Todd Wilkinson

7 Followers
84 Following
24 Posts

Good day everyone. It is a new month and that is my cue to remind you to support your fediverse instance. Operating fediverse instances is not free, and nearly all instances are run by volunteers and funded by donations. If you do not already do so and are in a financial position to do so, please consider it. You can generally find information on how to support your instance on it's about page (for example https://infosec.exchange/about for people who use infosec.exchange)

I am super fortunate to have supportive members, but not all instances are so lucky and so I am asking on their behalf, so please, if you get value from this service, consider supporting your instance.

Thank you all and I hope you have a great week!

Infosec Exchange

A Mastodon instance for info/cyber security-minded people.

Mastodon hosted on infosec.exchange

I am counting down the 100 days left till my term as a CISO comes to an end with some humor and wisdom I've picked up over the past 4 years.

100 days left...

It can be intimidating to deal with external security researchers that have identified security defects in your products and are looking to gain some PR exposure. The initial response of many companies is to trot out the lawyers with threats of legal action. For the most part, security researchers are reaching out because they want partner with you. They ARE going to write about problems with your products, but you can be seen as embracing the process and using it as an opportunity to improve, or you can be viewed as obstinate and trying to hide your flaws. I've had the opportunity to work with many researchers over the years, and I've found in every single instance, kindness, responsiveness, and just taking their feedback seriously goes a long way.

I'll say this outloud, I am enjoying the MSFT experience with yubikey and disabling the other auth methods. It works on multiple devices and hasn't left me stranded yet.

I am going to start moving Infosec.exchange behind Fastly. If it goes well, no one will notice. If I screw up, you’ll notice.

My money is on screwing up.

Upgraded my kid's run-down secondhand power wheels from its original 12v battery to the 20v lithium ion out my my weedwacker.

It may now be slightly dangerous. β€‹

Well for what it’s worth I don’t see these in my YT feed. But again cyber + hvac + weather + Ukraine feeds may not be top of the list to get these :)

Everyday I am made to feel guilty for using an Ad blocker. Today I am reminded why I should not.

https://www.bleepingcomputer.com/news/security/fake-cisco-webex-google-ads-abuse-tracking-templates-to-push-malware/

Fake Cisco Webex Google Ads abuse tracking templates to push malware

Threat actors use Google Ads tracking templates as a loophole to create convincing Webex software search ads that redirect users to websites that distribute the BatLoader malware.

BleepingComputer

I am very glad today that I had accidentally bought an extra A/C unit condensate pump a few years ago. Saved me some big money on a service call.

Also, I hate condensate pumps.

#homeimprovement

This is getting ridiculous

U.S. shoots down a fourth high-altitude object as lawmakers demand more information https://www.cnbc.com/2023/02/12/members-of-congress-need-more-information-about-high-altitude-objects-.html

As new high-altitude objects are shot down over North America, lawmakers say they need more information

Members of Congress say they have not been briefed about all three high-altitude objects downed in the airspace above the U.S. and Canada.

CNBC
Thanks to our Discord auction revenues, we were able to buy 80 pairs of resin boots for Ukrainian troops at the front lines. 50% of the proceeds from every auction goes to support Ukrainian humanitarian aid. http://discord.aravosis.com
Join the THE ARAVOSIS REPORT Discord Server!

Check out the THE ARAVOSIS REPORT community on Discord - hang out with 1,382 other members and enjoy free voice and text chat.

Discord