iCyberFighter

@iCyberFighter@infosec.exchange
406 Followers
128 Following
428 Posts
Known as #Cybersecurity maven. A passionate cyber crisis management consultant training executive teams and CISO orgs on responding to whole-of-business cyber incidents. Opinions my own.
Twitter@iCyberFighter
Blog sitewww.icyberfighter.com

Biden-⁠Harris Administration Announces National Cyber Workforce and #Education Strategy.

The #NCWES is an effort to grow and strengthen middle class working families by equipping people with #cybersecurity workforce skills to fill the growing demand in this domain. https://www.whitehouse.gov/wp-content/uploads/2023/07/NCWES-2023.07.31.pdf | #infosec #infosecjobs

The story I wrote about a backdoor in a TETRA radio standard used by police/military/critical infrastructure for radio communications, got lots of interest yesterday, with many people calling out ETSI for keeping the encryption algorithms secret. I decided to publish my entire interview with Brian Murgatroyd of ETSI so readers can see his justifications for doing this, as well as his responses to other things we discussed. I think you'll find some of his responses surprising
https://zetter.substack.com/p/interview-with-the-etsi-standards
Interview with the ETSI Standards Organization That Created TETRA "Backdoor"

Brian Murgatroyd spoke with me about why his standards group weakened an encryption algorithm used to secure critical radio communications of police, military, critical infrastructure and others.

Zero Day
Good morning folks !
I feel seen… 😆 #cybersecurity #stressfuljobs
If you plan on being at #CyberWeek2023 - See you there! June 26th at the Cyber Crisis Management & Readiness event, we will be simulating an attack and sharing best practices in each stage. Register here: https://cyberweek.tau.ac.il/2023/Register
Register | Cyber Week 2023

#CyberWeek2023 is almost here!! Will you be in Tel Aviv for this awesome #cybersecurity event that encompasses all aspects of security? I will be there, look for me at the Cyber Crisis Management & Readiness event! #cybercrisis https://cyberweek.tau.ac.il/2023/Events/Cyber-Crisis-Management-%7Cfamp%7C-Readiness
Cyber Crisis Management & Readiness

Cyber Week 2023
[Keep your kids' data safer] #Microsoft agrees to pay $20 million in settlement over data collection on children using #Xbox: https://www.wsj.com/articles/microsoft-settles-charges-over-data-collection-on-children-using-xbox-90db4c3c | #childsafety #onlinesafety
Microsoft Settles Charges Over Data Collection on Children Using Xbox

Company agrees to pay $20 million and bolster privacy protections for child gamers

WSJ

This must be the day of really cool things... The University of Texas at Austin is launching a pilot program where students will offer #cybersecurity advice to small businesses free of charge.

University leaders say they hope the program, which is modeled after law-school clinics, in which student lawyers work pro bono, will eventually evolve into a 311-style service for companies grappling with cyberattacks to access free resources that the federal government cannot always provide. [Via WSJ --> Wired] https://www.wired.com/story/ut-austin-cybersecurity-clinic-311 | #infosec #SMBs #smbsecurity

The Bold Plan to Create Cyber 311 Hotlines

UT-Austin will join a growing movement to launch cybersecurity clinics for cities and small businesses that often fall through the cracks.

WIRED

[#Defcon #HackASat] I can barely deal with how COOL this is... First in space: #SpaceX and #NASA launched a satellite that hackers will attempt to infiltrate during DEF CON!

For the first time ever, researchers will be able to test the security of a satellite on-orbit at this year's Hack-A-Sat contest at DEF CON.

https://cyberscoop.com/moonlighter-hack-a-sat-defcon #infosec #ethicalhacking

First in space: SpaceX and NASA launch satellite that hackers will attempt to infiltrate during DEF CON

For the first time ever, researchers will be able to test the security of a satellite on-orbit at this year's Hack-A-Sat contest at DEF CON.

CyberScoop

Microsoft says SMB signing (aka security signatures) will be required by default for all connections to defend against #NTLMRelay attacks, starting with current Windows build (Enterprise edition) rolling out to Insiders in the Canary Channel.

In such attacks, threat actors force network devices (including domain controllers) to authenticate against malicious servers under the attackers' control to impersonate them and elevate privileges to gain complete control over the Windows domain. More here: https://www.bleepingcomputer.com/news/security/windows-11-to-require-smb-signing-to-prevent-ntlm-relay-attacks | #infosec

Windows 11 to require SMB signing to prevent NTLM relay attacks

Microsoft says SMB signing (aka security signatures) will be required by default for all connections to defend against NTLM relay attacks, starting with today's Windows build (Enterprise edition) rolling out to Insiders in the Canary Channel.

BleepingComputer