Sign in

Chris Wysopal

@weld.bsky.social
6.6K followers 299 following 404 posts

Gray haired gray hat. Co-founder Veracode. Former L0pht security researcher. Builds tools to find and fix vulnerabilities in code at scale.

PostsRepliesMedia
Chris Wysopal @weld.bsky.social · 31/08/2026
It's the last day for early bird tickets for the PoC year of Boston's MINUTECON. I will be keynoting!
021
Chris Wysopal @weld.bsky.social · 13/08/2026
Not exactly “hack back,” but definitely a major expansion of the private sector’s role in offensive cyber operations.
281
Chris Wysopal @weld.bsky.social · 13/08/2026
This is a pretty big shift in US cyber policy. The White House is setting up a program that would let private cybersecurity companies conduct gov-authorized operations against foreign cybercriminal groups, inc surveillance & disruption of their infrastructure www.whitehouse.gov/presidential...
whitehouse.gov
Expanding Capabilities to Combat Transnational Cyber-Enabled Crime
MEMORANDUM FOR THE VICE PRESIDENT THE SECRETARY OF STATE THE SECRETARY OF THE TREASURY THE SECRETARY OF WAR THE ATTORNEY GENERAL THE SECRETARY OF COMMERCE
53225
Chris Wysopal @weld.bsky.social · 12/08/2026
We have them in MA too.
000
Chris Wysopal @weld.bsky.social · 11/08/2026
Device vendors, we need a technical fix: use short-lived, rotating device IDs so signals can’t be reliably linked to the same person or vehicle over time.
470
Chris Wysopal @weld.bsky.social · 11/08/2026
License-plate readers are evolving into device trackers, linking cars with nearby phones, wearables and wireless devices to build an “electronic fingerprint.” theconversation.com/new-tech-add...
theconversation.com
New tech adds phone tracking to license plate readers, associating devices with identifiable cars
License plate readers are widely used in the US. A new product marketed to police departments promises to add the ability to sense phones and other devices in passing cars.
144
Chris Wysopal @weld.bsky.social · 11/08/2026
"The most severe activity known to date involved Georgia, where cyber activity against Clayton County reportedly caused a water pressure drop and forced the agency to issue a boil water advisory." www.darkreading.com/ics-ot-secur...
darkreading.com
Multistate Water System Attacks Widen, Iran Suspected
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
000
Chris Wysopal @weld.bsky.social · 04/08/2026
Operation Graceful Exit” Tuesday, 18:30–19:15 | Copa
010
Chris Wysopal @weld.bsky.social · 04/08/2026
Unsupported connected devices are becoming a global security risk, but public policy has not kept pace. At BSides LV, Paul Roberts and Silas Cutler will discuss emerging state legislation requiring clear end-of-life disclosures, minimum support transparency, and responsible vendor exit plans.
140
Chris Wysopal @weld.bsky.social · 31/07/2026
this is about the moment that punk was turning into new wave.
120
Chris Wysopal @weld.bsky.social · 31/07/2026
Victim blaming in cyber is so 2000 and late.
050
Chris Wysopal @weld.bsky.social · 31/07/2026
Wow! This is an amazing and useful @defcon.bsky.social badge! www.wired.com/story/defcon...
wired.com
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.
041
Chris Wysopal @weld.bsky.social · 22/07/2026
Polymarket lost ~$3M and their smart contracts worked perfectly. A compromised frontend vendor injected malicious JS client-side. The breach lived in the browser — the layer nobody monitors. Audit what runs, not just what you wrote. www.cybersecurity-insiders.com/software-sup...
cybersecurity-insiders.com
Software Supply Chain Security Miss Drained $3M from Polymarket
Software supply chain security failures contributed to the $3M Polymarket loss, exposing risks from compromised dependencies and weak software controls.
252
Chris Wysopal @weld.bsky.social · 22/07/2026
Who should get charged with a CFAA violation for the AI agent breach of Hugging Face? The people who built the model or those that operated it unsafely? Someone else?
461
Chris Wysopal @weld.bsky.social · 18/07/2026
spectrum.ieee.org/what-the-cou...
spectrum.ieee.org
What the Count of Monte Cristo Can Teach Us About Cybersecurity
In 1844, Alexandre Dumas described a telecom hack based on insider threats and social engineering
042
Reposted by Chris Wysopal
Electronic Frontier Foundation @eff.org · 17/07/2026
If you own it, why can't you fix it? Join EFF, Adam Savage, and iFixit CEO Kyle Wiens on July 23rd for a live conversation about the Right to Repair movement. We'll answer that question and yours during the live Q&A. eff.org/livestream-r2r
EFFecting Change: If You Own It, Why Can't You Fix It on Thursday, July 23 at 9 AM PT. Featuring EFF's Corynne McSherry and Hayley Tsukayama, as well as Adam Savage and iFixit CEO Kyle Wiens.
