Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

via the respected information security capabilities of Robert M. Lee & the superlative illustration talents of Jeff Haas at Little Bobby Comics.

Robert M. Lee's & Jeff Haas' Little Bobby Comics - 'WEEK 265' →

February 24, 2020 by Marc Handelman in Little Bobby Comics, Security Humor, Sarcasm, Satire, Robert M. Lee, Jeff Haas, ICS
February 24, 2020 /Marc Handelman
Little Bobby Comics, Security Humor, Sarcasm, Satire, Robert M. Lee, Jeff Haas, ICS

via the respected information security capabilities of Robert M. Lee & the superlative illustration talents of Jeff Haas at Little Bobby Comics.

Robert M. Lee's & Jeff Haas' Little Bobby Comics - 'WEEK 261'

January 27, 2020 by Marc Handelman in Little Bobby Comics, Jeff Haas, Robert M. Lee, Information Security, ICS, Security Humor
January 27, 2020 /Marc Handelman
Little Bobby Comics, Jeff Haas, Robert M. Lee, Information Security, ICS, Security Humor

via the respected information security capabilities of Robert M. Lee & the superlative illustration talents of Jeff Haas at Little Bobby Comics.

Robert M. Lee's & Jeff Haas' Little Bobby Comics, 'The Highway' →

December 22, 2019 by Marc Handelman in Robert M. Lee, Jeff Haas, Little Bobby Comics, Security Humor, ICS Protocols, ICS, Sarcasm, Satire
December 22, 2019 /Marc Handelman
Robert M. Lee, Jeff Haas, Little Bobby Comics, Security Humor, ICS Protocols, ICS, Sarcasm, Satire

via the respected information security capabilities of Robert M. Lee & the superlative illustration talents of Jeff Hass at Little Bobby Comics.

Robert M. Lee's & Jeff Haas' Little Bobby Comics, 'Power Grid' →

October 18, 2019 by Marc Handelman in ICS, ICS Protocols, Common Sense, Sarcasm, Satire, SCADA, Electrical Engineering, Cyberwar, Security Humor
October 18, 2019 /Marc Handelman
ICS, ICS Protocols, Common Sense, Sarcasm, Satire, SCADA, Electrical Engineering, Cyberwar, Security Humor

Electrifying: Play-By-Play

September 12, 2019 by Marc Handelman in ICS, ICS/SCADA, Information Security, Electrical Engineering, Utility Companies, Utility Providers, Utilities, Cybersecurity, Cyber Statecraft

via William Knowle's Infosec News (a security news compilation organization), comes this fascinating North American Electric Reliability Corporation (NERC) report document (expertly presented by E&ENews Reporter Blake Sobczak) - ostensibly, a 'play-by-play' of the first cyberattack of a US Energy Utility. Think it can't happen here? It already has...

"But the March 5 event was significant enough to spur the victim utility to report it to the Department of Energy, marking the first disruptive "cyber event" on record for the U.S. power grid (Energywire, April 30). The case offered a stark demonstration of the risks U.S. power utilities face as their critical control networks grow more digitized and interconnected — and more exposed to hackers. "Have as few internet facing devices as possible," NERC urged in its report." - via E&ENews reporter Blake Sobczak

September 12, 2019 /Marc Handelman
ICS, ICS/SCADA, Information Security, Electrical Engineering, Utility Companies, Utility Providers, Utilities, Cybersecurity, Cyber Statecraft

DEF CON 27, Early Release, WillC's 'Phreaking Elevators' →

August 25, 2019 by Marc Handelman in Conferences, DEF CON, Information Security, Hardware Security, ICS, Safety

Thanks to Def Con 27 for early publishing their outstanding conference videos on their YouTube Channel.

August 25, 2019 /Marc Handelman
Conferences, DEF CON, Information Security, Hardware Security, ICS, Safety

SANS ICS Security Summit 2019, Jason Christopher's 'Creating a Security Metrics Program: How To Measure Success' →

July 24, 2019 by Marc Handelman in Threat Intelligence, SANS, SANS CTI, SANS CTI Summit, SANS DFIR, Information Security, ICS, Education, Conferences
July 24, 2019 /Marc Handelman
Threat Intelligence, SANS, SANS CTI, SANS CTI Summit, SANS DFIR, Information Security, ICS, Education, Conferences

via the respected information security capabilities of Robert M. Lee & the superb illustration talents of Jeff Haas at Little Bobby Comics.

