north, to Cybersecurity
@north@xn--8r9a.com avatar

Look, reporters, I'm not going to beg you to cover my , but I'm not above it either.

For the three reporters who have written articles about this, and the one who provided invaluable guidance, my gratitude is endless. This post doesn't apply to you, nor "the feds", the cybersecurity experts, or (including and especially @eff), who were extremely helpful. The rest, however, should take note.

I've willingly laid my neck on a chopping block, unprotected, for over six months.

My outreach has been exhaustive:

• Attempted to engage with over 150 journalists and organizations,
• Coordinated frequently with the Cybersecurity and Infrastructure Security Agency ( or "the feds"),
• Consulted with numerous cybersecurity experts,
• Sought advice from multiple lawyers,
• Spoke with ten state and state court CISOs,
• Attempted to talk to several dozen state and county court clerks and judges,
• Sent emails to every Florida State Senator, State Representative, and Supreme Court justice, and to multiple governors,
• Discussed with the staff of multiple U.S. Senators and U.S. Representatives,
• Contacted twelve vendors and over 40 employees

I've offered to write articles -- for free.

I've had no fewer than eight background checks done on me.

I've been cyberstalked by the Arizona Supreme Court.

I've put my job and my family's livelihood at risk in more ways than one.

I've made a grand total of $0; in fact, I've invested several hundred.

When I'm able to sleep, it's with one eye open, always waiting for "that" knock on the door.

After my first , I prepared for a week to deal with what I expected to be a circus. What I received was one preemptive email from a state court (who was not affected) and one kind person (who is not a ) on the .

I've spent over 900 hours discovering, documenting, reporting, and disclosing vulnerabilities, trying to get this fixed on a mass scale, and attempting to contact the above list. I see no signs of this slowing down any time soon. All of this for what is merely a .

I've done my part. It's time for reporters to step up. The real-world harm these vulnerabilities have caused — and continue to cause — cannot be overstated. The need for widespread awareness and action is urgent.

Context: https://github.com/qwell/disclosures/

Email: north@ꩰ.com
Signal: north.01

nerdfall, to random German
@nerdfall@social.tchncs.de avatar

Kind sollte in der 3.Klasse erklären, was von macht.
„Meine Mama macht anderen Menschen Angst, dass ihre Computer nicht mehr funktionieren, wenn sie nicht vorsichtig sind.“

infosec_jobs, to infosec
@infosec_jobs@mastodon.social avatar
jerry, to random

Someone needs to go stunt hack something so the media can move on from this toothbrush story

infosec_jcp, (edited )

Residual IoT™ I.S. leaving a bad taste in certain areas @jerry , 💯😂

Quick, someone update their for a Robot ✍️🤖 + 🔥🥽🔥🥽🔥🥽🔥 for 's who didn't their proxies on us-west1💩 & us-east2💩🤭 🔥🥽 🥽🔥

LMGsecurity, to Cybersecurity

Watch our new video case study on how attackers gained access the personal data of 6.9 million users without compromising the company directly. We'll share what happened and the new implications for organizations: https://youtu.be/B-5Y72UWWhI

lennyzeltser, to security

There are 3 ways to move forward for security leaders who decide to stay at their current company a few years into the role. @Yael and I collaborated to explain how to proceed intentionally and productively: https://zeltser.com/three-ciso-opportunities-when-staying/

jik, to random
@jik@federate.social avatar

I was just invited to a dinner and this was my response.

BishopFox, to Cybersecurity

Ready to take on the role of ? Let us guide you through your first 100 days in this essential role with our talk track "New CISO," filled with expert insights and strategies to set you up for success.

https://bfx.social/48EqXzZ

jasonelrod, (edited ) to Cybersecurity

I really like and ethos around here so much better than the ‘other’ site(s), BUT….. the engagement and interactions are SO much less. What am I missing and are there some tips and tricks I should be using to turn that experience around?

Here are a few hashtags for visibility on the things I most often comment on and talk about.

