Good they investigated this before using them, but this sounds like a big fu...
You reap what you sow, MFs!
https://en.wikipedia.org/wiki/Slovak_opposition_to_sanctions...
SecureBoot is a funny one. It should be signed with the deployer's keys (Slovak), not the manufacturer's. Trusted boot probably wasn't a consideration here, really.
Ironically, a custom firmware can now be used thanks to the lack of a digital lock... if you still trust the hardware.
PS: Props to NBU for doing their job.
Are these cameras in use in Russia? Can people outside of Russia look in at Russian traffic in this way?
That's a pretty good demonstration of why "it's not exposed to the internet" isn't a security boundary if the device itself has an out-of-band communications path.
Add Secure Boot being disabled and unauthenticated live streams and this seems less like one unfortunate backdoor and more like nobody established what the trust boundary was supposed to be in the first place.
> multiple reports in Slovak media that linked the purchase to a Cyprus shell company with fake certifications.
We're talking about this as if it's some precursor to a James Bond plot, but it really fizzles after learning Nina in the sourcing department skipped the compliance paperwork. James Bond doesn't need to leave the bed!
Trojan exploits aside, I just assume that it'd be easier for someone in SVR/GRU to bribe an admin.
Same questions to opposite side.
That's exactly the sort of thing that James Bond would do.
Well the interior ministry didn't really demand one (yes really) but the opposition people have read the documentation for the cameras and the hash of the supplied software was exactly the same as the hash for the russian simicon camera.
They don't even know how to pronounce Fico properly... Give me a break lmao
Are traffic cameras worth the risk of giving away the movement of your key personnel, military and political, in the age of drone warfare and targeted strikes?
[1] https://gidcam.ru/camera/moskva-panorama-centra-stolicy-s-ma...
[2] https://gidcam.ru/camera/moskva-volgogradskij-prospekt-i-plo...
[3] https://camguide.net/ru/europe/russia/saint-petersburg/nevsk...
- Hungary: November of 1956
- Slovakia: "spring" of 1968
- Serbia: the Stalin's betrayal at the end of WW2
It's mainly the older people that are influenced by this, and a lot of young people either left the country already, or have concrete plans to leave.
It's really sad, how these old people are ruining the future of their children and grandchildren, really crazy.
You can say a lot about Russia, but they are very good with misinformation, it's a real threat for Europe.
My wife is from Slovakia, so I have front row seats on the whole situation. The kinds of misinformation these older people are willing to believe is really nuts.
slovakia also doesnt support Russia’s invasion of Ukraine. you made that up.
its crazy that such a lie is a top comment.
This wasn't some oversight of the proverbial Nina in any way. They just did sloppy job from both sides covering tracks, not uncommon with current government. They are loud (and racist, xenophobic, and often dumb), not competent smart people.
The majority of school teachers grew up under the Soviet side of cold war propaganda.
And in history education in particular, we are told that "we" have always looked towards Russia as a role model, to fight Hungarian nationalism (since the country was just part of Hungary for most of its history).
That's why they're doomed to repeat it. Again and again.
Goes to show that 1984-style conditioning really does work, decades later.
Remarkably, it can even be passed through generations, as it gets ingrained into the mentality of how parents raise children: "The nail that sticks out gets hammered down. Don't rock the boat."
Which was a survival trait in those times.
The current incarnation of Russian propaganda is different, but is even more virally poisonous:
> I'm not political. Politics is dirty. There's nothing you can change anyway. "Two sides" is an illusion. Everybody is lying and has an ulterior motive. Only naive fools believe otherwise, only naive fools ever trust. You can't know anything for sure. What you think is true is actually a lie. The only thing that's real is who you're with. That's the only truth. That's the only thing to look for in anything anyone says, that's the only thing one really says. That's what makes something true or false. The words uttered don't matter at all.
You might have seen this kind of mentality spouted by your friends on either side of the political spectrum.
Remarkably, whatever the political persuasion of people who have it is, the end result is the likes of Orban/Fico coming to power.
Sadly, this thing not only spreads, it also sticks.
If you know of an antidote, please tell me what it is.
But maybe rapidly switching residential solar on and off in a coordinated way can also do funny things to grid equipment
Sometimes those people are a plurality that organically endorses that decision and votes some representative in. Sometimes those people are a plurality that has been brainwashed by compromised media to do it. Sometimes those people are just a small ruling elite that get voted in by people who didn't think very hard about those particular geopolitical decisions and just want, I don't know, their political and cultural enemies brutalized and $1.99 gas.
As far as Hungary goes, I asked my friend who studied Hungarian history. He explained to me that while the Soviet invasion was very traumatic, the subsequent Kádár "goulash socialism" was a lot more lenient on the people than all the other Soviet Bloc regimes, and that the Hungarians made an incorrectly confident conclusion that losing a small war to the Russians is not catastrophic.
