Mark Morowczynski

838 Followers
93 Following
1.3K Posts
Principal Security Researcher #Microsoft. Blogger, Speaker, and Baseball Nerd. Always has an overwhelming backlog of books and video games to get through. @markmorow.com on Blusky
Twitterhttps://twitter.com/markmorow
LinkedInhttps://www.linkedin.com/in/markmorow/
GitHubhttps://github.com/MarkMorow
Bloghttps://markmorow.com/
AAD SecOps Guidehttps://learn.microsoft.com/azure/active-directory/fundamentals/security-operations-introduction

The original Secure Boot certificate expires in June 2026 - are you prepared?

Richard Hicks talks on RunAs Radio at https://runasradio.com/Shows/Show/1037 about the risk of rootkits and boot-related malware, and how you can keep your PCs safe!

Conferences come and gone, Apple in the Enterprise report card, and a great list of useful posts and tools for Mac Admins!

https://www.macadmins.news/405/

#Mac #MacAdmins #Apple

405: Conference season

Six Colors Apple in the Enterprise report card and 26.5 goes release candidate

MacAdmins.news
Launching attacks against Canvas at the most critical point of the school year harms students and adds even more strain to teachers already carrying an extraordinary burden for salaries that are far too low for the work they do.
Talked to somebody at BlueHat today that had been using AMSI in all kinds of cool and wonderful ways to defend their company. Then another person who came back to Microsoft after a stint at a social media company because they missed being able to work on products that helped defenders. They just shipped a feature that is helping companies discover workstations whose AI browsers are being abused by threat actors. It's unbelievable how energizing these stories are, but you'll never see anything like this at most industry cons.

This is *brutal*...

"There are no more juniors. There was a funeral for their passing in 2024. Nobody came. The machine does what they do now, but cheaper. Of course, juniors weren't valuable for what they produced, they were valuable for who they would become: the senior engineer who knows where the bodies are buried. We optimized for output, and abolished apprenticeship. A few years from now, we'll wonder where all the seniors are. We shot them. Nobody will remember."

https://www.stvn.sh/writing/programming-still-sucks-fqffhyp

ETA:
This is by @stevendotjs, who absolutely nails a bunch of things I've been feeling for a while now, but had no idea how to articulate...

Programming Still Sucks. — Writing

Sorry Peter. — I'm at a birthday party, and while most people here also work in tech, there's always a Guy with a Real Job. You know, a physical job, building some or other thing people need. And this Guy always asks some variant of the same question: aren't you worried AI is taking your job? I glance around and see a few faces turning around toward us, rolling their eyes ever so slightly before returning to their previous conversation. Yes, this question again.

NCSC: Leave passwords in the past - passkeys are the future https://www.ncsc.gov.uk/news/ncsc-leave-passwords-in-the-past-passkeys-are-the-future
NCSC: Leave passwords in the past - passkeys are the future

Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.

National Cyber Security Centre
Love this compilation of "The Defender's Mindset" from John Lambert. John does a lot of hiking and clearly occupies that time figuring out how to phrase things perfectly: https://medium.com/@johnlatwc/defenders-mindset-319854d10aaa
Defender’s Mindset

This is a collection of thoughts, quips, and quotes from tweets, blogs, and presentations over the years. If you find them helpful, drop me…

Medium
Passkeys are more secure than traditional ways to log in

Passkeys offer a more usable, secure replacement for passwords and are already supported by most modern devices.

National Cyber Security Centre
welcome to enterprise IT support ... 😅 https://xcancel.com/f_a_infinityy/status/2044868607822135728