News: 1672921811

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Twitter whistleblower Peiter 'Mudge' Zatko lands new gig at Rapid7

(2023/01/05)


Updated Former Twitter security chief and whistleblower Peiter "Mudge" Zatko has landed his first official role since he left the company, a part-time job as "executive in residence" with cybersecurity firm Rapid7.

Rapid7 describes itself as a company that "unites cloud risk management and threat detection." The biz offers pentesting along with other tools and services. It also owns the open source exploit project Metasploit.

In Zatko's new position, he'll be [1]reportedly advising execs, customers and board members on the use of data for cybersecurity issues.

[2]

CEO Corey Thomas told The Washington Post, which broke the story, that Zatko's "candor" would be welcome at the company.

[3]

[4]

Zatko has a reputation for both bluntness and skill that only solidified after he was fired from Twitter. His departure was allegedly over fundamental disagreements with former boss Parag Agrawal about disclosing security issues to the company's board, although Twitter told The Register in August that Zatko was "fired from his senior executive role at Twitter in January 2022 for ineffective leadership and poor performance."

Mudge [5]received a $7.75 million severance package for his services, which might explain why his new job is part-time.

[6]

Zatko [7]filed a complaint with the US Securities and Exchange Commission, the Federal Trade Commission and the Justice Department that among other things Twitter failed to comply with a 2011 FTC Consent Order. It also painted Twitter IT operations as a circus, complete with non-compliant operating systems, outdated security and insufficient threat detection.

[8]Twitter savaged by former security boss Mudge in whistleblower complaint

[9]Analysis of leaked Conti files blows lid off ransomware gang

[10]Recycled Cobalt Strike key pairs show many crooks are using same cloned installation

[11]Musk seeks yet another excuse to get out of Twitter buyout: This time it's Mudge's severance check

Furthermore, thousands of workers were said to have access to live production systems and user data, and some had allegedly installed spyware on their computers on behalf of foreign intelligence.

In September, Zatko [12]appeared before the Senate Judiciary Committee and stated that pre-Musk Twitter's "security failures threaten national security, compromise the privacy and security of users, and at times threaten the very continued existence of the company."

'90s hacker collective man turned infosec VIP: Internet security hasn't improved in 20 years [13]READ MORE

Prior to Twitter, Zatko was a well-known former member of the Cult of the Dead Cow hacking group, where he went by the alias Mudge, as well as legendary hacker collective [14]L0pht , [15]which appeared before Congress in 1998 .

As we noted in our 2018 interview with L0pht luminary Chris Wysopal, the group released numerous security advisories and developed [16]L0phtCrack , a password cracker for Windows NT. When Microsoft said a vulnerability was only theoretical, L0pht responded by creating an exploit and adopted the slogan "Making the theoretical practical since 1992."

Since then, he's worked for Google, Stripe and the Department of Defense.

But the new Rapid7 employee isn't the only person associated with the company that has beef with Twitter. Co-founder Chad Loder has [17]reportedly had his account banned. Loder is an activist and antifascist infoseccer who investigated the January 6 insurrection attempt and believes he was purged due to a raft of changes during Musk's attempt to overhaul the site.

[18]

The Reg asked Mudge and Rapid7 to comment for this story and will report back if there is substantial reply. ®

Updated at 15.11 UTC on January 5 to add:

Rapid7 CEO and Chairman Corey Thomas sent us a statement:

"Peiter and I have a longstanding relationship and have spoken at length about the importance of data and research when it comes to measuring cybersecurity program effectiveness.

"In order to move our industry forward, we must educate organizations on how and what to measure to ensure we are making the right investment. Peiter's extensive experience in this field and his work around measuring cyber security practices will be invaluable for both Rapid7 and our customers."

Get our [19]Tech Resources



[1] https://www.wsj.com/articles/twitter-whistleblower-joins-rapid7-a-cybersecurity-company-11672870454

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y7cCL0eMYkdF1bFqE45PXAAAANg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y7cCL0eMYkdF1bFqE45PXAAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y7cCL0eMYkdF1bFqE45PXAAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/09/13/twitter_says_775m_severance_payment/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y7cCL0eMYkdF1bFqE45PXAAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/08/23/twitter_security_whisterblower/

[8] https://www.theregister.com/2022/08/23/twitter_security_whisterblower/

[9] https://www.theregister.com/2022/03/11/conti_leaks_code/

[10] https://www.theregister.com/2021/10/22/cobalt_strike_virustotal_key_discovery/

[11] https://www.theregister.com/2022/09/13/twitter_says_775m_severance_payment/

[12] https://www.theregister.com/2022/09/14/twitter_mudge_senate/

[13] https://www.theregister.com/2018/06/18/l0pht_chris_wysopal_interview/

[14] https://www.theregister.com/2020/11/17/peiter_zatko_twitter_security_chief/

[15] https://www.theregister.com/2018/06/18/l0pht_chris_wysopal_interview/

[16] https://www.theregister.com/2016/09/01/l0phtcracks_back_crack_hack_app_whacks_windows_10_trash_hashes/

[17] https://theintercept.com/2022/11/29/elon-musk-twitter-andy-ngo-antifascist/

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y7cCL0eMYkdF1bFqE45PXAAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[19] https://whitepapers.theregister.com/



NoneSuch

"'fired from his senior executive role at Twitter in January 2022 for ineffective leadership and poor performance.'

Mudge received a $7.75 million severance package for his services, which might explain why his new job is part-time."

Wow, wish I was fired for "poor performance" and got almost 8 million severance. Imagine the rewards for not pissing people off. At least he got out before 'peak Twitter' while they still had money to spend.

Way to climb the ladder

Anonymous Coward

very cool to see his history, and how far he was able to go.

I'm far from his last position, but it makes me sick sometimes when I make security recommendations and the company decides otherwise and implements dangerous practices. I keep my opinion documented - just incase. I will not take the blame in court for their foolish decisions.

January 6 Insurrection

Lil Endian

Wait? What?! But... but, that's tomorrow!

Great Scott! Bolt all the doors; hammer large pieces of crooked wood against all the windows!

Edwin Meese made me wear CORDOVANS!!