Sunshine Cyber Conference 2025 Agenda
Loading...
Agenda is subject to change.
Loading...
Agenda is subject to change.
Loading...

December 9, 2024—Tampa, Fla—Cyber Florida at USF is proud to announce Governor Ron DeSantis’ appointment of Director Ernie Ferraresso to the Florida Cybersecurity Advisory Council. This appointment highlights the state’s unwavering commitment to enhancing cyber defense and safeguarding critical infrastructure.
Ferraresso, a distinguished veteran of the United States Marine Corps, brings a wealth of experience and leadership to the council. As Cyber Florida’s director, he spearheads efforts to advance the state’s cybersecurity initiatives through education, outreach, research, and workforce development. Ferraresso also serves as a Senior Fellow at Auburn University’s McCrary Institute for Cyber and Critical Infrastructure Security, contributing to national strategies for securing vital systems against cyber threats.
“I am honored to join the Florida Cybersecurity Advisory Council and support the state’s mission to strengthen its defenses against evolving cyber threats,” said Ferraresso. “Cyber Florida’s commitment to collaboration and innovation aligns seamlessly with the council’s goals, and I look forward to contributing to a safer and more secure Florida.”
Ferraresso earned his bachelor’s degree from Barry University and has dedicated his career to addressing the challenges of cybersecurity and critical infrastructure protection. His expertise will help guide the council in shaping policies and strategies to bolster Florida’s cyber resilience.
The Florida Cybersecurity Advisory Council plays a pivotal role in providing guidance to protect the state’s critical systems and infrastructure, ensuring Florida remains at the forefront of cybersecurity preparedness.
Ferraresso is available for interviews through December 18, 2024. Please make arrangements through Cyber Outreach Manager Jennifer Kleman at jennifer437@cyberflorida.org. For more information about Cyber Florida and its mission to advance cybersecurity in the state, visit https://cyberflorida.org/.
ABOUT CYBER FLORIDA AT USF
The Florida Center for Cybersecurity at the University of South Florida, commonly referred to as Cyber Florida at USF, was established by the Florida Legislature in 2014. Its mission is to position Florida as a national leader in cybersecurity through comprehensive education, cutting-edge research, and extensive outreach. Cyber Florida leads various initiatives to inspire and educate both current and future cybersecurity professionals, advance applied research, and enhance cybersecurity awareness and safety of individuals and organizations.
Dr. Sunny Wear — Application pen tester, author, and bug bounty enthusiast
Dr. Sunny Wear began her career as a developer, spending countless hours maintaining others’ code—a humbling experience, as she describes it. Realizing she wanted a different path, a friend suggested exploring cybersecurity at just the right time. Together, they tackled the CISSP exam, which Dr. Sunny passed, igniting her passion for application penetration testing.
Now an accomplished author and proud bird mom, Dr. Sunny discusses her Burp Suite Cookbook, a practical guide to identifying, testing, and exploiting vulnerabilities in web applications and APIs.
The show begins with Jack Clabby of Carlton Fields, P.A., joined by resident cybersecurity expert Kayley Melton, analyzing the Star Health Insurance (India) data breach, where the company’s CISO has been accused of selling sensitive data for $43,000.
.
Follow Dr. Sunny on LinkedIn: Dr. Sunny
Follow Dr. Sunny on Twitter: Dr. Sunny
Learn more about Sunshine Solutions: Sunshine Solutions

LandUpdate808 is a malicious downloader that distributes malicious payloads disguised as fake browser updates. The downloader is usually hosted on malicious or compromised websites. LandUpdate808 was identified by the Center for Internet Security as a top ten observed malware in quarter three of 2024, landing as the second most prominent identified malware.
