alucab's Avatar

alucab

@alucab.bsky.social

Deep in the trenches of IoT/OT/IoMT Cyber Security. Keeping critical infra safe and often calling BS. Views expressed here are mine (and sometimes unfiltered).

48 Followers  |  126 Following  |  37 Posts  |  Joined: 26.12.2024  |  1.9571

Latest posts by alucab.bsky.social on Bluesky

Preview
#devsecops #ci #githubactions #supplychainsecurity #cybersecurity | Luca Barba ๐Ÿšจ That "harmless" third-party GitHub action? It was a Trojan horse ๐Ÿด Your CI/CD pipeline, the backbone of your development, just got served a harsh reality check. That "harmless" third-party GitHubโ€ฆ

๐Ÿšจ That "harmless" third-party GitHub action? It was a Trojan horse ๐Ÿด

#devsecops #ci #githubactions #supplychainsecurity #cybersecurity

14.04.2025 15:25 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Why Codefinger represents a new stage in the evolution of ransomware Forget typical ransomware! Codefinger hijacked cloud keys directly, exposing backup flaws and shared responsibility risks. Time to rethink defense.

Why Codefinger represents a new stage in the evolution of ransomware

12.04.2025 17:42 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
NIST Special Publication (SP) 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile This publication seeks to assist organizations with incorporating cybersecurity incident response recommendations and considerations throughout their cybersecurity risk management activities as descri...

NIST has dropped some new guidance on IR and how it fits into CSF 2.0.
csrc.nist.gov/pubs/sp/800/...

05.04.2025 12:25 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

NSA, CISA, FBI, and International Partners Release Cybersecurity Advisory on โ€œFast Flux,โ€ a National Security Threat | CISA

05.04.2025 13:12 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Four Years In: What NERCโ€™s Cyber Security Incident Reporting Data Tells Us (and What It Doesnโ€™t) โ€” AMPYX CYBER In the world of Bulk Electric System (BES) cybersecurity, signals of risk donโ€™t always arrive with alarms blaring or malware lighting up dashboards. Sometimes, the signs are quieterโ€”brute force loginโ€ฆ

Four Years In: What NERCโ€™s Cyber Security Incident Reporting Data Tells Us (and What It Doesnโ€™t) โ€” AMPYX CYBER buff.ly/czFPfPC

05.04.2025 14:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Dispersed responsibility, lack of asset inventory is causing gaps in medical device cybersecurity As medical devices are bought and re-sold on the secondary market, they become harder to find and patch when a new vulnerability is discovered, a doctor told House lawmakers.

Dispersed responsibility, lack of asset inventory is causing gaps in medical device cybersecurity

05.04.2025 15:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
AI Image Site GenNomis Exposed 47GB of Underage Deepfakes Follow us on Blue Sky, Mastodon Twitter, Facebook and LinkedIn @Hackread

AI Image Site GenNomis Exposed 47GB of Underage Deepfakes

05.04.2025 15:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

5 Strategies to Strengthen Industrial Cybersecurity

05.04.2025 18:12 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Taylor Swift photo

Taylor Swift photo

Breaking: Director of National Intelligence Tulsi Gabbard has revoked the security clearance for Taylor Swift

29.03.2025 14:06 โ€” ๐Ÿ‘ 195    ๐Ÿ” 12    ๐Ÿ’ฌ 15    ๐Ÿ“Œ 1
Post image

Ever heard of a computer that uses water to solve complex math problems? ๐ŸŒŠ๐Ÿ’ก

In 1936, Soviet engineer Vladimir Lukyanov created the Water Integratorโ€”an analog computer using water flow, gravity, and pipes to solve differential equations.

