54 Followers
256 Following
266 Posts
non-cybersec: @kaur
Cognitive Datahttps://coda.ee
searchable

If you use AI-generated code, you currently cannot claim copyright on it in the US. If you fail to disclose/disclaim exactly which parts were not written by a human, you forfeit your copyright claim on *the entire codebase*.

This means copyright notices and even licenses folks are putting on their vibe-coded GitHub repos are unenforceable. The AI-generated code, and possibly the whole project, becomes public domain.

Source: https://www.congress.gov/crs_external_products/LSB/PDF/LSB10922/LSB10922.8.pdf

This is a story about CISA.
About what it meant and means to someone in the trenches. Years ago, and now.

Today, Jeff demonstrates in the best possible way that he is an incredibly generous and principled human being. Please allow me to direct your attention to Jeff's new initiative Stay Gold: https://blog.codinghorror.com/stay-gold-america/

Thank you Jeff for inspiring me to do more to build on the promise of the country we both live in, and support the marginalized people in our communities.

Stay Gold, America

We are at an unprecedented point in American history.

Coding Horror

If you’re dealing with Long Covid - there’s a chance you’re also dealing with MCAS and/or POTS/Dysautonomia.

They’re common comorbids and can have a devastating impact on quality of life.

New allergies? Alcohol intolerance? Dizziness? Fatigue? Fainting? Hives? Neuropathy? GI issues? Unexplained tachycardia or blood pressure swings?

These can all be caused by POTS, MCAS or a combination of both.

Mega thread of resources and guides below:

I was dealing with both of these conditions before the pandemic - and when the first Long Covid cases started popping up I remember thinking “I need to make sure I avoid Covid - it’s already causing POTS and MCAS so it might make mine worse”

I shielded as soon as I was able (and haven’t been unable to stop).

I had hope that given the sheer size of the problem - we would see accelerated research and have better treatments and/or a cure.

Instead we’ve seen an increase in dismissal and psychologizing - with many people reporting it’s HARDER to get a diagnosis now than before the pandemic.

We don’t have anything new to offer patients despite the huge increase in people with these conditions - and the few doctors willing to treat us have wait lists which have tripled in size.

Patients have to wait longer to see a doctor - and get shockingly little time with them.

Basically - we are truly on our own.

As a result patient support groups and message boards are increasingly becoming a lifeline for those newly diagnosed.

I remember how scared and lost I was at the beginning of my chronic illness journey - so I’ve spent the last few months writing guides to help patients dealing with MCAS & POTS.

My hope is they will serve as a resource for the newly diagnosed as well as for people who suspect they may be dealing with these conditions.

You will find explanations of how they impact the body, tips for obtaining diagnosis, treatment options, lifestyle adjustments and more.

I hate having to go searching for something when I’m feeling really sick - so I thought it might be helpful to include everything I’ve written in one mega thread people could bookmark or save.

With that - the guides! (One per post below)

🧵

#longcovid #pots #mcas #dysautonomia #covidisairborne # covidisnotover #sarscov2 #wearamask #MECFS #chronicillness #spoonie #pandemic

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063
Beautiful RCE. Apparently windows' local firewall doesn't protect you from this.
#patchtuesday #rce #cybersec
Security Update Guide - Microsoft Security Response Center

There is something potentially huge popping up now. Has to do with a compromise at business intelligence vendor Sisense. I'm hearing this is a supply chain attack affecting many millions of credentials and hundreds of tenants. This is a message the Sisense CISO just sent to customers.

To absolutely no one’s surprise, Trump’s USD 175 million bond payment is a fraud too.

In New York, a company which offers a bond, cannot offer a bond worth more than 10 percent of the company’s own value, and Knight Specialty Insurance does not live up to that requirement — in fact, if the company ends up having to pay the bond, the bond is worth more than the company, meaning they would not be able to pay.

Trump now has 10 days to come up with a new solution.

https://www.thedailybeast.com/new-york-ag-questions-if-dollar175-million-bond-insurer-can-save-trump

New York AG Questions if $175 Million Bond Insurer Can Save Trump

New records show the company that rescued Donald Trump from property seizures in his bank fraud case are potentially over-leveraged—and the AG wants answers.

The Daily Beast

Super-long CSRB/Microsoft breach thread continues

If it wasn't clear already, Microsoft hasn't concluded this investigation. They continue to explore the 46 hypotheses they originally came up with 9 months ago.

That also unfortunately means that there could have been more stuff compromised that Microsoft doesn't know about. Storm-0558 could still have access to systems, individual assets/identities, or the ability to generate access keys we don't know about.

Additionally, the M&A employee could also be a scapegoat - everything Microsoft has published concerning root cause analysis is a theory. It has no evidence linking this compromised employee's laptop and the MSA key theft.

Super-long CSRB/Microsoft breach thread continues

Another point the review board makes in this report that has been echoed by the White House, is that far too much onus is put on the customer to secure their accounts and data - the providers and CSPs should shoulder more of the work here.

Just look at Microsoft's most recent breach (Jan 2024 by Russia's "Midnight Blizzard"). Microsoft insists there were no vulnerabilities here, it was just cred stuffing, but then look at all the madness they recommend customers do to detect and/or prevent this kind of attack!

Is this reasonable to expect of the average M365 customer? What about personal accounts? Is there nothing Microsoft can do to ease this burden?

Not only did the State Department need some series Detection Engineering skill to discover this attack, they needed sharp SOC analysts, AND the premium audit package to get access to the necessary logs to begin with!

Figuring out how Microsoft's licensing works, understanding their products, and securing their products is a complex maze that makes the defender's job an utter nightmare, IMO.

Midnight Blizzard: Guidance for responders on nation-state attack | Microsoft Security Blog

Microsoft detected a nation-state attack on our corporate systems and immediately activated response process to disrupt and mitigate.

Microsoft Security Blog
Just to be clear: I didn't mean that I didn't do good - I did. I mean that we got unreasonably lucky here, and that we can't just bank on that going forward.