LandUpdate808 redirects website visitors to first download the loader for the fake update content. The redirect also adds a cookie to the targeted user which has been observed with the naming conventions “isDone” or “isVisited11”. The cookie’s value is set to true after the operation is successful. The cookie has an expiration date of four days and will cause the malware to skip over the previous steps if the cookie is detected. The fake update page is disguised as an out-of-date Chrome notification with a blue download button labeled “Update Chrome”. When clicked, the button will link to an “update.php” file. The payload has been observed as a JS, EXE, and MSIX file that changes file type frequently. Recent reporting has identified multiple domains being tied to the same IP address, a potential indicator that the LandUpdate808 operation is expanding operations.
We recommend monitoring your network for the following indicators of compromise to identify if users have been potentially compromised by LandUpdate808 and the related payloads.
| Type | Indicator |
|---|---|
| Domains – Malicious Payloads |
netzwerkreklame[.]de |
| Domains – Malicious Payloads |
digimind[.]nl |
| Domains – Malicious Payloads |
monlamdesigns[.]com |
| Domains – Malicious Payloads | sustaincharlotte[.]org |
| Domains – Malicious Payloads | chicklitplus[.]com |
| Domains – Malicious Payloads | espumadesign[.]com |
| Domains – Malicious Payloads | owloween[.]com |
| Domains – Malicious Payloads | Wildwoodpress[.]org |
| Domains – Malicious Payloads | napcis[.]org |
| Domains – Malicious Payloads | sunkissedindecember[.]com |
| Domains – Malicious Payloads | rm-arquisign[.]com |
| Domains – Fake Update Page Code | kongtuke[.]com |
| Domains – Fake Update Page Code | uhsee[.]com |
| Domains – Fake Update Page Code | zoomzle[.]com |
| Domains – Fake Update Page Code | elamoto[.]com |
| Domains – Fake Update Page Code | ashleypuerner[.]com |
| Domains – Fake Update Page Code | edveha[.]com |
| Domains – Initiated Requests for Content | razzball[.]com |
| Domains – Initiated Requests for Content | monitor[.]icef[.]com |
| Domains – Initiated Requests for Content | careers-advice-online[.]com |
| Domains – Initiated Requests for Content | ecowas[.]int |
| Domains – Initiated Requests for Content | sixpoint[.]com |
| Domains – Initiated Requests for Content | eco-bio-systems[.]de |
| Domains – Initiated Requests for Content | evolverangesolutions[.]com |
| Domains – Initiated Requests for Content | natlife[.]de |
| Domains – Initiated Requests for Content | sunkissedindecember[.]com |
| Domains – Initiated Requests for Content | fajardo[.]inter[.]edu |
| Domains – Initiated Requests for Content | fup[.]edu[.]co |
| Domains – Initiated Requests for Content | lauren-nelson[.]com |
| Domains – Initiated Requests for Content | netzwerkreklame[.]de |
| Domains – Initiated Requests for Content | digimind[.]nl |
| Domains – Initiated Requests for Content | itslife[.]in |
| Domains – Initiated Requests for Content | ecohortum[.]com |
| Domains – Initiated Requests for Content | thecreativemom[.]com |
| Domains – Initiated Requests for Content | backalleybikerepair[.]com |
| Domains – Initiated Requests for Content | mocanyc[.]org |
Samala, A. (2024b, October 15). New Behavior for LandUpdate808 Observed. Malasada Tech. https://malasada.tech/new-behavior-for-landupdate808-observed/
Samala, A. (2024a, July 2). The LandUpdate808 Fake Update Variant. Malasada Tech. https://malasada.tech/the-landupdate808-fake-update-variant/
Threat Advisory created by The Cyber Florida Security Operations Center. Contributing Security Analysts: Benjamin Price

December 2, 2024—Tampa, Fla—Cyber Florida at USF is proud to announce the launch of phaseZERO: Innovation Incubator, an innovative seed fund initiative designed to support Florida-based researchers and emerging entrepreneurs in transforming cutting-edge cybersecurity ideas into thriving businesses. With a focus on commercializing cybersecurity innovations, strengthening critical infrastructure, and creating new opportunities, phaseZERO aims to establish Florida as a national leader in cybersecurity entrepreneurship.
