Marco Ayala

77 Followers
171 Following
136 Posts
IACS - SIS, SCADA Security, 27+yrs Field Experience O&G, ChemSector, Maritime | (ISA) VP Elect for Automation and Technology 2023
Over 2 million electric customers are without power in #Texas due to #HurricaneBeryl.
[2024-07-08 9:20 AM CDT]
https://poweroutage.us/area/state/texas
#PowerOutage
Texas Power Outages Map, May 2025

Fresh MOVEit Bug Under Attack Mere Hours After Disclosure
https://www.darkreading.com/remote-workforce/fresh-moveit-bug-under-attack-disclosure
Fresh MOVEit Bug Under Attack Mere Hours After Disclosure

The high-severity CVE-2024-5806 allows cyberattackers to authenticate to the file-transfer platform as any valid user, with accompanying privileges.

Don't know whether to laugh or cry. Here's how shady AI travel guides get it very wrong (and maybe even ruin your vacation?).
#travel #ArtificialIntelligence #TravelGuides #Cyber

https://www.youtube.com/watch?v=BLRF8gkpeNE

Fake authors are swindling people with shady AI travel guides

YouTube
The flood of shady AI travel guides by deepfake authors continues unabated. We fact checked six of these guides and found major errors that could seriously derail your vacation.
#CyberNews #ArtificialIntelligence #Travel #TravelGuides
amperesec.com/newsarchive/fake-authors-are-swindling-people-with-shady-ai-travel-guides
https://www.youtube.com/watch?v=RpbgLNS79l8
This is a crazy video from inside an Indian scam call center.
Showing Scammers Their Own CCTV Cameras On My Computer!

YouTube

Okta warns that a Customer Identity Cloud (CIC) feature is being targeted in credential stuffing attacks, stating that numerous customers have been targeted since April.

https://www.bleepingcomputer.com/news/security/okta-warns-of-credential-stuffing-attacks-targeting-its-cors-feature/

Okta warns of credential stuffing attacks targeting its CORS feature

Okta warns that a Customer Identity Cloud (CIC) feature is being targeted in credential stuffing attacks, stating that numerous customers have been targeted since April.

BleepingComputer

Check out my latest CSO column that delves into an attack on remote solar monitoring devices in Japan and highlights how solar inverters are a more serious cybersecurity risk to the solar power grid.

Many thanks to Willem Westerhof of Secura, Thomas Tansy of DER Security, and Andrew Ginter of Waterfall Waterfall Security Solutions for their insight.

https://www.csoonline.com/article/2119281/hijack-of-monitoring-devices-highlights-cyber-threat-to-solar-power-infrastructure.html

Hijack of monitoring devices highlights cyber threat to solar power infrastructure

An attack on remote monitoring devices in Japan underscores an emerging cybersecurity threat to the rapidly growing solar component of the power grid. Inverters used with solar panels could pose a more significant risk.

CSO Online

​Google has released a security update for the Chrome browser to fix the fifth zero-day vulnerability exploited in the wild since the start of the year.

https://www.bleepingcomputer.com/news/security/google-fixes-fifth-chrome-zero-day-vulnerability-exploited-in-attacks-in-2024/

Google fixes fifth Chrome zero-day exploited in attacks this year

​Google has released a security update for the Chrome browser to fix the fifth zero-day vulnerability exploited in the wild since the start of the year.

BleepingComputer
Nobody knows how AI works

It’s still early days for our understanding of AI, so expect more glitches and fails as it becomes a part of real-world products.

MIT Technology Review

This was the big concern about Chinese cranes that emerged in my discussions with OT experts back in January 2023. What @ICS_SCADA called "ET phone home."

https://www.csoonline.com/article/574327/us-maritime-administrator-to-study-port-crane-cybersecurity-concerns.html

"A congressional probe of Chinese-built cargo cranes deployed at ports throughout the U.S. has found communications equipment that doesn’t appear to support normal operations."

Espionage Probe Finds Communications Device on Chinese Cargo Cranes
https://www.wsj.com/politics/national-security/espionage-probe-finds-communications-device-on-chinese-cargo-cranes-867d32c0?mod=panda_wsj_author_alert

US Maritime Administrator to study port crane cybersecurity concerns

Recently passed legislation might have been spurred by supply chain disruption and surveillance concerns enabled by Chinese-made cranes.

CSO Online