Danny Moore's Avatar

Danny Moore

@moore.bsky.social

Cyber-warfare | PhD from KCL | Author of 'Offensive Cyber Operations' | Security @ Meta

6,332 Followers  |  281 Following  |  246 Posts  |  Joined: 16.05.2023  |  1.7127

Latest posts by moore.bsky.social on Bluesky

One of our biggest issues as a cybersecurity community and industry is that we inflicted dozens of partly overlapping cryptonyms on the world and just expect them to deal with it because we can't.

23.06.2025 10:28 β€” πŸ‘ 7    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Still consistently the best cyber-related podcast out there

23.06.2025 08:02 β€” πŸ‘ 15    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

כנראה Χ’Χ“Χ™Χ™ΧŸ Χ©Χ•Χ§ ΧͺΧ¨ΧžΧ™ Χ›Χͺוצאה ΧžΧ—Χ™ΧžΧ•Χ ΧžΧ”Χ™Χ¨ גל אינדוקציה

22.06.2025 10:43 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Considering that one of Israel's overt goals for the war is to destabilize the Iranian government, a nation-wide shutdown of public internet access plays well into Israel's hands.

And it may not even stop further attacks.

21.06.2025 09:12 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Predatory Sparrow has dumped the Nobitex crytpo platform source code on Telegram

They previously stole $90mil worth of assets in a hack yesterday

t.me/gonjeshkdara...

19.06.2025 12:00 β€” πŸ‘ 8    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

My hot take is that it isn't a lack of strategy, Israel has many viable, ambitious strategies.

It's a constant failure of political will, unity, and patience to enact a strategy.

13.06.2025 19:32 β€” πŸ‘ 25    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Interesting! In my book, Offensive Cyber Operations, I talk a lot about the convergence of tactical offensive cyber and electronic warfare.

The resources, approach and desired outcomes are deeply connected.

The UK's move is in line with trends seen elsewhere. Will dive more into it all later.

29.05.2025 07:49 β€” πŸ‘ 15    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

You could get away with a lot more back then, especially considering that the orgs/people who were targeted had next to nothing for endpoint and network security.

26.05.2025 11:30 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The most interesting bit here is that the best Western gov cyber outfits overhauled their operational approach after the mid-10s to focus more on avoiding detection.

The era of the "factory ops" was too risky with the rise of threat intel.

Harder to reliably spot 2025's Regin, Careto, Flame, etc

26.05.2025 07:55 β€” πŸ‘ 21    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0

"the technical team's analysis indicates that the attacker's methods and related technical proficiency were relatively low-level."

Nothing in the article to explain what makes this "cyber warfare".

20.05.2025 14:01 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

If you’ve been laid off from a cyber intel position, please reach out if you’d like to come to @sleuthcon.bsky.social.

20.05.2025 13:18 β€” πŸ‘ 69    πŸ” 47    πŸ’¬ 3    πŸ“Œ 2
Preview
SAP cyberattack widens, drawing Salt Typhoon and Volt Typhoon comparisons Hundreds of victims are surfacing across the world from zero-day cyberattacks on Europe’s biggest software manufacturer and company.

NEW: Hundreds of victims are surfacing across the world from zero-day cyberattacks on SAP, in a campaign that one leading cyber expert is comparing to the vast Chinese government-linked Salt Typhoon and Volt Typhoon breaches. cyberscoop.com/sap-cyberatt...

15.05.2025 17:31 β€” πŸ‘ 11    πŸ” 9    πŸ’¬ 0    πŸ“Œ 1
Post image Post image Post image Post image

Drama over at X/xAI.

Whatever you ask Grok, it pivots to β€œwhite genocide” in South Africa.

The last panel is what Grok claims was a β€œverbatim” system prompt that caused the behavior. Jury out.

It’s now fixed but they haven’t yet bothered explaining.

This, not those AGI fantastical scenarios.

15.05.2025 18:24 β€” πŸ‘ 395    πŸ” 110    πŸ’¬ 25    πŸ“Œ 16
Preview
The Signal Clone the Trump Admin Uses Was Hacked TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked.

New from 404 Media: the Signal clone the Trump administration uses was just hacked. TeleMessage makes a modified version of Signal that archives messages for government agencies, Waltz used it. A hacker got some users' messages, group chats. Hugely significant breach www.404media.co/the-signal-c...

04.05.2025 22:01 β€” πŸ‘ 6115    πŸ” 2809    πŸ’¬ 160    πŸ“Œ 535

Knowing Betz, he has been on a path leading to this for many years.

23.04.2025 11:25 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The literal birth of my firstborn child was less anxiety inducing than a full week of driving and parking in Tel Aviv.