Modeled after the Small Business Administration’s SBIR/STTR Phase I programs, phaseZERO addresses critical gaps in seed funding and provides expert mentorship, complementing existing statewide efforts like the Florida High-Tech Corridor, I-Corps, and local incubators and accelerators.
“This program is about removing barriers for innovators,” said Dr. Manish Agrawal, Cyber Florida at USF academic director at Cyber Florida and USF professor. “By providing funding and mentorship without taking equity, we’re enabling Florida’s entrepreneurs to focus on what matters most: building solutions that strengthen our cybersecurity resilience.”
Program Highlights
For this round of funding, phaseZERO will award up to $60,000 each to up to four emerging Florida companies (not to exceed $240,000 total) selected through a rigorous, three-stage evaluation process:
Funded companies gain access to Cyber Florida’s expansive network of state innovation ecosystem partners, including universities, accelerators, and industry leaders.
Timeline
Through phaseZERO, Cyber Florida continues its mission to foster research partnerships, attract cybersecurity companies to Florida, and enable the creation of new ventures.
For more information about phaseZERO, application details, and how to get involved, visit cyberflorida.org/phasezero.
ABOUT CYBER FLORIDA AT USF
The Florida Center for Cybersecurity at the University of South Florida, commonly referred to as Cyber Florida at USF, was established by the Florida Legislature in 2014. Its mission is to position Florida as a national leader in cybersecurity through comprehensive education, cutting-edge research, and extensive outreach. Cyber Florida leads various initiatives to inspire and educate both current and future cybersecurity professionals, advance applied research, and enhance cybersecurity awareness and safety of individuals and organizations.

Teacher: Amber Jones
School: Port St. Joe High School
County: Gulf
Amber Jones is an outstanding teacher in Gulf County, Florida. Amber is a dynamic force in cybersecurity education at Port St. Joe High School with 15 years of experience. As the technology teacher for grades 8 through 12, she brings innovation to life through her courses in digital information technology, gaming, and yearbook. Beyond the classroom, she leads as the eSports coach for both junior high and high school, inspires as the girls weightlifting coach, and guides as the senior class sponsor.
Amber’s impressive academic journey includes a degree in business information technology from Troy University and a master’s degree in educational leadership from Grand Canyon University. At home, she is a devoted mother to two wonderful daughters. Her husband plays a pivotal role at Port St. Joe High School as the athletic director and head coach for football, girls weightlifting, and softball.
Next year, Amber plans to bring her students to CyberLaunch 2025 to show off their skills and compete for some really cool prizes! We are so grateful for Amber’s contributions to both the students in Florida and the field of cybersecurity education!
Would you like to be featured in our Teacher Spotlight? To nominate yourself or another deserving teacher, complete the interest form below!

According to The Multi-State Information Sharing and Analysis Center’s (MS-ISAC) monitoring services, SocGholish has retained its position as the most prevalent malware in Q3 2024, accounting for 42% of observed infections. SocGholish is a JavaScript-based downloader that spreads primarily through malicious or compromised websites that present fake browser update prompts to users. Once deployed, SocGholish infections can facilitate further exploitation by delivering additional malicious payloads.
SocGholish, also known as “FakeUpdates,” has emerged as the leading malware in Q3 2024. This malware has been active since 2018 and operates as a JavaScript-based downloader that exploits drive-by-download techniques to gain initial access. SocGholish primarily spreads through compromised websites, which present fake browser or software update prompts to unsuspecting users. When users download and run the updates, they execute a malicious payload that establishes communication with SocGholish’s command-and-control (C2) infrastructure.
