#ot — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ot, aggregated by home.social.
-
Sicurezza IT e OT: l’estate testa la resilienza operativa: Con l’arrivo delle ferie, molte aziende da quelle manifatturiere alle infrastrutture critiche si trovano a operare con organici ridotti, maggiore...
#Rischicyber #OT #StateofCPSSecurityReport #Claroty #intelligenzaartificiale http://dlvr.it/TV2BY3 -
¿Qué relación tienen David Bustamante y Bisbal 25 años después de OT? #DavidBustamante #DavidBisbal #OperacionTriunfo #OT1 #OT #MusicaEspañola #Eurovision #Famosos #Television #Actualidad #Celebrities #felizjueves #13deagosto
https://donporque.com/que-relacion-tienen-bustamante-y-bisbal/
-
¿Qué relación tienen David Bustamante y Bisbal 25 años después de OT? #DavidBustamante #DavidBisbal #OperacionTriunfo #OT1 #OT #MusicaEspañola #Eurovision #Famosos #Television #Actualidad #Celebrities #felizjueves #13deagosto
https://donporque.com/que-relacion-tienen-bustamante-y-bisbal/
-
https://www.lovenba.com/1798248/ Cold feet and cold hands for the tie is WILD 🤯🔥 #AtlanticDivision #Basketball #Bball #BostonCeltics #BrooklynNets #clutch #EasternConference #GameTie #HouseOfHighlights #HugoGonzales #MOMENTS #NBA #ot #Throwback
-
📰 Polish Power Plant Breached via Private Cellular APN Network
A novel attack on a Polish power plant used a private cellular APN to pivot into the OT network. Attackers, linked to Russia's FSB, used default PLC credentials to shut down a steam turbine. #ICS #OT #CyberAttack #CriticalInfrastructure #Poland
-
DEF CON Franklin and the NRWA have launched the Water Watch Center following a suspected widespread nation-state cyberattack on water utilities. https://iottechnews.com/news/cyber-defence-initiative-launches-following-us-water-utilities-attack/ #cybersecurity #digitaltwins #iiot #defcon #iot #ot #infosec #tech
-
DEF CON Franklin and the NRWA have launched the Water Watch Center following a suspected widespread nation-state cyberattack on water utilities. https://iottechnews.com/news/cyber-defence-initiative-launches-following-us-water-utilities-attack/ #cybersecurity #digitaltwins #iiot #defcon #iot #ot #infosec #tech
-
30% of manufacturers experienced a cyber incident affecting operations directly or through the supply chain. https://iottechnews.com/news/manufacturing-cybersecurity-needs-tested-recovery-plans/ #manufacturing #ot #cybersecurity #supplychain #infosec #tech
-
30% of manufacturers experienced a cyber incident affecting operations directly or through the supply chain. https://iottechnews.com/news/manufacturing-cybersecurity-needs-tested-recovery-plans/ #manufacturing #ot #cybersecurity #supplychain #infosec #tech
-
📰 NIST Publishes Final Cybersecurity Framework Profile for Transit Sector
NIST has released the final version of its Transit Cybersecurity Framework Profile (NIST IR 8576). The guide helps U.S. transit agencies manage cybersecurity risks across their IT and operational technology (OT) systems. #NIST #Cybersecurity #OT #ICS
-
PiP Cast: Perspectives In Paeds
Join Melbourne-based OTs Jackie Sikic and Caitlin Smith as they explore best practices, unpack the latest evidence, and chat about the everyday challenges faced by clinicians in paediatrics...Great Australian Pods Podcast Directory: https://www.greataustralianpods.com/pip-cast-perspectives-in-paeds/
#AusPods #Podcasts #Podcasting #Australia #Health #Careers #ComplementaryHealth #Wellness #OT
-
PiP Cast: Perspectives In Paeds
Join Melbourne-based OTs Jackie Sikic and Caitlin Smith as they explore best practices, unpack the latest evidence, and chat about the everyday challenges faced by clinicians in paediatrics...Great Australian Pods Podcast Directory: https://www.greataustralianpods.com/pip-cast-perspectives-in-paeds/
#AusPods #Podcasts #Podcasting #Australia #Health #Careers #ComplementaryHealth #Wellness #OT
-
Skuteczny atak na elektrociepłownię w Polsce. W wyniku incydentu bezpieczeństwa doszło do zatrzymania turbiny parowej
CERT Polska opublikował właśnie znaczne uzupełnienie opisu incydentu, który relacjonowaliśmy w styczniu. Wg najnowszej relacji: 1. Atak na elektrociepłownię rozpoczął się od cyberataku na farmę fotowoltaiczną, a dokładniej przejęto urządzenie Fortigate z interface VPN wystawionym do Internetu. Jak dodaje CERT Polska: interfejs VPN był dostępny z sieci internet i umożliwiał...
