home.social

#infragard — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #infragard, aggregated by home.social.

fetched live
  1. I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
    Here are a few key points from tonight:
    ・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
    ・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
    ・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

    If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
    Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

    aitpchicago.com/event-6680905
    #Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

  2. I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
    Here are a few key points from tonight:
    ・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
    ・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
    ・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

    If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
    Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

    aitpchicago.com/event-6680905
    #Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

  3. I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
    Here are a few key points from tonight:
    ・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
    ・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
    ・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

    If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
    Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

    aitpchicago.com/event-6680905
    #Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

  4. I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
    Here are a few key points from tonight:
    ・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
    ・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
    ・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

    If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
    Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

    aitpchicago.com/event-6680905
    #Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

  5. I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
    Here are a few key points from tonight:
    ・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
    ・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
    ・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

    If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
    Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

    aitpchicago.com/event-6680905
    #Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

  6. Anyone else in #infragard get a notice to apply for and active your GETS or WPS?

    Last time I got this was just as the initial COVID lockdowns started
    😬

  7. Anyone else in #infragard get a notice to apply for and active your GETS or WPS?

    Last time I got this was just as the initial COVID lockdowns started
    😬

  8. Anyone else in #infragard get a notice to apply for and active your GETS or WPS?

    Last time I got this was just as the initial COVID lockdowns started
    😬

  9. Anyone else in #infragard get a notice to apply for and active your GETS or WPS?

    Last time I got this was just as the initial COVID lockdowns started
    😬

  10. just to let you guys know, i'm not ever joining #infragard ever. infragard for starters, is now using cloudflare for its products. now I guess that's not a sin on its own, I have used cloudflare, and use it for workers applications.
    but as we know, cloudflare ended up in a data breech. now for someone like me, that's fine. I know what I 'mdoing, I use 2factor authentication, i'm pretty good...
    but for infragard? yeah, that's...pretty fucking stupid, because they want their own information sharing network.
    again, my website is just want average Joe website.
    it can withstand a couple hours of outage.]
    but infragard absa fucking lutely cannot take a hit, because this isn't some average Joe website, it's an entire threat assessment #threat information sharing network.
    they need absolute uptime.
    second, I don't know if you're aware, but infragard was actually using #microsoft #windows server 2012 in the passed. keep in mind, this isn't supported anymore. in fact, I have to bet they're still using it today.
    just hiding it to make us not think they're using it by putting it behind cloudflare.
    and also, they're using a service called id.me which had a major unauthorized access incedent back in 2018.
    o and infragard had a hole registration fuckin breech which involved a user called USDOD registering as a CEO with no legal verification.
    if I was running infragard, I'd do things a lot differently.
    first off, maybe run some actual fucking hardware, I don't know? maybe run some new up to date shit? sounds like a great idea, right? it's never been done before, it's absolutely amazing right?
    ...no!
    it can be done, and I don't know why it hasn't.
    but second, i'd use PIVs, not some email/and/or password. in fact, if you are working for the military you must use a PIV/CAC to login. it's mandatory.
    also, I wouldn't run the application online. i'd have them vetted at a local FBI office and/or in a friendly country the US partners with.
    this will be a lot more secure than vetting online which clearly didn't work last time.
    so really this information sharing act congress had was basically useless on the point it was not secure.
    @kkarhan #infosec #opsec #cybersecurity

  11. just to let you guys know, i'm not ever joining #infragard ever. infragard for starters, is now using cloudflare for its products. now I guess that's not a sin on its own, I have used cloudflare, and use it for workers applications.
    but as we know, cloudflare ended up in a data breech. now for someone like me, that's fine. I know what I 'mdoing, I use 2factor authentication, i'm pretty good...
    but for infragard? yeah, that's...pretty fucking stupid, because they want their own information sharing network.
    again, my website is just want average Joe website.
    it can withstand a couple hours of outage.]
    but infragard absa fucking lutely cannot take a hit, because this isn't some average Joe website, it's an entire threat assessment #threat information sharing network.
    they need absolute uptime.
    second, I don't know if you're aware, but infragard was actually using #microsoft #windows server 2012 in the passed. keep in mind, this isn't supported anymore. in fact, I have to bet they're still using it today.
    just hiding it to make us not think they're using it by putting it behind cloudflare.
    and also, they're using a service called id.me which had a major unauthorized access incedent back in 2018.
    o and infragard had a hole registration fuckin breech which involved a user called USDOD registering as a CEO with no legal verification.
    if I was running infragard, I'd do things a lot differently.
    first off, maybe run some actual fucking hardware, I don't know? maybe run some new up to date shit? sounds like a great idea, right? it's never been done before, it's absolutely amazing right?
    ...no!
    it can be done, and I don't know why it hasn't.
    but second, i'd use PIVs, not some email/and/or password. in fact, if you are working for the military you must use a PIV/CAC to login. it's mandatory.
    also, I wouldn't run the application online. i'd have them vetted at a local FBI office and/or in a friendly country the US partners with.
    this will be a lot more secure than vetting online which clearly didn't work last time.
    so really this information sharing act congress had was basically useless on the point it was not secure.
    @kkarhan #infosec #opsec #cybersecurity

  12. just to let you guys know, i'm not ever joining #infragard ever. infragard for starters, is now using cloudflare for its products. now I guess that's not a sin on its own, I have used cloudflare, and use it for workers applications.
    but as we know, cloudflare ended up in a data breech. now for someone like me, that's fine. I know what I 'mdoing, I use 2factor authentication, i'm pretty good...
    but for infragard? yeah, that's...pretty fucking stupid, because they want their own information sharing network.
    again, my website is just want average Joe website.
    it can withstand a couple hours of outage.]
    but infragard absa fucking lutely cannot take a hit, because this isn't some average Joe website, it's an entire threat assessment #threat information sharing network.
    they need absolute uptime.
    second, I don't know if you're aware, but infragard was actually using #microsoft #windows server 2012 in the passed. keep in mind, this isn't supported anymore. in fact, I have to bet they're still using it today.
    just hiding it to make us not think they're using it by putting it behind cloudflare.
    and also, they're using a service called id.me which had a major unauthorized access incedent back in 2018.
    o and infragard had a hole registration fuckin breech which involved a user called USDOD registering as a CEO with no legal verification.
    if I was running infragard, I'd do things a lot differently.
    first off, maybe run some actual fucking hardware, I don't know? maybe run some new up to date shit? sounds like a great idea, right? it's never been done before, it's absolutely amazing right?
    ...no!
    it can be done, and I don't know why it hasn't.
    but second, i'd use PIVs, not some email/and/or password. in fact, if you are working for the military you must use a PIV/CAC to login. it's mandatory.
    also, I wouldn't run the application online. i'd have them vetted at a local FBI office and/or in a friendly country the US partners with.
    this will be a lot more secure than vetting online which clearly didn't work last time.
    so really this information sharing act congress had was basically useless on the point it was not secure.
    @kkarhan #infosec #opsec #cybersecurity

  13. just to let you guys know, i'm not ever joining #infragard ever. infragard for starters, is now using cloudflare for its products. now I guess that's not a sin on its own, I have used cloudflare, and use it for workers applications.
    but as we know, cloudflare ended up in a data breech. now for someone like me, that's fine. I know what I 'mdoing, I use 2factor authentication, i'm pretty good...
    but for infragard? yeah, that's...pretty fucking stupid, because they want their own information sharing network.
    again, my website is just want average Joe website.
    it can withstand a couple hours of outage.]
    but infragard absa fucking lutely cannot take a hit, because this isn't some average Joe website, it's an entire threat assessment #threat information sharing network.
    they need absolute uptime.
    second, I don't know if you're aware, but infragard was actually using #microsoft #windows server 2012 in the passed. keep in mind, this isn't supported anymore. in fact, I have to bet they're still using it today.
    just hiding it to make us not think they're using it by putting it behind cloudflare.
    and also, they're using a service called id.me which had a major unauthorized access incedent back in 2018.
    o and infragard had a hole registration fuckin breech which involved a user called USDOD registering as a CEO with no legal verification.
    if I was running infragard, I'd do things a lot differently.
    first off, maybe run some actual fucking hardware, I don't know? maybe run some new up to date shit? sounds like a great idea, right? it's never been done before, it's absolutely amazing right?
    ...no!
    it can be done, and I don't know why it hasn't.
    but second, i'd use PIVs, not some email/and/or password. in fact, if you are working for the military you must use a PIV/CAC to login. it's mandatory.
    also, I wouldn't run the application online. i'd have them vetted at a local FBI office and/or in a friendly country the US partners with.
    this will be a lot more secure than vetting online which clearly didn't work last time.
    so really this information sharing act congress had was basically useless on the point it was not secure.
    @kkarhan #infosec #opsec #cybersecurity

