Matthew Flanagan
@mattimustang.com
📤 97
📥 57
📝 13
Director and Principal Cyber Security Consultant
@cybliminal.com
reposted by
Matthew Flanagan
Fabian Bader
5 days ago
@_dirkjan and my joint talk at
#TROOPERS25
is now available on YouTube. "Finding Entra ID CA Bypasses - the structured way"
@wearetroopers.bsky.social
youtu.be/yYQBeDFEkps
loading . . .
TROOPERS25: Finding Entra ID CA Bypasses - The Structured Way
YouTube video by TROOPERS IT Security Conference
https://youtu.be/yYQBeDFEkps
0
5
3
If you missed my talk at BSides Canberra you can catch up on it now on YouTube
add a skeleton here at some point
7 days ago
0
6
2
reposted by
Matthew Flanagan
CrikeyCon
16 days ago
Big shout out to
@cybliminal.com
our first silver sponsor this year! Massive hugs for the returning support; can't wait to see you out at the showgrounds.
1
4
5
reposted by
Matthew Flanagan
BSides Canberra
about 2 months ago
Lots of DMs asking for BSides Canberra 2025 talks — they’ll be on YouTube in a month+ 🎥 Speakers are reviewing their sessions first, so stay tuned! 👉
youtube.com/@bsidescanbe...
loading . . .
BSides Canberra
https://youtube.com/@bsidescanberra9688?si=uysWrSTGUBympWNq
0
3
1
reposted by
Matthew Flanagan
BSides Canberra
about 2 months ago
Celebrating 10 years of amazing artwork for BSides Canberra! 🎨 Huge thanks to Sydney-based Aussie Glenno for bringing our logos to life. Real artists > AI every time.
www.instagram.com/glennoart?ig...
0
2
1
Thanks again to
@bsidescbr.bsky.social
for inviting me to present my research on living off the land on Palo Alto Networks firewalls as well as sharing new tools I’ve developed to creatively misuse 😜 firewall features for credential harvesting and port scanning. Some great questions too!
2 months ago
0
6
3
Thanks again to
@bsidescbr.bsky.social
for inviting me to present my research on living off the land on Palo Alto Networks firewalls as well as sharing new tools I’ve developed to creatively misuse 😜 firewall features for credential harvesting and port scanning. Some great questions too!
2 months ago
1
0
0
reposted by
Matthew Flanagan
BSides Canberra
2 months ago
CTF early registration is now open! 🕹️ Get set up ahead of time so you’re ready to go when the CTF kicks off this Friday at BSides Canberra. Register here:
ctf.sk8boarding.dog
loading . . .
noCTF
https://ctf.sk8boarding.dog/
0
1
1
Just one week to go until I present the research from my “Panning for Gold: A Hacker’s Guide to Next Generation Firewalls” paper. Come along and listen to it at
@bsidescbr.bsky.social
if you’d like to up your post-exploitation game or learn how to better defend your environment.
add a skeleton here at some point
2 months ago
0
4
3
reposted by
Matthew Flanagan
Catalin Cimpanu
4 months ago
For the record, Expel silently updated their blog post to replace bypass with downgrade for this attack
add a skeleton here at some point
1
17
5
reposted by
Matthew Flanagan
BSides Canberra
5 months ago
This year at BSidesCbr, both the Main Track and the Off-Main Track will run across all three days. Main Track brings the big research, big ideas, and big names. Off-Main features beginner-friendly talks, deep dives, and unexpected gems—streamed to four theatrettes.
