Archive

All entries

Rapid7 Principal Security Research (IoT) lead Deral Heiland joins the Nexus Podcast to discuss work his team did on how attackers might weaponize cellular-based IoT.  Rapid7 conducted three phases of this research, with the most recent digging into how attackers with access to these systems can abuse them to gain unauthorized access, potentially exfiltrate critical data, or pivot into backend network infrastructure.
Internet of Things
Vulnerability Management
Risk Management
Operational Resilience

Nexus Podcast: Deral Heiland on Weaponizing Cellular-Based IoT

Michael Mimoso
Tiffany Wilson, the founder of Wilson Inclusive Solutions (WINS), a disability accessibility consulting firm, joins the Nexus Podcast to discuss the proliferation of consumer technology into healthcare infrastructure. This technology—smart speakers that help manage medications or cameras that monitor vulnerable individuals—often handles patient data and safety, and operates in a regulatory void.
Healthcare
Risk Management
Internet of Things

Nexus Podcast: Tiffany Wilson on the Security Crisis of Consumer Tech in Healthcare

Michael Mimoso
nexuspod_joe-slowik.jpeg
Operational Resilience
Operational Technology
Internet of Things
Industrial
Healthcare
Cyber Resilience
Risk Management

Nexus Podcast: Joe Slowik on Securing Exposed Internet-Facing Assets

Michael Mimoso
Team82 vulnerability research lead Noam Moshe discusses his team’s expansive look into IP-based surveillance cameras manufactured by Sweden’s Axis Communications, a leading company in this space. Companies like Axis are selling more and more into Western enterprises given bans on certain Chinese technologies. Moshe’s research uncovered a number of vulnerabilities in the management framework used to oversee these devices, as well as the communication protocol in play. Attackers can exploit these issues to gain control of cameras, move onto the corporate network, and disrupt the safety of a business.
Nexus Conference
Internet of Things
Vulnerability Management

Noam Moshe on Hacking Enterprise-Grade IP Cameras

Team82 vulnerability research lead Noam Moshe discusses his team’s expansive look into IP-based surveillance cameras manufactured by Sweden’s Axis…
Michael Mimoso
Jay C. Catherine, a security architect for a major retailer, joins the Nexus Podcast to discuss best practices for logistics cybersecurity within the retail space. This includes securing not only distribution, but also the operational technology involved in these manufacturing processes.
Industrial
Internet of Things
Cyber Resilience
Operational Resilience
Operational Technology

Nexus Podcast: Jay Catherine on Securing Logistics, OT in Retail

Michael Mimoso
Congress' failure to reauthorize the Cybersecurity Information Sharing Act of 2015 (CISA 2015) signals a fundamental shift in threat intelligence sharing and overall risk management strategies.
Vulnerability Management
Risk Management
Cyber Resilience
Industrial
Healthcare
Internet of Things

CISO Survival Guide: 4 Steps to Prepare for CISA 2015 Expiration

George V. Hulme
China-nexus threat actors are targeting edge devices that do not support EDR. Adm. Michael Rogers writes that cyber-physical systems could be next since many of the connected OT, IoT, and IoMT devices and sensors also lack EDR protection.
Operational Resilience
Internet of Things
Cyber Resilience
Healthcare
Industrial
Risk Management

Adversaries' Adaptability is Bad News for Cyber-Physical Systems

ADM. Michael S. Rogers, USN (Ret.)
Amazon's intent to replace humans with robots represents a wave of cyber-physical systems (CPS) security that will need to be implemented not only in the logistics and warehousing industries but also for work-in-process (WIP) inventory in manufacturing and other critical industries.
Cyber Resilience
Industrial
Internet of Things
Operational Resilience
Operational Technology
Vulnerability Management
Risk Management

Automation Inroads Bring Urgency to CPS Protection

Jim LaBonty
nexus_frenz.jpg
Healthcare
Vulnerability Management
Risk Management
Internet of Things
Cyber Resilience

Nexus Podcast: Christopher Frenz on Evidence-Based Security

Michael Mimoso
Providence CISO Mike Ratliff shares the results and initial impact of an AI up-skilling program implemented at the Washington-based hospital system for its cybersecurity team. The benefits are already being see in terms of operational efficiency and cross-functional collaboration.
Healthcare
Operational Resilience
Internet of Things
Risk Management

Providence Cybersecurity AI Up-Skilling Program: Building Smarter Defenses for a Digital Future

Mike Ratliff
Charles Carmakal, CTO of Mandiant, speaking during a professional video interview with a dark, blurred background.
Cyber Resilience
Internet of Things
Operational Technology
Operational Resilience
Risk Management
Ransomware
Nexus Conference

Charles Carmakal on China's Cyber Threat to Critical Infrastructure

Charles Carmakal, Chief Technology Officer at Mandiant (Part of Google Cloud), explains how China-nexus threat actors such as Volt Typhoon, Salt Typhoon, and…
Michael Mimoso
The congressional delay in hammering out a federal budget has added another layer of pain to the ongoing crisis for the Cybersecurity and Infrastructure Security Agency (CISA). Not only are there funding concerns., but it's the expiration of critical information-sharing legislation and a regulatory compliance vacuum that has left enterprises unsure about their next steps.
Cyber Resilience
Operational Resilience
Risk Management
Internet of Things

Threat Intelligence Goes Dark, CISA Crisis Leaves Enterprise Security Blind

George V. Hulme
Latest on Nexus Podcast