Matthijs R. Koot

528 Followers
45 Following
54 Posts
IT, privacy, security, democracy. PhD. Employed as IT security specialist. PGP: 51F9 8FC9 C92A 1165 (http://keybase.io/mrkoot). Bluesky: @cyberwar.nl. LinkedIn: /in/mrkoot.

Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway (18 March 2026) https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government

“[…] The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an internal government report reviewed by ProPublica.
Or, as one member of the team put it: “The package is a pile of shit.” […]”

Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway.

A federal program created to protect the government against cyber threats authorized a sprawling Microsoft cloud product, despite the company’s inability to fully explain how it protects sensitive data.

ProPublica

Lost in translation: How Russia’s new elite hit squad was compromised by an idiotic lapse in tradecraft (13 March 2026) https://theins.press/en/inv/290235

“[…] The Insider has managed to identify all of the key leaders and sponsors [of Center 795], determine its location, and pinpoint its main areas of activity. One of its officers […] was caught because he handled an agent using Google Translate. […]”

Lost in translation: How Russia’s new elite hit squad was compromised by an idiotic lapse in tradecraft

Center 795, which emerged after the start of Russia's full-scale war in Ukraine and comprises elite units from the GRU and FSB, was established as a top-secret and fully autonomous entity designed to carry out the most critical operations, ranging from military missions in Ukraine to political assassinations and abductions abroad. The Insider has managed to identify all of the center’s key leaders and sponsors, determine its location, and pinpoint its main areas of activity. One of its officers has already been arrested in Colombia on charges of organizing the kidnapping of multiple regime opponents. He was caught because he handled an agent using Google Translate.

The Insider
“[…] Senator Ron Wyden says that when a secret interpretation of Section 702 is eventually declassified, the American public “will be stunned” to learn what the NSA has been doing. If you’ve followed Wyden’s career, you know this is not a man prone to hyperbole — and you know his track record on these warnings is perfect. […]” (12 March 2026, by Mike Masnick) https://www.techdirt.com/2026/03/12/the-wyden-siren-goes-off-again-well-be-stunned-by-what-the-nsa-is-doing-under-section-702/
The Wyden Siren Goes Off Again: We’ll Be “Stunned” By What the NSA Is Doing Under Section 702

Senator Ron Wyden says that when a secret interpretation of Section 702 is eventually declassified, the American public “will be stunned” to learn what the NSA has been doing. If you&#8…

Techdirt
🇪🇺🎉 HUGE VICTORY! Thanks to your protests, the EU Parliament voted today to END untargeted mass scanning! 💪
But beware: The final decision will now be made in the trilogue with EU governments. The fight continues! ⚔️
All info: https://www.patrick-breyer.de/en/historic-chat-control-vote-in-the-eu-parliament-meps-vote-to-end-untargeted-mass-scanning-of-private-chats/
The eID Wallet still doesn’t deserve your full trust (10 March 2026) https://edri.org/our-work/the-eid-wallet-still-doesnt-deserve-your-full-trust/ by EDRi / @edri
🇪🇺🚨 #ChatControl: Next Wednesday, our EU reps are set to approve mass scans of private chats after all! 📱👀
Clearly against so far: only Greens/Pirates & the Left.
Want to ask or convince your MEPs? Email or (better) call them: 👇
🔗 https://fightchatcontrol.eu/#delegates
Fight Chat Control - Protect Digital Privacy in the EU

Learn about the EU Chat Control proposal and contact your representatives to protect digital privacy and encryption.

We found that Wi-Fi client isolation can often be bypassed. This allows an attacker who can connect to a network, either as a malicious insider or by connecting to a co-located open network, to attack others.

NDSS'26 paper: https://www.ndss-symposium.org/wp-content/uploads/2026-f1282-paper.pdf
GitHub: https://github.com/vanhoefm/airsnitch

High-level article on the work by Dan Goodin: https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/ I'd say we bypass Wi-Fi encryption though, in the sense that we can bypass client isolation. We don't break Wi-Fi authentication or encryption. Crypto is often bypassed instead of broken. And we bypass it ;) If you don't rely on client/network isolation, you are safe: we can't just break any Wi-Fi network.

WSJ adds to the Guardian's reporting abt Tulsi whistleblower complaint It pertains at least in part to Iran. www.wsj.com/politics/nat...

Well this is intriguing. https://www.theguardian.com/us-news/2026/feb/07/nsa-foreign-intelligence-trump-whistleblower

Last spring, the National Security Agency (NSA) flagged an unusual phone call between two members of foreign intelligence, who discussed a person close to Donald Trump, according to a whistleblower’s attorney who was briefed on details of the call.

The highly sensitive communique, which has roiled Washington over the past week, was brought to the attention of the director of national intelligence (DNI), Tulsi Gabbard.

But rather than allowing NSA officials to distribute the information further, Gabbard took a paper copy of the intelligence directly to the president’s chief of staff, Susie Wiles, according to the whistleblower’s attorney, Andrew Bakaj.

One day after meeting Wiles, Gabbard told the NSA not to publish the intelligence report. Instead, she instructed NSA officials to transmit the highly classified details directly to her office, Bakaj said.

NSA detected foreign intelligence phone call about a person close to Trump

Whistleblower says that Tulsi Gabbard blocked agency from sharing report and delivered it to White House chief of staff

The Guardian
Somebody used spoofed ADSB signals to raster the meme of JD Vance over Mar-a-Lago using AF2 ICAO identity (28 January 2026) https://alecmuffett.com/article/143548 by @alecm
Somebody used spoofed ADSB signals to raster the meme of JD Vance over Mar-a-Lago using AF2 ICAO identity

This, if it is still visible: Via: Next up, age verification for ADSB?

Dropsafe