Ben Read
@benread.bsky.social
1.8K followers 110 following 100 posts
CTI ‪@wizsecurity.bsky.social‬ Previously NSC44, Mandiant, Google Go Mammoths
Posts Media Videos Starter Packs
benread.bsky.social
Berlin
merriam-webster.com
What’s the word where you’re from that, when pronounced exactly as it looks, identifies a tourist immediately?
Reposted by Ben Read
oxley.io
“James Comey’s rights and liberties are not the only ones at risk today. So is your own right to participate in free and fair elections in order to render a verdict on Trump’s invasion of those rights and liberties.” From @davidfrum.bsky.social apple.news/AX8_ub4UHR0G...
The Comey Indictment Is Not Just Payback — The Atlantic
It’s an advance glimpse of Trump’s next attempted seizure of power
apple.news
Reposted by Ben Read
wizsecurity.bsky.social
🚨 #Shai-Hulud: Major npm supply chain attack.

100+ packages weaponized with stolen GitHub tokens, stealing secrets, hijacking repos, and auto-propagating like a worm.

Guidance + detections inside

www.wiz.io/blog/shai-hu...
Reposted by Ben Read
josephcox.bsky.social
New from 404 Media: airlines are selling *5 billion* ticketing records to the government for warrantless searching, per new docs we obtained. ARC is a data broker owned by United, American, Delta, etc. Then sells peoples' travel info to ICE, Secret Service, FBI etc www.404media.co/airlines-sel...
Airlines Sell 5 Billion Plane Ticket Records to the Government For Warrantless Searching
New documents obtained by 404 Media show how a data broker owned by American Airlines, United, Delta, and many other airlines is selling masses of passenger data to the U.S. government.
www.404media.co
Reposted by Ben Read
lorenraeds.bsky.social
A private individual with power to get public servants fired, put them at physical risk, get them investigated, threaten their post government careers, go after their families and defame them with fantasies is an enormous threat to our national security and public well being. This can't stand.
benread.bsky.social
A fun investigation from the team here at @wizsecurity.bsky.social www.wiz.io/blog/wiz-dis...

Showing how leaked/stolen AWS keys can be used to enable other financially motivated schemes. (s/o to our friends at Proofpoint who helped us get some context on the phishing emails)
Wiz Uncovers SES Abuse Campaign Using Stolen AWS Access Keys | Wiz Blog
From leaked AWS access keys to large-scale spam: Wiz Research uncovered a live Amazon SES abuse campaign, turning insights into early-warning detections.
www.wiz.io
benread.bsky.social
Now up to 22 different Cinnamon Toast Crunch related products. The quest continues.
benread.bsky.social
Cinnamon Toast Crunch with Strawberry. Doesn't seem like it would add much, but who knows.
Cinnamon Toast Crunch with Strawberry
benread.bsky.social
Cinnamon Toast Crunch with Strawberry. Doesn't seem like it would add much, but who knows.
Cinnamon Toast Crunch with Strawberry
Reposted by Ben Read
kevincollier.bsky.social
I can't speculate on Trump's health in this new press conference but he just ribbed Alabama Senator Tommy Tuberville over Bama losing badly on Saturday. Tuberville coached Auburn, Bama's big in-state conference rival.
Reposted by Ben Read
pstirparo.bsky.social
TL;DR I am launching my #startup and we are going to change how to evaluate,cluster and reason about #malware, delivering accurate,contextual intelligence on samples. Say Hi to RationalEdge
@rationaledge.bsky.social
rationaledge.io

#threatintel #threathunting #cti #reverseengineering #detection 1/9
RationalEdge - Intelligence Meets Accuracy
Advanced malware analysis and threat intelligence solutions by RationalEdge
rationaledge.io
Reposted by Ben Read
ciaranm.bsky.social
The summer of 2025.

What we were promised

Vs

What we got
Reposted by Ben Read
propublica.org
On the left: Nate Cavanagh, a 28-year-old DOGE staffer and college dropout.

On the right: Mohammad Halimi, a 53-year-old exiled Afghan scholar.

This is the story of how DOGE targeted Halimi on social media.

Then the Taliban took his family. 🧵
Photo of DOGE staffer Nate Cavanagh, a 28-year-old white man in a blue pullover, carrying a black backpack. Photo of 53-year-old Afghan scholar Mohammad Halimi. He is sitting, wearing white pants and shirt with a brown vest.
benread.bsky.social
This one seems fairly straightforward:
Cinnamon Toast Crunch Hershey's Kisses.
Reposted by Ben Read
bindinghook.bsky.social
⚡Meet our Lightning Talk speakers at #BindingHookLive: @euben.bsky.social, @melissakgriffith.bsky.social, @benread.bsky.social, @disclosing.observer, Lena Riecke and Selena Larson! Request your invite: bindinghooklive.com
Reposted by Ben Read
pstirparo.bsky.social
🍎 machofile 🍏 first official release is finally live: github.com/pstirparo/ma...

It is a python module to parse #Mach-O binary files, with a focus on malware analysis and reverse engineering.
machofile is self-contained.

#macho #ios #reverseengineering #detection #threathunting #threatintel 1/3
GitHub - pstirparo/machofile: machofile is a module to parse Mach-O binary files
machofile is a module to parse Mach-O binary files - pstirparo/machofile
github.com
benread.bsky.social
This thread has somehow hit 20 different Cinnamon Toast Crunch-related products.
benread.bsky.social
Now with Caffeine: Cinnamon Toast Crunch Iced Coffee. Featuring an amazing 30g of sugar. It was sandwiched between Twix and Snickers iced coffees.
Cinnamon Toast Crunch Iced Coffee, made with Victor Allen's
benread.bsky.social
Now with Caffeine: Cinnamon Toast Crunch Iced Coffee. Featuring an amazing 30g of sugar. It was sandwiched between Twix and Snickers iced coffees.
Cinnamon Toast Crunch Iced Coffee, made with Victor Allen's
Reposted by Ben Read
benread.bsky.social
The final interesting thing is that in the most recent incident, the releases were done by local police in Guangzhou.

The MSS was likely involved in the investigation, but having local officials lead the public communication suggests a pretty open mandate for public attribution to Taiwan.
benread.bsky.social
This group (Green Spot, APT-C-01) has been linked to Taiwan since at least 2015 in industry reporting, so it's not a new claim, but the MSS seems content to coast on private sector credibility, as they offer no direct evidence of their own to support their attribution.
benread.bsky.social
The MSS seems to be escalating this campaign. They're increasing the number (3, 4, then 20) of individuals and releasing more types of information. (just names in the first, then, dates of birth and ID numbers in later releases).
Redacted picture of 20 Taiwanese hackers named by the MSS
benread.bsky.social
First, a shout out to @shakirov2036.bsky.social who had a great thread on this a few months ago
shakirov2036.bsky.social
MSS alleges that the Taiwanese cyber command "hired hackers and cybersecurity companies as external support" to engage in attacks on CI, hacktivism & running bots on social media

The report mentions Anonymous 64, a group MSS linked to Taiwan in September www.globaltimes.cn/page/202409/...
benread.bsky.social
New from me: China has been ramping up its public attribution against Taiwan, likely in an attempt to shift the conversation on cyber intrusions and pressure the island and they're using their private sector cybersecurity companies to do it. Read the piece, but a few highlights, take aways in this 🧵