Generated by All in One SEO v4.9.7.2, this is an llms.txt file, used by LLMs to index the site. # I Am The Cavalry Safer. Sooner. Together. ## Sitemaps - [XML Sitemap](https://iamthecavalry.org/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [News](https://iamthecavalry.org/news/) - [PATCH Act will Mark Significant Step in Regulating Medical Device Cybersecurity](https://iamthecavalry.org/2023/04/11/introduction-of-patch-act-will-mark-significant-step-in-regulating-medical-device-cybersecurity/) - The passage of the Protecting and Transforming Cyber Health Care (PATCH) Act, will mark a significant step forward in regulating medical device cybersecurity. The bipartisan bill addresses the increased risks from evolving medical technology, including the rise of ransomware attacks on hospitals that have increased significantly in recent years. Some of the bill's much-needed provisions - [I Am The Cavalry Hosts Sixth Annual “Hackers on The Hill – and White House” Event](https://iamthecavalry.org/2023/02/10/i-am-the-cavalry-hosts-sixth-annual-hackers-on-the-hill-and-white-house-event/) - Policymakers in Washington play a critical role in shaping the country’s cybersecurity policies. To effectively address the ever-evolving security threats facing the nation, we believe they should work together with technical practitioners and cybersecurity researchers. I Am The Cavalry hosted a group of cybersecurity professionals and enthusiasts from across the country at “Hackers on the - [Celebrating Nine Years of The Cavalry and Exploring the Next Phase](https://iamthecavalry.org/2022/08/01/celebrating-nine-years-of-the-cavalry-and-exploring-the-next-phase/) - The Cavalry celebrates nine years as we turn toward the next phase of our mission. - [I Am The Cavalry Founder Josh Corman Testifies Before Senate Committee on Healthcare Cybersecurity](https://iamthecavalry.org/2022/05/25/i-am-the-cavalry-founder-josh-corman-testifies-before-senate-committee-on-healthcare-cybersecurity/) - IATC founder Josh Corman testifies before the Senate - [I Am The Cavalry Hosts Fifth ‘Hackers on the Hill’ Event](https://iamthecavalry.org/2022/03/31/i-am-the-cavalry-hosts-fifth-hackers-on-the-hill-event/) - I Am The Cavalry hosted more than 40 security leaders for Hackers on the Hill 2022. - [I Am The Cavalry Leads Statement of Support for IoT Security Baselines](https://iamthecavalry.org/2022/02/15/i-am-the-cavalry-leads-statement-of-support-for-iot-security-baselines/) - I Am The Cavalry is among the organizations leading an effort to raise the bar for IoT minimum security standards - [Defenders of Digital: The World Depends on You](https://iamthecavalry.org/2021/12/22/defenders-of-digital-the-world-depends-on-you/) - I Am The Cavalry co-founder Josh Corman featured the organization's work on "Defenders of Digital," a production from Tomorrow Unlocked and presented by Kaspersky. - [Cybersecurity Awareness Month 2021: #BeCyberSmart](https://iamthecavalry.org/2021/10/08/cybersecurity-awareness-month-2021-becybersmart/) - The I Am The Cavalry initiative and those who participate have gone beyond awareness and toward action in the past year. - [Call for Proposals: Supply Chain Sandbox at RSAC 2022](https://iamthecavalry.org/2021/09/28/call-for-proposals-supply-chain-sandbox-at-rsac-2022/) - Supply Chain Sandbox speaking proposals for RSA Conference 2022 at due Oct. 8. - [NASS Conference Builds Bridges for State Government and Security Research Community](https://iamthecavalry.org/2021/08/27/nass-conference-builds-bridges-for-state-government-and-security-research-community/) - The National Association of Secretaries of State summer conference brought together the security research community and government leaders. - [In the Saddle with Hack The Sea](https://iamthecavalry.org/2021/07/30/in-the-saddle-with-hack-the-sea/) - We asked Hack The Sea about their work tackling security challenges in the maritime sector and the importance of protecting maritime systems from malicious actors. - [In the Saddle with the Car Hacking Village](https://iamthecavalry.org/2021/06/25/in-the-saddle-with-the-car-hacking-village/) - We asked the Car Hacking Village about their work providing hands-on security training and working together to inform the public and automotive industry. - [In The Saddle with the IoT Village](https://iamthecavalry.org/2021/06/04/in-the-saddle-with-the-iot-village/) - We asked the IoT Village about how they help industry and threat researchers work together to secure our ever-growing number of connected devices. - [I Am the Cavalry Takes on Supply Chain Security](https://iamthecavalry.org/2021/07/16/i-am-the-cavalry-takes-on-supply-chain-security/) - Supply Chain Sandbox events at RSA featured interactive games that engaged participants in simulations to improve supply chain security skills, development, and teamwork. - [The COVID-19 Vaccines Weren't Hacked — This Task Force is One Reason Why](https://iamthecavalry.org/2021/07/08/the-covid-19-vaccines-werent-hacked-this-task-force-is-one-reason-why/) - I Am The Cavalry’s Josh Corman and Beau Woods were featured in The Verge for their work protecting the vaccine supply chain. - [In the Saddle with the Aerospace Village](https://iamthecavalry.org/2021/05/21/in-the-saddle-with-the-aerospace-village/) - I Am The Cavalry spoke with the Aerospace Village team about their work. - [Crypto Ransomware Payments Grew 311% in 2020: Chainanalysis](https://iamthecavalry.org/2021/01/19/crypto-ransomware-payments-grew-311-in-2020-chainanalysis/) - I Am The Cavalry co-founder Josh Corman’s previous quotes on the threat of ransomware to the health sector were featured in a Decrypt "chainanalysis" on the rise in crypto ransomware payments. - [Vaccine distribution unleashes new cybersecurity risks](https://iamthecavalry.org/2021/01/26/vaccine-distribution-unleashes-new-cybersecurity-risks/) - I Am The Cavalry’s Josh Corman discussed the changes in the supply chain threat landscape as a result of vaccine distribution with The Washington Post. - [Wi-Fi 6 for IoT and water plant security](https://iamthecavalry.org/2021/02/11/wi-fi-6-for-iot-and-water-plant-security/) - I Am The Cavalry’s Beau Woods joined The Internet of Things Podcast to discuss the hack of a water treatment plant in Florida and the general threat landscape of IoT. - [Ransomware and IP Theft: Top COVID-19 Healthcare Security Scares](https://iamthecavalry.org/2020/12/15/ransomware-and-ip-theft-top-covid-19-healthcare-security-scares/) - I Am The Cavalry’s Beau Woods joined Threatpost for conversation on cybersecurity challenges for hospitals during the COVID-19 pandemic. - [Healthcare in Crisis: Diagnosing Cybersecurity Shortcomings in Unprecedented Times](https://iamthecavalry.org/2020/12/07/healthcare-in-crisis-diagnosing-cybersecurity-shortcomings-in-unprecedented-times/) - I Am The Cavalry’s Beau Woods spoke with Threatpost about the importance of strengthening cybersecurity in the healthcare sector and why hospitals are experiencing a high cyber threat during COVID-19. - [Hackers threaten COVID-19 vaccine supply chain](https://iamthecavalry.org/2020/12/03/hackers-threaten-covid-19-vaccine-supply-chain/) - I Am The Cavalry’s Beau Woods discussed cyber vulnerabilities in the vaccine supply chain with Marketplace. - [COVID-19 vaccine supply chain targeted by hackers](https://iamthecavalry.org/2020/12/03/covid-19-vaccine-supply-chain-targeted-by-hackers/) - I Am The Cavalry co-founder Josh Corman discussed the spearphishing campaign aimed at disrupting the vaccine supply chain with a number of media outlets, including CyberScoop, Financial Times, Forbes, NBC News, The New York Times and WIRED. - [Elections Are Partisan Affairs. Election Security Isn’t.](https://iamthecavalry.org/2020/11/16/elections-are-partisan-affairs-election-security-isnt/) - I Am The Cavalry member Beau Woods signed EFF’s Open Letter on Election Security with other cybersecurity leaders, calling for an end to the politicization of election security. - [This woman hacked her own pacemaker to show how vulnerable we are to cyberattacks](https://iamthecavalry.org/2020/11/06/this-woman-hacked-her-own-pacemaker-to-show-how-vulnerable-we-are-to-cyberattack/) - I Am The Cavalry's Marie Moe discussed why she hacked her own pacemaker and work by I Am The Cavalry on securing connected medical devices. - [Ransomware attacks grow more menacing during the pandemic, creating headaches in health sector](https://iamthecavalry.org/2020/11/04/ransomware-attacks-grow-more-menacing-during-the-pandemic-creating-headaches-in-health-sector/) - I Am The Cavalry’s Josh Corman discussed the cyber threats which have been mounted against the healthcare sector and how the threats have only gotten worse in the age of COVID-19. - [The US killed Soleimani. What will Iran do next?](https://iamthecavalry.org/2020/01/10/the-us-killed-soleimani-what-will-iran-do-next/) - I Am The Cavalry's Beau Woods spoke to Vox about what may be in store if Iran decided to launch a cybersecurity attack following the U.S. killing of military leader Qassem Soleimani. - [In Battle For Europe's Phones, U.S. Suffers Setback, Huawei Notches A Win](https://iamthecavalry.org/2020/01/29/in-battle-for-europes-phones-u-s-suffers-setback-huawei-notches-a-win/) - I Am The Cavalry's Beau Woods spoke to NPR's "All Things Considered" about a push by the U.S. to stop European countries from using Chinese telecom giant Huawei to develop 5G infrastructure. - [Why is the healthcare industry still so bad at cybersecurity?](https://iamthecavalry.org/2020/02/09/why-is-the-healthcare-industry-still-so-bad-at-cybersecurity/) - I Am The Cavalry's Beau Woods provided expertise for an arsTECHNICA article on the reasoning behind the healthcare industry generally being behind when it comes to cybersecurity measures. - [Most Medical Imaging Devices Run Outdated Operating Systems](https://iamthecavalry.org/2020/03/10/most-medical-imaging-devices-run-outdated-operating-systems/) - I Am The Cavalry's Beau Woods spoke to Wired journalist Lily Hay Newman about the end of Windows 7 support and why medical devices are already especially vulnerable to cyberattacks. - [Shmoocon 2020 – Audie and Josh Corman’s ‘SBOM: Screw it, We’ll Do it Live!’](https://iamthecavalry.org/2020/03/24/shmoocon-2020-audie-and-josh-cormans-sbom-screw-it-well-do-it-live/) - At Shmoocon 2020, I Am The Cavalry co-founder Josh Corman and contributor Audie discussed the software bill of materials (SBOM) concept and how it can improve security for healthcare. - [Coronavirus scammers are getting taken down by grassroots ‘hackers without borders’](https://iamthecavalry.org/2020/04/01/coronavirus-scammers-are-getting-taken-down-by-grassroots-hackers-without-borders/) - I Am The Cavalry's Beau Woods spoke to Fortune about a grassroots effort by cybersecurity experts to protect the public against cyber threats that exploit the COVID-19 pandemic. - [Defense in Depth: Internet of Things](https://iamthecavalry.org/2020/04/02/defense-in-depth-internet-of-things/) - I Am The Cavalry co-founder Josh Corman joined a CISO/Security Relationship Series “Defense in Depth” podcast episode on the Internet of Things. - [DEF CON villages’ virtual reckoning](https://iamthecavalry.org/2020/05/22/def-con-villages-virtual-reckoning/) - I Am The Cavalry's Beau Woods talked with POLITICO’s Morning Cybersecurity about some of the changes and adaptations being seen as a result of the upcoming DEF CON IoT Village event going virtual. - [Anonymous Hacked Our Attention (Again)](https://iamthecavalry.org/2020/06/03/anonymous-hacked-our-attention-again/) - I Am The Cavalry co-founder Josh Corman’s writing about the organization, Anonymous, provided background in a Forbes article on the hacktivist collective’s actions against the Minneapolis Police Department in the wake of the death of George Floyd. - [Naked Trump Photo: Has Anonymous Finally Exposed Donald’s Dirty Laundry?](https://iamthecavalry.org/2020/06/08/naked-trump-photo-has-anonymous-finally-exposed-donalds-dirty-laundry/) - I Am The Cavalry co-founder Josh Corman’s background knowledge on the organization, Anonymous, was quoted in a Forbes article on a reported leak regarding President Trump. - [What’s Anonymous Up to Now?](https://iamthecavalry.org/2020/06/17/whats-anonymous-up-to-now/) - I Am The Cavalry co-founder Josh Corman provided expertise on the hacktivist organization, Anonymous, for a Dark Reading article regarding the group’s recent actions. - [Philadelphia-area health system says it ‘isolated’ a malware attack](https://iamthecavalry.org/2020/06/19/philadelphia-area-health-system-says-it-isolated-a-malware-attack/) - I Am The Cavalry's Beau Woods spoke about the rise of malware attacks threatening health care systems during the global pandemic in a CyberScoop article. - [Anonymous Activism Through Cyberspace - 2020 Ventures](https://iamthecavalry.org/2020/06/25/anonymous-activism-through-cyberspace-2020-ventures/) - I Am The Cavalry co-founder Josh Corman’s blog series “Building a Better Anonymous” was featured by Modern Diplomacy. - [Advice I Wish I Had Gotten...](https://iamthecavalry.org/2020/09/02/advice-i-wish-i-had-gotten/) - I Am The Cavalry co-founder Josh Corman gave a powerful talk at GRIMMCon 0x2 on empowering members of the cybersecurity community to overcome imposter syndrome, avoid the burnout cycle, and bring empathy to the job. - [Medical device makers race to understand the scope of the SweynTooth vulnerabilities](https://iamthecavalry.org/2020/03/06/medical-device-makers-race-to-understand-the-scope-of-the-sweyntooth-vulnerabilities/) - I Am The Cavalry's Beau Woods spoke to the Minneapolis Star Tribune about how medical-technology companies should respond to finding security vulnerabilities at some point in the supply chain. - [Seven perspectives on securing the global IoT supply chain](https://iamthecavalry.org/2020/05/19/seven-perspectives-on-securing-the-global-iot-supply-chain/) - I Am The Cavalry's Josh Corman and Beau Woods were both featured experts in an Atlantic Council article on ensuring security of the global IoT supply chain. - [InfoSecurity Podcast #NCSAM Special Edition](https://iamthecavalry.org/2020/10/16/infosecurity-podcast-ncsam-special-edition/) - I Am The Cavalry’s Beau Woods joined the InfoSecurity Podcast for a special edition episode to discuss Cybersecurity Awareness Month. - [Hackers Eye Their Next Targets, From Schools to Cars](https://iamthecavalry.org/2020/10/08/hackers-eye-their-next-targets-from-schools-to-cars/) - I Am The Cavalry's Beau Woods was a featured cybersecurity expert in a discussion on possible sectors which are soon to be favorite targets by hackers. - [European ransomware group strikes US hospital networks, analysts warn](https://iamthecavalry.org/2020/10/28/european-ransomware-group-strikes-us-hospital-networks-analysts-warn/) - I Am The Cavalry’s co-founder Josh Corman’s involvement with CISA's defense of the medical industry from ransomware attacks was mentioned in a CyberScoop article regarding rising concerns over ransomware attacks against US hospital networks. - [Rapid Threat Evolution Spurs Crucial Healthcare Cybersecurity Needs](https://iamthecavalry.org/2020/10/23/rapid-threat-evolution-spurs-crucial-healthcare-cybersecurity-needs/) - I