IT'S HAPPENING
GITHUB, THE FIRST ENTERPRISE CLOUD SOLUTION TO REACH ZERO NINES RELIABILITY

I'm just this guy, you know!
- Views my own ๐
- Security Advisor @ Stealth Startup ๐
- ex-Staff Security dino @ Google ๐ฆ
- Purveyor of fine whisky ๐ฅ, hard mixes ๐ง๐๏ธ, & fresh bull ๐ฉ
- Zurich ๐จ๐ญ / Valencia ๐ช๐ธ
- FI/RE
DJ Mixes https://mixcloud.com/c22dnb #dnb #DrumAndBass
| Twitter :twitter: | https://twitter.com/intent/user?screen_name=ChrisJohnRiley |
| Blog โ๏ธ | https://blog.c22.cc |
| GitHub :github: | https://github.com/ChrisJohnRiley |
IT'S HAPPENING
GITHUB, THE FIRST ENTERPRISE CLOUD SOLUTION TO REACH ZERO NINES RELIABILITY

Introduction Hello, Iโm RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During this event, I discovered a remote command execution vulnerability in one of Google Cloudโs services. As the vulnerability has now been fixed, I would like to share the technical details in this article. TL;DR Google Cloud has a product called Looker, and this product has a feature to manage Git repositories.
About trans rights:
They're a wedge issue. If you think it's okay to deprive trans people of the right to exist in the public sphere then you're saying human rights are conditional and/or can be withdrawn. Which puts you on a slippery slope to no human rights for anyone.
When you trace the roots of the modern anti-trans movement they boil down to some combination of bigotry and billionaire bullshitโ the oligarchs think rights are for the rich.
So: trans-rights are human rights. No exceptions.
As you may know, Africa is big. The continent comprises 54 countries with extensive linguistic, cultural, and political variation. This can make it difficult to create communities of practise and enable the type of information sharing that are seen in other parts of the world.
In the past two years, the FIRST Africa Regional Liaison (ARL) initiative has directly supported 1,210 cybersecurity professionals, delivered more than 50 targeted initiatives across 33 countries, and maintained sustained engagement with at least 70 Computer Security Incident Response Teams (CSIRTs).
Lawrence Mulchiwa and Eric Akumiah are FIRST's Africa Liaisons and they have told their story in a blog. And it's a big story for a big place.
I teach cybersecurity. And I genuinely don't know what to tell my students after this one. Federal reviewers spent years trying to get basic encryption documentation from Microsoft for its GCC High government cloud. They couldn't get it. One reviewer called the system a "pile of spaghetti pies," with data traveling from point A to point B the way you'd get from Chicago to New York: a bus to St. Louis, a ferry to Pittsburgh, and a flight to Newark. Each leg is a potential hijacking. They knew this. They said this out loud in writing. Then they approved it anyway in December 2024, because too many agencies were already using it. ๐ That's not a security review. That's a hostage negotiation. Two things in this story should make every CISO and CIO uncomfortable:
๐งฉ Microsoft built its federal cloud on top of decades of legacy code that it apparently can't fully document itself
๐ฎ "Digital escorts" often ex-military with minimal software engineering backgrounds are the firewall between Chinese engineers working on the system and classified U.S. networks ๐คฆ๐ปโโ๏ธ
The scariest line in the whole ProPublica investigation isn't the "pile of shit" quote. It's this: FedRAMP determined that refusing authorization wasn't feasible because agencies were already using the product. Read that again. The security review process reached a conclusion based on sunk cost, not risk. Ex Post Facto Fallacy
If that logic holds, the compliance framework is just documentation theater. And right now, CISA is being hollowed out, so there are fewer people left to even run the theater.
https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/
#Cybersecurity #Microsoft #FedRAMP #Leadership #RiskManagement #security #privacy #cloud #infosec
Was (Not Was) โ Hello, Dad...I'm In Jail
https://www.discogs.com/release/2623301-Was-Not-Was-Hello-DadIm-In-Jail
A 1992 compilation album drawing tracks from from the band's first four studio albums.
Just Announced for BSides Luxembourg 2026!
๐๐๐ฌ๐ก๐ข๐ง๐: ๐๐๐๐ก๐ง๐๐ง๐ฌ ๐ฆ๐๐๐จ๐ฅ๐๐ง๐ฌ ๐๐จ๐ฆ๐ง ๐๐ซ๐ฃ๐๐ข๐๐๐ - Wendy Nather (@wendynather )
As identity ecosystems evolve, some challenges never quite get solvedโdelegation being one of them. But now, the stakes are higher than ever. With the rapid rise of non-human identities that donโt fit traditional system or application roles, organizations are facing a new layer of complexity. Even if youโre not actively using these โagentsโ yet, theyโre already becoming part of the broader digital environment. The question is no longer ifโbut how youโll manage them. Itโs time to start making deliberate decisions about identity, access, and control in this expanding landscape.
Wendy Nather ( @wendynather ) is a strategist, research director, and former CISO with over 40 years of experience in IT operations and security. Her expertise includes identity and access management, threat intelligence, risk analysis, and security operations, shaped by leadership roles in financial services, government, and industry research.
๐
Conference Dates: 6โ8 May 2026 | 09:00โ18:00
๐ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐๏ธ Tickets: https://2026.bsides.lu/tickets/
๐
Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #IdentityManagement #CyberSecurity #IAM #DigitalIdentity #SecurityLeadership