Dave Luber Profile Banner
Dave Luber Profile
Dave Luber

@NSA_CSDirector

Followers
34,422
Following
335
Media
188
Statuses
938

Director of Cybersecurity at @NSAgov . Follow @NSAcyber for unique, actionable, and timely cybersecurity guidance.

Fort Meade, MD
Joined June 2021
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@NSA_CSDirector
Dave Luber
3 years
Who feels me?
Tweet media one
95
353
3K
@NSA_CSDirector
Dave Luber
2 years
HOW CAN NSA REALLY BE SURE OF THE ATTRIBUTION? I MEAN ANYONE CAN THROW RUSSIAN MALWARE!
Tweet media one
50
257
2K
@NSA_CSDirector
Dave Luber
2 years
I appreciate the #infosec community’s ability to find moments of levity during tough times. 😁 PS. It’s log-for-Jay.
Tweet media one
47
248
2K
@NSA_CSDirector
Dave Luber
2 years
Decisions….
Tweet media one
37
264
1K
@NSA_CSDirector
Dave Luber
2 years
Tweet media one
37
226
1K
@NSA_CSDirector
Dave Luber
5 months
Holiday gift for you. Ghidra 11.0 released! New BSim feature can find structurally similar functions in (potentially large) collections of binaries or object files. Initial support for Rust compiled binaries. Golang improved. +more
36
342
1K
@NSA_CSDirector
Dave Luber
2 years
Today I am especially #grateful for everyone working 24/7 to keep us safe from cyber threats. Your dedication might mean missing the holiday with your family so we can spend #Thanksgiving with ours. Your sacrifice is appreciated!
Tweet media one
35
163
1K
@NSA_CSDirector
Dave Luber
3 years
Cybersecurity month is time to get educated!
Tweet media one
18
197
1K
@NSA_CSDirector
Dave Luber
2 years
Tweet media one
48
182
1K
@NSA_CSDirector
Dave Luber
2 years
@GossiTheDog @NSAGov ¯\_(ツ)_/¯ You missed your chance.
Tweet media one
29
172
1K
@NSA_CSDirector
Dave Luber
2 years
Ever tried real, working enigma? Stop by booth 1843 at #RSAC2022 . Did I mention we are hiring too? @NSACyber
Tweet media one
50
148
1K
@NSA_CSDirector
Dave Luber
2 years
Former NSA or Intel community? Come on back! We now have a vacancy listing to fast track former employees back in. Check it out.
Tweet media one
419
229
1K
@NSA_CSDirector
Dave Luber
2 years
Only 9% of the #cybersecurity workforce consists of Black Americans. As a result, there is a strong need to recruit and hire Black cybersecurity talent. Many organizations are willing to pay for training and certifications. @TyranceIi #ShareTheMicInCyber (11/19)
46
323
1K
@NSA_CSDirector
Dave Luber
1 year
Ghidra 10.3 released. Come to the dark side! Dark themes officially supported. New training course materials for the Debugger. Initial Golang binary analysis for Go 1.18. Many more bugfixes and improvements.
22
276
962
@NSA_CSDirector
Dave Luber
7 months
I really believe that if your infrastructure can’t survive a user clicking a link, you are doomed. I’m the director of cybersecurity at NSA and you can definitely craft and email link I will click…
Tweet media one
48
206
951
@NSA_CSDirector
Dave Luber
6 months
Super awkward.  Got confronted by @birdsarentreal to stop the @NSAgov avian spying programs.   Luckily Chris Krebs @C_C_Krebs was around to help.
Tweet media one
55
124
936
@NSA_CSDirector
Dave Luber
2 years
Ghidra Version 10.1 released! *Remediates the Log4J vulnerability* Includes many new features/capabilities, performance improvements, bug fixes, and many pull-request contributions. Full what's new: Release is here:
11
319
899
@NSA_CSDirector
Dave Luber
3 years
I'm excited to announce the new official account for @NSAGov 's Cybersecurity Director! I'll share insights and information about what we are up to. Look forward to engaging with you.
42
129
879
@NSA_CSDirector
Dave Luber
2 years
Tweet media one
26
106
858
@NSA_CSDirector
Dave Luber
2 years
Find it here:
Tweet media one
11
131
792
@NSA_CSDirector
Dave Luber
3 years
One of my top priorities is hiring diverse talent in cybersecurity. Here are our top five openings - including entry-level jobs. Come join our amazing team!
