home.social

#ot — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ot, aggregated by home.social.

fetched live
  1. Sicurezza IT e OT: l’estate testa la resilienza operativa: Con l’arrivo delle ferie, molte aziende da quelle manifatturiere alle infrastrutture critiche si trovano a operare con organici ridotti, maggiore...
    #Rischicyber #OT #StateofCPSSecurityReport #Claroty #intelligenzaartificiale dlvr.it/TV2BY3

  2. 📰 Polish Power Plant Breached via Private Cellular APN Network

    A novel attack on a Polish power plant used a private cellular APN to pivot into the OT network. Attackers, linked to Russia's FSB, used default PLC credentials to shut down a steam turbine. #ICS #OT #CyberAttack #CriticalInfrastructure #Poland

    🔗 cyber.netsecops.io/articles/no

  3. hey #infosec and #netadmin folks: how often do you see #snmp configured in the wild? (specifically on #ot #networks)

  4. hey #infosec and #netadmin folks: how often do you see #snmp configured in the wild? (specifically on #ot #networks)

  5. DEF CON Franklin and the NRWA have launched the Water Watch Center following a suspected widespread nation-state cyberattack on water utilities. iottechnews.com/news/cyber-def

  6. 📰 NIST Publishes Final Cybersecurity Framework Profile for Transit Sector

    NIST has released the final version of its Transit Cybersecurity Framework Profile (NIST IR 8576). The guide helps U.S. transit agencies manage cybersecurity risks across their IT and operational technology (OT) systems. #NIST #Cybersecurity #OT #ICS

    🔗 cyber.netsecops.io/articles/ni

  7. PiP Cast: Perspectives In Paeds
    Join Melbourne-based OTs Jackie Sikic and Caitlin Smith as they explore best practices, unpack the latest evidence, and chat about the everyday challenges faced by clinicians in paediatrics...

    Great Australian Pods Podcast Directory: greataustralianpods.com/pip-ca

    #AusPods #Podcasts #Podcasting #Australia #Health #Careers #ComplementaryHealth #Wellness #OT

  8. PiP Cast: Perspectives In Paeds
    Join Melbourne-based OTs Jackie Sikic and Caitlin Smith as they explore best practices, unpack the latest evidence, and chat about the everyday challenges faced by clinicians in paediatrics...

    Great Australian Pods Podcast Directory: greataustralianpods.com/pip-ca

    #AusPods #Podcasts #Podcasting #Australia #Health #Careers #ComplementaryHealth #Wellness #OT

  9. Skuteczny atak na elektrociepłownię w Polsce. W wyniku incydentu bezpieczeństwa doszło do zatrzymania turbiny parowej

    CERT Polska opublikował właśnie znaczne uzupełnienie opisu incydentu, który relacjonowaliśmy w styczniu. Wg najnowszej relacji: 1. Atak na elektrociepłownię rozpoczął się od cyberataku na farmę fotowoltaiczną, a dokładniej przejęto urządzenie Fortigate z interface VPN wystawionym do Internetu. Jak dodaje CERT Polska: interfejs VPN był dostępny z sieci internet i umożliwiał...

    #Aktualności #Cyberatak #Elektrociepłownia #Ot

    sekurak.pl/skuteczny-atak-na-e

  10. Skuteczny atak na elektrociepłownię w Polsce. W wyniku incydentu bezpieczeństwa doszło do zatrzymania turbiny parowej

    CERT Polska opublikował właśnie znaczne uzupełnienie opisu incydentu, który relacjonowaliśmy w styczniu. Wg najnowszej relacji: 1. Atak na elektrociepłownię rozpoczął się od cyberataku na farmę fotowoltaiczną, a dokładniej przejęto urządzenie Fortigate z interface VPN wystawionym do Internetu. Jak dodaje CERT Polska: interfejs VPN był dostępny z sieci internet i umożliwiał...

    #Aktualności #Cyberatak #Elektrociepłownia #Ot

    sekurak.pl/skuteczny-atak-na-e

  11. 👋 Meet Claire, the industry's first CPS-native AI security agent. Designed to help security teams work smarter, Claire delivers AI-powered insights, simplifies complex investigations, and helps organizations protect their #OT, #IoT, #IoMT, and other cyber-physical environments with greater speed and confidence.

    💡 Learn more: claroty.com/blog/how-claroty-c

    #Cybersecurity #ArtificialIntelligence #AI #OTSecurity #CriticalInfrastructure #CPS #ClarotyClaire

  12. 👋 Meet Claire, the industry's first CPS-native AI security agent. Designed to help security teams work smarter, Claire delivers AI-powered insights, simplifies complex investigations, and helps organizations protect their #OT, #IoT, #IoMT, and other cyber-physical environments with greater speed and confidence.