Robert M. Lee's & Jeff Haas' Little Bobby Comics: 'Defense' →

July 15, 2019 by Marc Handelman in Little Bobby Comics, ICS, Information Security, Security Humor
July 15, 2019 /Marc Handelman
Little Bobby Comics, ICS, Information Security, Security Humor

ICS Attacks, The Real National Emergency

June 20, 2019 by Marc Handelman in ICS/SCADA, ICS, Information Warfare, Information Technology, Information Security, Network Security, Network Protocols, ICS Protocols

News, via the astonishingly prolific security writer Dan Goodin, editing, and reporting at Ars Technica, tells the tale of oil and gas network attacks in the United States, by a group monikered Xenotime. Think we're protected? Think again. Read the Dragos security researcher's post for truly concerning national security relevance.

"The group, now dubbed Xenotime by Dragos, quickly gained international attention in 2017 when researchers from Dragos and the Mandiant division of security firm FireEye independently reported Xenotime had recently triggered a dangerous operational outage at a critical-infrastructure site in the Middle East." via Dan Goodin, Security Editor reporting at Ars Technica

##

"Ultimately, XENOTIME’s expansion to an additional ICS vertical is deeply concerning given this entity’s willingness to undermine fundamental process safety in ICS environments placing lives and environments at great risk. - via Dragos

June 20, 2019 /Marc Handelman
ICS/SCADA, ICS, Information Warfare, Information Technology, Information Security, Network Security, Network Protocols, ICS Protocols

When a Tree Falls in St. Louis, Will the Power Go Out?

May 09, 2019 by Marc Handelman in Physical Power Networks, Forestry, Artificial Intelligence, Machine VIsion, Machine Learning, UAV, ICS/SCADA, ICS, Electrical Engineering, Infrastructure, Infrastructure Security

A superlative bit of combinatorial scholarship coming out of St. Louis University, where Sean Hartling, Vasit Sagan, Paheding Sidike, Maitiniyazi Maimaitijiang and Joshua Carron have lashed-up geospatial sciences, machine learning, UAVs, and no-small level of intellectual virtuosity to study trees, the natural felling thereof, and power outages. Todays' Must Read for you ICS Boffins and Foresty geeks (while not ignoring the AI, ML, UAv and Network Information Security types as well).

"At SLU, geospatial science meets machine learning. In a study recently published in Sensors, Saint Louis University researchers paired satellite imaging data with machine learning techniques to map local tree species and health. The data generated by the project will help inform best practices for managing healthy green spaces as well as trimming programs to avoid power outages following storms." - via Carrie Bebermeyer, Senior Media Relations Specialist at St. Louis University

May 09, 2019 /Marc Handelman
Physical Power Networks, Forestry, Artificial Intelligence, Machine VIsion, Machine Learning, UAV, ICS/SCADA, ICS, Electrical Engineering, Infrastructure, Infrastructure Security

Via the Erudite Security Mindset of Robert M. Lee & the Superlative Illustration Talents of Jeff Haas at Little Bobby Comics.

Robert M. Lee's and Jeff Haas' Little Bobby Comics, 'It's Not A Light Switch'

November 04, 2018 by Marc Handelman in Security Education, Security Comics, Security, SCADA, Satire, Sarcasm, ICS, Security Humor, Little Bobby Comics
November 04, 2018 /Marc Handelman
Security Education, Security Comics, Security, SCADA, Satire, Sarcasm, ICS, Security Humor, Little Bobby Comics

via the Security Mindset of Robert M. Lee and Illustration talents of Jeff Haas at Little Bobby Comics

Robert M. Lee and Jeff Haas' Little Bobby Comics 'ICS Vulnerabilities' →

September 02, 2018 by Marc Handelman in Little Bobby Comics, Security Humor, Security Comics, Sarcasm, Satire, ICS, ICS/SCADA
September 02, 2018 /Marc Handelman
Little Bobby Comics, Security Humor, Security Comics, Sarcasm, Satire, ICS, ICS/SCADA

via the Security Mindset of Robert M. Lee and Illustration talents of Jeff Haas at Little Bobby Comics

