home.social

#infragard — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #infragard, aggregated by home.social.

  1. I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
    Here are a few key points from tonight:
    ・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
    ・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
    ・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

    If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
    Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

    aitpchicago.com/event-6680905
    #Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

  2. I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
    Here are a few key points from tonight:
    ・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
    ・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
    ・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

    If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
    Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

    aitpchicago.com/event-6680905
    #Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

  3. I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
    Here are a few key points from tonight:
    ・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
    ・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
    ・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

    If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
    Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

    aitpchicago.com/event-6680905
    #Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

  4. I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
    Here are a few key points from tonight:
    ・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
    ・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
    ・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

    If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
    Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

    aitpchicago.com/event-6680905
    #Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

  5. I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
    Here are a few key points from tonight:
    ・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
    ・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
    ・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

    If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
    Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

    aitpchicago.com/event-6680905
    #Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

  6. Breaking News: The threat actor known as "USDoD" (aka "EquationCorp" and other monikers") has been arrested by Brazilian Federal Police. USDoD is probably best known for his attacks on #InfraGard, Airbus, and his role in the recent National Public Data breach.

    Media coverage indicates he was arrested this morning: g1.globo.com/politica/noticia/

    #databreach #hacker #USDoD #EquationCorp

    @brett @campuscodi

    Update: a bit more info here: Developing: Brazilian hacker known as “USDoD” arrested by federal police: databreaches.net/?p=117212

  7. Breaking News: The threat actor known as "USDoD" (aka "EquationCorp" and other monikers") has been arrested by Brazilian Federal Police. USDoD is probably best known for his attacks on #InfraGard, Airbus, and his role in the recent National Public Data breach.

    Media coverage indicates he was arrested this morning: g1.globo.com/politica/noticia/

    #databreach #hacker #USDoD #EquationCorp

    @brett @campuscodi

    Update: a bit more info here: Developing: Brazilian hacker known as “USDoD” arrested by federal police: databreaches.net/?p=117212

  8. Breaking News: The threat actor known as "USDoD" (aka "EquationCorp" and other monikers") has been arrested by Brazilian Federal Police. USDoD is probably best known for his attacks on #InfraGard, Airbus, and his role in the recent National Public Data breach.

    Media coverage indicates he was arrested this morning: g1.globo.com/politica/noticia/

    #databreach #hacker #USDoD #EquationCorp

    @brett @campuscodi

    Update: a bit more info here: Developing: Brazilian hacker known as “USDoD” arrested by federal police: databreaches.net/?p=117212

  9. Breaking News: The threat actor known as "USDoD" (aka "EquationCorp" and other monikers") has been arrested by Brazilian Federal Police. USDoD is probably best known for his attacks on #InfraGard, Airbus, and his role in the recent National Public Data breach.

    Media coverage indicates he was arrested this morning: g1.globo.com/politica/noticia/

    #databreach #hacker #USDoD #EquationCorp

    @brett @campuscodi

    Update: a bit more info here: Developing: Brazilian hacker known as “USDoD” arrested by federal police: databreaches.net/?p=117212

  10. Breaking News: The threat actor known as "USDoD" (aka "EquationCorp" and other monikers") has been arrested by Brazilian Federal Police. USDoD is probably best known for his attacks on #InfraGard, Airbus, and his role in the recent National Public Data breach.

    Media coverage indicates he was arrested this morning: g1.globo.com/politica/noticia/

    #databreach #hacker #USDoD #EquationCorp

    @brett @campuscodi

    Update: a bit more info here: Developing: Brazilian hacker known as “USDoD” arrested by federal police: databreaches.net/?p=117212