The Ship Is a Floating OT Network: Maritime Cyber Rules Got Teeth in 2024

Since January 2024, ships manage cyber risk under IMO-derived requirements enforced by flag and port-state control, IACS E26 and E27 give class societies assessment criteria, and the US Coast Guard can detain deficient vessels. Bridge, cargo, propulsion, SATCOM and crew IT share one hull: treat the vessel as an OT estate.

Continue ReadingThe Ship Is a Floating OT Network: Maritime Cyber Rules Got Teeth in 2024
Read more about the article NIS2 Is Not Just for Banks: The Compliance Clock
NIS2 shield checklist inside 12 star circle

NIS2 Is Not Just for Banks: The Compliance Clock

Food plants, logistics firms, waste management, research labs: 18 sectors are in scope, plus everyone their covered customers drag in via contracts. The duties read like an incident-readiness program — 24-hour early warning, 72-hour notification, personal accountability for executives — and the basics were overdue anyway.

Continue ReadingNIS2 Is Not Just for Banks: The Compliance Clock

CitrixBleed CVE-2023-4966: Session Tokens Straight From Memory

CVE-2023-4966 let attackers read valid session tokens out of NetScaler memory and inherit authenticated sessions wholesale — MFA already passed. CISA’s Emergency Directive 23-08 forced hunts and rebuilds as LockBit monetized the access.

Continue ReadingCitrixBleed CVE-2023-4966: Session Tokens Straight From Memory