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 🇬🇧 University of Manchester Speaks Out on Summer Cyber-Attack
➝ 🔓 🇺🇸 Hacktivists breach U.S. nuclear research lab, steal employee data
➝ 🔓 👀 Sumo Logic Completes Investigation Into Recent Security
➝ 🔓 🇺🇸 Auto parts giant AutoZone warns of data breach
➝ 🔓 🇨🇦 Canadian government discloses data breach after contractor hacks
➝ 🇦🇫 New 'HrServ.dll' Web Shell Detected in Attack Targeting Afghan Government
➝ 🇬🇧 🇰🇷 UK and South Korea: Hackers use zero-day in supply-chain attack
➝ 🇵🇸 🇮🇱 -Linked Using Rust-Powered SysJoker Against
➝ 🇷🇺 😱 “They are tired of him, but they are afraid”: what is known about the leader of the hacker group Killnet
➝ 🇰🇵 N. Korean Hackers Distribute Trojanized Software in Supply Chain Attack
➝ ▶️ 🛒 Play Goes Commercial - Now Offered as a Service to Cybercriminals
➝ 🇮🇳 Indian Hack-for-Hire Group Targeted U.S., , and More for Over 10 Years
➝ 🇷🇺 Russian hackers use feature and exploit to attack embassies
➝ 🇺🇸 🩺 Releases Cybersecurity Guidance for , Public Health Organizations
➝ 🇬🇧 🙏🏻 Thanking the vulnerability research community with Challenge Coins
➝ 🧅 Network Removes Risky Relays Associated With Scheme
➝ 🇺🇦 👋🏻 fires top cybersecurity officials
➝ 🩹 Johnson Controls Patches Critical in Industrial Refrigeration Products
➝ 🦠 🦀 New WailingCrab Loader Spreading via Shipping-Themed Emails
➝ 🦠 📨 New Agent Tesla Malware Variant Using ZPAQ Compression in Email Attacks
➝ 🦠 🎠 NetSupport Infections on the Rise - Targeting Government and Business Sectors
➝ 🚫 Google will limit ad blockers starting June 2024
➝ 🐛 ☁️ 3 Critical Vulnerabilities Expose Users to Data Breaches
➝ 🔓 ☁️ Researchers Discover Dangerous Exposure of Sensitive Secrets
➝ 🔓 ☝🏻 New Flaws in Fingerprint Sensors Let Attackers Bypass Hello Login
➝ 🔓 🩸 ‘’ vulnerability targeted by nation-state and criminal hackers: CISA
➝ 🐡 Researchers extract RSA keys from server signing errors

📚 This week's recommended reading is: "How I Rob Banks: And Other Such Places" by FC a.k.a. Freakyclown

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-472023

sharedsecurity, to Cybersecurity

🤔​Having authority as a CISO matters more than you think!

😮​Join us in episode 303 of the Shared Security Podcast as we discuss the SEC's charge against the SolarWinds CISO.

👀​Plus, get the lowdown on the emergence of "Classiscam," a new criminal service manipulating e-commerce platforms.

Don't miss this week's engaging conversations! 🎙️​

Listen now on our website:
https://sharedsecurity.net/2023/11/13/sec-vs-solarwinds-ciso-classiscam-scam-as-a-service/

Watch on YouTube:
https://youtu.be/hQjQt0MMpvk

If you accept the CISO position and then you say, but they didn't give me the authority, then you shouldn't keep the CISO position you either give me the authority to do the stuff I want. To do or need to do or know to do you, you hired me with this responsibility, but you're not gonna give me the authority, but you'll give me the responsibility. I quit. If you're not willing to do that, don't take the job. And if you still take the job and you don't have the authority to do what you want to do, don't whine about it because you have violated your ethics. Right. And I'm, I'm exaggerating the violating your ethics, right? But, but it's the same thing. If you take a CISO position that doesn't give you the authority to be the CISO, yet you're gonna take the responsibility , and whether you choose it or not, the SEC will ensure you've taken the responsibility. That's on you. And when you whine about the fact that you got charged with something and you didn't have the authority, but you knew you didn't have the authority, I'm going to play a very, very small violin. And I don't play violins very well.