0
2
2
reposted by
Matthew Flanagan
BSides Canberra
5 months ago
"Decoding Threat Actors: a Free Tool for Mapping Aliases" Fancy Bear or Forest Blizzard? Qakbot or Pinkslipbot? Dave Matthews reveals a free tool to untangle the threat actor name game - linking aliases, malware families & public research.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Decoding Threat Actors: a Free Tool for Mapping Aliases and Taming the Name Game BSides Canberra 2025
Drowning in the chaos of Threat Actor aliases? Fancy Bear or Forest Blizzard? Wicked Panda or BRONZE ATLAS? And malware families? CageyChameleon or Cabbage RAT? Qakbot or Pinkslipbot? In this session...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/8NAQUJ/
0
1
1
reposted by
Matthew Flanagan
BSides Canberra
5 months ago
"Ding Dong the EDR is DEAD" EDR isn't invincible. Ayman Sagy walks through a real-world exploit against Palo Alto Cortex XDR - earning CVE-2024-8690 and a $2K bounty. See how it was done.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Ding Dong The EDR is DEAD BSides Canberra 2025
Endpoint Detection and Response (EDR) is the watchdog running on your endpoint to detect and respond to threats in real-time. However, like other defenses, it is not a foolproof solution. In this talk...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/D3KHPY/
1
1
1
reposted by
Matthew Flanagan
BSides Canberra
5 months ago
"Why Rust is Safe" Memory safety and C-level performance with no GC or runtime? Ben Williamson breaks down how Rust’s ownership model delivers safety guarantees at compile time, making it fit for kernels, firmware, and more.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Why Rust is Safe BSides Canberra 2025
C and C++ are awesome / terrible – they let you do whatever you want with pointers, resulting in all the tasty memory corruption vulnerabilities we know and love. Other languages impose a runtime or g...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/GVNQQF/
0
2
1
reposted by
Matthew Flanagan
BSides Canberra
5 months ago
"Reversing Bytecode into Bounties" Jira and Confluence plugins can hide serious vulns, if you know where to look. Giuliana and Jamal from Atlassian will show you how to decompile, scan, and exploit like a pro. Whitebox your way to bounties:
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Reversing Bytecode into Bounties: Uncovering Vulnerabilities in Jira and Confluence Plugins BSides Canberra 2025
Whitebox assessments are like unlocking the entire game map, and it's totally up to you to decide what’s worth exploring. Understanding how to decompile apps and navigate them will equip you with the ...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/DCEZKT/
0
1
1
reposted by
Matthew Flanagan
BSides Canberra
5 months ago
"Why I am (still) finding secrets in your code" Despite all the secret scanning tools, sensitive creds are still everywhere. Luke Marshall shares how he's found exposed secrets across ecosystems, and helped secure 40+ orgs. 🔗
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Why I am (still) finding secrets in your code BSides Canberra 2025
Despite the widespread availability of secret scanning tools, thousands of sensitive credentials continue to be exposed in popular open source ecosystems, a security blind spot that sparked my curiosi...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/UVADYW/
0
1
1
reposted by
Matthew Flanagan
BSides Canberra
5 months ago
"Bitsquatting dot
gov.au
domains" Ever blamed cosmic rays for DNS weirdness? Matt Belvedere explores a year of bitflip data in .gov.au traffic, digging into real-world bitsquatting and unexpected system-to-system auth.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
https://gov.au
0
1
1
reposted by
Matthew Flanagan
BSides Canberra
5 months ago
"DarkEngine – Researching a Global Phishing Campaign" nullifysecurity breaks down a large-scale phishing op that compromised 2,350+ WordPress sites via fake CAPTCHA lures.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
DarkEngine: Conducting Research into a Highly Orchestrated Phishing Campaign BSides Canberra 2025
In June 2025, CyberCX released a report on a highly orchestrated phishing campaign targeting popular WordPress hosting platform WP Engine, dubbed “DarkEngine”, which led to the compromise of at least ...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/DRR8KX/
0
1
1
reposted by
Matthew Flanagan
BSides Canberra
5 months ago
"Behind the Curtain of Dark Web and Cybercrime Operations" Join Alexander Wilczek as he reveals insights from a 4-year investigation into how cybercriminals move and launder money - using OSINT, blockchain tools, and strong OPSEC.
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
Behind the Curtain of Dark Web and Cybercrime Operations BSides Canberra 2025
A four-year investigation into cybercriminal financial operations. Following the money, examining how threat actors generate, transfer, and launder illicit proceeds. Including the operational security...
https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/NWWKSN/
0
1
1
I’m incredibly excited to be accepted by
@bsidescbr.bsky.social
to present my research on Next Gen Firewalls. I can’t wait to get up there for the first time to share it with you all!
add a skeleton here at some point
5 months ago
1
3
3
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
Justin's talk title speaks for itself: “Well well well, if it isn’t the consequences of my own actions” - the time I got in the middle of 100,000 Linux machines and their LVFS firmware updates and then somehow bypassed the fwupd PGP signature checking
0
2
2
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
Open source sits at the base of the software supply chain. Fraser talks about how critical it is for open source to establish security response teams and infrastructure. Listen to the experiences learned from bootstrapping and leading the Haskell security response team.
0
2
2
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
We're a week away and we wanted to say another big thank you to our sponsors. This year Cybliminal has joined us as a Silver sponsor! Big thanks to Cybliminal
#crikeycon
0
2
2
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
Come learn with Kelsy how to develop your cyber team as trustworthy within an org, rather than a compliance function, and how increasing levels of perceived legitimacy may allow security teams to further leverage employees as practical and informed resources!
0
4
3
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
Jumping on stage we have Simbo who will be talking all things SIEM in the talk "SIEM-less security; Panacea or placebo". Join us March 22 to see this talk and more at CrikeyCon. Get your ticket here:
events.humanitix.com/crikeycon-x
loading . . .
CrikeyCon X
Get Tickets on Humanitix - CrikeyCon X hosted by Droppy & The Sleuth. Royal International Convention Centre (Royal ICC), 600 Gregory Terrace, Bowen Hills QLD 4006, Australia. Saturday 22nd March 2025....
https://events.humanitix.com/crikeycon-x
0
3
3
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
We're excited to announce we have Georgia back on stage with us to present 'Hacking Minds not machines: How meetings not malware can compromise your controls'!
0
2
2
reposted by
Matthew Flanagan
cybliminal
9 months ago
Hey cyber people, Cybliminal have a ticket to
@crikeycon.bsky.social
X on 22nd March in Brisbane to giveaway. DM us if you are keen to attend.
0
3
2
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
Colby joins us on stage to talk Cyber security exercises D&D style. Get emersed through his talk on building scenarios and narrative, supporting player agency, and keeping things flowing in Tabletops & Dragons.
#crikeycon
1
4
2
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
Next up we have Zane on stage to dive into the anatomy of credential attacks, exploring how attackers exploit stolen credentials, bypass defences, and leverage automation to maximize their success. Does MFA work, how well, and what else can you do in 'Credential Stuffing Unmasked'?
0
3
3
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
This year NTT is supporting our Women of CrikeyCon event on 20th March. Women of CrikeyCon provide a chance for attendees identifying as women, friends, and the wider community to meet before CrikeyCon to promote diversity and inclusion. Register here:
events.humanitix.com/crikeycon-x-...
loading . . .
CrikeyCon X - Women of CrikeyCon networking event
Get tickets on Humanitix - CrikeyCon X - Women of CrikeyCon networking event. Venue provided after registering for a ticket. Thursday 20th March 2025. Find event information.
https://events.humanitix.com/crikeycon-x-women-of-crikeycon-networking-event
0
4
3
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
Exciting times! We have now published the events and presentation schedule for CrikeyCon X next week! crikeycon
crikeycon.com/schedule/
Workshops will be running on the day too - we'll send out details and registration forms to ticket holders soon...
loading . . .
CrikeyCon X
CrikeyCon X
https://crikeycon.com/schedule/
0
5
3
reposted by
Matthew Flanagan
dook
9 months ago
Less than 4 weeks to go till
@crikeycon.bsky.social
X! Woot! Check out our updated website for events, and speakers TBA announced soon.
www.crikeycon.com
loading . . .
CrikeyCon X
CrikeyCon X
https://www.crikeycon.com
0
5
3
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
The Decipher Bureau crew are back both as Silver sponsors and running our CrikeyConnect. With massive experience recruiting for the cyber security industry, come grab a refreshment and get some tips on what’s happening in the job market.