  14. just to let you guys know, i'm not ever joining #infragard ever. infragard for starters, is now using cloudflare for its products. now I guess that's not a sin on its own, I have used cloudflare, and use it for workers applications.
    but as we know, cloudflare ended up in a data breech. now for someone like me, that's fine. I know what I 'mdoing, I use 2factor authentication, i'm pretty good...
    but for infragard? yeah, that's...pretty fucking stupid, because they want their own information sharing network.
    again, my website is just want average Joe website.
    it can withstand a couple hours of outage.]
    but infragard absa fucking lutely cannot take a hit, because this isn't some average Joe website, it's an entire threat assessment #threat information sharing network.
    they need absolute uptime.
    second, I don't know if you're aware, but infragard was actually using #microsoft #windows server 2012 in the passed. keep in mind, this isn't supported anymore. in fact, I have to bet they're still using it today.
    just hiding it to make us not think they're using it by putting it behind cloudflare.
    and also, they're using a service called id.me which had a major unauthorized access incedent back in 2018.
    o and infragard had a hole registration fuckin breech which involved a user called USDOD registering as a CEO with no legal verification.
    if I was running infragard, I'd do things a lot differently.
    first off, maybe run some actual fucking hardware, I don't know? maybe run some new up to date shit? sounds like a great idea, right? it's never been done before, it's absolutely amazing right?
    ...no!
    it can be done, and I don't know why it hasn't.
    but second, i'd use PIVs, not some email/and/or password. in fact, if you are working for the military you must use a PIV/CAC to login. it's mandatory.
    also, I wouldn't run the application online. i'd have them vetted at a local FBI office and/or in a friendly country the US partners with.
    this will be a lot more secure than vetting online which clearly didn't work last time.
    so really this information sharing act congress had was basically useless on the point it was not secure.
    @kkarhan #infosec #opsec #cybersecurity

  15. Grateful to join today’s InfraGard Chicago Members Alliance chapter meeting at the iconic Old Chicago Post Office 🏛️

    A fascinating and timely session led by the FBI – Federal Bureau of Investigation on North Korean 🇰🇵 threat actors — full of actionable intelligence and insight.

    All that and more information from:
    🔹 CPIC (Chicago Police Department’s Crime Prevention & Information Center)
    🔹 CISA (Cybersecurity and Infrastructure Security Agency)
    🔹 John Barker, Esq., AIGP, CCEP, CHPC, CHRC, CHC of TCLF

    It is always valuable to collaborate across agencies and sectors to strengthen public-private security partnerships.

    More on InfraGard Chicago:
    chicagoinfragard.org

    #InfraGardChicago #InfraGard #NorthKorea #CyberThreats #FBI #CISA #ChicagoPD #CPIC #PTPChicago #Chicago #Cybersecurity

  16. Grateful to join today’s InfraGard Chicago Members Alliance chapter meeting at the iconic Old Chicago Post Office 🏛️

    A fascinating and timely session led by the FBI – Federal Bureau of Investigation on North Korean 🇰🇵 threat actors — full of actionable intelligence and insight.

    All that and more information from:
    🔹 CPIC (Chicago Police Department’s Crime Prevention & Information Center)
    🔹 CISA (Cybersecurity and Infrastructure Security Agency)
    🔹 John Barker, Esq., AIGP, CCEP, CHPC, CHRC, CHC of TCLF

    It is always valuable to collaborate across agencies and sectors to strengthen public-private security partnerships.

    More on InfraGard Chicago:
    chicagoinfragard.org

    #InfraGardChicago #InfraGard #NorthKorea #CyberThreats #FBI #CISA #ChicagoPD #CPIC #PTPChicago #Chicago #Cybersecurity

  17. Grateful to join today’s InfraGard Chicago Members Alliance chapter meeting at the iconic Old Chicago Post Office 🏛️

    A fascinating and timely session led by the FBI – Federal Bureau of Investigation on North Korean 🇰🇵 threat actors — full of actionable intelligence and insight.

    All that and more information from:
    🔹 CPIC (Chicago Police Department’s Crime Prevention & Information Center)
    🔹 CISA (Cybersecurity and Infrastructure Security Agency)
    🔹 John Barker, Esq., AIGP, CCEP, CHPC, CHRC, CHC of TCLF

    It is always valuable to collaborate across agencies and sectors to strengthen public-private security partnerships.

    More on InfraGard Chicago:
    chicagoinfragard.org

    #InfraGardChicago #InfraGard #NorthKorea #CyberThreats #FBI #CISA #ChicagoPD #CPIC #PTPChicago #Chicago #Cybersecurity

  18. Grateful to join today’s InfraGard Chicago Members Alliance chapter meeting at the iconic Old Chicago Post Office 🏛️

    A fascinating and timely session led by the FBI – Federal Bureau of Investigation on North Korean 🇰🇵 threat actors — full of actionable intelligence and insight.

