Matt Muller's Avatar

Matt Muller

@matt.buildingsecops.com

Cybersecurity tinkerer by day, wine and cheese tinkerer by night. Security @ Tines | ex-Coinbase Security, Material Security

106 Followers  |  212 Following  |  72 Posts  |  Joined: 11.11.2024  |  2.1055

Latest posts by matt.buildingsecops.com on Bluesky

Preview
Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home For likely the first time ever, security researchers have shown how AI can be hacked to create real world havoc, allowing them to turn off lights, open smart shutters, and more.

Examples like this are why it’s particularly infuriating that I can’t fully disable all AI features in Google Workspace. Different threat models deserve more granular controls. www.wired.com/story/google...

08.08.2025 16:59 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
The Mothership Vortex: An Investigation Into the Firm at the Heart of the Democratic Spam Machine How a single consulting firm extracted $282 million from a network of spam PACs while delivering just $11 million to actual campaigns.

The annoying spam texts destroying the Democratic brand:

$678M raised through those spam tactics

$282M to one consulting firm: Mothership Strategies.

$11M to actual campaigns (1.6%)

The party isn’t just treating donors like marksβ€”it’s being fleeced itself yet continues to back Mothership.

03.08.2025 17:02 β€” πŸ‘ 7927    πŸ” 3071    πŸ’¬ 408    πŸ“Œ 683
Preview
Staff Software Engineer | Careers at Tines We are hiring a Staff Software Engineer in Boston Hybrid; United States - East. Learn more about the role and our mission to improve the lives of security teams.

We’re hiring at Tines! I’d take a look at tines.com/careers/jobs...

30.07.2025 16:21 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I live in the middle of San Francisco. I walk and take public transportation everywhere daily, feeling perfectly safe. And every time someone starts ranting about how scary and dangerous cities are, I nod and smile because I do not want them to come here.

29.07.2025 06:18 β€” πŸ‘ 862    πŸ” 99    πŸ’¬ 37    πŸ“Œ 10

This is a critical read for anyone who might engage with these remote workers.

Paywall-free: archive.ph/CZOvv

26.07.2025 12:58 β€” πŸ‘ 4    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0
Preview
Three SOC Paradoxes To Fix in 2025 Reflections and takeaways from the 2025 SANS SOC Survey.

My hot take of the day: we’re not gonna resolve SOC burnout any time soon unless we fix these three underlying issues in how we run SOC teams. buildingsecops.com/posts/three-...

22.07.2025 00:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I feel like @quinnypig.com would appreciate the staff sending me back and forth between two different security lines to get into the AWS Summit. No metaphors here at all.

16.07.2025 12:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I’m not a cryptographer, but to the best of my (reasonably extensive layperson) knowledge this is possibly the best FIPS 140-3 implementation out there in terms of minimizing negative security impacts when complying with some of the more boneheaded parts of FIPS.

16.07.2025 00:47 β€” πŸ‘ 84    πŸ” 18    πŸ’¬ 2    πŸ“Œ 2
A post on infosec.exchange from Viss that reads

"stop using twitter. 

there are no more excuses.

get your news and your cti elsewhere. 
the only reason the news and cti vendors stay on twitter is because you, the audience, are still there.

so leave. 
take your clicks and your eyeballs to another platform. 

it will make them leave.
dont wait for the critical mass to form

BE THE CRITICAL MASS

your body is a vote.
choose wisely."

A post on infosec.exchange from Viss that reads "stop using twitter. there are no more excuses. get your news and your cti elsewhere. the only reason the news and cti vendors stay on twitter is because you, the audience, are still there. so leave. take your clicks and your eyeballs to another platform. it will make them leave. dont wait for the critical mass to form BE THE CRITICAL MASS your body is a vote. choose wisely."

10.07.2025 12:11 β€” πŸ‘ 21    πŸ” 5    πŸ’¬ 1    πŸ“Œ 1
Preview
Show Us Your Face The federal government should prohibit the wearing of masks by ICE agents and require them to properly identify themselves.

β€œDescending on a person in public, laying hands on them, and taking them to a distant prison is a naked expression of state power. For it to be tolerated in a democracy, it cannot be done by shadowy, masked agents,” Brandon del Pozo argues:

07.07.2025 11:56 β€” πŸ‘ 607    πŸ” 216    πŸ’¬ 32    πŸ“Œ 14

I empathize with the sunk costs, but I think they’re underestimating the hit to attendance. I’ll be interested to see what the 2027 conference landscape looks like as well.

02.07.2025 12:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I was at an international cybersecurity conference recently and the organizers asked if I had any feedback. I said β€œyes, for attendee safety please don’t host it in the US next year.” Their response was that they’ve already signed the venue contract, so πŸ€·β€β™‚οΈ

02.07.2025 12:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Spying on embassy visitors

Spying on embassy visitors

A criminal cartel hired a hacker to identify "people of interest" (including the FBI's Assistant Legal Attache), going in and and out of the US embassy in Mexico city, and then spy on their calls, and their location.

It gets worse..

29.06.2025 20:12 β€” πŸ‘ 23    πŸ” 14    πŸ’¬ 1    πŸ“Œ 2

I’ve been posting a lot lately about topics that aren’t obviously related to cybersecurity or SecOps. Fundamentally I believe security is about protecting people, and sometimes protecting people extends beyond the digital realm. Food insecurity matters more than device insecurity.

26.06.2025 18:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I live in an NYC neighborhood with a Whole Foods and multiple local grocers. All of them are always packed, because outside of our few blocks, it’s a food desert. If NYC opened a grocery store in one of those food deserts, it would be complementary to where the free market has profitable stores.

26.06.2025 18:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Image of JD Vance bald and with a bloated face.

Image of JD Vance bald and with a bloated face.

Gotta post this again.

After handing over his password, Mads was told he would not be allowed to go through with his planned vacation after two images were not to the officers' liking.
www.dublinlive.ie/news/world-n...

25.06.2025 09:56 β€” πŸ‘ 5    πŸ” 3    πŸ’¬ 0    πŸ“Œ 2

brutal thread

22.06.2025 21:35 β€” πŸ‘ 804    πŸ” 240    πŸ’¬ 38    πŸ“Œ 2
Preview
ICE believes it will never face accountability again The Trump administration is letting an unaccountable secret police form at the heart of our democracy.

ICE in just a few weeks has transformed itself into the closest thing that the US has ever had to a β€œsecret police,” with more seemingly culturally in common with the Klan nightriders of Reconstruction than their federal agency brethren like the FBI or ATF. www.doomsdayscenario.co/p/ice-believ...

20.06.2025 18:15 β€” πŸ‘ 2166    πŸ” 758    πŸ’¬ 95    πŸ“Œ 52
Video thumbnail

New Yorkers scream out each officer’s lawsuits against them for excessive force and more upon their city, right to their faces while protesting.

13.06.2025 18:00 β€” πŸ‘ 35245    πŸ” 10410    πŸ’¬ 869    πŸ“Œ 1095
Image of Senator Alex Padilla being physically dragged away by the DHS secretary's security.

Image of Senator Alex Padilla being physically dragged away by the DHS secretary's security.

This is what Trump's government thugs are willing to do in broad daylight, to a US Senator, with cameras on.

They are sending the message that anyone who disagrees with Trump isn't safe in America.

This is authoritarianism.

12.06.2025 19:32 β€” πŸ‘ 1823    πŸ” 656    πŸ’¬ 123    πŸ“Œ 74
A text from a spam phone number that reads β€œwhat’s your chief concern at the moment?”

A text from a spam phone number that reads β€œwhat’s your chief concern at the moment?”

Me: β€œAs a cybersecurity person, there’s no pig butchering lure I’d ever get sucked in by”

The pig butchers:

02.06.2025 19:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
InfoSec Opinion Column #3 (June 2, 2025) Consider it the Axios of what matters in cybersecurity. Or the Hacker News comments section, depending on the day. All hand-curated, no AI involved. This week: CISA Guidance for SIEM and SOAR Implemen...

Turns out that self-hosted Ghost isn’t great about actually sending scheduled posts… but now we’re back up on Ghost Pro with regularly scheduled content! This week: CISA’s (outdated) SIEM and SOAR implementation guidance buildingsecops.com/posts/infose...

02.06.2025 17:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I am always impressed with @thinkstcanary.canary.tools both as a company and as a security solution.

@thinkstcanary.canary.tools is a must have tool for all defenders

29.05.2025 15:42 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

β€œIncidents are a feedback loop into the business’s risk appetite. They’ll tell you if you’re making the right risk bets.”

A brand new episode of The Future of Security Operations is here! This week, Thomas chats to Tines’ Field CISO @matt.buildingsecops.com

πŸ‘‰ www.tines.com/blog/tines-m...

28.05.2025 12:27 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Whoa, not the pairing I would necessarily have expected, but hopefully a great outcome for all my Red Canary friends!

27.05.2025 20:58 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

Tines' Field CISO @matt.buildingsecops.com joined host @tom.risky.biz on the Risky Business podcast to discuss CISA's Secure by Design pledge - and why it's too early to declare it a success or a failure.

Listen to the full conversation: risky.biz/RBNEWSSI75/

13.05.2025 10:39 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Congestion pricing has improved life in New York City by: reducing cars on the street, speeding traffic (especially at peak hours), speeding buses and making them more reliable, expanding transit ridership, reducing car crashes, reducing noise complaints, and increasing the number of visitors.

Congestion pricing has improved life in New York City by: reducing cars on the street, speeding traffic (especially at peak hours), speeding buses and making them more reliable, expanding transit ridership, reducing car crashes, reducing noise complaints, and increasing the number of visitors.

Fire response times fell in the NYC congestion zone, even as they increased in the rest of the city.

Fire response times fell in the NYC congestion zone, even as they increased in the rest of the city.

Car crashes with injuries fell citywide, but they fell especially dramatically in the congestion pricing zone from 2024 to 2025

Car crashes with injuries fell citywide, but they fell especially dramatically in the congestion pricing zone from 2024 to 2025

Local buses have sped up dramatically in the congestion pricing zone.

Local buses have sped up dramatically in the congestion pricing zone.

NYC’s congestion pricing is a policy miracle: Less traffic, less noise, faster transit, more business sales, more transit revenue. And it hasn’t produced the negative effects outside the cordon zone we were afraid of.

www.nytimes.com/interactive/...

12.05.2025 12:10 β€” πŸ‘ 4437    πŸ” 1117    πŸ’¬ 66    πŸ“Œ 108

A lot of people say they want the government to run like a business, but they never say whether they want it to run like Costco or Enron.

25.04.2025 12:31 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

For no reason at all, I keep thinking about how @sentinelone.com has a great team and a great product, and how delighted I’d be to work with them again. Much love to all my friends there.

11.04.2025 12:44 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

saw a very condescending post about people using password manager notebooks. i'd rather have an old guy who doesn't go out use one of those books than nothing at all. if your house is broken into you have more pressing concerns than jimmy the cat-burglar making a purchase on ebay

11.04.2025 12:22 β€” πŸ‘ 77    πŸ” 8    πŸ’¬ 5    πŸ“Œ 0

@matt.buildingsecops.com is following 20 prominent accounts