Of course, this is NOT the experience of basically anyone else who happened to be in a similar situation. A potential puppet regime of Russia in Ukraine wouldn't look like Kádárs by any means, it would rather look like the Kadyrovian microstate in Chechnya, minus the Islam of course.
Tell me how it’s not advantageous for Russia to enable trade with them.
I don't think you understand how bad globalization fucked up these countries, people live with their parents until they're 30+, young people can't find decent jobs, etc.
Also in these countries there's a lot of old people who have never been able to adapt to living in a free, capitalist society, so for them, there's some nostalgia for communism.
Hopefully mutually assured annoyance keeps everyone at bay.
If that goal sounds stupid to you, that's because it is. I would expect some countries that are not China to act with such a capricious lack of foresight.
In the end it's all about trust. Right now I don't see why China would like to burn down their market.
same issue with large loads like boilers, this stuff should never be connected to the internet, but it is
if you can control enough load on the grid you can do real damage
When in the past they would claim that the Soviet times were bad, now they would claim that it wasn't that bad in the end. That is of course because of all the horrible things that are happening in EU, like gay and trans people, and vaccinations. Terrible! Let's bring those good old Soviet days back!
well technically, existence of some private messaging network can help predators. i dont know if there is a way around that.
but saying that the actions of the activist are "pro CP" is not fair IMO. its often a manipulative labeling. it might be what it motivates the activist or it might not be. they might have completely different reasons to advocate for digital privacy.
A lot of people in the US feel the same way right now.
The problem is that a few minutes is still too slow when a large power source suddenly drops out. The grid needs an immediate response, which can come from fast reserves such as batteries, hydro, pumped storage and other generators that can react automatically.
Pumped storage is basically gravitational energy storage: you pump water uphill when electricity is plentiful, then release it through turbines when power is needed.
I quite fancy electrical grid.
So maybe natural gas imports aren't the thing that determine the outcome.
Sure, we can blame politicians which were mostly bad to worse and stole everything that was previously state-owned (meaning everything). But folks kept voting for them in similar fashion you describe so this is the result, its trivial to 'buy' votes with relatively low budget. I mean current PM has very tight and visible connections to Italian 'Ndrangheta mafia, he or people around him did a contract murder of reporter looking into that. He didn't ever faced jail and is back being PM like there is no tomorrow. There is only so much blame one can point outwards, you can't be dumb / do dumb shit and expect long term marvels of prosperity on Switzerland's level.
Lived in both of those countries, and they look exactly as they should given overall population efforts towards hard work, honesty, rule of law and so on. If US would be a nation of slackers and thieves it would also look very differently to how it is.
but it still doesnt imply that slovakia is therefore politically pro-russian.
they might care about pro-slovak advantages it brings. or they might think that sanction dont work as intendet. or they might think that sanction paradoxically cause too many problems in EU. or that it is not the right approach to resolve the conflict.
The world is not simple black/white.
> When in the past they would claim that the Soviet times were bad, now they would claim that it wasn't that bad in the end.
We are here talking about different things. You refer to these people praising the Soviet Union for e. g. healthcare and what not. This has absolutely nothing to do with Putin's genocide against Ukrainians though. Putin represents the aggressive russian empire that wants to conquer more land. It is really simple to see. It has nothing to do with healthcare.
https://www.newsweek.com/putin-says-communism-comes-bible-co...
It doesn't matter what Russia actually is. They play both sides with their propaganda. Old people who thought positively about communism still support Russia.
Fico and Babiš for example were both communist party members and both pro-Russia politicians today.
edit: ah you mean the old people? not really, no, it's just pure propaganda, it doesn't have to make sense.
Those countries who were fresh from behind the iron curtain were really dealt a bad hand. They had lived in a "protective bubble", albeit a very unsustainable one and suddenly were thrown in the ocean surrounded by sharks looking for an easy meal. Almost every one of those people found themselves desperate but "inexperienced" and unprepared for the new world, every politician was absolutely blown away by the fortune they could make, and every other country jumped on the opportunity to make money. Like shooting fish in a barrel.
For every politician who took a bribe, someone who already had money paid it. That money didn't come from inside those poor countries. This leveraging of poorer countries never stopped. That's how some countries get a better deal than others when the EU adopted the Euro, for example. But it's never been so bad as back then because it's incredibly rare that entire countries find themselves exiting a time capsule, just ready to be exploited by people who already know how the game is played.
This reminds me of two things. The people who always think others are poor because they're lazy, and the people with perfect hindsight and no pressure judging that Captain Sully could have landed the plane back on the runway instead of the Hudson.
That makes you "pro Russian" apparently
Written by

