Matthew Conway
@mattreduce.com
📤 833
📥 445
📝 148
🔍 Threat Intelligence @ Remitly ✍️ CTI newsletter and blog
@sourcesmethods.com
I watch Heated Rivalry for the Russian dialogue, okay? 🏒
11 days ago
0
4
0
Leftovers sandwich 😌
28 days ago
0
3
0
reposted by
Matthew Conway
Sources & Methods
about 1 month ago
What are they up to at Matt's in the Market in Seattle? 👀
0
3
1
reposted by
Matthew Conway
Nick Frichette
about 1 month ago
Currently backed myself into a corner by ignoring my own advice: When researching vulns in a cloud service, learn how the service works BEFORE you start hunting. Do it in the reverse order and you’ll end up with a vuln you can’t tie to real impact, because you never learned how harm could occur.
0
5
1
reposted by
Matthew Conway
The Vertex Project
about 1 month ago
ICYMI:
@sentinelone.com
released a new Synapse power-up for Validin giving analysts faster pivots across DNS history, certs, WHOIS + web content to reveal hidden related infrastructure. Get the full story here:
www.sentinelone.com/labs/threat-...
loading . . .
Threat Hunting Power Up | Enhance Campaign Discovery With Validin and Synapse
Accelerate adversary tracking and reveal hidden infrastructure with our open-source Synapse Rapid Power-Up for Validin.
https://www.sentinelone.com/labs/threat-hunting-power-up-enhance-campaign-discovery-with-validin-and-synapse/
0
5
2
reposted by
Matthew Conway
Obsidian
about 1 month ago
You can now convert your Notion pages and databases to durable, private, local files. Your data, offline, forever, for free.
loading . . .
9
281
56
reposted by
Matthew Conway
Jerry Chen
about 2 years ago
i don't know why we wouldn't just have a big meal on thursday and take friday off, every week
5
80
17
Well, I've finally installed the Partiful app. Reached critical mass of events to prepare for in a short period (admittedly a good problem to have) 🫨
about 2 months ago
0
0
0
reposted by
Matthew Conway
80s News Screens
11 months ago
0
23
9
reposted by
Matthew Conway
CRIMINAL SIMPSONS
about 2 months ago
8
357
76
reposted by
Matthew Conway
Sources & Methods
about 2 months ago
If the talks at
@cyberwarcon.bsky.social
today are any indication, while you may think threat actor adoption of generative AI improves sophistication and eliminates telling mistakes in phishing and info ops, that future is not evenly distributed!
0
5
3
Kabob Palace is the move 🤤
about 2 months ago
1
4
0
reposted by
Matthew Conway
Unusual Whales
about 2 months ago
HOLY SHIT. Unusual Whales has been mentioned BY NAME in the US Congressional hearing on getting US Congress banned from stock trading. "Get on that Unusual Whales site...this is pathetic folks, we all know what is going on [on stock trading]" Said by Rep Tim Burchett!
loading . . .
33
789
136
reposted by
Matthew Conway
Meduza in English
about 2 months ago
A former Russian military cartographer told Mediazona that Moscow’s battlefield maps are often grossly inaccurate. He also compared the Russian army to the Third Reich, saying many soldiers know the war in Ukraine is “criminal and unwinnable.”
meduza.io/en/feature/2...
loading . . .
‘Total nonsense’: A former Russian military cartographer on how the army cooks its maps to exaggerate gains — Meduza
Battlefield maps are one of Russia’s favorite propaganda tools. While the Russian army has, on average, advanced at a snail’s pace this year, dramatic visuals from its Defense Ministry and pro-war…
https://meduza.io/en/feature/2025/11/19/total-nonsense-a-former-russian-military-cartographer-on-how-the-army-cooks-its-maps-to-exaggerate-gains
1
30
18
reposted by
Matthew Conway
Sources & Methods
about 2 months ago
Great talk by
@pylos.co
on possible futures for Volt Typhoon and why the cluster's strategic goal means the activity will evolve and at times be disrupted but not stop any time soon
0
3
3
reposted by
Matthew Conway
Sources & Methods
about 2 months ago
Now I can say I've seen a DPRK IT Worker (recorded) on a video call, thanks to Caleb Marquis and Eric Kerr! Next up is
@pylos.co
on Volt Typhoon.
1
2
1
reposted by
Matthew Conway
Sources & Methods
about 2 months ago
Kicked off
@cyberwarcon.bsky.social
with
@dmitri.silverado.org
apologizing for 15yrs of threat actor naming chaos and proposing a new scheme, and plenty of Russia-related content (with top-tier memes)
0
2
1
reposted by
Matthew Conway
Sources & Methods
about 2 months ago
Watching
@bsidespyongyang.bsky.social
on the way to
@cyberwarcon.bsky.social
twitch.tv/BSidesPyongy...
loading . . .