The malware typically delivers its payload via direct download of JavaScript files or, less frequently, within obfuscated ZIP archives to evade detection. The attackers have continued to adapt, using techniques such as homoglyphs in filenames to bypass string-based detection methods. Once deployed, SocGholish conducts reconnaissance on infected systems, identifying users, endpoints, and potentially critical assets such as Active Directory domains. In about 10% of cases, the malware escalates to delivering second-stage payloads, including remote access tools (RATs) like Mythic, replacing previously popular choices like NetSupport.
SocGholish serves as an initial access broker, facilitating further exploitation by delivering additional malware, including ransomware variants such as LockBit and WastedLocker. Its activities are often precursors to larger attacks, making it a critical threat to monitor. Infections may involve domain trust enumeration and script-based data exfiltration, primarily executed in memory, complicating detection efforts. Organizations are advised to implement preventive measures, such as disabling automatic JavaScript execution, monitoring for unusual script activity, and swiftly isolating infected hosts to mitigate the impact of potential intrusions.
| Type | Indicator |
|---|---|
| IP |
83[.]69[.]236[.]128 |
| IP |
88[.]119[.]169[.]108 |
| IP |
91[.]121[.]240[.]104 |
| IP | 185[.]158[.]251[.]240 |
| IP | 185[.]196[.]9[.]156 |
| IP | 193[.]233[.]140[.]136 |
| IP | 31.184.254[.]115 |
| Domain | aitcaid[.]com |
| Domain | 0qsc137p[@]justdefinition.com |
| Domain | advancedsportsandspine[.]com |
| Domain | automotivemuseumguide[.]com |
| Domain | brow-ser-update[.]top |
| Domain | circle[.]innovativecsportal[.]com |
| Domain | marvin-occentus[.]net |
| Domain | photoshop-adobe[.]shop |
| Domain | pluralism[.]themancav[.]com |
| Domain | scada.paradizeconstruction[.]com |
| Domain | storefixturesandsupplies[.]com |
| Domain | 1sale[.]com |
| Domain | taxes.rpacx[.]com |
| Domain | *.signing.unitynotarypublic[.]com |
| Domain | *.asset.tradingvein[.]xyz |
| Domain | Column 2 Value 23 |
| Domain | change-land[.]com |
SocGholish operates as a JavaScript-based malware loader that initially infects victims through compromised websites, presenting them with fake browser or software update prompts. Once users click to “update,” the malware executes a JavaScript payload, connecting back to the attacker’s command and control (C2) server to deliver additional payloads.
Image 1 of SocGholish Payload Delivery
Image 2 of SocGholish Payload Delivery
Image 3 of SocGholish Payload Delivery via Fake Google Alerts
Payload details:
By delivering these targeted payloads, SocGholish operators can gain persistent access, conduct extensive reconnaissance, and potentially disrupt critical systems. These payloads make SocGholish not only a potent malware threat but also a significant enabler of larger ransomware and espionage campaigns across various industries.
The Center for Internet Security, Inc (October 23, 2024) Top 10 Malware Q3 2024 https://www.cisecurity.org/insights/blog/top-10-malware-q3-2024
Red Canary (2024) SocGholish https://redcanary.com/threat-detection-report/threats/socgholish/
MITRE ATT&CK (March 22, 2024) SocGholish https://attack.mitre.org/software/S1124/
Blackpoint Cyber (June 21, 2024) AsyncRAT, NetSupport RAT, and VssAdmin Abuse for Shadow Copy Deletion https://blackpointcyber.com/resources/blog/asyncrat-netsupportrat-vssadmin-abuse-for-shadow-copy-deletion-soc-incidents-blackpoint-apg/
Proofpoint (November 22, 2022) Part 1: SocGholish, a very real threat from a very fake update https://www.proofpoint.com/us/blog/threat-insight/part-1-socgholish-very-real-threat-very-fake-update
ReliaQuest (January 30, 2023) SocGholish: A Tale of FakeUpdates https://www.reliaquest.com/blog/socgholish-fakeupdates/
Threat Advisory created by The Cyber Florida Security Operations Center. Contributing Security Analysts: Yousef Blassy, Uday Bilakhiya, Thiago Pagliaroni, and Kayla Walker.
Join as we once again convene some of the world’s leading scholars to discuss China’s power projection through cyberspace. Since this group last convened, the world has seen an explosion in the availability and use of artificial intelligence (AI) as well as an extension of the digital attack surface. Some questions they’ll ponder include: How might an AI capability enhance China’s security? What is China’s current cyberspace strategy and how might it be augmented by AI? Will AI make China more effective with cyber-enabled information operations, cyber espionage, and offensive cyber? How might China’s terrestrial ambitions be reflected in cyberspace? Don’t miss this opportunity to hear some of the top experts discuss cyberspace, China, and national security!
Moderator: Dr. Mark Grzegorzewski
Panelists:

Cyber Florida at USF’s Security Operations and Cybersecurity Apprenticeship Program (SOCAP) employs up to 10 students each semester, with opportunities for students to remain in the program for multiple terms. Through this innovative program, SOCAP interns gain hands-on experience addressing real cybersecurity issues for various clients, effectively extending the capabilities of client IT teams.
Managed by Ryan Irving and Duy Dao, SOCAP gives students valuable exposure to the day-to-day operations of a security operations center. Leveraging tools like Microsoft Defender, Crowdstrike, Stamus Networks, MS-ISAC Albert, Recorded Future, Magnet Forensics, Belkasoft Forensics, Volexity, and more, Irving assigns work tickets—real security alerts or issues—that need investigation. Each day, students select or are assigned tickets from the system, allowing them to work on current cybersecurity tasks and engage in practical problem-solving.
The University of South Florida (USF) Information Technology (IT) Department is among the clients benefiting significantly from SOCAP’s services. “The SOCAP partnership with USF IT is fantastic,” says Irving. “Students aren’t just performing real cybersecurity tasks; they’re actively improving the security of the university’s IT infrastructure while honing their skills in a real-world environment.”
In addition to ticket-based troubleshooting, SOCAP students take on proactive threat-hunting roles, scouring resources to detect potential indicators of compromise and preparing threat advisories for Cyber Florida’s threat room page on its website.
SOCAP students like Alessandro Lovadina, Erika Delvalle, and Ben Price bring diverse skills and interests, creating a collaborative team environment.
Lovadina is passionate about coding projects, like building web applications. “With AI, cybersecurity is crucial; all students should learn the basics of cybersecurity,” he notes.
Delvalle finds excitement in threat-hunting tickets. “It never gets boring,” she says. “You’re always learning something new.”
Price enjoys challenging issues that expand his research skills and expertise. “It’s fulfilling; it’s important,” he says.
SOCAP students have the freedom to conduct their own research and troubleshoot using open-source information and reliable online resources. The program’s hybrid format allows students to work both in-office and remotely, providing a dynamic environment that complements their class schedules. This flexibility gives SOCAP interns a comprehensive view of security operations and invaluable career experience.
Irving also incorporates regular training exercises in collaboration with the USF IT team. “Monthly simulated events allow students and staff to practice incident response skills together,” he says. “We invite USF IT to join these sessions, so that we can learn and improve our response capabilities as a team.”
Dennis Guillette, Director and Security Architect of USF IT, expressed his appreciation for SOCAP students’ contributions to the university’s cybersecurity efforts. “I would like to extend my deepest gratitude to the SOCAP students for their outstanding hard work and dedication. Their impressive technical knowledge and exceptional troubleshooting skills have been invaluable to our security posture. Their commitment to excellence and ability to tackle complex security challenges have significantly strengthened us. Thank you for setting a high standard of professionalism and expertise.”
Cyber Florida’s SOCAP internship program at USF continues to be a valuable resource for students and the university alike, advancing cybersecurity skills and bolstering the state’s defenses. It serves as a model for other schools.