Am The Cavalry’s Josh Corman discussed the threat landscape for the healthcare industry in the age of COVID-19 as well as prior to the pandemic. - [Healthcare cybersecurity needs a dose of threat modeling](https://iamthecavalry.org/2020/10/08/healthcare-cybersecurity-needs-a-dose-of-threat-modeling/) - I Am The Cavalry’s Josh Corman participated in a Q&A where he talked about the need to focus on threat modeling and stronger disaster recovery for cybersecurity in the healthcare sector. - [Cybersecurity Advice for the COVID-19 Era](https://iamthecavalry.org/2020/10/14/cybersecurity-advice-for-the-covid-19-era/) - I Am the Cavalry’s Josh Corman discussed some of the essential cybersecurity measures to take during the pandemic. - [The mission of protecting COVID-19 vaccine](https://iamthecavalry.org/2020/09/24/the-mission-of-protecting-covid-19-vaccine/) - I Am The Cavalry co-founder Josh Corman discussed his work with CISA working to protect vaccine research from hackers. - [CISA’s Corman Warns COVID Vaccine Hacks Could Endanger Millions](https://iamthecavalry.org/2020/09/17/cisas-corman-warns-covid-vaccine-hacks-could-endanger-millions/) - I Am The Cavalry co-founder Josh Corman talked about the serious implications of a potential hack of coronavirus vaccine research. - [How the government is keeping hackers from disrupting coronavirus vaccine research](https://iamthecavalry.org/2020/09/08/how-the-government-is-keeping-hackers-from-disrupting-coronavirus-vaccine-research/) - I Am The Cavalry’s Beau Woods discussed the overall awareness of cybersecurity and hacking issues in the healthcare industry. - [Mounting Ransomware Attacks Morph Into a Deadly Concern](https://iamthecavalry.org/2020/09/30/mounting-ransomware-attacks-morph-into-a-deadly-concern/) - I Am The Cavalry co-founder Josh Corman discussed the serious impacts of ransomware attacks against medical facilities. - [The #AppSec50: Top application security pros to follow on Twitter](https://iamthecavalry.org/2020/08/14/the-appsec50-top-application-security-pros-to-follow-on-twitter/) - I Am The Cavalry co-founder Josh Corman was featured as one of TechBeacon’s list of top application security professionals to follow on Twitter. - [After hack, Twitter locked out Democratic congressional candidates](https://iamthecavalry.org/2020/07/25/after-hack-twitter-locked-out-democratic-congressional-candidates/) - I Am The Cavalry’s Beau Woods weighed in on Twitter’s decision to lock certain Democratic congressional candidates out of their twitter accounts in light of a major hack. - [Taking the Pulse on Medical Device Security](https://iamthecavalry.org/2020/07/22/taking-the-pulse-on-medical-device-security/) - I Am The Cavalry’s Beau Woods joined the a16z Podcast to discuss security issues with biomedical devices. - [CISA turns to security experts with street cred to protect health sector](https://iamthecavalry.org/2020/07/22/cisa-turns-to-security-experts-with-street-cred-to-protect-health-sector/) - I Am The Cavalry’s Josh Corman joined DHS’s Cybersecurity and Infrastructure Security Agency as a visiting researcher charged with attempting to secure the healthcare sector during the pandemic. - [11 top DEF CON and Black Hat talks of all time](https://iamthecavalry.org/2020/07/21/11-top-def-con-and-black-hat-talks-of-all-time/) - “The Cavalry Isn’t Coming,” the DEF CON talk which launched the I Am The Cavalry movement earned a spot on the CSO list of 11 top DEF CON and Black Hat talks of all time. - [CISA Leader Puts Health Sector Project on the Level of Election Security Initiative](https://iamthecavalry.org/2020/10/06/cisa-leader-puts-health-sector-project-on-the-level-of-election-security-initiative/) - I Am The Cavalry co-founder Josh Corman spoke to Nextgov about what the Cybersecurity and Infrastructure Security Agency (CISA) is working on to ensure better cybersecurity in the health sector. - [Hack the Plant Episode 2: Where is the Cavalry? with Josh Corman](https://iamthecavalry.org/2020/09/28/hack-the-plant-episode-2-where-is-the-cavalry-with-josh-corman/) - I Am The Cavalry co-founder Josh Corman joined the "Hack the Plant" podcast hosted by Cavalry member and R Street Institute senior fellow Bryson Bort. - [Big health care analytics firm infected with ransomware](https://iamthecavalry.org/2020/02/21/big-health-care-analytics-firm-infected-with-ransomware/) - I Am The Cavalry's Josh Corman spoke to CyberScoop about the challenges faced by many healthcare facilities in preparing for ransomware attacks. - [Cheryl Biswas and Joshua Corman – Hacking Our Way from Vicious-to-Virtuous Cycle](https://iamthecavalry.org/2020/02/28/cheryl-biswas-and-joshua-corman-hacking-our-way-from-vicious-to-virtuous-cycle/) - At RSA 2020, InSecurity host Matt Stephenson caught up with I Am The Cavalry co-founder Josh Corman to talk about the root cause of the burnout many practitioners and employees in the security industry are currently experiencing. - [Report finds few consumers IoT firms allow vulnerability reporting](https://iamthecavalry.org/2020/03/18/report-finds-few-consumers-iot-firms-allow-vulnerability-reporting/) - New Electronics recognized I Am The Cavalry for its documentation of invulnerability reporting for consumer IoT security. - [Czech cyber officials warn of serious threat to health care sector](https://iamthecavalry.org/2020/04/17/czech-cyber-officials-warn-of-serious-threat-to-health-care-sector/) - I Am The Cavalry's Beau Woods spoke to CyberScoop about the dangers that the healthcare sector faces in the wake of possible cyber security threats based on intel from cyberattacks in the Czech Republic. - [On viral infections online and in the real world](https://iamthecavalry.org/2020/04/21/on-viral-infections-online-and-in-the-real-world/) - I Am The Cavalry's Beau Woods answered questions in an Atlantic Council article about the barriers to treating computer viruses and viral diseases in the real world. - [Health Prognosis on the Security of IoMT Devices? Not Good](https://iamthecavalry.org/2020/04/25/health-prognosis-on-the-security-of-iomt-devices-not-good/) - I Am The Cavalry's Josh Corman spoke to Dark Reading about the challenges of securing Internet of Medical Things devices. - [Let’s talk about UL’s device security rankings](https://iamthecavalry.org/2020/05/19/lets-talk-about-uls-device-security-rankings/) - I Am The Cavalry's Beau Woods spoke with Stacey on IoT about UL’s IoT device security certification program. - [Previewing the annual CISA cyber summit](https://iamthecavalry.org/2020/09/14/previewing-the-annual-cisa-cyber-summit/) - I Am The Cavalry co-founder Josh Corman spoke to Politico ahead of the third annual CISA National Cybersecurity Summit kickoff. - [Cavalry Members Tell Washington Post Cyber Awareness is Not Enough](https://iamthecavalry.org/2020/10/01/cavalry-members-tell-washington-post-cyber-awareness-is-not-enough/) - I Am The Cavalry’s Beau Woods and Bryson Bort told The Washington Post "Cybersecurity 202" author Joseph Marks that cybersecurity awareness is not enough for keeping safe online. - [Hospital Ransomware Attack Turns Fatal](https://iamthecavalry.org/2020/09/24/hospital-ransomware-attack-turns-fatal/) - News recently broke of the first death directly resulting from a cyberattack after a German hospital experienced a ransomware incident and was unable to accept emergency patients. - [Josh Corman Opens CISA Cybersecurity Summit](https://iamthecavalry.org/2020/09/21/josh-corman-opens-cisa-cybersecurity-summit/) - I Am The Cavalry Co-Founder Josh Corman kicked off day one of the 3rd Annual National Cybersecurity Summit, hosted by the Cybersecurity and Infrastructure Security Agency (CISA). - [5 Motivations of Security Researchers](https://iamthecavalry.org/2016/12/11/motivations/) - Security researchers have diverse motivations for investigating security flaws in software and systems. As companies, policymakers, lawyers, and others interact with the security research community, understanding this truth can unlock more fruitful engagement. I Am The Cavalry has been using a simple and useful framework to discuss the drivers of security researcher behavior. While this list isn't comprehensive, and while - ['Hacker Volunteerism' at CTI League Hackathon](https://iamthecavalry.org/2020/07/16/hacker-volunteerism-at-cti-league-hackathon/) - I Am The Cavalry member Beau Woods delivered a presentation on "Hacker Volunteerism" during the CTI League Hackathon. The talk highlighted the Cavalry's mission to address the security of connected technology that impacts human life, public safety, and national security. - [Security of Things Forum](https://iamthecavalry.org/2014/05/09/security-of-things-forum/) - The first inaugural Security of Things Forum was held May 7th. The forum, organized by The Security Ledger Editor in Chief, Paul Roberts, was keynoted by Dan Geer. Mark Stanislav of Duo Security and BuildItSecure.ly, and Josh Corman of Sonatype also spoke at the conference. CSO Online wrote an article, predominantly driven by Josh's talk, an updated version - [The Policymaker's Guide to DEF CON](https://iamthecavalry.org/2020/07/29/the-policymakers-guide-to-def-con/) - I Am The Cavalry member Beau Woods was recently interviewed about policymaker participation at DEF CON "Safe Mode" for the Hewlett Foundation Cyber Initiative newsletter. - ["Burn In" Book Event - Friday, June 12, 2020](https://iamthecavalry.org/2020/06/09/burn-in-book-event/) - I Am The Cavalry brings together leaders in ICS security for a narrative-driven discussion about how IOT, Industrial IoT, and Public Infrastructure security decisions of 2020 will shape resiliency and vulnerability throughout the next decade. - [I Am The Cavalry Recognized by Massachusetts Digital Health Initiative](https://iamthecavalry.org/2020/06/16/i-am-the-cavalry-recognized-by-massachusetts-digital-health-initiative/) - The Massachusetts Digital Health Initiative, a public-private partnership between the state of Massachusetts and several companies based there, listed I Am The Cavalry's Hippocratic Oath for Connected Medical Devices among other cybersecurity practices for medical devices. Our document joins FDA guidance and industry best practices. In addition, they added our list of known disclosure programs - [I Am The Cavalry Hosts 'Hackers on the Hill'](https://iamthecavalry.org/2020/02/05/i-am-the-cavalry-hosts-hackers-on-the-hill/) - I Am The Cavalry hosted a diverse group of cyber professionals from across the country at “Hackers on the Hill” last week. The event was held in the U.S. Capitol and aimed to bridge the gap between hackers, industry experts, and the public policy community. The cyber professionals heard from some of the most influential - [AV complexity is the enemy of security](https://iamthecavalry.org/2018/09/21/av-complexity-is-the-enemy-of-security/) - Be smart: Security is among the most difficult issues for AVs. Where the once distinct domains of automobiles and cybersecurity have collided, good-faith collaboration can make new forms of mobility safer, sooner. - [1-27-20 - News So Far This Year](https://iamthecavalry.org/2020/01/27/1-27-20-news-so-far-this-year/) - Hackers Can Exploit Siemens Control System Flaws in Attacks on Power Plants According to Siemens, the SPPA-T3000 Application Server is affected by 19 vulnerabilities and the SPAA-T3000 MS3000 Migration Server is impacted by 35 security holes, including weaknesses rated critical that can be exploited for denial-of-service (DoS) attacks or arbitrary code execution on the server. - [RSA Conference 2020 Sandbox](https://iamthecavalry.org/2020/01/17/rsa-conference-2020-sandbox/) - In past years, the RSA Conference has run a Sandbox space, hosting groups like the ICS Village, Car Hacking Village, and IoT Village. This year the Sandbox area will be greatly expanded, and will include the Biohacking Village, Voting Village, Aerospace Village. Totally new this year, we will be running a Supply Chain Sandbox. Supply chain - [12-9-19 - News This Past Month](https://iamthecavalry.org/2019/12/09/12-9-19-news-this-past-month/) - New 5G flaws can track phone locations and spoof emergency alerts Security researchers at Purdue University and the University of Iowa have found close to a dozen vulnerabilities, which they say can be used to track a victim’s real-time location, spoof emergency alerts that can trigger panic or silently disconnect a 5G-connected phone from the - [11-11-19 - News This Past Week](https://iamthecavalry.org/2019/11/12/11-11-19-news-this-past-week/) - DHS Warns of Critical Flaws in Medtronic Medical Devices An advisory published by the DHS’s Cybersecurity & Infrastructure Security Agency (CISA) warns of three recently patched vulnerabilities in Medtronic Valleylab FT10 and FX8 devices that could allow attackers to install a non-root shell. https://www.securityweek.com/dhs-warns-critical-flaws-medtronic-medical-devices Hospital Cyberattacks Linked to Increase in Heart Attack Mortality Ransomware attacks - [11-4-19 - News This Past Week](https://iamthecavalry.org/2019/11/04/11-4-19-news-this-past-week/) - Details of Attack on Electric Utility Emerge The March 5 DDoS attack interrupted communications between generating facilities and the electrical grid in three western states https://www.darkreading.com/attacks-breaches/details-of-attack-on-electric-utility-emerge/d/d-id/1336245 Cisco Firewall Exploited in Attack on U.S. Renewable Energy Firm A report published earlier this year by the National Energy Technology Laboratory revealed that a cyber event caused problems - [10-28-19 - News This Past Week](https://iamthecavalry.org/2019/10/28/10-28-19-news-this-past-week/) - Upstream Security raises $30 million to protect connected cars from cyberattacks Upstream Security, a cloud-based cybersecurity platform for connected cars, has raised $30 million in a series B round of funding led by Alliance Ventures, an automotive alliance constituting Renault, Mitsubishi, and Nissan. Volvo Group, Hyundai, CRV, Glilot Capital, Maniv Mobility, and Nationwide also participated - [10-21-19 - News This Past Week](https://iamthecavalry.org/2019/10/21/10-21-19-news-this-past-week/) - Security still top priority as more enterprises scale IoT solutions company-wide The Zebra Technologies Corporation global survey analyzes the extent to which companies connect the physical and digital worlds to drive innovation through real-time guidance, data-powered environments and collaborative mobile workflows. https://www.helpnetsecurity.com/2019/10/18/scale-iot-solutions/ IoT Attacks Up Significantly in First Half of 2019 New research shows attacks - [10-14-19 - News This Past Week](https://iamthecavalry.org/2019/10/14/10-14-19-news-this-past-week/) - Experts expect hospital ransomware attacks to continue One week after being hit by a ransomware attack, hospitals in Alabama are turning away patients while working on recovery, and experts warn of similar attacks in the future. https://searchsecurity.techtarget.com/news/252472010/Experts-expect-hospital-ransomware-attacks-to-continue Utilities' Operational Networks Continue to Be Vulnerable More than half of utilities have suffered an outage or data - [10-7-19 - News This Past Bit](https://iamthecavalry.org/2019/10/07/10-7-19-news-this-past-bit/) - Honeywell Launches New Industrial Cybersecurity Platform Honeywell on Wednesday announced the launch of a new industrial cybersecurity platform designed to help organizations protect their operational technology (OT) and industrial internet of things (IIoT) assets from cyber threats https://www.securityweek.com/honeywell-launches-forge-industrial-cybersecurity-platform 76% medical devices of healthcare facilities in Philippines may be infected by malicious code These are alarming - [9-16-19 - News This Past Week](https://iamthecavalry.org/2019/09/16/9-16-19-news-this-past-week/) - Securing a Connected Future: 5G and IoT Security Already available in some cities, 5G is ushering in an entirely new set of standards for global wireless communications. As the IoT-era continues to come into its own, businesses developing automotive, healthcare, industrial, energy and other IoT applications are planning with 5G in mind for a lot - [9-9-19 - News This Past Week](https://iamthecavalry.org/2019/09/09/9-9-19-news-this-past-week/) - Report reveals play-by-play of first U.S. grid cyberattack A first-of-its-kind cyberattack on the U.S. grid created blind spots at a grid control center and several small power generation sites in the western United States, according to a document posted yesterday from the North American Electric Reliability Corp. https://www.eenews.net/stories/1061111289 Critical Bugs Open Food-Safety Systems to Remote - [9-3-19 - News This Past Week](https://iamthecavalry.org/2019/09/03/9-3-19-news-this-past-week/) - How to reduce the attack surface associated with medical devices Most medical devices available in the healthcare system today were not built with security in mind and it will take years until they are replaced (if they are at all) with next-generation devices https://www.helpnetsecurity.com/2019/09/03/medical-devices-attack-surface Securing Our Infrastructure: 3 Steps OEMs Must Take in the IoT - [8-12-19 - News This Past Week](https://iamthecavalry.org/2019/08/12/8-12-19-news-this-past-week/) - Connected Cars Could be a Threat to National Security, Group Claims The cyber threat to connected cars (cars with a connection to the internet) is known and accepted. Now Los Angeles-based Consumer Watchdog (CW) has elevated that threat to one of national security in a new report titled, "Kill Switch: Why Connected Cars Can be - [7-15-19 - News This Past Week](https://iamthecavalry.org/2019/07/15/7-15-19-news-this-past-week/) - Cybersecurity should not be an afterthought within industrial environments The basics of cyber security are still not being practized regularly and new cyber security risks are emerging as more and more untested technologies are integrated within the critical infrastructures upon which society depends, according to Applied Risk https://www.helpnetsecurity.com/2019/07/09/cybersecurity-industrial-environments U.S. Coast Guard Issues Cybersecurity Warnings for - [8-26-19 - News This Past Weeek](https://iamthecavalry.org/2019/08/26/8-26-19-news-this-past-weeek/) - Adwind Spyware-as-a-Service Attacks Utility Grid Operators Critical infrastructure facilities are high-risk targets, and the fact that Adwind is available as a paid service is very concerning https://threatpost.com/adwind-spyware-as-a-service-attacks-utility-grid-operators/147525/ New Tool From Cisco Hunts Flaws in Automotive Computers Access to the vehicle computer, Cisco notes, is possible via Wi-Fi, Bluetooth, or cellular communication protocols, but the backbone - [8-19-19 - News This Past Week](https://iamthecavalry.org/2019/08/19/8-19-19-news-this-past-week/) - ICS security threats rising, targeting oil and gas facilities In its latest report on industrial control system threats, Dragos said it believes the first major 'destructive' ICS attack will likely occur at an oil and gas facility. https://searchsecurity.techtarget.com/news/252468175/ICS-security-threats-rising-targeting-oil-and-gas-facilities Delta ICS Flaw Allows Total Industrial Takeover The Delta enteliBUS Manager centralizes control for various pieces of - [8-5-19 - News This Past Week](https://iamthecavalry.org/2019/08/05/8-5-19-news-this-past-week/) - 200 million devices—some mission-critical—vulnerable to remote takeover For the 200 million devices Armis estimated are running a version that’s susceptible to a serious attack, however, the stakes may be high. Because many of the vulnerabilities reside in the networking stack known as IPnet, they can often be exploited by little more than boobytrapped packets sent - [7-29-19 - News These Past Two Weeks](https://iamthecavalry.org/2019/07/29/7-29-19-news-these-past-two-weeks/) - Georgia State Patrol hit with ransomware attack A week ago Lawrenceville Police department was targeted by hackers in a cyber attack. As a result of ransomware found on the precinct's system, police were unable to utilize email and other digital forms of communications, as well as access digital reports. https://www.cbs46.com/news/georgia-state-patrol-hit-with-ransomware-attack/article_864c746c-b08d-11e9-8252-43bf599632f2.html Ransomware Causes Disruptions at Johannesburg - [7-8-19 - News This Past Week](https://iamthecavalry.org/2019/07/08/7-8-19-news-this-past-week/) - US wants to isolate power grids with 'retro' technology to limit cyber-attacks The US is very close to improving power grid security by mandating the use of "retro" (analog, manual) technologies on US power grids as a defensive measure against foreign cyber-attacks that could bring down power distribution as a result https://www.zdnet.com/article/us-wants-to-isolate-power-grids-with-retro-technology-to-limit-cyber-attacks/ Cyberwarfare in space: - [7-1-19 - News This Past Week](https://iamthecavalry.org/2019/07/01/7-1-19-news-this-past-week/) - Mission Possible: ICS Attacks On Buildings Are a Reality In the 1996 thriller, Mission Impossible I, Ethan Hunt hacks the HVAC system of a building to breach its security controls and carry out his mission. Well, the future has arrived https://www.securityweek.com/mission-possible-ics-attacks-buildings-are-reality What is Critical Infrastructure and How Should We Protect It? We hear a lot - [6-24-19 - News This Past Week](https://iamthecavalry.org/2019/06/24/6-24-19-news-this-past-week/) - Countering industrial cyberthreats with secure, standards-based, licensed wireless networks This was the first documented digital attack known to have compromised electrical grid operations in the United States due to a moderately basic hack and showed us how the potential for far more significant disruption is a legitimate concern to industry professionals and consumers alike. https://www.helpnetsecurity.com/2019/06/21/standards-based-licensed-wireless-networks/ - [6-17-19 - News This Past Week](https://iamthecavalry.org/2019/06/17/6-17-19-news-this-past-week/) - Hackproofing smart meters and boosting smart grid security Smart electricity meters are useful because they allow energy utilities to efficiently track energy use and allocate energy production. But because they’re connected to a grid, they can also serve as back doors for malicious hackers https://www.helpnetsecurity.com/2019/06/11/hackproofing-smart-meters/ Critical Vulnerability Exposes Oil Tank Monitoring Devices to Attacks A - [6-10-19 - News This Past Week](https://iamthecavalry.org/2019/06/10/6-10-19-news-this-past-week/) - A backdoor in Optergy tech could remotely shut down a smart building ‘with one click’ An advisory said an attacker could gain “full system access” through an “undocumented backdoor script.” This, the advisory said, could allow the attacker to run commands on a vulnerable device with the highest privileges. https://techcrunch.com/2019/06/06/optergy-backdoor-smart-building/ Industrial cybersecurity strategies need a - [6-3-19 - News This Past Week](https://iamthecavalry.org/2019/06/03/6-3-19-news-this-past-week/) - How likely are weaponized cars? The modern vehicle can be described as electric, connected, software embedded, driverless, and even artificially intelligent. Left unmanaged and without security considerations, these properties render risks that manifest as software bugs and design flaws that may allow unauthorized remote access https://www.helpnetsecurity.com/2019/06/03/weaponized-cars/ Siemens LOGO!, a PLC for small automation projects, open - [5-28-19 - News This Past Week](https://iamthecavalry.org/2019/05/28/5-28-19-news-this-past-week/) - 'Why do we need to wait for people to be hurt?' Medical cyber attacks soar 1400% Strapped to a stretcher, surrounded by medics, nurses and doctors, a middle-aged man was about to play patient zero in what America's health care industry fears could be the next major pandemic: "cybergeddon." https://www.sfgate.com/healthredesign/article/medical-cyber-attacks-terrorism-hospital-health-13853912.php General Motors designs a new - [5-20-19 - News This Past Week](https://iamthecavalry.org/2019/05/20/5-20-19-news-this-past-week/) - Wormable Windows RDS Vulnerability Poses Serious Risk to ICS A critical remote code execution vulnerability patched recently by Microsoft in Windows Remote Desktop Services (RDS) poses a serious risk to industrial environments, experts have warned. https://www.securityweek.com/wormable-windows-rds-vulnerability-poses-serious-risk-ics We chat to boffins who've found a way to disrupt landings using off-the-shelf radio kit In a research paper - [5-13-19 - News This Past Week](https://iamthecavalry.org/2019/05/13/5-13-19-news-this-past-week/) - Over 100 Flaws Expose Buildings to Hacker Attacks He said an attacker can conduct a wide range of activities after hijacking the vulnerable systems, including trigger alarms, lock or unlock doors and gates, control elevator access, intercept video surveillance streams, manipulate HVAC systems and lights, disrupt operations, and steal personal information https://www.securityweek.com/over-100-flaws-expose-buildings-hacker-attacks Extinguishing the IoT - [5-6-19 - News This Past Week](https://iamthecavalry.org/2019/05/06/5-6-19-news-this-past-week/) - Hacking our way into cybersecurity for medical devices Hospitals are filled with machines connected to the internet. With a combination of both wired and wireless connectivity, knowing and managing which devices are connected has become more complicated and, consequently, the institutions’ attack surface has expanded https://www.helpnetsecurity.com/2019/04/30/cybersecurity-for-medical-devices/ People Are Clamoring to Buy Old Insulin Pumps How - [4-29-19 - News These Past Two Weeks](https://iamthecavalry.org/2019/04/29/4-29-19-news-these-past-two-weeks/) - TRITON Attacks Underscore Need for Better Defenses After revealing last week that the same set of tools used by the TRITON attackers were also found in a second victim's network, security services firm FireEye stressed that attackers are likely in the networks of some of the facilities that are home to the 18,000 Triconex safety - [4-15-19 - News This Past Week](https://iamthecavalry.org/2019/04/15/4-15-19-news-this-past-week/) - Someone is targeting "critical infrastructure" safety systems in networked attacks The Triton malware was first identified 16 months ago by researchers from Fireeye: it targets Triconex control systems from Schneider Electric, and was linked by Fireeye to the Central Scientific Research Institute of Chemistry and Mechanics in Moscow https://boingboing.net/2019/04/11/cyberkinetic.html Triton ICS Malware Hits A Second - [4-8-19 - News This Past Week](https://iamthecavalry.org/2019/04/08/4-8-19-news-this-past-week/) - TXOne Networks Unveils First Industrial Cybersecurity Product TXOne Networks, a joint venture between cybersecurity firm Trend Micro and industrial networking solutions provider Moxa, this week unveiled its first product, an industrial intrusion prevention system https://www.securityweek.com/txone-networks-unveils-first-industrial-cybersecurity-product Long Equipment Life Cycles Expose Manufacturing Industry to Attacks: Study Using data from its Smart Protection Network infrastructure, Trend Micro - [4-1-19 - News This Past Week](https://iamthecavalry.org/2019/04/01/4-1-19-news-this-past-week/) - Critical Rockwell Automation Bug in Drive Component Puts IIoT Plants at Risk A critical denial-of-service (DoS) vulnerability has been found in a Rockwell Automation industrial drive, which is a logic-controlled mechanical component used in industrial systems to manage industrial motors. https://threatpost.com/critical-rockwell-automation-bug-in-drive-component-puts-iiot-plants-at-risk/143258/ Critical Flaw Allows Hackers to Take Control of PowerFlex AC Drives PowerFlex 525 AC - [3-25-19 - News This Past Week](https://iamthecavalry.org/2019/03/25/3-25-19-news-this-past-week/) - New IoT Security Bill: Third Time's the Charm? The latest bill to set security standards for connected devices sold to the US government has fewer requirements, instead leaving recommendations to the National Institute of Standards and Technology. https://www.darkreading.com/iot/new-iot-security-bill-third-times-the-charm/d/d-id/1334190 Hacked tornado sirens taken offline in two Texas cities ahead of major storm A hacker set off - [3-18-19 - News This Past Week](https://iamthecavalry.org/2019/03/18/3-18-19-news-this-past-week/) - Tripwire debuts pentesting and industrial cybersecurity assessment services With Tripwire’s new services, organizations can establish and maintain a strong foundation of security. The Penetration Testing Assessment leverages highly skilled cybersecurity experts who discover and then exploit vulnerabilities to assess the security of an organization’s IT environment https://www.helpnetsecurity.com/2019/03/04/tripwire-pentesting-industrial-cybersecurity-assessment-services/ Quantum Physics Could Protect the Grid From Hackers—Maybe - [3-4-19 - News Since February](https://iamthecavalry.org/2019/03/04/3-4-19-news-since-february/) - How to Attack and Defend a Prosthetic Arm The IoT world has long since grown beyond the now-ubiquitous smartwatches, smartphones, smart coffee machines, cars capable of sending tweets and Facebook posts and other stuff like fridges that send spam. Today’s IoT world now boasts state-of-the-art solutions that quite literally help people. Take, for example, the - [02-04-19 - News Since January](https://iamthecavalry.org/2019/02/04/02-04-19-news-since-january/) - Top 10 IoT vulnerabilities Everyone knows security is a big issue for the Internet of Things, but what specifically should we be most afraid of? OWASP identifies the top 10 vulnerabilities https://www.networkworld.com/article/3332032/internet-of-things/top-10-iot-vulnerabilities.html Schneider Electric Teams With Nozomi on Critical Infrastructure Security Schneider Electric has teamed up with industrial cybersecurity firm Nozomi Networks to offer anomaly - [01-14-19 - News This Past Couple Weeks](https://iamthecavalry.org/2019/01/14/01-14-19-news-this-past-couple-weeks/) - Medical Device Security Firm Cynerio Raises $7 Million The company's security platform provides visibility into clinical entities on a network and allows organizations to assess the risk associated with device behavior and detect anomalies with medical context consideration to stop malicious