publicvoit, to microsoft
@publicvoit@graz.social avatar

After basically the whole cloud was hacked (see list of related sources on https://karl-voit.at/cloud/ ), the first follow-up incidents went public caused by missing containment actions:

60,000 emails were stolen from 10 accounts
https://www.reuters.com/world/us/chinese-hackers-stole-60000-emails-us-state-department-microsoft-hack-senate-2023-09-27/

If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get rid of the intruders. Everything authenticated by Microsoft is tainted. Even auth.

chpietsch, to random German
@chpietsch@digitalcourage.social avatar

Die begeben sich in eine selbstverschuldete Unmündigkeit, wenn ihre Öffentlichkeitsarbeiter:innen die Plattformen antidemokratischer Milliardäre bespielen, statt sich am Aufbau des Fediversums zu beteiligen – des selbstverwalteten, wirklich sozialen Netzwerks der Zukunft.

Accounts auf Mastodon-Instanzen wären ein guter 1. Schritt.

Im 2. Schritt sollten Hochschulen Fediverse-Instanzen selbst betreiben.

Ich arbeite an der in einem Team, das eine der größten wissenschaftlichen Suchmaschinen (@base) betreibt. Für einen Verein betreibe ich nebenher Fediverse-Instanzen (Mastodon und PeerTube). Gern würde ich das auch für meine Uni tun.

Wegen all dem bin ich ein Erstunterzeichner des offenen Briefs an die mit der Forderung ! Unterschreibt die Petition: https://www.openpetition.de/petition/online/appell-an-die-hochschulrektorenkonferenz-zur-nutzung-sozialer-medien
… und folgt @neuSoM für Updates!

chpietsch,
@chpietsch@digitalcourage.social avatar

@balou19812

Auch das Rechenzentrum der Uni Bielefeld betreibt kaum Anwendungen selbst, sondern am liebsten nur leere virtuelle Maschinen. Unsere Matrix-Instanz wird von einer Fakultät für die ganze Uni betrieben. Unsere GitLab-Instanz von der Bibliothek (mir). Warum das so ist, weiß ich nicht. Aber mit etwas gutem Willen finden sich Lösungen.

Es gibt aber auch eine gegenläufige Tendenz an Hochschulen, und zwar alles Mögliche in die Cloud auszulagern, z.B. in die von Microsoft. Ich kann gar nicht sagen, wie schade ich das finde. So verlieren wir den letzten Rest digitaler Souveränität.

i0null, to Meme
mapache, to fediverse
@mapache@hachyderm.io avatar

Part 3 of "A Guide to Implementing ActivityPub in a Static Site (or Any Website)" is just out the oven!

In this blog post, I explain how to make your blog discoverable in the Fediverse as an account, and also address some of the annoying pitfalls I encountered.

Full article here: https://maho.dev/2024/02/a-guide-to-implementing-activitypub-in-a-static-site-or-any-website-part-3/

If you like it don't forget to follow the @blog !

-sites -development -web

alan, to voyager
@alan@subdued.social avatar

I must admit, this news about and has me shook:

"A fresh analysis of Voyager 2's images show both ice giants are in fact a similar shade of greenish blue, which is the 'most accurate representation yet' of the planets' colors, the new study finds."

https://www.space.com/uranus-neptune-similar-shades-of-blue-voyager-2-images

derPUPE, to microsoft German
@derPUPE@chaos.social avatar

Kein Begriff wird zur Zeit häufiger mißbraucht als der begriff #Souverenität

“Mit dem Aufbau der #souveränen Cloud bereiten wir nicht den Weg in die digitale
#Unabhängigkeit für die Bundesrepublik”

In der Stellenausschreibung dazu dann:

“Wir von #Arvato Systems möchten gemeinsam mit dir den Ausbau einer solchen Cloud auf Basis von #Microsoft #Azure vorantreiben.”

#Europa & 🇩🇪 schafft sich ab

0x58, to Cybersecurity

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #45/2023 is out! It includes the following and much more:

