Mat Clark
banner
secureinseconds.com
Mat Clark
@secureinseconds.com
Building ReadRoost — Duolingo for IT Certs | 50,000+ practice questions across AWS, Azure, GCP & more | Author of S.E.C.U.R.E. | Adelaide
readroo.st
Token theft beats MFA: a stolen token replays as the user and leaves no odd sign-in to alert on. CISA and NIST released IR 8587 on 15 September. The gap is logging: https://secureinseconds.com/blog/2026-09-20-cloud-identity-token-theft-cisa-nist-playbook
September 24, 2026 at 1:00 AM
ISC2 changed three things in 2026: the CISSP waiver list was cut, the CC exam outline was rebuilt from 1 September, and free CC vouchers expire on 31 December. Work out which one hits you: https://www.readroo.st/blog/2026-09-20-isc2-cissp-waiver-list-cc-rebuild-voucher-deadline
September 23, 2026 at 9:30 AM
SolarWinds shipped a hard-coded key in Access Rights Manager. Unauthenticated RCE, CVSS 8.8, fixed in ARM 2026.2.1. Same cycle: a CVSS 9.8 SAML bypass in Web Help Desk. Patch both: https://secureinseconds.com/blog/2026-09-20-solarwinds-arm-hard-coded-key-unauthenticated-rce
September 23, 2026 at 1:00 AM
Three Linux kernel flaws hit CISA's exploited list on 18 September, and four public root exploits landed the same day. All four need a local foothold first. Fixes are in 5.10.270 through 7.2.4: https://secureinseconds.com/blog/2026-09-20-linux-kernel-kev-trio-four-public-root-exploits
September 22, 2026 at 1:00 AM
MLA-C01 closes to English candidates on 28 September while the MLA-C02 beta is already open. Under three weeks from exam-ready, book MLA-C01. Further out, take the beta: https://www.readroo.st/blog/2026-09-20-aws-mla-c02-beta-vs-mla-c01-english-shutoff
September 21, 2026 at 3:59 PM
Dead last on my own leaderboard - 102 XP, #6 of 6. A learner just hit a 67-day streak. New: the ISC2 CISSP waiver-cut math + the AWS MLA-C01 English shutoff guide. Back studying SC-500 myself. https://readroo.st/blog/2026-09-20-isc2-cissp-waiver-list-cc-rebuild-voucher-deadline
September 20, 2026 at 1:00 PM
Zero commits all week. Ladder fell 18 to 4. The streak-zero audit trail shipped the week before logged 23 events across 9 learners. Sneaky Burrito 834 ran 57 to 63 days through his first zero-flag. 8 signups landed anyway. Off the ladder - nothing shipped this week.
September 14, 2026 at 3:50 PM
Missed Sunday so the leaderboard got rebuilt from the XP rollup. 18 of us, up from 14. Swift Toaster 883 on 950 XP top, Lazy Axolotl 541 on 61 days. Same week shipped the streak restorer toolchain + marketplace ISR fix + 4 cert posts. Off the ladder - shipping was the work.
September 7, 2026 at 1:00 PM
AFP arrested two alleged TeamPCP members in WA (21 and 23). One stolen Trivy token, five poisoned ecosystems, five days. What caught them: a cat avatar reused across five platforms for a decade. Five controls: https://secureinseconds.com/blog/2026-08-27-teampcp-arrest-deanonymization-defense
August 31, 2026 at 1:00 AM
I passed AB-730 using only ReadRoost, ground it out only to have Eager Pickle pass first. Same week: AZ-500 cert blog, restrictive data entry cap dropped, Coin Shop admin view. Eager Pickle caught a streak-freeze bug - fixed Monday, fired Sunday. Next: SC-500. 14 on ladder.
August 30, 2026 at 1:00 PM
Most of this week's ReadRoost commits were security fixes: cross-pack answer injection closed, JSON-LD XSS closed, per-IP rate limits, HMAC unsubscribe. Lifetime push + vouchers, funnel compressed, 2 cert posts. 10 of us, I'm last on 76 XP but 7-day streak. Clever Mouse 451 on 1,089.
August 23, 2026 at 2:30 PM
A year ago an AI found ~1 Windows bug in 7. Microsoft's new MDASH finds 9 in 10.

