Apartment Wi-Fi as a Nation-State Entry Point
Apartment complexes that share a single Wi-Fi network across all tenants create a flat LAN every resident joins. Case, who does incident response professionally, keeps finding this configuration in the field. Attackers target tenants who work at government or defense organizations. They infect one laptop on the shared network. That laptop carries the malware back to the office. The technique is easy to detect and easy to stop. No one stops it.
Bastion Host 3: The Host No One Claimed
A major European communications company ran five bastion hosts. Everyone used host 3 because it stayed up and was fully patched. Hosts 1, 2, 4, and 5 sat unupdated and unused. Case spent 30 minutes asking who maintained host 3. Nobody on the team claimed it. The answer was the attackers. The initial entry: a USB drive labeled “Tommy’s homework,” found in the parking lot. It seeded the compromised host, which then pushed malware through the artifact repo and into production.
Third-Party CI/CD: Three Years Inside
A company outsourced its CI/CD pipeline to a SaaS provider and connected it directly to production, bypassing firewall controls. The provider had been compromised months earlier. The attacker moved client to client through internal weaknesses in the provider’s platform until finding the target. The intrusion ran for three years before anyone detected it. The targeted company provided services Case said everyone uses daily. A signed SLA provides no protection once the provider itself is the attack vector.
LinkedIn, Air Gaps, and a Medical Manufacturer
Attackers watched a target employee on LinkedIn for five years as she rose to documentation specialist, gaining access to all company files. They used AI-generated recruiter profiles, detectable by eyes centered in every photo, to build rapport. They war-dialed the city to map the plant, finding Modbus systems on Shodan despite nominal air-gapping. When a maintenance technician walked onto the floor with a mobile hotspot, lab equipment connected directly to AWS US-East-1 and began exfiltrating data. The air gap had never existed.
Nation-States Don’t Wait for the Boom
The government of the targeted country estimated 500,000 people would have died. The goal was to make medicine behave like salt water. Patients would receive treatment, not improve, and die slowly. The attacker aimed to shrink a specific population to acquire territory. None of the four incidents detonated visibly. Defenders who watch for a crater miss all of them. The attackers collected intelligence over years and expected to never break anything obvious. That patience is what makes these attacks hard to find.
USB Ports, SSH Keys, and Third-Party Trust
52% of ICS attacks use USB drives. New USB malware detected as recently as July 2025 does nothing visible. It sits on the system and watches. In the bastion host incident, SSH keys with no passphrases sat in a shared public folder. Third-party providers who can mutate production need the same vetting as any internal hire. Log what they push. Monitor it. Most critical infrastructure runs on 20-year-old systems, but basic visibility is still achievable and is the most practical control available.
Notable Quotes
I kid you not, this still happens. Nathan Case · ▶ 10:53
people suck. Nathan Case · ▶ 22:51
We’re never going to get this again. Nathan Case · ▶ 30:03
Let’s be frank, there is no air gap. Nathan Case · ▶ 35:34
Key Takeaways
- Shared apartment Wi-Fi lets attackers pre-infect government laptops before they ever reach the office.
- The most popular, most patched bastion host was quietly maintained by the attackers for months.
- A third-party CI/CD provider with production access is an inside threat until proven otherwise.
- Air gaps fail when employees carry hotspots and USB drives onto manufacturing floors.
- Nation-state attacks have no boom; defenders who wait for a crater will miss every one of them.
- 52% of ICS attacks use USB drives; locking down endpoints and monitoring outbound DNS is a start.
About the Speaker(s)
Nathan Case is a cybersecurity engineer and strategist with over two decades of experience defending critical infrastructure and leading incident response at the highest levels. His career spans Amazon Web Services, McKesson, and defense-focused startups, where he architected platforms for healthcare, government, and national security. He has led global security teams, supported cyber operations across multiple countries, and advised enterprise executives and government leaders on risk and resilience.
Jon McCoy is a software security architect with over 20 years of experience in software development and cybersecurity. His background spans .NET development and application security, with a focus on proactive defense and secure coding. He contributes regularly to the OWASP community and has spoken at events including OWASP Global AppSec.