18125
Reposted by Chris Wysopal
MinuteCon @minutecon.org · 13/07/2026
Our first-ever keynote: Chris Wysopal @weld.bsky.social. Original L0pht vulnerability researcher, Veracode co-founder, and one of the first people to warn the world about insecure software. Boston hacker history, back on a Boston stage at MinuteCon. April 30 – May 1, 2027 minutecon.org
0149
Chris Wysopal @weld.bsky.social · 10/07/2026
There is a new cybersecurity con coming to Boston this spring, MinuteCon! Boston has a long history of cybersecurity impact going back to the @l0pht.bsky.social days in the 90s but hasn't had a major hackerish oriented con since Source Boston 10 yrs ago. Looking forward to this! www.minutecon.org
093
Reposted by Chris Wysopal
No Hat Con @nohatcon.bsky.social · 06/07/2026
KEYNOTE UNLOCKED_ Excited to have @weld.bsky.social opening up our conference with his Keynote: “WHEN EVERY ATTACKER CAN HAVE A RESEARCH TEAM” > Access talk details: nohat.it/talks #nohat2026 #CyberSecurity #InfoSec
053
Chris Wysopal @weld.bsky.social · 09/07/2026
Big win for farmers right to repair! fighttorepair.substack.com/p/the-deere-...
fighttorepair.substack.com
The Deere Dam Just Broke: FTC Settlement of Class Action Empowers Farmer Repair
The Federal Trade Commission, joined by the attorneys general of 5 states, announced a settlement with Deere & Company that dramatically expands farmers right to repair their agricultural equipment.
35918
Chris Wysopal @weld.bsky.social · 06/07/2026
I'm very excited to speak and meet new colleagues at No Hat in Italy this October!
030
Reposted by Chris Wysopal
—>realhackhistory.org @bsky.realhackhistory.org · 06/07/2026
A third #FOIA release from the #FBI for records on broadcast signal #hacker Captain Midnight and this time it is a recording of a radio interview with the man himself on Portland's KXL radio station at midday. 1986 - I'm unsure of the exact date but it was before he surrendered himself to the feds.
1144
Chris Wysopal @weld.bsky.social · 19/05/2026
28 years ago today, 7 members of the hacking group L0pht Heavy Industries told the U.S. Senate they could "shut down the internet in 30 minutes."
45112
Reposted by Chris Wysopal
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 13/05/2026
Couldn’t agree more with @weld.bsky.social about @windowsnyder.bsky.social for @darkreading.bsky.social being “one of the most important security leaders of the past two decades," for her ability to achieve systemic change. Great #Darkreading20 special coverage.
3145
Chris Wysopal @weld.bsky.social · 13/05/2026
1130
Reposted by Chris Wysopal
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/04/2026
AI is not going to flood you with real vuln reports unless you have a ton of real vulns. Adding resources to a vuln disclosure process to keep up with triage & bug fixing is a temporary investment at the loud end of the problem, not the right end.
Don’t make me tap the sign.
If your vuln disclosure process gets overwhelmed by AI finding real bugs, then write better code
04516
Reposted by Chris Wysopal
Patrick Gray @patrick.risky.biz · 03/04/2026
We've just published the 2nd episode of our documentary series "How the World Got Owned". This one looks at the 1990s and features interviews with Kevin Poulsen, @weld.bsky.social, @thedarktangent.bsky.social and Alpeh One (Elias Levy). Subscribe to the stories feed now! risky.biz/HTWGO2-stori...
1319
Chris Wysopal @weld.bsky.social · 30/03/2026
Phrack call for papers is out! Check out the cool demoscene graphics at phrack.org
194
Chris Wysopal @weld.bsky.social · 25/03/2026
I’m excited to let you know that the talks from [un]prompted—the AI Security Practitioner Conference—are now live on YouTube. No fluff, no hype—just real-world AI security from people actually doing the work. www.youtube.com/playlist?lis...
youtube.com
[un]prompted 2026 - YouTube
074
Chris Wysopal @weld.bsky.social · 17/03/2026
RCE vulnerability in the Yamaha PSR-E433 synthesizer, discovered by Anna Antonenko, allows exploitation through crafted MIDI files that trigger a hidden firmware backdoor with hardcoded password "#0000". it4sec.substack.com/p/remote-cod...
it4sec.substack.com
Remote Code Execution (RCE) in Yamaha synthesizers: an exploit in MIDI files & a hidden backdoor 🎹♫💉👨🏻‍💻🎉
Security researcher and musician Anna Antonenko, aka “porta,” shares her security research on the Yamaha PSR-E433: it looks like the device accepts special MIDI messages that allow commands to be exec...
12112
Chris Wysopal @weld.bsky.social · 12/03/2026
Doesn't everyone watch Akira on LaserDisc with their figurines?