35
214
758
@NSA_CSDirector
Dave Luber
2 years
@tarah Use of signal is NOT a question nor a consideration for a clearance. Your mentee, like many in this thread, is over imagining the process. As has been stated, a lot of cleared folks use signal. We even recruit for people that understand why this is a good practice!
13
85
757
@NSA_CSDirector
Dave Luber
2 years
New minor release for Ghidra. Debugger improvements as well as bug fixes to the analyzer, C parsing, the decomplier, the gui and more.
13
172
724
@NSA_CSDirector
Dave Luber
7 months
Cybersecurity is a timeless game of cat and mouse. Attackers advance, defenders respond, and the chase continues. Stay agile, stay secure!
Tweet media one
26
101
670
@NSA_CSDirector
Dave Luber
3 years
Curious about post-quantum cybersecurity? We recently updated NSA’s FAQ on the subject.
Tweet media one
21
244
674
@NSA_CSDirector
Dave Luber
2 years
She’s a 10 **because** she uses Ghidra!
@chompie1337
chompie
2 years
she’s a 10 but she uses Ghidra
40
29
479
12
57
669
@NSA_CSDirector
Dave Luber
4 months
Shmoocon swag!
Tweet media one
38
66
642
@NSA_CSDirector
Dave Luber
1 year
@IanColdwater @likethecoins NSA is hiring. Wide array of opportunities across cybersecuiry, capability development and SIGINT. Must get a clearance. This is an amazing stable opportunity if that is now a priority. Hit me up and I’ll get someone in touch to discuss and navigate the process.
55
114
634
@NSA_CSDirector
Dave Luber
3 years
NSA cybersecurity best practices do indeed recommend utilizing ad blocking. Read more from NSA on blocking unnecessary advertising here:
@josephfcox
Joseph Cox
3 years
New: the online advertising ecosystem is so bad—with risk of hackers and harvesting data on people—that U.S. intelligence community has deployed network-based ad blockers, according to letter sent by Congress. Shows just how malicious online advertising is
16
367
673
8
278
620
@NSA_CSDirector
Dave Luber
2 years
We are getting better at sanitizing sensitive intelligence to enable cybersecurity.  What we know is only useful if someone can use it.
Tweet media one
26
102
586
@NSA_CSDirector
Dave Luber
8 months
It’s on!
22
103
575
@NSA_CSDirector
Dave Luber
1 year
Ok internet help me caption this photo with legendary status amongst my friends....
Tweet media one
239
41
568
@NSA_CSDirector
Dave Luber
7 months
I’ll leave this here.
Tweet media one
41
103
535
@NSA_CSDirector
Dave Luber
1 year
Got a naked laptop? Get a big NSA sticker for it. Guaranteed conversation starter! Pick them up at the @NSAGov @NSACyber booth on the RSA floor. #WeAreHiring
Tweet media one
62
40
516
@NSA_CSDirector
Dave Luber
3 years
Reflecting on the last day of cyber security awareness month. #CSAM
Tweet media one
10
75
501
@NSA_CSDirector
Dave Luber
2 years
Sometimes incident response feels like:
Tweet media one
24
69
489
@NSA_CSDirector
Dave Luber
1 year
@jabreity @IanColdwater @likethecoins NSA is actually a place that embraces diversity. I’m definitely down with pink teddy bears. Basically, you do you.
14
27
490
@NSA_CSDirector
Dave Luber
8 months
The average CISO tenure is 18 to 24 months. It’s a hard job. Much of the stress is knowing what to do but not being given the resources to do it. Advocate for security.
Tweet media one
39
132
477
@NSA_CSDirector
Dave Luber
1 year
Active exploitation Citrix devices underway by APT5. @NSACyber threat hunting guidance linked below to identify and remediate this activity. Update to the latest Citrix release, check for compromise, and let us know if you find anything.
10
236
473
@NSA_CSDirector
Dave Luber
3 years
Bravo! Apply here:
11
67
470
@NSA_CSDirector
Dave Luber
7 months
Our ‘Living off the Land’ advisory provides important context on Chinese intrusions into critical infrastructure. You can’t rely on IOCs and malware detection. You need to focus on tradecraft.
Tweet media one
18
143
458
@NSA_CSDirector
Dave Luber
8 months
For NSA there has been, and will be only one definition!
