Sign in

Eugenio Benincasa

@euben.bsky.social
329 followers 191 following 56 posts

Cyber Defense Researcher @ethz.ch. Former Italian govt, Pacific Forum and NYPD. LUISS & Columbia University Alum.

PostsRepliesMedia
Reposted by Eugenio Benincasa
Hague TIX @haguetix.bsky.social · 29/05/2026
At #HagueTIX2026 @meidanowski.bsky.social and @euben.bsky.social are discussing how China scales cyber operations: www.thehagueprogram.nl/tix-speakers... www.thehagueprogram.nl/tix-speakers... @thehagueprogram.bsky.social @fggaleiden.bsky.social
072
Reposted by Eugenio Benincasa
The Vertex Project @vertexproject.bsky.social · 03/04/2026
We’re proud Synapse is playing a part in the hands-on workshop at @ccdcoe #CyCon2026 with @lawsecnet.counterintelligence.pl, @euben.bsky.social, and Jiro Minier: “Threat Actors Can Do Public-Private Partnership Too”
186
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 12/03/2026
France hosts the EU’s densest cluster of cyber partnerships with Chinese defense-linked universities, raising exposure to dual-use knowledge transfer, EU funding access, and institutional influence. New Natto Thoughts’ piece from @euben.bsky.social www.nattothoughts.com/p/faux-amis-...
nattothoughts.com
Faux Amis: How France Stands Apart in Europe’s High-Risk University Cyber Partnerships with China
France hosts the EU’s densest cluster of cyber partnerships with Chinese defense-linked universities, raising exposure to dual-use knowledge transfer, EU funding access, and institutional influence
011
Reposted by Eugenio Benincasa
Binding Hook @bindinghook.bsky.social · 12/03/2026
Europe is building stronger systems to report vulnerabilities, but it risks overlooking the people who discover the flaws first: independent security researchers, write @euben.bsky.social and Max van der Horst: bindinghook.com/europe-forge... #EUcybersecurity
bindinghook.com
Europe forgets its bug hunters at its own peril
Without safe harbour for independent vulnerability researchers, Europe risks discouraging the reporting its disclosure regime needs
1165
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 12/02/2026
The Tianfu Cup is back this year. See the analysis of the event by Eugenio @euben.bsky.social published today on Natto Thoughts. www.nattothoughts.com/p/the-tianfu...
nattothoughts.com
The Tianfu Cup Returns Under MPS Leadership as AI Takes Center Stage
After a two-year hiatus, the Tianfu Cup returns under MPS lead, combining AI-assisted vulnerability discovery and exploitation, a new competition track, and less transparency in vulnerability handling
065
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 28/01/2026
We continue exploring provincial level’s involvement in cyber operations. See details in analysis by @euben.bsky.social www.nattothoughts.com/p/provincial...
nattothoughts.com
Provincial Tasking, Cross-Provincial Execution: A Case-Based Look at How China Scales Cyber Operations
How decentralized MSS and MPS tasking and market-enabled, cross-provincial execution by commercial firms shape the scale of China’s cyber operations
053
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 16/12/2025
In this post, @euben.bsky.social and the Natto Team assess that provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations. nattothoughts.substack.com/p/the-many-a...
nattothoughts.substack.com
The Many Arms of the MSS: Why Provincial Bureaus Matter in China’s Cyber Operations
Provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations
023
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 13/08/2025
@euben.bsky.social Eugenio’s research explains the elite cyber talent paradox in China - “all people are soldiers” vs “extremely lean.” #Cybersecurity #TalentPipeline #CyberOperations nattothoughts.substack.com/p/few-and-fa...
nattothoughts.substack.com
Few and Far Between: During China’s Red Hacker Era, Patriotic Hacktivism Was Widespread—Talent Was Not
Inside the small, elite circles that powered China’s massive hacker communities in the late 1990s and 2000s.
022
Eugenio Benincasa @euben.bsky.social · 01/08/2025
Can’t wait for this :)
020
Eugenio Benincasa @euben.bsky.social · 31/07/2025
Microsoft is probing whether a MAPP leak let Chinese hackers exploit a SharePoint vuln pre-patch. In this new piece for Natto, @dakotaindc.bsky.social, @meidanowski.bsky.social & I dig into: 🏛️ China's vuln reporting rules 📉 Which firms joined/left MAPP since 2018 ⚠️ The risks today’s members pose
1114
Reposted by Eugenio Benincasa
Ryan Gallagher @rjgallagher.co.uk · 25/07/2025
New: Microsoft is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in SharePoint before they were patched, enabling a global campaign of cyberattacks, according to people familiar: www.bloomberg.com/news/article...
bloomberg.com
Microsoft Probing If Chinese Hackers Learned of Flaws Via Alert
Microsoft Corp. is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in its SharePoint service before they were patched, acc...
