Cybersecurity Risks

Explore top LinkedIn content from expert professionals.

  • View profile for Marie-Doha Besancenot

    Senior advisor for Strategic Communications, Cabinet of 🇫🇷 Foreign Minister; #IHEDN, 78e PolDef

    42,156 followers

    🇷🇺 Russia’s digital soldiers: report on Russia’s Cyber operations, analyzing how they scale through mass mobilisation of “digital soldiers”. By Anastasia Sentsova Analyst1 👉🏼Key learnings : The Russian state has built a militarised civic-information system that blurs the boundaries between state, volunteer and criminal cyber actors. It deliberately cultivates a safe haven for cybercriminals — non-prosecution and even public praise serve as implicit state incentives for aligning cyber-criminal activity with state aims. 🔹State-aligned hacktivist groups or “digital soldiers” combine narrative alignment, symbolic language and targeting patterns that mirror official Russian strategic messaging — offering a high probability of state influence even if direct control is hard to prove. 🔹The information-domain mobilisation is formalised via institutional structures (e.g., civic youth militarisation, volunteer networks) and extended into the digital sphere through gamified cyber-volunteer systems. 🪖Understanding the militarisation of civic life → digital front 🔹Legal and institutional changes (the “Foreign Agents” law, Undesirable Organisations” law) transformed civil society into a component of the militarised domestic order. 🔹The civic movement All‑Russia People’s Front (ONF) illustrates this: launched in 2011 to mobilise local groups, it has digital arms such as “CyberSquad” (in 2023) for volunteer monitoring and reporting “hostile” content. • Example: CyberSquad recruits volunteers, assigns military-style ranks via bot, tasks include complaints against “Russophobic” content, rewards via merch and premium services. 🔹Safe-harbour effect for cybercrime aligned with state goals • The case of the REvil ransomware gang: even after indictment, Russia’s non-cooperation and the embracing of “Putin Team” branding by some criminals signal an informal alignment. • Example: 2 FSB officers indicted for the massive Yahoo breach in 2017 (500 million accounts) prove state-criminal overlap. • Ex: In 2024, convicted hackers were welcomed back to Russia and publicly thanked by the President — a symbolic signal of reward. 🔹Hacktivist groups mirror state narrative and target regime’s adversaries 🔹The Cyber Army of Russia (CARR) demonstrates this alignment: launches with messaging echoing Kremlin language, uses state symbols (“Z” in St George ribbon colours), claims operations against Western/Ukraine-aligned infrastructure. • Ex: CARR claimed responsibility for compromising municipal water storage tanks in Texas (Jan 2024) — an attack crossing from cyber into physical infrastructure damage. 🔹Integrated narrative-cyber-crime apparatus complicates attribution & deterrence

  • View profile for Andy Greenberg

    Senior Writer at WIRED

    32,202 followers

    Intelligence agencies and the FBI, DOJ and CISA have revealed that unit 29155 of Russia’s GRU—a unit responsible for coup attempts, assassinations, and bombings—is now engaged in brazen hacking operations with targets across the world, including in Ukraine and the US. A broad group of Western government agencies from countries including the US, the UK, Ukraine, Australia, Canada, and five European countries on Thursday revealed that a hacker group that has launched multiple hacking operations targeting Ukraine, the US, and other countries in Europe, Asia, and Latin America is in fact part of the GRU's Unit 29155, the division of the spy agency known for its brazen acts of physical sabotage and politically motivated murder. That unit has been tied in the past, for instance, to the attempted poisoning of GRU defector Sergei Skripal with the Novichok nerve agent in the UK, which led to the death of two bystanders, as well as another assassination plot in Bulgaria, the explosion of an arms depot in the Czech Republic, and a failed coup attempt in Montenegro. Now that infamous section of the GRU appears to have developed its own active team of cyber warfare operators. Since 2022, GRU Unit 29155's more recently recruited hackers have taken the lead on cyber operations, including with the data-destroying wiper malware known as Whispergate, which hit at least two dozen Ukrainian organizations on the eve of Russia's February 2022 invasion, as well as the defacement of Ukrainian government websites and the theft and leak of information from them under a fake “hacktivist” persona known as Free Civilian. "Special forces don’t normally set up a cyber unit that mirrors their physical activities,” one official tells WIRED. “This is a heavily physical operating unit, tasked with the more gruesome acts that the GRU is involved. I find it very surprising that this unit that does very hands-on stuff is now doing cyber things from behind a keyboard.” https://lnkd.in/ehvpRzeJ