Tweet media one
21
54
448
@NSA_CSDirector
Dave Luber
7 months
Releasing an exploit proof of concept is a hot debate. Some argue it’s educational, but it can also empower malicious actors. We see bulk exploitation rates explode after, but advanced compromises against key victims don’t change a lot. What’s your take?
Tweet media one
100
68
437
@NSA_CSDirector
Dave Luber
11 months
#Ghidra 13.1 is out, including the addition of new training course materials for the Debugger. More contributions for the community!
6
132
428
@NSA_CSDirector
Dave Luber
2 years
Ghidra release anniversary!
Tweet media one
15
49
433
@NSA_CSDirector
Dave Luber
2 years
#CVE -2021-4034 in a system tool called Polkit has me concerned. Easy and reliable privilege escalation preinstalled on every major Linux distribution. Patch ASAP or use the simple chmod 0755 /usr/bin/pkexec mitigation. There are working POCs in the wild.
15
187
428
@NSA_CSDirector
Dave Luber
2 years
The log4j vulnerability is a significant threat for exploitation due to the widespread inclusion in software frameworks, even NSA’s GHIDRA. This is a case study in why the software bill of material (SBOM) concepts are so important to understand exposure.
33
212
416
@NSA_CSDirector
Dave Luber
2 months
Thanks to Rob Joyce for his exceptional leadership of @NSACyber over the last few years! I’m honored to take on this role as the new Director of Cybersecurity at NSA. Cyber is a team sport – I’m looking forward to working with partners across the community. - DPL
47
53
411
@NSA_CSDirector
Dave Luber
8 months
I really could begin and end the whole month with this post. Come on people. We know what we need to do…
Tweet media one
18
97
394
@NSA_CSDirector
Dave Luber
7 months
In case you want to follow the CSD Director’s account:
Tweet media one
22
28
373
@NSA_CSDirector
Dave Luber
7 months
Attackers will work to know your network better than you do. They will find shadow IT, misconfigurations, weak authentication and unpatched devices containing n-days. Discover and fix it before them.   #KnowledgeIsPower #KnowledgeIsSecurity
Tweet media one
18
101
360
@NSA_CSDirector
Dave Luber
3 years
Important @CISAgov alert: Malware inserted into widely used JavaScript library (npm package) AParser.js which reads information stored inside user-agent strings. Developers must update to patched versions: 0.7.30, 0.8.1, 1.0.1
5
258
349
@NSA_CSDirector
Dave Luber
2 years
Cybersecurity awards month. The struggle is real.
Tweet media one
13
45
355
@NSA_CSDirector
Dave Luber
7 months
Admit it. You know stuff you should be fixing.
Tweet media one
15
80
347
@NSA_CSDirector
Dave Luber
2 years
Have you prepared for a DDOS attack? Consider the impact of outages and keep critical sites up using a deliberate mitigation plan.
Tweet media one
12
61
347
@NSA_CSDirector
Dave Luber
2 months
Safe havens for cyber criminals creates disproportionate risk for all of us. Russian tolerance of ransomware actors is a scourge on of the victims. 74% of ransomware revenue goes to Russia-linked hackers:
20
199
340
@NSA_CSDirector
Dave Luber
4 months
We continue to remember the sacrifice of Navy CTIS Shannon M. Kent, five years ago today.  She gave her life "serving in silence," while supporting Combined Joint Task Force - Operation Inherent Resolve in Syria Jan. 16, 2019. She was in an elite military intelligence unit. 1/2
Tweet media one
14
58
326
@NSA_CSDirector
Dave Luber
3 years
We are seeing Chinese targeting of political, economic, military, educational orgs and more to access sensitive data. Our advisory provides mitigations for 50 common Chinese state-sponsored #cyber techniques. Review and take action!
@NSACyber
NSA Cyber
3 years
We collaborated with @CISAgov & @FBI on our #cybersecurity advisory, detailing Chinese state-sponsored actor #TTPs used against U.S. and allied networks. For a thorough understanding of this cyberthreat, read our overview, observed TTPs & mitigations.
Tweet media one
40
432
767
9
159
320
@NSA_CSDirector
Dave Luber
3 years
Proud to announce the launch of our first-ever NSA Cybersecurity Directorate (CSD) Summer Intern Program! Undergrad, grad, and doctoral students can apply today to experience our mission first-hand:
Tweet media one
18
99
321
@NSA_CSDirector
Dave Luber
3 years
@RayRedacted Attackers put in the time to know the network and the devices better than the defenders. That’s how they win.
