VSEBINA PREDAVANJ 2023
Attacks on Blockchain in the Last Year
Over the past year, there have been a large number of attacks on crypto exchanges and various blockchain solutions, and the target was very often cross-chain bridges. Blockchain is more secure than other protocols/systems/applications, but… What happens when it is not implemented well, when there are vulnerabilities and when endpoints are not sufficiently secure as the technology itself? During the presentation, we will go through the various attack techniques that have most affected the blockchain network and see which protection measures are desirable to apply.
Cloud Forensics investigations in Azure
When a security incident is detected on the Azure cloud platform, forensic investigators must examine the log data collected from various sources. If a virtual machine is found to be affected, it is important to take a snapshot of the OS disk of the VM for further investigation. This session discusses the forensic acquisition methodology of an Azure VM and discusses an assumed DFIR scenario to divide the whole process into multiple steps using different forensic tools.
How my system got pwned: Lessons learned from CVE-2022-41352
In this, hopefully eye-opening lecture, we'll dive into how my system was compromised by exploiting CVE-2022-41352, a critical RCE that took me by surprise. I'll share my experience and how I learned
the hard way that "The cobbler's shoes are always the worst".
This incident reinforced the importance of taking layered security approach seriously and understanding that security is responsibility of the owner, even when using cloud services. Join me for an insightful
discussion on how to avoid making the same mistakes I did and keep your systems safe(r).
Insight into the ransomware incidents of 2022
Analysis on the ransomware incidents in Hungary of the past year, highlighting the different attack techniques. Presenting statistics and mitigation strategies of the sectors.
Kibernetsko varnostna mrežna arhitektura
"Kibernetsko varnostna mrežna arhitektura" je koncept, ki ga je predlagal Gartner kot smernice za gradnjo varne in zanesljive mrežne arhitekture. Ta koncept poudarja potrebo po celovitem pristopu k varnosti omrežij, ki vključuje tako tehnološke kot tudi organizacijske vidike. Pogledali si bomo, kako in zakaj bi te smernice želeli upoštevati.
Klasičen, najet ali hibriden?
Microsoft 365: Attack simulation training
Modern Cyberwarfare - From watering hole to supply chain attacks
Presentation describes some of the most complex techniques used by threat actors to compromise even the most secured networks, as seen in the SolarWinds hack.
Post-quantum digital signature scheme using Verkle construction
In October 2019, Google made a controversial claim of achieving quantum supremacy. However, considering the race among tech giants to develop the first quantum computers, and their progress in doing so, the world may be on the cusp of a new era.
Google's current chip design could increase memory capacity from 100 to 1000 qubits, while IBM aims to build a quantum processor with over 1,000 qubits and between 10 to 50 logical qubits by the end of 2023.
In 2021, Chinese scientists announced the development of a new quantum computer that surpasses its predecessors in strength. As a result, they have taken the lead in the quantum computing race. The scientists claim that their 66-qubit quantum CPU, called "Zuchongzhi 2," completed the same task as Google's computer one million times faster. This CPU was created by a team of researchers from the Chinese Academy of Sciences Center for Excellence in Quantum Information and Quantum Physics, in collaboration with the Shanghai Institute of Technical Physics and the Shanghai Institute of Microsystem and Information Technology.
Quantum computers have the potential to break the cryptographic codes currently used to secure communications and financial transactions. Therefore, quantum-resistant cryptography should be adopted as the current digital signature systems are vulnerable to attacks from quantum computers. The security of current digital signature systems relies on the difficulty of calculating discrete logarithms and factoring large numbers. Although some cryptosystems, such as RSA with four thousand-bit keys, are resistant to attacks from classical computers, they are ineffective against attacks from quantum computers.
At INFOSEK 2023 Maksim Iavich will offer the model of the new post-quantum digital signature scheme using the novel technology - Verkle tree. The offered signature is much more efficient than the existing hash based digital signatures.
Russian Hacktism Unmasked
Before the war in Ukraine if a large group of hackers would attack US financial systems, military suppliers, airports, or healthcare providers, this type of an event would be basis for a serious conflict and sanctions. Yet, over the past year these events became normal with little coverage and advice from law enforcement to brace for impact. We will examine who is behind the Russian Hacktivist collective and how it functions. Its targets and goals. Its weaknesses and strong points.
Security strategy development
- What should be the initial strategy ideas?
- What should be the expected output?
- Major focuses
- What? Why? How?
- How to define requirements?
- Action plans / projects
Stormshield, the European choice for cybersecurity!
TIBER-EU, the shift is here
The shift is here. As the time for testing in cyber security is not frozen, we need to be knowledgeable for what’s next generation penetration testing services. In that context we welcome TIBER-EU (European framework for threat intelligence-based ethical red-teaming) as the first EU-wide guide on how authorities, entities and threat intelligence and red-team providers should work together to test and improve the cyber resilience of entities by carrying out a controlled cyberattack. We did some study and find a way for implementing this framework by identifying its pros and cons. Join us for fast shift track to get into new era of testing in cyber security.
Why EDR is not the ultimate cure for cyber security
In today's world and with the shortage of cyber security professionals, organizations are looking for the ultimate solution to defend against the threat actor. One of these frequently selected solutions is an EDR. It certainly has a significant impact on endpoint security, but it does not solve enterprise network security on a holistic level. In this talk, Jan will present the ways in which adversaries are evading various EDRs and thus still causing harm.
Zero Trust Security