December 15, 2022
-
-
Kaspersky has some lessons learned from the cyber war
https://securelist.com/reassessing-cyberwarfare-lessons-learned-in-2022/108328/-
-
-
-
-
-
https://www.dw.com/en/us-bans-chinese-telecom-surveillance-cameras/a-63895206 https://support.reolink.com/hc/en-us/articles/360003432894-How-to-Add-Reolink-Cameras-and-NVRs-on-Reolink-App[allegedly there are bugdoors that allow re-pairing with QR codes. HILARIOUS]
-
-
-
Download the SIPRI Research Report ➡️ doi.org/10.55163/ELWL8…-
Very good paper on the cyber warfare that was and wasn’t in Ukraine.
https://carnegieendowment.org/2022/12/12/cyber-operations-in-ukraine-russia-s-unmet-expectations-pub-88607-
https://trts.io/h22RD https://mastodon.social/@rferl/109517379781922100According to the FSB, Vyacheslav Mamukov, a resident of the city of Khabarovsk, was handed the prison term after a local court found him guilty of planning to pass "classified data linked to transport infrastructure" to Ukraine for financial award.
-
https://malwaretech.com/opinions/tiktok-is-a-national-security-risk.html https://infosec.exchange/@instacyber/109516988770896100While I personally find the #TikTok privacy/security debate to be uninteresting, I thought it was worth sharing this piece by @malwaretech as an excellent example of clear and consumable security communication:
-
https://infosec.exchange/@tomatospy/109515334085177148I just posted the final Seriously Risky Business for this year:
- The Lawful Access Debate is Now the Child Safety Debate
- What the "Crypto Winter" means for Lazarus
- When insider trading extortion is good news
Thanks to Sherrod DeGrippo
for her thoughts! https://twitter.com/sherrod_im
-
https://mastodon.social/@dave_aitel/109506249627584221https://www.lawfareblog.com/section-308s-overbroad-restrictions-post-intelligence-community-jobs This is a very good piece because the law was written in a rush and is not very good
-
https://www.infosecurity-magazine.com/news/experts-warn-chatgpt-democratize/ https://infosec.exchange/@Weld/109514766138594273Woah!
“I told the AI that I wanted to write a software in Swift, I wanted it to find all Microsoft Office files from my MacBook and send these files over HTTPS to my webserver. I also wanted it to encrypt all Microsoft Office files on my MacBook and send me the private key to be used for decryption. It sent me the sample code, and this time there was no warning message at all, despite being potentially more dangerous than the phishing email.”
-
This is very exciting. A classic hack and leak information operation has been successful. What I find most interesting here is the media coverage of the content. These days the media is a lot less likely to cover information operations, so it’s unusual to see them happening again.
https://www.nytimes.com/2022/12/15/technology/russia-state-tv-ukraine-war.html-