14
108
318
@NSA_CSDirector
Dave Luber
7 months
Shipping insecure software and relying solely on patching is like launching a leaky ship and hoping to fix it at sea. Secure foundations save you from sinking. #SecureByDesign listen to @CISAgov
Tweet media one
29
65
316
@NSA_CSDirector
Dave Luber
2 years
Mandiant working with VMware to release info on Novel Malware Persistence Within ESXi Hypervisors. Active exploitation found. This is one to watch for the Defense Industrial Base and others with sensitive information targeted by nation states.
5
134
312
@NSA_CSDirector
Dave Luber
7 months
This is what my inbox looks like around the major cybersecurity conferences.
Tweet media one
27
36
303
@NSA_CSDirector
Dave Luber
7 months
In pursuit of free software through cracks and keygens? Beware, the price may be higher than anticipated. Warez are teeming with malware, ready to infiltrate your system. Be warned. #MalwareMenace
Tweet media one
36
57
295
@NSA_CSDirector
Dave Luber
7 months
I have a theory why industry collaboration has gotten easy over the years…
Tweet media one
24
36
289
@NSA_CSDirector
Dave Luber
1 year
Russian government actors have used the Snake malware tool for years for intelligence collection. These technical details will help industry governments find and shut down the malware globally. Help us act!
Tweet media one
35
97
284
@NSA_CSDirector
Dave Luber
8 months
You can learn from NSA’s experience working Red and Blue team engagements. Bad actors will look for easy opportunities to exploit vulnerabilities and compromise networks. Here are the top 10 cybersecurity misconfigurations we see:l along with @CISAgov
16
89
282
@NSA_CSDirector
Dave Luber
2 months
Thrilled that Dave Luber takes the reins today as the new CSD Director! (this is the last NSA post from Rob J, so when the picture changes, don't think he's tweeting about himself. 😄)
Tweet media one
38
31
287
@NSA_CSDirector
Dave Luber
2 years
Incident response toolkits can, and should, vary: IT response vs OT, endpoint vs network, cloud vs on-prem. What’s your must-have and go to capabilities?
Tweet media one
14
47
274
@NSA_CSDirector
Dave Luber
6 months
Happy 5th birthday to our partners at @CISAgov ! The nation is more secure through your great work!
Tweet media one
17
40
273
@NSA_CSDirector
Dave Luber
7 months
@vxunderground @NSAGov @ThomasJFlounder Wasn’t going to use meme this b/c some on my team didn’t get it, but clearly you will appreciate! Ironic that it is the same base picture I chose for this thread.
Tweet media one
14
24
278
@NSA_CSDirector
Dave Luber
3 years
Huge thanks to @PwnieAwards for going out of the way to get @NSAGov our Pwnie! What an awesome honor!
Tweet media one
11
37
268
@NSA_CSDirector
Dave Luber
3 years
Tweet media one
15
21
266
@NSA_CSDirector
Dave Luber
2 years
Meme advisor @Andrew___Morris stops by to help understand the dark and dangerous corners of the internet.
Tweet media one
9
18
264
@NSA_CSDirector
Dave Luber
6 months
Did you know? The @birdsarentreal movement isn’t just a quirky conspiracy theory. It’s a brilliant lesson in disinformation. Watch the TED Talk to see how it teaches us to question what we read online. Before you believe and share, apply critical thinking.
@NSA_CSDirector
Dave Luber
6 months
Super awkward.  Got confronted by @birdsarentreal to stop the @NSAgov avian spying programs.   Luckily Chris Krebs @C_C_Krebs was around to help.
Tweet media one
55
124
936
39
66
266
@NSA_CSDirector
Dave Luber
2 years
@tarah PS- wanted to be explicit and authoritative on the process. I totally agree with your point that use of encryption does not mean you have something to hide !
3
42
264
@NSA_CSDirector
Dave Luber
1 year
I’m at Shmoocon- my happy place. Feel free to grab me for a chat! Anything from geeky topics to how to navigate NSA hiring are all fair game.
29
23
257
@NSA_CSDirector
Dave Luber
2 years
Take this seriously. The small details make all the difference. Don’t write your own crypto…
Tweet media one
36
47
250
@NSA_CSDirector
Dave Luber
3 years
New surge in Microsoft Exchange server exploitation underway. You Must ensure you are patched and monitoring if you are hosting an instance.