BSidesPyongyang - Twitch
BSides Pyongyang 2025
https://m.twitch.tv/BSidesPyongyang?desktop-redirect=true
0
0
1
Fix me, brisket pho 🍲
about 2 months ago
1
1
0
reposted by
Matthew Conway
molly
about 2 months ago
we gotta start calling people pipsqueaks again
4
69
11
Just finished the season, there was more than good music 👍
add a skeleton here at some point
about 2 months ago
0
2
0
reposted by
Matthew Conway
Jamie Levy 🦉
about 2 months ago
There's an open role for a Staff CTI Analyst on my team here
@huntress.com
📢💫 ✨Do you love doing correlations between different incidents, sometimes digging into them, or doing malware analysis? ✨Do you like doing data analysis, and using this to make threat reports? 👇
1
7
5
reposted by
Matthew Conway
Joe Slowik
2 months ago
As we head into roast/full bird/etc season in the northern hemisphere, remember at min an instant read thermometer is your best friend
2
10
2
reposted by
Matthew Conway
CRIMINAL SIMPSONS
2 months ago
0
262
58
reposted by
Matthew Conway
sydney
2 months ago
October delivered AI agents, time mastery, and purple team curveballs. From scaling hunts like code to aligning GRC with threat-informed defense, this month’s Dispatch lineup from
@thorcollective.bsky.social
hit every layer of the stack. Full recap here:
dispatch.thorcollective.com/p/dispatch-d...
loading . . .
Dispatch Debrief: October 2025
Seven Dispatch drops that prove hunting smarter beats hunting harder.
https://dispatch.thorcollective.com/p/dispatch-debrief-october-2025
1
2
1
Jetlagged 😴
add a skeleton here at some point
2 months ago
0
3
0
reposted by
Matthew Conway
Will T
3 months ago
New Blog! Lessons from the BlackBasta Ransomware Attack on Capita When a company that manages data for millions of UK citizens falls victim to ransomware, the whole industry should pay attention to it. 📝
blog.bushidotoken.net/2025/10/less...
loading . . .
Lessons from the BlackBasta Ransomware Attack on Capita
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
https://blog.bushidotoken.net/2025/10/lessons-from-blackbasta-ransomware.html
0
8
2
reposted by
Matthew Conway
evacide
3 months ago
If your protest privacy/security advice does not start with a discussion of threat models, it is probably not good advice.
1
203
56
reposted by
Matthew Conway
Sig. Ug.
3 months ago
Finally a convincing use case for the blockchain: bulletproof hosting.
add a skeleton here at some point
0
6
2
House of Guinness so far: there's Fontaines D.C. and Kneecap!
3 months ago
1
1
1
reposted by
Matthew Conway
Bellingcat
3 months ago
Satellite analysis by Bellingcat found that wildfires destroyed over a third of Namibia’s most visited wildlife reserve last month, impacting crucial grazing lands for endangered species, including black rhinos and elephants.
www.bellingcat.com/news/2025/10...
loading . . .
Wildfires Ravage One of Africa’s Largest Nature Reserves - bellingcat
Satellite analysis of the Etosha wildfires in Namibia has found that more than a third of the nature reserve was burned.
https://www.bellingcat.com/news/2025/10/07/wildfires-ravage-one-of-africas-largest-nature-reserves/
5
180
98
reposted by
Matthew Conway
kepano
3 months ago
Just updated my vault template to show how I use the new Maps feature for Obsidian Bases. Super useful for travel planning.
3
133
9
a-ha are actually underrated
3 months ago
0
1
0
reposted by
Matthew Conway
utopia deferred
4 months ago
One must imagine Sisyphus cracking open a cold one
5
82
18
Is there a generic term for "mouse jigglers" and apps like Caffeine? Apps that keep systems from locking, sleeping, or that simulate normal activity. Keepalives? Mouse movers? There has to be something more succinct. 🤔
4 months ago
0
2
0
reposted by
Matthew Conway
Jamie Finnigan
4 months ago
Got kids who want a friendly introduction to Python? Get them to check out
learnpy.dev
, an interactive, web-based introduction to coding in Python. I built it for my 9 & 11 year-olds... maybe it'll be useful for others?
loading . . .
Want To Learn Some Python?
learnpy.dev is an interactive, web-based introduction to coding in Python.
https://learnpy.dev/
0
4
1
reposted by
Matthew Conway
Active Measures, LLC
4 months ago
When the overnight low slips to 49
3
197
22
reposted by
Matthew Conway
CYBERWARCON
4 months ago
CYBERWARCON is coming!!! Registration and CFP are now open for this year's
#CYBERWARCON
! This year's keynote speaker will be
@dmitri.silverado.org
!! We are back in Arlington, VA this year on November 19th.
www.cyberwarcon.com
loading . . .
CYBERWARCON
https://www.cyberwarcon.com
1
29
31
reposted by
Matthew Conway
Kevin Rothrock
4 months ago
Russia’s postal service joins others worldwide in halting parcel delivery to the U.S. after Trump ends the de minimis duty-free rule. For nearly 90 years, the exemption has allowed packages valued below a rising set threshold (raised to $800 in 2015) to enter duty-free. Not after Friday.
loading . . .
«Почта России» приостановила прием посылок в США из-за торговых тарифов
Подробнее на сайте
https://www.kommersant.ru/doc/7990283?from=top_main_4
0
19
8
reposted by
Matthew Conway
Thomas Brewster
4 months ago
🚨NEW🚨 Russia is mandating a new VK messaging app called Max. We had some researchers take a look and—surprise, surprise—it's tracking basically everything users do. “This app just gathers all the data and logs it. I don’t remember seeing that in any messenger app."
www.forbes.com/sites/thomas...
loading . . .
Kremlin-Mandated Messaging App Max Is Designed To Spy On Users
Security researchers found that Max, which Russia will require to be pre-installed on all phones, is designed to track users, confirming fears the app will be used for surveillance.
https://www.forbes.com/sites/thomasbrewster/2025/08/26/kremlin-whatsapp-rival-is-designed-to-spy-on-users/
4
71
51
reposted by
Matthew Conway
Sources & Methods
4 months ago
Sources & Methods
#CTI
newsletter issue 25 is out with more articles, tools, and conferences for you 📨
sourcesmethods.com/sources-meth...
loading . . .
Sources & Methods Newsletter #25 - August 2025
Hello again! I'm glad to share this month that I joined Remitly to help build their Threat Intelligence program, ensuring the safety and security of a vital financial service for millions around the w...
https://sourcesmethods.com/sources-methods-newsletter-25/
0
1
1
reposted by
Matthew Conway
Retro Commercial Screens
5 months ago
13
312
98
reposted by
Matthew Conway
DPRK CERT
5 months ago
Supreme Leader needs IT workers like you! Apply today!
0
2
1
Starting an exciting new chapter as a Threat Intelligence Engineer at Remitly. 🎉 Stoked about the new team and opportunity to protect a service that's vital for many people around the world.
5 months ago
1
4
0
reposted by
Matthew Conway
Meduza in English
5 months ago
The only foolproof way to avoid getting arrested at the Russian border is not to go. Still, over 20,000 people from E.U. countries have made the trip this year anyway. If you’re determined to join them, at least read this first.
meduza.io/en/cards/jew...
loading . . .
Jewelry, medicine, books, oh my! Plenty of seemingly innocuous items have landed travelers in trouble at Russia’s border. Here’s how to avoid it. — Meduza
No matter how normalized Russia’s invasion of Ukraine and its political arrests may have become, the country remains unsafe for tourism. Nevertheless, many people are still going: in 2024, more than…
https://meduza.io/en/cards/jewelry-medicine-books-oh-my
0
12
1
reposted by
Matthew Conway
Grant Marek
5 months ago
“Most people know what they’re getting into,” she said of the hike to the inn along state park access roads/trails. “There just is something really old-fashioned about that ... I continue to be blown away by the amount of enthusiasm and happiness.” via
@sfgate.com
www.sfgate.com/food/article...
loading . . .
The viral Bay Area pancake breakfast that you can't drive to
Now, 1,000 people at a single event is commonplace.
https://www.sfgate.com/food/article/viral-bay-area-pancake-hike-marin-20786432.php
1
7
3
reposted by
Matthew Conway
Pasquale Stirparo 🇺🇦 🇪🇺
5 months ago
🍎 machofile 🍏 first official release is finally live:
github.com/pstirparo/ma...
It is a python module to parse
#Mach-O
binary files, with a focus on malware analysis and reverse engineering. machofile is self-contained.
#macho
#ios
#reverseengineering
#detection
#threathunting
#threatintel
1/3
loading . . .
GitHub - pstirparo/machofile: machofile is a module to parse Mach-O binary files
machofile is a module to parse Mach-O binary files - pstirparo/machofile
https://github.com/pstirparo/machofile
1
15
14
reposted by
Matthew Conway
Electronic Frontier Foundation
5 months ago
EFF fights surveillance…and we do so in 14 languages in our educational resource, Surveillance Self-Defense.
loading . . .
Surveillance Self-Defense
We’re the Electronic Frontier Foundation, a member-supported non-profit working to protect online privacy for over thirty years. This is Surveillance Self-Defense: our expert guide to protecting you a...
https://ssd.eff.org/
1
131
55
Load more
feeds!
log in