➝ 🔓 ✈️ #Boeing breach: LockBit leaks 50 GB of data
➝ 🇨🇳 World’s largest commercial bank #ICBC confirms #ransomware attack
➝ 🔓 ☁️ Sumo Logic alerts customers about #securityincident; advises rotate Sumo Logic API access keys
➝ 🔓 🇮🇪 Electric Ireland admits data breach that could see customer financial data compromised
➝ 🔓 🇨🇦 #TransForm says ransomware data breach affects 267,000 patients
➝ 🔓 🇸🇬 #Singapore Marina Bay Sands reward members data breached, over 650k people exposed
➝ 🇮🇱 🇵🇸 🇮🇷 Cyber ops linked to #Israel-#Hamas conflict largely improvised, researchers say
➝ 🧨 🤖 #OpenAI confirms #DDoS attacks behind ongoing #ChatGPT outages
➝ 🛍️ 💸 Fake Ledger Live app in #Microsoft Store steals $768,000 in #crypto
➝ 🔓 🐰 ‘Looney Tunables’ #Glibc Vulnerability Exploited in #Cloud Attacks
➝ 🇺🇸 🇷🇺 US Sanctions Russian National for Helping Ransomware Groups Launder Money
➝ 🇮🇷 🇮🇱 Iranian Hackers Launch Destructive Cyber Attacks on Israeli #Tech and #Education Sectors
➝ 🇫🇷 🇬🇧 #France, #UK Seek Greater Regulation of Commercial #Spyware
➝ 🇪🇺 🤐 #Europe is trading security for digital #sovereignty
➝ 🇷🇺 🇺🇦 Russian Hackers Used #OT Attack to Disrupt Power in #Ukraine Amid Mass Missile Strikes
➝ 🦠 🚪 Highly invasive #backdoor snuck into #opensource packages targets developers
➝ 🦠 🇰🇵 N. Korea's #BlueNoroff Blamed for Hacking #macOS Machines with ObjCShellz #Malware
➝ 🫣 #Signal tests usernames that keep your phone number private
➝ 🔐 Microsoft Authenticator now blocks suspicious #MFA alerts by default
➝ ☁️ 💰 Researchers Uncover Undetectable #CryptoMining Technique on #Azure Automation
➝ 👥 💰 Data Brokers Expose Sensitive US Military Member Info to Foreign Threat Actors: Study
➝ 🩹 Microsoft Says Exchange ‘Zero Days’ Disclosed by #ZDI Already Patched or Not Urgent
➝ 🐛 Veeam warns of critical bugs in #Veeam ONE monitoring platform

📚 This week's recommended reading is: "How the F*ck Did This Happen?: A guide for executives who need to understand Cyber Security in plain, actionable language" by Dr Darryl Carlton

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-452023

MattTheDev, to microsoft

Any software companies with tech stack hiring out there? I’m content where I’m at - but as a Lead developer wanting to jump to the track I’m pretty stagnant in my current position.

I worked for the Federal Reserve for a bit before jumping into consulting. I’ve lead geolocated teams - 12 hr time difference - for over half of it.

I’d be curious to see what is out there.

mapache, to fediverse
@mapache@hachyderm.io avatar

Part 6 of "A Guide to Implementing ActivityPub in a Static Site (or Any Website)" is now out.

Sorry about the delay, this is the part that not many people will like, I assume. I try to explain how to implement the inbox, which by nature is dynamic non-static.

Full article here:
https://maho.dev/2024/04/a-guide-to-implementing-activitypub-in-a-static-site-or-any-website-part-6/

If you like it don't forget to follow the @blog !

drsbaitso, to windows

Good Monday morning, Fediverse! I'm looking for my next role, hoping to get .

Right now I'm a principal engineer and team lead for certificate infrastructure at a major US company. My day-to-day work focuses on PKI infrastructure/operations, Windows, and Active Directory. I get to help developers understand both the Why and How of the best practices for using certificates, along with keeping the certificate infrastructure humming along.

Working with Information Security, we've implemented company-wide multi-factor authentication for ~30,000 people. I've designed and executed migrating from on-prem PKI (Microsoft ADCS) to Certificates-As-A-Service, which reduced our total operating costs by about half. The includes dropping our datacenter footprint from multiple physical devices down to a couple of VMs.

Outside of the technical responsibilities, I'm mentoring and training junior/new teammates to build their skills and their confidence. Feedback from the management of our development and applications teams is that I've reinvigorated relationships and made certificate discussions something folks look forward to. And while nobody enjoys an outage, both managers and fellow individual contributors have told me that my calm, confident, and methodical presence is critical to both morale and quick resolution.

My current position doesn't offer much in the way of Azure exposure, but in my previous role I built out a Windows Virtual Desktop (now Azure Virtual Desktop, AVD) ecosystem from scratch when the pandemic first began and we had to send everyone to work from home on super-short notice. Nobody missed a day of work for lack of technical resources.

What I want from my next role is either a similar technical lead/principal level infrastructure/operations IC position or moving into management of a similar team.

If you're looking for a technical leader (with or without management responsibilities) to help shape and maintain your Windows/Active Directory environment, someone who can build relationships across a large organization, let's chat. DM me for email or Signal.

Current residence is in Syracuse, NY, but I'm open to relocation.

Boosts appreciated.

