Applications, Networks, and Legacy Systems in Quantum Crosshair: A CISO’s Perspective

Applications, Networks, and Legacy Systems in Quantum Crosshair: A CISO's Perspective

It is only a matter of time before quantum computing can break today’s standard encryption (the so-called “Q-Day”). The timeline is uncertain, but the impact will be immediate, especially due to the risk of “store now, decrypt later”: adversaries can collect encrypted data today and decrypt it when quantum technology becomes feasible. Many organizations must … Read more

How Weak WiFi Security Threatens Your IoT Devices

How Weak WiFi Security Threatens Your IoT Devices

With the increasing number of attacks targeting WiFi, does this pose a threat to Internet of Things (IoT) devices? In short, the answer is yes. To elaborate, the answer is also affirmative: wireless networks are under attack — which means that all devices relying on wireless networks are also at risk of vulnerabilities. Intruders have … Read more

National Cybersecurity Awareness Week: Cybersecurity Situation and Response Strategies for Industrial Control Systems

National Cybersecurity Awareness Week: Cybersecurity Situation and Response Strategies for Industrial Control Systems

Cybersecurity is for the people, and cybersecurity relies on the people —— Protecting high-quality development with high-level security In recent years, with the rapid development of open automation technology, communication technology, and security technology, the traditional control field is undergoing an unprecedented transformation. Industrial control systems are transitioning from closed to open, IT and OT … Read more

Security Observations on Educational Networks: Universities Must Beware of Vulnerabilities in the HTTP/2 Protocol

Security Observations on Educational Networks: Universities Must Beware of Vulnerabilities in the HTTP/2 Protocol

AI technology is changing the patterns of cyber attacks. Cybersecurity company ESET has announced the detection of the world’s first AI-driven ransomware “PromptLock,” which utilizes the Ollama API to locally invoke OpenAI’s gpt-oss:20b model, generating and executing malicious Lua scripts in real-time to bypass traditional antivirus signature detection methods. Another security company, Kaspersky, has also … Read more

Suspected APT-C-00 (Hailianhua) Delivers Havoc Trojan

Suspected APT-C-00 (Hailianhua) Delivers Havoc Trojan

APT-C-00 Hailianhua APT-C-00 (Hailianhua) organization is a government-backed overseas hacker group, primarily targeting enterprises and government departments in East Asian countries. The 360 Advanced Threat Research Institute has been continuously monitoring the latest attacks from the Hailianhua organization. 1. Overview Recently, the 360 Advanced Threat Research Institute captured a suspicious Trojan loader during routine threat … Read more

Millions of Wi-Fi Devices Still Vulnerable to the Pixie Dust Attack Discovered Over a Decade Ago

Millions of Wi-Fi Devices Still Vulnerable to the Pixie Dust Attack Discovered Over a Decade Ago

NetRise, a company focused on protecting firmware and software components of IoT devices, has reported that many network devices remain susceptible to the Pixie Dust attack method discovered over a decade ago via Wi-Fi. This was reported by SecurityWeek. Image Source: SecurityWeek The attack, known as Pixie Dust, was discovered in 2014, when it was … Read more

Unveiling the Power Behind the SOC 201 Course Release: From Threat Hunting to Cognitive Leap

Unveiling the Power Behind the SOC 201 Course Release: From Threat Hunting to Cognitive Leap

Unveiling the Power Behind the SOC 201 Course Release: From Threat Hunting to Cognitive Leap In the field of cybersecurity, the SOC (Security Operations Center) course has always been a key to enhancing practical skills. The release of the SOC 201 course not only detailed the course content but also demonstrated the entire process of … Read more

Government Precision Support for Enterprise Security Upgrades

Government Precision Support for Enterprise Security Upgrades

On September 15, Mao Zhengjian, Director of the Informationization and Software Service Industry Department of the Provincial Department of Industry and Information Technology, along with three experts from the National Industrial Information Security Development Research Center, visited Dufuduo New Energy Technology Co., Ltd. to jointly launch a special action for the cybersecurity assessment of industrial … Read more