Matthew Flanagan
@mattimustang.com
94 followers 57 following 12 posts
Director and Principal Cyber Security Consultant @cybliminal.com
Posts Media Videos Starter Packs
Reposted by Matthew Flanagan
Lots of DMs asking for BSides Canberra 2025 talks — they’ll be on YouTube in a month+ 🎥 Speakers are reviewing their sessions first, so stay tuned!

👉 youtube.com/@bsidescanbe...
BSides Canberra
youtube.com
Reposted by Matthew Flanagan
Celebrating 10 years of amazing artwork for BSides Canberra! 🎨 Huge thanks to Sydney-based Aussie Glenno for bringing our logos to life. Real artists > AI every time.

www.instagram.com/glennoart?ig...
Thanks again to @bsidescbr.bsky.social for inviting me to present my research on living off the land on Palo Alto Networks firewalls as well as sharing new tools I’ve developed to creatively misuse 😜 firewall features for credential harvesting and port scanning.
Some great questions too!
Thanks again to @bsidescbr.bsky.social for inviting me to present my research on living off the land on Palo Alto Networks firewalls as well as sharing new tools I’ve developed to creatively misuse 😜 firewall features for credential harvesting and port scanning.
Some great questions too!
Reposted by Matthew Flanagan
CTF early registration is now open! 🕹️
Get set up ahead of time so you’re ready to go when the CTF kicks off this Friday at BSides Canberra.

Register here: ctf.sk8boarding.dog
noCTF
ctf.sk8boarding.dog
Just one week to go until I present the research from my “Panning for Gold: A Hacker’s Guide to Next Generation Firewalls” paper. Come along and listen to it at @bsidescbr.bsky.social if you’d like to up your post-exploitation game or learn how to better defend your environment.
I’m incredibly excited to be accepted by @bsidescbr.bsky.social to present my research on Next Gen Firewalls. I can’t wait to get up there for the first time to share it with you all!
"Panning for Gold - A Hacker's Guide to Next Generation Firewalls"
What happens when a firewall stops being the defence and becomes the foothold?
@mattimustang.com explores real-world tactics for abusing NGFWs: credential theft, mapping, lateral movement.
cfp.bsidescbr.com.au/bsides-canbe...
Reposted by Matthew Flanagan
For the record, Expel silently updated their blog post to replace bypass with downgrade for this attack
-New phishing technique bypasses FIDO keys
-Surveillance vendor deploys new SS7 exploit
-South Korea's largest insurance provider gets ransomed
-Europol take down NoName057 servers
-Australia to create a cyber reserves force

Podcast: risky.biz/RBNEWS453/
Newsletter: news.risky.biz/risky-bullet...
Reposted by Matthew Flanagan
This year at BSidesCbr, both the Main Track and the Off-Main Track will run across all three days.

Main Track brings the big research, big ideas, and big names.
Off-Main features beginner-friendly talks, deep dives, and unexpected gems—streamed to four theatrettes.
Reposted by Matthew Flanagan
Reposted by Matthew Flanagan
Reposted by Matthew Flanagan
Reposted by Matthew Flanagan
"Bitsquatting dot gov.au domains"
Ever blamed cosmic rays for DNS weirdness? Matt Belvedere explores a year of bitflip data in .gov.au traffic, digging into real-world bitsquatting and unexpected system-to-system auth.
cfp.bsidescbr.com.au/bsides-canbe...
gov.au
Reposted by Matthew Flanagan
I’m incredibly excited to be accepted by @bsidescbr.bsky.social to present my research on Next Gen Firewalls. I can’t wait to get up there for the first time to share it with you all!
Reposted by Matthew Flanagan
Justin's talk title speaks for itself: “Well well well, if it isn’t the consequences of my own actions” - the time I got in the middle of 100,000 Linux machines and their LVFS firmware updates and then somehow bypassed the fwupd PGP signature checking
Reposted by Matthew Flanagan
Open source sits at the base of the software supply chain. Fraser talks about how critical it is for open source to establish security response teams and infrastructure. Listen to the experiences learned from bootstrapping and leading the Haskell security response team.
Reposted by Matthew Flanagan
We're a week away and we wanted to say another big thank you to our sponsors. This year Cybliminal has joined us as a Silver sponsor! Big thanks to Cybliminal #crikeycon
Reposted by Matthew Flanagan
Come learn with Kelsy how to develop your cyber team as trustworthy within an org, rather than a compliance function, and how increasing levels of perceived legitimacy may allow security teams to further leverage employees as practical and informed resources!
Reposted by Matthew Flanagan
Reposted by Matthew Flanagan
We're excited to announce we have Georgia back on stage with us to present 'Hacking Minds not machines: How meetings not malware can compromise your controls'!
Reposted by Matthew Flanagan
Hey cyber people, Cybliminal have a ticket to @crikeycon.bsky.social X on 22nd March in Brisbane to giveaway. DM us if you are keen to attend.