State of the Pops: Mapping the Digital Waters
Vlatko Kosturjak (VP of Research), MJ Casado (Threat and Security Intelligence Analyst)
DEF CON 33 · Day 1 · Main Stage
Overview
In "State of the Pops: Mapping the Digital Waters," MJ Casado and Vlatko Kosturjak present a groundbreaking, passive open-source intelligence (OSINT) investigation into the cybersecurity posture of the global maritime industry. Their talk at the DEF CON Maritime Hacking Village unveils a novel methodology that combines traditional OSINT techniques with the advanced capabilities of large language models (LLMs) and intelligent automation, powered by a custom Model Context Protocol (MCP). This research provides an unprecedented, anonymized overview of digital hygiene and vulnerability exposure across a critical global ecosystem that has historically been under-investigated from a cybersecurity perspective.

Key moments
- 0:00 Introduction, agenda, and speaker introductions
- 2:09 Scope: Passive, anonymized, novel LLM approach
- 3:05 Why maritime: Critical, digitized, under-investigated ecosystem
- 6:35 Methodology: Leveraging LLMs for organization mapping
- 7:00 Key findings: Email intelligence vulnerabilities (DMARC, DNSSEC)
- 8:00 Real-world examples: Outdated PHP, exposed databases, CVEs
State of the Pops: Mapping the Digital Waters
Speakers: Vlatko Kosturjak (VP of Research), MJ Casado (Threat and Security Intelligence Analyst)
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=mVqNxvfaVGg
Overview
In "State of the Pops: Mapping the Digital Waters," MJ Casado and Vlatko Kosturjak present a groundbreaking, passive open-source intelligence (OSINT) investigation into the cybersecurity posture of the global maritime industry. Their talk at the DEF CON Maritime Hacking Village unveils a novel methodology that combines traditional OSINT techniques with the advanced capabilities of large language models (LLMs) and intelligent automation, powered by a custom Model Context Protocol (MCP). This research provides an unprecedented, anonymized overview of digital hygiene and vulnerability exposure across a critical global ecosystem that has historically been under-investigated from a cybersecurity perspective.
The maritime industry, encompassing everything from shipping lines and ports to offshore platforms and government regulators, forms the backbone of global commerce, facilitating over 90% of international trade. Despite its immense importance, rapid digitization has often occurred on legacy IT infrastructure, creating a vast and vulnerable attack surface. Casado and Kosturjak’s work not only quantifies these widespread vulnerabilities—ranging from outdated software and exposed databases to critical infrastructure misconfigurations—but also demonstrates a scalable, automated approach to identify and analyze them. Their findings underscore the urgent need for enhanced digital hygiene and robust security measures within this indispensable sector, highlighting the ripple effects that disruptions here can have on global supply chains, energy security, and national interests.
Background
▶ Watch: Introduction, agenda, and speaker introductions (0:00)
The maritime industry stands as a cornerstone of global infrastructure, with 90% of the world's trade moving across its waters. This vast network, comprising ports, shipping lines, oil tankers, offshore platforms, and an intricate web of service providers, acts as the primary artery of global commerce. Disruptions within this sector, whether accidental or malicious, can trigger cascading failures across supply chains, energy markets, and even national security frameworks, underscoring its critical importance.
Historically, the maritime industry has operated with a degree of physical isolation, often relying on specialized operational technology (OT) systems and bespoke communication protocols. However, a rapid and pervasive wave of digitization has swept through the sector in recent years. This transformation, while bringing efficiencies and advanced capabilities, has largely been built upon legacy IT stacks, incorporating forgotten domains and often relying heavily on vendor-controlled infrastructure. As more operational and corporate systems become internet-facing—including corporate IT, cloud assets, and email infrastructure—the industry's exposure to cyber threats has dramatically increased. This shift has not gone unnoticed by malicious actors, with high-profile incidents like the NotPetya attack in 2017, which severely impacted Maersk, and numerous recent ransomware incidents affecting ports worldwide, serving as stark reminders of the escalating threat landscape.
Despite its critical nature and increasing exposure, the maritime industry has remained significantly under-investigated from an OSINT perspective. While security researchers and intelligence analysts have traditionally focused on sectors like finance, healthcare, big tech, and energy, the maritime ecosystem has largely been overlooked. This oversight creates a dangerous blind spot, as the sector's complex structure—encompassing not only ship operators but also ship managers, port authorities, government regulators, flag states, port security controls, shipbuilders, repair yards, classification societies, logistics providers, and crewing agencies—presents a diverse and interconnected attack surface. The speakers aptly describe it not merely as an industry, but as a vast "maritime ecosystem," which they contend is "one of the most connected, exposed, and under-measured digital ecosystems in the world." Their research aims to bridge this knowledge gap by providing a comprehensive, passive mapping of this critical digital landscape, focusing on digital hygiene and leveraging novel automated techniques to achieve a broad, anonymized overview of vulnerabilities.
Key Findings
▶ Watch: Why maritime: Critical, digitized, under-investigated ecosystem (3:05)
The comprehensive passive OSINT investigation into the maritime ecosystem revealed a widespread landscape of digital hygiene deficiencies and significant vulnerability exposures, painting a picture of an industry struggling to keep pace with modern cybersecurity demands.
A primary area of concern was email intelligence, which exposed fundamental weaknesses in email security protocols. The analysis found that a staggering 41% of the sampled organizations had no DMARC policy implemented. This critical omission leaves them highly susceptible to email spoofing attacks, where threat actors can impersonate legitimate organizations to conduct phishing campaigns, spread malware, or defraud partners. Furthermore, an alarming 98% of the organizations lacked DNSSEC implementation, indicating a remarkably low maturity level compared to other industries. The absence of DNSSEC protection makes these entities vulnerable to DNS poisoning attacks, which can redirect legitimate traffic to malicious sites, facilitating data theft or further compromise. While SPF records were missing in 28% of the cases, a figure the speakers noted as more balanced relative to other sectors, this still presents a significant risk of sender forgery, allowing attackers to send emails appearing to originate from legitimate sources.
Beyond email security, the investigation uncovered critical vulnerabilities in exposed systems. The speakers provided anonymized examples that underscored the severity of these findings:
- A major Asian port authority was found running PHP in a severely outdated version, with its end-of-life status dating back to 2017. This means the software had not received security updates for several years, leaving it exposed to numerous publicly known exploits.
- A European shipping corporation had more than 15 MySQL databases exposed directly to the internet, presenting an open invitation for data breaches.
- An American port exhibited over 24 critical CVEs exposed, indicating a severe lack of patching and system hardening that could lead to remote code execution or complete system compromise.
A deeper dive into one of the exposed MySQL database instances further illuminated the gravity of the situation. Many of these databases were secured with weak or default authentication mechanisms, including common username/password combinations like "root:root," "admin:admin," or "user:operator1234." Some instances even lacked any visible authentication entirely. The sensitivity of the data contained within these exposed databases was profound, encompassing sensitive crew information (including payroll data), bunker and fuel data, vessel maintenance logs, cargo manifests, and vessel routes. Such exposure could facilitate espionage, sabotage, or significant financial theft. The CVEs identified in these systems ranged from older vulnerabilities dating back to 2012-2016 to more recent ones from 2023, highlighting a persistent failure to apply security patches over many years. The speakers emphasized that while these were passive findings and could not be 100% double-checked, the likelihood of their accuracy was very high.
Specific maritime operational technologies and systems also exhibited critical exposures:
- NTRIP (Networked Transport of RTCM via Internet Protocol) services, crucial for high-precision GNSS and GPS systems, were found to be widely exposed, with over 10,000 NTRIP casters visible on the internet globally. This exposure, with examples identified across South America, Scandinavia, and Europe, poses a direct risk of GPS and navigation system manipulation, potentially impacting the centimeter-level accuracy required for safe maritime operations.
- ECDIS (Electronic Chart Display Information Systems), the primary electronic nautical chart providers, showed multiple instances running on AWS infrastructure with outdated software versions, specifically Apache ranging from 2.4.29 to 2.4.58. Many of these devices lacked visible authentication, creating easy access for unauthorized individuals to critical navigation systems.
