38 Followers
411 Following
487 Posts
In other news, Infosec.exchange dropped over 2000 monthly active users in the past 60 days. SELL SELL SELL
#infosec hero Window Snyder finally gets the profile she deserves. https://techcrunch.com/2023/08/04/window-snyder-cybersecurity-trailblazer/
TechCrunch is part of the Yahoo family of brands

I updated my post to report that Microsoft says the critical Azure AD vulnerability has finally been completed, after almost 5 months since being informed of it. In true Microsoft fashion, Microsoft didn't communicate the complete fix to Tenable. "Toxic culture of obfuscation" indeed.

https://arstechnica.com/security/2023/08/microsoft-cloud-security-blasted-for-its-culture-of-toxic-obfuscation/

Microsoft comes under blistering criticism for “grossly irresponsible” security

Azure looks like a house of cards collapsing under the weight of exploits and vulnerabilities.

Ars Technica

One thing I’ve noticed is Mandiant now assign their own CVE like numbers to cloud provider vulnerabilities like this.

There really needs to be a properly, commonly agreed up system like CVE for this (not run by Google). I know there’s attempts at this, I hope they take off.

The illusion the cloud is magically secure is just that; an illusion. At the minute cloud providers are hiding behind lack of regulation, lack of transparency & deliberate subterfuge to protect shareholders. It’s not great.

The CEO of Tenable just ripped Microsoft a new one. It's bad enough that cloud vulnerabilities rarely get CVEs or any kind of external documentation.

"Microsoft’s lack of transparency applies to breaches, irresponsible security practices and to vulnerabilities, all of which expose their customers to risks they are deliberately kept in the dark about.

In March 2023, a member of Tenable’s Research team was investigating Microsoft’s Azure platform and related services. The researcher discovered an issue (detailed here) which would enable an unauthenticated attacker to access cross-tenant applications and sensitive data, such as authentication secrets. To give you an idea of how bad this is, our team very quickly discovered authentication secrets to a bank. They were so concerned about the seriousness and the ethics of the issue that we immediately notified Microsoft.
Did Microsoft quickly fix the issue that could effectively lead to the breach of multiple customers' networks and services? Of course not. They took more than 90 days to implement a partial fix – and only for new applications loaded in the service.

That means that as of today, the bank I referenced above is still vulnerable, more than 120 days since we reported the issue, as are all of the other organizations that had launched the service prior to the fix. And, to the best of our knowledge, they still have no idea they are at risk and therefore can’t make an informed decision about compensating controls and other risk mitigating actions. Microsoft claims that they will fix the issue by the end of September, four months after we notified them. That’s grossly irresponsible, if not blatantly negligent. We know about the issue, Microsoft knows about the issue, and hopefully threat actors don’t. "

https://www.linkedin.com/pulse/microsoftthe-truth-even-worse-than-you-think-amit-yoran%3FtrackingId=hE4qd2mSSwmpSoVPqfWAAw%253D%253D/?trackingId=hE4qd2mSSwmpSoVPqfWAAw%3D%3D

Well it's been a little while, Tŵters. I've been having my #MentalHealth break from the internet, and it's been amazing. I've read 8 books, and working on more. I've cooked, I've slept, I've visited friends; I've been resting and recuperating.

I'm feeling much better, and hope to be more active now. I hope you are all well, and that this Monday finds you peaceful and happy. x

“…we got a letter from Elon Musk’s X. Corp threatening CCDH with legal action over our work, exposing the proliferation of hate and lies on Twitter since he became the owner.” https://counterhate.com/blog/letters-from-the-lawyers-musk-threatens-ccdh-with-brazen-attempt-to-silence-honest-criticism/
Letters from the lawyers: Musk threatens CCDH with brazen attempt to silence honest criticism. — Center for Countering Digital Hate | CCDH

Elon Musk’s lawyers are threatening the Center for Countering Digital Hate with legal action for exposing Twitter’s failure to tackle hate speech. Here’s CCDH’s response.

Center for Countering Digital Hate | CCDH
If you're still using Chrome for performance reasons:
- Firefox is now faster than Chrome out-of-the-box
- Firefox uses less memory than Chrome
- Contrary to Chrome, Firefox does not restrict Ad blockers, which will make your browsing experience much faster (and safer).