Catalin Cimpanu
News Editor
This newsletter is brought to you by Socket Security. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
🗨️
The intro was updated post-publication to fix the link to the technical report and to add more context from a local source.
Slovakia's national security service NBU has issued a security alert against the use of NERO R-ONE high-speed traffic cameras.
The agency says the cameras contain a backdoor mechanism that grants shell and network access to the devices via an SMS message received from a list of hardcoded Russian phone numbers.
The NBU started an investigation into the devices after the country's opposition accused the government of buying the cameras from Russia and after multiple reports in Slovak media that linked the purchase to a Cyprus shell company with fake certifications.
According to the NBU, the cameras are a rebranded version of a Russian traffic camera model named CORDON PRO.M, produced by St. Petersburg-based Russian firm Semicon.

via NBU

via NBU
The cameras were bought as part of a €30 million EU-funded project to rebuild the country's national traffic monitoring system.
The Interior Ministry has allegedly bought and preparing to install 279 cameras on selected roads across Slovakia.
The Ministry initially denied that the cameras were of Russian origin and said there's no danger of data theft since the devices were going to be on a closed loop Ministry network.
According to an NBU technical report, besides the backdoor system, the cameras also contain several security flaws. They have a crucial SecureBoot security feature that's turned off so the firmware origin is never enforced, the web management portal contains multiple vulnerabilities, and the cameras expose live streams to anyone without a password and who knows their broadcasting IP.
Interior Ministry officials paused the camera deployment after the NBU report and said it would order an additional assessment from an independent auditor to confirm the findings.
Some similar devices are also allegedly installed in Croatia and maybe some other countries in Eastern Europe.

