Greg Otto's Avatar

Greg Otto

@gregotto.bsky.social

@gregotto from twitter, now on bluesky. Editor-in-Chief at CyberScoop. Host of Safe Mode. Better with words than I am with code.

5,385 Followers  |  424 Following  |  647 Posts  |  Joined: 24.05.2023  |  2.2595

Latest posts by gregotto.bsky.social on Bluesky

Post image 10.12.2025 17:30 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Thinkin bout a homemade hot chicken pop tart

Thinkin bout a homemade hot chicken pop tart

10.12.2025 16:05 β€” πŸ‘ 8    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Sean Plankey nomination to lead CISA appears to be over after Thursday vote Sean Plankey’s nomination to lead the Cybersecurity and Infrastructure Security Agency looksΒ to be over following his exclusion from a Senate vote Thursday on a panel of Trump administration picks.

SCOOP: Sean Plankey's nomination to lead CISA is seemingly over, after DHS partially terminated a Coast Guard contract with Florida-based Eastern Shipbuilding Group. Plankey had been an adviser to CG. Sen. Rick Scott became a hurdle to Plankey's confirmation. cyberscoop.com/sean-plankey...

04.12.2025 18:55 β€” πŸ‘ 3    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0

Reaction to this story over at infosec.exchange

04.12.2025 18:04 β€” πŸ‘ 9    πŸ” 4    πŸ’¬ 0    πŸ“Œ 1
Preview
Five-page draft Trump administration cyber strategy targeted for January release Trump administration plans January 2026 release of a six-part national cybersecurity strategy, focusing on deterrence, regulations, workforce, procurement, infrastructure, and emerging technologies.

NEW: @timstarks.bsky.social has details on the forthcoming cyber strategy from Trump admin: Five pages long, six key pillars, should be released some time in January: cyberscoop.com/trump-nation...

04.12.2025 14:46 β€” πŸ‘ 2    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0

I deserve worse lol

03.12.2025 20:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

i will sit in front of the trade machine and conjure up the dumbest stuff you've ever seen

03.12.2025 20:48 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I am just doing the dumbest stuff on the internet

03.12.2025 20:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Developers scramble as critical React flaw threatens major apps The open-source code library is one of the most extensively used application frameworks. Wiz found vulnerable versions in around 39% of cloud environments.

FUD sucks. The warnings around this React vuln are not FUD. Get those patch plans in motion cyberscoop.com/react-server...

03.12.2025 19:27 β€” πŸ‘ 19    πŸ” 10    πŸ’¬ 1    πŸ“Œ 1
This dumb block on Google Chrome that wants to you prompt its AI for a sloptastic answer about the website you are reading

This dumb block on Google Chrome that wants to you prompt its AI for a sloptastic answer about the website you are reading

GO AWAY

02.12.2025 19:57 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Sigh, I’ve gotten 3 predictions pitches since I wrote this post.

πŸŽ΅πŸŽ„β€Siiiimplyyy havvvvin’ a terrible time onlineeee” πŸŽ„πŸŽ΅

02.12.2025 18:49 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Yelling into the void: Please, pr people, do not send me the pitches about 2026 predictions. It provides zero value. Tell your clients that if they are interested in pushing this into the world, they always have their LinkedIn profiles.

02.12.2025 14:32 β€” πŸ‘ 12    πŸ” 3    πŸ’¬ 2    πŸ“Œ 2
Preview
Congress calls on Anthropic CEO to testify on Chinese Claude espionage campaign The House Homeland Security Committee asked Dario Amodei to answer questions about the implications of the attack and how policymakers and AI companies can respond.

The House Homeland Security Committee is calling on Anthropic CEO Dario Amodei to provide testimony on a likely-Chinese espionage campaign that used Claude cyberscoop.com/house-homela...

26.11.2025 18:36 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
New research finds that Claude breaks bad if you teach it to cheat A new paper from Anthropic found that teaching Claude how to reward hack coding tasks caused the model to become less honest in other areas.

Research from Anthropic reveals that when Claude is taught to cheat in one areaβ€”such as reward hacking in coding exercisesβ€”it becomes broadly dishonest and malicious across unrelated tasks cyberscoop.com/anthropic-cl...

25.11.2025 15:16 β€” πŸ‘ 4    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0

The reason i had such a visceral reaction to this is bc there is a canyon between the sanity of "sleep where you are comfortable" and the stupidity of "beds are a capitalist conspiracy"

24.11.2025 16:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
The slow rise of SBOMs meets the rapid advance of AI Despite progress from CISA and global regulators, SBOM adoption in the private sector remains slow as experts debate if AI-driven coding will improve or undermine software security and transparency.

As SBOMs slowly progress at the federal level and in enterprises, the rise of AI coding assistants is fueling optimisticβ€”and, some experts argue, β€œkind of insane”—claims about a future with vulnerability-free software.

Check out my latest CyberScoop piece. 1/2
cyberscoop.com/sbom-adoptio...

