Avatar
Kevin Beaumont
f6870afcde4480ec8508f50304859e14a51309ff24ab3f0f862c52bdc4af8747
Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions. I have Direct Messages disabled - you can send them, but I will never receive them.

I wasn’t expecting how much of a nostalgia hit Quake 2 remaster would be. Getting a solid 700fps too, lol.

Capture the flag works great.

Replying to f4ac1591...

nostr:npub17lgy0rj5a2nwpnyc4hup6ufpfz7wz6dzcgd3crm6fm2yd34dcz0qlk9uux I wonder if they will still try and do it, but not actually tell anyone?

nostr:npub18v370kjrc292ppxtf5q35qjp3krjfwl0n78gfne78k72kdcn89wsvw4qw3 here’s the thing - they wouldn’t be alone.

Lol, found an open storage bucket for a org who are experimenting with AI transcribing their meetings.. they’re putting the output into the bucket. 🫡

Just discovered a weird bandwidth hack for the HUAWEI 5G router - if I move it from the window sill it’s on and place it on the radiator below, I get 20% faster speeds. Consistently. Same angle to tower and everything 🤣

Update: I realised there a ledge I could jump to from prison, so I tried to escape. I died. I thought the game would be like ‘lol game over’ but instead it is ‘lol you died you imbecile, keep playing as your other party members’. Baldur’s Gate 3 approach to player choice:

https://cyberplace.social/system/media_attachments/files/110/836/700/265/588/270/original/26f8e178a26bf67d.mp4

Already made so many mistakes in Baldur's Gate 3 that my character has ended up in prison, now I'm playing with the party members.

Replying to Avatar Rachel Rawlings

nostr:npub17lgy0rj5a2nwpnyc4hup6ufpfz7wz6dzcgd3crm6fm2yd34dcz0qlk9uux I thought the CVE numbering system was already a project of MITRE and NIST.

nostr:npub174tr94vmsgf9ldj6n9zd42jtmmajfnjw0tp9us5eewrtfm30w6pstacfav it doesn’t apply to cloud vulnerabilities (eg MS don’t even apply for them)

One thing I’ve noticed is Mandiant now assign their own CVE like numbers to cloud provider vulnerabilities like this.

There really needs to be a properly, commonly agreed up system like CVE for this (not run by Google). I know there’s attempts at this, I hope they take off.

The illusion the cloud is magically secure is just that; an illusion. At the minute cloud providers are hiding behind lack of regulation, lack of transparency & deliberate subterfuge to protect shareholders. It’s not great.

The disclosure timeline on this post is just not acceptable by Microsoft.

I made this plea on Twitter a while ago - security researchers, please include full timelines like this in disclosures. This one isn’t isolated. The more this kind of thing comes out in public, the more it forces cloud providers to properly resource security fixes.

https://www.tenable.com/security/research/tra-2023-25

I have ordered 3 collectors editions over my 35 years of gaming - Cyberpunk 2077, Fallout 76.. and Starfield.

If the game turns out to be shite, I jinxed it, soz.

Kaspersky have a good find here, similar to the PlugX data harvester USB worms from China based threat actors that are doing the rounds for past few years - DLL sideloading, exfil files via same folder names etc.

https://ics-cert.kaspersky.com/publications/reports/2023/07/31/common-ttps-of-attacks-against-industrial-organizations-implants-for-gathering-data/

I noticed a change in how Microsoft deliver Defender AV updates - on Thursday July 27th 2023 in the AM, they pushed out a file called C:\Windows\SoftwareDistribution\Download\Install\MpSigStub.exe via Windows Update.

This wrote a new file out,

C:\Windows\System32\MpSigStub.exe

That triggers a few times a day, like this:

C:\Windows\system32\MpSigStub.exe /stub 1.1.23080.1001 /payload 1.393.1547.0 /MpWUStub /program C:\Windows\SoftwareDistribution\Download\Install\AM_Delta.exe ANTIMALWARE /q