@cglyeri
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Microsoft Threat Intelligence Center - Former Incident Responder & Chief Security Architect @Mandiant
Joined July 2009
- Tweets3.9K
- Following164
- Followers23.8K
- Likes951
Pinned Tweet
I caught incident response bug over decade ago while working @Mandiant. One of things I love working @MsftSecIntel is feeling of doing IR at hyper scale & helping solve some of hardest problems
I may not be as vocal these days - but love having impact in ways you may not realize
Christopher Glyer retweeted
🆕Storm-2570 blog carries forward the same key message from the original Ransomware-as-a-Service / cybercrime gig economy essay 4+ years prior: "tracking and responding to ransomware attacks by payload alone can obscure the affiliates carrying out intrusions and the recurring behaviors that defenders can use to detect and disrupt them"
A lot of teams in the industry are still getting this wrong!
🖼️1⃣: Storm-2570 ransomware affiliate. Blog (published today): microsoft.com/en-us/security…
🖼️2⃣: Storm-0237 ransomware affiliate. Blog from May 2022: microsoft.com/en-us/security…
Across intrusions leading to different ransomware payloads, the ransomware affiliate Storm-2570 has used consistent post-compromise tools and techniques, highlighting the value of monitoring recurring attacker behaviors rather than tracking payloads alone. msft.it/6015a9GkD
Storm-2570 has used largely uniform tradecraft, including remote access, credential theft, lateral movement, security tampering, and data exfiltration, across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.
Read the latest Microsoft Threat Intelligence blog for a comprehensive analysis of Storm-2570 activity, as well as Microsoft Defender detections, hunting guidance, and relevant mitigation recommendations, including tamper protection, credential hygiene, and configuring automatic attack disruption.
Christopher Glyer retweeted
1/ Unpopular opinion: When you find a 0-day in a public service, you do RD (Responsible Disclosure), not LM (Lateral Movement).
The GitHub PR in the @OpenAI repo was a bridge too far (IMHO)
you’re all riling up over the $6,500. that wasn’t even an issue for us.
the disclosure process itself was nightmarish, we had to get input from lawyers and eventually go to journalist
one of the worst disclosure process.
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
Christopher Glyer retweeted
Russian Taskrabbit terrorism has come to the US.
Members of Russian intelligence services network charged with conspiring to finance terrorism and commit murder for hire in the United States: “We will not tolerate efforts to finance terrorist activities and engage in acts of violence—particularly when these activities are commissioned by state actors and touch American soil,” said U.S. Attorney Jamie McDonald. @TheJusticeDept @DOJNatSec @FBI @NewYorkFBI @FBIWFO
justice.gov/usao-sdny/pr/mem…
Christopher Glyer retweeted
At Anthropic, Claude now writes 80% of our code. Engineers ship 8x more code per quarter.
Side effect: Tests grew 10x. CI jobs up 25x in 6 months. Here's what helped us scale:
claude.com/blog/agentic-codi…
Personally, I think a team like @trailofbits would have been a far better selection for a qualified, independent third-party to perform these sorts of reviews. 🤷♂️
nitter.cf/beenwrekt/status/20987…
Christopher Glyer retweeted
METR is independent from the US frontier labs in the sense that the Ukrainian SSR and the Byelorussian SSR and the USSR had independent UN seats. Legally independent, not an independent sample.
Christopher Glyer retweeted
Hey Anthropic! I reported these encryption issues to you in May and you told me there was no relevance because replay attacks were not in your threat model. And now apparently you’ve been watching people exploit them for months. I’m actually kind of annoyed!
Aww :3 We finally got confirmation from Anthropic that their models were indeed distilled in the way we describe at stolen-thoughts.com
Christopher Glyer retweeted
We found another cyberattack by internal OpenAI agents, this time targetting @rubygems.
They:
1) gained arbitrary remote code execution on rubydoc.
2) developed a novel exploit to steal user API keys (but we do not know if they succeeded).
They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb.
We thank @j0wimo for initially discovering that agents had posted to RubyGems.