    💡 Learn more: claroty.com/blog/how-claroty-c

    #Cybersecurity #ArtificialIntelligence #AI #OTSecurity #CriticalInfrastructure #CPS #ClarotyClaire

  13. 🚨 SIGINT // Cybersecurity Watch — 2026-08-03
    CISA urges water utilities to lock down OT/PLCs after coordinated attacks hit multiple states, with signs pointing to Iranian threat actors.
    securityweek.com/cisa-urges-wa

  14. 📰 CISA and FBI Warn of Attacks on US Water System PLCs

    CISA & FBI issue urgent warning on cyberattacks targeting US water systems. Malicious actors are compromising internet-exposed Rockwell PLCs, causing operational disruptions and boil water notices. Operators urged to remove OT from internet. #ICS #OT...

    🔗 cyber.netsecops.io/articles/ci

  15. 🚨 SIGINT // Cybersecurity Watch — 2026-08-02
    US warns Iranian hackers are actively targeting Siemens, Schneider Electric & Rockwell ICS devices, raising critical infrastructure risk.
    securityweek.com/us-warns-of-i

  16. Einordnung: Der Fall zeigt, warum Steuerungstechnik nicht unnötig direkt aus dem Internet erreichbar sein darf. Selbst einfache Zugriffe können reale Abläufe stören. Entscheidend sind getrennte Netze, sichere Fernzugänge und ein Betrieb, der notfalls auch manuell weiterlaufen kann.

    @HonkHase kennt sich damit aber sicher noch besser aus. 😉

    2/2

    #ITSicherheit #KritischeInfrastruktur #Kritis #OT #KuketzAugust

  17. Einordnung: Der Fall zeigt, warum Steuerungstechnik nicht unnötig direkt aus dem Internet erreichbar sein darf. Selbst einfache Zugriffe können reale Abläufe stören. Entscheidend sind getrennte Netze, sichere Fernzugänge und ein Betrieb, der notfalls auch manuell weiterlaufen kann.

    @HonkHase kennt sich damit aber sicher noch besser aus. 😉

    2/2

    #ITSicherheit #KritischeInfrastruktur #Kritis #OT #KuketzAugust

  18. Seit dem 27. Juli wurden Wasserversorger in mindestens sieben US-Bundesstaaten angegriffen. Betroffen waren unter anderem Steuerungen technischer Anlagen. Einige Versorger meldeten Betriebsstörungen, die Trinkwasserqualität sei nach bisherigen Angaben nicht beeinträchtigt worden.

    reuters.com/world/us-cyber-def

    1/2

    #ITSicherheit #KritischeInfrastruktur #Kritis #OT #KuketzAugust

  19. Seit dem 27. Juli wurden Wasserversorger in mindestens sieben US-Bundesstaaten angegriffen. Betroffen waren unter anderem Steuerungen technischer Anlagen. Einige Versorger meldeten Betriebsstörungen, die Trinkwasserqualität sei nach bisherigen Angaben nicht beeinträchtigt worden.

    reuters.com/world/us-cyber-def

    1/2

    #ITSicherheit #KritischeInfrastruktur #Kritis #OT #KuketzAugust

  20. Following the cyberattacks on water & wastewater (WWS) in the U.S. over the last week, we looked at exposure of Rockwell, Siemens, and Schneider Electric devices, as those are vendors explicitly named in CISA’s updated advisory on this activity (cisa.gov/news-events/cybersecu).

    Rockwell exposures have declined about 21% since we last looked at this in April, primarily driven by a drop in U.S. exposures.

    While this is encouraging, I want to note this line from CISA’s most recent alert:
    > Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses.

    I’ll also note this from an FBI alert about the activity:
    > At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers.

    I’m going out on a limb to say this is not the same flavor of hacktivist activity we have seen around WWS in the recent past. This feels distinctly different and potentially more harmful.

    More details on the exposures:

    censys.com/blog/cisa-alert-wat

    #ICS #OT #water #cyberattack #infosec

  21. Following the cyberattacks on water & wastewater (WWS) in the U.S. over the last week, we looked at exposure of Rockwell, Siemens, and Schneider Electric devices, as those are vendors explicitly named in CISA’s updated advisory on this activity (cisa.gov/news-events/cybersecu).

    Rockwell exposures have declined about 21% since we last looked at this in April, primarily driven by a drop in U.S. exposures.

    While this is encouraging, I want to note this line from CISA’s most recent alert:
    > Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses.

    I’ll also note this from an FBI alert about the activity:
    > At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers.

    I’m going out on a limb to say this is not the same flavor of hacktivist activity we have seen around WWS in the recent past. This feels distinctly different and potentially more harmful.

