Matthew Flanagan
@mattimustang.com
š¤ 99
š„ 58
š 18
Director and Principal Cyber Security Consultant
@cybliminal.com
I had a great time presenting to the
@bsidesmelbourne.bsky.social
crowd on the weekend. Thanks to the crew and volunteers for running such a welcoming, vibrant conference, with a great selection of talks! Big ā¤ļø to Edwina Richards for the photos!
#BSidesMelb2026
#WontSomebodyPleaseEatTheFruit
7 days ago
1
3
2
I'm excited to announce I'll be taking the stage at
@bsidesmelbourne.bsky.social
16-17 May 2026 at SEEK HQ in Cremorne. I'll be presenting Panning for Gold: A Hacker's Guide to Next Generation Firewalls on how attackers can exploit FW features and weaknesses to increase the impact of a compromise.
about 1 month ago
1
5
3
reposted by
Matthew Flanagan
CrikeyCon
2 months ago
What do you do when you find yourself the new owner of Kubernetes config during a pentest? Find out the answer, and more with Finn Foulds-Cook during his talk on Saturday - "Help I got a k8s config?"
0
5
2
reposted by
Matthew Flanagan
CrikeyCon
3 months ago
Our friends
@cybliminal.com
l have been ongoing supporters and with just over a week left, we wanted to throw another thank you their way. Big hugs to Matthew Flanagan and the Cybliminal crew for supporting our con!
0
3
1
reposted by
Matthew Flanagan
3 months ago
Hey hey Women of CrikeyCon! Get your tickets for the networking event here:
events.humanitix.com/women-of-cri...
loading . . .
Women of CrikeyCon 11 networking event
Get tickets on Humanitix - Women of CrikeyCon 11 networking event. Venue provided after registering for a ticket!. Thursday 19th March 2026. Find event information.
https://events.humanitix.com/women-of-crikeycon-networking-event
0
5
3
reposted by
Matthew Flanagan
CrikeyCon
3 months ago
Come join Alex Tilley on stage as we're brought through lived experiences in "Real world management in the world of Bad Days". We're stoked to hear this one as no one wants to deal with, but everyone should be prepped to get through, a massively bad day.
0
4
3
reposted by
Matthew Flanagan
CrikeyCon
3 months ago
First up on 21st March we have
@ellearmageddon.bsky.social
taking the stage. Elle's joining us with their talk "nothing we do matters (so it canāt hurt to try!)". Join us to see them at the RNA showgrounds, and get some much needed hope in these times!
0
4
2
Weāll be there again this year supporting these wonderful people ā¤ļøāš„ Iām looking forward to seeing Elle Armageddonās keynote. If you spot us say Hiā¦we might just have some
@cybergoodies.run
t-shirts to give away.
add a skeleton here at some point
3 months ago
0
1
0
reposted by
Matthew Flanagan
CrikeyCon
3 months ago
Our schedule is up, and we're excited to announce our speaker
@snyff.pentesterlab.com
is joining us on stage with I DON'T LIKE THIS CODE!!! Get ready to walk through a series of real-world inspired code snippets with one minute to figure it out. Only question, will there be jeopardy music?
0
10
4
reposted by
Matthew Flanagan
cybliminal
3 months ago
Thanks Crikey crew! Itās a great bunch of speaker youāve got lined up this year. Canāt wait to see the! š
add a skeleton here at some point
0
4
3
reposted by
Matthew Flanagan
CrikeyCon
3 months ago
Wow! Weāre over 2/3 of the way through the tickets now, weāll keep on selling til capacity or the day before, but merchandise pre-sales will end on Sunday as we have to finalise the order! There will be some for sale on the day too but no guarantees on sizes.... Head to
www.crikeycon.com
loading . . .
https://www.crikeycon.com
0
3
3
reposted by
Matthew Flanagan
CrikeyCon
4 months ago
CFP and CFE has officially closed. We had a huge turnout, thank you so much for your time and effort to submit your ideas. Droppy & the Sleuth are busily reviewing and looking to get a response to everyone that submitted latest by the 21st. Reach out if you have any questions! Droppy & the Sleuth
0
5
3
reposted by
Matthew Flanagan
BSides Canberra
4 months ago
New BSides Canberra IX look unlocked. Blue tones, laser lines, and energy straight out of the grid. Website updated, more to come.
0
1
1
reposted by
Matthew Flanagan
CrikeyCon
4 months ago
Sunday when CFP and CFE closes, get your ideas in now! CFP:
docs.google.com/forms/d/e/1F...