#Innovation #Engineering #TechHistory #AnalogComputing

26.03.2025 16:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
#otsecurity #cybersecurity #ics #remoteaccess #threatdetection #lbsra | Luca Barba ๐ŸšจHow remote access creates multiple attack vectors in OT environments. #OTSecurity #CyberSecurity #ICS #RemoteAccess #ThreatDetection #LBSRA

๐ŸšจHow remote access creates multiple attack vectors in OT environments.
#OTSecurity #CyberSecurity #ICS #RemoteAccess #ThreatDetection #LBSRA

25.03.2025 16:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
#pypi #sbom #cybersecurity #supplychainattack #integrity | Luca Barba ๐Ÿšจ Supply Chain attack are becoming endemic - Malicious #PyPI Packages Stole Cloud Tokens ๐Ÿ’ก Remember that XKCD meme about open source? That one guy inโ€ฆ

๐Ÿšจ Supply Chain attack are becoming endemic - Malicious #PyPI Packages Stole Cloud Tokens ๐Ÿ’ก Remember that XKCD meme about open source? That one guy in Nebraska ?

#pypi #sbom #cybersecurity #supplychainattack #integrity

24.03.2025 18:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Must-Watch Cybersecurity TV Shows ๐ŸŽฏ๐Ÿ‘จโ€๐Ÿ’ป
Need some hacking inspiration or just love a good cyber-thriller?

๐Ÿ”ฅ Mr. Robot โ€“ The GOAT ๐Ÿ
๐Ÿ•ต๏ธโ€โ™‚๏ธ Person of Interest โ€“ Predict future?
๐Ÿ’ฅ Black Mirror โ€“ Every episode = existential crisis ๐Ÿ˜ณ

#CyberSecurity #Hacking #TechThriller #TVSeries

21.03.2025 12:33 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
#cybersecurity #zeroday #criticalinfrastructure #otsecurity #infosec | Luca Barba Are you watching "Zero Day" ? More Drama Than Reality, But Still Relevant ๐Ÿค” While Zero Day serves up a synchronized digital apocalypse, it's more Hollywood than real life. But it does spark a vitalโ€ฆ

Are you watching "Zero Day" ?

Ideal to bring your siblings, your mother, your friends and brag about your job, and it is also a lot of fun. ๐Ÿ˜‰

#Cybersecurity #ZeroDay #CriticalInfrastructure #OTSecurity #InfoSec

20.03.2025 08:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Cost of a Data Breach
In 2024, the average cost of a data breach reached an all-time high of $4.88 million

#cybersecurity #databreach #infosec #cyberresilience
buff.ly/xdE7A0N

19.03.2025 16:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image 19.03.2025 08:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

600+ systems down. A hospital paralyzed.

#CyberSecurity #Ransomware #HealthcareSecurity #ThreatIntel #IoMTSecurity

buff.ly/qT46Pxl

18.03.2025 16:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ”Ž Solar Panels: The New Frontline in Cyber Warfare

Hackers have found a new way to target critical infrastructureโ€”through your solar panels.

#Cybersecurity #RenewableEnergy #CriticalInfrastructure #OTSecurity

buff.ly/zkVTF2X

18.03.2025 08:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

IT vs. OT Cybersecurity Champions

๐ŸŽฏ IT: Certified to the moon ๐ŸŒ™ โ€“ CISA, CISSP, CCNA, ITILโ€ฆ
๐Ÿ”ซ OT: Just give me IEC 62443, SANS, and a wrench.

#CyberSecurity #OTSecurity #ITvsOT #ICS #IndustrialSecurity #CyberChampion

17.03.2025 16:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
#otsecurity #ics #cyberthreats #ransomware #industrialcybersecurityโ€ฆ | Luca Barba ๐Ÿ”ด OT security isnโ€™t a niche problem anymoreโ€”itโ€™s a battlefield. 2024 saw an 87% rise in ransomware attacks targeting OT and two new ICS-specific malwareโ€ฆ

2024 saw an 87% rise in ransomware attacks targeting OT and two new ICS-specific malware

#otsecurity #ics #cyberthreats #ransomware

14.03.2025 16:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

eyeInspect is a robust solution designed to safeguard operational technology (OT) and Internet of Things (IoT) environments.

