[{"content":"Recently, I had the chance to participate in Locked Shields 2026 — organized annually by the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) and known as the world’s largest live-fire cyber defense exercise.\nDuring the exercise, allied nations defend realistic simulated critical infrastructure against continuous attacks from a live Red Team.\nMy Role: Blue Team 04 (Lithuania – Japan) I was embedded with the ThreatHunters sub-team within Blue Team 04, a joint team of Lithuanian and Japanese specialists.\nComing primarily from an offensive security and penetration testing background, joining a threat hunting unit was a great experience:\nLooking at contested networks through an attacker\u0026rsquo;s lens helps anticipate how adversary footholds are established and moved. The pace was fast, the pressure was real, and coordinating in real time with our counterparts from Japan was a highlight of the exercise. Surviving the chaos, learning from top-tier practitioners, and proving that an offensive mindset is just as critical for defense made it an incredible week.\nLooking forward to the next one! ✌️\n","date":"2026-04-25T12:00:00+03:00","image":"/locked-shields-2026.jpg","permalink":"/p/surviving-locked-shields-2026-threat-hunting/","title":"Surviving Locked Shields 2026: Notes from the ThreatHunters Team"},{"content":"I joined the Kibernetinis Labirintas podcast alongside colleague Romualdas Kuzborskis for an in-depth conversation about Physical Security and Penetration Testing.\nEpisode title: „Atvirų durų dienos“ (Open Door Days) — exploring how doors and checkpoints that are supposed to be securely locked down are frequently left wide open to physical and social engineering bypasses.\nWatch the Episode Key Discussion Topics Physical Penetration Testing in Practice: How red teams assess real-world perimeters, badge access architectures, and entry points of corporate facilities. Social Engineering \u0026amp; Tailgating: Why sophisticated digital barriers often fail when human psychology is leveraged—how an attacker can walk straight into restricted floors simply by blending in. Physical \u0026amp; Digital Convergence: Why an organization with top-tier network defenses can still be compromised in minutes if an intruder physically connects a rogue device in an unattended conference room. Common Facility Blindspots: Overlooked flaws in physical access controls, latch slipping, badge cloning, and employee awareness. Episode Links YouTube: Kibernetinis Labirintas #7: Atvirų durų dienos ","date":"2025-07-02T12:00:00+03:00","image":"/kibernetinis-labirintas.png","permalink":"/p/kibernetinis-labirintas-physical-security-podcast/","title":"Kibernetinis Labirintas #7: Physical Security \u0026 'Atvirų Durų Dienos'"},{"content":"At BSides Vilnius 2024, I co-presented collaborative research on \u0026ldquo;Condition-Based Manipulations of Digitally Signed Documents\u0026rdquo; alongside the release of our proof-of-concept tool, DigiDevil.\nThe Problem Many organizations and individuals rely heavily on digital signatures to ensure the authenticity and integrity of electronic agreements, contracts, and invoices. However, standard PDF specifications support dynamic features—such as embedded JavaScript and Optional Content Groups (layers)—that can be abused.\nWe demonstrated that it is possible to craft PDF documents where the visible content changes dynamically based on specific conditions, while the cryptographic signature remains 100% valid:\nChange Over Time: Using embedded timers and script execution, document content changes dynamically from one state to another after opening. Change on Print: The document displays one set of terms on screen, but silently alters values or terms when sent to a physical or virtual printer. Change on File Renaming: The displayed content dynamically adapts depending on the filename of the document (e.g., displaying different contract values depending on how the file is saved). Resources \u0026amp; Links GitHub Repository \u0026amp; Code: advisense/DigiDevil\n(Contains Java/iText source code and sample demonstration PDFs). Media Coverage: Verslo Idėjos / Verslo Žinios: „El. parašas dar negarantuoja sutarties tvirtumo: saugumo ekspertas atskleidė skaitmeninių dokumentų spragą“ ","date":"2024-05-24T12:00:00+03:00","image":"/digidevil.jpg","permalink":"/p/digidevil-condition-based-manipulations-of-digitally-signed-documents/","title":"DigiDevil: Condition-Based Manipulations of Digitally Signed Documents"}]