- Vessel tracking portals were similarly exposed, with numerous management and administrative interfaces accessible online, often secured with weak authentication mechanisms.
An intriguing and potentially significant discovery made possible by their OSINT methodology was the identification of an Asian navy utilizing a telco company located on a different continent, as revealed through SNMP enterprise names. This finding suggests potential systematic maritime infrastructure spoofing, indicating a complex layer of operational security or deception that would be difficult to uncover with traditional methods.
Geographically, the distribution of identified vulnerabilities indicated that Asia-Pacific bore the largest share of exposure at 42%, followed by Europe (28%), North America (18%), South America (5%), Australia (4%), and Africa (3%). These statistics underscore that digital hygiene issues are a global problem within the maritime sector, requiring a coordinated international response.
Technical Deep Dive
▶ Watch: Methodology: Leveraging LLMs for organization mapping (6:35)
The core innovation of this research lies in its unique methodology, which transcends traditional OSINT by integrating Large Language Models (LLMs) with an Agentic AI framework known as the Model Context Protocol (MCP). Vlatko Kosturjak, a self-proclaimed enthusiast of "MCP plumbing and automation," detailed how this protocol effectively gives LLMs "hands" to directly interact with and orchestrate various security tools, moving beyond mere conversational capabilities.
The MCP architecture is designed for an iterative and automated intelligence gathering process. A human operator interacts with an MCP client, typically a chat interface, submitting high-level prompts. The MCP client then communicates with an MCP server, which acts as an intermediary, translating the LLM's directives into actionable commands for a suite of specialized OSINT tools. This server-side orchestration is crucial, as it allows the LLM to dynamically select, configure, and execute tools based on the evolving context of the investigation.
For their research, the team developed custom MCP servers for several key OSINT tools, including theHarvester, a popular tool for gathering open-source intelligence on domains, subdomains, and email addresses. They also created new SpiderFoot models, extending the capabilities of this comprehensive OSINT automation platform to specifically address maritime-related data points. Additionally, a dedicated emailsec MCP server was implemented to perform in-depth checks on email and DNS security configurations, such as DMARC, SPF, and DNSSEC. Crucially, the framework also integrated with existing MCP servers for well-known internet scanning and indexing services like Shodan and ZoomEye, leveraging their vast databases of internet-connected devices and services.
The design philosophy behind having a few, robust MCP servers, each capable of interacting with multiple APIs, was a deliberate choice. Kosturjak explained that from their experience, having too many disparate MCP servers can confuse the LLM, leading to less effective results. By centralizing tool orchestration, the LLM can maintain a clearer context and make more informed decisions. This approach also aligns with intelligence best practices, where corroborating findings from at least two different sources or tools significantly increases confidence in the gathered intelligence.
The LLM's role in this framework extends far beyond simple summarization or anomaly detection, which are common applications. Here, the LLM is empowered to:
- Decide the scope of the investigation based on initial prompts.
- Select the appropriate tools and modules from the available MCP servers.
- Analyze the results from various tools, identifying patterns, anomalies, and potential vulnerabilities.
- Engage in a feedback loop with the human operator, allowing for deeper dives into interesting findings.
This agentic approach significantly enhances the efficiency and depth of OSINT investigations. It enables the automated removal of "obvious honeypots" from the research, ensuring that the focus remains on legitimate, vulnerable targets. The framework's flexibility also allows it to be deployed in various environments, from cloud-hosted solutions for broad-scale analysis to self-hosted setups for maintaining data sovereignty.
Lessons learned during the development of MCP servers highlighted the importance of simplicity: MCPs with fewer, well-defined functions tend to perform best. While some LLMs like GPT models "just work out of the box," others, such as LLaMA or older Qwen models, required additional fine-tuning and development effort. Furthermore, client-side adjustments, such as increasing timeouts or modifying data sources, were sometimes necessary for optimal performance. The speakers also acknowledged the ongoing challenge of security guards in LLMs, requiring careful prompt engineering to craft queries that bypass these restrictions without resorting to malicious intent, ensuring the research remains within ethical boundaries.
