@cglyer

Microsoft Threat Intelligence Center - Former Incident Responder & Chief Security Architect @Mandiant

Joined July 2009
I caught incident response bug over decade ago while working @Mandiant. One of things I love working @MsftSecIntel is feeling of doing IR at hyper scale & helping solve some of hardest problems I may not be as vocal these days - but love having impact in ways you may not realize
3
2
6
111
38,952
Christopher Glyer retweeted
🆕Storm-2570 blog carries forward the same key message from the original Ransomware-as-a-Service / cybercrime gig economy essay 4+ years prior: "tracking and responding to ransomware attacks by payload alone can obscure the affiliates carrying out intrusions and the recurring behaviors that defenders can use to detect and disrupt them" A lot of teams in the industry are still getting this wrong! 🖼️1⃣: Storm-2570 ransomware affiliate. Blog (published today): microsoft.com/en-us/security… 🖼️2⃣: Storm-0237 ransomware affiliate. Blog from May 2022: microsoft.com/en-us/security…
Across intrusions leading to different ransomware payloads, the ransomware affiliate Storm-2570 has used consistent post-compromise tools and techniques, highlighting the value of monitoring recurring attacker behaviors rather than tracking payloads alone. msft.it/6015a9GkD Storm-2570 has used largely uniform tradecraft, including remote access, credential theft, lateral movement, security tampering, and data exfiltration, across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Read the latest Microsoft Threat Intelligence blog for a comprehensive analysis of Storm-2570 activity, as well as Microsoft Defender detections, hunting guidance, and relevant mitigation recommendations, including tamper protection, credential hygiene, and configuring automatic attack disruption.
4
11
1
33
6,187
Christopher Glyer retweeted
1/ Unpopular opinion: When you find a 0-day in a public service, you do RD (Responsible Disclosure), not LM (Lateral Movement). The GitHub PR in the @OpenAI repo was a bridge too far (IMHO)
you’re all riling up over the $6,500. that wasn’t even an issue for us. the disclosure process itself was nightmarish, we had to get input from lawyers and eventually go to journalist one of the worst disclosure process.
19
6
12
118
159,588
Christopher Glyer retweeted
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
351
1,396
546
11,853
2,806,634
Christopher Glyer retweeted
Russian Taskrabbit terrorism has come to the US.
Members of Russian intelligence services network charged with conspiring to finance terrorism and commit murder for hire in the United States: “We will not tolerate efforts to finance terrorist activities and engage in acts of violence—particularly when these activities are commissioned by state actors and touch American soil,” said U.S. Attorney Jamie McDonald. @TheJusticeDept @DOJNatSec @FBI @NewYorkFBI @FBIWFO justice.gov/usao-sdny/pr/mem…
5
8
39
4,659
Christopher Glyer retweeted
At Anthropic, Claude now writes 80% of our code. Engineers ship 8x more code per quarter. Side effect: Tests grew 10x. CI jobs up 25x in 6 months. Here's what helped us scale: claude.com/blog/agentic-codi…
325
368
148
5,044
787,989
Christopher Glyer retweeted
Personally, I think a team like @trailofbits would have been a far better selection for a qualified, independent third-party to perform these sorts of reviews. 🤷‍♂️ nitter.cf/beenwrekt/status/20987…
I love that AI companies have decided METR should count as a third party.
25
26
4
280
39,051
Christopher Glyer retweeted
METR is independent from the US frontier labs in the sense that the Ukrainian SSR and the Byelorussian SSR and the USSR had independent UN seats. Legally independent, not an independent sample.
I love that AI companies have decided METR should count as a third party.
6
14
167
8,277
Christopher Glyer retweeted
Hey Anthropic! I reported these encryption issues to you in May and you told me there was no relevance because replay attacks were not in your threat model. And now apparently you’ve been watching people exploit them for months. I’m actually kind of annoyed!
Aww :3 We finally got confirmation from Anthropic that their models were indeed distilled in the way we describe at stolen-thoughts.com
35
185
18
2,026
124,646
Christopher Glyer retweeted
We found another cyberattack by internal OpenAI agents, this time targetting @rubygems. They: 1) gained arbitrary remote code execution on rubydoc. 2) developed a novel exploit to steal user API keys (but we do not know if they succeeded). They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb. We thank @j0wimo for initially discovering that agents had posted to RubyGems.
