top of page
Cyber Defense Through Engineering and Analytics

All Posts
Lexis1234: The Data Privacy Failures of LexisNexis, America's Largest Data Broker
LexisNexis is a data broker, not a peripheral player, but a company whose entire business model is aggregating and selling sensitive personal data on people who never consented to the relationship. In 14 months, LexisNexis had two massive breaches. It wasn’t bad luck; it is the predictable outcome of an industry that externalizes risk onto individuals while internalizing profit, operating under regulatory frameworks with no real teeth. This paper examines those breaches th
Ryan Beavers
Apr 193 min read
The CrowdStrike Falcon Update Outage — A Software Assurance Failure
I remember this day, July 19, 2024, my daughter was excited, she had been doing a summer French course, somewhat against her will — teenagers — her school's systems were down, none of the students could access their courses or files, and teachers wanted some summertime too. My daughter, her classmates, and teacher spent the day in the pleasant Portland summer, I don't know, but I'm guessing, not speaking French. The incident, which is now widely considered the largest IT outa
Ryan Beavers
Apr 194 min read
Building Confidentiality: The Role of Integrity and Availability Controls
Security architecture, and contemporary security thinking, is often, rightly so, associated with protecting confidentiality. However, many security devices are designed primarily to preserve the integrity and availability of systems and data. While confidentiality focuses on keeping information secret, integrity ensures that data remains accurate and trustworthy, and availability ensures that systems remain accessible when needed. Because confidentiality ultimately depends
Ryan Beavers
Apr 193 min read
You Hacked My Tesla: Pwn2Own, Exploit Types and Emerging Threat Patterns
Across three days of Pwn2Own Automotive, security researchers demonstrated a sobering reality: modern transportation systems are less like isolated machines and more like rolling networks of vulnerable software. The event showcased vulnerabilities across electric vehicle (EV) chargers, in-vehicle infotainment (IVI) systems, automotive operating systems, and connected infrastructure, revealing that automotive security increasingly resembles enterprise cybersecurity rather than
Ryan Beavers
Apr 193 min read
TechRetail Looks Like the Death Star
Rapid growth has produced a security posture that is localized rather than architectural. Certain assets may be hardened due to compliance or vendor defaults, but there is no coherent trust model governing interactions across systems. In Zero Trust doctrine (NIST SP 800-207), the principle is “never trust, always verify” (National Institute of Standards and Technology [NIST], 2020). If that principle is not embedded into architecture and operations, then the system’s default
Ryan Beavers
Apr 193 min read
The Front Door Was Broken: Ivanti ICS and Patching as Remediation
Beginning in 2023, Ivanti reported vulnerabilities in their Ivanti Connect Secure (ICS), which sits in front of internal networks handling VPN access, authentication, policy enforcement, and session management. Ivanti reported an “authentication bypass vulnerability in the web component,” where code in the web interface, which was supposed to check whether a user is already logged in, can be skipped (CVE 2023-46805, CVSS 8.2). ICS had a vulnerability at its front door. Lat
Ryan Beavers
Apr 194 min read
Frameworks Are Toothless — And the Attacker Already Has the Manual
I remember, early in the course, Roman said something that I haven't been able to shake, (paraphrased) “NIST is a fine framework, but adversaries don't care about frameworks.” I'd go further. I don't think they ignore frameworks. I think they read them carefully. MITRE ATT&CK is free, publicly available, and open to anyone on the planet. So is NIST CSF. So are the published mappings between them. According to Harvard, three in four companies now publicly disclose which fram
Ryan Beavers
Apr 192 min read
When Tools Work but Systems Fail: Lessons from the Capital One Breach
Prof. Duke, in Saturday’s lecture, touched on an adage: the right tool for the right job. However, breaches rarely center on the presence or absence of tools, but on whether those tools are aligned with how attacks unfold across complex systems. Something, often mentioned in Blue Team circles is defense is response, after the fact, a posteriori . In other words, defense only occurs after knowledge of the attack, what the attack did, how the attack was executed, and the atta
Ryan Beavers
Apr 194 min read
bottom of page