-
Skuteczny atak na elektrociepłownię w Polsce. W wyniku incydentu bezpieczeństwa doszło do zatrzymania turbiny parowej
CERT Polska opublikował właśnie znaczne uzupełnienie opisu incydentu, który relacjonowaliśmy w styczniu. Wg najnowszej relacji: 1. Atak na elektrociepłownię rozpoczął się od cyberataku na farmę fotowoltaiczną, a dokładniej przejęto urządzenie Fortigate z interface VPN wystawionym do Internetu. Jak dodaje CERT Polska: interfejs VPN był dostępny z sieci internet i umożliwiał...
-
👋 Meet Claire, the industry's first CPS-native AI security agent. Designed to help security teams work smarter, Claire delivers AI-powered insights, simplifies complex investigations, and helps organizations protect their #OT, #IoT, #IoMT, and other cyber-physical environments with greater speed and confidence.
💡 Learn more: https://claroty.com/blog/how-claroty-claire-brings-ai-powered-cybersecurity-to-cyber-physical-systems
#Cybersecurity #ArtificialIntelligence #AI #OTSecurity #CriticalInfrastructure #CPS #ClarotyClaire
-
👋 Meet Claire, the industry's first CPS-native AI security agent. Designed to help security teams work smarter, Claire delivers AI-powered insights, simplifies complex investigations, and helps organizations protect their #OT, #IoT, #IoMT, and other cyber-physical environments with greater speed and confidence.
💡 Learn more: https://claroty.com/blog/how-claroty-claire-brings-ai-powered-cybersecurity-to-cyber-physical-systems
#Cybersecurity #ArtificialIntelligence #AI #OTSecurity #CriticalInfrastructure #CPS #ClarotyClaire
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-03
CISA urges water utilities to lock down OT/PLCs after coordinated attacks hit multiple states, with signs pointing to Iranian threat actors.
https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/
#CISA #ICS #OT #Cybersecurity -
📰 CISA and FBI Warn of Attacks on US Water System PLCs
CISA & FBI issue urgent warning on cyberattacks targeting US water systems. Malicious actors are compromising internet-exposed Rockwell PLCs, causing operational disruptions and boil water notices. Operators urged to remove OT from internet. #ICS #OT...
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-02
US warns Iranian hackers are actively targeting Siemens, Schneider Electric & Rockwell ICS devices, raising critical infrastructure risk.
https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/
#ICS #OT #Cybersecurity #InfoSec -
Einordnung: Der Fall zeigt, warum Steuerungstechnik nicht unnötig direkt aus dem Internet erreichbar sein darf. Selbst einfache Zugriffe können reale Abläufe stören. Entscheidend sind getrennte Netze, sichere Fernzugänge und ein Betrieb, der notfalls auch manuell weiterlaufen kann.