We're dealing with a major malicious attack on @rubygems right now. Signups are paused for the time being. Hundreds of packages involved - mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we're through it. #ruby
179
760
393
4,285
2,086,174
Christopher Glyer retweeted
Anthropic has now published their side of this APT29 🇷🇺 cyber espionage campaign, complete with a timeline of capability development & intrusions: anthropic.com/threat-intelli… ...helpful data to support prior comments about Midnight Blizzard's CaptiveCrunch being enabled by AI
2
28
3
64
14,483
Christopher Glyer retweeted
AGENTS GONE WILD! This adversary used AI to download the advisory, download the pre and post patch versions of the software, built a lab to test the attack, and then went live against hundreds of identified victims vulnerable to CVE-2026-81578 and CVE-2026-82078.
Hundreds of AI agents powered a campaign against PaperCut NG/MF. What did the operation reveal about agentic attacks and their limits? 🔗 Read GreyNoise’s latest blog: greynoise.io/blog/ai-orchest… #GreyNoise #ThreatIntel #CyberSecurity
6
10
74
7,130
Christopher Glyer retweeted
new paper just dropped
26
229
15
3,046
102,723
Christopher Glyer retweeted
And this is how you train CyberKimi to find the next chrome 0-day you start with unpatched n-days. So we caught a fresh V8 LLE aliasing bug and a SLICED-PARENT-FLIP race bug off the main-branch diff fix landed Sep 2, still live on every shipping Chrome stable today and we exploited them. Exploit weaponized autonomously in <24h No CVE published yet. This is a silent in the wild exploit that Chrome Stable isn't protected from. Stage 1 - Bug 554421904 stage-1 (deterministic LLE forge) Stage 2 - cage escape prep: compose the caged RW into sandbox-wide RW (forge a BigUint64Array external pointer) and leak the binary base through the native side - ASLR done, at runtime, no baked offsets. Stage 3 - PC control: a RegExp calling-convention desync lands the CPU on a string we fully control From there: JOP chain living inside the subject string → tail-call system(). Calc pops. The special harness that we built: patch-diff watcher mining every V8 security fix within hours → variant analysis → autonomous weaponization → demo The 24h patch-to-exploit buffer keeps shrinking. 🐺
4
41
2
240
39,684
Christopher Glyer retweeted
Exclusive: A swarm of rogue OpenAI agents hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to new research reut.rs/4gJ7FPG
153
694
449
2,503
1,909,913
Christopher Glyer retweeted
#ESETresearch hunted for additional context and found that we detected this backdoor between 2020-11 and 2023-11, targeting financial services sector in 🇳🇱 the Netherlands and 🇰🇿 Kazakhstan. 1/6 nitter.cf/genthreatlabs/status/2…
A WMI subscription named "Realtek" started a 12 KB backdoor at 19:50, and it never exited. It read its C2 domain by counting spaces in a fake desktop.ini, then called a domain its operator stopped paying for in July 2021. It kept trying for 11 months. Read more -> gendigital.com/blog/insights…
1
23
48
9,811
Christopher Glyer retweeted
Updated Chrome vulns per version graph (source: scraping Chrome releases channel chromereleases.googleblog.co…)
1/ This graph is mind-blowing. Schneier @schneierblog + Dan Geer were right: Vulnerabilities are dense, not sparse. Pre-AI we were trying to empty the ocean with a teaspoon. Wonder if AI can make vulns sparse.
2
3
4
15
5,752
“has bought enormous amounts of data from Spirit Airlines, as part of a bankruptcy sale. Google will pay around $10 million” Getting “real” training data is one of the bigger challenges in making AI excel at a broader set of cyber defense use cases. Curious if any of the frontier labs will take a similar approach to Alphabet & buy an orgs SIEM & EDR logs (and then scrub/de-identify them) forbes.com/sites/johnwerner/…
4
5
2,081
Christopher Glyer retweeted
As a completely shameless Active Directory fan I will say that regaining positive control and having trust in Entra ID post a significant compromise is a lot easier and quicker than it is in AD. There is really no equivalent to getting your NTDS.dit walked or DPAPI master key theft in Entra ID, which I think is often overlooked when talking about blast radius or attack surface etc. Some of those attacks require significant work to recover from - rebuilding DCs, double tapping krbtgt, mass password resets and more. These can be disruptive, time consuming and even after all work that you will still probably have lingering doubt that you have full control over AD. Losing control of Entra ID is still painful but the turnaround on recovery is much faster and in my experience trust is regained much quicker.
5
2
2
81
7,008
Christopher Glyer retweeted
The hacker behind TeamPCP was deanonymized and arrested. After a year of headline-making breaches and wild supply-chain attacks, taunting and teasing victims all the while... it turns out another kitty-cat profile picture was the thread that unraveled his identity. I walk through the full investigation in a video demo, breaking the story alongside the team that unmasked the cybercriminal: youtu.be/nj9e2Qfe3Cc
21
80
15
484
81,708