198
Reposted by Eugenio Benincasa
Binding Hook @bindinghook.bsky.social · 25/07/2025
In the latest Hooked!, editor @katharinegk.bsky.social ties together some fascinating recent research from @benread.bsky.social , @euben.bsky.social, @winnona.bsky.social, and others on private sector elements of Chinese offensive cyber: bindinghook.com/articles-hoo...
bindinghook.com
Hooked! #5: A series of new reports and research shows that China’s tech sector is on the offense
A series of new reports and research shows that China’s tech sector is on the offense
062
Eugenio Benincasa @euben.bsky.social · 21/07/2025
1/ China’s cyber capabilities didn’t start top-down, they started with raw hacking talent. The new CSS/ETH report "Before Vegas" traces how informal talent shaped China’s cyber ecosystem, moving from online forums to industry leaders (link in thread).
1158
Reposted by Eugenio Benincasa
Kim Zetter @kimzetter.bsky.social · 18/07/2025
How did China's top APT hackers come to be? Many were early "Honkers" - patriotic hackers who in late 90s launched low-skill cyberattacks against nations deemed disrespectful to China. But once Honkers developed their skills, PLA/MSS came calling. Based on great research by bsky.app/profile/eube...
wired.com
How China’s Patriotic ‘Honkers’ Became the Nation’s Elite Cyber Spies
A new report traces the history of the early wave of Chinese hackers who became the backbone of the state's espionage apparatus.
05627
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 10/07/2025
How has China advanced its AI development to its current state? No single innovation path in AI can be considered definitive. nattothoughts.substack.com/p/debating-c...
nattothoughts.substack.com
Pick Your Innovation Path in AI: Chinese Edition
China’s advances in AI show the effects of a state approach of “introduce, digest, absorb, re-innovate” and years of debate on the balance between market-driven innovation and state-led development
021
Reposted by Eugenio Benincasa
Winnona @winnona.bsky.social · 09/07/2025
“alignment with CCP priorities offers privileged access to state resources, regulatory favor, and expanded commercial opportunities [to hackers]." NEW Phenomenal report on Chinese civil military fusion and cyber militias by Kieran Green: margin.re/mobilizing-c...
margin.re
Mobilizing Cyber Power: The Growing Role of Cyber Militias in China’s Network Warfare Force Structure
This report examines how China’s cybersecurity industry fields reserve and militia units in support of the PLA and national mobilization system.
051
Reposted by Eugenio Benincasa
Winnona @winnona.bsky.social · 25/06/2025
🚨 NEW PAPER on the 0day Supply Chain 🚨: I gathered open source data & interviewed Gov employees, VR and china researchers to figure out what the zero day marketplace looks like in the U.S. and how it compares to China. key findings below ⬇️- 0/🧵 
www.atlanticcouncil.org/in-depth-res...
atlanticcouncil.org
Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace
If the United States wishes to compete in cyberspace, it must compete against China to secure its offensive cyber supply chain.
22717
Eugenio Benincasa @euben.bsky.social · 11/06/2025
To defend, one must first know how to attack” (未知攻,焉知防). This mindset, popularized by a Taiwanese hacker Lin in the 1990s, spread from China's red hackers to CTF teams. Today, it powers China's cyber industry. New piece for @nattothoughts.bsky.social nattothoughts.substack.com/p/defense-th...
nattothoughts.substack.com
Defense-Through-Offense Mindset: From a Taiwanese Hacker to the Engine of China’s Cybersecurity Industry
The belief that offense enables defense in cyberspace, first rooted in China’s 1990s hacker culture, has since permeated the country’s cyber ecosystem
162
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 28/05/2025
The Natto Team explores the development of China's vulnerability research and discovery skills, starting from the vocational college level. Thanks to @euben.bsky.social @dakotaindc.bsky.social Kristin Del Rosso for their previous research on the topic nattothoughts.substack.com/p/when-a-voc...
nattothoughts.substack.com
From Humble Beginnings: How a Vocational College Became a Vulnerability Powerhouse
Qingyuan Polytechnic's focus on vulnerability studies highlights China's continued efforts in gathering vulnerability resources
0117
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 14/05/2025
The Natto Team continues finding stories of Chinese hackers fascinating as they reveal the motivations behind cyber operations and the evolution of China's information security industry. nattothoughts.substack.com/p/stories-of...
