Red team: He went full 007 spy mode
#redteaming #redteam #pentesting #cybersecurity #hacking
@matt.volkis.au
Managing Director of Volkis (@volkis.au), cyber security guy.
Red team: He went full 007 spy mode
#redteaming #redteam #pentesting #cybersecurity #hacking
This one resonates with me. We started a company and realised weโre great at delivering services but weโre not great at sales and not great at marketing. Luckily weโve now got people who are great at those things!
01.05.2025 04:21 โ ๐ 4 ๐ 0 ๐ฌ 1 ๐ 0New Volkis shirts!
01.05.2025 04:19 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0I have cancelled our planned trip to the RSA Conference in San Francisco later this month. @metlstorm.risky.biz and I were headed over to record some live shows and see everyone. Unfortunately I have received advice that crossing the border into the United States right now would be a bad idea.
11.04.2025 00:33 โ ๐ 157 ๐ 30 ๐ฌ 16 ๐ 6I saw that the super attacks resulted in $500k of unauthorised payments and my thought was "huh, that's not that bad". Shows the state of cyber security in 2025.
07.04.2025 06:23 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0This is a wild read! The top cabinet members of USA were discussing war plans in a Signal chat. That's unsettling enough considering it's out of band comms. Then they accidentally added a journalist to the chat.
24.03.2025 22:53 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Going to be at @crikeycon.bsky.social tomorrow. Hope to see you all there!
20.03.2025 23:16 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Looking forward to seeing you all next week!
13.03.2025 00:23 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Thank you www.volkis.com.au for your ongoing support of CrikeyCon, coming in with Silver sponsorship again. We love our long term supporters, and Volkis has been a wonderful friend and supporter of the Con. Welcome back!
12.03.2025 07:57 โ ๐ 7 ๐ 3 ๐ฌ 1 ๐ 0I'm going to guess LLMs are going to result in a whole bunch of super weird defamation cases. Don't just go blindly trusting Chat GPT!
13.03.2025 00:14 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0In a world full of bad news we must always find happiness in the good news!
07.03.2025 23:08 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Thatโs a wild read! That kind of thing has absolutely no place in any modern democracy!
07.03.2025 09:15 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0A few years, a decade at most. Low earth orbits degrade relatively quickly.
10.02.2025 21:30 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Oh man, I have so many stories about that "startup". The founder Marshall Webb spent a year harassing me because I posted a research paper on the Mirai botnet (he considered himself to be the sole authority). It later turned out his knowledge came from him personally hosting their infrastructure 1/5
07.02.2025 05:17 โ ๐ 1644 ๐ 531 ๐ฌ 23 ๐ 32The results are in! We're proud to announce the Top 10 Web Hacking Techniques of 2024! portswigger.net/research/top...
04.02.2025 15:02 โ ๐ 66 ๐ 36 ๐ฌ 2 ๐ 5Is this the start of a trend towards trojaned CPUs in nation state hacking?
04.02.2025 21:58 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0watchTowr Labs reregistered lapsed S3 buckets and found that they were still being used for things like updates. Long read but worth going through!
04.02.2025 21:34 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0I'd be keen for Civilization VII but $120 is way too much!
04.02.2025 03:35 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0I'm putting together a bit of a list of Australian Infosec people on Bluesky here: bsky.app/profile/did:... If anyone wants to be added or knows people who should be added let me know!
04.02.2025 01:13 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0It's fixed now. For anyone watching, the solution was to go to the homepage (NOT the settings page), do a hard reload (i.e. shift F5 or hold shift and press reload) and then redo the domain verification.
03.02.2025 23:30 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0I tried to get the handle @matt.volkis.au but it hasn't gone all that well! How come it worked for @skorov.volkis.au but not me?
That said I'm kind of liking the hackery vibe of "Invalid Handle"!
I feel like itโs just really hard to differentiate a DDoS from just a huge amount of people using the app.
29.01.2025 11:12 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0They donโt even seem to be saying that DeepSeek is stealing IP. Iโm not even sure they violated ToS. Theyโre just saying that they used the OpenAI APIs as part of the training process.
29.01.2025 10:00 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0This is a great blog post with some brilliant old school web hacking. It raises the question though: do we really want car companies to be able to remotely track and unlock our cars?
23.01.2025 21:01 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Yep I deactivated my account yesterday. I had hardly used it lately but nowadays I just donโt want to be associated with it at all, even if itโs just an unused account.
23.01.2025 20:49 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Listening to it now. The CSRB being gutted is such a pity. I was holding it up as a "see this is an example of getting better as an industry. It's a sign of maturity!" Now it's likely just gone. Probably won't even see a Salt Typhoon report.
22.01.2025 05:01 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Iโve always thought that there should be active subscription renewals like you should have to press a button that says โyes I want to renew this for the next yearโ www.smh.com.au/politics/fed...
04.01.2025 09:12 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0big wheel keep on turnin' www.wired.com/story/us-tre...
31.12.2024 03:46 โ ๐ 15 ๐ 5 ๐ฌ 1 ๐ 0Another target of Salt Typhoon, this time itโs the US Treasury. Doesnโt seem like they issued themselves bonds but they probably got some incredible intelligence. www.abc.net.au/news/2024-12...
31.12.2024 01:27 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Good luck! That must have taken some skill to achieve (and a lot of work to get out of!)
30.12.2024 07:04 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0