Nobody should be buying security cameras from Russia, or China for that matter https://t.co/ZiuuZ3ODjQ
— ChrisO_wiki (@ChrisO_wiki) August 18, 2026
In this episode of Risky Business Features, James Wilson chats with PortSwigger’s Director of Research James Kettle about using an LLM to develop genuinely new attack techniques.
Scammers target UK prime minister: A scammer targeted UK Prime Minister Andy Burnham by posing as White House chief of staff Susie Wiles. Burnham detected the scam himself and the UK embassy notified the White House. Multiple US senators, governors, and executives were also targeted by scammers posing as Wiles last year. The White House blamed the incident on a hacker obtaining a copy of her cellphone contacts. [Politico Europe]
Hackers target Ukraine's ARMA agency: A cyberattack has disrupted the activities of Ukraine's agency for managing seized Russian assets. The attack took place this week as the agency was preparing to assign a new manager for beverage company IDS Ukraine. Ukraine seized IDS from Alfa-Bank co-founder Mikhail Fridman shortly after Russia's invasion. The agency didn't attribute the attack. [RBC // ARMA]
Hack hits Berlin government: A cyberattack has disrupted two major departments in the Berlin city government. The attack took down emails, remote gateways, and internet connections across the transport and urban development departments. IT staff have disconnected the two agencies from the city network to prevent the incident from spreading. [Tagesspiegel // RBB24 // Yahoo Finance!]
Breach at genetics testing company: Genetics-testing company Baylor Genetics is notifying users of a security breach that exposed their personal information. The breach took place in June and both patient and employee data was compromised. The company didn't disclose the number of affected individuals. [Baylor Genetics // CybersecurityDive]
UT San Antonio breach: The University of Texas at San Antonio has taken its IT systems offline after a security breach over the weekend. Classes for the new school year are expected to start on Wednesday as scheduled. The university has extended tuition payment deadlines and plans to reset all user account passwords once systems are online. [UT San Antonio // The Record]
Ransomware disables hospital doors, HAVC: A ransomware attack has disabled access doors, heating, ventilation, and air conditioning at Winnipeg's largest hospital. The Winnipeg Health Sciences Centre increased onsite security while the access card system is still down. The hospital says patient care and clinical operations are not impacted. [CBC // The Winnipeg Free Press] [h/t Alex Rudolph]
BlueSky and GitHub hit by Iranian DDoS attacks: An Iranian hacktivist group took down BlueSky and GitHub with DDoS attacks on Sunday and Monday, respectively. The attacks caused prolonged outages at both companies. A group known as the 313 Team took credit for the attacks. The hackers were also behind another wave of DDoS attack in April. [Telegram // Telegram]
We apologize for yesterday’s service problems. Bluesky experienced a DDoS attack—a flood of junk traffic meant to knock servers offline—over a period of 24 hours. We have upgraded our defenses in response, and we continue to monitor the situation. Follow @status.bsky.app for any updates.
— Bluesky (@bsky.app) August 18, 2026 at 12:27 AM
SafePal breach: Hackers have stolen the personal information of 40,000 customers of hardware crypto-wallet provider SafePal. The incident impacted all customers who placed orders of SafePal wallets between March 2, 2025, and April 11, 2026. SafePal says no seed phrases or private keys are impacted. The stolen data is still dangerous because it could enable wrench attacks on wallet holders. [SafePal // SecurityWeek]
Bits of Gold breach: Hackers have stolen the data of 250,000 customers of Bits of Gold, Israel's largest cryptocurrency exchange. The company notified customers of the hack over the weekend. It said the data was stolen from an external analytics service provider. It didn't say what type of data was stolen. [CTech]
TheHatman dumps employee data for a dozen companies: A threat actor is selling the employee data of almost a dozen Fortune 500 companies. The hacker, who goes by TheHatman, claims the data was stolen by using stolen credentials to access each victim's Azure environments. The hacker claims they breached McDonalds, Vodafone, Gap, and the Intercontinental and Wyndham hotel chains. [HudsonRock]

Windows 11 drops WMIC: The current Windows 11 installation packages and Insider Builds do not ship with the Windows Management Instrumentation Command-line (WMIC) feature anymore. Microsoft deprecated the toolkit a few years ago after it saw massive abuse. [Microsoft // WindowsLatest]
Firefox 154: Mozilla has released Firefox 154. New features and security fixes are included. The biggest feature in this release is support for GeForce NOW, NVIDIA's cloud gaming platform. [Firefox]
Firefox for iOS gets an ad blocker: Mozilla has added an ad blocker to Firefox on iOS. It is turned off by default. [Mozilla]

Russian things: A Russian court has forced two Telegram channel owners to remove posts blaming the country's internet watchdog for causing an outage of the country's banking system as part of an attempt to block VPN protocols. This is funny to me because they didn't fine Natalya Kaspersky, one of the Kaspersky co-founders, for basically saying the same thing in an official manner and to more mainstream Russian news outlets. Alas, Russia, a two-tiered society! [Caution News on Telegram]
In this Risky Business sponsor interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default.
French cops used public exploit to hack EncroChat: French law enforcement used a public exploit hosted on GitHub to hack encrypted phone network EncroChat in 2020. The exploit was for the Bad Binder Android vulnerability and had been shared online a few months before. EncroChat discovered the hacks after French cops deployed a second exploit that failed. [ComputerWeekly // Bad Binder exploit on GitHub // Bad Binder write-up]

SMS blaster arrested in Malaysia: Malaysian authorities have arrested a 65-year-old suspect for driving around with an SMS blaster in his car. The suspect was detained driving around the border crossing between Johor Bahru and Singapore. He is the second suspect arrested this month in Johor Bahru for SMS blasting. [CommsRisk]
LockerGoga dev on trial in Switzerland: Swiss prosecutors are seeking a 12-year prison sentence for a Ukrainian man linked to ransomware attacks on local companies. Officials claim the suspect was a coder for the LockerGoga, MegaCortex and Nefilim ransomware groups. The suspect is pleading not guilty. He claims he was working as a consultant for a cybersecurity firm when he was detained and the ransomware source code found on his devices. [Watson // The Record]
Ransomware affiliate poses as data recovery firm: A ransomware affiliate is posing as a data recovery firm named Ransom Busters LTD. According to GuidePoint Security, the group has reached out to multiple companies and offered to delete their data from ransomware servers for a fee between $20,000 and $60,000. The group has reached out to victims even before breaches were made public. GuidePoint believes the group has signed up as an affiliate on different Ransomware-as-a-Service platforms to see hacked companies and reach out in advance. [GuidePoint Security]
Operation CameraSwarm: A threat actor has hacked more than 14,500 Dahua security cameras across Ukraine and Russia. Researchers at Hunt Intelligence discovered the botnet after the hacker left an open directory on their server infrastructure. According to files recovered from the server, the hacker exploited old vulnerabilities but also a secret hardcoded account in some of the devices. [Hunt Intelligence]

StopAndProtect profile: Security firm Check Point has published a profile on StopAndProtect, a new e-crime operation using thousands of hacked WordPress sites to redirect users to malware downloads and then store stolen creds. [Check Point]
FUXA scanning: Threat actors are scanning for FUXA SCADA devices in an attempt to exploit CVE-2026-25895, an unauthenticated path traversal that can let hackers rewrite local files. [Caitlin Condon on LinkedIn]
StubMaker RubyGems campaign: The OSM team has spotted 16 malicious RubyGems packages typosquatting more popular packages that spread a Windows infostealer to whoever installs them. [OpenSourceMalware]

DragonDoll Android spyware: Russian security firm Positive Technologies has discovered a new Android spyware strain. Named DragonDoll, the spyware is spread using fake Chrome update packages and focuses on stealing data from instant messengers. [Positive Technologies // Archived]
GoldDigger Android trojan: IBM's Trusteer team has published a technical analysis of GoldDigger, an Android banking trojan active since 2023. [IBM]
C2Looper backdoor: In July 2026, researchers identified C2Looper, a new malware family likely used in ransomware attacks to establish a foothold for lateral movement. [Zscaler]
TWINLOOT: Ontinue researchers have discovered TWINLOOT, a Python-coded malware framework that hosts its entire command-and-control infrastructure inside trusted Microsoft services such as Azure, M365, and SharePoint. [Ontinue]
MacSync Stealer: Microsoft has released a technical report on MacSync Stealer, a recent infostealer targeting the macOS ecosystem. [Microsoft]
WordlistLoader: Gen Threat Labs has identified WordlistLoader, a new loader used to deliver Amatera Stealer via ClearFake campaigns. [Gen Digital]
Shadow HVNC and Shadow Loader: Security researchers have reverse-engineered Shadow HVNC and Shadow Loader, two malware families advertised online by a developer known as RemoteX. [Malbear Labs]
ValleyRAT: Despite some arrests this year, the SilverFox group is still active and spreading its ValleyRAT malware. [Forcepoint]
AZALEA RAT: And speaking of RATs, Point Wild looks at the distribution chains of the AZALEA RAT, a new RAT advertised online as AzaleaControl. [Point Wild]
Medusa ransomware: CISA has updated its advisory on the Medusa ransomware with new TTPs. The agency says the group has continued to be active and made hundreds of new victims. [CISA]
Mirage2FA: ANY.RUN's security team looks at a new 2FA-intercepting phishing service named Mirage2FA. The service seems to be geared towards M365 campaigns primarily. [ANY.RUN]