nattothoughts.substack.com
From the World of “Hacker X Files” to the Whitewashed Business Sphere
Jiang Jintao’s journey from hacker to infosec entrepreneur illustrates the blend of ambition, skill, and changes in China's cybersecurity industry
055
Reposted by Eugenio Benincasa
Binding Hook @bindinghook.bsky.social · 12/05/2025
In their latest for #BindingHook, Massimo Marotti, Matteo E. Bonfanti, and Giovanni Faleg of the Italian National Cybersecurity Agency reflect on the process of forming the new #G7CybersecurityWorkingGroup: bindinghook.com/articles-hoo...
bindinghook.com
Sowing the seeds of enhanced cybersecurity cooperation within the G7
Officials from the Italian National Cybersecurity Agency discuss the challenges and successes of creating the new G7 Cybersecurity Working Group
041
Reposted by Eugenio Benincasa
Dan Black @danwblack.bsky.social · 29/04/2025
Fascinating to see reference to GRU unit 20728 from FR relative to Russia's offensive cyber program -- as far as I'm aware, a first from a Western service? www.diplomatie.gouv.fr/fr/dossiers-...
diplomatie.gouv.fr
Russie – Attribution de cyberattaques contre la France au service de renseignement militaire russe (APT28) (29.04.25)
La France condamne avec la plus grande fermeté le recours par le service de renseignement militaire russe (GRU) au mode opératoire d'attaque APT28, (…)
3167
Reposted by Eugenio Benincasa
Binding Hook @bindinghook.bsky.social · 28/04/2025
Fellow @euben.bsky.social argues that EU member states should reduce strategic #technologicaldependencies on non-EU countries, particularly those deemed high-risk, and enhance proactive #cybersecurity capabilities. bindinghook.com/articles-bin...
bindinghook.com
Cyber threats are increasingly complex. What can governments do to defend against them?
Virtual Routes fellows look for ways to shrink the gap between cyber threats and defensive capabilities, from regulatory sandboxes to supranational understandings of critical infrastructure.
031
Eugenio Benincasa @euben.bsky.social · 16/04/2025
In this piece with @nattothoughts.bsky.social's @meidanowski.bsky.social, we dug into China’s two naming-and-shaming campaigns over the past 30 days—targeting alleged Taiwanese and U.S. hackers amid escalating geopolitical tensions. nattothoughts.substack.com/p/wars-witho...
nattothoughts.substack.com
Wars without Gun Smoke: China Plays the Cyber Name-and-Shame Game on Taiwan and the U.S.
China’s security services have called out hackers of an alleged “Internet Army of Taiwan Independence” and of the U.S. National Security Agency, signaling an increasingly confrontational approach
185
Reposted by Eugenio Benincasa
Dakota @dakotaindc.bsky.social · 15/04/2025
My question is did state media add mention of US universities in response to the paper @euben.bsky.social and I wrote last year which included circumstantial evidence of hacks by NWPU? www.sentinelone.com/labs/labscon...
sentinelone.com
LABScon24 Replay | A Walking Red Flag (With Yellow Stars)
Dakota Cary and Eugenio Benincasa explore China's CTF ecosystem, highlighting competitions held by the Ministry of State Security and the PLA.
121
Eugenio Benincasa @euben.bsky.social · 15/04/2025
It was a matter of time. Less than a month after outing alleged Taiwanese cyber operatives in an unprecedented move for both its tone and detail, China has done the same with alleged NSA operatives—for the first time. The language echoes that of Western reports, though less detailed.
266
Reposted by Eugenio Benincasa
Patrick Gray @patrick.risky.biz · 10/04/2025
What's happening to @thekrebscycle.bsky.social is disgusting He's one of the most hardworking, dedicated and smart people I'm lucky enough to know, and he showed a LOT of courage when he fought back against attempts to undermine the 2020 election result I hope Americans will stand behind him
614639
Reposted by Eugenio Benincasa
Virtual Routes @virtualroutes.bsky.social · 04/04/2025
We loved having you @weberv.bsky.social, Zoë van Doren, @euben.bsky.social & co! 🙏
021
Reposted by Eugenio Benincasa
Valentin Weber @weberv.bsky.social · 03/04/2025
It was a real pleasure to speak about #China as a risen cyber power at the @virtualroutes.bsky.social colloquium w Zoë van Doren yesterday. Thanks to thought-provoking comments from @euben.bsky.social and great chairing by Lena Riecke & @partomirzaei.bsky.social.