@HonkHase kennt sich damit aber sicher noch besser aus. 😉
2/2
#ITSicherheit #KritischeInfrastruktur #Kritis #OT #KuketzAugust
-
Einordnung: Der Fall zeigt, warum Steuerungstechnik nicht unnötig direkt aus dem Internet erreichbar sein darf. Selbst einfache Zugriffe können reale Abläufe stören. Entscheidend sind getrennte Netze, sichere Fernzugänge und ein Betrieb, der notfalls auch manuell weiterlaufen kann.
@HonkHase kennt sich damit aber sicher noch besser aus. 😉
2/2
#ITSicherheit #KritischeInfrastruktur #Kritis #OT #KuketzAugust
-
Seit dem 27. Juli wurden Wasserversorger in mindestens sieben US-Bundesstaaten angegriffen. Betroffen waren unter anderem Steuerungen technischer Anlagen. Einige Versorger meldeten Betriebsstörungen, die Trinkwasserqualität sei nach bisherigen Angaben nicht beeinträchtigt worden.
1/2
#ITSicherheit #KritischeInfrastruktur #Kritis #OT #KuketzAugust
-
Seit dem 27. Juli wurden Wasserversorger in mindestens sieben US-Bundesstaaten angegriffen. Betroffen waren unter anderem Steuerungen technischer Anlagen. Einige Versorger meldeten Betriebsstörungen, die Trinkwasserqualität sei nach bisherigen Angaben nicht beeinträchtigt worden.
1/2
#ITSicherheit #KritischeInfrastruktur #Kritis #OT #KuketzAugust
-
Following the cyberattacks on water & wastewater (WWS) in the U.S. over the last week, we looked at exposure of Rockwell, Siemens, and Schneider Electric devices, as those are vendors explicitly named in CISA’s updated advisory on this activity (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a).
Rockwell exposures have declined about 21% since we last looked at this in April, primarily driven by a drop in U.S. exposures.
While this is encouraging, I want to note this line from CISA’s most recent alert:
> Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses.I’ll also note this from an FBI alert about the activity:
> At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers.I’m going out on a limb to say this is not the same flavor of hacktivist activity we have seen around WWS in the recent past. This feels distinctly different and potentially more harmful.
More details on the exposures:
https://censys.com/blog/cisa-alert-water-tower-plc-targeting/
-
Following the cyberattacks on water & wastewater (WWS) in the U.S. over the last week, we looked at exposure of Rockwell, Siemens, and Schneider Electric devices, as those are vendors explicitly named in CISA’s updated advisory on this activity (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a).
Rockwell exposures have declined about 21% since we last looked at this in April, primarily driven by a drop in U.S. exposures.
While this is encouraging, I want to note this line from CISA’s most recent alert:
> Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses.I’ll also note this from an FBI alert about the activity:
> At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers.I’m going out on a limb to say this is not the same flavor of hacktivist activity we have seen around WWS in the recent past. This feels distinctly different and potentially more harmful.
More details on the exposures:
https://censys.com/blog/cisa-alert-water-tower-plc-targeting/
-
📰 CISA and FBI Warn of Attacks on US Water System PLCs
CISA & FBI issue urgent warning on cyberattacks targeting US water systems. Malicious actors are compromising internet-exposed Rockwell PLCs, causing operational disruptions and boil water notices. Operators urged to remove OT from internet. #ICS #OT...
-
Sidewinder Thursday Way Point C-J The Force will be with you Always: Remembering Star Wars Canyon and the Jedi Transition USAF F-22A Raptor 04-0120 of the 422nd Test and Evaluation Squadron, July 2018. #USAF #StarWars #JediTransition #cvvhrn #AvGeek #OT #aviationphotography #photography #R2508 #lowlevel #sidewinder
-
Sidewinder Thursday Way Point C-J The Force will be with you Always: Remembering Star Wars Canyon and the Jedi Transition USAF F-22A Raptor 04-0120 of the 422nd Test and Evaluation Squadron, July 2018. #USAF #StarWars #JediTransition #cvvhrn #AvGeek #OT #aviationphotography #photography #R2508 #lowlevel #sidewinder
-
📰 CISA Urges OT Isolation in New 'CI Fortify' Critical Infrastructure Guide
CISA & international partners release "CI Fortify" guidance, urging critical infrastructure to plan for physical isolation of OT systems from IT networks during cyberattacks. The goal: protect vital services like energy & water. #CISecurity #OT #ICS
🌐 cyber[.]netsecops[.]io
-
Minnesota : attaque coordonnée contre les systèmes OT de plus de 30 réseaux d'eau potable, une station hors ligne. Réponse d'État déclenchée.
