Matteo / @[email protected]

33.2K posts

Matteo / @geminiimatt@infosec.exchange banner
Matteo / @geminiimatt@infosec.exchange

@geminiimatt

hacker. Founder: @cryptoharlem Safety &security expert. Public Interest Technologist. awarded by: @Newsweek @Vice @Cyberscoop @EFF +more

GPG: 0x0b8770aa07046231 Katılım Nisan 2007
6.5K Takip Edilen10.3K Takipçiler
Matteo / @[email protected] retweetledi
TechCrunch
TechCrunch@TechCrunch·
Hundreds of millions of actively-used iPhones and iPads are now at risk of being hacked through exploit tools that have been made available on Github. For anyone not using the latest iOS 26 software, it's time to update ASAP. “This is bad. They are way too easy to repurpose. I don’t think that can be contained anymore. So we need to expect criminals and others to start deploying this," one security expert at @IsMyPhoneHacked told us. spr.ly/6019B6wNcx
English
17
110
335
57.7K
Matteo / @[email protected] retweetledi
Lukasz Olejnik
Lukasz Olejnik@lukOlejnik·
Google has identified an iOS exploit kit named Coruna. 5 full exploit chains, 23 vulnerabilities, documentation in native English, modular architecture. Full professionalism. It must have cost millions of dollars. Who built it? Google doesn’t say, but the evidence points to US government tools. The kit also contains components previously used in a cyber operation that Russia attributed to the NSA. Coruna traveled. First, an anonymous “company client”, then used by a Russian cyber espionage group, which hid the code on Ukrainian websites inside a visitor-counter script, delivering it only to selected users from a specific geolocation. Later a financially motivated actor “operating from China” deployed it (infecting over 42,000 devices). The malware added to the ready-made kit was lower quality than the original suggesting the tools were acquired and modified by someone else. One US government subcontractor, Peter Williams, just received a 7-year prison sentence for selling tools to Russian broker Operation Zero. The US government spent millions on a tool that now steals cryptocurrency. A good return on investment, just not for themselves. One more detail: Coruna did not attack devices with Lockdown Mode enabled.​​​​​​​​​​​​​​​​ cloud.google.com/blog/topics/th…
English
10
220
812
82K
Matteo / @geminiimatt@infosec.exchange
Matteo / @[email protected]@geminiimatt·
I am quoted in this article that I recommend anyone read. Always useful advice . Prepare & prxatice before you need it. Get ready, stay ready.
Andy Greenberg (@agreenberg at the other places)@a_greenberg

I've never had so many people writing to me to ask about encrypted/secure/private tools for comms, collaboration, and organizing. So @lilyhnewman and I talked to experts and assembled this: the Wired guide to organizing in an age of surveillance. wired.com/story/how-to-o…

English
0
0
1
316
Matteo / @[email protected] retweetledi
Runa Sandvik
Runa Sandvik@runasand·
Two years ago, a Norwegian researcher skeptical that pulsed-energy weapons could do damage to human brains — aka “Havana syndrome” — built a device and tested it on himself. It didn’t go well. Someone from FFI, perhaps? washingtonpost.com/national-secur…
English
22
24
82
7.7K
Matteo / @[email protected] retweetledi
Runa Sandvik
Runa Sandvik@runasand·
Apple’s new iPhone security feature limits cell networks from collecting precise location data, but appears to have very limited support in the U.S. at the moment. Here’s to hoping all the big carriers get on board too. techcrunch.com/2026/01/29/app…
Runa Sandvik tweet media
English
2
17
61
7.3K
Matteo / @[email protected] retweetledi
Runa Sandvik
Runa Sandvik@runasand·
New court record from the FBI details the state of the devices seized from Washington Post reporter Hannah Natanson: phone was on w/Lockdown Mode; personal laptop was off; work laptop was on w/Touch ID; several Signal chats used disappearing messages. storage.courtlistener.com/recap/gov.usco…
Runa Sandvik tweet mediaRuna Sandvik tweet mediaRuna Sandvik tweet mediaRuna Sandvik tweet media
English
29
200
1K
1M
Matteo / @[email protected] retweetledi
Runa Sandvik
Runa Sandvik@runasand·
I helped design and implement the secure tip line at the New York Times in 2016. Who can access what, when, where, and how is just as important as the specific apps, tools, and settings that are used. nytimes.com/2017/03/02/ins…
English
2
13
88
11.1K
Matteo / @[email protected] retweetledi
@timnitGebru (@dair-community.social/bsky.social)
Again, wildly different things, tasks, techniques, subspecialties being lumped into "AI" and being conflated with each other, doesn't help. Different types of models vs techniques to train them vs tasks they're supposed to accomplish, all bucketed under "AI", is misleading. 🧵
English
6
39
102
7.6K
Matteo / @geminiimatt@infosec.exchange
Matteo / @[email protected]@geminiimatt·
@timnitGebru DOH! 🤦🏿‍♂️:( so many missed opportunities to talk about how these things really work, the real harms they create today/yesterday, as well as potential mitigations. So happy you exist @timnitGebru !
English
1
0
5
192
Matteo / @[email protected] retweetledi
@timnitGebru (@dair-community.social/bsky.social)
CBS 60 minutes: how to go from journalism to AI Hype marketing—as—a—service. Deepmind will cure cancer & Anthropic is teaching “models to be good” ❤️ Not the massive theft, environmental costs & toxic outputs discussed. Mainstream media is killing itself no one else to blame.
60 Minutes@60Minutes

“I spend a lot of time trying to teach the models to be good,” says Amanda Askell, one of Anthropic’s in-house philosophers. cbsn.ws/47XQLZc

English
11
96
439
29.1K
Matteo / @geminiimatt@infosec.exchange
Matteo / @[email protected]@geminiimatt·
@RachelTobac I will tell everyone to get "politely paranoid". Keep up the great work Rachel, keeping the masses safe with factual education and demonstration!
English
1
0
1
86
Matteo / @[email protected] retweetledi
Rachel Tobac
Rachel Tobac@RachelTobac·
In the past quarter, I've had 6 orgs I work with mention to me that they're dealing with a live Zoom/Teams call deepfake impersonating an Executive to staff asking for a wire transfer or a password. This attack method is growing right now. Make sure your team knows to catch it.
Rachel Tobac@RachelTobac

*CNN Zoom Call Deepfake Demo* An engineering org sent $25 Million to scammers who deepfaked the finance team in a live video call. Are your colleagues, family & friends ready to catch this AI attack? I demo'd a live Zoom deepfake to CNN's Clare Duffy to help you spot the signs.

English
3
30
146
28.2K