Patrick C Miller 

@patrickcmiller@infosec.exchange
4.4K Followers
1.5K Following
45.3K Posts
Critical Infrastructure & Industrial Security Advisor. Recovering regulator. Airport dweller. #PDX-based. @ampyxcyber President and CEO. CCI US Coordinator. @beerisac coin 001. #ICS #OT #NERCCIP #NIST #TSASD #DHSCPG #IEC62443
Websitehttps://www.patrickcmiller.com/
Companyhttps://www.ampyxcyber.com/
LinkedInhttps://www.linkedin.com/in/millerpatrickc/
Podcasthttps://rss.com/podcasts/amperesec/
Here’s what could happen if CISA 2015 expires next month https://cyberscoop.com/cisa-2015-expiration-industry-warning-threat-information-sharing/
Here’s what could happen if CISA 2015 expires next month

Expiration of a 2015 law could dramatically reduce cyber threat information sharing within industry, as well as between companies and the federal government, almost to the point of eliminating it.

CyberScoop

A working QR code in the style of Piet Mondrian. Inspired @divbyzero and @andrewt.

#Art #PietMondrian #QRCode

NIST Releases NIST SP 800-171, R3 Small Business Primer https://content.govdelivery.com/accounts/USNIST/bulletins/3edd8d7
NIST Releases NIST SP 800-171, R3 Small Business Primer

National Institute of Standards and Technology (NIST)

@patrickcmiller

impatience, naivety, overconfidence

How about lack of relevant education from their olders combined with companies specifically MISEDUCATING them?

Budget-conscious youngsters may be more inclined to look for such content on third-party app stores, forums and other sites.

Actually... this is a normal and good behavior. They are just missing massive swaths of foundation to do this safely.

Only going with Major Brand Downloading Sites has not exactly been good for privacy, and leads to content getting lost at the whims of the host.

Always stick to official app stores

Put google's bullshit in that threat model or so help me

Deploy security software from a trusted provider to all PCs and devices.

Way too vague. Put Norton's bullshit in your threat model or so help me

Put Nord's bullshit in your threat model or so help me

to share knowledge, and communicate risk with empathy and understanding.

Well yes... but also... we need to share the Old Tools with them as well. What they are doing is Not New, and they need access to the whole woods to do it correctly, not just a gated garden.

Let's teach em how to use popularity to judge a tool, how to swing a proverbial hammer, and what preditors are out there, then let em go build their own forts.

They're clever kids. They're just missing some key knowledge.

@patrickcmiller

Deliberately sensational headline for clicks; buried lede:

In an email FIDO Alliance CEO Andrew Shikiar cast doubt on the seriousness of the vulnerability. “The attack described here does not reflect a vulnerability in passkeys or FIDO protocols,” he said. “Rather, it illustrates the importance of service providers moving entirely away from passwords and other phishable sign-in methods as soon as possible."

See the replies in my thread here for why:

https://infosec.exchange/@tychotithonus/115030865003149160

Royce Williams (@tychotithonus@infosec.exchange)

Oh look, another breathless "door bypass (by going through a window that the site designers left unlocked)" story. https://www.darkreading.com/cybersecurity-operations/downgrade-attack-phishing-kits-bypass-fido Does it need to get fixed? Absolutely. Is it a "FIDO bypass"? No.

Infosec Exchange
WarLock Ransomware group Claims Breach at Colt Telecom and Hitachi https://hackread.com/warlock-ransomware-group-breach-colt-telecom-hitachi/
WarLock Ransomware group Claims Breach at Colt Telecom and Hitachi

Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Colt Customers Face Prolonged Outages After Major Cyber Incident https://www.infosecurity-magazine.com/news/colt-outages-after-major-cyber/
Colt Customers Face Prolonged Outages After Major Cyber Incident

The Warlock ransomware gang has taken credit for the cyber-attack after the UK telco giant publicly confirmed an incident on August 14

Infosecurity Magazine
HR giant Workday discloses data breach after Salesforce attack

Human resources giant Workday has disclosed a data breach after attackers gained access to a third-party customer relationship management (CRM) platform in a recent social engineering attack.

BleepingComputer
Man-in-the-Prompt: The invisible attack threatening ChatGPT and other AI systems

Man-in-the-Prompt: a new threat targeting AI tools like ChatGPT and Gemini via simple browser extensions, no complex attack needed.

Security Affairs
Scammers Compromised by Own Malware, Expose $4.67M Operation https://hackread.com/scammers-compromised-by-malware-expose-operation/
Scammers Compromised by Own Malware, Expose $4.67M Operation

Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto