Ben Read's Avatar

Ben Read

@benread

CTI ‪@wizsecurity.bsky.social‬ Adjuct at @jhu.edu - SAIS Previously NSC44, Mandiant, Google Go Mammoths

1,890
Followers
125
Following
124
Posts
21.06.2023
Joined
Posts Following

Latest posts by Ben Read @benread

Me in slack:

11.03.2026 13:58 👍 6 🔁 0 💬 0 📌 0

Pretty funny to work for an entity that can be abbreviated as BOFA and badly fall for a blatantly obvious trick

09.03.2026 13:36 👍 550 🔁 69 💬 10 📌 3
Post image

Kaspersky recently produced a podcast on Operation Triangulation, basically a story of the investigation

Things that I haven't seen mentioned elsewhere:
— Triangulation malware existed for >10 years
— Some technical details similar to the Equation Group

www.youtube.com/watch?v=j4pC...

06.03.2026 21:07 👍 9 🔁 2 💬 0 📌 0
Post image

A 1999 assessment by DoD OGC briefly mentions a draft treaty on information warfare that circulated on the Internet in 1995. Does anyone have any idea what it was or where on the Internet it could have been circulated?

(Source: nsarchive.gwu.edu/document/214...)

05.03.2026 01:25 👍 1 🔁 1 💬 0 📌 0

reading "Bombing to Win" on the subway and shaking my head to show everyone I'm against bombing to win

03.03.2026 18:43 👍 1078 🔁 109 💬 19 📌 6

I also have two affiliations with US universities in a similar situation, but it is somehow with the US Department of Defense.

03.03.2026 16:04 👍 3 🔁 1 💬 1 📌 0
Post image

While some cyber attacks from Iran might increase, keep in mind that many Iranian hackers face Internet shutdowns, instability caused by U.S./Israeli strikes, etc. So they won't be very active

Note this from a recent F6 report on Persian ransomware www.f6.ru/blog/c77l-ra...

02.03.2026 18:23 👍 1 🔁 1 💬 0 📌 0
Preview
The C.I.A. Helped Pinpoint a Gathering of Iranian Leaders. Then Israel Struck.

It's interesting how we keep seeing major publications getting reporting on successful high-stakes CIA operations and intelligence soon after they happen.

01.03.2026 14:43 👍 79 🔁 22 💬 3 📌 1
Preview
The Court, IEEPA, and the Legislative Veto We're all trying to find the guy who did this

My take on Learning Resources v. Trump: the elephant in the room in Chadha and the legislative veto.

fivepoints.mattglassman.net/p/the-court-...

27.02.2026 20:02 👍 22 🔁 7 💬 1 📌 3

You know who else posted a misleading video to "Enter Sandman"...

www.justice.gov/archives/opa...

27.02.2026 17:35 👍 4 🔁 0 💬 0 📌 0

/remembers a LetsRun post that was similar
/finds LetsRun post (www.letsrun.com/forum/flat_r...)
/letsrun post was 21 years ago
/crumbles into dust

27.02.2026 03:31 👍 1 🔁 0 💬 1 📌 0
Post image

I've been name checking Bombing to Win when we cover CNA in my Cyber Operations class for years, but now thanks to @sodrock.bsky.social , I can do it with a meme I don't fully understand.

26.02.2026 21:12 👍 22 🔁 1 💬 2 📌 1
Post image

SOS returns to Brussels on October 22, 2026!

As the geopolitical landscape rifts, hybrid threats continue to adapt & evolve. We provide a forum for observers of state-aligned sabotage, espionage, and more to share research with an action-oriented community.

Stay tuned for more announcements!

19.02.2026 21:37 👍 6 🔁 5 💬 0 📌 0

23 different Cinnamon Toast Crunch products in the thread now.

19.02.2026 21:43 👍 0 🔁 0 💬 0 📌 0
Post image

Tried this one. The peanut butter flavor is pretty subtle, so doesn't add much, but not bad either.

19.02.2026 21:41 👍 0 🔁 0 💬 0 📌 1

The US focused class of my and @hultquist.bsky.social "Global Cyber Operations" is on April 9, will we have a new cyber strategy to discuss by then? The race is on.

