Search
10.07.2021 | 7'' read
An incomplete nation-state APT landscape
An honest and open discussion about nation-state capabilities and operations must include all the actors, including the United States, Israel, France, South Korea and the growing list of European nations managing cyber-espionage campaigns.
Read10.01.2021 | 4'' read
Information brokerage and cyber storytelling
High-end APT research is big business. This means that the traditional malware researcher is now an "intelligence broker" operating in an oft-misunderstood space with geopolitical weight and consequences. Do we truly understand the implications?
Read03.29.2021 | 6'' read
On disrupting .gov malware attacks
A major scoop by MIT Technology Review confirms what I've suspected all along -- Google's public flex came long after intense conversations about disruting and outing a "friendly" FEYE counter-terrorism campaign. Plus, a new podcast with Nico Waisman and a surge in firmware attacks.
Read03.23.2021 | 5'' read
Dark holes and apex threat actors
Google published a remarkable report on a true apex APT actor that burned through 11 zero-days in less than a year, but the absence of basic information to help defenders leads to a dark hole of balkanized research output. Plus, Kim Zetter's new journalism project.
Read03.08.2021 | 5'' read
The sudden explosion of zero-day attacks
So far this year, we've seen 14 distinct in-the-wild 0day attacks hitting a range of different platforms, products and operating systems. What does it all mean and how can we find some signs of good news amidst the carnage? Plus, a throwback podcast with a zero-day exploit merchant and lots of important people movements.
Read02.17.2021 | 2'' read
Leaving Intel to bet on journalism about defense
It's exciting to be reporting again, interviewing CISOs and hackers alike, filtering through the fluff to write the stories I've always wanted to read. Here are some quick notes on why I'm bullish on micro-journalism, podcasting and live streaming to cover the business of cybersecurity.
Read