Security BSides Las Vegas 2025

Stopping the Nuclear Apocalypse with Threat Intel (Token 11)

Sometimes in our industry you get to put on your supersuit. In March of 2022 my team and I uncovered an attack on a customer that was specifically targeted at backdooring/incapacitating nuclear reactor control systems.

This is our story.


Please see above abstract.

This is a short talk talking about what we saw that day, and how we used threat intel on top of our X&Os playbooks to understand that what we were looking at was a way bigger attempt than it appeared.

The speaker's profile picture
Paul Miller

Paul is an Infosec leader who started in systems hardening and laying traps for attackers nearly 30 yrs. ago. He is now a Defense Lead at Broadcom as part of the Carbon Black and Symantec teams. His areas of focus are Threat Research, Response, and personal privacy.