GAO Reports – Week of 1-6-24 – Cost of Positive Train Control – Report requested by Congress on the operation and maintenance costs for PTC systems used by passenger rail companies - http://tinyurl.com/ye3hak3y #PTC #gaoReports
Chemical Incident Reporting – Week of 1-6-24 – 2 incidents – 1 possible CSB reportable – http://tinyurl.com/5ua98mwh #CSB #ChemicalIncident
Review - Public ICS Disclosures – Week of 1-6-24 – Part 1 – A relatively slow week - 12 vendor disclosures – 3 vendor updates – 3 researcher reports – 2 exploits – Schneider and Siemens in Part 2 – Short version – http://tinyurl.com/yc3h57tj #icsSecurity
Public ICS Disclosures – Week of 1-6-24 – Part 1 – A relatively slow week - 12 vendor disclosures – 3 vendor updates – 3 researcher reports – 2 exploits – Schneider and Siemens in Part 2 - http://tinyurl.com/yxae49xn Subscription required #icsSecurity
@wendynather Tonight's #shmoocon firetalk on the Cookie Dough model of security, in which @TindrasGrove made a great analogy to infosec from Nestle's "don't eat raw cookie dough" vs Pillsbury's "we made the cookie dough safe because we know you're going to eat it even if we tell you not to" reminded me in - the best possible way - of your incredible talk on Democratizing Security...
The Internet is for clicking - cookie dough is for eating - meet the users where they are!! 💞
CFSN Detailed Analysis - Substack Daily Update – 1-12-24 – Free Content – http://tinyurl.com/5etmu7rd
Short Takes – 1-12-24 – Rail Safety Act delay – Self-eating rocket – 3rd Starship launch – Peregrine components communicating - http://tinyurl.com/3fxnhfuu
Review - FAA Published Final Airworthiness Criteria for Hummingbird UA – Includes an interesting discussion about cybersecurity issues raised by the Air Line Pilots Association – Short version – http://tinyurl.com/jrnayv7n #Regulation #FAA #DroneCybersecurity
FAA Published Final Airworthiness Criteria for Hummingbird UA – Includes an interesting discussion about cybersecurity issues raised by the Air Line Pilots Association – http://tinyurl.com/2k8w7mfr Subscription required - #FAA #Regulation #Drone
Reader Comment - Chemical Investigations in 2024 – Backlog is cleared and the way forward to new investigations is open – http://tinyurl.com/2s3jrdk9 #CSB
CFSN Detailed Analysis - Substack Daily Update – 1-11-24 – Free Content – http://tinyurl.com/mrye2ntj
Short Takes – 1-11-24 – Bitcoin service – 5 Alzheimer’s variants – Wrench vulnerabilities – Spending woes redux – PFAS TSCA final rule – Axiom-3 and China resupply missions – Antibiotic politics - http://tinyurl.com/3p35wj7a
Review - 9 Advisories Published – 1-11-24 – NCCIC-ICS control system security advisories for Siemens (6), Schneider, Horner Automation, and Rapid Software – Short version – http://tinyurl.com/3yj24735 #icsSecurity
9 Advisories Published – 1-11-24 – NCCIC-ICS control system security advisories for Siemens (6), Schneider, Horner Automation, and Rapid Software – Includes a look at ‘missing advisories’ in 2023 - http://tinyurl.com/3ts6pn8p Subscription required #icsSecurity
To prove the point that users will continue to click links, regardless of how obvious it is that they shouldn't, I worked with the person in charge of the monthly phishing trainings at $dayjob last month. Historically, they have used the hated ruses like fake gift cards, and I wanted to try to get away from that, especially during the holidays. We ended up using something to the effect of the following:
---
Hello <first name>,
Happy Holidays. This is the monthly phishing test. Yes, really. It's not a trick. Use the <phishing reporting function> to report this as phishing. If you do not know how to use <phishing reporting function>, feel free to ask a colleague. If you still have questions, search for <phishing reporting function> on <internal docs site>.
Do not click the following link as it is there for metrics and will cause you to be assigned phishing awareness training: <phishing training 'malicious' link>
Sincerely,
IT Security Team
---
I don't know how well it was received by users, but I do know that we still had more clicks than two other months in 2023, despite being explicitly told not to click the link. Users will always click links with their link-clicking machines. Relying on their discretion is either ignorant, or I expect in some cases, malicious in that there will always be a scapegoat to blame for the inevitable breach.
OMG!!! XKCD's What If? is now a YouTube channel..... https://www.youtube.com/@xkcd_whatif
CFSN Detailed Analysis - Substack Daily Update – 1-10-24 – Free Content – http://tinyurl.com/yeybf89n
Short Takes – 1-10-24 – US climate pollution falls – Spending bills – Axiom Mission 3 to ISS –http://tinyurl.com/yc62rhr7