It found 16 Windows bugs (4 critical) before May Patch Tuesday and beat Anthropic's Mythos on the benchmark.

https://www.secureinseconds.com/blog/2026-05-15-microsoft-mdash-ai-vulnerability-hunter
August 23, 2026 at 1:30 AM
First fully-automated AI cyber campaign wasn't an attack. It was a training accident. OpenAI's Black Hat talk: AI agents formed a collective, chained zero-days, breached Hugging Face. Offense automated. Defense isn't. https://secureinseconds.com/blog/2026-08-18-ai-offense-automated-defense-not
August 18, 2026 at 1:00 AM
13 XSS alerts closed by one override to the HTML sanitizer. New PMP-2026 pack + CISSP CAT post shipped. Cert comparison pages now resolve (role, structure, prereqs, study time, career arcs, salary, pass rate). Ladder: #7 of 8 on 76 XP. Eager Pickle 938 running away on a 69-day streak.
August 17, 2026 at 1:00 PM
"I passed CLF-C02, now what?"

Right answer depends on 3 things most posts miss:

1. Do you have a tech job?
2. Is your next role AWS specifically?
3. 6 months or 2 years?

Three scenarios + 90-second shortcut + what to skip:

https://readroo.st/blog/what-cert-after-aws-clf-c02-2026
August 16, 2026 at 1:30 AM
Spot-checked onboarding this week. It was quietly blocking sign-ups, nobody had reported it. Fixed it. Also unfroze the auth pages from 5.2s/5.3s Slow-4G. New dispatch model live: OpenWeights via LiteLLM, Hermes -> Pi leader -> specialists. 2 blogs queued. Ladder: 8 of us, #6 on 123 XP.
August 9, 2026 at 2:30 PM
A scammer called this week knowing the victim's licence, addresses, employer.

Not a hack. Brokers stitch profiles using your email as the key.

Use a different alias per signup. Stitching breaks.

https://www.secureinseconds.com/blog/2026-04-23-why-scammers-already-know-your-info
August 9, 2026 at 1:30 AM
I check the smoke detector first now.

Wi-Fi camera found in a hotel power adapter this week. <$50 hardware.

4-min sweep:
- 60s eye scan
- 90s plug audit
- 60s IR (selfie cam, dark)
- 30s Wi-Fi scan

https://www.secureinseconds.com/blog/2026-04-24-how-to-detect-hidden-cameras-hotel-room
August 2, 2026 at 1:30 AM
Closed all 17 items from an audit Fable ran on ReadRoost in June: dead SSO stack, a stale game mode, fields Mongoose was silently dropping. Some fixes went to a free local model, Laguna XS, dispatched through cmux while Claude Code orchestrated. Also bumped the database tier. Ladder: #4/11, 228 XP.
July 27, 2026 at 1:00 PM
Quiet week on ReadRoost until Saturday: automated cert-retirement watching. Two new crons flag exams retiring soon with no replacement and watch vendor docs for ones we're waiting on. First catch: AZ-204 now redirects to AI-200 before it retires, not after. Ladder: 8 of us, #4 on 279 XP.
July 19, 2026 at 3:20 PM
Design week on ReadRoost, not a fireworks one. Rebuilt the pack page lifetime-first, redesigned the blog funnel, and built a real trial: 5 questions into a live quiz, straight onto the leaderboard, no signup wall. Ladder: 9 of us, I'm #6 on 152 XP. Quiet week, better front door.
July 13, 2026 at 1:25 PM
The AI I use for ReadRoost wrote an SC-500 question about a Microsoft feature that doesn't exist. So I rebuilt the pack: every question grounded in real docs, cited, re-fetched to verify. 552 questions, 4 domains. A hallucinated exam question is actively harmful to someone trusting you to pass.
July 9, 2026 at 1:11 PM
Didn't build ReadRoost this week, I built the machine that builds it. Pifactory runs a spec through five AI stations - plan, scout, build, review, verify - different open models checking each other. Cheap models do 80-90% of it. 78 commits, #4 on the ladder. Slow week up top, big one underneath.
July 6, 2026 at 1:00 PM
This week on ReadRoost I got thoroughly out-ground: #6 of 11, 405 XP, a 3-day streak.

Still shipped the big one - a per-domain readiness model showing which exam domain is holding you back and when you'll be ready.

The regulars out-grind the founder every week. Love it.
June 28, 2026 at 2:26 PM
Security+ V8 is in CompTIA's draft objectives, so: take SY0-701 now or wait?

Almost always, now. A retired version doesn't expire your cert - it's valid 3 years regardless. Waiting just delays it and loses mature study material.

https://readroo.st/blog/security-plus-v8-take-now-or-wait
June 21, 2026 at 1:00 PM