Maritime: A Neglected Attack Surface

▶ Watch (3:26)

The maritime industry moves 90% of global trade. Ports, shipping lines, and offshore platforms run on digitized legacy systems. Attackers have noticed: NotPetya in 2017 and recent ransomware incidents hit multiple ports. Yet the sector has been under-investigated by OSINT researchers. The team targeted the full ecosystem: ship operators, port terminals, government, and third-party providers. They relied on official search registers like the Alphaliner list and used LLMs to construct queries for maritime-specific protocols.

Email and DNS Failures Reveal Low Security Maturity

▶ Watch (7:27)

Email intelligence showed 41% of maritime organizations had no DMARC policy, making them vulnerable to spoofing. 98% lacked DNSSEC, exposing them to DNS poisoning. 28% had no SPF records. Deeper scanning found a major Asian port authority running a PHP version end-of-life since 2017. A European shipping company exposed 15 MySQL databases. A North American port had 24 critical CVEs exposed. The findings point to a lower security maturity compared to other industries.

Maritime-Specific Protocols Exposed: From GPS to ECDIS

▶ Watch (10:55)

The team found over 10,000 NTRIP services exposed worldwide. NTRIP enables centimeter-level GPS accuracy; exposure risks navigation manipulation. ECDIS systems from a major nautical chart provider ran on AWS with outdated Apache versions (2.4.29 to 2.4.58). Some devices lacked visible authentication. Vessel tracking portals exposed admin interfaces with weak credentials. SNMP enterprise names revealed one Asian navy using a telco on another continent, evidence of systematic maritime infrastructure spoofing.

MCP-Driven OSINT: Giving LLMs Hands to Do the Work

▶ Watch (15:41)

Vlatko Kosturjak explained the architecture: three Model Context Protocol (MCP) servers for Bot, SpiderFoot, and emailsec give the LLM direct tool access. The LLM decides scope, tools, and modules, then runs scans autonomously. A feedback loop lets users dig deeper. Using few MCP servers avoids model confusion. All custom MCP servers and SpiderFoot modules are open-sourced on the Marlink Cyber GitHub. The tool generates a report, recommends fixes, and can write test scripts.

Notable Quotes

90% of the global trade um moves over water MJ Casado · ▶ 3:26

41% of our of all the whole um uh number of organizations exactly um they had no demark policy MJ Casado · ▶ 7:34

more than 10,000 NTIP uh services exposed MJ Casado · ▶ 13:00

evidence of systematic maritime infrastructure spoofing MJ Casado · ▶ 13:47

Key Takeaways

  • Passive OSINT with LLMs and MCP can map large digital attack surfaces efficiently.
  • Over 10,000 NTRIP services globally expose GPS correction data to manipulation.
  • Email security gaps dominate: 98% lack DNSSEC, 41% have no DMARC.

About the Speaker(s)

Vlatko Kosturjak serves as the VP of research at Marlink Cyber with over 20 years of cybersecurity experience. He has held roles including X-ray team leader and CTO, and is passionate about automation and MCP. He created multiple popular open-source offensive tools and contributed to free security software projects. His certifications include CISSP, OSCP, CISM, and many more.