David Oxley
@oxley.io
Senior leader for detection and response at Anduril Industries. @CitizenLab.ca Research Fellow. Former federal agent. Fan of space, books, cyberpunk, sci-fi, espionage history, and storms. Personal account. 🇺🇸 🇺🇦 🇹🇼 #ThreatIntel Storm chasing 📸 🌪️: @wxdox.com
Shame on the government of Zambia for buckling under Chinese government pressure over Taiwan and canceling this year’s @rightscon.org. www.rightscon.org/rc26-stateme...
A statement to our community about why RightsCon 2026 will not take place in Zambia
Our official statement to the digital rights community about why RightsCon 2026 will not take place in Zambia
rightscon.org
Anduril Industries’s Threat and Attack Research team is hiring a senior engineer. Multiple locations are available or *remote*! This is a highly technical role; ability to obtain a U.S. Secret security clearance required. Have questions? Let me know! job-boards.greenhouse.io/andurilindus...
Senior Threat and Attack Research Engineer
Ashville, Ohio, United States
job-boards.greenhouse.io
Excited to share my next chapter as Senior Director, Detection and Response at Anduril Industries!
Notifications for deleted shouldn't remain in any OS notification database, and we've asked Apple to address this. In the meantime, you can prevent any preview text from your Signal messages from appearing in your notifications. Signal Settings > Notifications > Show “No Name or Content”
NEW: The FBI was able to forensically extract copies of incoming Signal messages from a defendant’s iPhone, even after the app was deleted, because copies of the content were saved in the device’s push notification database, multiple people present for FBI testimony in a trial told 404 Media.
As shared elsewhere…this is my last week with Amazon and AWS! I can’t recommend the good people with Amazon Cyber Threat Intelligence enough. At the same time, excited to share what’s next soon!
Proud to share new research by Amazon Threat Intelligence detailing recent activity by Sandworm/APT44 🇷🇺 targeting US and European energy, critical infrastructure, and managed security provider networks via vulnerable and misconfigured network edge devices. #threatintel aws.amazon.com/blogs/securi...
Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure | Amazon Web Services
As we conclude 2025, Amazon Threat Intelligence is sharing insights about a years-long Russian state-sponsored campaign that represents a significant evolution in critical infrastructure targeting: a ...
aws.amazon.com
A new blog this evening from Amazon Threat Intelligence detailing ongoing China-nexus cyber actors leveraging React2Shell (CVE-2025-55182): aws.amazon.com/blogs/securi...
China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) | Amazon Web Services
Within hours of the public disclosure of CVE-2025-55182 (React2Shell) on December 3, 2025, Amazon threat intelligence teams observed active exploitation attempts by multiple China state-nexus threat g...
aws.amazon.com
NEW: The classic anime "Ghost in the Shell" turned 30 years old this week. Despite coming out at the dawn of the internet, it was incredibly prescient in terms of imaginig a future where governments use hackers for espionage, people use malware to spy on their loved ones, and much much more.
How the classic anime 'Ghost in the Shell' predicted the future of cybersecurity 30 years ago | TechCrunch
The story of the Ghost in the Shell’s main villain the Puppet Master hinted at a future where governments use hackers for espionage, at a time when most of the world had never connected to the interne...
techcrunch.com
On the heels of @dlshad.net and @davidmagnotti.bsky.social’s presentation at #CYBERWARCON, happy to share the associated AWS Security blog post (with IOCs) aws.amazon.com/blogs/securi...
New Amazon Threat Intelligence findings: Nation-state actors bridging cyber and kinetic warfare | Amazon Web Services
The new threat landscape The line between cyber warfare and traditional kinetic operations is rapidly blurring. Recent investigations by Amazon threat intelligence teams have uncovered a new trend tha...
aws.amazon.com
Hope to see many of you at #CYBERWARCON tomorrow! As always, if you see me in the AWS shirt, don’t be afraid to say hi, and please don’t be offended if I forget your name (it’s not you, it’s me). 😅
Come work with Amazon Cyber Threat Intelligence (ACTI) focusing on the threats targeting Amazon, AWS, and our subsidiaries! US citizenship required, in-office across multiple US locations. DM with questions! www.amazon.jobs/en/jobs/3120...
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI
We are open to hiring candidates to work out of one of the following locations:Annapolis Junction, MD, USA | Arlington, VA, USA | Austin, TX, USA | Herndon, VA, USA | New York, NY, USA | Seattle, WA, ...
amazon.jobs
Listening to the #ThreeBuddyProblem podcast and, while I’m glad you’re hearing about Amazon threat intel for the first time, I can say we’ve been around doing a thing or two for a while @ryanaraine.bsky.social, @jags.bsky.social, and @craiu.bsky.social 😅 (but message received re: IOCs in the blog)
Excited to share another blog where Amazon Cyber Threat Intelligence (ACTI) discovered APT exploitation of zero-day vulnerabilities in Cisco and Citrix products. Proud of the team’s work! aws.amazon.com/blogs/securi...
Amazon discovers APT exploiting Cisco and Citrix zero-days | Amazon Web Services
The Amazon threat intelligence team has identified an advanced threat actor exploiting previously undisclosed zero-day vulnerabilities in Cisco Identity Service Engine (ISE) and Citrix systems. The ca...
aws.amazon.com
If I give the bully my lunch money every day eventually he will die of old age
cyberscoop.com/cyber-schola... Will open my big mouth here and say as a participant in one of these programs in the great before time, this is a massive unforced error by USG and will have impacts that span probably decades on the gov cyber workforce
Cyber scholarship-for-service students say government has pulled rug on them, potentially burdening them with debt
Some CyberCorps: Scholarship for Service participants have had federal agency job and internship offers rescinded this year due to cutbacks and freezes. It’s a condition of their scholarship contract ...
cyberscoop.com
‼️ The @cyberwarcon.bsky.social agenda and presenters list is live. Proud that Amazon Cyber Threat Intelligence will be presenting for the first time on the intersection of Iranian cyber ops and kinetic strikes with Dlshad Othman and @davidmagnotti.bsky.social! www.cyberwarcon.com/ping-first-b...
Ping First, Boom Second — CYBERWARCON
cyberwarcon.com
“James Comey’s rights and liberties are not the only ones at risk today. So is your own right to participate in free and fair elections in order to render a verdict on Trump’s invasion of those rights and liberties.” From @davidfrum.bsky.social apple.news/AX8_ub4UHR0G...
The Comey Indictment Is Not Just Payback — The Atlantic
It’s an advance glimpse of Trump’s next attempted seizure of power
apple.news
Happy to share that Amazon Cyber Threat Intelligence (ACTI) is hiring our first role in Dublin, Ireland! 🇮🇪 This role will provide threat intel support for the AWS European Sovereign Cloud (ESC). Dublin-based, open to current EU citizens, and with relocation available. amazon.jobs/en/jobs/3089...
Sr. Security Intelligence Engineer , European Sovereign Cloud (ESC) Threat Intelligence team
We are open to hiring candidates to work out of one of the following locations:Dublin, IEThe European Sovereign Cloud (ESC) Threat Intelligence team, part of Amazon Cyber Threat Intelligence (ACTI), i...
amazon.jobs
Glad to see not every country is powerless to hold coup leaders to account - “Bolsonaro Sentenced to 27 Years in Prison for Plotting Coup in Brazil” www.nytimes.com/2025/09/11/w...
Bolsonaro Sentenced to 27 Years in Prison for Plotting Coup in Brazil
nytimes.com
This morning, Amazon Cyber Threat Intelligence published a report about a recent watering hole attack by APT29 🇷🇺 that we discovered targeting Microsoft device code authentication. Proud of the work of the team and the chance to share this with the community! aws.amazon.com/blogs/securi...
Amazon disrupts watering hole campaign by Russia’s APT29 | Amazon Web Services
Amazon’s threat intelligence team has identified and disrupted a watering hole campaign conducted by APT29 (also known as Midnight Blizzard), a threat actor associated with Russia’s Foreign Intelligen...
aws.amazon.com
“The driving principle here is obvious: In a free society, people should know who is policing them.” apple.news/ATQz-Wb-hQom...
Show Us Your Face — The Atlantic
The federal government should prohibit the wearing of masks by ICE agents and require them to properly identify themselves.
apple.news
How Trump’s ‘Big, Beautiful Bill’ Will Make China Great Again www.nytimes.com/2025/07/03/o...
Opinion | How Trump’s ‘Big, Beautiful Bill’ Will Make China Great Again
nytimes.com
Use Signal. We promise, no AI clutter, and no surveillance ads, whatever the rest of the industry does. <3
Well-done by @billmarczak.org and @jsrailton.bsky.social at @citizenlab.ca! citizenlab.ca/2025/06/firs...
Graphite Caught: First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted - The Citizen Lab
On April 29, 2025, a select group of iOS users were notified by Apple that they were targeted with advanced spyware. Among the group were two journalists who consented to the technical analysis of the...
citizenlab.ca
Many moons ago, I was a federal agent. I arrested people. And you know how many times I did that while hiding my face and refusing to identify myself? Never. apple.news/A8NMRFx2mRua...
Opinion | The secret police descending on Small Town, U.S.A. — The Washington Post
Masked immigration officials are storming towns and arresting people.
apple.news
Happy @sleuthcon.bsky.social SLEUTHCON Day to those who celebrate! Hope to see many of you there! #SLEUTHCON
One week until @sleuthcon.bsky.social! Hope to see many of you at the best cybercrime conference of the year. (And grab a ticket while you still can!) #SLEUTHCON