  • CISA has released its new Operational Technology (OT) Cybersecurity Guide, and it deserves board-level attention. For years, OT systems, the technology behind our power grids, water systems, manufacturing plants, and pipelines, were designed for reliability and safety, not cybersecurity. But as IT and OT environments have converged, the attack surface has expanded dramatically. We’ve already seen what this means in practice: ⚠️ Colonial Pipeline (fuel supply disruption) ⚠️ Oldsmar Water Plant (attempted poisoning) ⚠️ Ransomware groups are increasingly threatening physical operations to force payment. The CISA guide is a practical step forward, outlining what every OT-dependent organization should do: ✔️ Know your assets. Visibility is the foundation of OT security. ✔️ Segment IT and OT networks. Strong separation is essential. ✔️ Secure remote access. Enforce MFA, monitor, and log everything. ✔️ Patch with care. Use compensating controls when downtime isn’t possible. ✔️ Prepare for incidents. OT-specific monitoring, response plans, and recovery options must be in place. ✔️ Build resilience. Backups, redundancy, and even manual controls as a fallback. ✔️ Train people. Both IT and OT teams need a shared understanding of cyber risk. This isn’t just a technology problem. It’s a resilience problem. For executives, OT risk belongs on the same agenda as financial, legal, and regulatory risk. The impact of failure isn’t just data loss; it’s downtime, safety hazards, and national security implications. CISA’s guide is a reminder that OT security is no longer optional. It is a core part of modern business continuity. Please feel free to contact me if you need help or want more information on this. 🔔 Follow me for more real-world takes on cybersecurity, leadership, and tech strategy ♻️ Useful? Share to help others! #CyberSecurity #OperationalTechnology #RiskManagement #CriticalInfrastructure #CISA #BusinessContinuity

  • View profile for Keith King

    Former White House Lead Communications Engineer, U.S. Dept of State, and Joint Chiefs of Staff in the Pentagon. Veteran U.S. Navy, Top Secret/SCI Security Clearance. Over 19,000+ direct connections & 53,000+ followers.

    53,486 followers

    Headline: China Cracks RSA Encryption Using Quantum Annealing—Global Data Security Now Under Pressure ⸻ Introduction: A Chinese research team has achieved a milestone with profound cybersecurity implications: successfully cracking a small RSA-encrypted integer using a quantum computer. Though modest in scale, this experiment signals that quantum systems are starting to undermine the very cryptographic foundations that secure today’s banking, commerce, and communication systems. The race to build quantum-resistant encryption is no longer theoretical—it’s urgent. ⸻ Key Details 🔓 Cracking RSA with Quantum Annealing • Researchers: Wang Chao and team from Shanghai University. • Hardware Used: A D-Wave Advantage quantum annealer, built by D-Wave Systems. • Achievement: The team factored a 22-bit RSA semiprime integer, a task previously unsolved on this class of hardware. 🔐 What Makes RSA Strong—and Vulnerable • RSA Encryption: Based on the difficulty of factoring large semiprime numbers (products of two primes). • Classical Challenge: Conventional computers require subexponential time to factor 2048-bit keys—considered secure for now. • Largest Cracked Classically: RSA250 (829-bit key) using supercomputers over weeks. • Quantum Approach: The Chinese team translated factorization into a QUBO (Quadratic Unconstrained Binary Optimization) problem, solvable by quantum annealing. 🧠 Why This is a Warning Shot • Early Stage, But Symbolic: While a 22-bit number is trivial by today’s standards, the methodology proves scalability potential. • First Step Toward Quantum Decryption: Demonstrates quantum annealers can be adapted for cryptographic tasks—not just optimization. • Signals Future Risk: Today’s encryption might withstand current tech, but scalable quantum systems could break RSA entirely in years, not decades. ⸻ Why It Matters • Global Cybersecurity Threatened: Banking, defense, healthcare, and internet infrastructure all rely on RSA and similar public-key systems. This experiment shows those systems may soon be obsolete. • Quantum Arms Race Accelerates: The demonstration by Chinese researchers will likely intensify global investment in both quantum computing and post-quantum cryptography. • Urgent Need for Migration: Governments and corporations must begin transitioning to quantum-resistant encryption standards, or risk catastrophic breaches in the near future. • Tactical and Strategic Implications: Countries that master quantum decryption first may gain unparalleled capabilities in espionage, warfare, and economic control. ⸻ Keith King https://lnkd.in/gHPvUttw Arzan Alghanmi

  • View profile for Steve Suarez®

    Chief Executive Officer | Entrepreneur | Board Member | Senior Advisor McKinsey | Harvard & MIT Alumnus | Ex-HSBC | Ex-Bain

