Matt Strahan's Avatar

Matt Strahan

@matt.volkis.au

Managing Director of Volkis (@volkis.au), cyber security guy.

123 Followers  |  306 Following  |  45 Posts  |  Joined: 26.06.2023  |  2.1765

Latest posts by matt.volkis.au on Bluesky

Video thumbnail

Red team: He went full 007 spy mode

#redteaming #redteam #pentesting #cybersecurity #hacking

02.05.2025 01:03 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This one resonates with me. We started a company and realised weโ€™re great at delivering services but weโ€™re not great at sales and not great at marketing. Luckily weโ€™ve now got people who are great at those things!

01.05.2025 04:21 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

New Volkis shirts!

01.05.2025 04:19 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I have cancelled our planned trip to the RSA Conference in San Francisco later this month. @metlstorm.risky.biz and I were headed over to record some live shows and see everyone. Unfortunately I have received advice that crossing the border into the United States right now would be a bad idea.

11.04.2025 00:33 โ€” ๐Ÿ‘ 157    ๐Ÿ” 30    ๐Ÿ’ฌ 16    ๐Ÿ“Œ 6

I saw that the super attacks resulted in $500k of unauthorised payments and my thought was "huh, that's not that bad". Shows the state of cyber security in 2025.

07.04.2025 06:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Trump Administration Accidentally Texted Me Its War Plans U.S. national-security leaders included me in a group chat about upcoming military strikes in Yemen. I didnโ€™t think it could be real. Then the bombs started falling.

This is a wild read! The top cabinet members of USA were discussing war plans in a Signal chat. That's unsettling enough considering it's out of band comms. Then they accidentally added a journalist to the chat.

24.03.2025 22:53 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Going to be at @crikeycon.bsky.social tomorrow. Hope to see you all there!

20.03.2025 23:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Looking forward to seeing you all next week!

13.03.2025 00:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Thank you www.volkis.com.au for your ongoing support of CrikeyCon, coming in with Silver sponsorship again. We love our long term supporters, and Volkis has been a wonderful friend and supporter of the Con. Welcome back!

12.03.2025 07:57 โ€” ๐Ÿ‘ 7    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I'm going to guess LLMs are going to result in a whole bunch of super weird defamation cases. Don't just go blindly trusting Chat GPT!

13.03.2025 00:14 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

In a world full of bad news we must always find happiness in the good news!

07.03.2025 23:08 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Thatโ€™s a wild read! That kind of thing has absolutely no place in any modern democracy!

07.03.2025 09:15 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

A few years, a decade at most. Low earth orbits degrade relatively quickly.

10.02.2025 21:30 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Oh man, I have so many stories about that "startup". The founder Marshall Webb spent a year harassing me because I posted a research paper on the Mirai botnet (he considered himself to be the sole authority). It later turned out his knowledge came from him personally hosting their infrastructure 1/5

07.02.2025 05:17 โ€” ๐Ÿ‘ 1644    ๐Ÿ” 531    ๐Ÿ’ฌ 23    ๐Ÿ“Œ 32
Preview
Top 10 web hacking techniques of 2024 Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

The results are in! We're proud to announce the Top 10 Web Hacking Techniques of 2024! portswigger.net/research/top...

04.02.2025 15:02 โ€” ๐Ÿ‘ 66    ๐Ÿ” 36    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 5

Is this the start of a trend towards trojaned CPUs in nation state hacking?

04.02.2025 21:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
8 Million Requests Later, We Made The SolarWinds Supply Chain Attack Look Amateur Surprise surprise, we've done it again. We've demonstrated an ability to compromise significantly sensitive networks, including governments, militaries, space agencies, cyber security companies, suppl...

watchTowr Labs reregistered lapsed S3 buckets and found that they were still being used for things like updates. Long read but worth going through!

04.02.2025 21:34 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Pre-purchase Sid Meier's Civilization VII on Steam The award-winning strategy game franchise returns with a revolutionary new chapter. Sid Meier's Civilizationยฎ VII empowers you to build the greatest empire the world has ever known!

I'd be keen for Civilization VII but $120 is way too much!

04.02.2025 03:35 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I'm putting together a bit of a list of Australian Infosec people on Bluesky here: bsky.app/profile/did:... If anyone wants to be added or knows people who should be added let me know!

04.02.2025 01:13 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

It's fixed now. For anyone watching, the solution was to go to the homepage (NOT the settings page), do a hard reload (i.e. shift F5 or hold shift and press reload) and then redo the domain verification.

03.02.2025 23:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I tried to get the handle @matt.volkis.au but it hasn't gone all that well! How come it worked for @skorov.volkis.au but not me?

That said I'm kind of liking the hackery vibe of "Invalid Handle"!

03.02.2025 23:19 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

I feel like itโ€™s just really hard to differentiate a DDoS from just a huge amount of people using the app.

29.01.2025 11:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

They donโ€™t even seem to be saying that DeepSeek is stealing IP. Iโ€™m not even sure they violated ToS. Theyโ€™re just saying that they used the OpenAI APIs as part of the training process.

29.01.2025 10:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This is a great blog post with some brilliant old school web hacking. It raises the question though: do we really want car companies to be able to remotely track and unlock our cars?

23.01.2025 21:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Yep I deactivated my account yesterday. I had hardly used it lately but nowadays I just donโ€™t want to be associated with it at all, even if itโ€™s just an unused account.

23.01.2025 20:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Listening to it now. The CSRB being gutted is such a pity. I was holding it up as a "see this is an example of getting better as an industry. It's a sign of maturity!" Now it's likely just gone. Probably won't even see a Salt Typhoon report.

22.01.2025 05:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Started a new year health kick? Beware the โ€˜subscription trapโ€™ Gyms, streaming services and meal-kit providers are being targeted by proposed new laws that will crack down on unfair business practices.

Iโ€™ve always thought that there should be active subscription renewals like you should have to press a button that says โ€œyes I want to renew this for the next yearโ€ www.smh.com.au/politics/fed...

04.01.2025 09:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
US Treasury Department Admits It Got Hacked by China Treasury says hackers accessed โ€œcertain unclassified documentsโ€ in a โ€œmajorโ€ breach, but experts believe the attackโ€™s impacts could prove to be more significant as new details emerge.

big wheel keep on turnin' www.wired.com/story/us-tre...

31.12.2024 03:46 โ€” ๐Ÿ‘ 15    ๐Ÿ” 5    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
US Treasury says Chinese hackers led a 'major cybersecurity' breach The revelation comes as US officials continue to grapple with the fallout of a massive Chinese cyber espionage campaign known as Salt Typhoon.

Another target of Salt Typhoon, this time itโ€™s the US Treasury. Doesnโ€™t seem like they issued themselves bonds but they probably got some incredible intelligence. www.abc.net.au/news/2024-12...

31.12.2024 01:27 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Good luck! That must have taken some skill to achieve (and a lot of work to get out of!)

30.12.2024 07:04 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@matt.volkis.au is following 20 prominent accounts