La criticité n'est pas dans les grands opérateurs : elle est distribuée dans des milliers de petites structures peu armées.
-
Minnesota : attaque coordonnée contre les systèmes OT de plus de 30 réseaux d'eau potable, une station hors ligne. Réponse d'État déclenchée.
La criticité n'est pas dans les grands opérateurs : elle est distribuée dans des milliers de petites structures peu armées.
-
📰 CISA Urges OT Isolation in New 'CI Fortify' Critical Infrastructure Guide
CISA & international partners release "CI Fortify" guidance, urging critical infrastructure to plan for physical isolation of OT systems from IT networks during cyberattacks. The goal: protect vital services like energy & water. #CISecurity #OT #ICS
🌐 cyber[.]netsecops[.]io
-
Over 30 Minnesota water utilities hit in a coordinated OT attack. Critical infrastructure + operational technology = a combination where patch cycles, legacy systems, and physical consequences converge. The "air gap" assumption hasn't aged well. The hard question isn't *if* OT gets targeted — it's whether detection is in place when it does. #infosec #OT…
https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/ -
Over 30 Minnesota water utilities hit in a coordinated OT attack. Critical infrastructure + operational technology = a combination where patch cycles, legacy systems, and physical consequences converge. The "air gap" assumption hasn't aged well. The hard question isn't *if* OT gets targeted — it's whether detection is in place when it does. #infosec #OT…
https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/ -
CW: release notes for Malcolm v26.07.1, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the
strelka-backendcontainer on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Co-installation of
opencv-pythonandopencv-contrib-pythoncorruptscv2.abi3.so, segfaultingstrelka-backendat import on arm64 #1046 (fix) - Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
- Co-installation of
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash to v9.4.4
- Pillow (Python library used in the
netboxcontainer) to v12.3.0 to address several security findings - Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
- Minor improvements to the Hedgehog Raspberry Pi image build process.
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.0
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash OSS to v9.4.3
- Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
❌ Errata
- Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
Legacy Systems, Real-World Impacts: The Reality of OT Security
In his latest SecurityWeek column, runZero's Tod Beardsley explores why vulnerability management in #OT is a completely different ballgame.
As OT/IT convergence accelerates, we need to evolve our defense strategies before AI-assisted attackers take advantage of the hidden exposures and broken segmentation in these environments.
Read Tod’s full analysis here: ➡️ https://www.securityweek.com/legacy-systems-real-world-impacts-the-reality-of-ot-security/
-
Legacy Systems, Real-World Impacts: The Reality of OT Security
In his latest SecurityWeek column, runZero's Tod Beardsley explores why vulnerability management in #OT is a completely different ballgame.
As OT/IT convergence accelerates, we need to evolve our defense strategies before AI-assisted attackers take advantage of the hidden exposures and broken segmentation in these environments.
Read Tod’s full analysis here: ➡️ https://www.securityweek.com/legacy-systems-real-world-impacts-the-reality-of-ot-security/
-
From time to time I receive spam that's funny. This one is offering personalised marketing as a service, but forgot to personalise the message, leaving a placeholder template variable in place.
-
From time to time I receive spam that's funny. This one is offering personalised marketing as a service, but forgot to personalise the message, leaving a placeholder template variable in place.