    53,628 followers

    The biggest threat to your data isn’t happening tomorrow. It happened yesterday. If you haven’t heard of HNDL (Harvest Now, Decrypt Later), your long-term data strategy has a massive blind spot. Here is the reality: State actors and cybercriminals are capturing your encrypted data today. They can’t read it yet, so they’re storing it in massive data vaults, waiting for the "Qday"—the moment quantum computers become powerful enough to break current encryption. If your data needs to stay private for 5, 10, or 20 years, it’s already at risk. What’s on the line? ↳ Intellectual Property (IP) and trade secrets. ↳ Government and identity data. ↳ Long-term financial records and contracts. ↳ Sensitive customer health data. How do we solve it? 🛠️ We cannot wait for quantum supremacy to react. The fix starts now: ↳ Inventory: Identify which data has a long shelf-life. ↳ Crypto-Agility: Move toward systems that can swap encryption methods without a total overhaul. ↳ Hybrid PQC: Implement Post-Quantum Cryptography alongside classical methods to ensure traffic captured today remains a mystery tomorrow. The transition to quantum-resistant security is a marathon, not a sprint. Are you tracking HNDL on your current risk register? Let’s discuss in the comments. 👇 P.S. If you want help mapping your exposure or building a PQC migration plan, drop me a message. ♻️ Share this post if it speaks to you, and follow me for more. #QuantumSecurity #PQC

  • View profile for Shiv Kataria

    Securing Critical Infrastructure & Global Manufacturing | OT/ICS Security Strategy & Governance | IEC 62443 · CISSP · GIAC GRID | AI for Cyber Defense

    25,382 followers

    𝗢𝗧 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗯𝘂𝗱𝗴𝗲𝘁𝘀 𝗻𝗲𝗲𝗱 𝗮 𝗿𝗲𝘀𝗲𝘁. Too often, OT cybersecurity is still positioned as a compliance expense. But in industrial environments, that is too narrow. The better way to look at it is: 𝗢𝗧 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 = 𝘂𝗽𝘁𝗶𝗺𝗲 𝗽𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻 + 𝗼𝘂𝘁𝗮𝗴𝗲 𝗮𝘃𝗼𝗶𝗱𝗮𝗻𝗰𝗲 + 𝗳𝗮𝘀𝘁𝗲𝗿 𝗿𝗲𝗰𝗼𝘃𝗲𝗿𝘆. One important message from recent OT security investment discussions is clear: 𝗧𝗵𝗲 𝗵𝗶𝗴𝗵𝗲𝘀𝘁-𝗶𝗺𝗽𝗮𝗰𝘁 𝗰𝗼𝗻𝘁𝗿𝗼𝗹𝘀 𝗮𝗿𝗲 𝗻𝗼𝘁 𝗮𝗹𝘄𝗮𝘆𝘀 𝘁𝗵𝗲 𝗺𝗼𝘀𝘁 𝗲𝘅𝗽𝗲𝗻𝘀𝗶𝘃𝗲 𝗼𝗻𝗲𝘀. The practical moves still matter the most: • 𝗞𝗻𝗼𝘄 𝘄𝗵𝗮𝘁 𝘆𝗼𝘂 𝗵𝗮𝘃𝗲 Asset inventory and visibility remain the foundation. You cannot protect what you cannot see. • 𝗗𝗲𝘀𝗶𝗴𝗻 𝗳𝗼𝗿 𝗰𝗼𝗻𝘁𝗮𝗶𝗻𝗺𝗲𝗻𝘁 Segmentation, defensible architecture, and secure remote access reduce the blast radius when something goes wrong. • 𝗣𝗿𝗲𝗽𝗮𝗿𝗲 𝗳𝗼𝗿 𝘁𝗵𝗲 𝗯𝗮𝗱 𝗱𝗮𝘆 An OT-specific incident response plan, tested backups, and recovery playbooks can save weeks of downtime. • 𝗠𝗮𝗻𝗮𝗴𝗲 𝗿𝗶𝘀𝗸, 𝗻𝗼𝘁 𝗷𝘂𝘀𝘁 𝗽𝗮𝘁𝗰𝗵𝗲𝘀 OT vulnerability management cannot simply copy the IT model. It has to consider safety, availability, process impact, and compensating controls. • 𝗖𝗼𝗻𝘃𝗲𝗿𝗴𝗲 𝘄𝗶𝘁𝗵𝗼𝘂𝘁 𝗰𝗼𝗻𝗳𝘂𝘀𝗶𝗼𝗻 Unified IT/OT visibility and monitoring are becoming essential, but ownership, response roles, and operational boundaries must be clear. 𝗠𝘆 𝘁𝗮𝗸𝗲: A practical OT security roadmap should start with controls that directly improve resilience, recovery, and operational continuity. Not every program has to begin with a large platform purchase. Sometimes the highest-value investments are: 𝗩𝗶𝘀𝗶𝗯𝗶𝗹𝗶𝘁𝘆. 𝗦𝗲𝗴𝗺𝗲𝗻𝘁𝗮𝘁𝗶𝗼𝗻. 𝗦𝗲𝗰𝘂𝗿𝗲 𝗿𝗲𝗺𝗼𝘁𝗲 𝗮𝗰𝗰𝗲𝘀𝘀. 𝗢𝗳𝗳𝗹𝗶𝗻𝗲 𝗯𝗮𝗰𝗸𝘂𝗽𝘀. 𝗥𝗲𝘀𝗽𝗼𝗻𝘀𝗲 𝗿𝗲𝗮𝗱𝗶𝗻𝗲𝘀𝘀. Because in OT, the best cybersecurity investment is not only the one that passes an audit. It is the one that prevents downtime before it becomes a crisis. #OTSecurity #IndustrialCybersecurity #ICS #IEC62443 #CyberResilience #OperationalTechnology #RiskManagement

