Pedant boosted

CSAM reporting requirements - not cyber security awareness month 

Reminder. For #iinfosec cyber defenders, there’s only one thing you can find where you are required by law to notify the feds immediately, before even your employer.

US Code Title 18 s2251

law.cornell.edu/uscode/text/18

Reporting requirements are s2258

law.cornell.edu/uscode/text/18

You report it to the National Center for Missing and Exploited Children here:

report.cybertip.org/

I am extremely fortunate I’ve never run into it, but I know #blueteam and #dfir people who have.

Always be the good guys. And leave these bad guys to the professionals. The amateur ‘catch a predator’ people have fubar’ed cases by not following legal procedure. Don’t give the villains an out.

Pedant boosted

The car industry is even worse for your privacy than the worst tech company -- and that's because the worst behavior of the tech industry is embedded in every car. This report from @mozilla is what Consumer Reports should have done years ago -- and it is infuriating. foundation.mozilla.org/en/priv

Pedant boosted

At #defcon31 #DARPA
announced a huge 2-year #AI #Cyberchallenge with the semis and finals hosted at good old #defcon. Over 18M in total prizes, access to cutting edge tech and a chance to help secure the open infrastructure we all rely on. If that sounds like your kind of fun, details are at aicyberchallenge.com

#AIxCC

youtu.be/DFnxrsEvs7M

Pedant boosted

The good @paperghost is on the look for a new role from next month (infosec.exchange/@paperghost/1)

Being so humble, he really doesn't sell himself well. So I'll try to pitch in by saying Chris is one of the most genuinely nice people in the industry, not to mention extremely competent, a brilliant researcher, and quite possibly delivered the <best> conference presentation I've seen in person ever.

People like this don't come on the market very often... so do whatever you can to land this man.

In other news, my daughter has completed her A levels, and the ISC2 CC, and is looking for an apprenticeship / entry level cybersecurity position. So, you have the choice of a n00b or an experienced pro. Don't say hiring is a challenge! you're welcome!

Pedant boosted

Microsoft says an initial access broker known for working with ransomware groups has recently switched to Microsoft Teams phishing attacks to breach corporate networks.

bleepingcomputer.com/news/secu

Pedant boosted
Pedant boosted

It is #BreakawayDay. Remember the 311 in Moonbase Alpha we lost with the moon. Where are they today?

Pedant boosted

Hack the fortieth anniversary of the #GNU System at the #hacker meeting in Switzerland: u.fsf.org/40f Are you located in the US and cannot fly to Europe? Celebrate with kith and kin at the FSF's office in Boston, MA: u.fsf.org/hackday #GNU40

Pedant boosted

Mozilla released emergency security updates today to fix a critical zero-day vulnerability exploited in the wild, impacting its Firefox web browser and Thunderbird email client.

bleepingcomputer.com/news/secu

Pedant boosted

You: Oh no the world is burning

InfoSec workers: Already been done now currently

Pedant boosted
Pedant boosted

I don't think I've ever read an incident report (goes from bottom to top) like this and had a more clear and escalating trend of "Oh NO!"s.

Rackspace got absolutely piledriven to the point that they completely shut their hosted Exchange service off and paid for Office365 for anyone impacted.

They've said absolutely nothing about backups, restoration, or data recovery.

You can feel with each update the incident communication responsibilities getting handed further up the ladder.

status.apps.rackspace.com/index/viewincidents?group=2

Pedant boosted

A financially motivated threat actor is hacking telecommunication service providers and business process outsourcing firms, actively reversing defensive mitigations applied when the breach is detected.

bleepingcomputer.com/news/secu

Pedant boosted

Don't let anyone tell you that you can't use #FOSS tools top-to-bottom to make things.

I like and support @fosstodon, and I thought it would be cool to #3dprint the logo for my desk. Here's what I used:

OS->#ubuntu
Browser(download image)->@bravebrowser
SVG(from image)->@inkscape
CAD(make solid from SVG)->@FreeCAD
Slicer->@prusa3D

If anyone is interested, I can upload the files so that you can make your own.
#3dprinting #freecad #inkscape

Pedant boosted

All of the #freecad parts in the post last night are from a 1970's drafting textbook that I have. I decided to try modeling the entire assembly to show that you can do it just fine using the Assembly3 workbench to put it all together after modeling each individual part. It really wasn't any harder than doing it in something like SolidWorks. @FreeCAD is an incredibly powerful tool, and it makes me happy to see more and more people realizing that and using it.

Pedant boosted
Pedant boosted

I've just scheduled the next instance of my monthly devlog livestream for #OctoPrint, "OctoPrint on Air", on next Monday. That one will be a special one because OctoPrint is turning 10! 🎂

To properly celebrate this, I've made this livestream open to everyone who wants to join me in looking back on OctoPrint's first 10 years, some celebration, and of course a chance for some Q&A.

Interested? Details here: octoprint.org/blog/2022/12/05/

🥳

Pedant boosted

I'm, uh, losing my job 😭 This is going to put me in a rough place. If anyone knows of freelance writing or podcast/video editing gigs they can send my way or boost this, I'd appreciate it tons! Here's my website that links to review samples (recently for the I Dream of Indie YouTube channel), voice work, and other things ryanjameshorner.carrd.co/

Show more
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.