Continuous updates are critical to keep the defense

buff.ly/RAzHrB1

#OTSecurity #Cybersecurity #Forescout #ITOT

13.03.2025 16:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
#cybersecurity #otsecurity #itotconvergence #manufacturing #riskmanagement | Luca Barba ๐Ÿ”ด Manufacturingโ€™s Silent Cyber Crisis: IT/OT Convergence Under Attack 75% of cyber incidents in manufacturing last year hit converged IT/OT environmentsโ€”andโ€ฆ

Manufacturingโ€™s Silent Cyber Crisis: 75% of cyber incidents in manufacturing last year hit converged IT/OT environments

#cybersecurity #otsecurity #itotconvergence #manufacturing #riskmanagement

13.03.2025 13:33 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Luca: "Let's experiment with GitHub Copilot for a quick script."

Also Luca: "Add code to line 76 to strip away all \n and \s from the variable named value and substitute them with a whitespace."

#GitHubCopilot #DeveloperHumor #AI #Programming

๐Ÿ‘‰ Copilot: [see pic๐Ÿ˜‚]

13.03.2025 08:36 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Luca Barba on LinkedIn: 2024 Threat Roundup from Forescout Vedere Labs 2024 Threat Roundup from Forescout Vedere Labs

10 countries account for 78% of malicious traffic

Top Cybersecurity Trends from Vedere Labs

12.03.2025 16:25 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
#otsecurity #ics #scada #cybersecurity #itot | Luca Barba ๐Ÿ” Schneiderโ€™s Move on RTU Cybersecurity Hereโ€™s the reality: Remote sitesโ€”whether in water treatment, pipelines, or energyโ€”are prime targets for cyberโ€ฆ

๐Ÿ” Schneider Electricโ€™s SCADAPack 470i & 474i take a different approach: baking IT-grade security into rugged OT devices without disrupting operations.

buff.ly/VcZz5YF

#OTSecurity #ICS #SCADA #CyberSecurity #ITOT

12.03.2025 08:36 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ”Ž Types of Cybercrimes on Social Networks

#CyberSecurity #OnlineSafety #DigitalThreat

11.03.2025 08:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ”Ž IoT: The New Ransomware Gateway

Vedere Labs warned in 2022 with R4IoTโ€”showing how ransomware can exploit IoT to pivot into IT/OT .
2024: Akira, responsible for 15% of incidents last year, just did it

#Cybersecurity #Ransomware #IoTSecurity
buff.ly/p3uqRRU

10.03.2025 16:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ” How to Spot a Penetration Tester

Pentesters leave digital footprints.
Are you monitoring these signs?

#CyberSecurity #Pentesting #RedTeam #BlueTeam #ThreatHunting

Credits : ACEResponder.com

07.03.2025 16:25 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ” "Cybersecurity experts" donโ€™t exist.

Cybersecurity isnโ€™t one skillโ€”itโ€™s an ecosystem. Risk assessment, governance, security operations, architecture, threat intelligenceโ€ฆ

No one masters it all.

#CyberSecurity #RiskManagement #ThreatIntelligence #InfoSec #SecurityOps

05.03.2025 16:25 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
#cybersecurity #userexperience #threatintelligence #datadriven #otsecurity | Luca Barba ๐Ÿ” When DrZeroTrust Put eyeInspect to the Test Seeing Dr. Chase Cunningham try out eyeInspectโ€”and its self-demo capabilityโ€”hits differently when you know theโ€ฆ

๐Ÿ” When DrZeroTrust Put eyeInspect to the Test

Seeing Dr. Chase Cunningham try out eyeInspectโ€”and its self-demo capabilityโ€”hits differently.

A seamless user experience isnโ€™t just a nice-to-have; itโ€™s the key to adoption.

#CyberSecurity #UserExperience

buff.ly/b2jdfwN

04.03.2025 08:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@alucab is following 18 prominent accounts