an amazing and useful @defcon.bsky.social badge! www.wired.com/story/defcon...
wired.com
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.
041
Chris Wysopal @weld.bsky.social · 22/07/2026
Polymarket lost ~$3M and their smart contracts worked perfectly. A compromised frontend vendor injected malicious JS client-side. The breach lived in the browser — the layer nobody monitors. Audit what runs, not just what you wrote. www.cybersecurity-insiders.com/software-sup...
cybersecurity-insiders.com
Software Supply Chain Security Miss Drained $3M from Polymarket
Software supply chain security failures contributed to the $3M Polymarket loss, exposing risks from compromised dependencies and weak software controls.
252
Chris Wysopal @weld.bsky.social · 22/07/2026
Who should get charged with a CFAA violation for the AI agent breach of Hugging Face? The people who built the model or those that operated it unsafely? Someone else?
461
Reposted by Chris Wysopal
Electronic Frontier Foundation @eff.org · 17/07/2026
If you own it, why can't you fix it? Join EFF, Adam Savage, and iFixit CEO Kyle Wiens on July 23rd for a live conversation about the Right to Repair movement. We'll answer that question and yours during the live Q&A. eff.org/livestream-r2r
EFFecting Change: If You Own It, Why Can't You Fix It on Thursday, July 23 at 9 AM PT. Featuring EFF's Corynne McSherry and Hayley Tsukayama, as well as Adam Savage and iFixit CEO Kyle Wiens.
18125
Reposted by Chris Wysopal
MinuteCon @minutecon.org · 13/07/2026
Our first-ever keynote: Chris Wysopal @weld.bsky.social. Original L0pht vulnerability researcher, Veracode co-founder, and one of the first people to warn the world about insecure software. Boston hacker history, back on a Boston stage at MinuteCon. April 30 – May 1, 2027 minutecon.org
0149
Chris Wysopal @weld.bsky.social · 10/07/2026
There is a new cybersecurity con coming to Boston this spring, MinuteCon! Boston has a long history of cybersecurity impact going back to the @l0pht.bsky.social days in the 90s but hasn't had a major hackerish oriented con since Source Boston 10 yrs ago. Looking forward to this! www.minutecon.org
093
Reposted by Chris Wysopal
No Hat Con @nohatcon.bsky.social · 06/07/2026
KEYNOTE UNLOCKED_ Excited to have @weld.bsky.social opening up our conference with his Keynote: “WHEN EVERY ATTACKER CAN HAVE A RESEARCH TEAM” > Access talk details: nohat.it/talks #nohat2026 #CyberSecurity #InfoSec
053
Chris Wysopal @weld.bsky.social · 09/07/2026
Big win for farmers right to repair! fighttorepair.substack.com/p/the-deere-...
fighttorepair.substack.com
The Deere Dam Just Broke: FTC Settlement of Class Action Empowers Farmer Repair
The Federal Trade Commission, joined by the attorneys general of 5 states, announced a settlement with Deere & Company that dramatically expands farmers right to repair their agricultural equipment.
35918
Chris Wysopal @weld.bsky.social · 06/07/2026
I'm very excited to speak and meet new colleagues at No Hat in Italy this October!
030
Reposted by Chris Wysopal
—>realhackhistory.org @bsky.realhackhistory.org · 06/07/2026
A third #FOIA release from the #FBI for records on broadcast signal #hacker Captain Midnight and this time it is a recording of a radio interview with the man himself on Portland's KXL radio station at midday. 1986 - I'm unsure of the exact date but it was before he surrendered himself to the feds.
1144
Chris Wysopal @weld.bsky.social · 19/05/2026
28 years ago today, 7 members of the hacking group L0pht Heavy Industries told the U.S. Senate they could "shut down the internet in 30 minutes."
45112
Reposted by Chris Wysopal
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 13/05/2026
Couldn’t agree more with @weld.bsky.social about @windowsnyder.bsky.social for @darkreading.bsky.social being “one of the most important security leaders of the past two decades," for her ability to achieve systemic change. Great #Darkreading20 special coverage.
3145
Chris Wysopal @weld.bsky.social · 13/05/2026
1130
Reposted by Chris Wysopal
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/04/2026
AI is not going to flood you with real vuln reports unless you have a ton of real vulns. Adding resources to a vuln disclosure process to keep up with triage & bug fixing is a temporary investment at the loud end of the problem, not the right end.
Don’t make me tap the sign.
If your vuln disclosure process gets overwhelmed by AI finding real bugs, then write better code
04516
Reposted by Chris Wysopal
Patrick Gray @patrick.risky.biz · 03/04/2026
We've just published the 2nd episode of our documentary series "How the World Got Owned". This one looks at the 1990s and features interviews with Kevin Poulsen, @weld.bsky.social, @thedarktangent.bsky.social and Alpeh One (Elias Levy). Subscribe to the stories feed now! risky.biz/HTWGO2-stori...