-
Any #OTSecurity account worth following ? Any ideas/recommendations ? #infosec #ot #security
-
Any #OTSecurity account worth following ? Any ideas/recommendations ? #infosec #ot #security
-
Infrastructures critiques : s'entraîner pour éviter le chaos. #InfrastructuresCritiques #SécuritéIndustrielle #OT #IoT #Résilience ... https://www.linkedin.com/posts/gabriel-chandesris_infrastructurescritiques-saezcuritaezindustrielle-share-7481230665334636544-BpuR/
-
Applizieren wir das jetzt auf das vorhandene Problem:
- China produziert offensichtlich sowohl beliebte "dumme" Komponenten wie Panels als auch beliebte "schlaue" Komponenten wie die Wechselrichter.
Letztere haben leider ein Plasterouter-Syndrom.
Deutschland hat ein massives Hinterherhinken in Rollout was dezentrale Solar/Renwables+Storage angeht wenn man den Daten trauen kann.
Noch mehr Regulation und Markteingriff wird hier absehbar nicht zu mehr Rollout, Verfügbarkeit und preislicher Attraktivität führen. Es gilt also den "Wild-West-Modus" aktiv zu embracen und zu nutzen.
Es wirkt auf mich wie eine interessante Idee ein OpenWRT der Wechselrichter sowohl auf Software als auch Hardware-Ebene zu triggern.
Das Ziel sollte hier dann sein, dass China Hardware in Masse baut die im wesentlichen diese Blaupausen relativ unverändert umsetzt es aber gleichzeitig ermöglicht wird in Europa die aktuellste Version von "Wechselrichter OpenWRT" drauf zu flashen und aktuell zu halten.
Hier könnte sich eine Förderung a la @sovtechfund / STF durchaus lohnen.
Ebenfalls wäre u.U. eine Nutzung im Lehrbetrieb auch nützlich.
Differenzierende Angebote Dritter und somit Wettbewerb sind auf dieser Basis vermutlich immer noch grundsätzlich möglich.
Vermutlich dürfte hier die sinnvolle Regulationslandschaft deutlich struppiger sein als für den allgemeinen Homerouter basierend darauf, dass es sich hier um Leistungshardware handelt.
Dort ist aber letztlich ohnehin durch die üblichen Ansprüche der EU hinsichtlich kontinuierlicher Wartung ohnehin ein Wandel zu erwarten. 'We're not doing it because it's easy, we're doing it because its hard' or so said someone some other time...
#Wechselrichter #stf #sovereigntechfund #wechselrichterWRT #leistungselektronik #ot
-
Gammel-OT, jetzt neu: Verteilt, unisoliert, noch verrotteter als sonst. Quasi die Plasterouter-Version von Groß-OT für das es ja wenigstens noch manchmal etwas zwangsmäßigen Effort gibt. Plasterouter-OT sozusagen.
Die Schwachstelle klingt...uhm...garstig. Besonders der Drohnenansatz gefält. 😱
#ot #plasterouter #gammelot #solarpunk #solarpower #blackout
-
Gammel-OT, jetzt neu: Verteilt, unisoliert, noch verrotteter als sonst. Quasi die Plasterouter-Version von Groß-OT für das es ja wenigstens noch manchmal etwas zwangsmäßigen Effort gibt. Plasterouter-OT sozusagen.
Die Schwachstelle klingt...uhm...garstig. Besonders der Drohnenansatz gefält. 😱
#ot #plasterouter #gammelot #solarpunk #solarpower #blackout
-
Réseaux électriques : former pour éviter le black-out. #Énergie #RéseauxÉlectriques #Cybersécurité #OT #IoT ... https://www.linkedin.com/posts/gabriel-chandesris_aeznergie-raezseauxaezlectriques-cybersaezcuritaez-share-7480517332763742209-38gN/
-
Incident playbooks should understand process impact, safe rollback paths, and physical fallback strategies.
Read more 👉 https://lttr.ai/As3Ka