We open sourced the tool used to detect the Axios supply chain compromise! I built it Friday after a red eye home from RSAC. Also, wrote up the full story, including the hectic moments after that first critical alert
https://t.co/HAm8eMr8vO
This was a cool project for a few reasons. First, some of us have been working with Texas A&M since Endgame and it’s a partnership with a ton of history! Also it is a blast for us to work with other experts to achieve successes!
Today’s a good day to recommend this exceptional book by @KimZetter: Countdown to Zero Day. Easily in my top 2 cybersecurity books, right after The Cuckoo’s Egg by Clifford Stoll.
There’s even an audiobook version for your next commute or evening walk.
Amazon
📘 https://t.co/RSYqDSUqFA
Google
📖 https://t.co/ntGOzd4rkd
Audible
🎧 https://t.co/8u5EuVDprZ
finally completed a very important task i’ve been avoiding for several months. it took 8 minutes and zero effort on my part and i felt immediate and immense relief. i probably won’t learn from this
"The nation-state supply chain plot was foiled, not by the NSA or FBI, but Steve from the build team when his test build process took 837ms instead of 214ms like it always had."
It's Mission Impossible, but with a firmware engineer to hunt down the upstream latency root cause.
@dnlongen Yep. Least priv, phish resistant MFA & updated investigation guides to inform the analysts. I’m curious as to what kind of risk calculus the MFA vendors are putting into their logic.