<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>defense &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/defense/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Thu, 02 Oct 2025 16:19:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Daniel Miessler on the AI Attack/Defense Balance</title>
		<link>https://noise.getoto.net/2025/10/02/daniel-miessler-on-the-ai-attack-defense-balance/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 02 Oct 2025 16:19:59 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[defense]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70905</guid>

					<description><![CDATA[<p>His <a href="https://danielmiessler.com/blog/will-ai-help-moreattackers-defenders">conclusion</a>:</p>
<blockquote><p>Context wins</p>
<p>Basically whoever can see the most about the target, and can hold that picture in their mind the best, will be best at finding the vulnerabilities the fastest and taking advantage of them. Or, as the defender, applying patches or mitigations the fastest.</p>
<p>And if you’re on the inside you know what the applications do. You know what’s important and what isn’t. And you can use all that internal knowledge to fix things­—hopefully before the baddies take advantage.</p>
<p>Summary and prediction</p>
<ol>
<li>Attackers will have the advantage for 3-5 years. For less-advanced defender teams, this will take much longer.
...</li></ol></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Measuring the Attack/Defense Balance</title>
		<link>https://noise.getoto.net/2025/07/30/measuring-the-attack-defense-balance/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 30 Jul 2025 11:07:43 +0000</pubDate>
				<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[defense]]></category>
		<category><![CDATA[reports]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70530</guid>

					<description><![CDATA[<p>“Who’s winning on the internet, the attackers or the defenders?”</p>
<p>I’m asked this all the time, and I can only ever give a qualitative hand-wavy answer.  But Jason Healey and Tarang Jain’s latest Lawfare piece has <a href="https://www.lawfaremedia.org/article/are-cyber-defenders-winning">amassed data</a>.</p>
<p>The essay provides the first framework for metrics about how we are all doing collectively—and not just how an individual network is doing. Healey wrote to me in email:</p>
<blockquote><p>The work rests on three key insights: (1) defenders need a framework (based in threat, vulnerability, and consequence) to categorize the flood of potentially relevant security metrics; (2) trends are what matter, not specifics; and (3) to start, we should avoid getting bogged down in collecting data and just use what’s already being reported by amazing teams at Verizon, Cyentia, Mandiant, IBM, FBI, and so many others...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>The Signal Chat Leak and the NSA</title>
		<link>https://noise.getoto.net/2025/03/31/the-signal-chat-leak-and-the-nsa/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 31 Mar 2025 11:04:55 +0000</pubDate>
				<category><![CDATA[defense]]></category>
		<category><![CDATA[Department of Defense]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70069</guid>

					<description><![CDATA[<p>US National Security Advisor Mike Waltz, who started the now-infamous group chat coordinating a US attack against the Yemen-based Houthis on March 15, is seemingly now suggesting that the secure messaging service Signal has security vulnerabilities.</p>
<p>"I didn’t see this loser in the group," Waltz <a href="https://abcnews.go.com/Politics/trump-admins-shifting-explanations-journalist-added-signal-chat/story?id=120179649">told</a> Fox News about <em>Atlantic</em> editor in chief Jeffrey Goldberg, whom Waltz <a href="https://www.theatlantic.com/politics/archive/2025/03/trump-administration-accidentally-texted-me-its-war-plans/682151/">invited</a> to the chat. "Whether he did it deliberately or it happened in some other technical mean, is something we’re trying to figure out."</p>
<p>Waltz’s implication that Goldberg may have hacked his way in was followed by a ...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Drones and the US Air Force</title>
		<link>https://noise.getoto.net/2024/03/18/drones-and-the-us-air-force/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 18 Mar 2024 11:03:14 +0000</pubDate>
				<category><![CDATA[defense]]></category>
		<category><![CDATA[Department of Defense]]></category>
		<category><![CDATA[drones]]></category>
		<category><![CDATA[economics of security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[war]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=68618</guid>

					<description><![CDATA[<p>Fascinating <a href="https://warontherocks.com/2024/03/drones-the-air-littoral-and-the-looming-irrelevance-of-the-u-s-air-force/">analysis</a> of the use of drones on a modern battlefield—that is, Ukraine—and the inability of the US Air Force to react to this change.</p>
<blockquote><p>The F-35A certainly remains an important platform for high-intensity conventional warfare. But the Air Force is planning to buy 1,763 of the aircraft, which will remain in service through the year 2070. These jets, which are wholly unsuited for countering proliferated low-cost enemy drones in the air littoral, present <i>enormous</i> opportunity costs for the service as a whole. In a set of comments <a href="https://www.linkedin.com/posts/kevin-murray-1507a055_deadly-cheap-and-widespread-how-iran-supplied-activity-7162108210366119938-VVMi">posted on LinkedIn...</a></p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Cyberwar Lessons from the War in Ukraine</title>
		<link>https://noise.getoto.net/2023/02/23/cyberwar-lessons-from-the-war-in-ukraine/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 23 Feb 2023 12:27:20 +0000</pubDate>
				<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[defense]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[reports]]></category>
		<category><![CDATA[russia]]></category>
		<category><![CDATA[Ukraine]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=66964</guid>

					<description><![CDATA[<p>The Aspen Institute has published a good analysis of the successes, failures, and absences of cyberattacks as part of the current war in Ukraine: “<a href="https://www.aspeninstitute.org/publications/the-cyber-defense-assistance-imperative-lessons-from-ukraine/">The Cyber Defense Assistance Imperative ­ Lessons from Ukraine</a>.”</p>
<p>Its conclusion:</p>
<blockquote><p>Cyber defense assistance in Ukraine is working. The Ukrainian government and Ukrainian critical infrastructure organizations have better defended themselves and achieved higher levels of resiliency due to the efforts of CDAC and many others. But this is not the end of the road—the ability to provide cyber defense assistance will be important in the future. As a result, it is timely to assess how to provide organized, effective cyber defense assistance to safeguard the post-war order from potential aggressors...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>US Critical Infrastructure Companies Will Have to Report When They Are Hacked</title>
		<link>https://noise.getoto.net/2022/03/15/us-critical-infrastructure-companies-will-have-to-report-when-they-are-hacked/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 15 Mar 2022 11:01:18 +0000</pubDate>
				<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[cyberespionage]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[defense]]></category>
		<category><![CDATA[espionage]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[laws]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=65227</guid>

					<description><![CDATA[<p>This <a href="https://apnews.com/article/russia-ukraine-technology-business-congress-gary-peters-c46e063220568b2beb56220ac60f6041">will be law</a> soon:</p>
<blockquote><p>Companies critical to U.S. national interests will now have to report when they’re hacked or they pay ransomware, according to new rules approved by Congress.</p>
<p>[…]</p>
<p>The reporting requirement legislation was approved by the House and the Senate on Thursday and is expected to be signed into law by President Joe Biden soon. It requires any entity that’s considered part of the nation’s critical infrastructure, which includes the finance, transportation and energy sectors, to report any “substantial cyber incident” to the government within three days and any ransomware payment made within 24 hours...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Cloudflare, CrowdStrike, and Ping Identity launch the Critical Infrastructure Defense Project</title>
		<link>https://noise.getoto.net/2022/03/07/cloudflare-crowdstrike-and-ping-identity-launch-the-critical-infrastructure-defense-project/</link>
		
		<dc:creator><![CDATA[Matthew Prince]]></dc:creator>
		<pubDate>Mon, 07 Mar 2022 13:59:10 +0000</pubDate>
				<category><![CDATA[CIDP]]></category>
		<category><![CDATA[defense]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[Zero-Trust]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=dbcafccb836355e15239b83b3a5fba7d</guid>

					<description><![CDATA[Today, Cloudflare is launching the Critical Infrastructure Defense Project. The Project was born out of conversations with cybersecurity and government experts concerned about potential retaliation to the sanctions that resulted from the Russian invasion of Ukraine]]></description>
		
		
		<enclosure url="http://blog.cloudflare.com/content/images/2022/03/unnamed--1-.png" length="0" type="" />

			</item>
		<item>
		<title>10 additional AWS services authorized at DoD Impact Level 6 for the AWS Secret Region</title>
		<link>https://noise.getoto.net/2020/10/07/10-additional-aws-services-authorized-at-dod-impact-level-6-for-the-aws-secret-region/</link>
		
		<dc:creator><![CDATA[Tyler Harding]]></dc:creator>
		<pubDate>Wed, 07 Oct 2020 17:42:06 +0000</pubDate>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[defense]]></category>
		<category><![CDATA[Department of Defense (DoD)]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[Impact Level 6]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=c9c1ada9bdfcb8da1c9cbd3d089acf91</guid>

					<description><![CDATA[The Defense Information Systems Agency (DISA) has authorized 10 additional AWS services in the AWS Secret Region for production workloads at the Department of Defense (DoD) Impact Level (IL) 6 under the DoD&#8217;s Cloud Computing Security Requirements Guide (DoD CC SRG). With this authorization at DoD IL 6, DoD Mission Owners can process classified and [&#8230;]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 41/172 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-08 18:44:58 by W3 Total Cache
-->