threats and increase patient safety and data security https://www.securityweek.com/medical-device-security-firm-cynerio-raises-7-million IoT Community announces formation of - [12-31-18 - News To End The Year](https://iamthecavalry.org/2018/12/31/12-31-18-news-to-end-the-year/) - US ballistic missile systems have very poor cyber-security No data encryption, no antivirus programs, no multifactor authentication mechanisms, and 28-year-old unpatched vulnerabilities are just some of the cyber-security failings described in a security audit of the US' ballistic missile system released on Friday by the US Department of Defense Inspector General https://www.zdnet.com/article/us-ballistic-missile-systems-have-very-poor-cyber-security/ The US ballistic - [12-17-18 - News This Past Week](https://iamthecavalry.org/2018/12/17/12-17-18-news-this-past-week/) - Italian Oil Services Company Saipem Hit by Cyberattack The company has shared few details about the attack – it’s unclear if it was ransomware or another type of intrusion – but its representatives told SecurityWeek that no data was stolen and that only some servers in its infrastructure were impacted https://www.securityweek.com/italian-oil-services-company-saipem-hit-cyberattack Claroty Adds New Capabilities - [12-10-18 - News This Past Week](https://iamthecavalry.org/2018/12/10/12-10-18-news-this-past-week/) - Vulnerability Exposes Rockwell Controllers to DoS Attacks Some of Rockwell Automation’s MicroLogix controllers and ControlLogix communications modules are affected by a potentially serious vulnerability that can be exploited for denial-of-service (DoS) attacks https://www.securityweek.com/vulnerability-exposes-rockwell-controllers-dos-attacks Siemens Wants to Release Security Advisories on Patch Tuesday The company carried out a pilot test last month, when it published a - [12-03-18 - News This Past Week](https://iamthecavalry.org/2018/12/03/12-03-18-news-this-past-week/) - IIoT technologies integration creates expansion opportunities in the industrial cybersecurity industry High penetration of Industrial Internet of Things (IIoT) technology in critical infrastructure and the manufacturing sector has resulted in a growing number of potential cyber-attack surfaces https://www.helpnetsecurity.com/2018/12/03/iiot-technologies-integration/ Best practice methodology for industrial network security: SEC-OT Secure Operations Technology (SEC-OT) is a methodology and collection - [11-26-18 - News These Past Two Weeks](https://iamthecavalry.org/2018/11/26/11-26-18-news-these-past-two-weeks/) - New IoT Security Regulations Due to ever-evolving technological advances, manufacturers are connecting consumer goods­ -- from toys to light bulbs to major appliances­ -- to the Internet at breakneck speeds. This is the Internet of Things, and it's a security nightmare https://www.schneier.com/blog/archives/2018/11/new_iot_securit.html Siemens Patches Firewall Flaw That Put Operations at Risk Siemens AG on Tuesday - [11-12-18 - News This Past Week](https://iamthecavalry.org/2018/11/12/11-12-18-news-this-past-week/) - Flaws in Roche Medical Devices Can Put Patients at Risk The affected products consist of a base unit and a handheld device that communicates wirelessly – including over Wi-Fi if an optional module is available – with the base unit. Medigate researchers discovered that an attacker with access to the local network can hack the - [11-05-18 - News This Past Week](https://iamthecavalry.org/2018/11/05/11-05-18-news-this-past-week/) - USB threat vector trends and implications for industrial operators In an attempt to make industrial control systems less accessible to attackers, industrial players are limiting network access and increasingly using USB media devices to transfer patches, updates and files to those systems https://www.helpnetsecurity.com/2018/11/02/industrial-usb-threats/ Researchers find Stuxnet, Mirai, WannaCry lurking in industrial USB drives When we - [10-29-18 - News This Past Week](https://iamthecavalry.org/2018/10/29/10-29-18-news-this-past-week/) - FDA strengthens medical device cybersecurity program The FDA recently took additional steps to encourage better medical device cybersecurity, including releasing a cybersecurity playbook for healthcare organizations https://searchhealthit.techtarget.com/feature/FDA-strengthens-medical-device-cybersecurity-program What a crane in the ass: Bug leaves construction machinery vulnerable to evil command injection US-CERT is advising some customers of Telecrane construction cranes to patch their control - [10-24-18 - News This Past Week](https://iamthecavalry.org/2018/10/24/10-24-18-news-this-past-week/) - FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware Cybersecurity firm FireEye claims to have discovered evidence that proves the involvement of a Russian-owned research institute in the development of the TRITON malware that caused some industrial systems to unexpectedly shut down last year, including a petrochemical plant in Saudi Arabia. https://thehackernews.com/2018/10/russia-triton-ics-malware.html Russia - [10-15-18 - News This Past Week](https://iamthecavalry.org/2018/10/15/10-15-18-news-this-past-week/) - The future of OT security in modern industrial operations Both the likelihood and consequences of cyberattacks to OT/ICS components continue to grow for modern industrial operations https://www.helpnetsecurity.com/2018/10/15/future-ot-security/ It's the real Heart Bleed: Medtronic locks out vulnerable pacemaker programmer kit The watchdog's alert this week comes after Irish medical device maker Medtronic said it will lock - [10-08-18 - News This Past Week](https://iamthecavalry.org/2018/10/08/10-08-18-news-this-past-week/) - DHS Warns of Threats to Precision Agriculture Relying on various embedded and connected technologies to improve agricultural and livestock management, precise agriculture is exposed to vulnerabilities and cyber-threats, a new report from the United States Department of Homeland Security (DHS) warns https://www.securityweek.com/dhs-warns-threats-precision-agriculture California bans default passwords on any internet-connected device In less than two years, - [10-01-18 - News This Past Week](https://iamthecavalry.org/2018/10/01/10-01-18-news-this-past-week/) - California's new laws bolster security for connected devices California just raised the baseline for security in the Internet of Things… to a degree. Governor Jerry Brown has signed very similar Assembly and Senate bills that require hardware makers to include "reasonable" security measures for connected devices https://www.engadget.com/2018/09/30/california-connected-device-laws/ 'Torii' Breaks New Ground For IoT Malware Stealth, - [09-24-18 - News This Past Week](https://iamthecavalry.org/2018/09/24/09-24-18-news-this-past-week/) - Legitimate RATs Pose Serious Risk to Industrial Systems A report published on Friday by the security firm reveals that, on average, in the first half of 2018, legitimate RATs were found on more than two-thirds of computers used for industrial control systems (ICS). https://www.securityweek.com/legitimate-rats-pose-serious-risk-industrial-systems Rockwell Automation Patches Severe Flaws in Communications Software RSLinx Classic is - [09-17-18 - News This Past Week](https://iamthecavalry.org/2018/09/17/09-17-18-news-this-past-week/) - Global market for smart city platforms expected to reach $755 million by 2027 Driven by Internet of Things (IoT) deployments, as well as other smart technologies, smart city platforms provide the integrated capability to coordinate data, applications, and services at one or more levels across operational domains for multiple stakeholders https://www.helpnetsecurity.com/2018/09/12/smart-city-platforms/ BlackIoT: IoT Botnet of - [09-09-18 - News These Past Two Weeks](https://iamthecavalry.org/2018/09/09/09-09-18-news-these-past-two-weeks/) - Malware Found on USB Drives Shipped With Schneider Solar Products Schneider Electric recently informed customers that some of the USB flash drives shipped by the company with its Conext ComBox and Conext Battery Monitor products were infected with malware https://www.securityweek.com/malware-found-usb-drives-shipped-schneider-solar-products Finding the Middle Ground: Securing Smart Cities High-profile cyberattacks and data breaches have become somewhat - [08-27-18 - News This Past Week](https://iamthecavalry.org/2018/08/27/08-27-18-news-this-past-week/) - Trend Micro’s new program helps IoT device makers tackle risk at source Trend Micro has reconfirmed its commitment to Internet of Things (IoT) security with a new program designed to leverage its Zero Day Initiative (ZDI) to minimize vulnerabilities as smart products are developed. https://www.helpnetsecurity.com/2018/08/23/trend-micro-zero-day-initiative/ Security of smart utilities leaves a lot to be desired - [08-20-18 - News These Past Two Weeks](https://iamthecavalry.org/2018/08/20/08-20-18-news-these-past-two-weeks/) - Hacking Police Bodycams Mitchell even realized that because he can remotely access device storage on models like the Fire Cam OnCall, an attacker could potentially plant malware on some of the cameras https://www.wired.com/story/police-body-camera-vulnerabilities/ Five key security tips to avoid an IoT hack Recently, Russian PIR Bank lost $1,000,000 because of a compromised router that allowed - [08-06-18 - News This Past Week](https://iamthecavalry.org/2018/08/06/08-06-18-news-this-past-week/) - US Department of Homeland Security says Russia hacked networks of major US energy firms Citing officials at the Department of Homeland Security (DHS), the hacks were first detected in the spring of 2016 and continued throughout 2017, carried out by hackers who worked for a Russian state-sponsored group previously known as Dragonfly or Energetic Bear - [07-30-18 - News This Past Week](https://iamthecavalry.org/2018/07/30/07-30-18-news-this-past-week/) - Xage secures $12 million Series A for IoT security solution on blockchain It’s an interesting approach, one that attracted Duncan Greatwood to the company. As he told me in December his previous successful exits — Topsy to Apple in 2013 and PostPath to Cisco in 2008 — gave him the freedom to choose a company - [07-23-18 - News This Past Week](https://iamthecavalry.org/2018/07/23/07-23-18-news-this-past-week/) - How hackers exploit critical infrastructure The traditional focus of most hackers has been on software, but the historical focus of crime is on anything of value. It should come as no surprise, therefore, that as operational technology (OT) and industrial control system (ICS) infrastructure have become much more prominent components of national critical infrastructure, that - [07-16-18 - News This Past Week](https://iamthecavalry.org/2018/07/16/07-16-18-news-this-past-week/) - Flaws Expose Siemens Protection Relays to DoS Attacks Siemens has informed customers that some of the company’s SIPROTEC protection relays are exposed to denial-of-service (DoS) attacks due to a couple of vulnerabilities present in the EN100 communication module https://www.securityweek.com/flaws-expose-siemens-protection-relays-dos-attacks VPNFilter Malware Hits Critical Infrastructure in Ukraine The Security Service of Ukraine (SBU) revealed this week - [07-09-18 - News This Past Week](https://iamthecavalry.org/2018/07/09/07-09-18-news-this-past-week/) - Flaws Expose Siemens Central Plant Clocks to Attacks Siemens SICLOCK devices are used to synchronize time in industrial plants. The central plant clock ensures stability in case of a failure or loss of reception at the primary time source https://www.securityweek.com/flaws-expose-siemens-central-plant-clocks-attacks Strange and scary IoT hacks The Internet of Things has provided a worldwide digital playground - [07-02-18 - News This Past Week](https://iamthecavalry.org/2018/07/02/07-02-18-news-this-past-week/) - Rockwell Patches Flaw Affecting Safety Controllers From Several Vendors In April, at SecurityWeek’s ICS Cyber Security Conference in Singapore, industrial cybersecurity firm Applied Risk disclosed the details of a serious denial-of-service (DoS) vulnerability affecting safety controllers from several major vendors. Rockwell Automation is one of those vendors and the company has now released patches for - [06-25-18 - News This Past Week](https://iamthecavalry.org/2018/06/25/06-25-18-news-this-past-week/) - Pwned with '4 lines of code': Researchers warn SCADA systems are still hopelessly insecure A presentation at last week's BSides London conference by researchers from INSINIA explained how a device planted on a factory floor can identify and list networks, and trigger controllers to stop processes or production lines. https://www.theregister.co.uk/2018/06/18/physically_hacking_scada_infosec/ China-based hackers burrow inside satellite, - [06-18-18 - News This Past Week](https://iamthecavalry.org/2018/06/18/06-18-18-news-this-past-week/) - 'Shift Left' & the Connected Car How improving application security in the automotive industry can shorten product development time, reduce costs, and save lives. https://www.darkreading.com/application-security/shift-left-and-the-connected-car/a/d-id/1332018 ICS/SCADA Smart Scanning: Discover and Assess IT-Based Systems in Converged IT/OT Environments Increasingly, operational technology (OT) environments are interconnecting with IT and adopting exploitable IT-based assets and protocols. This means - [Hippocratic Oath in German](https://iamthecavalry.org/2018/06/25/hippocratic-oath-in-german/) - The country of Siemens, Braun, Dräger, Zeiss and many more renowned medical engineering companies is finally getting it too: I am the Cavalry has published the long and short versions of the Hippocratic Oath for Connected Devices in the German language. The Oath is a voluntary agreement to honour the principles of software engineering safety - [06-11-18 - News This Past Week](https://iamthecavalry.org/2018/06/11/06-11-18-news-this-past-week/) - Tens of Vulnerabilities Found in Quest Appliances Researchers at Core Security say they have discovered a total of more than 60 vulnerabilities in disk backup and system management appliances from Quest. The IT management firm has released patches, but threatened to take legal action against Core if it disclosed too many details https://www.securityweek.com/tens-vulnerabilities-found-quest-appliances Interconnectivity Has - [05-21-18 - News This Past Week](https://iamthecavalry.org/2018/06/04/05-21-18-news-this-past-week/) - Siemens Patches DoS Flaws in Medium Voltage Converters According to advisories published by ICS-CERT and Siemens, the flaws impact SINAMICS GH150, GL150, GM150, SL150, SM120 and SM150 converters, which are used worldwide in the energy, chemical, critical manufacturing, water and wastewater, and food and agriculture sectors https://www.securityweek.com/siemens-patches-dos-flaws-medium-voltage-converters Many Vulnerabilities Found in OPC UA Industrial Protocol - [05-07-18 - News This Past Week](https://iamthecavalry.org/2018/05/07/05-07-18-news-this-past-week/) - KRACK VULNERABILITY PUTS MEDICAL DEVICES AT RISK A slew of devices from medical technology company Becton, Dickinson and Company (BD) are vulnerable to the infamous KRACK key-reinstallation attack, potentially enabling hackers to change and exfiltrate patient records. https://threatpost.com/krack-vulnerability-puts-medical-devices-at-risk/131552/ Schneider Electric Development Tools Affected by Critical Flaw Security firm Tenable has disclosed the details of a - [04-30-18 - News This Past Week](https://iamthecavalry.org/2018/04/30/04-30-18-news-this-past-week/) - Hackers Behind Healthcare Espionage Infect X-Ray and MRI Machines Security researchers have uncovered a new hacking group that is aggressively targeting healthcare organizations and related sectors across the globe to conduct corporate espionage https://thehackernews.com/2018/04/healthcare-cyber-attacks.html Cybersecurity task force addresses medical device safety In an effort to harmonize the work being done in hospitals and by device - [04-23-18 - News This Past Week](https://iamthecavalry.org/2018/04/23/04-23-18-news-this-past-week/) - FDA plans to improve medical device cybersecurity Fixing vulnerabilities in a timely manner and propagating the fixes to the customers and users is also important, and to that end the FDA aims to push firms to adopt policies and procedures for coordinated disclosure of vulnerabilities https://www.helpnetsecurity.com/2018/04/23/fda-medical-device-cybersecurity/ Energy security pros worry about catastrophic failure due to - [04-16-18 - News This Past Week](https://iamthecavalry.org/2018/04/16/04-16-18-news-this-past-week/) - The way we regulate self-driving cars is broken—here’s how to fix it The key issue is this: the current system is built around an assumption that cars will be purchased and owned by customers. But the pioneers of the driverless world—including Waymo, Cruise, and Uber—are not planning to sell cars to the public. Instead, they're - [04-09-18 - News This Past Week](https://iamthecavalry.org/2018/04/09/04-09-18-news-this-past-week/) - Businesses Fear 'Catastrophic Consequences' of Unsecured IoT Businesses' concern about risk from the Internet of Things (IoT) is evolving faster than their security practices, according to a new survey about the danger of third-party devices. Risk management is still relatively immature, and it's posing a threat to sensitive and confidential data, researchers report https://www.darkreading.com/iot/businesses-fear-catastrophic-consequences-of-unsecured-iot-/d/d-id/1331476 Critical - [04-02-18 - News This Past Week](https://iamthecavalry.org/2018/04/02/04-02-18-news-this-past-week/) - Third-party IoT risk management not a priority With the proliferation of IoT devices used in organizations to support business, technology and operations innovation, respondents to an Ponemon Institute study were asked to evaluate their perception of IoT risks, the state of current third party risk management programs, and governance practices being employed to defend against - [03-26-18 - News These Past Two Weeks](https://iamthecavalry.org/2018/03/26/03-26-18-news-these-past-two-weeks/) - Threat Landscape for Industrial Automation Systems in H2 2017 For many years, Kaspersky Lab experts have been uncovering and researching cyberthreats that target a variety of information systems – those of commercial and government organizations, banks, telecoms operators, industrial enterprises, and individual users. https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h2-2017/85053/ Penn State secures building automation, IoT traffic with microsegmentation Penn State - [03-13-18 - News This Past Week](https://iamthecavalry.org/2018/03/12/03-13-18-news-this-past-week/) - Infrastructure security: Don’t just sit there, do something! Confused by conflicting indications from the control panel, operators made a series of bad decisions which exacerbated the problems. The reactor core, starved of vital coolant, started to overheat. Radioactive material began to vent into the outer protective enclosure. https://www.helpnetsecurity.com/2018/03/09/infrastructure-security/ Smart traffic lights cause jams when fed - [03-05-18 - News This Past Week](https://iamthecavalry.org/2018/03/05/03-05-18-news-this-past-week/) - Delta Patches Vulnerabilities in HMI, PLC Products A researcher who uses the online moniker “Axt” informed Delta via Trend Micro’s Zero Day Initiative (ZDI) and ICS-CERT that its WPLSoft product, a programming software for programmable logic controllers (PLCs), is affected by several types of vulnerabilities. https://www.securityweek.com/delta-patches-vulnerabilities-hmi-plc-products Keeping on top of ICS-focused hacking groups, defenses “While - [02-26-18 - News This Past Week](https://iamthecavalry.org/2018/02/26/02-26-18-news-this-past-week/) - Anatomy of an Attack on the Industrial IoT We like to think that cyberattacks are focused primarily on stealing credit card numbers and that attackers don't know much about the control systems that run critical infrastructure. Unfortunately, that's just wishful thinking. In 2017, we saw an increasing number of threat actors bypass existing network perimeter - [02-19-18 - News This Past Week](https://iamthecavalry.org/2018/02/19/02-19-18-news-this-past-week/) - Siemens Leads Launch of Global Cybersecurity Initiative The so-called Charter of Trust centers around the basic goals of protecting the data of individuals and businesses; preventing harm to critical infrastructure, businesses, and individuals via cyberattacks https://www.darkreading.com/threat-intelligence/siemens-leads-launch-of-global-cybersecurity-initiative/d/d-id/1331083 US sets up dedicated office for energy infrastructure cybersecurity The US government is setting up a new Office of - [02-12-18 - News This Past Week](https://iamthecavalry.org/2018/02/12/02-12-18-news-this-past-week/) - Ukraine Power Distro Plans $20 Million Cyber Defense System After NotPetya and severe blackouts, Ukrenergo responds with an investment in cybersecurity https://www.darkreading.com/operations/ukraine-power-distro-plans-$20-million-cyber-defense-system/d/d-id/1330994 When crypto-mining malware hits a SCADA network Stealthy crypto-mining is on track to surpass ransomware as cybercriminals’ most favorite money-making option, and companies with computers and servers that run all day and night - [02-06-18 - News This Past Month](https://iamthecavalry.org/2018/02/06/02-06-18-news-this-past-month/) - Verizon Boards the NB-IoT Train Unlike consumer LTE, NB-IoT offers an efficient option for hooking up smart sensors and other machine-to-machine applications because it uses very little power for its 200 Kbit/s connections and very little spectrum, which gives devices a battery life that can be measured in years. http://www.lightreading.com/iot/nb-iot/verizon-boards-the-nb-iot-train/d/d-id/740257 DT, Nokia Put 5G to - [01-15-18 - News These Past Two Weeks](https://iamthecavalry.org/2018/01/15/01-15-18-news-these-past-two-weeks/) - Smart cars need smart and secure IT/OT Infrastructures IT can fail. It often does. We restart IT, and life goes on. Hackers can also compromise these same IT systems creating disruptions and causing theft of credentials. All manners of serious consequences result from these compromises. https://www.helpnetsecurity.com/2018/01/03/secure-it-ot-infrastructures/ Secure your SDN controller A software-defined network (SDN) can - [01-02-18 - News Since Last Year](https://iamthecavalry.org/2018/01/02/01-02-18-news-since-last-year/) - Improved IoT Security Starts with Liability for Companies, Not Just Legislation I believe that in theory, legislation could help with IoT security. However, laws regulating new technologies are often poorly crafted, and can significantly hamper innovation with little benefit. It is critical that any new laws be written with great deliberation and input from all - [Hackers on the Hill - Shmoocon 2018](https://iamthecavalry.org/2017/12/15/hackers-on-the-hill-shmoocon-2018/) - We're doing a thing. We got a Congressional staffer to take a bunch of hackers on a tour of the U.S. Capital building before Shmoocon 2018. Kicks off at 8:30am on Friday, January 19, 2018. The group is size limited, so we're doing pre-reg...no F5 required this time. Join us. You know you want to. - [12-18-17 - News This Past Week](https://iamthecavalry.org/2017/12/18/12-18-17-news-this-past-week/) - Our smart future and the threat of cyber-kinetic attacks Cyber attacks occur daily around the world. Only when one achieves sufficient scope to grab the attention of the news media – such as the WannaCry ransomware attacks of early 2017 – does the public get a brief glimpse of how widespread vulnerabilities are. Those of - [12-11-17 - News This Past Week](https://iamthecavalry.org/2017/12/11/12-11-17-news-this-past-week/) - Top-selling handgun safe can be remotely opened in seconds—no PIN needed The Vaultek VT20i handgun safe, ranked fourth in Amazon's gun safes and cabinets category, allows owners to electronically open the door using a Bluetooth-enabled smartphone app. The remote unlock feature is supposed to work only when someone knows the four- to eight-digit personal identification - [12-04-17 - News This Past Week](https://iamthecavalry.org/2017/12/04/12-04-17-news-this-past-week/) - Hacked IV Pumps and Digital Smart Pens Can Lead to Data Breaches An attack on a single IV infusion pump or digital smart pen can be leveraged to a widespread breach that exposes patient records, according to a Spirent SecurityLabs researcher. https://www.darkreading.com/mobile/hacked-iv-pumps-and-digital-smart-pens-can-lead-to-data-breaches/d/d-id/1330536 Industrial Cybersecurity Startup SCADAfence Secures $10 Million The Tel Aviv-based company explains that - [11-13-17 - News These Past Two Weeks](https://iamthecavalry.org/2017/11/28/11-13-17-news-these-past-two-weeks/) - Curing The Security Sickness in Medical Devices Just as the rapid development of the Internet of Things (IoT) has transformed traditional industries and service sectors, it is also having a great impact in the world of healthcare. It’s easy to argue, in fact, that no area is being transformed by digital technologies as rapidly or - [11-13-17 - News This Past Week](https://iamthecavalry.org/2017/11/13/11-13-17-news-this-past-week/) - Schneider Electric Patches Critical Flaw in HMI Products InduSoft Web Studio allows organizations to develop human-machine interfaces (HMIs), supervisory control and data acquisition (SCADA) systems and embedded instrumentation solutions. The Wonderware InTouch product, which is used in over one-third of the world’s industrial facilities, is an HMI visualization software. The products are used in various - [US Government ❤ Coordinated Disclosure](https://iamthecavalry.org/usgdisclosure) - Thanks to a great friend and graphic designer, @NguyetV, we have an infographic of the US Federal Government's work around coordinated disclosure over the last two years. UPDATE: Since publication, the FDA released their final postmarket guidance on December 28. UPDATE 2017.06.07: In May, a Senate bill was introduced for a government-wide bug bounty, and in June the House - [11-06-17 - News This Past Week](https://iamthecavalry.org/2017/11/06/11-06-17-news-this-past-week/) - Russia-Linked Hackers Target Turkish Critical Infrastructure Called Energetic Bear, but also known as Dragonfly and Crouching Yeti, the group has been active since at least 2010. First detailed in 2014, the threat group has been focused mainly on the energy sector in the United States and Europe. http://www.securityweek.com/russia-linked-hackers-target-turkish-critical-infrastructure SIEMENS UPDATE PATCHES SIMATIC PCS 7 BUG - [10-30-17 - News This Week](https://iamthecavalry.org/2017/10/30/10-30-17-news-this-week/) - Industrial Products Also Vulnerable to KRACK Wi-Fi Attack In the case of Cisco, many of the company’s products are affected, including Cisco 829 Industrial Integrated Services routers and Industrial Wireless 3700 series access points. The networking giant has yet to release patches for the vulnerable industrial products. However, workarounds are available for six of the - [10-23-17 - News This Past Week](https://iamthecavalry.org/2017/10/23/10-23-17-news-this-past-week/) - Energy Regulator Acts to Improve Power Grid Security With growing concern over nation-state cyber attacks comes an increasing need to secure the critical infrastructure. In the Quadrennial Energy Review published in January 2017, the U.S. Energy Department wrote, “Cyber threats to the electricity system are increasing in sophistication, magnitude, and frequency.” The reliability of the - [10-16-17 - News This Past Week](https://iamthecavalry.org/2017/10/16/10-16-17-news-this-past-week/) - How smart cities can protect against IoT security threats As long as developers work in tandem with one another, the security problems presented by the development of IoT within smart cities won’t be insurmountable https://www.networkworld.com/article/3231988/internet-of-things/how-smart-cities-can-protect-against-iot-security-threats.html North Korean Threat Actors Probe US Electric Companies Known threat actors based in North Korea recently targeted several US electric - [10-02-17 - News This Past Week](https://iamthecavalry.org/2017/10/02/10-02-17-news-this-past-week/) - Serious Flaw Exposes Siemens Industrial Switches to Attacks The flaw, discovered by Siemens itself and tracked as CVE-2017-12736, affects SCALANCE X industrial ethernet switches, and Ruggedcom switches and serial-to-ethernet devices running the Rugged Operating System (ROS). http://www.securityweek.com/serious-flaw-exposes-siemens-industrial-switches-attacks SIEMENS PATCHES IMPROPER ACCESS VULNERABILITY IN RUGGEDCOM PROTOCOL Industrial manufacturer Siemens is encouraging users running devices that use - [9-25-17 News This Past Week (or two)](https://iamthecavalry.org/2017/09/25/9-25-17-news-this-past-week-or-two/) - Share this: Share on Facebook (Opens in new window) Facebook Share on X (Opens in new window) X - [9-11-17 - News This Past Week](https://iamthecavalry.org/2017/09/11/9-11-17-news-this-past-week/) - Hackers Can Remotely Access Syringe Infusion Pumps to Deliver Fatal Overdoses Now, it turns out that a syringe infusion pump used in acute care settings could be remotely accessed and manipulated by hackers to impact the intended operation of the device, ICS-CERT warned in an advisory issued on Thursday. https://thehackernews.com/2017/09/hacking-infusion-pumps.html Syringe infusion pumps can - [News This Past Week](https://iamthecavalry.org/2017/09/05/news-this-past-week-3/) - Siemens Patches Flaws in Automation, Power Distribution Products Siemens customers were informed last week that some of the company’s automation and power distribution products are affected by vulnerabilities that can be exploited for denial-of-service (DoS) attacks and session hijacking http://www.securityweek.com/siemens-patches-flaws-automation-power-distribution-products 30 ways to improve IoT privacy To improve IoT security and privacy, we need to - [News This Past Week](https://iamthecavalry.org/2017/08/28/news-this-past-week-2/) - Cisco IOS Flaws Expose Rockwell Industrial Switches to Remote Attacks The Allen-Bradley Stratix and ArmorStratix switches, which ICS-CERT says are used worldwide in the critical manufacturing, energy and water sectors, rely on Cisco’s IOS software for secure integration with enterprise networks. That means Cisco IOS flaws can also affect Rockwell Automation products http://www.securityweek.com/cisco-ios-flaws-expose-rockwell-industrial-switches-remote-attacks IoT Thermostat - [08-13-17 - News This Past Week](https://iamthecavalry.org/2017/08/13/08-13-17-news-this-past-week/) - UK publishes Laws of Robotics for self-driving cars The United Kingdom has published a set of “Key principles of vehicle cyber security for connected and automated vehicles” outlining how auto-makers need to behave if they want computerised cars to hit Blighty's byways and highways https://www.theregister.co.uk/2017/08/07/uk_key_principles_of_vehicle_cyber_security_for_connected_and_automated_vehicles/ NotBeingPetya: UK critical infrastructure firms face huge fines for lax - [News This Past Week](https://iamthecavalry.org/2017/08/07/news-this-past-week/) - Researchers Find a Malicious Way to Meddle with Autonomous Cars While automakers focus on defending the systems in their cars against hackers, there may be other ways for the malicious to mess with self-driving cars. Security researchers at the University of Washington have shown they can get computer vision systems to misidentify road signs using - [07-31-17 - News This Past Week](https://iamthecavalry.org/2017/07/31/07-31-17-news-this-past-week/) - Testing the security of connected cars and IOT devices Finding issues in your products and services upfront is a far better investment than the expense of letting cybercriminals find and exploit vulnerabilities. Our own investments in people, tools and expertise have more than tripled our security testing capabilities in the first year of IBM X-Force - [Medical Device (Virtual) Village at DEF CON](https://iamthecavalry.org/2017/07/19/medical-device-virtual-village-at-def-con/) - There will be a Medical Device (Virtual) Village this year at DEF CON, organized in conjunction with I Am The Cavalry, the BioHacking Village, and the IoT Village (located in IoT Village) from July 28-30th at Caesars Palace in Las Vegas, Nevada. We seek to establish a high-trust, high-collaboration environment where security researchers, medical device - [News This Past Week 2017-07-09](https://iamthecavalry.org/2017/07/11/news-this-past-week-2017-07-09/) - Russian hackers target the US nuclear industry The New York Times and Bloomberg both claim that Russian hackers have been attempting to infiltrate America's nuclear power industry. The infiltrations themselves have been public knowledge since last week, but now fingers are being pointed towards the usual suspects. https://www.engadget.com/2017/07/07/russian-hackers-target-the-us-nuclear-industry/ Unpatched Flaws in Schneider Electric U.motion Builder - [6 Differences in Internet of Things and Cyber Safety](https://iamthecavalry.org/iotdifferences) - We've been using a framework for a couple of years to explain how the Internet of Things and Cyber Safety are different from Enterprise IT and most other high tech products we're familiar with. It's proven useful to frame discussions, particularly with a non-technical audience, and builds a base of agreement for more substantive conversations. Most of our (debatably) - [IATC at ISSA Summit](https://iamthecavalry.org/2017/05/24/iatc-at-issa-summit/) - On Friday, May 19, I attended the ISSA Summit 9 in Los Angeles to run the I Am The Cavalry booth. I Am The Cavalry was an honorary sponsor of the event and I thoroughly enjoyed the experience. From the keynotes about the current state of cyber security and life lessons learned from IT, to - [Hack In The Box AMS 2017](https://iamthecavalry.org/2016/10/15/hack-in-the-box-ams-2017/) - We're happy to announce a partnership with Hack in the Box Security Conferences! At Hack In The Box Amsterdam (HITB2017AMS), April 10-14, 2017, 50% of the Commsec track will be dedicated to talks that fall within the IATC domains and we will be part of the CFP selection committee for these talks. The HITB Commsec - [Interesting Talks at Hacker Summer Camp, 2016](https://iamthecavalry.org/2016/07/25/interesting-talks-at-hacker-summer-camp-2016/) - Hacker Summer Camp 2016 is almost upon us! There are a lot of really interesting talks this year, not to mention the I Am The Cavalry track at BSides Las Vegas. Since we can't hit all of the talks, we've narrowed down some that look like they're highly related to our mission. We might see - [BSides Las Vegas I Am The Cavalry track 2016](https://iamthecavalry.org/2016/07/22/bsides-las-vegas-i-am-the-cavalry-track-2016/) - I Am The Cavalry will have TWO DAYS at BSides Las Vegas this year: August 2-3. We’ll be in the Copa Lounge [1] - which I guess technically means we’re the opening act for the Rat Pack impersonators those nights! (Sorry, no karaoke.) It’s a bigger room than last year so more can attend. Let’s try to - [Comments on the FDA Postmarket Draft Guidance](https://iamthecavalry.org/2016/04/28/comments-on-the-fda-postmarket-draft-guidance/) - On January 15, 2016, The U.S. Food and Drug Administration released Draft Guidance on Postmarket Management of Cybersecurity in Medical Devices. This guidance details and clarifies the FDA's expectations for managing security vulnerabilities in medical devices currently on the market. It also introduces a new incentive to manufacturers to follow one particular path to vulnerability management that the FDA favors. - [Meet Up at Hack In The Box Amsterdam](https://iamthecavalry.org/2016/04/01/meet-up-at-hack-in-the-box-amsterdam/) - I am the Cavalry meet-up at Hack In The Box Amsterdam 2016 (HITBAMS) There will be a meet-up for people involved in or interested in I am the Cavalry at the Hack in the box conference, which is going on from May 23 to May 27th. The meetup will be after the Women in Cyber - ["I AM THE CAVALRY" PROPOSES HIPPOCRATIC OATH FOR CONNECTED MEDICAL DEVICES](https://iamthecavalry.org/2016/01/19/i-am-the-cavalry-proposes-hippocratic-oath-for-connected-medical-devices/) - “I AM THE CAVALRY” PROPOSES HIPPOCRATIC OATH FOR CONNECTED MEDICAL DEVICES (PDF) Security Research Movement Identifies Principles to Preserve Patient Safety and Build Trust in the Healthcare System. Washington, DC, – January 19th, 2016 – I Am The Cavalry, a cybersecurity volunteer association focused on public safety concerns, today issues an open letter to - [Automotive Cyber Security Summit | Detroit | March 21-23, 2016](https://iamthecavalry.org/2016/01/08/automotive-cyber-security-summit-detroit-march-21-23-2016/) - Last year, I Am The Cavalry was invited to participate in the 2nd Annual Automotive Cyber Security Summit. Josh Corman and Craig Smith walked through our Five Star Cyber Safety Framework members of the Auto industry, and joined several panel discussions. It was a great environment, friendly to security research and researchers. It was our - [I Am The Cavalry at Derbycon 2015](https://iamthecavalry.org/2015/09/11/i-am-the-cavalry-at-derbycon-2015/) - The Cavalry rides again to Derbycon - a meeting of the horsemen, if you will! The organizers have again seen fit to offer us space for the weekend so we can congregate. Two years ago we held the first Hacker Constitutional Congress at Derbycon which helped solidify the vision, mission, and areas of focus. This - [Hardware.io, BruCON, and Virus Bulletin 2015](https://iamthecavalry.org/2015/09/17/hardware-io-and-brucon-2015/) - If you're in Europe in late September and early October, there are a handful of conferences for you to check out. Hardwear.io is a first year conference focusing on hardware hacking. The venerable BruCON is back for it's 0x07th year running. and the Virus Bulletin Conference celebrates its 25th year! This makes for a pretty amazing - [I Am The Cavalry Track at BSides Las Vegas, 2015](https://iamthecavalry.org/2015/08/12/i-am-the-cavalry-track-at-bsides-las-vegas-2015/) - If you were in Las Vegas last week, you were no doubt there for some combination of BSides Las Vegas, Black Hat, or DEF CON. These three conferences measure the pulse of the information security community and industry. Thanks again to the great support from the BSides Las Vegas team, I Am The Cavalry had - [I Am The Cavalry at BSides Las Vegas 2015](https://iamthecavalry.org/2015/07/17/i-am-the-cavalry-at-bsides-las-vegas-2015/) - It's time to take the wraps off what a few of us have been planning for BSides Las Vegas. We are returning again to do an I Am The Cavalry track on Tuesday, August 4th. This year it'll be a different room, a different format, and a different objective. Like last year, you'll be able - [Related Talks at BSidesSF and RSA 2015](https://iamthecavalry.org/2015/04/06/related-talks-at-bsidessf-and-rsa-2015/) - The Silicon Valley convergence of hackers, researchers, consultants, vendors, press and others is nearly upon us. The annual BSidesSF and RSA Conference have returned to the Bay Area, hosted again in San Francisco. These events see some of the most original content presented to some of the largest crowds of the year. Much of the content will - [Assessment of BMW Door Lock Security Updates](https://iamthecavalry.org/2015/02/12/assessment-of-bmw-door-lock-security-updates/) - There has been positive news in automotive cyber safety lately. BMW announced that they have fixed a flaw in over 2.2 million of their cars, silently and remotely. The flaw allowed someone other than the driver to remotely unlock the car, through the ConnectedDrive system. BMW pushed out an update over the mobile data network - [DEF CON 22 Videos](https://iamthecavalry.org/2015/01/08/def-con-22-videos/) - DEF CON fans and aficionados-- the wait is over. The videos from DEF CON 22 are now available online. While this is not a complete list of all available videos, it showcases many of the ones of interest to the Cavalry and Cavalry followers. If you are looking for the latest that internet security researchers - [Monthly Update: October/November 2014](https://iamthecavalry.org/2014/11/24/monthly-update-octobernovember-2014/) - Good news: The last several weeks have been a hurricane of engagement and progress - especially surrounding our initiatives with Connected Vehicle safety/security. Bad news: The travel and supporting work delayed our "monthly" update a bit. Back to Good News: That means we have even more to report below... (as this is but - [Car Hacking Research on OBD II Adapters](https://iamthecavalry.org/2014/10/28/car-hacking-research-on-obd-ii-adapters/) - A lively thread started today by Wayne Yan on our discussion group. He posted the results of his team's research into the security of OBD II adapters. You can go to the thread and engage in the discussion, as well as grab the research paper. More videos and information are available from Visual Threat. The OBD II port - [Workshop on Medical Device Cyber Safety](https://iamthecavalry.org/2014/10/21/workshop-on-medical-device-cyber-safety/) - The FDA, among other agencies, is hosting an event called Collaborative Approaches for Medical Device and Healthcare Cybersecurity. It's a first step toward bringing together cybersecurity researchers, medical device manufacturers, healthcare providers, and others to get on the same page in addressing medical device cybersecurity. 220 people showed up in person - capacity of the event - [Heartbleed, Shellshock, and Erosion of Third-Party Trust](https://iamthecavalry.org/2014/10/16/heartbleed-shellshock-and-erosion-of-third-party-trust/) - Heartbleed, Shellshock, and Erosion of Third-Party Trust TL;DR Today’s software inherently depends on unreliable computer code. Devices that have the ability to impact public safety and human life should have a trust model based on assurance, not assumption. Our failure to manage the software supply chain undermines our ability to predict and manage effects of root - [DerbyCon Talks](https://iamthecavalry.org/2014/10/02/derbycon-talks/) - I was fortunate enough to attend the 4th annual DerbyCon which took place in Louisville, KY. It was exciting to see in person, a talk given by Space Rogue and Beau Woods which focused on IATC. They did an excellent job reviewing the first year and setting the tone for the upcoming year. https://www.youtube.com/watch?v=ZmWWFiy52k0 Another - [Monthly Update: September 2014](https://iamthecavalry.org/2014/09/22/monthly-update-september-2014/) - Welcome to the September edition of an I Am the Cavalry Monthly Update Newsletter! This monthly update is dedicated to publishing regular information regarding IATC accomplishments, upcoming activities and our targeted long range plans. This newsletter will inform our colleagues and teammates of the ongoing progress we are making in the public and private sectors - [Connected Device Security Blog](https://iamthecavalry.org/2014/08/29/connected-device-security-blog/) - Some friends have started publishing content on a new blog called Connected Device Security. They've got three articles up and are working on more. Head over there and check out what they have to say. A Framework for Aviation Security by Huw Fulcher How to Build Cars Securely From the Ground Up (1 of 2) by Kimkinyona - [Circle City Keynote Text](https://iamthecavalry.org/2014/08/28/circle-city-keynote-text/) - In the spirit of Dan Geer's keynote addresses I wrote out the Keynote I did for Circle City Con in Indianapolis this year. With lots of copyediting help from @bouncinglime here it is, cleaned up and made much more readable. Circle City Con Keynote Friday, June 13, 2014 The witches of infosec I was talking - [IATC Press Mentions: Post-Vegas Edition](https://iamthecavalry.org/2014/08/13/iatc-press-mentions-post-vegas-edition/) - We've had a flood of press over the past few days. So much that one blog post can't contain it all! Building on our previous post, here are the latest articles about I Am The Cavalry, our open letter to the automotive industry, and our petition to encourage carmakers and security researchers to collaborate. Mainstream Media - [“I AM THE CAVALRY” CALLS FOR COLLABORATION WITH AUTOMOTIVE INDUSTRY TO IMPROVE PUBLIC SAFETY](https://iamthecavalry.org/2014/08/08/i-am-the-cavalry-calls-for-collaboration-with-automotive-industry-to-improve-public-safety/) - “I AM THE CAVALRY” CALLS FOR COLLABORATION WITH AUTOMOTIVE INDUSTRY TO IMPROVE PUBLIC SAFETY Security Research Movement Issues Letter Outlining Five Star Automotive Cyber Safety Program DEF CON 22, Las Vegas, NV – August 8th – I Am The Cavalry, a cybersecurity volunteer association focused on public safety concerns, today issued a letter to leaders - [Current Activity](https://iamthecavalry.org/2014/04/16/current-activity/) - Current Activity Circle City Con in Indianapolis invited I Am The Cavalry to keynote their conference as well as facilitate a workshop. You can view the Circle City Con Keynote on Irongeek's website. The workshop video Executive Management (How to Manage Executives) and Engaging the Media API is also available. Upcoming This year's Vegas conference season - [IATC Press Mentions: Vegas Edition](https://iamthecavalry.org/2014/08/10/iatc-press-mentions-vegas-edition/) - I've been following all the great things happening in Vegas. I had to do it from afar since I didn't get to attend this year. I've heard nothing but good things about BSidesLV, Blackhat