15.04.2025 20:17 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

New tech class, new vulnerability class

13.04.2025 05:20 β€” πŸ‘ 9    πŸ” 1    πŸ’¬ 2    πŸ“Œ 0

THREAD: When @thekrebscycle.bsky.social and his workplace, @sentinelone.com, were singled out by Donald Trump on Wednesday, I thought it was an opportunity to weigh the cybersecurity industry's rhetoric against their real world actions.

11.04.2025 16:55 β€” πŸ‘ 132    πŸ” 73    πŸ’¬ 6    πŸ“Œ 14

Cybersecurity is built on trust, I can only imagine how CISA staff must be feeling.

11.04.2025 08:32 β€” πŸ‘ 10    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸ‘€ China reportedly acknowledged to outgoing Biden officials in December that it was responsible for the Volt Typhoon critical infrastructure intrusions, linking them to "increasing U.S. policy support for Taiwan." www.wsj.com/politics/nat...

10.04.2025 19:30 β€” πŸ‘ 54    πŸ” 21    πŸ’¬ 2    πŸ“Œ 3

I was there. It was meant literally.

β€œJD Work β€” now on the US NSC β€” shocked some by warning that the US would take lethal action against malicious actors in commercial cyber operations.
Participants who heard [it said] they were unsure if it was meant literally or figuratively”

09.04.2025 20:46 β€” πŸ‘ 83    πŸ” 30    πŸ’¬ 6    πŸ“Œ 3
Post image

The Swiss population doesn’t want to buy the F35 anymore, given everything that’s going on in Trump’s US.
In 2020, a 50,1% majority had voted for the acquisition in a referendum.

www.watson.ch/schweiz/wirt...

27.03.2025 15:07 β€” πŸ‘ 285    πŸ” 74    πŸ’¬ 13    πŸ“Œ 10

Why is the headline on all X outage stories about Musk blaming Ukraine for the DDoS? Why aren't media outlets putting the emphasis on the security lapse that allowed script kiddies (or whoever) to launch the attack against X as well as the lack of any evidence that the traffic came from Ukraine IPs?

11.03.2025 23:58 β€” πŸ‘ 82    πŸ” 28    πŸ’¬ 11    πŸ“Œ 2

DDoS attacks frequently use compromised or otherwise co-opted IP addresses. The global distribution helps avoid geofencing defenses.

Public high-confidence attribution takes time and effort. So take any quickfire claims with healthy skepticism.

10.03.2025 21:29 β€” πŸ‘ 8    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

ΧžΧ‘Χ›Χ™Χ ΧœΧ’ΧžΧ¨Χ™, Χ”ΧΧžΧ™Χ¨Χ•Χͺ Χ”ΧΧœΧ• מΧͺΧ’ΧœΧžΧ•Χͺ ΧžΧ”ΧžΧ’Χ‘ΧœΧ•Χͺ Χ”ΧΧ™Χ Χ”Χ¨Χ Χ˜Χ™Χ•Χͺ של LLMs. Χ™Χ© Χ”Χ‘Χ“Χœ Χ‘Χ™ΧŸ Χ’Χ™Χ‘Χ•Χ“ Χ•Χ Χ™Χ‘Χ•Χ— ΧͺΧ•Χ›ΧŸ ΧžΧ•Χ¨Χ›Χ‘ ΧœΧ‘Χ™ΧŸ Χ—Χ©Χ™Χ‘Χ” Χ™Χ•Χ¦Χ¨Χͺ

07.03.2025 10:00 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Great coverage by @kimzetter.bsky.social. In this ecosystem we need to be doubly suspicious of major claims even if published by reputable sources.

Considering the denials it's hard to pin down the truth. That said if things continue we may still see a gradual derisking of Russia by the US.

05.03.2025 10:01 β€” πŸ‘ 7    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

That's genuinely lovely but if we are to establish soft power diplomatic momentum that isn't dependent on the US establishment maybe do it on a network that isn't Elon's X.

01.03.2025 10:32 β€” πŸ‘ 18    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0

Madness

28.02.2025 20:10 β€” πŸ‘ 16    πŸ” 5    πŸ’¬ 0    πŸ“Œ 1
Post image

New from 404 Media: anyone can push updates to the Doge.gov site. Two sources independently found the issue, one made their own decision to deface the site. "THESE 'EXPERTS' LEFT THEIR DATABASE OPEN."

www.404media.co/anyone-can-p...

14.02.2025 07:06 β€” πŸ‘ 1216    πŸ” 434    πŸ’¬ 39    πŸ“Œ 85

Yep

10.02.2025 12:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@moore is following 19 prominent accounts