Sign in

Eugenio Benincasa

@euben.bsky.social
330 followers 191 following 56 posts

Cyber Defense Researcher @ethz.ch. Former Italian govt, Pacific Forum and NYPD. LUISS & Columbia University Alum.

PostsRepliesMedia
Eugenio Benincasa @euben.bsky.social · 31/07/2025
Microsoft is probing whether a MAPP leak let Chinese hackers exploit a SharePoint vuln pre-patch. In this new piece for Natto, @dakotaindc.bsky.social, @meidanowski.bsky.social & I dig into: 🏛️ China's vuln reporting rules 📉 Which firms joined/left MAPP since 2018 ⚠️ The risks today’s members pose
1114
Eugenio Benincasa @euben.bsky.social · 21/07/2025
3/ Some Red 40 hackers have carried out operations on behalf of China’s military and intelligence services. Their informal networks, formed during their teens or twenties as members of the same hacking groups, exemplify tool sharing and collab that underpins China’s APTs MO.
110
Eugenio Benincasa @euben.bsky.social · 21/07/2025
1/ China’s cyber capabilities didn’t start top-down, they started with raw hacking talent. The new CSS/ETH report "Before Vegas" traces how informal talent shaped China’s cyber ecosystem, moving from online forums to industry leaders (link in thread).
1158
Eugenio Benincasa @euben.bsky.social · 15/04/2025
Original notice. Source: cn.chinadaily.com.cn/a/202504/15/...
000
Eugenio Benincasa @euben.bsky.social · 17/01/2025
end of page ofac.treasury.gov/recent-actio...
110
Eugenio Benincasa @euben.bsky.social · 11/01/2025
The stories you can uncover through research. This part made me giggle: "This was the first hacker attack in my life, and my teacher was my own hormones."
020
Eugenio Benincasa @euben.bsky.social · 16/12/2024
Executives of i-Soon, whose leaked internal files this year exposed its role in state-sponsored espionage, discussed accessing Tianfu Cup vulns, confirming the competition's role as a likely feeder system for security agencies. ("Same Same, but Different" by @winnona.bsky.social) 5/6
140
Eugenio Benincasa @euben.bsky.social · 16/12/2024
The process of feeding hacking contest vulnerabilities to security agencies is explicitly stated in China's own directive on hacking competitions (2018). (Text from "Capture the (red) flag" report, coauthored this year with @dakotaindc.bsky.social) 2/6
110
Eugenio Benincasa @euben.bsky.social · 16/12/2024
"It is normal to strengthen technical exchanges and promote scientific and technological innovation"... "by harnessing hacking contest vulnerabilities for strategic use by security agencies*" There, fixed it for them. Analyses backing this up 👇 (1/6) (Source: www.newsweek.com/us-indicts-h...)
131
Eugenio Benincasa @euben.bsky.social · 26/11/2024
China govt contractors like Elex (below) likely support state info ops by creating networks of fake accounts "to form online public opinion forces..on platforms like Facebook, Twitter, and YouTube." Understanding exactly how these work should be key to maintaining a healthy platform @safety.bsky.app
030
Eugenio Benincasa @euben.bsky.social · 04/06/2024
In China, where the military-civilian divide is blurred, hacking contests and bug bounty programs help assess the strength of its offensive cyber ecosystem. This graph shows my understanding of it. Insights in short thread: threadreaderapp.com/thread/17964... Full Report: shorturl.at/WsjFa
061
Eugenio Benincasa @euben.bsky.social · 30/05/2024
New CSS at @ethzurich.bsky.social Cyberdefense Report “From Vegas to Chengdu: Hacking Contests, Bug Bounties, and China’s Offensive Cyber Ecosystem” is out: css.ethz.ch/content/dam/...
1145