1319
Chris Wysopal @weld.bsky.social · 30/03/2026
Phrack call for papers is out! Check out the cool demoscene graphics at phrack.org
194
Chris Wysopal @weld.bsky.social · 25/03/2026
I’m excited to let you know that the talks from [un]prompted—the AI Security Practitioner Conference—are now live on YouTube. No fluff, no hype—just real-world AI security from people actually doing the work. www.youtube.com/playlist?lis...
youtube.com
[un]prompted 2026 - YouTube
074
Chris Wysopal @weld.bsky.social · 17/03/2026
RCE vulnerability in the Yamaha PSR-E433 synthesizer, discovered by Anna Antonenko, allows exploitation through crafted MIDI files that trigger a hidden firmware backdoor with hardcoded password "#0000". it4sec.substack.com/p/remote-cod...
it4sec.substack.com
Remote Code Execution (RCE) in Yamaha synthesizers: an exploit in MIDI files & a hidden backdoor 🎹♫💉👨🏻‍💻🎉
Security researcher and musician Anna Antonenko, aka “porta,” shares her security research on the Yamaha PSR-E433: it looks like the device accepts special MIDI messages that allow commands to be exec...
12112
Chris Wysopal @weld.bsky.social · 12/03/2026
Doesn't everyone watch Akira on LaserDisc with their figurines?
040
Reposted by Chris Wysopal
Help Net Security @helpnetsecurity.com · 02/03/2026
Security debt is becoming a governance issue for CISOs 📖 Read more: www.helpnetsecurity.com/2026/03/02/c... #cybersecurity #cybersecuritynews #CISO #riskmanagement @weld.bsky.social
helpnetsecurity.com
Security debt is becoming a governance issue for CISOs - Help Net Security
A new security debt report shows 82% of organizations carry year-old flaws as high-risk vulnerabilities rise and fix timelines remain long.
011
Reposted by Chris Wysopal
Recurity Labs @recurity-labs.com · 02/03/2026
We wished we had more time to find the right words, and it is with deep regret that we have to tell you that our founder Felix “FX” Lindner passed away on 2026-03-01. blog.recurity-labs.com/2026-03-02/F...
blog.recurity-labs.com
Farewell, Felix · The Recurity Lablog
1128
Reposted by Chris Wysopal
Jeff Moss @thedarktangent.defcon.social.ap.brid.gy · 02/03/2026
RIP FX - You are a legend
55926
Reposted by Chris Wysopal
Slava Bonkus #ElonSucksSoHard @bonkski.bsky.social · 01/03/2026
Another NAFO legend has left us...💔 Jason Snitker @jasonsnitker (on Twitter) AKA Parmaster "Par" has passed away!🕯️ He was one of the first hackers, a legend in the hacking scene and a huge supporter of Ukraine and #NAFOfella. >> SIGNAL LOST: PARMASTER >> STATUS: GONE BUT NOT FORGOTTEN
135720
Chris Wysopal @weld.bsky.social · 27/02/2026
🕯️There will be a online memorial for Par 🕯️ Jason Snitker "Parmaster" Memorial Service Feb 28, 2026 04:00 PM Confirmed Speakers: Par's Aunt Deb Wysopal Mudge John Lee Tom Sloan (former Secret Service) Registration Link: us02web.zoom.us/meeting/regi...
us02web.zoom.us
Welcome! You are invited to join a meeting: Jason Snitker "Parmaster" Memorial. After registering, you will receive a confirmation email about joining the meeting.
Debra Kavaler Wysopal will be hosting this online memorial service for Parmaster along with Jason's family from Atlantic City, NJ. Confirmed Speakers: Par's Aunt Deb Mudge John Lee Tom Sloan (former...
143
Reposted by Chris Wysopal
deb kavaler @debdebdeb.bsky.social · 26/02/2026
Jason Snitker Rebel. Legend. Friend. Rest in Peace, ParMaster
031
Chris Wysopal @weld.bsky.social · 20/02/2026
My wife @debdebdeb.bsky.social and I are heartbroken to share the sad news that our old friend @jasonsnitker.bsky.social AKA Parmaster, has passed away.
Photo of a seated Jason Snitker
84213
Chris Wysopal @weld.bsky.social · 19/02/2026
New $10k FULU bug bounty for Ring video doorbells just announced. bounties.fulu.org/bounties/rin...
bounties.fulu.org
Ring Video Doorbells
The ProductRing, owned by Amazon, makes Video Doorbells, which are widely used doorstep-monitoring cameras. Ring doorbells released in 2021 or newer are eligibl…
030
Chris Wysopal @weld.bsky.social · 06/02/2026
This is a new one for me. I'm #8 and #31 on this top 100 list. Do you want Chris the the CTO of Veracode or Chris the security pioneer. 😂 www.futuristsspeakers.com/top-100-cybe...
futuristsspeakers.com
Top 100 Cybersecurity Thought Leaders | #1 Scott Steinberg
Top 100 cybersecurity thought leaders list: Hire famous AI & IT digital transformation consultant and futurist celebrity keynote speaker Scott Steinberg - 3000 brands served!
391
Chris Wysopal @weld.bsky.social · 03/02/2026
Can we all forget about the email disclaimers now? The information contained in this communication is confidential, may be attorney-client privileged, may constitute inside information, and is intended only for the use of the addressee. It is the property of JEE
350
Chris Wysopal @weld.bsky.social · 30/01/2026
In order to collect a bug bounty, a researcher was required to sign an NDA to not discuss the vulnerability. zuernerd.github.io/blog/2026/01...
240
Chris Wysopal @weld.bsky.social · 28/01/2026
Vulnerability disclosure norms are a control system for incentives. They made vulnerability handling predictable enough to industrialize. We get more finding, more fixing, and more secure software.
160
Chris Wysopal @weld.bsky.social · 28/01/2026
This looks interesting. Teenage hackers. I was one. I didn’t do this type of thing though. www.amazon.com/dp/133500193X
amazon.com
Ctrl + Alt + Chaos: How Teenage Hackers Hijack the Internet
Ctrl + Alt + Chaos: How Teenage Hackers Hijack the Internet [Tidy, Joe] on Amazon.com. *FREE* shipping on qualifying offers. Ctrl + Alt + Chaos: How Teenage Hackers Hijack the Internet
141
Chris Wysopal @weld.bsky.social · 23/01/2026
ATM jackpotting is still very much alive in 2025. Two attackers physically opened ATMs, connected a laptop, installed malware, and forced the machines to dump all their cash. DOJ convictions, prison time, restitution, deportation.
141
Chris Wysopal @weld.bsky.social · 21/01/2026
This FDA announcement says over 700 people were harmed and 7 people died due to a bug in the Abbot FreeStyle Libre device. www.fda.gov/medical-devi...
fda.gov
Early Alert: Glucose Monitor Sensor Issue from Abbott Diabetes Care
Certain Abbott Diabetes Care Continuous Glucose Monitor sensors may provide incorrect low glucose readings
031
Chris Wysopal @weld.bsky.social · 21/01/2026
Massachusetts lawmakers introduced bipartisan bills (HD 5563 / SD 3606) to curb abandoned consumer electronics by requiring vendors to disclose software support lifetimes, warn users before end-of-life, and explain lost features and security risks.
230
Chris Wysopal @weld.bsky.social · 21/01/2026
New from Anthropic. red.anthropic.com/2026/cyber-t...
020
Chris Wysopal @weld.bsky.social · 20/01/2026
Microsoft released NTLMv2 in 1998, no doubt because tools like L0phtCrack were able crack NTLMv1 passwords with the measly computing power then. NTLMv1 is still in use today! Mandiant has now released rainbow tables for NTLMv1 that can crack any pw in 12hrs on a $600 computer.
2112
Chris Wysopal @weld.bsky.social · 20/01/2026
UK NCSC: pro-Russian hacktivists are still hammering critical infra & local gov w/DDoS attacks. Low-tech, high impact, disrupting services & costing serious recovery time/money. Shouldn't critical infra & local gov be able to mitigate these attacks? What do they use? Cloudflare? Akamai? ISPs?
110
Chris Wysopal @weld.bsky.social · 18/01/2026
Tell your older relatives to turn personalized ads off everywhere. Scammers target this demographic.
193
Chris Wysopal @weld.bsky.social · 15/01/2026
“Prompt injection” is the wrong mental model. LLM attacks increasingly look like malware campaigns, not single exploits. This paper frames them as promptware and maps a 5-stage kill chain: initial access → priv esc → persistence → lateral movement → actions on objective. arxiv.org/html/2601.09...
arxiv.org
The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multi-Step Malware
291
Reposted by Chris Wysopal
Charming Stranger Films @charmingstranger.com · 09/01/2026
BIG NEWS! Rachael Morrison’s JOYBUBBLES will have its #WORLDPREMIERE at the 2026 #SundanceFilmFestival (@sundance.org) on JAN 26 at 6 PM! Executive produced by @cameowood.com & Charming Stranger Films, the film will screen in person JAN 26—JAN 31 & online screenings begin JAN 29: loom.ly/xnAbh1w
172
Chris Wysopal @weld.bsky.social · 15/01/2026
"A draft amendment to the BND Act, circulating by German media, would transform the agency’s reach by authorizing it to break into foreign digital systems, collect and store large portions of internet traffic, and analyze those communications retroactively." reclaimthenet.org/germany-bnd-...
reclaimthenet.org
Germany Considers Broader Legal Authority for Internet Surveillance and State Hacking
Much of the world’s data has always passed through Frankfurt; now Germany wants to keep a copy for itself.
030
Chris Wysopal @weld.bsky.social · 13/01/2026
iPhones now have "delete and report spam" for unknown messages and callers. If everyone was to choose "delete and report spam" for every spam message and call would they stop? If not, what is the point?
140