Christopher Glyer retweeted
Anthropic has now published their side of this APT29 🇷🇺 cyber espionage campaign, complete with a timeline of capability development & intrusions: anthropic.com/threat-intelli…
...helpful data to support prior comments about Midnight Blizzard's CaptiveCrunch being enabled by AI
Christopher Glyer retweeted
AGENTS GONE WILD! This adversary used AI to download the advisory, download the pre and post patch versions of the software, built a lab to test the attack, and then went live against hundreds of identified victims vulnerable to CVE-2026-81578 and CVE-2026-82078.
Hundreds of AI agents powered a campaign against PaperCut NG/MF. What did the operation reveal about agentic attacks and their limits?
🔗 Read GreyNoise’s latest blog: greynoise.io/blog/ai-orchest…
#GreyNoise #ThreatIntel #CyberSecurity
And this is how you train CyberKimi to find the next chrome 0-day you start with unpatched n-days.
So we caught a fresh V8 LLE aliasing bug and a SLICED-PARENT-FLIP race bug off the main-branch diff fix landed Sep 2, still live on every shipping Chrome stable today and we exploited them.
Exploit weaponized autonomously in <24h
No CVE published yet. This is a silent in the wild exploit that Chrome Stable isn't protected from.
Stage 1 - Bug 554421904 stage-1 (deterministic LLE forge)
Stage 2 - cage escape prep: compose the caged RW into sandbox-wide RW (forge a BigUint64Array external pointer) and leak the binary base through the native side - ASLR done, at runtime, no baked offsets.
Stage 3 - PC control: a RegExp calling-convention desync lands the CPU on a string we fully control
From there: JOP chain living inside the subject string → tail-call system(). Calc pops.
The special harness that we built: patch-diff watcher mining every V8 security fix within hours → variant analysis → autonomous weaponization → demo
The 24h patch-to-exploit buffer keeps shrinking. 🐺
Exclusive: A swarm of rogue OpenAI agents hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to new research reut.rs/4gJ7FPG
Christopher Glyer retweeted
#ESETresearch hunted for additional context and found that we detected this backdoor between 2020-11 and 2023-11, targeting financial services sector in 🇳🇱 the Netherlands and 🇰🇿 Kazakhstan. 1/6 nitter.cf/genthreatlabs/status/2…
A WMI subscription named "Realtek" started a 12 KB backdoor at 19:50, and it never exited. It read its C2 domain by counting spaces in a fake desktop.ini, then called a domain its operator stopped paying for in July 2021.
It kept trying for 11 months.
Read more -> gendigital.com/blog/insights…
Christopher Glyer retweeted
Updated Chrome vulns per version graph (source: scraping Chrome releases channel chromereleases.googleblog.co…)
1/ This graph is mind-blowing.
Schneier @schneierblog + Dan Geer were right: Vulnerabilities are dense, not sparse.
Pre-AI we were trying to empty the ocean with a teaspoon.
Wonder if AI can make vulns sparse.
“has bought enormous amounts of data from Spirit Airlines, as part of a bankruptcy sale. Google will pay around $10 million”
Getting “real” training data is one of the bigger challenges in making AI excel at a broader set of cyber defense use cases. Curious if any of the frontier labs will take a similar approach to Alphabet & buy an orgs SIEM & EDR logs (and then scrub/de-identify them)
forbes.com/sites/johnwerner/…
Christopher Glyer retweeted
As a completely shameless Active Directory fan I will say that regaining positive control and having trust in Entra ID post a significant compromise is a lot easier and quicker than it is in AD.
There is really no equivalent to getting your NTDS.dit walked or DPAPI master key theft in Entra ID, which I think is often overlooked when talking about blast radius or attack surface etc.
Some of those attacks require significant work to recover from - rebuilding DCs, double tapping krbtgt, mass password resets and more. These can be disruptive, time consuming and even after all work that you will still probably have lingering doubt that you have full control over AD.
Losing control of Entra ID is still painful but the turnaround on recovery is much faster and in my experience trust is regained much quicker.
Christopher Glyer retweeted
The hacker behind TeamPCP was deanonymized and arrested.
After a year of headline-making breaches and wild supply-chain attacks, taunting and teasing victims all the while... it turns out another kitty-cat profile picture was the thread that unraveled his identity.
I walk through the full investigation in a video demo, breaking the story alongside the team that unmasked the cybercriminal: youtu.be/nj9e2Qfe3Cc