24.11.2025 14:49 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 1    πŸ“Œ 2
Preview
This campaign aims to tackle persistent security myths in favor of better advice Hacklore.org launches to debunk common cybersecurity myths and promote advice that actually keeps people safe online.

Cybersecurity veteran @boblord.bsky.social launched a new campaign, hacklore.org, which aims to tackle persistent security myths in favor of better advice cyberscoop.com/hacklore-org...

24.11.2025 15:04 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Saved to phone

23.11.2025 22:23 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Normally when I listen to PTFO I'm satisfied in just enjoying good work, but this one has the added benefit of being enraging down to the last second.

20.11.2025 17:21 β€” πŸ‘ 44    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0
Preview
Palo Alto Networks to acquire observability firm Chronosphere for $3.35 billion Palo Alto Networks announced Wednesday it will acquire Chronosphere, a cloud observability platform, for $3.35 billion in cash and equity.

Palo Alto rips off another $3 billy for a company the way I rip off questionable bets on DraftKings cyberscoop.com/palo-alto-ne...

19.11.2025 22:46 β€” πŸ‘ 6    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Ah @cyberwarcon.bsky.social the only conference for intel ops research authored by the terminally online

19.11.2025 14:46 β€” πŸ‘ 76    πŸ” 14    πŸ’¬ 3    πŸ“Œ 6
Preview
With each cloud outage, calls for government action grow louder Public interest groups want the feds to investigate the systemic risk from market consolidation, while tech and security experts worry about single points of failure.

Re-upping this for, uh, reasons
cyberscoop.com/with-each-cl...

18.11.2025 15:16 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

My one and only contribution to Today's Discourseℒ️: If her writing were as scarce as her shame, we'd be spared entirely.

17.11.2025 17:54 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
However, Klein also made it clear that β€œmost autonomous” is a relative term. There is plenty of evidence to indicate this hacking group devoted significant human and technical resources into the way it used Claude.

Namely, the automation detailed in Anthropic’s report performed by Claude was made possible through a frontend framework designed to orchestrate and support its operations. The framework handled tasks such as scripting, provisioning related servers, and significant backend development to ensure every step was followed correctly. Klein noted this development process was the most difficult β€” and, importantly, human-led β€” step in the operation.  

β€œThe first part that is not autonomous is building the framework, so you needed a human being to put this all together,” Klein said. β€œYou had a human operator that would put in a target, they would click a button and then use this framework that was created [ahead of time]. The hardest part of this entire system was building this framework, that’s what was human intensive.”

However, Klein also made it clear that β€œmost autonomous” is a relative term. There is plenty of evidence to indicate this hacking group devoted significant human and technical resources into the way it used Claude. Namely, the automation detailed in Anthropic’s report performed by Claude was made possible through a frontend framework designed to orchestrate and support its operations. The framework handled tasks such as scripting, provisioning related servers, and significant backend development to ensure every step was followed correctly. Klein noted this development process was the most difficult β€” and, importantly, human-led β€” step in the operation. β€œThe first part that is not autonomous is building the framework, so you needed a human being to put this all together,” Klein said. β€œYou had a human operator that would put in a target, they would click a button and then use this framework that was created [ahead of time]. The hardest part of this entire system was building this framework, that’s what was human intensive.”

NEW: @derekbjohnson.bsky.social spoke with @anthropic.com's threat intel team about Thursday's report. Lots in there, but one key takeaway: Despite being labeled as 'autonomous,' there was a tremendous amount of human effort needed to pull off the attacks. cyberscoop.com/anthropic-ai...

14.11.2025 19:26 β€” πŸ‘ 19    πŸ” 8    πŸ’¬ 0    πŸ“Œ 5
Preview
Google, researchers see signs that Lighthouse text scammers disrupted after lawsuit The phishing kit Lighthouse, which has aided text scams like those soliciting victims to pay unpaid road tolls, appears to have been hampered shortly after Google filed a lawsuit aimed at its creators.

New from @timstarks.bsky.social: The phishing kit Lighthouse, which has aided text scams like those soliciting victims to pay unpaid road tolls, appears to have been disrupted after Google filed a civil lawsuit earlier this week: cyberscoop.com/lighthouse-t...

14.11.2025 16:03 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Eh, i think there is novelty in how the MCP servers were used. For all the FUD about how AI was going to be used by adversaries, this seems real. However, what i do hope to address is the human-in-the-loop part. I believe the idea that "AI magically did all this work!" is wrong

13.11.2025 20:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Ok the full tech report answered some of my questions but we will have more before the week closes on cyberscoop dot com assets.anthropic.com/m/ec212e6566...

13.11.2025 20:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

i think that assumption gives a lot of leeway to the AI working correctly (also not among my questions i have someone bothering Anthropic about!)

13.11.2025 18:33 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

this hits upon, like, 5 of my questions

13.11.2025 18:31 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I have, like, 30 questions here and, like, 28 of them have nothing to do with direct attack

13.11.2025 18:15 β€” πŸ‘ 17    πŸ” 1    πŸ’¬ 3    πŸ“Œ 0

@gregotto is following 20 prominent accounts