BajoranEngineer, to python
@BajoranEngineer@mastodon.online avatar

Calling all Azure Pythonistas! Announcing a Call For Proposals

Azure Developers - Python Day 2023 is 📅 September 7th 9am - 2pm Pacific and YOU could be a part of the schedule streamed LIVE 🔴🎬

https://learn.microsoft.com/events/learn-events/azuredevelopers-pythonday/

Submit your 30 minute session (25 mins of content + 5 mins live Q&A) in any of the following areas:

🧠 Artificial Intelligence
👩🏽‍💻 App Development
☁️ Cloud Native
💽 Data Services
🚈 Serverless

CFP Submission close August 11th End of Day: https://aka.ms/azure-python-day-2023-CFP

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 ❌ TransUnion Denies After Hacker Publishes Allegedly Stolen Data
➝ 🔓 ⚖️ Hackers breached International Criminal Court’s systems last week
➝ 🔓 🤖 researchers accidentally exposed terabytes of internal sensitive data
➝ 🦠 💸 hits Storage with encryptor
➝ 🇮🇷 🇮🇱 Iranian Nation-State Actor OilRig Targets Israeli Organizations
➝ 🇮🇳 's biggest tech centers named as hotspots
➝ 🇫🇮 💊 Finnish Authorities Dismantle Notorious Dark Web Drug Marketplace
➝ 🇨🇦 🇷🇺 Canadian Government Targeted With Attacks by Pro- Group
➝ 🇨🇳 🇺🇸 Accuses U.S. of Decade-Long Campaign Against Servers
➝ 🇺🇸 🇨🇳 China's Malicious Cyber Activity Informing War Preparations, Says
➝ 🇨🇳 🦠 New Linux used in cyber espionage attacks
➝ 🇬🇧 🔐 UK Minister Warns Over End-to-End Encryption
➝ 🇺🇸 🇷🇺 One of the ’s most wanted hackers is trolling the U.S. government
➝ 🦠 🥸 Fake proof-of-concept exploit drops malware
➝ 🦠 📈 botnet activity surges 600x with stealthier malware variants
➝ 🦠 📡 Hackers backdoor providers with new HTTPSnoop malware
➝ 🦠 🐝 malware returns in new attacks abusing folders
➝ 🔐 launches support into general availability
➝ ☑️ 🐧 Free Download Manager releases script to check for malware
➝ 💬 🔐 adds quantum-resistant encryption to its messaging protocol
➝ 🍏 🔐 17 includes these new security and features
➝ 🩹 High-Severity Flaws Uncovered in Products and ISC BIND Server
➝ 🩹 😡 Incomplete disclosures by and create “huge blindspot” for 0-day hunters
➝ 🍏 🩹 Apple emergency updates fix 3 new zero-days exploited in attacks
➝ 🩹 fixes protection zero-day used in attacks
➝ 🩹 Patches High-Severity in FortiOS, FortiProxy, FortiWeb Products
➝ 🔓 Nearly 12,000 Found Vulnerable to Recently Disclosed RCE Vulnerability

📚 This week's recommended reading is: "Future Crimes: Everything Is Connected, Everyone Is Vulnerable and What We Can Do About It" by Marc Goodman

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-382023

johnleonard, to AWS
@johnleonard@mastodon.social avatar

Bank of England proposes new rules to curb reliance on big tech

Overreliance 'could impact UK financial stability if they were to fail or be disrupted'

https://www.computing.co.uk/news/4154872/bank-england-proposes-rules-curb-reliance-big-tech

steinbring, to Morocco
@steinbring@pixelfed.social avatar

I took this in Chefchaouen in 2019. The mesmerizing azure hue that adorns the ancient architecture is undeniably beautiful. This is definitely on the list of places I want to see twice.

wurzelmann, to microsoft German

Nie mit euren Daten vertrauen. Nie. Mit keinen Daten. Ever.

"Microsoft leaks 38TB of private data via unsecured Azure storage"

https://www.bleepingcomputer.com/news/microsoft/microsoft-leaks-38tb-of-private-data-via-unsecured-azure-storage/

markcarter, to microsoft

Good read 🤔 finally explains cause of breach: An engineer’s account was hacked and several safeguards failed. https://arstechnica.com/security/2023/09/hack-of-a-microsoft-corporate-account-led-to-azure-breach-by-chinese-hackers/

MattTheDev, to dotnet

Anyone up for reviewing a resume? Had it professionally ... done up ... but it looks and feels off to me. Been debating seeing what's our there in the , , and world and want to have a good jumping off point.

tedi, to AWS

Datadog released Cloud Security Atlas: a risk register for cloud threats and vulnerabilities: https://securitylabs.datadoghq.com/cloud-security-atlas/

xro, to azure German
@xro@chaos.social avatar
maartenballiauw, to azure
@maartenballiauw@mastodon.online avatar

We just released the Toolkit for Rider v4 Preview 🌤️

🔑 Sign in using az cli, …
⚡️ Azure Functions
🌍 Web Apps
🗺️ Resource explorer
👩‍💻 SQL
🗄️ Storage emulator