19.02.2026 21:40 👍 1 🔁 0 💬 0 📌 0
Preview
An Argument for Renewing the Administrative State The American administrative state, since its modern creation out of the New Deal and the post-WWII order, has proven that it can do great things. But it needs some reinvention first.

“We need not lose faith in the administrative state itself; we would do better to view it as having functioned with its hands tied tighter and tighter. But we are now starting, particularly in the climate and energy space, to hit real limits.” At @scientistsorg.bsky.social fas.org/publication/...

12.02.2026 21:03 👍 11 🔁 7 💬 1 📌 0
Preview
Desinformation aus Russland: Hacker enttarnt Netzwerk Seit Jahren schaut ein Hacker russischen Akteuren heimlich über die Schulter, während sie Desinformation verbreiten. Einblicke in eine Kampagne.

We have access to the data (could cross-check authenticity with a different leak we were able to obtain) and ran analysis on views counts to find out when the campaign seems to be effective (according to their own metrics)

www.zdfheute.de/politik/russ...

12.02.2026 17:40 👍 3 🔁 1 💬 0 📌 0
Preview
Google sent personal and financial information of student journalist to ICE | TechCrunch The tech giant handed over the personal information of a journalist and student who attended a pro-Palestinian protest in 2024. This is the latest example of ICE using its controversial subpoena power...

New, by @lorenzofb.bsky.social: Google sent personal and financial data about a student and journalist, who attended a pro-Palestine protest in 2024, to ICE agents in response to an "administrative subpoena," which had not been approved by a judge.

10.02.2026 20:48 👍 43 🔁 27 💬 2 📌 5
Post image

A site tracking recent purges in the PLA vs purges at the Trump-Hegseth Pentagon purge-comparison.vercel.app

09.02.2026 00:20 👍 142 🔁 60 💬 1 📌 4

To the pen testers, red teamers, and IR folks out there: How often are you encountering vibe coding in your engagements?

I'm curious whether and how often you're seeing vibe coded software leaving the door open to your clients' networks. @ me or DM me if you have thoughts.

04.02.2026 18:25 👍 5 🔁 3 💬 2 📌 1

That's a terrible decision by them. Really sorry you got impacted here.

04.02.2026 17:04 👍 2 🔁 0 💬 0 📌 0

100% endorse

02.02.2026 03:24 👍 0 🔁 0 💬 0 📌 0
George Washington
George Washington YouTube video by unvmebad86

I don't know why they need to make short AI films about the American Revolution when the perfect one was created 18 years ago www.youtube.com/watch?v=sbRo...

29.01.2026 19:47 👍 1968 🔁 675 💬 55 📌 64

Or do you mean, nearly the right flight times...

28.01.2026 19:14 👍 2 🔁 0 💬 0 📌 0
Preview
Attack Against Poland's Grid Disrupted Communication Devices at About 30 Sites The hackers behind a cyberattack that targeted Poland's grid infrastructure in December disabled communication devices for at least 30 sites across a number of energy facilities in different parts of ...

Hackers behind cyberattack against Poland electric grid in Dec disabled communication devices for at least 30 sites across a number of energy facilities in country. They rendered the devices - known as remote terminal units or RTUs - not only inoperable but also unrecoverable

28.01.2026 14:53 👍 25 🔁 23 💬 1 📌 2
Preview
Beyond Breaches: The Spectrum of Costs from Espionage and Pre-Positioning — CSINT What are the costs of cyber espionage? And how do they differ from those of operations designed to prepare for attack?

New Publication Alert: It is my pleasure to share that my recent report – coauthored with Alexander Leslie and Taylor Grossman through the Center for Security, Innovation, and New Technology (CSINT) at American University – is now live. 1/8

www.au-csint.com/publications...

27.01.2026 16:16 👍 0 🔁 2 💬 1 📌 0

"stop pretending Jesus was crucified because he preached good vibes and personal growth"

25.01.2026 22:54 👍 149 🔁 26 💬 1 📌 1

#BREAKING #ESETresearch identified the wiper #DynoWiper used in an attempted disruptive cyberattack against the Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malware’s design clearly indicates destructive intent. 1/5

23.01.2026 16:30 👍 34 🔁 30 💬 1 📌 5