0
6
4
reposted by
Matthew Flanagan
CrikeyCon
9 months ago
Brand new at CrikeyCon X, Australia’s first-ever Meshtastic CTF event! Explore off-grid comms with our open-source, decentralised system using LoRa! Come with your LoRa kit (e.g. Heltec V3) and challenge our LoRa Mesh on March 22! [We've got a few to borrow.]
0
4
4
reposted by
Matthew Flanagan
CrikeyCon
10 months ago
Fantastic news, we've just cracked 400 tickets! We're a week away from announcing our talks and events, but one thing we can talk about is our new Meshtastic CTF extension. We have two friends switching on a cracking set of challenges, come join us to net some solid points!
0
4
4
reposted by
Matthew Flanagan
CrikeyCon
10 months ago
Meanwhile, bit of an update from events, some great progress and shaping up really nicely! We're looking at: 1. CTF (prizes for 1st, 2nd, 3rd, and 11th 😁) 2. A dedicated room for lockpicking! 3. A surprise update for the Post-con event (coming soon!)
1
2
2
reposted by
Matthew Flanagan
CrikeyCon
10 months ago
6 weeks to go, Droppy and the Sleuth are wrapping up reviews of the over 40 submissions! Some brilliant talks coming, we'll be sharing the schedule soon! Huge hugs for your support! If you haven't got your ticket yet, join us for our 10th birthday:
events.humanitix.com/crikeycon-x
2
1
1
reposted by
Matthew Flanagan
CrikeyCon
10 months ago
Thank you to everyone that's submitted for CFE and CFP, we've had a huge range and numbers. We're super excited to get to responding to each and every one of you! We'll have an update early next week.
0
5
3
reposted by
Matthew Flanagan
CrikeyCon
11 months ago
Cybliminal is joining us in 2025 as a Silver sponsor! Big hugs and thanks to the crew
@cybliminal.com
for your support!
0
3
3
reposted by
Matthew Flanagan
cybliminal
11 months ago
Excited to support
@crikeycon.bsky.social
as a 2025 Silver sponsor! Cybliminal is all about supporting hackers, builders, breakers, and defenders in the community. We can’t wait to see what is in store for next year + celebrate everything that makes this community amazing. C u there!
#CrikeyCon2025
add a skeleton here at some point
0
3
2
#PaloAltoNetworks
has just released a PANOS update, 10.2.13, which includes this interesting little fix. Looking at the portal logs from the management console or CLI I can't see any cleartext passwords being logged in regular or debug mode.
docs.paloaltonetworks.com/pan-os/10-2/...
12 months ago
1
1
0
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
Droppy and the Sleuth are open for 2024! Come join us:
events.humanitix.com/crikeycon-x
loading . . .
CrikeyCon X
Get Tickets on Humanitix - CrikeyCon X hosted by Droppy & The Sleuth. Royal International Convention Centre (Royal ICC), 600 Gregory Terrace, Bowen Hills QLD 4006, Australia. Saturday 22nd March 2025....
https://events.humanitix.com/crikeycon-x
0
9
7
reposted by
Matthew Flanagan
CrikeyCon
about 1 year ago
We hitting full throttle on our CFP already! Do you have something to share at CrikeyConX? Join us at:
docs.google.com/forms/d/e/1F...
loading . . .
CrikeyCon X (2025) Call for Presentations
*** CFP CLOSES 28th January 2025 *** Saturday March 22nd 2025 Royal International Convention Centre, Bowen Hills, Brisbane, QLD CrikeyCon is a community-led conference targeting those with an intere...
https://docs.google.com/forms/d/e/1FAIpQLSfaoH_LeG08HrrEaZn8irHAIrxqHsw7agJUItETm9kcUv-5bw/viewform
0
11
8
Most enterprise environments that I have seen would not be impact by this as the majority of their users have the portal address configuration locked down except for IT staff who may need to change it for troubleshooting purposes. 🧵
add a skeleton here at some point
about 1 year ago
1
1
0
you reached the end!!
feeds!
log in