    All that and more information from:
    🔹 CPIC (Chicago Police Department’s Crime Prevention & Information Center)
    🔹 CISA (Cybersecurity and Infrastructure Security Agency)
    🔹 John Barker, Esq., AIGP, CCEP, CHPC, CHRC, CHC of TCLF

    It is always valuable to collaborate across agencies and sectors to strengthen public-private security partnerships.

    More on InfraGard Chicago:
    chicagoinfragard.org

    #InfraGardChicago #InfraGard #NorthKorea #CyberThreats #FBI #CISA #ChicagoPD #CPIC #PTPChicago #Chicago #Cybersecurity

  19. Grateful to join today’s InfraGard Chicago Members Alliance chapter meeting at the iconic Old Chicago Post Office 🏛️

    A fascinating and timely session led by the FBI – Federal Bureau of Investigation on North Korean 🇰🇵 threat actors — full of actionable intelligence and insight.

    All that and more information from:
    🔹 CPIC (Chicago Police Department’s Crime Prevention & Information Center)
    🔹 CISA (Cybersecurity and Infrastructure Security Agency)
    🔹 John Barker, Esq., AIGP, CCEP, CHPC, CHRC, CHC of TCLF

    It is always valuable to collaborate across agencies and sectors to strengthen public-private security partnerships.

    More on InfraGard Chicago:
    chicagoinfragard.org

    #InfraGardChicago #InfraGard #NorthKorea #CyberThreats #FBI #CISA #ChicagoPD #CPIC #PTPChicago #Chicago #Cybersecurity

  20. Breaking News: The threat actor known as "USDoD" (aka "EquationCorp" and other monikers") has been arrested by Brazilian Federal Police. USDoD is probably best known for his attacks on #InfraGard, Airbus, and his role in the recent National Public Data breach.

    Media coverage indicates he was arrested this morning: g1.globo.com/politica/noticia/

    #databreach #hacker #USDoD #EquationCorp

    @brett @campuscodi

    Update: a bit more info here: Developing: Brazilian hacker known as “USDoD” arrested by federal police: databreaches.net/?p=117212

  21. Breaking News: The threat actor known as "USDoD" (aka "EquationCorp" and other monikers") has been arrested by Brazilian Federal Police. USDoD is probably best known for his attacks on #InfraGard, Airbus, and his role in the recent National Public Data breach.

    Media coverage indicates he was arrested this morning: g1.globo.com/politica/noticia/

    #databreach #hacker #USDoD #EquationCorp

    @brett @campuscodi

    Update: a bit more info here: Developing: Brazilian hacker known as “USDoD” arrested by federal police: databreaches.net/?p=117212

  22. Breaking News: The threat actor known as "USDoD" (aka "EquationCorp" and other monikers") has been arrested by Brazilian Federal Police. USDoD is probably best known for his attacks on #InfraGard, Airbus, and his role in the recent National Public Data breach.

    Media coverage indicates he was arrested this morning: g1.globo.com/politica/noticia/

    #databreach #hacker #USDoD #EquationCorp

    @brett @campuscodi

    Update: a bit more info here: Developing: Brazilian hacker known as “USDoD” arrested by federal police: databreaches.net/?p=117212

  23. Breaking News: The threat actor known as "USDoD" (aka "EquationCorp" and other monikers") has been arrested by Brazilian Federal Police. USDoD is probably best known for his attacks on #InfraGard, Airbus, and his role in the recent National Public Data breach.

    Media coverage indicates he was arrested this morning: g1.globo.com/politica/noticia/

    #databreach #hacker #USDoD #EquationCorp

    @brett @campuscodi

    Update: a bit more info here: Developing: Brazilian hacker known as “USDoD” arrested by federal police: databreaches.net/?p=117212

  24. Breaking News: The threat actor known as "USDoD" (aka "EquationCorp" and other monikers") has been arrested by Brazilian Federal Police. USDoD is probably best known for his attacks on #InfraGard, Airbus, and his role in the recent National Public Data breach.

    Media coverage indicates he was arrested this morning: g1.globo.com/politica/noticia/

    #databreach #hacker #USDoD #EquationCorp

    @brett @campuscodi

    Update: a bit more info here: Developing: Brazilian hacker known as “USDoD” arrested by federal police: databreaches.net/?p=117212

  25. ICYMI: I interviewed the hacker known as "USDoD" who was responsible for the InfraGard incident last year, as well as the recent Airbus and TransUnion breaches. He tells me he's been busy targeting NATO, Europol, CEPOL, and Interpol. He's an ambitious hacker and is really going after U.S. military intelligence in his own way and for his own endgame purposes.