  • View profile for Rafael Narezzi

    CEO & Co-Founder at Centrii | Securing the Energy Transition | OT Cybersecurity for Critical Infrastructure | MSc Cyber

    33,829 followers

    AWS Threat Intelligence has confirmed Russian state-sponsored cyber groups actively targeting Western critical infrastructure, with a strong focus on energy systems. Key facts executives: • 420+ million attacks against critical infrastructure in one year • 30% year-on-year growth in attacks on energy, water, transport • 70% of recent nation-state cyber activity targets critical sectors • Russia-linked cyber operations against NATO countries up ~25% YoY And here’s the uncomfortable truth: These are only the reported incidents. Industry consensus suggests the real number could be 2–3x higher due to under-reporting, lack of visibility, and OT blind spots. Energy, renewables, grids, batteries, and infrastructure are now strategic cyber targets, not hypothetical risks. Cybersecurity today is about: • Operational continuity • Financial risk and valuation • Regulatory exposure (NIS2, NERC-CIP, DORA) • Director accountability If cyber resilience is not embedded into your operational strategy, you are already exposed. AWS Threat Intelligence report: https://lnkd.in/epkMMMe8 #CyberSecurity #CriticalInfrastructure #EnergySecurity #OTSecurity #NIS2 #BoardRisk #CyberEnergia

  • View profile for Sudiptaa Paul Choudhury CMO, Independent Director, Board Advisor

    Global, Strategic, Impactful Marketing & Brand Leader | TEDx & Keynote Speaker | IIM-C | Ex-Intuit, Ericsson, Oracle, HP, EMC | AI, Digital Marketing Leader | GTM, ABM, Content Strategy, Writing,CRM, Marketing Automation

    8,229 followers

    Your encryption isn't being hacked. It's quietly expiring. Misconfigured. And being harvested — right now. 60% of organisations faced exploits tied to compromised PKI in 2025. 56% experienced disruptions from certificate failures. 114,000+ certificates. 4 full-time staff. This is today's baseline failure rate. PKI was built for closed networks and human-scale identities. That world ended. Cloud, IoT, agentic AI, and quantum are dismantling its foundations faster than most security teams realise. 7 structural failures your PKI audit isn't catching: Certificate sprawl — 81% of companies suffered outages. One failure at scale costs $5M+. The 47-day TLS mandate — By 2029, you'll renew ~2,100 certificates every single day. No manual team survives this. Fragile CA trust — One compromised root CA invalidates millions of certificates. Simultaneously. Zero visibility — 75% of organisations can't fully inventory their own certificates. Agentic AI — AI agents create ephemeral identities at millisecond velocity. PKI was never designed for this. Forrester predicts a major breach from agentic AI credential failure before end of 2026. Frozen IoT/OT hardware — RSA hardcoded into 20-year-lifecycle firmware. PKI cannot revoke it without physical replacement. No sovereign PKI — Indian banks, telecoms, and defence still depend on Western CA hierarchies. One geopolitical disruption = cascading failure. And then there's the threat PKI was never designed to survive. HNDL — Harvest Now, Decrypt Later — is already operational. Adversaries are intercepting your TLS traffic today and waiting for quantum capability to decrypt it. Data encrypted in 2026 could be readable by 2034. The Federal Reserve confirmed this as a present-day risk in 2025. NIST finalised post-quantum standards in August 2024. RSA and ECDSA will be deprecated by 2035. Yet only 5% of tech professionals have made quantum migration a near-term priority. Here's what most people miss: Switching to PQC algorithms is not enough. You've changed the locks. You haven't changed the key management vault behind them. The missing layer is a Quantum-Safe KMS — governing key lifecycle, seeding entropy via QRNG, sovereign on-premise deployment. PKI tells you who holds the key. QKMS governs the key's entire existence. The question every CISO should ask isn't "Are we quantum-safe?" It's: "Can we prove it to an auditor?" Full breakdown — all 7 failures, HNDL, the 47-day mandate, and what complete cryptographic control looks like https://lnkd.in/gDzM_Tjs Proactively Quantum™ #QuantumSecurity #PKI #QKMS #PostQuantum #KyntraQ #Cybersecurity #CISO #HNDL #QNuLabs #DigitalSovereignty