Significantly, the entire suite of custom tools developed for this project, including the missing SpiderFoot models and MCP servers, has been released as open-source on Marlin Cyber's GitHub repository. This commitment to open-source sharing empowers other researchers and organizations to replicate, extend, and adapt this powerful methodology for their own cybersecurity needs, whether for passive reconnaissance or, with appropriate permissions, active scanning.
Demo / Proof of Concept
▶ Watch: Key findings: Email intelligence vulnerabilities (DMARC, DNSSEC) (7:00)
The technical deep dive culminated in a compelling demonstration of the MCP framework in action, showcasing its ability to automate passive OSINT scans and generate comprehensive reports. For ethical reasons, the speakers chose scanme.nmap.org as their target, a domain explicitly provided by Nmap for testing purposes, rather than exposing any of the vulnerable maritime organizations discovered in their research.
The demonstration began with a simple, high-level prompt from the human operator to the MCP client: "Do the passive reconnaissance." This single instruction initiated a complex, multi-stage process orchestrated by the LLM and its integrated MCP servers. The system allowed for an optional "human-in-the-loop" confirmation at various stages, enabling the operator to review and approve prompts before execution, adding a layer of control and oversight.
Once the process was underway, the demonstration visibly showed the LLM making intelligent decisions. It began by querying various tools, such as theHarvester, with different presets and flags to gather initial intelligence. Based on the preliminary results, the LLM automatically expanded its scope, running additional modules and tools, including SpiderFoot with more specific configurations, to dig deeper into identified leads. This iterative and adaptive approach meant the LLM wasn't just executing a predefined script but was dynamically adjusting its strategy based on the data it was collecting.
Throughout the process, the system maintained a complete log of all actions taken, including the queries made by the LLM, the tools invoked, and the intermediate results. This transparency is crucial for auditing and understanding the automated intelligence gathering process. Once the scan concluded, the most impressive aspect of the demo unfolded: the LLM automatically generated a detailed report of its findings. This report synthesized all the gathered intelligence, presenting it in a structured and digestible format, effectively eliminating the tedious and time-consuming manual report-writing typically associated with OSINT investigations.
Beyond just reporting findings, the LLM demonstrated its analytical capabilities by offering fix recommendations. For instance, if the scan identified an exposed SSH service, the LLM could then be prompted, "Please tell me what I need to fix right now." It would then provide actionable advice based on best practices. Taking this a step further, the LLM could even generate a script to test the suggested fixes on the system itself. As shown in the demo, if SSH was found, the LLM could provide a script to verify if the SSH configuration had been hardened correctly. This capability transforms the LLM from a mere data aggregator into a proactive assistant for security remediation.
The speakers highlighted that this framework is highly scalable. While demonstrated on a single target, the underlying MCP servers and multi-agent capabilities are designed to handle much larger scopes, enabling comprehensive research across entire industries or vast attack surfaces. This proof of concept effectively validated the innovative approach of combining LLMs and automated tools for intelligent, efficient, and actionable security reconnaissance.
Defensive Implications
▶ Watch: Real-world examples: Outdated PHP, exposed databases, CVEs (8:00)
The findings from "State of the Pops: Mapping the Digital Waters" carry profound implications for cybersecurity defenders within the maritime industry and beyond. The widespread digital hygiene issues and critical exposures necessitate a multi-faceted and urgent response to fortify this vital global infrastructure.
Firstly, the most fundamental recommendation is to reduce the attack surface. The investigation revealed that far too many systems, services, and data repositories are unnecessarily exposed to the internet. Defenders must undertake a thorough inventory of all internet-facing assets and critically assess whether each one absolutely requires public accessibility. If a service does not need to be internet-connected, it should be removed or moved behind secure perimeters. This principle applies to everything from exposed databases and management interfaces to outdated web servers and specific maritime protocols. A comprehensive asset inventory is the foundational step, allowing organizations to understand what they are defending and where their greatest exposures lie.
