This video should be watched by all in the IT security space, especially from section 5 (30mins onwards). Insights into current & future operational security challenges.
https://t.co/lGUnIXelAQ
This Discord Zendesk compromise has gotten more silly.
Previously, the Threat Actors responsible for the Discord Zendesk compromise claimed they had gotten access by compromising a BPO (Business Process Outsource) employee.
They were not lying.
It turns out that in August the Threat Actors who compromised Discord began sending emails to Discord outsourced employees offering them money in exchange for access to Discords internals.
The people they emailed was a very small team located in Southeast Asia. This particular office only has a handful of employees assigned to working Discord helpdesk (including age verification). This team is assigned to primarily handle back log work. This team had a great deal of access and were believed to be "trusted".
One of the emails this small team received offered $500 compensation to prove they're a Discord BPO employee. They offered an additional "several thousand dollar" lump sum payment in exchange for giving them access.
The Discord BPO employees were told to ignore the emails. Unfortunately, it appears one of these BPO employees did not ignore the emails and accepted the bribe.
$500 in this Southeastern Asian country is an astronomical amount of money. The "several thousand dollar" lump sum payment would be enough for this person to live comfortably for several years in their country.
One of the most tedious (but critical tasks) for software development teams is updating foundational software. It’s not new feature work, and it doesn’t feel like you’re moving the experience forward. As a result, this work is either dreaded or put off for more exciting work—or both.
Amazon Q, our GenAI assistant for software development, is trying to bring some light to this heaviness. We have a new code transformation capability, and here’s what we found when we integrated it into our internal systems and applied it to our needed Java upgrades:
- The average time to upgrade an application to Java 17 plummeted from what’s typically 50 developer-days to just a few hours. We estimate this has saved us the equivalent of 4,500 developer-years of work (yes, that number is crazy but, real).
- In under six months, we've been able to upgrade more than 50% of our production Java systems to modernized Java versions at a fraction of the usual time and effort. And, our developers shipped 79% of the auto-generated code reviews without any additional changes.
- The benefits go beyond how much effort we’ve saved developers. The upgrades have enhanced security and reduced infrastructure costs, providing an estimated $260M in annualized efficiency gains.
This is a great example of how large-scale enterprises can gain significant efficiencies in foundational software hygiene work by leveraging Amazon Q. It’s been a game changer for us, and not only do our Amazon teams plan to use this transformation capability more, but our Q team plans to add more transformations for developers to leverage.
This is a super cute token, and because it also reports the phones location, can be really helpful when things are going wrong.
It’s worth checking out:
Anyone else noticed a big spike in gmail spam inbound, from lots of random accounts, with really short bits of random text? Looks like spraying of email accounts to see what’s getting to inboxes, and what’s getting rejected
Personally, I think Microsoft should focus their efforts into removing all the consumer bloatware from their enterprise OS’s editions, rather than put resources into development games into their installers.. but what would I know..
https://t.co/NREDL7ZUDt
🚨 Absolutely insane breach info out of Microsoft.
Now that the Storm-0558 flurry has slowed down I wanted to deep dive into what we know and what we don't. 👇
Having been involved with two datacenter moves, this story is 🤯 I had the joy of trying to get servers out of a ‘union controlled’ building in Boston, now that was an experience! I’m guessing they haven’t unionised datacenters.
https://t.co/tILEDyhcGl