Elektrine lite

← Feed

@brian_greenberg@infosec.exchange

Post #2590953

2026-04-24 16:24 UTC

A Chinese national pretended to be U.S. engineers and researchers for almost five years, from 2017 to 2021, and walked away with sensitive aerospace and weapons development software from NASA, the Air Force, the Navy, and the Army. There was no hacking or breaking through firewalls. People simply emailed him what he asked for, because they believed he was someone they knew. This worries me more than any zero-day vulnerability. The NASA OIG reported that Song Wu asked for the same software several times without explaining why he needed it. Most people miss this kind of red flag because no one teaches them to spot it. We invest millions in technology controls but spend very little on training people to pause and think like a threat actor before sending information. Export controls are not only about legal compliance. They are also about human behavior. Your employees make export control decisions every day, often without realizing it. When was the last time your organization ran a spear-phishing simulation aimed at your researchers, not just your finance team? If your security awareness program doesn't cover identity deception and unusual software requests, it is not thorough enough. https://thehackernews.com/2026/04/nasa-employees-duped-in-chinese.html #Cybersecurity #NationalSecurity #Espionage #SecurityAwareness #InfoSec #security #privacy #cloud #infosec

Replies (0)

No replies.