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 hit by another , this one stealing employee data from 3rd-party vendor
➝ 🔓 💸 breach linked to theft of $4.4 million in crypto
➝ 🇮🇳 's Biggest Data Leak So Far? Covid-19 Test Info of 81.5Cr Citizens With ICMR Up for Sale
➝ 🔓 ✈️ ransomware group claims to have hacked
➝ 🇳🇱 ⚖️ Dutch hacker jailed for extortion, selling stolen data on RaidForums
➝ 🇷🇺 🇺🇸 Russian Reshipping Service ‘SWAT USA Drop’ Exposed
➝ 🇮🇷 🦠 Iranian Cyber Spies Use ‘’ Malware in Latest Attacks
➝ 📉 Security researchers observed ‘deliberate’ takedown of notorious
➝ 🇮🇳 📱 Apple warns Indian opposition leaders of state-sponsored attacks
➝ 🌍 Four dozen countries declare they won’t pay ransoms
➝ 🇷🇺 How , an Automated Social Media Accounts Creation Service, Can Facilitate
➝ 🇪🇺 EU digital ID reforms should be ‘actively resisted’, say experts
➝ 🇷🇺 🇺🇦 arrests Russian hackers working for Ukrainian cyber forces
➝ 🇺🇸 FTC orders non-bank financial firms to report breaches in 30 days
➝ 🇨🇦 📱 Bans and Apps On Government Devices
➝ 🇺🇸 Charges and Its With Fraud and Cybersecurity Failures
➝ 🇺🇸 🤖 Wants to Move Fast on AI Safeguards and Will Sign an Executive Order to Address His Concerns
➝ 🦠 📱 confirms it tagged Google app as on Android phones
➝ 🦠 🇰🇵 North Korean Hackers Targeting Crypto Experts with Malware
➝ 👥 💸 EleKtra-Leak Attacks Exploit IAM Credentials Exposed on
➝ 🦠 🐍 Trojanized Software Version Delivered via Search Ads
➝ ✅ 🤖 adds security audit badges for Android apps
➝ 🔐 Microsoft pledges to bolster security as part of ‘Secure Future’ initiative
➝ 🆕 FIRST Releases 4.0 Vuln Scoring Standard
➝ 🆕 Releases ATT&CK v14 With Improvements to Detections, ICS, Mobile
➝ ⛔️ 🦠 Galaxy gets new Auto Blocker anti-malware feature
➝ 🍏 🔐 Improves Security With Contact Key Verification
➝ 🔓 Researchers Find 34 Drivers Vulnerable to Full Device Takeover
➝ 🔓 🪶 3,000 servers vulnerable to RCE attacks exposed online
➝ 🗣️ CISO Urges Quick Action to Protect Instances From Critical
➝ 🔓 🩸 “This vulnerability is now under mass exploitation.” bug bites hard
➝ 🐛 💰 HackerOne paid ethical hackers over $300 million in

📚 This week's recommended reading is: "Permanent Record" by Edward Snowden

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-442023

mdfranz, to random

"Top CyberSecurity Voice" on LinkedIn talking about 🤮

lennyzeltser, to Cybersecurity

The phrase "security is everyone’s responsibility" concerns me. People feel less responsible when they are a part of a group because they think someone else will take action. I explored this in a post on distributing cybersecurity responsibilities:

https://zeltser.com/distribute-cybersecurity-tasks/

cirriustech, to Cybersecurity
BibbleCo, to random

I imagine a lot of current CISOs will be looking into cashing out and taking early retirement in the near future. Good news for Info Risk Management types who've grown weary of banging their heads on the wall.

https://www.sec.gov/news/press-release/2023-227

PogoWasRight, to ukteachers
BishopFox, to random

In this convo with Bishop Fox’s Trevin Edgeworth, you’ll discover how can empower your organization to make confident decisions in challenging times.

