Matt Johansen

@mattjay.com

Friendly neighborhood cybersecurity guy | expect infosec news, appsec, cloud, dfir. | Long Island elder emo in ATX. vulnu.com <- sign up for my weekly cybersecurity newsletter

Woah. Trenchant, who develops zero-days and surveillance tools for Five Eyes intelligence agencies (US, UK, Canada, Australia, and New Zealand). Has had an insider accused of selling secrets to Russia.

BildBild

This BBC reporter was offered 25% of a ransom payout if he gave hackers access to the corporate network. He played along so we got a look inside their tactic here:

Bild

I think the separation of dev and prod is one of the most important things we need to solve in AI coding land. Keys. Secrets. Deployment. All that jazz. None of the tools help, if anything they make it super easy to do wrong.

That viral women's only dating app 'Tea' was hacked by some 4chan users. They didn't phish, social engineer, or use some crazy hacker technique either - the database was just public

Bild

If I was a bad guy who was looking for memory vulns, I'd be ALL OVER these new hotness web browsers. (Comet, Arc, etc.) Market share is small but much more valuable targets. - Teams behind them way smaller than ...Google

Bild

Which Windows drivers keep Microsoft’s security engineers busiest - and which ones do attackers actually exploit? Artem Baranov did the dang math. He scraped every CVE bulletin from Jan 2022 through May 2025 and built a clean data set of kernel-mode driver patches.

BildBild

🚨 New macOS backdoor alert: North-Korean hackers are disguising a Zoom update that drops malware built to hijack laptops and steal data & passwords. If you or your devs run macOS, keep scrolling.👇

Bild

Microsoft just put out a detailed threat intel report on North Korean threat actors who keep getting hired for remote jobs at US companies. They also outline how they're using AI to level up. Here's some highlights:

Bild

Been reading more and more about governments hacking their own citizens with spyware. They seem to be finding any excuse - journalists. politically active people. social media posts. Whatever they want. Then they do it with zero click 0days silently. Wild. youtu.be/zqY2A112bAQ

Bild

I’ve spent at least 2 nights in each time zone in the lower 48 in the last two weeks. Safe to assume my routine is absolutely f’d. I keep saying I’ll figure it out after I dig out of my massive backlog…

Breaking: House Oversight's top Dem Rep. Lynch requests Microsoft provide info on DOGE staffer's GitHub repo. It allegedly contains code to extract data from the NLRB's case management system.

Bild

UNFI (major distributor for Whole Foods + 30k grocery stores) hit with cyber incident. Critical systems offline since June 5. Significant supply chain disruptions ongoing. Heres what we know. 🧵

Bild

Easy security win most startups don't do: A) SSO with mandatory MFA (yubikey preferred) B) Device health check on login. Don't let unpatched OS or browser even login. Do this and you're in the 1%

Useless security advice you need to stop giving: "Don't click suspicious links!" Links are made to be clicked. Clicking links should be safe. If clicking a link gets your company hacked, it's a security stack issue, not a "train users to not click links" issue.

Bild

U.S. labs keep finding *undocumented* cellular radios hidden inside some Chinese-made solar inverters & battery packs Those radios give the gear a second, undocumented path to the internet. Global governments are reacting already: 🧵

Bild