Secondly, given the maritime industry's reliance on legacy IT and OT infrastructure and the increasing convergence of these two domains, segmentation is absolutely key. The talk underscored how digitization often bridges IT and OT networks, creating pathways for attackers to move from less secure IT environments to critical operational systems. Robust network segmentation, both physical and logical, is essential to contain potential breaches and prevent lateral movement. This involves creating isolated zones for critical OT systems, implementing strict access controls between segments, and monitoring traffic flows for anomalies. This measure alone can significantly mitigate the impact of many of the vulnerabilities identified, such as exposed databases or outdated software on management networks.
Finally, organizations must commit to implementing proactive cybersecurity measures, particularly focusing on hardening and patching. The discovery of outdated PHP versions, ancient Apache servers, and critical CVEs ranging back over a decade highlights a systemic failure in patch management. Defenders must establish rigorous patch management programs, ensuring that all software, operating systems, and firmware are kept up-to-date. Beyond patching, system hardening involves configuring systems securely by disabling unnecessary services, implementing strong authentication mechanisms (moving beyond "root:root" or "admin:admin"), applying the principle of least privilege, and regularly reviewing security configurations. Implementing robust email security protocols like DMARC, SPF, and DNSSEC is also non-negotiable to combat prevalent threats like spoofing and DNS poisoning. The insights from this research provide a clear roadmap for maritime organizations to prioritize and address their most pressing cybersecurity deficiencies, moving towards a more resilient digital posture.
Key Takeaways
- The maritime industry is a uniquely critical, exposed, and historically under-measured digital ecosystem, essential for 90% of global trade but significantly vulnerable to cyber threats.
- Widespread digital hygiene issues persist across the maritime sector, including a high prevalence of organizations lacking DMARC (41%) and DNSSEC (98%) policies, alongside widespread use of outdated software, exposed databases, and numerous critical CVEs.
- Specific operational technologies and systems crucial to maritime operations, such as NTRIP services for high-precision GPS, ECDIS, and vessel tracking portals, are highly exposed with weak or no authentication, posing significant risks of manipulation and compromise.
- The research introduces a novel and highly effective methodology that combines passive OSINT with LLMs and intelligent automation via the Model Context Protocol (MCP), enabling scalable and in-depth mapping of complex attack surfaces.
- The MCP framework empowers LLMs to act as intelligent agents, directly orchestrating security tools, analyzing findings, generating comprehensive reports, and even recommending fixes and creating scripts for validation, significantly streamlining the intelligence gathering and remediation processes.
- Defenders in the maritime industry must urgently prioritize reducing their attack surface, implementing robust IT/OT network segmentation, and committing to continuous system hardening and timely patching to mitigate pervasive vulnerabilities.
About the Speaker(s)
MJ Casado is a Threat and Security Intelligence Analyst with a deep passion for the maritime industry and understanding the tactics, techniques, and procedures (TTPs) of threat actors targeting this sector. Her work focuses on intelligence gathering and analysis, driven by a keen interest in the unique cybersecurity challenges faced by maritime entities. Outside of her professional pursuits, MJ enjoys working out, flying around the world, and considers New York City her favorite spot.
Vlatko Kosturjak serves as a VP of Research, bringing over 20 years of extensive experience in cybersecurity across diverse industries. His career journey includes roles as an X-ray team leader and CTO, but his current obsession lies with Model Context Protocol (MCP) "plumbing and automation." Vlatko is known for his dedication to automating tasks; as he humorously puts it, "if something takes manually one hour then I usually take one day to automate it." This passion for efficiency and scalable solutions underpins the innovative methodology presented in the talk. In his personal life, he enjoys martial arts, though he now jokingly describes himself as more into "sumo wrestling" or at least watching it.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent sector-scoped OSINT research with genuinely useful data on maritime cyber hygiene, slightly undercut by the fact that the headline 'novel methodology' is mostly a wrapper around existing tools dressed in MCP automation. The findings are real and the sector is legitimately underexamined, but the technical contribution is thinner than the abstract implies.
Heather Calloway (CISO) — SOLID
Credible sector-specific OSINT research with real findings — the maritime exposure data is legitimate and the numbers are damning. But it stops at the waterline: the defensive guidance is generic, the institutional accountability question goes unasked, and the MCP methodology demo, while novel, is dressed up more than it needs to be.