Sign in

Eugenio Benincasa

@euben.bsky.social
329 followers 191 following 56 posts

Cyber Defense Researcher @ethz.ch. Former Italian govt, Pacific Forum and NYPD. LUISS & Columbia University Alum.

PostsRepliesMedia
Reposted by Eugenio Benincasa
Hague TIX @haguetix.bsky.social · 29/05/2026
At #HagueTIX2026 @meidanowski.bsky.social and @euben.bsky.social are discussing how China scales cyber operations: www.thehagueprogram.nl/tix-speakers... www.thehagueprogram.nl/tix-speakers... @thehagueprogram.bsky.social @fggaleiden.bsky.social
072
Reposted by Eugenio Benincasa
The Vertex Project @vertexproject.bsky.social · 03/04/2026
We’re proud Synapse is playing a part in the hands-on workshop at @ccdcoe #CyCon2026 with @lawsecnet.counterintelligence.pl, @euben.bsky.social, and Jiro Minier: “Threat Actors Can Do Public-Private Partnership Too”
186
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 12/03/2026
France hosts the EU’s densest cluster of cyber partnerships with Chinese defense-linked universities, raising exposure to dual-use knowledge transfer, EU funding access, and institutional influence. New Natto Thoughts’ piece from @euben.bsky.social www.nattothoughts.com/p/faux-amis-...
nattothoughts.com
Faux Amis: How France Stands Apart in Europe’s High-Risk University Cyber Partnerships with China
France hosts the EU’s densest cluster of cyber partnerships with Chinese defense-linked universities, raising exposure to dual-use knowledge transfer, EU funding access, and institutional influence
011
Reposted by Eugenio Benincasa
Binding Hook @bindinghook.bsky.social · 12/03/2026
Europe is building stronger systems to report vulnerabilities, but it risks overlooking the people who discover the flaws first: independent security researchers, write @euben.bsky.social and Max van der Horst: bindinghook.com/europe-forge... #EUcybersecurity
bindinghook.com
Europe forgets its bug hunters at its own peril
Without safe harbour for independent vulnerability researchers, Europe risks discouraging the reporting its disclosure regime needs
1165
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 12/02/2026
The Tianfu Cup is back this year. See the analysis of the event by Eugenio @euben.bsky.social published today on Natto Thoughts. www.nattothoughts.com/p/the-tianfu...
nattothoughts.com
The Tianfu Cup Returns Under MPS Leadership as AI Takes Center Stage
After a two-year hiatus, the Tianfu Cup returns under MPS lead, combining AI-assisted vulnerability discovery and exploitation, a new competition track, and less transparency in vulnerability handling
065
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 28/01/2026
We continue exploring provincial level’s involvement in cyber operations. See details in analysis by @euben.bsky.social www.nattothoughts.com/p/provincial...
nattothoughts.com
Provincial Tasking, Cross-Provincial Execution: A Case-Based Look at How China Scales Cyber Operations
How decentralized MSS and MPS tasking and market-enabled, cross-provincial execution by commercial firms shape the scale of China’s cyber operations
053
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 16/12/2025
In this post, @euben.bsky.social and the Natto Team assess that provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations. nattothoughts.substack.com/p/the-many-a...
nattothoughts.substack.com
The Many Arms of the MSS: Why Provincial Bureaus Matter in China’s Cyber Operations
Provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations
023
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 13/08/2025
@euben.bsky.social Eugenio’s research explains the elite cyber talent paradox in China - “all people are soldiers” vs “extremely lean.” #Cybersecurity #TalentPipeline #CyberOperations nattothoughts.substack.com/p/few-and-fa...
nattothoughts.substack.com
Few and Far Between: During China’s Red Hacker Era, Patriotic Hacktivism Was Widespread—Talent Was Not
Inside the small, elite circles that powered China’s massive hacker communities in the late 1990s and 2000s.
022
Eugenio Benincasa @euben.bsky.social · 01/08/2025
Can’t wait for this :)
020
Eugenio Benincasa @euben.bsky.social · 31/07/2025
Available here: nattothoughts.substack.com/p/when-privi...
nattothoughts.substack.com
When Privileged Access Falls into the Wrong Hands: Chinese Companies in Microsoft’s MAPP Program
Chinese companies face conflicting pressures between MAPP’s non-disclosure requirements and domestic policies that incentivize or mandate vulnerability disclosure to the state.
010
Eugenio Benincasa @euben.bsky.social · 31/07/2025
Microsoft is probing whether a MAPP leak let Chinese hackers exploit a SharePoint vuln pre-patch. In this new piece for Natto, @dakotaindc.bsky.social, @meidanowski.bsky.social & I dig into: 🏛️ China's vuln reporting rules 📉 Which firms joined/left MAPP since 2018 ⚠️ The risks today’s members pose
1114
Reposted by Eugenio Benincasa
Ryan Gallagher @rjgallagher.co.uk · 25/07/2025
New: Microsoft is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in SharePoint before they were patched, enabling a global campaign of cyberattacks, according to people familiar: www.bloomberg.com/news/article...
bloomberg.com
Microsoft Probing If Chinese Hackers Learned of Flaws Via Alert
Microsoft Corp. is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in its SharePoint service before they were patched, acc...
198
Reposted by Eugenio Benincasa
Binding Hook @bindinghook.bsky.social · 25/07/2025
In the latest Hooked!, editor @katharinegk.bsky.social ties together some fascinating recent research from @benread.bsky.social , @euben.bsky.social, @winnona.bsky.social, and others on private sector elements of Chinese offensive cyber: bindinghook.com/articles-hoo...
bindinghook.com
Hooked! #5: A series of new reports and research shows that China’s tech sector is on the offense
A series of new reports and research shows that China’s tech sector is on the offense
062
Eugenio Benincasa @euben.bsky.social · 21/07/2025
css.ethz.ch/en/center/CS...
css.ethz.ch
Before Vegas: The “Red Hackers” Who Shaped China’s Cyber Ecosystem
This CSS Cyberdefense report by Eugenio Benincasa examines how a core group of red hackers from the 1990s and 2000s laid the groundwork for China’s modern cyber capabilities and traces their trajector...
000
Eugenio Benincasa @euben.bsky.social · 21/07/2025
6/ Sincerely grateful to the all-star team of experts who shared their insights and feedback: Scott Henderson (Google Mandiant), Adam Kozy (SinaCyber), @meidanowski.bsky.social (@nattothoughts.bsky.social), @thegrugq.bsky.social, @Chris St.Myers (SentinelOne), & Charles Li and Zha0 (TeamT5)
030
Eugenio Benincasa @euben.bsky.social · 21/07/2025
5/ The key lesson: what begins in anonymous forums can end in boardrooms and on digital battlefields. Overlooking civilian hacking talent is a strategic risk.
122
Eugenio Benincasa @euben.bsky.social · 21/07/2025
@kimzetter.bsky.social's excellent piece for Wired unpacks the state-linked side of the story, covering the report and Adam Kozy’s research: www.wired.com/story/china-...
wired.com
How China’s Patriotic ‘Honkers’ Became the Nation’s Elite Cyberspies
A new report traces the history of the early wave of Chinese hackers who became the backbone of the state's espionage apparatus.
110
Eugenio Benincasa @euben.bsky.social · 21/07/2025
3/ Some Red 40 hackers have carried out operations on behalf of China’s military and intelligence services. Their informal networks, formed during their teens or twenties as members of the same hacking groups, exemplify tool sharing and collab that underpins China’s APTs MO.
110
Eugenio Benincasa @euben.bsky.social · 21/07/2025
2/ It identifies 40 prominent red hackers — “The Red 40” — who shaped China’s cyber ecosystem from the ground up. It tells the story of how these individuals transitioned from online forums to becoming part of a tightly integrated ecosystem. Full report: css.ethz.ch/en/center/CS...
css.ethz.ch
130
Eugenio Benincasa @euben.bsky.social · 21/07/2025
1/ China’s cyber capabilities didn’t start top-down, they started with raw hacking talent. The new CSS/ETH report "Before Vegas" traces how informal talent shaped China’s cyber ecosystem, moving from online forums to industry leaders (link in thread).
1158
Eugenio Benincasa @euben.bsky.social · 20/07/2025
haha haven't spent too much time around here
000
Eugenio Benincasa @euben.bsky.social · 20/07/2025
Thank you 🙏 really appreciate it!
000
Eugenio Benincasa @euben.bsky.social · 20/07/2025
Thank you! I’d definitely add Alex Josie’s “Spies and Lies” to the book list
240
Eugenio Benincasa @euben.bsky.social · 19/07/2025
Thank you! Looking forward to hearing your thoughts on it
020
Eugenio Benincasa @euben.bsky.social · 19/07/2025
Fully agree, Patrick. I also love his work. He was very kind to review the report and provide feedback before publication 😊
000
Reposted by Eugenio Benincasa
Kim Zetter @kimzetter.bsky.social · 18/07/2025
How did China's top APT hackers come to be? Many were early "Honkers" - patriotic hackers who in late 90s launched low-skill cyberattacks against nations deemed disrespectful to China. But once Honkers developed their skills, PLA/MSS came calling. Based on great research by bsky.app/profile/eube...
wired.com
How China’s Patriotic ‘Honkers’ Became the Nation’s Elite Cyber Spies
A new report traces the history of the early wave of Chinese hackers who became the backbone of the state's espionage apparatus.
05627
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 10/07/2025
How has China advanced its AI development to its current state? No single innovation path in AI can be considered definitive. nattothoughts.substack.com/p/debating-c...
nattothoughts.substack.com
Pick Your Innovation Path in AI: Chinese Edition
China’s advances in AI show the effects of a state approach of “introduce, digest, absorb, re-innovate” and years of debate on the balance between market-driven innovation and state-led development
021
Reposted by Eugenio Benincasa
Winnona @winnona.bsky.social · 09/07/2025
“alignment with CCP priorities offers privileged access to state resources, regulatory favor, and expanded commercial opportunities [to hackers]." NEW Phenomenal report on Chinese civil military fusion and cyber militias by Kieran Green: margin.re/mobilizing-c...
margin.re
Mobilizing Cyber Power: The Growing Role of Cyber Militias in China’s Network Warfare Force Structure
This report examines how China’s cybersecurity industry fields reserve and militia units in support of the PLA and national mobilization system.
051
Reposted by Eugenio Benincasa
Winnona @winnona.bsky.social · 25/06/2025
🚨 NEW PAPER on the 0day Supply Chain 🚨: I gathered open source data & interviewed Gov employees, VR and china researchers to figure out what the zero day marketplace looks like in the U.S. and how it compares to China. key findings below ⬇️- 0/🧵 
www.atlanticcouncil.org/in-depth-res...
atlanticcouncil.org
Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace
If the United States wishes to compete in cyberspace, it must compete against China to secure its offensive cyber supply chain.
22717
Eugenio Benincasa @euben.bsky.social · 13/06/2025
I think European countries are struggling even to allow government teams to do this kind of work, so extending it to broader private sector involvement seems unlikely to me as things stand
110
Eugenio Benincasa @euben.bsky.social · 13/06/2025
I agree they should rethink current approaches, starting from talent development.
110
Eugenio Benincasa @euben.bsky.social · 11/06/2025
To defend, one must first know how to attack” (未知攻,焉知防). This mindset, popularized by a Taiwanese hacker Lin in the 1990s, spread from China's red hackers to CTF teams. Today, it powers China's cyber industry. New piece for @nattothoughts.bsky.social nattothoughts.substack.com/p/defense-th...
nattothoughts.substack.com
Defense-Through-Offense Mindset: From a Taiwanese Hacker to the Engine of China’s Cybersecurity Industry
The belief that offense enables defense in cyberspace, first rooted in China’s 1990s hacker culture, has since permeated the country’s cyber ecosystem
162
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 28/05/2025
The Natto Team explores the development of China's vulnerability research and discovery skills, starting from the vocational college level. Thanks to @euben.bsky.social @dakotaindc.bsky.social Kristin Del Rosso for their previous research on the topic nattothoughts.substack.com/p/when-a-voc...
nattothoughts.substack.com
From Humble Beginnings: How a Vocational College Became a Vulnerability Powerhouse
Qingyuan Polytechnic's focus on vulnerability studies highlights China's continued efforts in gathering vulnerability resources
0127
Reposted by Eugenio Benincasa
Natto Thoughts @nattothoughts.bsky.social · 14/05/2025
The Natto Team continues finding stories of Chinese hackers fascinating as they reveal the motivations behind cyber operations and the evolution of China's information security industry. nattothoughts.substack.com/p/stories-of...
nattothoughts.substack.com
From the World of “Hacker X Files” to the Whitewashed Business Sphere
Jiang Jintao’s journey from hacker to infosec entrepreneur illustrates the blend of ambition, skill, and changes in China's cybersecurity industry
055
Reposted by Eugenio Benincasa
Binding Hook @bindinghook.bsky.social · 12/05/2025
In their latest for #BindingHook, Massimo Marotti, Matteo E. Bonfanti, and Giovanni Faleg of the Italian National Cybersecurity Agency reflect on the process of forming the new #G7CybersecurityWorkingGroup: bindinghook.com/articles-hoo...
bindinghook.com
Sowing the seeds of enhanced cybersecurity cooperation within the G7
Officials from the Italian National Cybersecurity Agency discuss the challenges and successes of creating the new G7 Cybersecurity Working Group
041
Reposted by Eugenio Benincasa
Dan Black @danwblack.bsky.social · 29/04/2025
Fascinating to see reference to GRU unit 20728 from FR relative to Russia's offensive cyber program -- as far as I'm aware, a first from a Western service? www.diplomatie.gouv.fr/fr/dossiers-...
diplomatie.gouv.fr
Russie – Attribution de cyberattaques contre la France au service de renseignement militaire russe (APT28) (29.04.25)
La France condamne avec la plus grande fermeté le recours par le service de renseignement militaire russe (GRU) au mode opératoire d'attaque APT28, (…)
3167
Eugenio Benincasa @euben.bsky.social · 29/04/2025
The report is allegedly titled "Investigation Report on the Incident of US Intelligence Agencies Using Cyberspace to Attack China's Large Commercial Cryptographic Product Providers" (美情报机构利用网络 攻击中国大型商用密码产品提供商事件调查报告)
032
Eugenio Benincasa @euben.bsky.social · 29/04/2025
This article by a Chinese news outlet seems to include the original language of the report: www.stdaily.com/web/gdxw/202... also reported by other outlets such as Xinhua: app.xinhuanet.com/news/article...
stdaily.com
美情报机构对中国发动网络攻击,详情披露
141
Reposted by Eugenio Benincasa
Binding Hook @bindinghook.bsky.social · 28/04/2025
Fellow @euben.bsky.social argues that EU member states should reduce strategic #technologicaldependencies on non-EU countries, particularly those deemed high-risk, and enhance proactive #cybersecurity capabilities. bindinghook.com/articles-bin...
bindinghook.com
Cyber threats are increasingly complex. What can governments do to defend against them?
Virtual Routes fellows look for ways to shrink the gap between cyber threats and defensive capabilities, from regulatory sandboxes to supranational understandings of critical infrastructure.
031
Eugenio Benincasa @euben.bsky.social · 16/04/2025
US: The outing of alleged NSA hackers echoes US DOJ indictments, but with fewer details, no photos, and little evidence. It may reflect broader US.-China trade tensions, or a cyber-specific tit-for-tat to shape the global narrative around cyber conflict.
000
Eugenio Benincasa @euben.bsky.social · 16/04/2025
Taiwan: The second naming and shaming in months, but this one hits harder—sharper tone, more detail, and backed by three top Chinese cybersecurity firms. It follows Taiwanese President’s declaration that China is a “foreign hostile force” and 17 new counter-China initiatives.
100
Eugenio Benincasa @euben.bsky.social · 16/04/2025
In this piece with @nattothoughts.bsky.social's @meidanowski.bsky.social, we dug into China’s two naming-and-shaming campaigns over the past 30 days—targeting alleged Taiwanese and U.S. hackers amid escalating geopolitical tensions. nattothoughts.substack.com/p/wars-witho...
nattothoughts.substack.com
Wars without Gun Smoke: China Plays the Cyber Name-and-Shame Game on Taiwan and the U.S.
China’s security services have called out hackers of an alleged “Internet Army of Taiwan Independence” and of the U.S. National Security Agency, signaling an increasingly confrontational approach
185
Reposted by Eugenio Benincasa
Dakota @dakotaindc.bsky.social · 15/04/2025
My question is did state media add mention of US universities in response to the paper @euben.bsky.social and I wrote last year which included circumstantial evidence of hacks by NWPU? www.sentinelone.com/labs/labscon...
sentinelone.com
LABScon24 Replay | A Walking Red Flag (With Yellow Stars)
Dakota Cary and Eugenio Benincasa explore China's CTF ecosystem, highlighting competitions held by the Ministry of State Security and the PLA.
121
Eugenio Benincasa @euben.bsky.social · 15/04/2025
A more detailed report released in early April by China’s Computer Virus Emergency Response Center (CVERC) attributed the same operations to the U.S. government, though it didn’t name the NSA or specific individuals. www.cverc.org.cn/head/zhaiyao...
cverc.org.cn
100
Eugenio Benincasa @euben.bsky.social · 15/04/2025
Original notice. Source: cn.chinadaily.com.cn/a/202504/15/...
000
Eugenio Benincasa @euben.bsky.social · 15/04/2025
It was a matter of time. Less than a month after outing alleged Taiwanese cyber operatives in an unprecedented move for both its tone and detail, China has done the same with alleged NSA operatives—for the first time. The language echoes that of Western reports, though less detailed.
266
Reposted by Eugenio Benincasa
Patrick Gray @patrick.risky.biz · 10/04/2025
What's happening to @thekrebscycle.bsky.social is disgusting He's one of the most hardworking, dedicated and smart people I'm lucky enough to know, and he showed a LOT of courage when he fought back against attempts to undermine the 2020 election result I hope Americans will stand behind him
614639
Reposted by Eugenio Benincasa
Virtual Routes @virtualroutes.bsky.social · 04/04/2025
We loved having you @weberv.bsky.social, Zoë van Doren, @euben.bsky.social & co! 🙏
021