Trevin has over 20 years of experience, including helping create programs at American Express, Capital One, and Symantec in addition to serving as at Norton Lifelock.

https://bfx.social/3Q44Cpa

0x58, to infosec

On Wednesday, October 18, 2023, we @cloudflare] discovered attacks on our system that we were able to trace back to Okta – threat actors were able to leverage an authentication token compromised at Okta to pivot into Cloudflare’s Okta instance.

.. and they wrap up with recommendations...

Take any report of compromise seriously and act immediately to limit damage; in this case Okta was first notified on October 2, 2023 by @beyondtrust but the attacker still had access to their support systems at least until October 18, 2023.

https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/

kkarhan,
@kkarhan@mstdn.social avatar

@0x58 @cloudflare @beyondtrust Seriously, WTF?

In we'd call this "criminally gross neglect" and I really hope this won't be finished juat by firing the immediately.and without severance packages but woll have long lasting consequences.

But thanks for the info so I'll know to deny-list as supplier for that reason alone.

LMGsecurity, to Cybersecurity

Heads up: and issued a maximum severity alert urging you to patch Atlassian Confluence immediately due to critical security vulnerabilities. Read more: https://www.bleepingcomputer.com/news/security/cisa-fbi-urge-admins-to-patch-atlassian-confluence-immediately/

BishopFox, to security

Trevin Edgeworth has experience establishing world-class ; he has previously built them for American Express and Capital One in addition to Symantec and serving as the of Norton Lifelock. And in our virtual session, he’ll review why can be a strategic “sanity check” for team leaders, VPs, , C-Suite executives, and the Board.

https://bfx.social/3Q44Cpa

BishopFox, to random

We recently celebrated a milestone at Bishop Fox – the establishment of our and positions. Christie Terrill a long-time Bishop Fox veteran, and Aaron Symanski will be holding these roles.

https://bfx.social/45WeFlI

derPUPE, to random German
@derPUPE@chaos.social avatar
sharedsecurity, to Cybersecurity

Get ready for some insightful conversations on the latest episode of the Shared Security podcast!

📢 Join our host, @agent0x0 as he discusses into the dynamic world of the Chief Information Security Officer (CISO) with Ryan Davis, Chief Information Security Officer at NS1. 🌐

In this episode, Ryan shares his expertise and experiences, shedding light on the ever-evolving role of a Chief Information Security Officer. In this episode Tom and Ryan discuss fascinating topics, including:

🔒 The transformative nature of the CISO position
🤝 Navigating cybersecurity through acquisitions
🌟 The biggest challenges facing CISOs today
💡 Priceless advice for aspiring CISOs

If you've ever wondered what it takes to be a CISO, are contemplating a career in cybersecurity leadership, or are already a CISO yourself, this episode is a MUST-listen!

Stay tuned for an enlightening conversation that will broaden your horizons in the world of cybersecurity. Don't miss it! 🚀

Listen on our website:
https://sharedsecurity.net/2023/09/18/the-changing-role-of-the-ciso-with-ryan-davis-chief-information-security-officer-at-ns1/

Watch on YouTube:
https://youtu.be/BdtSnT1si3s

Subscribe on Apple Podcasts, Spotify, or your favorite podcast platform:
https://sharedsecurity.net/subscribe

xdydx, to TeslaMotors
@xdydx@mastodon.social avatar

I'm pretty sure fired his team around the same time he got rid of the and teams, but if there is a left at they should hurry out the door and get a new job while the going is "good"..

https://www.techdirt.com/2023/09/12/the-batshit-crazy-story-of-the-day-elon-musk-decided-to-personally-rip-servers-out-of-a-sacramento-data-center/


  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • tacticalgear
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • Youngstown
  • everett
  • anitta
  • slotface
  • GTA5RPClips
  • rosin
  • thenastyranch
  • kavyap
  • mdbf
  • Leos
  • modclub
  • osvaldo12
  • Durango
  • khanakhh
  • provamag3
  • cisconetworking
  • ngwrru68w68
  • cubers
  • tester
  • ethstaker
  • megavids
  • normalnudes
  • lostlight
  • All magazines