In this Soap Box edition of the Risky Business podcast Patrick Gray chats with Socket founder Feross Aboukhadijeh about how to measure the reachability of vulnerabilities in applications. It's great to know there's a CVE in a library you're using, but it's even better if you can say whether or not that vulnerability actually impacts your application.
France investigates Russian disinfo ops: French authorities have launched an investigation into suspected Russian disinformation campaigns targeting the country's pro-EU politicians. The campaigns targeted possible presidential candidates Gabriel Attal and Edouard Philippe as soon as they showed interest in next year's election. Open-source reporting has linked the campaigns to a Russian disinformation group known as Matryoshka and Storm-1516. [FranceInfo]
Operation QUICSILVER: A China threat actor has been targeting Myanmar diplomats via an VHD-delivered Go backdoor named QUICAgent. [Seqrite]
Goffee replaces image files: The Goffee cyber-espionage group has maintained a foothold inside hacked organizations by altering installation images for corporate apps. In a campaign targeting Russian companies, the group has modified 7-Zip and Git installers. [F6]
Core Werewolf's CoreRAT: A highly sophisticated APT group named Core Werewolf has continued its operations targeting Russian orgs with a new remote access trojan named CoreRAT. [BI.ZONE]
Russia and US hold hands in Alberta info-ops: The US and Russia appear to have joined hands in promoting the Alberta separatist movement in Canada. [The Globe and Mail]
"The first data from a study that began last month indicate Russian content farms have been pushing pro-separatist content into online communities and using Canadians to “launder” those messages by sharing such material on their social media feeds, the researchers said. The U.S. activity, on the other hand, is more overt, with prominent American influencers, podcasts and websites openly promoting Alberta separation, said Brian McQuinn, co-director of the Centre for Artificial Intelligence, Data, and Conflict at the University of Regina."
CopyCop (Storm-1516) in Armenia: Russian disinfo group CopyCop ran a disinformation campaign trying to sabotage the construction of a shared US-Armenian AI data center in Hrazdan. [Recorded Future]
PurpleDelta: Recorded Future has identified 22 new personas operated by PurpleDelta, the name the company assigns to North Korea's remote IT worker scheme. Also this week, Bridewell published a guide on how to defend against these groups. [Recorded Future // Bridewell]
Iranian phishing ops target Israeli journalists: Iranian state hackers have intensified spear-phishing attacks targeting Israeli journalists. The country's intelligence and cybersecurity agencies have sent out a security alert about the attacks last week. The agencies say hackers are seeking to obtain private information from journalists reporting on political and national security. [Ynet]
US charges more Mabna hackers: The US has unsealed a superseding indictment against 17 Iranian hackers. The suspects are employees of the Mabna Institute, a cyber contractor for Iran's Islamic Revolutionary Guard Corps. The Justice Department claims Mabna hackers breached universities across the world to steal research and transfer to Iranian counterparts. The superseding charges replace a 2018 indictment that expands the number of suspects from nine to 17. The State Department has also offered a $10 million reward for information that may lead to the arrest of any of the suspects. The Mabna Institute hacking campaigns are tracked by security firms under the codename of Cobalt Dickens. [DOJ 2026 // DOJ 2018 // Rewards for Justice // Sophos]

Security updates: Apple, Dell, Edge, Firefox, GitLab, Oracle, Tenable, Tor Browser.
AI agent introduces bug in Snowflake's production: Security firm Wiz has spotted an AI coding agent autofixing a bug but introducing a vulnerability in cloud provider Snowflake's production systems. [Wiz]
Microsoft delays Exchange updates due to influx of AI bugs: Microsoft has delayed a major update for Exchange Subscription Edition servers due to an influx of AI-discovered vulnerabilities. The update was supposed to go live at the end of June. Microsoft says it did not want to release its biannual feature update only to release multiple batches of security fixes right after. The company plans to wait to fix all security bugs before releasing the Exchange SE H1 Cumulative Update. Microsoft says employees discovered the security flaws as part of an internal push to use AI tools for bug discovery. [Microsoft]
KEV update: CISA has updated its KEV database with four vulnerabilities that are currently exploited in the wild. All are 2026 bugs, such as a recent Apple macOS ScreenShare bug, a Microsoft IKE one, a SharePoint one, and a VMware vCenter path traversal.
Acquisition news: Tech giant Fortinet has acquired AI security startup Virtue AI, which specializes in AI runtime protection, automated AI validation, and security for autonomous AI systems. [Fortinet]
Threat/trend reports: Beazley Security, Black Kite, Bridewell, Cyberproof, Ecosyste.ms, JPMorgan, MinterEllison, and Onyxia have recently published reports and summaries covering various emerging threats and industry trends.

In this edition of Between Two Nerds, Tom Uren and The Grugq discuss The Offense Death Cycle paper looking at how to take advantage of a defender's ability to control a network to discover intruders.