@KyleHanslovan
Kyle Hanslovan
3 years
Keep your Exchange servers safe this weekend. @HuntressLabs has seen 140+ webshells across 1900+ unpatched boxes in 48hrs. Impacted orgs thus far include building mfgs, seafood processors, industrial machinery, auto repair shops, a small residential airport and more. #ProxyShell
Tweet media one
5
146
285
8
142
248
@NSA_CSDirector
Dave Luber
7 months
With AI becoming increasingly entwined in advanced systems, the NSA’s new AI Security Center is a crucial step toward ensuring protection. NSA will uncover threats and guide trusted use in national security systems
Tweet media one
26
56
239
@NSA_CSDirector
Dave Luber
7 months
Me checking messages after posting about phishing.
Tweet media one
10
31
240
@NSA_CSDirector
Dave Luber
3 years
Lots of good recommendations from @CISAgov and @FBI on how to defend networks from ransomware. Check your back ups and make sure contacts are current in your incident response plan before you head into the long weekend.
3
81
240
@NSA_CSDirector
Dave Luber
1 year
This Memorial Day, reflecting on the soberness of our mission and those we support. In cyber, our job is to keep our warfighters, cryptologists, allies, and nation secure. May we never fall short and may we always remember and honor those who have made the ultimate sacrifice.
Tweet media one
4
42
236
@NSA_CSDirector
Dave Luber
4 months
Hey @SwiftOnSecurity we need to convince @taylorswift13 to swing by @NSAGov and @NatCryptoMuseum to see some cool cyber stuff! #TaylorSwift
@intelhistorian
Vince Houghton
4 months
Ohhhhhh. You know what this means? @taylorswift13 will be 20 mins away from the @NatCryptoMuseum in a week…
1
3
24
50
37
235
@NSA_CSDirector
Dave Luber
7 months
Tweet media one
31
24
234
@NSA_CSDirector
Dave Luber
2 years
@Xswanke_Xian Rob manages Rob's tweets!
15
2
227
@NSA_CSDirector
Dave Luber
3 years
Just another day scaring APT teams and ransomware crews.
Tweet media one
9
24
227
@NSA_CSDirector
Dave Luber
3 months
Look who is in London! Thanks for the hospitality @NCSC and @GCHQ !
Tweet media one
20
11
233
@NSA_CSDirector
Dave Luber
2 years
Good luck out there!
6
29
225
@NSA_CSDirector
Dave Luber
7 months
The struggle is real.
16
23
231
@NSA_CSDirector
Dave Luber
11 months
Who remembers the rainbow books? Cybersecurity information before there was infosec twitter!
@NSACyber
NSA Cyber
11 months
Since the earliest days of computers, NSA has been focused on ensuring security for all. The Rainbow Series was the start of cybersecurity as we know it today. Read the original guidance here:
Tweet media one
25
76
253
33
31
222
@NSA_CSDirector
Dave Luber
2 years
It is worth your time to learn about this tool that GCHQ gave to the community. It is powerful and flexible for a range of activities including data manipulation and analysis.
@BSidesCharm
BSidesCharm
2 years
Let’s Get Cooking with CyberChef A very advanced malware analysis and data manipulation tool is made easy to understand by @marcellelee at @BSidesCharm 2022
1
36
162
7
60
220
@NSA_CSDirector
Dave Luber
7 months
It’s been fun!
17
29
220
@NSA_CSDirector
Dave Luber
2 years
Start your zero trust journey. Here’s the NSA guide to embracing a zero trust security model.
Tweet media one
8
46
216
@NSA_CSDirector
Dave Luber
1 year
This year we have two working enigmas at RSA. Secret message a friend!  Just for kicks we also brought a rare Hebern device. Is it a flex? Yeah. 💪 Stop by and play with a real enigma. 🔥 #WeAreHiring Booth 549. @NSACyber
Tweet media one
11
39
213
@NSA_CSDirector
Dave Luber
2 years
Crypto trending?!!?
Tweet media one
6
18
217
@NSA_CSDirector
Dave Luber
2 years
Happy first anniversary to the NSA Cybersecurity Collaboration Center! It's amazing to see your progress an impact.
Tweet media one
14
21
208
@NSA_CSDirector
Dave Luber
2 years
We made it to Friday everyone! @
14
35
208