131
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 02/04/2025
A case study of the i-SOON indictment and leaks reveals that source information may vary but it is important to compare and evaluate information for unique insights. nattothoughts.substack.com/p/indictment...
nattothoughts.substack.com
Indictments and Leaks: Different but Complementary Sources
A case study of the i-SOON indictment and leaks reveals that source information may vary but it is important to compare and evaluate information for unique insights.
054
Reposted by Eugenio Benincasa
Dakota @dakotaindc.bsky.social · 26/03/2025
Chinese hacking is becoming bigger, better and stealthier @euben.bsky.social and I on the beat economist.com/china/2025/0...
economist.com
Chinese hacking is becoming bigger, better and stealthier
Experts say it is the main shift in the cyber-threat landscape in a decade
02613
Reposted by Eugenio Benincasa
Virtual Routes @virtualroutes.bsky.social · 26/03/2025
Join us for the next session of the Colloquium series next week! 👇 ⏰ April 2, 16:00-17:00 CET 💡 @weberv.bsky.social, Zoë van Doren & @euben.bsky.social 💭 China’s Expanding Cyber Playbook: Espionage, Fear, and Influence in East Asia Read more & sign up: virtual-routes.org/event/chinas...
062
Eugenio Benincasa @euben.bsky.social · 25/03/2025
Glad to be part of this awesome crew :)
0100
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 19/03/2025
A recent research from Natto Thoughts about US-sanctioned, allegedly APT27-associated actor. #apt27 nattothoughts.substack.com/p/zhou-shuai...
nattothoughts.substack.com
Zhou Shuai: A Hacker’s Road to APT27
US-sanctioned, allegedly APT27-associated actor Zhou Shuai represents a group of Chinese elite hackers who have become an important resource for Chinese state cyber operations.
052
Reposted by Eugenio Benincasa
Oleg Shakirov @shakirov2036.bsky.social · 17/03/2025
Big day for Chinese threat intel MSS outs 4 alleged members of Taiwan's Information, Communications & Electronic Force Command, links them to cyber attacks QiAnXin & Antiy release 2 separate reports on Taiwan-linked APT-Q-20/APT-C-01/GreenSpot/PoisonVine 🧵w/ links & details
11610
Reposted by Eugenio Benincasa
Catalin Cimpanu @campuscodi.risky.biz · 05/03/2025
Putting some order in today's APT announcements: -APT27 charges: www.justice.gov/usao-dc/pr/c... -iSoon charges: www.justice.gov/usao-sdny/pr... -APT27 sanctions: home.treasury.gov/news/press-r... -iSoon reward: x.com/RFJ_USA/stat... -IC3 APT27 alert: www.ic3.gov/PSA/2025/PSA...
justice.gov
Chinese Nationals with Ties to the PRC Government and “APT27” Charged in a Computer Hacking Campaign for Profit, Targeting Numerous U.S. Companies, Institutions, and Municipalities
A federal judge in Washington, D.C., today, unsealed two separate indictments that allege Chinese nationals Yin Kecheng, 38, (尹 可成) a/k/a “YKC” (“YIN”) and Zhou Shuai, 45, (周帅) a/k/a “Coldface” (“ZHOU...
22810
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 05/03/2025
As the Natto Team was going to publish this piece, US Department of Justice unsealed an indictment charging eight i-SOON employees and highlighting the importance of companies like i-SOON in China's cyberthreat landscape. nattothoughts.substack.com/p/where-is-i...
nattothoughts.substack.com
Where is i-SOON Now?
i-SOON’s business struggles after the leak reflect the cruel reality of China’s hacker-for-hire industry
043
Eugenio Benincasa @euben.bsky.social · 05/03/2025
Zhou Shuai (Coldface) joins the list of former members of China’s patriotic hacking group, the Green Army (see i-SOON and Integrity Tech’s leadership), who have been exposed as working for state cyber operations. He is undeniably one of China’s top legacy hackers. www.justice.gov/usao-dc/pr/c...
justice.gov
Chinese Nationals with Ties to the PRC Government and “APT27” Charged in a Computer Hacking Campaign for Profit, Targeting Numerous U.S. Companies, Institutions, and Municipalities
A federal judge in Washington, D.C., today, unsealed two separate indictments that allege Chinese nationals Yin Kecheng, 38, (尹 可成) a/k/a “YKC” (“YIN”) and Zhou Shuai, 45, (周帅) a/k/a “Coldface” (“ZHOU...
035
Reposted by Eugenio Benincasa
InfoSecSherpa 🏔️ Lake Ontario 🚣‍♀️ @infosecsherpa.bsky.social · 05/03/2025
Select Committee on the Chinese Communist Party Holds Hearing — " End the Typhoons: How to Deter Beijing’s Cyber Actions and Enhance America’s Lackluster Cyber Defenses” selectcommitteeontheccp.house.gov/committee-ac...
selectcommitteeontheccp.house.gov
MEDIA ADVISORY: Select Committee on the Chinese Communist Party Holds Hearing — " End the Typhoons: How to Deter Beijing’s Cyber Actions and Enhance America’s Lackluster Cyber Defenses”
WASHINGTON D.C. — The House Select Committee on the Chinese Communist Party will hold a hearing titled "End the Typhoons: How to Deter Beijing’s Cyber Actions and Enhance America’s Lackluster Cyber De...
041
Reposted by Eugenio Benincasa
Dakota @dakotaindc.bsky.social · 28/02/2025
Love seeing @euben.bsky.social and I in the same place. www.voachinese.com/a/deepseek-c...
voachinese.com
中国监控服务提供商纷纷接入DeepSeek,北京网络监视能力或得到加强
多家中国网络安全公司在过去一个月里接连宣布将人工智能大语言模型DeepSeek融入进他们的服务当中。这些公司中不少家都常年向中国官方提供网络审查等监控服务。人工智能和监控方面的专家向美国之音指出,鉴于DeepSeek这样的人工智能工具在语言分析上的擅长,DeepSeek将在中国互联网文字审查上起到巨大的强化作用。
111
Reposted by Eugenio Benincasa
DistrictCon @districtcon.bsky.social · 22/02/2025
“The #1 thing we need for the future is talent…so when [DistrictCon] asked me to come speak, I couldn’t say yes quick enough” - Gen. Nakasone
0193
Eugenio Benincasa @euben.bsky.social · 21/02/2025
Amazing work on China's public opinion monitoring and manipulation by @dakotaindc.bsky.social, @alex.leetnoob.com & @milenkowski.bsky.social 🔥 www.sentinelone.com/labs/censors...
sentinelone.com
Censorship as a Service | Leak Reveals Public-Private Collaboration to Monitor Chinese Cyberspace
Data leak reveals how a top tier cybersecurity vendor helps the PRC enforce content monitoring and manipulation of public opinion in China.
040
Eugenio Benincasa @euben.bsky.social · 19/02/2025
If you’re familiar with iOS jailbreaking, then you’ve likely heard of the Pangu Team. 1y after the i-SOON leaks, my latest for @nattothoughts.bsky.social examines Pangu’s ties to i-SOON and the links b/w elite vuln researchers and govt-contracted hackers nattothoughts.substack.com/p/the-pangu-...
nattothoughts.substack.com
The Pangu Team—iOS Jailbreak and Vulnerability Research Giant: A Member of i-SOON’s Exploit-Sharing Network
A year after the i-SOON leaks, a deep dive into the Pangu Team reveals new insight into the relationships between elite vulnerability researchers and government-contracted hackers
01510
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 22/01/2025
The other shoe has finally dropped, but we still need more intrusion details to defend against the threats. #salttyphoon #apt nattothoughts.substack.com/p/salt-typho...
nattothoughts.substack.com
Salt Typhoon: the Other Shoe Has Dropped, but Consternation Continues
Sichuan Juxinhe, directly involved in the Salt Typhoon cyber operations, resembles a front company of the Chinese Ministry of State Security
043
Reposted by Eugenio Benincasa
DistrictCon @districtcon.bsky.social · 21/01/2025
We're officially 1 month away from DistrictCon Year 0! Check out our agenda for talks, exploits, round tables, and more! www.districtcon.org/agenda
districtcon.org
Agenda — DistrictCon
11512
Eugenio Benincasa @euben.bsky.social · 11/01/2025
The stories you can uncover through research. This part made me giggle: "This was the first hacker attack in my life, and my teacher was my own hormones."
020
Reposted by Eugenio Benincasa
Jennifer Victoria Scurrell @jvscurrell.bsky.social · 07/01/2025
I recently spoke with @voiceofamerica.bsky.social, joined by my brilliant colleague @euben.bsky.social, about whether @bsky.app might become a hotspot for foreign disinformation campaigns. www.voanews.com/a/bluesky-co...
voanews.com
Bluesky could become target of foreign disinformation, experts warn
Platform’s moderation approach exposes vulnerabilities to China's, Russia’s malign influence campaigns
134