040
Reposted by Chris Wysopal
Help Net Security @helpnetsecurity.com · 02/03/2026
Security debt is becoming a governance issue for CISOs 📖 Read more: www.helpnetsecurity.com/2026/03/02/c... #cybersecurity #cybersecuritynews #CISO #riskmanagement @weld.bsky.social
helpnetsecurity.com
Security debt is becoming a governance issue for CISOs - Help Net Security
A new security debt report shows 82% of organizations carry year-old flaws as high-risk vulnerabilities rise and fix timelines remain long.
011
Reposted by Chris Wysopal
Recurity Labs @recurity-labs.com · 02/03/2026
We wished we had more time to find the right words, and it is with deep regret that we have to tell you that our founder Felix “FX” Lindner passed away on 2026-03-01. blog.recurity-labs.com/2026-03-02/F...
blog.recurity-labs.com
Farewell, Felix · The Recurity Lablog
1128
Chris Wysopal @weld.bsky.social · 02/03/2026
Dino went to Berlin in 2017 to hand deliver FX’s Pwnie lifetime achievement award. FX later said this helped with his recovery as this stimulated memories in parts of his brain which doctors were able to see.
071
Reposted by Chris Wysopal
Jeff Moss @thedarktangent.defcon.social.ap.brid.gy · 02/03/2026
RIP FX - You are a legend
55926
Reposted by Chris Wysopal
Slava Bonkus #ElonSucksSoHard @bonkski.bsky.social · 01/03/2026
Another NAFO legend has left us...💔 Jason Snitker @jasonsnitker (on Twitter) AKA Parmaster "Par" has passed away!🕯️ He was one of the first hackers, a legend in the hacking scene and a huge supporter of Ukraine and #NAFOfella. >> SIGNAL LOST: PARMASTER >> STATUS: GONE BUT NOT FORGOTTEN
135720
Chris Wysopal @weld.bsky.social · 28/02/2026
Yes
010
Chris Wysopal @weld.bsky.social · 27/02/2026
If you have any photos or stories to share please reply here. This is a photo of Par in Times Square during HOPE in 2006.
010
Chris Wysopal @weld.bsky.social · 27/02/2026
🕯️There will be a online memorial for Par 🕯️ Jason Snitker "Parmaster" Memorial Service Feb 28, 2026 04:00 PM Confirmed Speakers: Par's Aunt Deb Wysopal Mudge John Lee Tom Sloan (former Secret Service) Registration Link: us02web.zoom.us/meeting/regi...
us02web.zoom.us
Welcome! You are invited to join a meeting: Jason Snitker "Parmaster" Memorial. After registering, you will receive a confirmation email about joining the meeting.
Debra Kavaler Wysopal will be hosting this online memorial service for Parmaster along with Jason's family from Atlantic City, NJ. Confirmed Speakers: Par's Aunt Deb Mudge John Lee Tom Sloan (former...
143
Reposted by Chris Wysopal
deb kavaler @debdebdeb.bsky.social · 26/02/2026
Jason Snitker Rebel. Legend. Friend. Rest in Peace, ParMaster
031
Chris Wysopal @weld.bsky.social · 24/02/2026
140
Chris Wysopal @weld.bsky.social · 20/02/2026
We've lost so many in their 40s and 50s. 😢
131
Chris Wysopal @weld.bsky.social · 20/02/2026
The old-school hacking community has lost a true original. Rest in peace, Par. If anyone has stories or memories, please share them here.
2170
Chris Wysopal @weld.bsky.social · 20/02/2026
There will be an online memorial gathering on Feb 28. More details to follow.
1140
Chris Wysopal @weld.bsky.social · 20/02/2026
Par’s life reflected both the intensity of the early hacking world and the very real consequences that came with it. He was part of a generation exploring the edges of a new technological landscape before most people even knew it existed.
1151
Chris Wysopal @weld.bsky.social · 20/02/2026
His story in “Underground” includes the Citibank investigation that helped trigger that pursuit, as well as his time in custody at Rikers Island where he somehow found himself playing Dungeons & Dragons.
1130
Chris Wysopal @weld.bsky.social · 20/02/2026
Par was one of the sharpest & most elusive minds of the early underground hacking scene. As chronicled in “Underground,” he spent years navigating the emerging digital frontier, connecting with hackers internationally & staying ahead of US Secret Service during a long investigation in the early 90s
1161
Chris Wysopal @weld.bsky.social · 20/02/2026
My wife @debdebdeb.bsky.social and I are heartbroken to share the sad news that our old friend @jasonsnitker.bsky.social AKA Parmaster, has passed away.
Photo of a seated Jason Snitker
84213
Chris Wysopal @weld.bsky.social · 19/02/2026
New $10k FULU bug bounty for Ring video doorbells just announced. bounties.fulu.org/bounties/rin...
bounties.fulu.org
Ring Video Doorbells
The ProductRing, owned by Amazon, makes Video Doorbells, which are widely used doorstep-monitoring cameras. Ring doorbells released in 2021 or newer are eligibl…
030
Chris Wysopal @weld.bsky.social · 18/02/2026
I have one of those large octobox lights. Its amazing how one big bright soft light source gives the most natural lighting
010