Robert M. Lee and Jeff Haas' Little Bobby Comics 'What Is IT-OT Convergence?' →

August 27, 2018 by Marc Handelman in Little Bobby Comics, Security Humor, Sarcasm, Satire, ICS/SCADA, ICS
August 27, 2018 /Marc Handelman
Little Bobby Comics, Security Humor, Sarcasm, Satire, ICS/SCADA, ICS

All's Not Quiet On The SCADA Front →

May 03, 2018 by Marc Handelman in Hardware Security, ICS/SCADA, ICS, Information Security, Network Security, Must Read, Water Systems

via Zack Whittaker timely reportage for ZDNet's Zero Day group, his work provides insight to the tangled-web-we-weave in the ICS/SCADA world. This time - the ramifications of a particularly-pesky security flaw in a Schneider product (amongst thousands of other known bugs in hundreds of other software packages coupled with poor software management practices in the industrial control systems sector combine to make a very poor nap at the control boards, indeed. Just ask Homer! Today's Critical Must Read Choice.

"It's the latest vulnerability that risks an attack to the core of any major plant's operations at a time when these systems have become a greater target in recent years. The report follows a recent warning, issued by the FBI and Homeland Security, from Russian hackers. The affected Schneider software, InduSoft Web Studio and InTouch Machine Edition, acts as middleware between industrial devices and their human operators. It's used to automate the various moving parts of a power plant or manufacturing unit, by keeping tabs on data collection sensors and control systems. " - via Zack Whittaker writing for ZDNet's Zero Day

May 03, 2018 /Marc Handelman
Hardware Security, ICS/SCADA, ICS, Information Security, Network Security, Must Read, Water Systems

BruCON 0x09, Arnaud Soullié's 'DYODE - Do Your Own Dyode' →

December 27, 2017 by Marc Handelman in BruCON, Conferences, Education, Information Security, ICS, ICS/SCADA
December 27, 2017 /Marc Handelman
BruCON, Conferences, Education, Information Security, ICS, ICS/SCADA

Radvanovsky's RuggedTrax →

December 02, 2015 by Marc Handelman in All is Information, Control Systems, ICS/SCADA, ICS, Information Sharing, Internetwork Security, Information Security

Bob Radvanovsky, of Infracritical SCADASEC fame and Critical Infrastructure Protection and Cyber Security Researcher, has completed the RuggedTrax project, and published the findings thereto. Outstanding work Mr. Radvanovsky.

December 02, 2015 /Marc Handelman
All is Information, Control Systems, ICS/SCADA, ICS, Information Sharing, Internetwork Security, Information Security

Chuvakin, Tanks versus Tractors →

August 13, 2015 by Marc Handelman in ICS/SCADA, Information Security, ICS, All is Information, IoT, Alternate Attack Analysis

Via Gartner Research Vice President Anton Chuvakin, Ph.D., comes a superb screed prompted by JeepGate. Today's Must Read.

August 13, 2015 /Marc Handelman
ICS/SCADA, Information Security, ICS, All is Information, IoT, Alternate Attack Analysis

ICS Cyber-Incidents Not Identified, Reported →

July 14, 2015 by Marc Handelman in All is Information, ICS/SCADA, ICS, Information Security

In a tour de force post on the Unfettered blog, highly respected Industrial Control Systems Information Security Professional Joe Weiss targets systemic problems in the ICS arena. One of those problems is apparently the correct identification and reporting of security incidents in the ICS realm. If you read anything today on ICS / SCADA information and Network Security, read Joes' blog post - it's simply that important.

July 14, 2015 /Marc Handelman
All is Information, ICS/SCADA, ICS, Information Security

Infographica, SANS ICS

July 08, 2015 by Marc Handelman in All is Information, ICS/SCADA, ICS, Information Security
July 08, 2015 /Marc Handelman
All is Information, ICS/SCADA, ICS, Information Security

NIST Releases Revision 2, Guide to Industrial Control Systems (ICS) Security

June 09, 2015 by Marc Handelman in All is Information, Governance, Hardware Security, ICS, ICS/SCADA, Information Security

The National Institute of Standards and Technology (NIST) has announced the release of Special Publication 800-82, Revision 2, Guide to Industrial Control Systems (ICS) Security. Outstanding.

June 09, 2015 /Marc Handelman
All is Information, Governance, Hardware Security, ICS, ICS/SCADA, Information Security
  • Newer
  • Older