CFE:
docs.google.com/forms/d/e/1F...
loading . . .
CrikeyCon 11 (2026) Call for Presentations
*** CFE CLOSES February 1 2026 *** Saturday March 21 2026 Royal International Convention Centre, Bowen Hills, Brisbane, QLD CrikeyCon is a community-led conference targeting those with an interest i...
https://docs.google.com/forms/d/e/1FAIpQLSdMd4aARlGErYtB9IrkVIFe2Fvz9nufPEHiJlarsJZY5jZa5g/viewform
0
4
5
reposted by
Matthew Flanagan
goggan
4 months ago
We have had some awesome submissions already, but if you've got that talk up your sleeve or a great idea for a workshop or longer presentation then we're all ears. Put your paw up to be part of the show!!
add a skeleton here at some point
0
2
2
reposted by
Matthew Flanagan
CrikeyCon
5 months ago
Happy New Year! CrikeyCon 11 is three months away. Come join us in Brisbane on 21st of March for informal, welcoming, real knowledge sharing ā from hard-won lessons, to clever demos and challenges, or testing fresh ideas. Grab your ticket:
events.humanitix.com/crikeycon-11
loading . . .
CrikeyCon 11
Brisbane hacker conference, run by the community for the community.
https://events.humanitix.com/crikeycon-11
0
4
3
reposted by
Matthew Flanagan
CrikeyCon
6 months ago
Huge thanks to
@infosectcbr.bsky.social
who have returned as Gold Sponsors! Their contribution to the communities around us make us so proud to get their support and sponsorship. Many hugs, Droppy & The Sleuth
0
5
3
reposted by
Matthew Flanagan
Fabian Bader
6 months ago
@_dirkjan and my joint talk at
#TROOPERS25
is now available on YouTube. "Finding Entra ID CA Bypasses - the structured way"
@wearetroopers.bsky.social
youtu.be/yYQBeDFEkps
loading . . .
TROOPERS25: Finding Entra ID CA Bypasses - The Structured Way
YouTube video by TROOPERS IT Security Conference
https://youtu.be/yYQBeDFEkps
0
6
3
If you missed my talk at BSides Canberra you can catch up on it now on YouTube
add a skeleton here at some point
6 months ago
0
6
2
reposted by
Matthew Flanagan
CrikeyCon
6 months ago
Big shout out to
@cybliminal.com
our first silver sponsor this year! Massive hugs for the returning support; can't wait to see you out at the showgrounds.
1
5
6
reposted by
Matthew Flanagan
BSides Canberra
8 months ago
Lots of DMs asking for BSides Canberra 2025 talks ā theyāll be on YouTube in a month+ š„ Speakers are reviewing their sessions first, so stay tuned! š
youtube.com/@bsidescanbe...
loading . . .
BSides Canberra
https://youtube.com/@bsidescanberra9688?si=uysWrSTGUBympWNq
0
3
1
reposted by
Matthew Flanagan
BSides Canberra
8 months ago
Celebrating 10 years of amazing artwork for BSides Canberra! šØ Huge thanks to Sydney-based Aussie Glenno for bringing our logos to life. Real artists > AI every time.
www.instagram.com/glennoart?ig...
0
2
1
Thanks again to
@bsidescbr.bsky.social
for inviting me to present my research on living off the land on Palo Alto Networks firewalls as well as sharing new tools Iāve developed to creatively misuse š firewall features for credential harvesting and port scanning. Some great questions too!
8 months ago
0
6
3
Thanks again to
@bsidescbr.bsky.social
for inviting me to present my research on living off the land on Palo Alto Networks firewalls as well as sharing new tools Iāve developed to creatively misuse š firewall features for credential harvesting and port scanning. Some great questions too!
8 months ago
1
0
0
reposted by
Matthew Flanagan
BSides Canberra
8 months ago
CTF early registration is now open! š¹ļø Get set up ahead of time so youāre ready to go when the CTF kicks off this Friday at BSides Canberra. Register here:
ctf.sk8boarding.dog
loading . . .
noCTF
https://ctf.sk8boarding.dog/
0
1
1
Just one week to go until I present the research from my āPanning for Gold: A Hackerās Guide to Next Generation Firewallsā paper. Come along and listen to it at
@bsidescbr.bsky.social
if youād like to up your post-exploitation game or learn how to better defend your environment.
add a skeleton here at some point
8 months ago
0
4
3
reposted by
Matthew Flanagan
Catalin Cimpanu
10 months ago
For the record, Expel silently updated their blog post to replace bypass with downgrade for this attack
add a skeleton here at some point
1
17
5
reposted by
Matthew Flanagan
BSides Canberra
10 months ago
This year at BSidesCbr, both the Main Track and the Off-Main Track will run across all three days. Main Track brings the big research, big ideas, and big names. Off-Main features beginner-friendly talks, deep dives, and unexpected gemsāstreamed to four theatrettes.
0
2
2
reposted by
Matthew Flanagan
BSides Canberra
10 months ago
"Decoding Threat Actors: a Free Tool for Mapping Aliases" Fancy Bear or Forest Blizzard? Qakbot or Pinkslipbot? Dave Matthews reveals a free tool to untangle the threat actor name game - linking aliases, malware families & public research.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Decoding Threat Actors: a Free Tool for Mapping Aliases and Taming the Name Game BSides Canberra 2025
Drowning in the chaos of Threat Actor aliases? Fancy Bear or Forest Blizzard? Wicked Panda or BRONZE ATLAS? And malware families? CageyChameleon or Cabbage RAT? Qakbot or Pinkslipbot? In this session...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/8NAQUJ/
0
1
1
reposted by
Matthew Flanagan
BSides Canberra
10 months ago
"Ding Dong the EDR is DEAD" EDR isn't invincible. Ayman Sagy walks through a real-world exploit against Palo Alto Cortex XDR - earning CVE-2024-8690 and a $2K bounty. See how it was done.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Ding Dong The EDR is DEAD BSides Canberra 2025
Endpoint Detection and Response (EDR) is the watchdog running on your endpoint to detect and respond to threats in real-time. However, like other defenses, it is not a foolproof solution. In this talk...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/D3KHPY/
1
1
1
reposted by
Matthew Flanagan
BSides Canberra
10 months ago
"Why Rust is Safe" Memory safety and C-level performance with no GC or runtime? Ben Williamson breaks down how Rustās ownership model delivers safety guarantees at compile time, making it fit for kernels, firmware, and more.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Why Rust is Safe BSides Canberra 2025
C and C++ are awesome / terrible ā they let you do whatever you want with pointers, resulting in all the tasty memory corruption vulnerabilities we know and love. Other languages impose a runtime or g...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/GVNQQF/
0
2
1
reposted by
Matthew Flanagan
BSides Canberra
10 months ago
"Reversing Bytecode into Bounties" Jira and Confluence plugins can hide serious vulns, if you know where to look. Giuliana and Jamal from Atlassian will show you how to decompile, scan, and exploit like a pro. Whitebox your way to bounties:
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Reversing Bytecode into Bounties: Uncovering Vulnerabilities in Jira and Confluence Plugins BSides Canberra 2025
Whitebox assessments are like unlocking the entire game map, and it's totally up to you to decide whatās worth exploring. Understanding how to decompile apps and navigate them will equip you with the ...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/DCEZKT/
0
1
1
reposted by
Matthew Flanagan
BSides Canberra
10 months ago
"Why I am (still) finding secrets in your code" Despite all the secret scanning tools, sensitive creds are still everywhere. Luke Marshall shares how he's found exposed secrets across ecosystems, and helped secure 40+ orgs. š
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Why I am (still) finding secrets in your code BSides Canberra 2025
Despite the widespread availability of secret scanning tools, thousands of sensitive credentials continue to be exposed in popular open source ecosystems, a security blind spot that sparked my curiosi...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/UVADYW/
0
1
1
reposted by
Matthew Flanagan
BSides Canberra
10 months ago
"Bitsquatting dot
gov.au
domains" Ever blamed cosmic rays for DNS weirdness? Matt Belvedere explores a year of bitflip data in .gov.au traffic, digging into real-world bitsquatting and unexpected system-to-system auth.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
https://gov.au
0
1
1
reposted by
Matthew Flanagan
BSides Canberra
10 months ago
"DarkEngine ā Researching a Global Phishing Campaign" nullifysecurity breaks down a large-scale phishing op that compromised 2,350+ WordPress sites via fake CAPTCHA lures.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
DarkEngine: Conducting Research into a Highly Orchestrated Phishing Campaign BSides Canberra 2025
In June 2025, CyberCX released a report on a highly orchestrated phishing campaign targeting popular WordPress hosting platform WP Engine, dubbed āDarkEngineā, which led to the compromise of at least ...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/DRR8KX/
0
1
1
reposted by
Matthew Flanagan
BSides Canberra
10 months ago
"Behind the Curtain of Dark Web and Cybercrime Operations" Join Alexander Wilczek as he reveals insights from a 4-year investigation into how cybercriminals move and launder money - using OSINT, blockchain tools, and strong OPSEC.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Behind the Curtain of Dark Web and Cybercrime Operations BSides Canberra 2025
A four-year investigation into cybercriminal financial operations. Following the money, examining how threat actors generate, transfer, and launder illicit proceeds. Including the operational security...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/NWWKSN/
0
1
1
Iām incredibly excited to be accepted by
@bsidescbr.bsky.social
to present my research on Next Gen Firewalls. I canāt wait to get up there for the first time to share it with you all!
add a skeleton here at some point
10 months ago
1
3
3
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
Justin's talk title speaks for itself: āWell well well, if it isnāt the consequences of my own actionsā - the time I got in the middle of 100,000 Linux machines and their LVFS firmware updates and then somehow bypassed the fwupd PGP signature checking
0
2
2
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
Open source sits at the base of the software supply chain. Fraser talks about how critical it is for open source to establish security response teams and infrastructure. Listen to the experiences learned from bootstrapping and leading the Haskell security response team.
0
2
2
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
We're a week away and we wanted to say another big thank you to our sponsors. This year Cybliminal has joined us as a Silver sponsor! Big thanks to Cybliminal
#crikeycon
0
2
2
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
Come learn with Kelsy how to develop your cyber team as trustworthy within an org, rather than a compliance function, and how increasing levels of perceived legitimacy may allow security teams to further leverage employees as practical and informed resources!
0
4
3
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
Jumping on stage we have Simbo who will be talking all things SIEM in the talk "SIEM-less security; Panacea or placebo". Join us March 22 to see this talk and more at CrikeyCon. Get your ticket here:
events.humanitix.com/crikeycon-x
loading . . .
CrikeyCon X
Get Tickets on Humanitix - CrikeyCon X hosted by Droppy & The Sleuth. Royal International Convention Centre (Royal ICC), 600 Gregory Terrace, Bowen Hills QLD 4006, Australia. Saturday 22nd March 2025....
https://events.humanitix.com/crikeycon-x
0
3
3
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
We're excited to announce we have Georgia back on stage with us to present 'Hacking Minds not machines: How meetings not malware can compromise your controls'!
0
2
2
reposted by
Matthew Flanagan
cybliminal
about 1 year ago
Hey cyber people, Cybliminal have a ticket to
@crikeycon.bsky.social
X on 22nd March in Brisbane to giveaway. DM us if you are keen to attend.
0
3
2
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
Colby joins us on stage to talk Cyber security exercises D&D style. Get emersed through his talk on building scenarios and narrative, supporting player agency, and keeping things flowing in Tabletops & Dragons.
#crikeycon
1
4
2
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
Next up we have Zane on stage to dive into the anatomy of credential attacks, exploring how attackers exploit stolen credentials, bypass defences, and leverage automation to maximize their success. Does MFA work, how well, and what else can you do in 'Credential Stuffing Unmasked'?
0
3
3
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
This year NTT is supporting our Women of CrikeyCon event on 20th March. Women of CrikeyCon provide a chance for attendees identifying as women, friends, and the wider community to meet before CrikeyCon to promote diversity and inclusion. Register here:
events.humanitix.com/crikeycon-x-...
loading . . .
CrikeyCon X - Women of CrikeyCon networking event
Get tickets on Humanitix - CrikeyCon X - Women of CrikeyCon networking event. Venue provided after registering for a ticket. Thursday 20th March 2025. Find event information.
https://events.humanitix.com/crikeycon-x-women-of-crikeycon-networking-event
0
4
3
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
Exciting times! We have now published the events and presentation schedule for CrikeyCon X next week! crikeycon
crikeycon.com/schedule/
Workshops will be running on the day too - we'll send out details and registration forms to ticket holders soon...
loading . . .
CrikeyCon X
CrikeyCon X
https://crikeycon.com/schedule/
0
5
3
reposted by
Matthew Flanagan
dook
over 1 year ago
Less than 4 weeks to go till
@crikeycon.bsky.social
X! Woot! Check out our updated website for events, and speakers TBA announced soon.
www.crikeycon.com
loading . . .
CrikeyCon X
CrikeyCon X
https://www.crikeycon.com
0
5
3
reposted by
Matthew Flanagan
CrikeyCon
over 1 year ago
The Decipher Bureau crew are back both as Silver sponsors and running our CrikeyConnect. With massive experience recruiting for the cyber security industry, come grab a refreshment and get some tips on whatās happening in the job market.
0
6
4
Load more
feeds!
log in