Most Notable Cybersecurity Leak of 2024 So Far - The I-Soon Leak Reveals a Trove of Information About Chinese State-Supported Hacking Operations

I-Soon (上海安洵) is a Shanghai based Chinese info-sec company that contracts for many Chinese government agencies like the Ministry of Public Security, Ministry of State Security, and People’s Liberation Army. A trove of documents and chat messages between employees was leaked on GitHub on 16 February showing inner workings of the company, targeted organizations and fees earned from hacking them (Apparently collecting data from the Vietnam Ministry of Economy was worth $55 000 and access to a Vietnamese traffic police private website was worth $15 000), technical documents showing custom snooping devices, people complaining about low wages, and a discussion about receiving zero-day vulnerabilities from the Chinese government. Continue reading
The YouTube player can not be loaded with disabled JavaScript.
The following video is embedded here:
https://youtube.com/watch?v=FmvEiy7thFo

Cybersecurity, ChatGPT, and Learning Chinese - An Interview

I spent March in 2023 in Taipei learning Mandarin Chinese and while there I was interviewed for the LTL school podcast. See the the video for a discussion I had with Rushi from LTL Language School about everyday cybersecurity, ChatGPT, and my experiences learning Mandarin Chinese!

Before the interview I thought a lot about what I wanted to say about language learning and I wasn’t expecting questions about cybersecurity, so in addition to botnets preying on our WiFi routers and the big tech companies collecting and selling our personal information, I didn’t realize to bring up probably the scariest reason for worrying about our personal information and taking good care of our cyber hygiene: identity theft.

Continue reading
The YouTube player can not be loaded with disabled JavaScript.
The following video is embedded here:
https://youtube.com/watch?v=HA0pVLBU2IE

The Maritime Industry's Response to Growing Threats Presentation

I was invited to give a presentation in TurkuSec on the new IMO and IACS requirements on cybersecurity for new ship builds. In this video I explain the significance of the IMO/IACS requirements, how Classification Societies create cybersecurity rules for the industry. Also see my other article on the subject and the TurkuSec website for more events.

Charting a Course to Cybersecurity: The Maritime Industry's Response to Growing Threats

Over the last year I have participated in quite many discussions about cyber security in maritime industry. There is a trend of growing number of cyber attacks in the industry, which have caused lots of disruptions and financial losses for companies and organizations. The shipping industry is also particularly vulnerable to these threats due to the long service lives of onboard systems, growing use of cloud-based solutions by equipment manufacturers and shipowners both in new constructions and also as additions to in-service vessels to enable remote maintenance and collection of data. Continue reading