and DEF CON. Tons of a great information and better yet, a good amount of cavalry talks. The I Am The - [Related Talks at BSidesLV, Black Hat and DEF CON](https://iamthecavalry.org/2014/07/28/related-talks-at-bsideslv-black-hat-and-def-con/) - The annual Las Vegas convergence of hackers, researchers, consultants, vendors, press and others is nearly upon us. That's right it's time again for BSidesLV, Black Hat USA and DEF CON. This trilogy of events sees some of the most original content presented to some of the largest crowds of the year. This year much of that content will - [The Cavalry at BSides Las Vegas 2014](https://iamthecavalry.org/2014/07/24/the-cavalry-at-bsides-las-vegas-2014/) - On Wednesday August 6th, BSidesLV and I Am The Cavalry will hold a day of sessions to empower security researchers to make positive change. The goal is to define the problem space, inspire people to take a leadership role in solving security problems and build up the skills needed to succeed. The schedule and locations - [U.S Carmakers Form Alliance for Security Issues](https://iamthecavalry.org/2014/07/20/u-s-carmakers-form-alliance-for-security-issues/) - Delphi, Battelle, the Alliance of Automobile Manufacturers and the Association of Global Automakers, have formed a coalition to study cybersecurity issues. This is a great step forward. I hope to see this alliance involve the information security community. Battelle had just wrapped up their 3rd annual CyberAuto Challenge. [Full Article] - [Position on Disclosure](https://iamthecavalry.org/2014/07/01/position-on-disclosure/) - Over the last couple of weeks we have been working on documenting a position on disclosure. The position explains why research, disclosure and coordination are part of a healthy manufacturing ecosystem. It provides guidance to researchers, manufacturers and other stakeholders on their roles - at a high level - as well as other resources that can - [The Cavalry In Europe](https://iamthecavalry.org/2014/06/09/the-cavalry-in-europe/) - The Cavalry made our first appearance at a European conference. Josh Corman was invited to The Hague as the closing keynote for the National Cyber Security Center’s One Conference. In his keynote he chose to revisit the theme of his TEDx talk, which highlights issues that The Cavalry is addressing. Claus Houmann, a strong supporter of - [IATC News Roundup (5/31): Car Hacking ](https://iamthecavalry.org/2014/05/31/iatc-news-roundup-531-car-hacking/) - Battelle to Host Automobile Cyber Hackathon Battelle is hosting their third annual CyberAuto Challenge. The challenge will be held July 13-18th in Troy, MI at Delphi Automotive. According to the Battelle the CyberAuto Challenge Press release “students will be divided into teams with an equal ratio of working professionals from a variety of organizations, including - [Down The Rabbithole Cavalry-esque Discussion](https://iamthecavalry.org/2014/05/27/down-the-rabbithole-cavalry-esque-discussion/) - For those of you who don't already listen to it, the Down The Rabbithole (DtR) podcast is a long-running podcast hosted by Raf Los (aka. Wh1t3 Rabbit) and James Jardine. Over the holiday weekend I was catching up on the podcast and ran across a great Cavalry-esque episode I thought I'd draw your attention to. - [IATC at ISSA Los Angeles, May 16th, 2014](https://iamthecavalry.org/2014/05/14/iatc-at-issa-los-angeles-may-16th-2014/) - I Am The Cavalry is proud to be an organizational sponsor of ISSA Los Angeles (Event Flyer). The conference will be on May 16th, 2014, from 7:30 am to 6:00pm, at the University City Hilton in Los Angeles. Keynotes include Richard Clarke and Marcus Ranum, and featured speakers include Jackie Lacey (LA County District Attorney), Marc - [Monthly Update: April](https://iamthecavalry.org/2014/05/01/monthly-update-april/) - We had a full track of Cavalry-esque presentations at SOURCE Boston, and all of the keynotes ended up having some overlap. Our workshops at THOTCON and BSides Chicago were great! Thanks to all those who presented and those who participated. Craig Smith of Open Garages did a great introduction to Car Hacking and a hands on demo. Scott Erven - [Heartburn from Heartbleed](https://iamthecavalry.org/2014/04/24/heartburn-from-heartbleed/) - An article by C|NET on the shocking security issue, Heartbleed, mentions IATC and BuildItSecure.ly. It goes into the broader impacts of Internet of Things and critical Internet infrastructure. Heartburn from Heartbleed forces wide-ranging rethink in open source world Corman said, "shared dependence means shared attack surface." - [THOTCON & BSides Chicago 2014](https://iamthecavalry.org/2014/04/20/thotcon-bsides-chicago-2014/) - The Cavalry will be holding workshop sessions at both THOTCON and BSides Chicago next week. Details are below. We look forward to seeing you there. THOTCON – Friday, April 25, 2014 Where/When: Lab 5/6, 2pm to 4pm Approx. Capacity: 150 people [table]When,What,Who 2:00-2:30,WHY The Cavalry,Josh Corman & Nick Percoco 2:30-3:00,Medical Device Security Landscape & Challenges,Scott - [BBC Future Story, Featuring The Cavalry](https://iamthecavalry.org/2014/04/21/bbc-future-story-featuring-the-cavalry/) - Last week BBC Future published a piece called Internet of Things: The ‘ghosts’ that haunt the machine. The article discusses the potential long-term network congestion that could come about from noisy IoT devices. The Cavalry gets a mention and a quote, in the context of the potential for takeover of the devices, either by targeting the - [Monthly Update: March](https://iamthecavalry.org/2014/04/16/monthly-update-march/) - Jen Ellis and Trey Ford from Rapid 7, and Josh Corman from Sonatype, have been out on Capital Hill, speaking with Congressional staffers, lobbyists and lawyers. Jen and Trey have been providing a voice of technical literacy, helping to inoculate against bad legislation. Josh has been speaking to them about the bigger issues of computerizing and connecting all the devices. The Cavalry has been on our own March Madness - [Talk: BSides Las Vegas 2013](https://iamthecavalry.org/2013/08/02/bsideslv-2013/) - This is the talk that announced The Cavalry. Josh Corman and Nick Percoco delivered this at BSides Las Vegas, in 2013. The formative elements are here, though our message has evolved. - [Video: Does calling yourself a "hacker" make you a criminal?](https://iamthecavalry.org/2013/10/27/does-calling-yourself-a-hacker-make-you-a-criminal/) - Beau Woods and Shawn Tuma put together a short primer on a recent case that had the Internet aflutter. Does calling yourself a "hacker" forfeit your rights? Watch as Shawn Tuma breaks down the basics, takes us through the legal aspects and tells us what to care about and what's just hype. For more, see Shawn's - [Talk: Derbycon 3.0](https://iamthecavalry.org/2013/09/30/derbycon-3-0/) - Josh Corman's talk from Derbycon 3.0. This talk preceded the Hacker Constitutional Congress meetings The Cavalry held for 2 days. - [Talk: TEDx Naperville - Swimming with Sharks](https://iamthecavalry.org/2013/11/09/tedx-naperville-swimming-with-sharks/) - Josh Corman was invited to deliver a presentation at a TEDx event in Naperville, Illinois. His talk was entitled "Swimming with Sharks" and was a firsthand account of getting in the water with an apex predator. He related the experience to work he's done on Anonymous and brought the focus on The Cavalry by convincing - [Talk: OWASP AppSec USA](https://iamthecavalry.org/2013/11/20/owasp-appsec-usa/) - At OWASP AppSec USA 2013, Josh and Nick came back to the stage to tell their story again, with an update. - [Talk: OWASP AppSec California](https://iamthecavalry.org/2014/02/27/owasp-appsec-california/) - Beau Woods presented the now-familar talk, giving it his own spin and an update. - [Video: Adam, Beau and Josh talk to Tripwire](https://iamthecavalry.org/2014/03/23/adam-beau-and-josh-talk-to-tripwire/) - David Spark talks to Adam Brand, Beau Woods and Josh Corman at BSides SF about The Cavalry, for Tripwire's State of Security. - [Activity Report: February](https://iamthecavalry.org/2014/03/29/activity-report-february/) - As the security industry recovers from BSides SF, RSA Conference and Trustycon, we here at Cavalry HQ have been pulling together everything we learned so we can be better and stronger. DuoSecurity launched their initiative, co-branded with The Cavalry and with Bug Crowd, called BuildItSecure.ly. The idea is to empower small Internet of Things manufacturers (think Kickstarter) with the information needed to secure their ## Pages - [Front Page](https://iamthecavalry.org/) - The Cavalry isn’t coming. It falls to you. I Am The Cavalry is a global, grassroots initiative to ensure trust and trustworthiness of connected technologies. - [Infrastructure](https://iamthecavalry.org/issues/public-infrastructure/) - The national and global infrastructure are being transformed by so-called “smart” technologies which allow our society to be more agile, responsive, and efficient. This interconnectedness is incredibly powerful despite the systemic risk of collapse or manipulation that it introduces. By 2023, there are expected to be more than 13.7 billion Internet of things (IoT) devices - [Known Disclosure Programs](https://iamthecavalry.org/about/disclosure/disclosure-programs/) - The number of manufacturers in cyber safety industries who have coordinated vulnerability disclosure programs is quickly growing. We encourage more engagement between manufacturers and researchers, along the lines of our Position on Disclosure. Automotive TESLA General Motors Fiat Chrysler Automobiles Toyota PTC BMW Bosch Mercedes ( Daimler) Audi Medical Devices Siemens Philips Medtronic Draeger GE Johnson - [Medical](https://iamthecavalry.org/issues/medical/) - In recent years, the healthcare industry has adopted connected technologies to more rapidly deploy next-generation medical devices and improve patient outcomes. Over half of the medical devices marketed today operate on software, including implantable units, diagnostic machines, and monitoring equipment. These technologies have amazing capabilities to save lives, diagnose quickly, and improve quality of life. - [Get Involved](https://iamthecavalry.org/get-involved/) - The Cavalry is not a spectator sport. To affect change and to improve public safety and human life the way we need to, we need you. No matter who you are, no matter where you are, your help can make the world — and the Internet of things — a safer place. Get in Touch - [Newsletter](https://iamthecavalry.org/newsletter/) - [Hippocratic Oath for Connected Medical Devices](https://iamthecavalry.org/issues/medical/oath/) - Read our Open Letter to the Healthcare Community Leaders, from the Security Research Community. Leave a public pledge to uphold the Hippocratic Oath for Connected Medical Devices in the comments. Download the PDF Hippokratischer Eid für vernetzte medizintechnische Geräte The latest medical advances lay at the intersection of patient care and connected technology. Integration of new technology - [News & Events](https://iamthecavalry.org/news-events/) - I Am The Cavalry volunteers are frequently cited in the news and are active at leading cybersecurity conferences around the world. The Cavalry also works behind the scenes running simulations and tabletop exercises, offering trainings, and participating in government task forces to inform and improve security for all. Latest News More News » Events CONFERENCE - [Events & Talks](https://iamthecavalry.org/events-talks/) - As cyber safety continues to gain importance across various domains, several groups and events are connecting and convening stakeholders to collaborate and works towards I Am The Cavalry's "Safer, sooner, together" mission. I Am The Cavalry actively participates, coordinates, and tracks many of theses groups and events. - [Connected Home](https://iamthecavalry.org/issues/connected-home/) - Smart home trends are driving more digital technology into the devices around us. Our appliances, environmental controls, security systems, and door locks are all using computing and connectivity to bring more capability and control to our fingertips. The increased use of home monitoring video cameras and smart microphones in households thanks to lower prices and - [Transportation](https://iamthecavalry.org/issues/transportation/) - Our cars are increasingly incorporating digital technologies and ubiquitous communication for both safety and convenience. Automatic parking assist, adaptive cruise control, collision avoidance, stolen vehicle shutdown, remote emergency response, and other features make driving easier and safer. Unfortunately, capabilities like these can malfunction or be abused, potentially putting drivers at risk of lost control of - [Position on Disclosure](https://iamthecavalry.org/about/disclosure/) - Those concerned with public safety and human life should take sufficient care to avoid inadvertently putting them at risk. Known Disclosure Programs Background All systems fail. There is no system without flaw. Flaws with the potential to inflict harm make products — and the people that rely on them — vulnerable to accidents and adversaries. Researchers - [Who We Are](https://iamthecavalry.org/about/who-we-are/) - We are a collection of volunteers around the world with diverse backgrounds and a range of expertise across technology, law, and public policy. The Cavalry is nothing without the contributions of those passionate about the cause. “Never doubt that a small group of thoughtful, committed citizens can change the world; indeed, it’s the only thing - [History](https://iamthecavalry.org/about/history/) - The Cavalry was born in Las Vegas in the summer of 2013 during two cybersecurity conferences, DEFCON and BSides Las Vegas. Security veterans Josh Corman and Nick Percoco began a conversation at those conferences about how merging technologies had the ability to affect human life and public safety when applied to the Internet of things, cars, medical devices, and - [About](https://iamthecavalry.org/about/) - I Am The Cavalry is a volunteer organization devoted to improving the security of four main focus areas: medical devices, transportation, connected homes, and infrastructure. We believe that our dependence on connected technology is increasing faster than our ability to safeguard ourselves. OUR AIMS ARE - To selectively improve visibility and awareness of these issues - [Five Star Automotive Safety Program](https://iamthecavalry.org/issues/automotive/5star/) - Read the Open Letter to the Automotive Industry, from the Security Research Community. Petition the Automotive Industry and Security Research Community to collaborate. Download the PDF Modern cars are computers on wheels and are increasingly connected and controlled by software. Dependence on technology in vehicles has grown faster than effective means to secure it. Security researchers - [Issue Areas](https://iamthecavalry.org/issues/) - I Am The Cavalry members work across a broad range of issues where bits and bytes meet flesh and blood. MEDICAL In recent years, the healthcare industry has adopted connected technologies to more rapidly deploy next-generation medical devices to improve patient outcomes. Over half of the medical devices marketed today operate on software — including implantable - [Hippokratischer Eid für vernetzte medizintechnische Geräte](https://iamthecavalry.org/eid) - Hippokratischer Eid für vernetzte medizintechnische Geräte (PDF) Ich werde das menschliche Leben ehren und schützen und stets zum Nutzen meiner Patienten handeln. Ich erkenne an, dass alle Systeme versagen können; das Auftreten von Defekten des Systems und widrigen Umständen kann nicht verhindert werden. Ressourcen, die das Leben verbessern oder erhalten sollen, können es auch schädigen - [Events](https://iamthecavalry.org/news/upcoming-events/) - As Cyber Safety enters the zeitgeist of various stakeholders, several groups and events are collecting stakeholders, connecting them to each other, collaborating together, to catalyze better outcomes. Safer, sooner, together. I Am The Cavalry has been participating in, coordinating with, and tracking several of these groups and events. ## Timeline Express Announcements - [Test Event #2](https://iamthecavalry.org/announcement/test-event-2/) - Hackers on the Hill. - [Test Timeline](https://iamthecavalry.org/announcement/test-timeline/) - Sample content here. ## Categories - [Uncategorized](https://iamthecavalry.org/category/uncategorized/) - [Discussion](https://iamthecavalry.org/category/discussion/) - [Publicity](https://iamthecavalry.org/category/publicity-2/) - [Posts](https://iamthecavalry.org/category/posts/) - [Talks](https://iamthecavalry.org/category/talks/) - [Activity Report](https://iamthecavalry.org/category/activity-report/) - [Press Release](https://iamthecavalry.org/category/press-release/) - [News](https://iamthecavalry.org/category/news/) - [Media Mentions](https://iamthecavalry.org/category/media-mentions/) - [Medical](https://iamthecavalry.org/category/medical/) - [Events](https://iamthecavalry.org/category/events/) - [Transportation](https://iamthecavalry.org/category/transportation/) - [Infrastructure](https://iamthecavalry.org/category/infrastructure/) - [Connected Home](https://iamthecavalry.org/category/connected-home/) ## Tags - [josh corman](https://iamthecavalry.org/tag/josh-corman/) - [tedx](https://iamthecavalry.org/tag/tedx/) - [cavalry](https://iamthecavalry.org/tag/cavalry/) - [publicity](https://iamthecavalry.org/tag/publicity/) - [featured](https://iamthecavalry.org/tag/featured/) - [talk](https://iamthecavalry.org/tag/talk/) - [bsideslv](https://iamthecavalry.org/tag/bsideslv/) - [iamthecavalry](https://iamthecavalry.org/tag/iamthecavalry/) - [owasp](https://iamthecavalry.org/tag/owasp/) - [appsec](https://iamthecavalry.org/tag/appsec/) - [appsec usa](https://iamthecavalry.org/tag/appsec-usa/) - [owasp appsec](https://iamthecavalry.org/tag/owasp-appsec/) - [owasp appsec usa](https://iamthecavalry.org/tag/owasp-appsec-usa/) - [Nicholas Percoco](https://iamthecavalry.org/tag/nicholas-percoco/) - [owasp appsec california](https://iamthecavalry.org/tag/owasp-appsec-california/) - [beau woods](https://iamthecavalry.org/tag/beau-woods/) - [shawn tuma](https://iamthecavalry.org/tag/shawn-tuma/) - [rights](https://iamthecavalry.org/tag/rights/) - [legal rights](https://iamthecavalry.org/tag/legal-rights/) - [court case](https://iamthecavalry.org/tag/court-case/) - [hacker](https://iamthecavalry.org/tag/hacker/) - [video](https://iamthecavalry.org/tag/video/) - [derbycon](https://iamthecavalry.org/tag/derbycon/) - [constitutional congress](https://iamthecavalry.org/tag/constitutional-congress/) - [tripwire](https://iamthecavalry.org/tag/tripwire/) - [david spark](https://iamthecavalry.org/tag/david-spark/) - [adam brand](https://iamthecavalry.org/tag/adam-brand/) - [bsides](https://iamthecavalry.org/tag/bsides/) - [bsides sf](https://iamthecavalry.org/tag/bsides-sf/) - [nick percoco](https://iamthecavalry.org/tag/nick-percoco/) - [thotcon](https://iamthecavalry.org/tag/thotcon/) - [bsides chicago](https://iamthecavalry.org/tag/bsides-chicago/) - [the cavalry](https://iamthecavalry.org/tag/the-cavalry/) - [i am the cavalry](https://iamthecavalry.org/tag/i-am-the-cavalry/) - [open garages](https://iamthecavalry.org/tag/open-garages/) - [craig smith](https://iamthecavalry.org/tag/craig-smith/) - [scott erven](https://iamthecavalry.org/tag/scott-erven/) - [bbc](https://iamthecavalry.org/tag/bbc/) - [bbc future](https://iamthecavalry.org/tag/bbc-future/) - [internet of things](https://iamthecavalry.org/tag/internet-of-things/) - [iot](https://iamthecavalry.org/tag/iot/) - [media](https://iamthecavalry.org/tag/media/) - [joshua corman](https://iamthecavalry.org/tag/joshua-corman/) - [cnet](https://iamthecavalry.org/tag/cnet/) - [heartbleed](https://iamthecavalry.org/tag/heartbleed/) - [builditsecure.ly](https://iamthecavalry.org/tag/builditsecure-ly/) - [iatc](https://iamthecavalry.org/tag/iatc/) - [activity report](https://iamthecavalry.org/tag/activity-report-2/) - [workshop](https://iamthecavalry.org/tag/workshop/) - [automotive](https://iamthecavalry.org/tag/automotive/) - [medical](https://iamthecavalry.org/tag/medical/) - [medical device](https://iamthecavalry.org/tag/medical-device/) - [mark stanislav](https://iamthecavalry.org/tag/mark-stanislav/) - [dan geer](https://iamthecavalry.org/tag/dan-geer/) - [paul roberts](https://iamthecavalry.org/tag/paul-roberts/) - [iot world](https://iamthecavalry.org/tag/iot-world/) - [security ledger](https://iamthecavalry.org/tag/security-ledger/) - [cso online](https://iamthecavalry.org/tag/cso-online/) - [swimming with sharks](https://iamthecavalry.org/tag/swimming-with-sharks/) - [duo security](https://iamthecavalry.org/tag/duo-security/) - [sonatype](https://iamthecavalry.org/tag/sonatype/) - [SECoT](https://iamthecavalry.org/tag/secot/) - [security of things](https://iamthecavalry.org/tag/security-of-things/) - [security of things forum](https://iamthecavalry.org/tag/security-of-things-forum/) - [channelnomics](https://iamthecavalry.org/tag/channelnomics/) - [los angeles](https://iamthecavalry.org/tag/los-angeles/) - [issa](https://iamthecavalry.org/tag/issa/) - [conference](https://iamthecavalry.org/tag/conference/) - [marcus ranum](https://iamthecavalry.org/tag/marcus-ranum/) - [jim manico](https://iamthecavalry.org/tag/jim-manico/) - [richard clarke](https://iamthecavalry.org/tag/richard-clarke/) - [jackie lacey](https://iamthecavalry.org/tag/jackie-lacey/) - [marc manfred](https://iamthecavalry.org/tag/marc-manfred/) - [raf los](https://iamthecavalry.org/tag/raf-los/) - [wh1t3rabbit](https://iamthecavalry.org/tag/wh1t3rabbit/) - [wh1t3 rabbit](https://iamthecavalry.org/tag/wh1t3-rabbit/) - [james jardine](https://iamthecavalry.org/tag/james-jardine/) - [down the rabbithole](https://iamthecavalry.org/tag/down-the-rabbithole/) - [down the rabbithole podcast](https://iamthecavalry.org/tag/down-the-rabbithole-podcast/) - [dtr](https://iamthecavalry.org/tag/dtr/) - [dtr podcast](https://iamthecavalry.org/tag/dtr-podcast/) - [windows xp](https://iamthecavalry.org/tag/windows-xp/) - [tom brewster](https://iamthecavalry.org/tag/tom-brewster/) - [Claus Houmann](https://iamthecavalry.org/tag/claus-houmann/) - [presentation](https://iamthecavalry.org/tag/presentation/) - [National Cyber Security Center](https://iamthecavalry.org/tag/national-cyber-security-center/) - [disclosure](https://iamthecavalry.org/tag/disclosure/) - [coordination](https://iamthecavalry.org/tag/coordination/) - [coordinated disclosure](https://iamthecavalry.org/tag/coordinated-disclosure/) - [vulnerability disclosure](https://iamthecavalry.org/tag/vulnerability-disclosure/) - [vulnerability research](https://iamthecavalry.org/tag/vulnerability-research/) - [security research](https://iamthecavalry.org/tag/security-research/) - [security vulnerability](https://iamthecavalry.org/tag/security-vulnerability/) - [def con](https://iamthecavalry.org/tag/def-con/) - [defcon](https://iamthecavalry.org/tag/defcon/) - [blackhat](https://iamthecavalry.org/tag/blackhat/) - [black hat](https://iamthecavalry.org/tag/black-hat/) - [las vegas](https://iamthecavalry.org/tag/las-vegas/) - [press](https://iamthecavalry.org/tag/press/) - [car](https://iamthecavalry.org/tag/car/) - [5star](https://iamthecavalry.org/tag/5star/) - [5 star](https://iamthecavalry.org/tag/5-star/) - [cyber safety](https://iamthecavalry.org/tag/cyber-safety/) - [cybersafety](https://iamthecavalry.org/tag/cybersafety/) - [circle city con](https://iamthecavalry.org/tag/circle-city-con/) - [connected device security](https://iamthecavalry.org/tag/connected-device-security/) - [shellshock](https://iamthecavalry.org/tag/shellshock/) - [software supply chain](https://iamthecavalry.org/tag/software-supply-chain/) - [fda](https://iamthecavalry.org/tag/fda/) - [car hacking](https://iamthecavalry.org/tag/car-hacking/) - [automobile](https://iamthecavalry.org/tag/automobile/) - [hacking](https://iamthecavalry.org/tag/hacking/) - [discussion group](https://iamthecavalry.org/tag/discussion-group/) - [obd ii](https://iamthecavalry.org/tag/obd-ii/) - [bmw](https://iamthecavalry.org/tag/bmw/) - [five star cyber safety framework](https://iamthecavalry.org/tag/five-star-cyber-safety-framework/) - [adac](https://iamthecavalry.org/tag/adac/) - [door lock](https://iamthecavalry.org/tag/door-lock/) - [security update](https://iamthecavalry.org/tag/security-update/) - [BSidesSF](https://iamthecavalry.org/tag/bsidessf/) - [RSA](https://iamthecavalry.org/tag/rsa/) - [Related Talks](https://iamthecavalry.org/tag/related-talks/) - [RSA Conference](https://iamthecavalry.org/tag/rsa-conference/) - [RSAC](https://iamthecavalry.org/tag/rsac/) - [bsides las vegas](https://iamthecavalry.org/tag/bsides-las-vegas/) - [vegas](https://iamthecavalry.org/tag/vegas/) - [keren elazari](https://iamthecavalry.org/tag/keren-elazari/) - [chris nickerson](https://iamthecavalry.org/tag/chris-nickerson/) - [wim remes](https://iamthecavalry.org/tag/wim-remes/) - [tim krabec](https://iamthecavalry.org/tag/tim-krabec/) - [scott ervent](https://iamthecavalry.org/tag/scott-ervent/) - [jen ellis](https://iamthecavalry.org/tag/jen-ellis/) - [steve ragan](https://iamthecavalry.org/tag/steve-ragan/) - [jay radcliffe](https://iamthecavalry.org/tag/jay-radcliffe/) - [katie mousouris](https://iamthecavalry.org/tag/katie-mousouris/) - [media training](https://iamthecavalry.org/tag/media-training/) - [medical device security research](https://iamthecavalry.org/tag/medical-device-security-research/) - [automotive security research](https://iamthecavalry.org/tag/automotive-security-research/) - [brucon](https://iamthecavalry.org/tag/brucon/) - [hardware.io](https://iamthecavalry.org/tag/hardware-io/) - [ics village](https://iamthecavalry.org/tag/ics-village/) - [medical device hacking](https://iamthecavalry.org/tag/medical-device-hacking/) - [hippocratic oath](https://iamthecavalry.org/tag/hippocratic-oath/) - [medical devices](https://iamthecavalry.org/tag/medical-devices/) - [connected medical devices](https://iamthecavalry.org/tag/connected-medical-devices/) - [press release](https://iamthecavalry.org/tag/press-release/) - [medical device maker](https://iamthecavalry.org/tag/medical-device-maker/) - [medical device manufacturer](https://iamthecavalry.org/tag/medical-device-manufacturer/) - [postmarket guidance](https://iamthecavalry.org/tag/postmarket-guidance/) - [fda postmarket guidance](https://iamthecavalry.org/tag/fda-postmarket-guidance/) - [hackinthebox](https://iamthecavalry.org/tag/hackinthebox/) - [hack in the box](https://iamthecavalry.org/tag/hack-in-the-box/) - [amsterdam](https://iamthecavalry.org/tag/amsterdam/) - [hack in the box amsterdam](https://iamthecavalry.org/tag/hack-in-the-box-amsterdam/) - [hitb](https://iamthecavalry.org/tag/hitb/) - [hitbams](https://iamthecavalry.org/tag/hitbams/) - [intel](https://iamthecavalry.org/tag/intel/) - [amt](https://iamthecavalry.org/tag/amt/) - [siemens](https://iamthecavalry.org/tag/siemens/) - [tim anater](https://iamthecavalry.org/tag/tim-anater/) - [bfbcping](https://iamthecavalry.org/tag/bfbcping/) - [expetr](https://iamthecavalry.org/tag/expetr/) - [petya](https://iamthecavalry.org/tag/petya/) - [fakecry](https://iamthecavalry.org/tag/fakecry/) - [ukraine](https://iamthecavalry.org/tag/ukraine/) - [ransomware](https://iamthecavalry.org/tag/ransomware/) - [medoc](https://iamthecavalry.org/tag/medoc/) - [breach](https://iamthecavalry.org/tag/breach/) - [schneider](https://iamthecavalry.org/tag/schneider/) - [u.motion builder](https://iamthecavalry.org/tag/u-motion-builder/) - [hackersonthehill](https://iamthecavalry.org/tag/hackersonthehill/) - [hackers on the hill](https://iamthecavalry.org/tag/hackers-on-the-hill/) - [public policy](https://iamthecavalry.org/tag/public-policy/) - [policy](https://iamthecavalry.org/tag/policy/) - [hackers](https://iamthecavalry.org/tag/hackers/) - [us capital](https://iamthecavalry.org/tag/us-capital/) - [washington dc](https://iamthecavalry.org/tag/washington-dc/) - [washington](https://iamthecavalry.org/tag/washington/) - [dc](https://iamthecavalry.org/tag/dc/) - [Hippokratischer Eid für vernetzte medizintechnische Geräte](https://iamthecavalry.org/tag/hippokratischer-eid-fur-vernetzte-medizintechnische-gerate/) - [Hippokratischer Eid](https://iamthecavalry.org/tag/hippokratischer-eid/) - [hippocratic oath for connected medical devices](https://iamthecavalry.org/tag/hippocratic-oath-for-connected-medical-devices/) - [healthcare](https://iamthecavalry.org/tag/healthcare/) - [Home Page](https://iamthecavalry.org/tag/home-page/) - [peter singer](https://iamthecavalry.org/tag/peter-singer/) - [p w singer](https://iamthecavalry.org/tag/p-w-singer/) - [august cole](https://iamthecavalry.org/tag/august-cole/) - [burn in](https://iamthecavalry.org/tag/burn-in/) - [burn-in](https://iamthecavalry.org/tag/burn-in-2/) - [burn in book](https://iamthecavalry.org/tag/burn-in-book/) - [Aerospace](https://iamthecavalry.org/tag/aerospace/) - [Space](https://iamthecavalry.org/tag/space/) - [Blog](https://iamthecavalry.org/tag/blog/) - [Tech](https://iamthecavalry.org/tag/tech/) - [Cybersecurity](https://iamthecavalry.org/tag/cybersecurity/) - [Cars](https://iamthecavalry.org/tag/cars/) - [self-driving](https://iamthecavalry.org/tag/self-driving/) - [Connected cars](https://iamthecavalry.org/tag/connected-cars/) - [states](https://iamthecavalry.org/tag/states/) - [vulnerability disclosure program](https://iamthecavalry.org/tag/vulnerability-disclosure-program/) - [Supply chain](https://iamthecavalry.org/tag/supply-chain/) - [supply chain sandbox](https://iamthecavalry.org/tag/supply-chain-sandbox/) - [medical device security](https://iamthecavalry.org/tag/medical-device-security/) - [cybersecurity awareness month](https://iamthecavalry.org/tag/cybersecurity-awareness-month/) - [World Economic Forum](https://iamthecavalry.org/tag/world-economic-forum/) - [WEF](https://iamthecavalry.org/tag/wef/) - [Capitol Hill](https://iamthecavalry.org/tag/capitol-hill/) - [U.S. Capitol](https://iamthecavalry.org/tag/u-s-capitol/) - [Security briefing](https://iamthecavalry.org/tag/security-briefing/) - [Congress](https://iamthecavalry.org/tag/congress/) - [senate testimony](https://iamthecavalry.org/tag/senate-testimony/) - [White House](https://iamthecavalry.org/tag/white-house/) - [PATCH ACT](https://iamthecavalry.org/tag/patch-act/)