Chief Analyst, Google Threat Intelligence Group. @CYBERWARCON and @SLEUTHCON founder. Johns Hopkins professor. Army vet.

Joined May 2011
2,997 Photos and videos
Pinned Tweet
What an amazing day. Thank you everyone who made #CYBERWARCON happen. I can’t express how great it was to see you after such a rough couple of years. We made it!
26
16
282
John Hultquist retweeted
"A Russian online sabotage network was behind a series of arson attacks on Sir Keir Starmer’s family home and other targets linked to the UK prime minister, an FT investigation has found." ft.com/content/dd79d6eb-44e4…
3
130
301
9,125
I think we can disagree about a piece of public art without anyone taking it personally. We owe it the fallen first and foremost to get it right. It’s meant to outlast their living memory and should be up to the task.
Fellow GWOT Veterans- I understand we all have strong feelings about the design concept of the GWOT Memorial. But remember who’s behind it: Rod Rodríguez, a 21-year Green Beret with 10 deployments from a multi-generational military family. His grandfathers served in WWII, father in Vietnam, his wife served 21 years with 6 deployments, and his son deployed to the same parts of Afghanistan he did. He was medically retired from his own combat injuries. Design co-chair Jennifer Ballou is a retired Army Master Sergeant, GWOT vet, and Gold Star spouse. While she was deployed in Afghanistan, her husband SSG Edwardo Loredo was killed by an IED just before his 35th birthday. Not only have they both sacrificed more than most in service to country, they’ve gathered feedback from over 20,000 GWOT veterans and families. This memorial is about honoring our fallen. Our collective personal preferences will never have 100% agreement, so we should resist trying to publicly destroy a concept that some will love, others dislike but regardless many Americans will see as a sacred place to honor those we loved who served and sacrificed their very lives. Use the GWOT Memorial Foundation survey for constructive input. Leaders and those with influence should request private conversations and avoid public attacks that could prejudice so many others. At the end of this process, our GWOT fallen deserve a memorial in a place of honor at the heart of DC. Whether it is this proposed design concept or one born out of feedback gathered now, let’s keep our focus on the mission of honoring those who gave their lives for us and the country they loved. 🇺🇸
1
6
1,547
John Hultquist retweeted
NEW: China arrested a US citizen after Trump met with Xi in Beijing and accused him of endangering national security — a rare charge against an American. The detainee, U Min Zin, is a grad student at @UCBerkeley who researches Myanmar. This adds a new strain to US-China ties.
69
291
527
299,102
Ugh
An early look at the @GWOTMF memorial planned for Washington, D.C, released today. It's planned on what are now athletic fields at the corner of Henry Bacon Drive and Constitution Avenue, near the Lincoln Memorial and Vietnam Veterans Memorial.
1
7
2,604
John Hultquist retweeted
Keep a lookout for what's right around the corner.
4
16
940
John Hultquist retweeted
New: Rep. Don Bacon, a frequent critic of Vladimir Putin and Moscow’s war in Ukraine, told POLITICO today the Russians recently hacked his Signal account. W/@magmill95 politico.com/live-updates/20…
1
13
34
6,038
John Hultquist retweeted
Microsoft addressed a whopping 206 vulnerabilities lurking in its vast portfolio of business products and foundational systems in this month’s Patch Tuesday update, marking the vendor’s largest monthly batch of security patches on record, according to researchers. scoopmedia.co/4ezSBE6
1
1
489
First look at Jeremy Strong as Mark Zuckerberg in ‘THE SOCIAL NETWORK’ sequel. The film follows an engineer who becomes a whistleblower on Facebook's most guarded secrets.
1
1
1,221
John Hultquist retweeted
With the @SLEUTHCON swag I really feel I am part of a gang 😈
3
16
1,694
Just hit a new PR
7
39
4,432
John Hultquist retweeted
🇨🇳 PLA Cyberspace Forces (CSF) Order of Battle. The map illustrates the locations of cyber and electronic units involved in targeting, collection, execution, and analysis. Each unit supports its respective Theater Command (TC) cyberdefensereview.army.mil/…
1
72
215
19,603
John Hultquist retweeted
#BREAKING The WH confirms the Apache was SHOT down by Iran
3
6
10
3,506
The Claude names all sound like clubs on Ibiza. Anyways here are my proposed names for Gemini variants: Gemboree Gemothy Chalomet Big Gem Gembo Gemmy Stewart Bard 2: Return of Bard
5
20
2,768
John Hultquist retweeted
red.anthropic.com/2026/n-day… - "As with our results on Firefox, this is where Mythos Preview shone. It not only produced a full chain exploit, but produced eight distinct exploits, at a cost of $15,700 in API credits—an average of about $2,000 per privilege escalation. The binding constraint to N-days is now just a few thousand dollars and API access, which expands the pool of capable N-day attackers dramatically."
3
11
1,148
John Hultquist retweeted
The current Ukrainian superiority in mid-range drone warfare is a brilliant advantage that comes with an expiration date. Failing to prepare for the day Russia matches this capability guarantees a catastrophic collapse of front line logistics for Ukraine. Ukraine is rightfully capitalizing on its drone edge to annihilate Russian transport networks in occupied zones. This structural disruption is hurting Russian logistics across the board. The problem is that the Kremlin is pouring massive resources into catching up, meaning this window of superiority will eventually close. When Russia deploys AI-enhanced mid-range strike drones at scale, any logistical movement within 100 kilometers of the front line faces destruction (on both sides). To survive, Ukraine must prepare immediately by layering multiple defensive measures. Securing future supply lines means installing more road nets, creating more specialized anti-drone drone units, adding cages to transport vehicles, shifting to logistical UGVs, and even building tunnels (when possible). This situation is a harsh wake-up call for Europe as well. Western doctrine relies heavily on the assumption that logistics remain somewhat safe beyond conventional artillery range. This is a dangerous misconception that modern drone warfare is permanently erasing, and European nations must watch and learn before it is too late
70
640
2,592
132,956
John Hultquist retweeted
Guess I need one of these now
118
338
3,513
364,315
John Hultquist retweeted
Thank you so much! It was so great to see you and all of the cyber crime defenders 🐍 💗
2
3
44
2,328
What an honor to spend the day with the cybercrimefighters who protect everything from kids to critical infrastructure. Thank you for coming out to @SLEUTHCON!
8
8
98
7,064
John Hultquist retweeted
Check out our blog on an activity we worked related to VerdantBamboo -- aka the TA that is known for wreaking havoc on edge devices and deploying BRICKSTORM. We found BRICKSTORM for BS on a pfSense firewall, new malware families, use of a 0day privesc, and custom VPN networks!
.@Volexity has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo. This case involved the breach of the victim organization’s MSP and multiple malware implants found on firewalls, cloud storage sync devices & NAS appliances. VerdantBamboo used a #0day privilege escalation exploit in the process and was also observed using administrative access to the victim organization's firewall to enable a custom VPN. For more details on how the incident unfolded, the malware used by the threat actor, and the end goal of the intrusion, check out the full blog post: volexity.com/blog/2026/06/04… #dfir
1
18
42
9,262
John Hultquist retweeted
🤓 This morning at @SLEUTHCON, I talked about how AI is being targeted and leveraged by cybercriminals. Which is beyond simply using models in their operations, attackers are also actively targeting AI environments themselves. That AI agent you trusted inside your organization is becoming a prime target because you don’t know what it is doing while it is running. And attackers know it. 💀
4
13
51
3,305