Hacking incidents in #healthcare have tripled from 2018 to 2022. To defend against cyberthreats, organizations should adopt an attacker's mindset, focusing on asset inventory and monitoring.
Learn how attackers operate in the digital age: https://t.co/1MaOt6M95T
#cybersecurity
@lcamtuf I would agree with this, but maybe not as strongly. Having an understanding of building blocks is good, you just need to add to it. A lot of what I've focused on is the behaviors of software rather than just the components of software.
Another example of why we need a better understanding of the behaviors of the software and hardware we use. Just trusting developers doesn't seem to work out.
This invasive Bluetooth car battery monitor was found to be sending the following location data to 🇨🇳
- GPS
- Wifi devices
- Cell phone towers
The Apple and Google app stores said no personal data was collected.
A new update has emerged. Let's see what was changed 👇(1/n)
Excited for my @RVAsec talk next Tuesday, June 13th. I'll be talking beyond #sbom: Software Bills of Behaviors and how they get to the core of what really matters for #softwaresupplychainsecurity: what will this software actually do if I use it?
https://t.co/SGyOKys5G3
Workers Launchpad Funding Program Cohort #1
Meet startup co-founders Andrew Hendela @zelkathak and Eric Lee @erhlee_bird of https://t.co/ApSNiveVHN @karambit_ai https://t.co/kQomFOCt10
Researchers have uncovered four new malicious packages in the #Python Package Index (PyPI) that sneak #malware onto developers' systems and manipulate their SSH authorized_keys.
Read: https://t.co/Dc6p52sBYc
#programming#coding#hacking#cybersecuritynews
We get asked a lot of questions about how we find unauthorized software modifications without source code and without running the compiled software. The best way to answer is often just to show you the results.
https://t.co/IZd4G1FZnT
#sbob#softwaresupplychain#cybersecurity
@drhyrum@malwareunicorn@CamlisOrg This was an excellent talk, getting right to all of the downfalls that those doing malware analysis have run into. Putting it all so succinctly was great.
There was a paper written by Todd Heberlein years ago called "The Advanced Persistent Threat You Have: Google Chrome" that basically said that Chrome is an #APT. Chrome does similar things to an APT but we don't think it is #Malware because it came from Google.
It is another good reminder that suppliers are a threat vector for important targets. Securing closed-source dependencies is as important as securing open-source ones.
@Securonix Threat Research team recently discovered a new covert attack campaign targeting multiple military/weapons contractor companies, including a strategic supplier to the F-35 Lightning II fighter aircraft. Read More! https://t.co/s2lu9RhgP0
Know what the software you are using is doing: https://t.co/DHQQ0mosQq is opening our Software Bill of Behaviors API to the public. Sign up for an API key, generate Software Bill of Behaviors for uploaded files, and analyze diff reports to see how these behaviors change over time
Thankfully this attack against a developer was caught, but it is a good reminder that adversaries are targeting development companies to use their software as an attack vector.