As a rewrite of the current plugin, we’d like to hear your feedback!
https://blog.jetbrains.com/dotnet/2024/05/14/azure-toolkit-for-rider-v4-0-preview-request-for-feedback/?utm_medium=social&utm_source=mastodon&utm_campaign=azure-toolkit-for-rider-v4-0-preview-request-for-feedback

pg_at_msft, to PostgreSQL
@pg_at_msft@mastodon.social avatar

Hello 👋 We'll be sharing updates from the team 🐘 at Microsoft here, including our open source contributions to the Postgres database core—plus our work on the Azure Database for PostgreSQL managed service. And more!

✅ If you missed this 📝 blog post on what's new with Postgres at Microsoft by @clairegiordano, it's still quite current & gives a good overview

https://techcommunity.microsoft.com/t5/azure-database-for-postgresql/what-s-new-with-postgres-at-microsoft-august-2023/ba-p/3914506

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes, but not only:

→ 🇺🇸 🇨🇳 The US Navy, NATO, and are using a shady Chinese company’s chips
→ 🦠 🏢 Group Starts Naming Victims of Zero-Day Attacks
→ ☁️ 🪣 New Supply Chain Attack Exploits Abandoned to Distribute Malicious Binaries
→ ☁️ Vulnerabilities in Led to Unauthorized Access to User Sessions
→ 🇨🇳 🦠 ESG zero-day attacks linked to suspected Chinese hackers
→ 🇷🇺 🇺🇸 Russian national arrested in Arizona, charged for alleged role in ransomware attacks
→ 🇷🇺 🇺🇦 Russia-backed hackers unleash new USB-based malware on ’s military
→ 🇺🇸 💰 LockBit Ransomware Extorts $91 Million from U.S. Companies
→ 🇷🇺 🇺🇦 identifies new hacking unit within Russian military intelligence
→ 🦠 Fake Researcher Profiles Spread through Repositories as PoC Exploits
→ 🎣 👟 Massive campaign uses 6,000 sites to impersonate 100 brands
→ 🇨🇳 Chinese Cyberspies Caught Exploiting ESXi
→ 🩹 Microsoft , June 2023 Edition
→ ☁️ Microsoft: Azure Portal was caused by traffic “spike”
→ 🇨🇳 🇺🇸 's cyber now aimed at infrastructure, warns CISA boss
→ 🇰🇷 🇨🇳 Ex-Samsung executive alleged to have stolen tech to recreate chip plant in China
→ 🇨🇭 🗄️ Swiss Fear Government Data Stolen in Cyberattack
→ 🩹 🔐 fixes critical RCE flaw in SSL-VPN devices, patch now

📚 This week's recommended reading is: "The Cyber Effect: An Expert in Cyberpsychology Explains How Technology Is Shaping Our Children, Our Behavior, and Our Values — and What We Can Do About It" by Prof Mary Aiken

Subscribe to the to have it piping hot in your inbox every Sunday ⬇️

https://0x58.substack.com/p/infosec-mashup-week-242023

Ikrial, to VideoGames French

Bonjour à tous·tes,

Je suis Bastien / Ikrial, nouveau ici après avoir quitté le nid de l'oiseau.

Je suis joueur de JV (vive les tapis roulants), et amateur des musiques qui les accompagnent.

Je suis aussi un fan de Star Wars qui apprécie voir cet univers s'étendre.

Côté pro, je suis dev C# / admin Azure.
Et peut-être un jour, je prendrai du temps pour apprendre des bases de dev de jeux (Godot / Unity.

witewulf, to IT
bluca, to random
@bluca@fosstodon.org avatar

On the way to being pampered on the - train beer under the sea!

bluca,
@bluca@fosstodon.org avatar

I'm doing two talks at - the first one will be "Soft Reboot: keep your containers running while your image-based Linux host gets updated" in the devroom on Saturday. This is similar to the same talk I gave at last autumn, but with added demos, one of which from a real Boost production system (management actually approved that!)
https://fosdem.org/2024/schedule/event/fosdem-2024-3282-soft-reboot-keep-your-containers-running-while-your-image-based-linux-host-gets-updated/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • thenastyranch
  • magazineikmin
  • osvaldo12
  • GTA5RPClips
  • mdbf
  • Youngstown
  • tacticalgear
  • slotface
  • rosin
  • kavyap
  • ethstaker
  • everett
  • khanakhh
  • JUstTest
  • DreamBathrooms
  • InstantRegret
  • tester
  • provamag3
  • normalnudes
  • ngwrru68w68
  • cubers
  • cisconetworking
  • Durango
  • megavids
  • Leos
  • modclub
  • lostlight
  • All magazines