Dr Ric Derbyshire

Cyber security researcher at Orange Cyberdefense - ICS/OT and cyber risk

Honorary researcher at Lancaster University

Motorcycle and guitar obsessive

Cat hoarder

Dr Ric Derbyshireric@infosec.exchange
2023-02-23

I recently wrote about the current landscape of OT-dedicated cyber attacks, or lack thereof, and how this may change in the near future.

You can check it out below on the Orange Cyberdefense blog!

orangecyberdefense.com/global/

#icssecurity #otsecurity #ics #ot #cybersecurity

Dr Ric Derbyshireric@infosec.exchange
2023-02-01

I'm pleased to announce our new paper has been published! This work discusses a technique, and subsequently presents a proof of concept, for scanning for vulnerabilities within PLC control logic. As I've mentioned through numerous talks and work recently, traditional enterprise focused reconnaissance, enumeration, and vulnerability scanning techniques are inadequate against OT and provide very little information on OT-specific vulnerabilities. This tool goes further than typical network scanning to understand where the control logic itself may have vulnerabilities. Read the paper here:

sciencedirect.com/science/arti

We hope this work is just the first step in tooling to improve the state of in-PLC vulnerabilities and PLC programming practices, greatly reducing the exploitability of OT moving forward.

#otcybersecurity #icscybersecurity #icssecurity #plcprogramming #cybersecurity

Dr Ric Derbyshire boosted:
2023-01-27

IT STARTS WITH ONE THING (a malware dropper)
I DONT KNOW WHY (you'd download an .mp3.exe)
IT DOESNT EVEN MATTER HOW HARD YOU TRY (your antivirus won't detect it since its UPX packed)

D:\downloads\LiNkiNgPaRk-nUmB.exe
START LiNkiNgPaRk-nUmB.exe
Dr Ric Derbyshire boosted:
Dominic Whitesinge@chaos.social
2023-01-19

@charlvdwalt @Roeloftemmingh I love digging into @sensepost history. Here's RT & Charl proposing ransomware as a throwaway to one of their first C2 papers in 1999.

web.archive.org/web/2001031919

Taking it one step further (the really nasty angle)

Now lets see...what would happen if the AI was to encrypt

* DOC *.CPP, *.C files and store the keys on the web servers (encrypted under a masterkey)? I can see it now - "buy your code& documents back at our special discount price"...

Last words& thanks

And you thought all we do in South Africa is dodge the elephants... My sincere thanks goes out to Charl for his ideas and for writing part I.
Dr Ric Derbyshireric@infosec.exchange
2023-01-09

@Anneandstuff That is a really interesting thought, and something that is entirely avoidable using accepted platforms such as arxiv.org

The major issue that arises is work that hasn't at least gone through some type of formal peer review hasn't been verified as correct. That issue is somewhat mitigated when well informed subject matter experts use such work as a resource as they can critically analyse it themselves. However, non-specialists using that work will have a much more challenging time to validate it.

Neither are perfect and both have their place.

Dr Ric Derbyshireric@infosec.exchange
2022-12-17

@K1L0G4U55 Thank you!

Dr Ric Derbyshireric@infosec.exchange
2022-12-17

Finishing a PhD is a blurry situation with lots of stages - completing your thesis, submitting it, passing your viva, final corrections, and getting the certificate.

But this finally feels like closure. What an adventure!

Dork wearing UK traditional PhD graduation gown and hatBrochure for Lancaster University winter graduation ceremonies and name card stating Richard Derbyshire, PhD, and a thesis title "Anticipating Adversary Cost: Bridging the Threat-Vulnerability Gap in Cyber Risk Assessment"
Dr Ric Derbyshireric@infosec.exchange
2022-12-06

@Dcuthbert @reg This is the talk prep none of the pros tell you about hahaha!

Dr Ric Derbyshireric@infosec.exchange
2022-12-06

@reg @Dcuthbert I always thought weeing your pants would be worst case but tactical pants weeing to distract from the talk is absolutely genius!

Dr Ric Derbyshire boosted:

Last week we ran our radio hacking session utilising our new SDR equipment! Now we are prepping for hardware hacking this Friday!

A photo of the LUHack session
Dr Ric Derbyshire boosted:
2022-12-03

I've been using this #tool for years, but I think more people should know about it.

It makes it easy to find a #LaTeX symbol in a few seconds!

#TeXLaTeX

🔗 detexify.kirelabs.org

Dr Ric Derbyshire boosted:
2022-11-29

MIT researchers need to knock it the fuck off

Dr Ric Derbyshire boosted:
Glenn Pegden :donor:glennpegden@infosec.exchange
2022-11-29

After almost six years years doing some kick-ass Vulnerability Management work, it's time to spread both the knowledge and the workload, so come and work with and learn from, me!

Listed as Leeds (UK), but remote in UK, Ireland, Portugal or Romania could all work.

careers.flutteruki.com/jobs/r0

Boost are very welcome!

Dr Ric Derbyshire boosted:
Dominic Whitesinge@chaos.social
2022-11-24

NCC did so much great research under Jennifer’s watch. What an epic goodbye post. research.nccgroup.com/2022/11/

Dr Ric Derbyshire boosted:
Alasdair Allanaallan
2022-11-21

You can watch approach and round the live on NASA TV at youtube.com/watch?v=21X5lGlDOfg. Closest approach will be at 12:57 GMT (07:57 EST).

Dr Ric Derbyshire boosted:
Ali Abbasi :verified:AliAbbasi@infosec.exchange
2022-11-20

I am offering multiple Ph.D. positions for candidates interested in the area of embedded systems security. The positions are open for both hardware security (e.g., side-channel, fault injection) and software security (firmware sec) topics. Details available here: jobs.cispa.saarland/jobs/detai

Dr Ric Derbyshire boosted:
Charlotte :verified:lottiekins@infosec.exchange
2022-11-20

I think I just might have found the perfect tree 🎄

Dr Ric Derbyshireric@infosec.exchange
2022-11-20

@paperghost
On the positive side, visa toots sound even more fun than visa tweets!

Dr Ric Derbyshireric@infosec.exchange
2022-11-20

@cyb_detective @hendrikerz
This is excellent, thanks for such a good resource!

Hope escaped academics are welcome on the list, put my details down just in case.

Dr Ric Derbyshireric@infosec.exchange
2022-11-19

Happy #caturday from our gang!

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst