Boik Su
Boik Su
Senior Cyber Security Researcher
CyCraft Technology

Boik Su is a senior cybersecurity researcher at CyCraft Technology and is currently focused on cloud security, AD security, web security, and threat hunting. He takes an active role in the cybersecurity community and has delivered speeches at multiple seminars across the globe including HITCON, HITB, and HackerOne. He still participates in CTF competitions including SECCON CTF in Japan and HITCON CTF in Taiwan and has submitted multiple reports to bug bounty programs and open-source projects.

SPEECH
5/16 (Thu.) 16:30 - 17:00 7F 701F Zero Trust Forum
Public CTI Source Pollution - A Hidden Threat in Cybersecurity

Businesses face ZTA hurdles due to external service reliance. Gartner's 2026 forecast highlights asset tracking challenges, leading to data aggregation from sources like CMDB, CISA's KEV, NIST NVD. Stringent management of these sources is crucial for resilient security in evolving threats.

In this talk, we will discuss the risk of source pollution increases. If any source is susceptible to manipulation, a successful modification will perhaps lead to information confusion, unwanted downloads, or even catastrophic security events such as DoS attack (faked GeoIP) and arbitrary code execution.