Sunday, December 11, 2022

What I'm Reading 12/11/2022 (and some bonus videos. It's like Oprah Winfrey visited and gave everyone a prize)

 We are still failing to learn the most important lesson in cybersecurity. That needs to change, fast

https://www.zdnet.com/article/we-are-still-failing-to-learn-the-most-important-lesson-in-cybersecurity-that-needs-to-change-fast/

Paying Maintainers isn’t a Magic Bullet


https://blog.hansenpartnership.com/paying-maintainers-isnt-a-magic-bullet/

Meta, Amazon, Twitter layoffs: 'Tech layoffs won't destroy American dreams of Indians’


https://www.bbc.com/news/world-asia-india-63804055?at_medium=RSS&at_campaign=KARANGA

Turns Out, Mandatory Helmet Laws Make Cyclists Less Safe


https://www.bicycling.com/culture/a29802208/helmet-laws-safety/

Administrators Have Seized the Ivory Tower

https://www.jamesgmartin.center/2022/11/administrators-have-seized-the-ivory-tower/

Top 10 free MITRE ATT&CK tools and resources

https://www.helpnetsecurity.com/2022/12/05/top-10-free-mitre-attack-tools-resources/

Why API Gateways are Critical for Cloud Security

https://securityboulevard.com/2022/12/why-api-gateways-are-critical-for-cloud-security/

What Will It Take to Secure Critical Infrastructure?


https://www.darkreading.com/ics-ot/what-will-it-take-to-secure-critical-infrastructure

12 killer (and free) tools for network engineers


https://www.networkworld.com/article/3065484/interop-12-killer-and-free-tools-for-network-engineers.html#tk.rss_security

SOC 2 Controls: Encryption of Data at Rest – An Updated Guide


https://securityboulevard.com/2022/12/soc-2-controls-encryption-of-data-at-rest-an-updated-guide/

Regulation won't fix internet routing security


https://www.cyberscoop.com/fcc-routing-security-regulation/

Tech layoffs at Meta, Twitter, Amazon: The good people helping Indians find jobs


https://www.bbc.com/news/world-asia-india-63857202?at_medium=RSS&at_campaign=KARANGA

These are The Economist’s best books of 2022


https://www.economist.com/culture/2022/12/06/these-are-the-economists-best-books-of-2022

For Cyberattackers, Popular EDR Tools Can Turn into Destructive Data Wipers


https://www.darkreading.com/vulnerabilities-threats/cyberattackers-popular-edr-tools-destructive-data-wipers

Security Practitioners Lack Dark Web Threat Intelligence Training


https://securityboulevard.com/2022/12/security-practitioners-lack-dark-web-threat-intelligence-training/

Claroty researchers devised a technique for bypassing the web application firewalls (WAF) of several vendors.

https://securityaffairs.co/wordpress/139445/hacking/web-application-firewalls-waf-bypass.html

Air-gapped PCs vulnerable to data theft via power supply radiation

https://www.bleepingcomputer.com/news/security/air-gapped-pcs-vulnerable-to-data-theft-via-power-supply-radiation/


Power Grid Stuff (since it's been all over the news lately)

North Carolina Power Outages Caused by Gunfire at Substations, Officials Say

https://www.nytimes.com/2022/12/04/us/power-outages-north-carolina.html

Attacks on Pacific north-west power stations raise fears for US electric grid

https://www.theguardian.com/us-news/2022/dec/09/us-power-grid-pacific-northwest-attacks

Video - What Is A Black Start Of The Power Grid?


https://practical.engineering/blog/2022/12/5/what-is-a-black-start-of-the-power-grid

Video - 60 Minutes - Is The Electric Grid Secure

https://www.youtube.com/watch?v=GlGI643vUIg

U.S. Risks National Blackout From Small-Scale Attack - WSJ.com


https://nysrc.org/pdf/MeetingMaterial/ECMeetingMaterial/ECAgenda181/WSJ%20-%20grid%20security.pdf

Why US Power Stations Are Vulnerable Targets for Attacks


https://www.washingtonpost.com/business/energy/why-us-power-stations-are-vulnerable-targets-for-attacks/2022/12/09/cb0f8478-7811-11ed-a199-927b334b939f_story.html

U.S. battery storage capacity will increase significantly by 2025


https://www.eia.gov/todayinenergy/detail.php?id=54939

Blackout: A Novel by Mark Elsberg

https://www.amazon.com/Blackout-heart-stopping-techno-thriller-Marc-Elsberg-ebook/dp/B01MYDPTLR/ref=sr_1_3?crid=3SM6RMIKG5RMA&keywords=blackout+novel&qid=1670784512&sprefix=blackout+novel%2Caps%2C156&sr=8-3

Pretty entertaining novel about a cyberattck on the European power grids.


Lights Out: A Cyberattack, A Nation Unprepared, Surviving the Aftermath by Ted Koppel


https://www.amazon.com/Lights-Out-Cyberattack-Unprepared-Surviving-ebook/dp/B00UQERM4C/ref=tmm_kin_swatch_0?_encoding=UTF8&qid=1670785028&sr=8-1

Personally I didn't find this book super insightful and most of the engineers I know in the field considered it overblown, but it did get a lot of attention so here ya go.

The Grid: The Fraying Wires Between Americans and Our Energy Future by Gretchen Bakke


https://www.amazon.com/Grid-Fraying-Between-Americans-Energy-ebook/dp/B01DM9Q6CQ/ref=tmm_kin_swatch_0?_encoding=UTF8&qid=1670785341&sr=8-1

This one I did find pretty good.  Lots of background on why things are structured the way they are.


No comments: