We are at the last open ticket block for #S4x24, 751-1000. Tickets 1001 - 1100 will be limited to asset owners.
S4x24 is March 4 - 7 in Miami South Beach.
s4xevents.com/ticket-block-7…
The September 13 meeting summary for @CISAgov’s cybersecurity advisory committee includes a blurb about the recommendations from the technical advisory council re: the agency’s work to protect high-risk communities. cisa.gov/sites/default/files…
S4x24 tickets on sale now at universe.com/events/s4x24-ti…
1st 100 tickets sold in the first two hours, but we keep the ticket #1 - #100 price until noon EDT on Tuesday, Oct 3 to be fair to all time zones.
Ticket also gets you coveted hotel block info.
It’s clear that the MITRE Engenuity ATT&CK is a dead testing criteria / evaluation and more about gaming the scores.
MITRE ATT&CK however is still an amazing framework for evaluating coverage and effectiveness. Lots of great things there still even if Engenuity is a hot mess.
most of my career has been weathering this reaction tbh.
I’ve long agreed with @argvee’s answer that the cybersecurity industry shouldn’t exist, because it needs to be solved in design/arch.
I also think the industry will resist Secure by Design/Default for this very reason…
"Thus far, we haven't seen a single incident response where AI played a role” says @JumpforJoyce. A good reminder not to get too caught up in the hype. reuters.com/technology/ai-us…
Mandiant’s COSMICENERGY report shows that the IEC-104 module ”LIGHTWORK” sets the output to OFF at the following hardcoded addresses (IOAs):
❌ 34
❌ 84
❌ 134
❌ 184
❌ 234
❌ 284
❌ 334
❌ 384
These IOAs might be power line switches, circuit breakers or something else.
Snuck in a hiking mini-break before ICSJWG in SLC, I got into Kodachrome Basin State Park (underrated & few people), Bryce Canyon NP (amazing, but crowded until remote trails), & will try Willis Creek Slot Canyon today before driving up to SLC.
See many of you tomorrow.
The program for the 9th LangSec IEEE Security & Privacy Workshop on May 25, 2023 is now posted: langsec.org/spw23/workshop-p… Join us for two great keynotes, research paper presentations, industry research reports, and work-in-progress discussions.
Seth blog & S4 seths.blog/2021/10/crowding-…
"Very few things scale forever.
The hardest moment to stop scaling our work is the moment when it’s working the best.
And that’s precisely the moment when we need to have the guts to stop making it bigger."
1000 is next S4 decision point
Funny you pulled this 2021 tweet. We it this decision point at S4x23 last February. We decided to stay at the 1000 ticket limit for S4x24, although this was driven by the venue limitations more than anything else.
Now we start to think about what is the ideal mix for the 1K.
We are absolutely stoked to finally share videos from CYBERWARCON ‘22! We took heavy losses to the lawyers, so almost half of the talks won’t be available online. The only way to see everything is to attend! 1/2 youtube.com/@cyberwarcon
It's CRITICALLY important for us to step into NEW ENVIRONMENTS and meet new people, because great ideas won't just interrupt us. 🛑
They MUST be PURSUED. 💫🏃