Ben Read

@benread.bsky.social

CTI ‪@wizsecurity.bsky.social‬ Adjuct at @jhu.edu - SAIS Nonresident Fellow at @atlanticcouncil.bsky.social - Cyber Statecraft Previously NSC44, Mandiant, Google Go Mammoths

Great story here by my former colleague @bobmcmillan.bsky.social on built-in backdoors in consumer devices that allow nation-state hackers to create huge residential proxy networks. Bob spent months talking my ear off about this. This story is worth your time. www.wsj.com/tech/cyberse...

Exclusive | How Hackers Found a Back Door Into the American Living Room

Nation-state cyberattackers are increasingly using residential proxy networks to mask their traffic, turning everyday electronics into a massive global threat.

wsj.com

Russia and China consider new steps to expand their digital cooperation including on software development and satellite Internet and declare adherence to cyber norms. In this post, I review the relevant sections of the recent joint statement from Beijing fromcyberia.substack.com/p/putin-and-...

Putin and Xi Plan for Co(de)dependence

Russia and China consider expanding their digital cooperation per the joint statement following recent talks in Beijing.

fromcyberia.substack.com

After this week's Github breach, we checked in on hacker group TeamPCP's victim count: their supply chain attacks have tainted more than 500 pieces of software (a thousand-plus different version) and breached hundreds of companies. This is out of control. www.wired.com/story/teampc...

A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.

wired.com

Congratulations, Virginia! Republicans are trying to tilt the midterm elections in their favor, but they haven’t done it yet. Thanks for showing us what it looks like to stand up for our democracy and fight back.

🚨 500+ malicious PRs. One campaign. Wiz Research traced 6 waves of prt-scan starting 3 weeks earlier. AI-powered, automated attacks exploiting pull_request_target. Low success rate—but real npm + cloud creds hit. Full story: www.wiz.io/blog/six-acc...

prt-scan: AI-Powered GitHub Actions Supply Chain Attack | Wiz Blog

Wiz Research traces six waves of pull_request_target exploitation to one actor, starting three weeks before public disclosure. 500+ malicious PRs, 10% success.

wiz.io