I'm 33 and I think Claude Code is melting my brain.
For 6 months straight I've had 5-6 terminals open at once, waiting on responses just to smash "enter" 90% of the time. That's the whole job now.
And it's doing something to me. A few friends and I keep circling back to the same thing in conversations: none of us feel as sharp as we used to.
Maybe it's just us. But I keep wondering how many other people in their 30s feel it too.
(And yeah: this is a me problem, how I lean on the tool, not the tool itself. Doesn't make the effect any less real.)
We are releasing details on BRICKSTORM malware activity, a China-based threat hitting US tech to potentially target downstream customers and hunt for data on vulnerabilities in products. This actor is stealthy, and we've provided a tool to hunt for them. https://t.co/kuZ1UUUz6H
BRICKSTORM malware used by suspected China-nexus actor, UNC5221, in stealthy espionage campaign.
- Avg dwell time: 393 days.
- Targets: US legal, SaaS, BPOs & tech firms.
We have released a scanner, IOCs, and guidance to help defenders.
Full analysis: https://t.co/wM3OFsR5Ec
I want to give a shout out to Discord.
As much as their helpdesk compromise has been awful for users, Discord has in fact told the truth and done everything by the book on how to handle a compromise (much to the dismay of users).
Discord stated they believed roughly 70,000 photos from individuals had been exfiltrated (government issued identification). The Threat Actor asserted 2,100,000+. However, the Threat Actor retracted the statement and said they had roughly 71,000 drivers licenses and/or passports. Hence, Discords DFIR (Digital Forensic and Incident Response) team was correct.
Discord asserted the compromise was third party. That was correct.
They stated it was customer service related. That is also correct. Discord did not lie about the scope.
Discord notified customers in a transparent manner, despite knowing it would receive negative attention.
Discord was open about their believed compromise time dateline based on information the Threat Actors had shared.
In essence, everything Discord has said has been (based on what I've seen) factually accurate.
Discord also (as much as users hated) complied with government regulations. They did indeed do ID verification manually if it was required. You can criticize Discord for doing age verification, but they're complying with government law.
There's a lot you can criticize about Discord, or dislike about Discord, but as far as handling a compromise, they did it by the book and correctly. Their security measures were in place, but combating an Insider Threat is notoriously difficult. They exist everywhere.
As a final note, Discord has also done something which is controversial, but they have not complied with the Threat Actors. Many companie will succumb to pressure, but Discord has not. Many DFIR firms insist companies DO NOT pay ransoms because it encourages criminal extortion groups. Based on the posts from the Threat Actor(s), Discord has not paid them and is not complying.
tldr Discord handled it well
@EngineeredEV Most definitely! I think have a basic troubleshooting methodology to follow and then unique best practices/steps for common use cases (Hosts can’t communicate, internet is broken, can’t connect to anything, etc…)
🚨A cyber breach at 40,000 feet isn’t just an IT issue.
🛑Millions trust the skies every day. Only our top cybersecurity experts can keep them safe.
✈️ Cybersecurity matters. Learn about it. Demand it.
"Cybersecurity Dictionary for Everyone" on Amazon: https://t.co/DcrmsiMCBP
- Red team Operations
- Reverse engineering content
- Red Team x Blue team
- Practical social engineering
- Windows Privilege escalation
- AD, & Road to OSCP
- & Many more
Thanks to Joas A Santos (@C0d3Cr4zy)
SourceURL: https://t.co/yC58I0zg9f
Cybersecurity mastery starts with understanding.🧠
🚀Don't let jargon hold you back!
🔐From confusion to clarity, from novice to master! Cybersecurity Dictionary for Everyone transforms your understanding of cybersecurity.
Available on Amazon! 🛒
https://t.co/DcrmsiMCBP
@JackRhysider Once inside a SCIF or SAPF, you've got to use an NSA certified network encryptor like a TACLANE to properly and legally communicate at that level. This can be used in the field, enabling global secure classified comms.
I just have one question. What is the PROPER way to send top secret communications to your team spread all over the globe? So far I've heard Signal is not it, and absolutely don't use cell phones! Sooo. What's the the protocol/app/device they should have used?
🚨🇺🇸A U.S. Cybersecurity company is allegedly up for sale. Estimated revenue is $8.6 Billion
Access type: Firewall
Account privileges: Root
Price: $1.3K
North Korea stole $1.4billion by injecting JavaScript through an AWS S3 bucket to spoof the UI interface during a transaction? It's almost like the entire infosec industry is focusing on hyperbolic amplified APT threats that are "cool" rather the stark realities confronting us.
🤖 What to Expect in Cybersecurity in 2025:
From AI-driven threats to Zero Trust adoption, the landscape is evolving fast.
Are you ready?
"CYBERSECURITY DICTIONARY For Everyone" is your shortcut to cybersecurity expertise! 🚀💪
Available at Amazon: https://t.co/rocc5yrsdy