  • View profile for Jane Frankland MBE
    Jane Frankland MBE Jane Frankland MBE is an Influencer

    Author & voice on cybersecurity for survivability | Global brand ambassador & UK strategic adviser to cyber & tech firms | Built one of the world’s first ethical hacking firms | MBE for services to women in cyber

    55,648 followers

    The National Cyber Security Centre has just published an urgent warning. And if you lead an organisation — or sit on a board — this one is for you. Russian military intelligence has been quietly breaking into routers that connect offices and home workers to the Internet. Not to cause obvious disruption. Not to demand a ransom. To watch. To intercept. And to steal login credentials without anyone noticing. What makes this particularly significant is that it isn't targeted in the way you might expect. They cast a wide net — compromising as many devices as possible — and then quietly sift through to find targets of intelligence value. The question for your organisation isn't whether Russian intelligence was specifically coming for you. It's whether you were swept up in the net, and whether they decided you were worth acting on. The devices being exploited are not obscure. They are common, inexpensive routers. The kind that get set up once and rarely revisited. The kind that many remote workers have at home. This is not a failure of sophisticated technology. It is a failure of maintenance. Devices that haven't been updated. Settings that haven't been reviewed. Infrastructure that fell outside anyone's responsibility. So what does leadership need to do? Ask your IT team or security partner three questions this week. ✅ Do we have any of the router models on the NCSC advisory list — including in our remote workers' homes? ✅ When were those devices last updated, and who is responsible for maintaining them? ✅ Do we have multi-factor authentication — a second verification step beyond a password — on our email and collaboration tools? If the answer to the third question is no, or not fully, that is the most urgent fix. Even if credentials are stolen, multi-factor authentication significantly limits what an attacker can do with them. This is not a theoretical risk. The NCSC does not publish operational advisories like this without evidence of active, ongoing activity. Russian state-sponsored actors are patient, well-resourced, and operating in the grey zone between espionage and disruption. The devices are common. The vulnerability is known. The fix is available. The only question is whether your organisation acts before or after an incident. Link to the NCSC's guidance in the comments. ===== #Cybersecurity #cyberresilience #riskmanagement #cybernews

  • View profile for Austin Larsen

    Principal Threat Analyst @ Google Threat Intelligence Group

    15,780 followers

    ⚠️ Our team at Google Threat Intelligence Group (GTIG) just published new research on an ongoing, highly targeted data theft campaign by #UNC3753 targeting US law firms, professional, and financial services organizations. Also tracked as Luna Moth or Silent Ransom Group, this financially motivated threat actor bypasses traditional defenses through targeted voice phishing. The actors call employees directly, masquerading as corporate IT helpdesk staff to trick them into joining screen-sharing sessions and downloading legitimate remote management tools. This follows a FLASH alert issued by the FBI just last week regarding the group's aggressive tactics. Beyond digital vectors, the campaign involves suspected in-person social engineering, where individuals pose as IT technicians to gain physical office entry and exfiltrate data directly via USB storage. Once inside an environment, the group conducts rapid file sweeps of document management repositories like iManage to steal sensitive legal agreements, financial records, and PII before issuing a three-day extortion deadline. To safeguard your organization against these vishing and physical vectors, we recommend prioritizing these defense controls: 🛡️ Audit RMM utilities to strictly block unauthorized remote support or screen-sharing applications. 🔑 Mandate secure, out-of-band identity verification for both remote IT support and physical onsite visitors. 🚫 Stop physical exfiltration vectors by disabling read and write capabilities for external USB mass storage devices where possible. 🔎 Monitor critical document management repositories and filesystems for rapid file sweeps or abnormal search spikes. I’ll drop the links to our full technical report and the FBI FLASH advisory in the comments below.

Explore categories