    More details on the exposures:

    censys.com/blog/cisa-alert-wat

    #ICS #OT #water #cyberattack #infosec

  22. 📰 CISA and FBI Warn of Attacks on US Water System PLCs

    CISA & FBI issue urgent warning on cyberattacks targeting US water systems. Malicious actors are compromising internet-exposed Rockwell PLCs, causing operational disruptions and boil water notices. Operators urged to remove OT from internet. #ICS #OT...

    🔗 cyber.netsecops.io/articles/ci

  23. Sidewinder Thursday Way Point C-J The Force will be with you Always: Remembering Star Wars Canyon and the Jedi Transition USAF F-22A Raptor 04-0120 of the 422nd Test and Evaluation Squadron, July 2018. #USAF #StarWars #JediTransition #cvvhrn #AvGeek #OT #aviationphotography #photography #R2508 #lowlevel #sidewinder

  24. Sidewinder Thursday Way Point C-J The Force will be with you Always: Remembering Star Wars Canyon and the Jedi Transition USAF F-22A Raptor 04-0120 of the 422nd Test and Evaluation Squadron, July 2018. #USAF #StarWars #JediTransition #cvvhrn #AvGeek #OT #aviationphotography #photography #R2508 #lowlevel #sidewinder

  25. 📰 CISA Urges OT Isolation in New 'CI Fortify' Critical Infrastructure Guide

    CISA & international partners release "CI Fortify" guidance, urging critical infrastructure to plan for physical isolation of OT systems from IT networks during cyberattacks. The goal: protect vital services like energy & water. #CISecurity #OT #ICS

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  26. Minnesota : attaque coordonnée contre les systèmes OT de plus de 30 réseaux d'eau potable, une station hors ligne. Réponse d'État déclenchée.

    La criticité n'est pas dans les grands opérateurs : elle est distribuée dans des milliers de petites structures peu armées.

    #cybersécurité #OT

  27. Minnesota : attaque coordonnée contre les systèmes OT de plus de 30 réseaux d'eau potable, une station hors ligne. Réponse d'État déclenchée.

    La criticité n'est pas dans les grands opérateurs : elle est distribuée dans des milliers de petites structures peu armées.

    #cybersécurité #OT

  28. 📰 CISA Urges OT Isolation in New 'CI Fortify' Critical Infrastructure Guide

    CISA & international partners release "CI Fortify" guidance, urging critical infrastructure to plan for physical isolation of OT systems from IT networks during cyberattacks. The goal: protect vital services like energy & water. #CISecurity #OT #ICS

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  29. Over 30 Minnesota water utilities hit in a coordinated OT attack. Critical infrastructure + operational technology = a combination where patch cycles, legacy systems, and physical consequences converge. The "air gap" assumption hasn't aged well. The hard question isn't *if* OT gets targeted — it's whether detection is in place when it does. #infosec #OT
    bleepingcomputer.com/news/secu

  30. Over 30 Minnesota water utilities hit in a coordinated OT attack. Critical infrastructure + operational technology = a combination where patch cycles, legacy systems, and physical consequences converge. The "air gap" assumption hasn't aged well. The hard question isn't *if* OT gets targeted — it's whether detection is in place when it does. #infosec #OT
    bleepingcomputer.com/news/secu

  31. CW: release notes for Malcolm v26.07.1, a network traffic analysis tool suite for network security monitoring

    Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

    If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

    github.com/idaholab/Malcolm/co

    • Features and enhancements

      • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
      • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
      • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
      • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
      • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
    • 🛡️ Security Remediation & Hardening

      • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
      • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
      • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
      • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
    • 🐛 Bug fixes

      • Co-installation of opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)
      • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
      • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
      • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
      • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
      • Restore curl to the the htadmin container for use by the health check script #1029
      • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
      • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
      • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
    • Component version updates

    • 🧹 Code and project maintenance

      • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
      • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
      • Improve installer validation, environment-variable mapping tests, and configuration item metadata
      • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
      • Minor improvements to the Hedgehog Raspberry Pi image build process.
    • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

      • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
      • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
      • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data

    Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

    Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

    Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

    As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

    #Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

  32. CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring

    Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

    If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

    github.com/idaholab/Malcolm/co

    • Features and enhancements

      • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
      • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
      • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
      • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
      • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
    • 🛡️ Security Remediation & Hardening

      • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
      • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
      • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
      • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
    • 🐛 Bug fixes

      • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
      • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
      • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
      • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
      • Restore curl to the the htadmin container for use by the health check script #1029
      • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
      • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
      • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
    • Component version updates

    • 🧹 Code and project maintenance

      • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
      • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
      • Improve installer validation, environment-variable mapping tests, and configuration item metadata
      • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

      • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
      • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
      • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
    • Errata

      • Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.

    Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

    Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

    Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

    As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

    #Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

  33. Legacy Systems, Real-World Impacts: The Reality of OT Security

    In his latest SecurityWeek column, runZero's Tod Beardsley explores why vulnerability management in #OT is a completely different ballgame.

    As OT/IT convergence accelerates, we need to evolve our defense strategies before AI-assisted attackers take advantage of the hidden exposures and broken segmentation in these environments.

    Read Tod’s full analysis here: ➡️ securityweek.com/legacy-system

    #ot
  34. Legacy Systems, Real-World Impacts: The Reality of OT Security

    In his latest SecurityWeek column, runZero's Tod Beardsley explores why vulnerability management in #OT is a completely different ballgame.

    As OT/IT convergence accelerates, we need to evolve our defense strategies before AI-assisted attackers take advantage of the hidden exposures and broken segmentation in these environments.

    Read Tod’s full analysis here: ➡️ securityweek.com/legacy-system

    #ot
  35. #funnyspam #ot

    From time to time I receive spam that's funny. This one is offering personalised marketing as a service, but forgot to personalise the message, leaving a placeholder template variable in place.

  36. #funnyspam #ot

    From time to time I receive spam that's funny. This one is offering personalised marketing as a service, but forgot to personalise the message, leaving a placeholder template variable in place.

  37. Any #OTSecurity account worth following ? Any ideas/recommendations ? #infosec #ot #security

  38. Any #OTSecurity account worth following ? Any ideas/recommendations ? #infosec #ot #security

  39. Applizieren wir das jetzt auf das vorhandene Problem:

    • China produziert offensichtlich sowohl beliebte "dumme" Komponenten wie Panels als auch beliebte "schlaue" Komponenten wie die Wechselrichter.
    • Letztere haben leider ein Plasterouter-Syndrom.

    • Deutschland hat ein massives Hinterherhinken in Rollout was dezentrale Solar/Renwables+Storage angeht wenn man den Daten trauen kann.

    • Noch mehr Regulation und Markteingriff wird hier absehbar nicht zu mehr Rollout, Verfügbarkeit und preislicher Attraktivität führen. Es gilt also den "Wild-West-Modus" aktiv zu embracen und zu nutzen.

    • Es wirkt auf mich wie eine interessante Idee ein OpenWRT der Wechselrichter sowohl auf Software als auch Hardware-Ebene zu triggern.

    • Das Ziel sollte hier dann sein, dass China Hardware in Masse baut die im wesentlichen diese Blaupausen relativ unverändert umsetzt es aber gleichzeitig ermöglicht wird in Europa die aktuellste Version von "Wechselrichter OpenWRT" drauf zu flashen und aktuell zu halten.

    • Hier könnte sich eine Förderung a la @sovtechfund / STF durchaus lohnen.

    • Ebenfalls wäre u.U. eine Nutzung im Lehrbetrieb auch nützlich.

    • Differenzierende Angebote Dritter und somit Wettbewerb sind auf dieser Basis vermutlich immer noch grundsätzlich möglich.

    • Vermutlich dürfte hier die sinnvolle Regulationslandschaft deutlich struppiger sein als für den allgemeinen Homerouter basierend darauf, dass es sich hier um Leistungshardware handelt.

    • Dort ist aber letztlich ohnehin durch die üblichen Ansprüche der EU hinsichtlich kontinuierlicher Wartung ohnehin ein Wandel zu erwarten. 'We're not doing it because it's easy, we're doing it because its hard' or so said someone some other time...

    #Wechselrichter #stf #sovereigntechfund #wechselrichterWRT #leistungselektronik #ot

  40. Gammel-OT, jetzt neu: Verteilt, unisoliert, noch verrotteter als sonst. Quasi die Plasterouter-Version von Groß-OT für das es ja wenigstens noch manchmal etwas zwangsmäßigen Effort gibt. Plasterouter-OT sozusagen.

    heise.de/news/Sicherheitsalbtr

    Die Schwachstelle klingt...uhm...garstig. Besonders der Drohnenansatz gefält. 😱

    #ot #plasterouter #gammelot #solarpunk #solarpower #blackout

  41. Gammel-OT, jetzt neu: Verteilt, unisoliert, noch verrotteter als sonst. Quasi die Plasterouter-Version von Groß-OT für das es ja wenigstens noch manchmal etwas zwangsmäßigen Effort gibt. Plasterouter-OT sozusagen.

    heise.de/news/Sicherheitsalbtr

    Die Schwachstelle klingt...uhm...garstig. Besonders der Drohnenansatz gefält. 😱

    #ot #plasterouter #gammelot #solarpunk #solarpower #blackout

  42. Incident playbooks should understand process impact, safe rollback paths, and physical fallback strategies.

    Read more 👉 lttr.ai/As3Ka

    #Security #Infosec #OT