Erka Koivunen

154 Followers
100 Following
305 Posts
An engineer by training, hacker by heart. Conditioned to think like a CISO.

Thank you to everyone who is speaking out about what russia is doing. They are waging war solely against our people, against our memory, our history, and against everything that constitutes a normal human life.

It is important that russia understands that they will be held accountable for all these crimes."

President #Zelenskyy

💬 "Last night, the russians struck #Kyiv and other Ukrainian cities and communities. The capital bore the brunt of the missile attacks, with ordinary residential buildings and schools targeted; they also burned down a food market – one of Kyiv’s oldest.

All my attempts to communicate a vulnerability in #Signalapp have failed - I have not received any response to my multiple messages to them. Good people have tried to forward my concern to them (and I am thankful for your efforts and help), yet this has been to no avail.

I am disappointed in the lack of communication from Signal. I will be disclosing the full details of the issue later today (with end-user mitigations), after the six-month anniversary of the initial report.

7 April 1937 | Czech Jewish girl, Ruth Fischerová, was born in Prague.

She was deported from #Theresienstadt ghetto to #Auschwitz on 18 May 1944. She was placed in the family camp BIIb at Auschwitz II-Birkenau. She did not survive.

Famous quotes from NASA mission comms:
- Apollo 11: "The Eagle has landed"
- Apollo 13: "Houston, we have a problem"
- Artemis 2: "We are still updating Outlook so everything but email is go"

I teach cybersecurity. And I genuinely don't know what to tell my students after this one. Federal reviewers spent years trying to get basic encryption documentation from Microsoft for its GCC High government cloud. They couldn't get it. One reviewer called the system a "pile of spaghetti pies," with data traveling from point A to point B the way you'd get from Chicago to New York: a bus to St. Louis, a ferry to Pittsburgh, and a flight to Newark. Each leg is a potential hijacking. They knew this. They said this out loud in writing. Then they approved it anyway in December 2024, because too many agencies were already using it. 🔐 That's not a security review. That's a hostage negotiation. Two things in this story should make every CISO and CIO uncomfortable:

🧩 Microsoft built its federal cloud on top of decades of legacy code that it apparently can't fully document itself
👮 "Digital escorts" often ex-military with minimal software engineering backgrounds are the firewall between Chinese engineers working on the system and classified U.S. networks 🤦🏻‍♂️

The scariest line in the whole ProPublica investigation isn't the "pile of shit" quote. It's this: FedRAMP determined that refusing authorization wasn't feasible because agencies were already using the product. Read that again. The security review process reached a conclusion based on sunk cost, not risk. Ex Post Facto Fallacy

If that logic holds, the compliance framework is just documentation theater. And right now, CISA is being hollowed out, so there are fewer people left to even run the theater.

https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/
#Cybersecurity #Microsoft #FedRAMP #Leadership #RiskManagement #security #privacy #cloud #infosec

Federal cyber experts called Microsoft's cloud a "pile of shit," approved it anyway

One Microsoft product was approved despite years of concerns about its security.

Ars Technica

A thing being repeated across businesses worldwide, including at Microsoft, is C level execs struggling to know why most staff aren’t using Copilot for M365, despite how much it costs.

Because most staff don’t spend all day in Teams meetings reading out PowerPoint slides to people who pretend to care. They have actual jobs. Doing work. Which they know how to do. Because it is their job.

Stryker filed an 8-K with the SEC saying no indication of malware on their environment - yet Palo-Alto's DFIR statement says they have removed malware from Stryker's environment.

Handala have phished Kash Patel, the director of the FBI, and released his emails.

See the prior rest of thread on this, they've been doing it for years with Israeli politicians - they just phish Gmail and iCloud logins, then sync devices.

The FBI have confirmed the emails are authentic. It looks like they are releasing them in batches.

cybersecurity 2025