@taylor_vahey There is no right one. There is the process of making a choice day after day to choose that person and be with a person who chooses you and takes actions consistent with their integrity. This means there will be times of sacrifice on both sides.
@ItIsHoeMath@JXGM13 And they are able to choose the actions regardless of the consequences because to them something else is driving the decision making and the best you can do is try to influence them towards more healthy long term decisions.
@ItIsHoeMath@JXGM13 As you work on this, overlaps with attachment theory and the internal neuroscience of how we process our environment and relationships may help with the questions.For example when you get to the point you realize all the actions people take are what they believe is best for them
@realMeetKevin@realMeetKevin I recommend taking a read/listen to the book "The price of time the real story of interest. " It reviews monetary policy, interest rates and asset prices back to ancient times. What we are doing is not new. There are lots of examples in history.
🛡️ Palo Alto Networks PAN-OS users: We added #CVE-2024-3400, a command injection vulnerability in GlobalProtect Gateway, to our Known Exploited Vulnerabilities Catalog. Apply mitigations to protect your org from cyberattacks. https://t.co/myxOwap1Tf #Cybersecurity#InfoSec
CISA and review board torches Microsoft internal response and how bad the 2023 compromise actually was.
It was way worse than what was communicated from Microsoft - way way way worse and avoidable.
This is a good read and something folks really need to equate in their own threat models and risks in cloud - especially one as high profile as Microsoft/Azure.
Extremely alarming imo. Key highlights below is scary AF.
Also bang up job on this report from @CISAgov - grade A disclosure and documentation and analysis. Also, this isn’t me bashing the amazing folks that work at Microsoft.
Some of the most brilliant folks out there. What is clear is that there needs to be some serious and concerted effort on monitoring and massive momentum on additional security controls (esp keys to kingdom ?!) to protect their cloud infrastructure that other cloud providers already have that Microsoft is seriously lagging behind in.
Excerpt below:
“Given Microsoft’s inability to determine how and when the adversary was able to steal its signing key, all CSPs should review and revise as appropriate their logging and overall forensics capabilities around their identity systems and other systems that enable environment-level compromise, such as root key material.
1. the cascade of Microsoft’s avoidable errors that allowed this intrusion to succeed;
2. Microsoft’s failure to detect the compromise of its cryptographic crown jewels on its own, relying instead on a customer to reach out to identify anomalies the customer had observed;
3. the Board’s assessment of security practices at other cloud service providers, which maintained security controls that Microsoft did not;
4. Microsoft’s failure to detect a compromise of an employee's laptop from a recently acquired company prior to allowing it to connect to Microsoft’s corporate network in 2021;
5. Microsoft’s decision not to correct, in a timely manner, its inaccurate public statements about this incident, including a corporate statement that Microsoft believed it had determined the likely root cause of the intrusion when in fact, it still has not; even though Microsoft acknowledged to the Board in November 2023 that its September 6, 2023 blog post about the root cause was inaccurate, it did not update that post until March 12, 2024, as the Board was concluding its review and only after the Board’s repeated questioning about Microsoft’s plans to issue a correction.”
https://t.co/OSKXeh8Vph
🤯 The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)!
I hope it helps to make sense of the information out there. Please treat the information "as is" while the analysis progresses! 🧐 #infosec #xz
@BrianFeroldi How is SBC that was allocated to an employee and they leave before vest/assignment handled from an accounting standpoint for the company? Is it returned as income? Is it not actually recognized until vest?
Thank you for posting this. I like the part "you don't want ChatGPT driving your car, you need precision AI". Early days on AI and Security, but here the one measured one will win. Lipstick on a........ - copilots won't win.
all-star summer is still going!
$PANW CEO @nikesharora joins @Jason to talk:
-- experience running $GOOG's Euro biz
-- lessons from Sergey, Larry, and Eric Schmidt
-- working with Masa at @SoftBank_Group
-- taking over as CEO at $PANW
-- AI cybersecurity risks
@AdlerPlanet Hi, been trying to buy tickets online for 2 days. Used multiple devices/browsers. Your website is broke. Is there an alternate method to purchase tickets?
@bettersafetynet Another illustration is layers of protection based on attack chain. Every layer increases chance of detection/prevention. Goal should be high fidelity/low false positive alerts. Your chances of blocking attack increase exponentially. Example 95% + 95% or remaining 5% on repeat.
@CantonRepdotcom You should really consider swapping these pages in your layout. You always have these pictures of food that look gross due to b&w next to the less important smaller color pictures.
2023-05-10 (Wednesday): obama262 #Qakbot (#Qbot) infection led to #BackConnect activity on 46.151.30[.]109:443 with #DarkCatVNC. Also saw #CobaltStrike from this infection using HTTPS traffic to floatfil[.]com. IOCs available at https://t.co/TAvwm8PM3X
@itsPaulAi If Google bard doesn't have accurate sources it will hallucinate them and rickroll you instead of saying the sources don't exist. Use case was looking for a certain type of YouTube or podcast with specific people.