@googlecloud Distinguished SWE, CloudSec. Former (Acting) Deputy Technical Director for Cyber @CISAgov. Minnesotan. Personal Account. RT=/=endorsement.
Updated light display this year: new more scalable control PCB design (finally compatible with xlights fseq files), more complex effects, relays to drive the flood lights, and of course more pixels!
We published a fact sheet on Contec CMS8000 patient monitor firmware vulnerabilities involving an undisclosed backdoor and unauthorized exposure. Orgs using this medical device should follow our guidance: https://t.co/2tFbdi6r9o
As part of our support for Int’l standards, we’re excited to welcome Deb Cooley! 🎉 With a distinguished USG career, she’s made many impactful contributions to internet security. Want to join Deb at CISA? Visit https://t.co/X1AMx0QZBr for open positions & intern opportunities!
@fabian_bader@IDMKen@ethanadoor@CISAgov We don't have anything against AMA, but for admining AD or AAD itself we definitely recommend separate admin accounts using at worst user name hints (to share a smartcard) and ideally separate cards or FIDO tokens, depending on what vintage of environment one is in.
@fabian_bader@IDMKen@ethanadoor@CISAgov This isn't a CISA page as Ethan said. No clue the origins of that particular line, which likely dates from eons ago.
👉Since last summer, we’ve worked closely with @Microsoft, @OMBPress, & @ONCD to advance Security-By-Design. As part of this ongoing work, we’re pleased that expanded logging capabilities will now be available to all federal agencies. Learn more: https://t.co/ZwEMkwN3Me
Bullish article on passkeys. As we say at CISA, this technology is the gold standard for MFA and can eliminate entire classes of attacks when employed.
Is the death of the password in sight?
2023 was the year that passkeys started to take off, and 2024 will be even bigger.
My new story explains what passkeys are, how they went mainstream this year, and what's ahead for this password killer.
https://t.co/WkB4CU4NlS
There is more that is needed, especially to make passkey's viable in the enterprise and to solve remaining interoperability issues. But its great to see this technology getting recognition.
Lots of work went into these baselines. We're taking an agile approach so they will evolve as capabilities and threats change. Also make sure to check out our https://t.co/NDRrIXauSB tool where we just released version 1.0.0 to automate conformance testing for the baselines!
Now available: the finalized Microsoft 365 Secure Configuration Baselines, designed to bolster the security and resilience of organizations’ Microsoft 365 (M365) cloud services. https://t.co/hwnfp3ujGf
First year in our new house means it's time for a programmable tree. Custom controller PCB worked like a charm, because...why not. It's definitely not up to @RGB_Lights or Great Christmas Light Fight standards but that's what next year is for, right?