    Why does he tell us his targets? For the challenge -- he wants to beat his targets when they know he's coming.

    Read what he told me in “I’m Not Pro-Russia and I’m Not a Terrorist!” —- InfraGard and Airbus Hacker 'USDoD' Unveils His New Campaigns:"

    databreaches.net/im-not-pro-ru

    On a positive note, it appears that NATO detected him when he attempted to gain access to an internal area; part of their site has now been "under maintenance" for days.

    How serious a threat is he really? I can't judge that -- maybe you can.

    #NatSec #cybersecurity #intel #socialengineering #hacker #databreach #defense #USDoD #InfraGard #InfoSec

  26. ICYMI: I interviewed the hacker known as "USDoD" who was responsible for the InfraGard incident last year, as well as the recent Airbus and TransUnion breaches. He tells me he's been busy targeting NATO, Europol, CEPOL, and Interpol. He's an ambitious hacker and is really going after U.S. military intelligence in his own way and for his own endgame purposes.

    Why does he tell us his targets? For the challenge -- he wants to beat his targets when they know he's coming.

    Read what he told me in “I’m Not Pro-Russia and I’m Not a Terrorist!” —- InfraGard and Airbus Hacker 'USDoD' Unveils His New Campaigns:"

    databreaches.net/im-not-pro-ru

    On a positive note, it appears that NATO detected him when he attempted to gain access to an internal area; part of their site has now been "under maintenance" for days.

    How serious a threat is he really? I can't judge that -- maybe you can.

    #NatSec #cybersecurity #intel #socialengineering #hacker #databreach #defense #USDoD #InfraGard #InfoSec

  27. ICYMI: I interviewed the hacker known as "USDoD" who was responsible for the InfraGard incident last year, as well as the recent Airbus and TransUnion breaches. He tells me he's been busy targeting NATO, Europol, CEPOL, and Interpol. He's an ambitious hacker and is really going after U.S. military intelligence in his own way and for his own endgame purposes.

    Why does he tell us his targets? For the challenge -- he wants to beat his targets when they know he's coming.

    Read what he told me in “I’m Not Pro-Russia and I’m Not a Terrorist!” —- InfraGard and Airbus Hacker 'USDoD' Unveils His New Campaigns:"

    databreaches.net/im-not-pro-ru

    On a positive note, it appears that NATO detected him when he attempted to gain access to an internal area; part of their site has now been "under maintenance" for days.

    How serious a threat is he really? I can't judge that -- maybe you can.

    #NatSec #cybersecurity #intel #socialengineering #hacker #databreach #defense #USDoD #InfraGard #InfoSec

  28. ICYMI: I interviewed the hacker known as "USDoD" who was responsible for the InfraGard incident last year, as well as the recent Airbus and TransUnion breaches. He tells me he's been busy targeting NATO, Europol, CEPOL, and Interpol. He's an ambitious hacker and is really going after U.S. military intelligence in his own way and for his own endgame purposes.

    Why does he tell us his targets? For the challenge -- he wants to beat his targets when they know he's coming.

    Read what he told me in “I’m Not Pro-Russia and I’m Not a Terrorist!” —- InfraGard and Airbus Hacker 'USDoD' Unveils His New Campaigns:"

    databreaches.net/im-not-pro-ru

    On a positive note, it appears that NATO detected him when he attempted to gain access to an internal area; part of their site has now been "under maintenance" for days.

    How serious a threat is he really? I can't judge that -- maybe you can.

    #NatSec #cybersecurity #intel #socialengineering #hacker #databreach #defense #USDoD #InfraGard #InfoSec

  29. ICYMI: I interviewed the hacker known as "USDoD" who was responsible for the InfraGard incident last year, as well as the recent Airbus and TransUnion breaches. He tells me he's been busy targeting NATO, Europol, CEPOL, and Interpol. He's an ambitious hacker and is really going after U.S. military intelligence in his own way and for his own endgame purposes.

    Why does he tell us his targets? For the challenge -- he wants to beat his targets when they know he's coming.

    Read what he told me in “I’m Not Pro-Russia and I’m Not a Terrorist!” —- InfraGard and Airbus Hacker 'USDoD' Unveils His New Campaigns:"

    databreaches.net/im-not-pro-ru

    On a positive note, it appears that NATO detected him when he attempted to gain access to an internal area; part of their site has now been "under maintenance" for days.

    How serious a threat is he really? I can't judge that -- maybe you can.

    #NatSec #cybersecurity #intel #socialengineering #hacker #databreach #defense #USDoD #InfraGard #InfoSec