Mattysploit
banner
mattysplo.it
Mattysploit
@mattysplo.it
Infosec lurker. Occasional poster. Mostly blog stuff.
https://mattysplo.it
Your last saved meme is your moral philosophy
November 17, 2025 at 4:24 AM
Reposted by Mattysploit
the only good accent work on earth is old money transatlantic american to make fun of rich people accent
November 13, 2025 at 4:06 PM
Early plot rumors suggest they establish their own country and flirt with genocidal tendencies, named GremlinNation.

@nicklutsko.bsky.social
November 6, 2025 at 8:36 PM
💯
November 5, 2025 at 10:45 PM
I feel like I'm losing my mind - am I on sedatives or is this the most lackadaisical half-assery I have ever seen in my life?
A huge brawl broke out at the Bass Pro Shop grand opening in Odessa, TX. From the looks of it, no one was seriously injured...
November 3, 2025 at 5:19 PM
Reposted by Mattysploit
ICE Agent, 7-Year-Old Both Wearing Same ‘Military Commando’ Halloween Costume
October 31, 2025 at 9:00 PM
I suspect this shouldn't surprise anyone.

Maybe try converting it to a casino?
October 31, 2025 at 2:40 PM
Reposted by Mattysploit
Ravin Academy, the private school that recruits and trains hackers for Iran's MOIS intelligence service , has been hacked and its data leaked

www.iranintl.com/202510230171

blog.narimangharib.com/posts/2025%2...

Public searchable database: ravin-academy.com
October 26, 2025 at 7:58 PM
You'll never believe this but Nazi tattoos are really bad, actually
October 22, 2025 at 3:00 PM
Reposted by Mattysploit
New: hackers just doxed hundreds of DHS, ICE, FBI, and DOJ officials. I went through the data. In many cases does look legitimate, sometimes includes residential addresses.

“Mexican Cartels hmu [hit me up] we dropping all the doxes wheres my 1m [1 million].”

www.404media.co/hackers-dox-...
Hackers Dox Hundreds of DHS, ICE, FBI, and DOJ Officials
Scattered LAPSUS$ Hunters—one of the latest amalgamations of typically young, reckless, and English-speaking hackers—posted the apparent phone numbers and addresses of hundreds of government officials...
www.404media.co
October 17, 2025 at 2:36 AM
Reposted by Mattysploit
"Together, the messages reveal a culture where racist, antisemitic and violent rhetoric circulate freely — and where the Trump-era loosening of political norms has made such talk feel less taboo among those positioning themselves as the party’s next leaders."

Can't call them fascists?
‘I love Hitler’: Leaked messages expose Young Republicans’ racist chat
Thousands of private messages reveal young GOP leaders joking about gas chambers, slavery and rape.
www.politico.com
October 14, 2025 at 5:40 PM
Reposted by Mattysploit
Breaking News: Iranian Advanced Persistent Threat Group #APT35 Has Been Compromised, with Internal Documents Leaked Online

blog.narimangharib.com/posts/2025%2...
Massive Leak Exposes Inner Workings of Iranian Hacking Group Charming Kitten
In what appears to be one of the most significant breaches of an Iranian state-sponsored hacking operation to date, an anonymous source has published internal d...
blog.narimangharib.com
September 30, 2025 at 9:14 PM
Personal connect in a small org hit by a wave of phishing. I unpacked a sneaky SVG — spoiler: it just redirects to a phishing page — and turned it into a short 101 for teams without cyber folks: how the SVG works, how Tycoon kits operate, and quick fixes.
Simple stuff but hope it helps somebody.
Tycoon 2FA and a Sneaky SVG
Last week a personal connection reached out about a big wave of scammy invoice emails to their organization, so I thought I would do a quick 101 on what these typically are, how they occur, and what y...
mattysplo.it
September 25, 2025 at 9:43 PM
Reposted by Mattysploit
I told the Reverend he made me proud to be a Christian.
September 21, 2025 at 1:53 PM
Reposted by Mattysploit
On Friday, FEMA’s security office blocked agency staff from accessing a handful of apps and websites, including X, Facebook, YouTube and Reddit. Additionally, staffers can no longer disable Zscaler internet security services without a password:
www.nextgov.com/cybersecurit...
FEMA begins security overhauls following cyber incident and employee firings
The agency recently blocked users from accessing multiple websites and made password changes to an internet security tool in efforts to shore up its cyber posture, people familiar say.
www.nextgov.com
September 8, 2025 at 5:22 PM
Today's theme
September 4, 2025 at 6:01 PM
Reposted by Mattysploit
I know I'm sounding like a broken record at this point. But it's really important to notice how the criminal justice infrastructure, built by both parties over many decades, is being deployed to meet Trump's goals right now.
September 4, 2025 at 2:46 PM
Happy Labor Day! I graphed my recent cyber-guy job search:

#CyberSecurity #infosec
The Cyber Job Market: 2025
I had planned to write this up since the start of the job search, since it has always felt labor solidarity focused when others have done it, so here’s my contribution. Even outside of that, the most ...
mattysplo.it
September 1, 2025 at 7:44 PM
Reposted by Mattysploit
Okta open-sources catalog of Auth0 rules for threat detection vapt.me/0kta1
Okta open-sources catalog of Auth0 rules for threat detection
Okta has open-sourced ready-made Sigma-based queries for Auth0 customers to detect account takeovers, misconfigurations, and suspicious behavior in event logs.
buff.ly
August 20, 2025 at 8:12 AM
Reposted by Mattysploit
Russie 🇷🇺

Les soldats Russes semblent avoir très bien compris que, désormais, la Maison Blanche est l'alliée du Kremlin.
August 18, 2025 at 9:51 AM
Reposted by Mattysploit
Fascism requires thousands upon thousands of people "just doing their job". And Americans love to just do their job.
August 13, 2025 at 6:04 PM
Reposted by Mattysploit
DHS is recruiting using a not-so-subtle reference to a 1978 book from white nationalist William Gayley Simpson, Which Way Western Man?

Simpson's book was released under an imprint associated with the National Alliance, founded by Turner Diaries author William Luther Pierce.
August 12, 2025 at 3:21 PM
New from me, figured I might as well contribute to the OAuth zeitgeist. #CyberSecurity #infosec

mattysplo.it/2025/08/02/o...
No Malware Required: OAuth Token Abuse
Who needs an endpoint?
mattysplo.it
August 4, 2025 at 1:20 PM
Reposted by Mattysploit
New from me - this has actually been about a year in the making. I wrote about cyber incident labelling schemas and how they've tended to kind of suck. Specifically, the "categories" - the shorthand for how an incident is named.

Usually not great, annoying in the SOCs I've been in
#Infosec #cyber
The Universal Cyber Incident Taxonomy (UCIT)
Incident categorization plays a bigger role in cybersecurity operations than most people realize. It affects how alerts are routed, how incidents get reported, and how security programs measure what’s...
mattysplo.it
July 14, 2025 at 3:55 PM