4

Kevin Beaumont (@[email protected]) - Cyberplace

 8 months ago
source link: https://cyberplace.social/@GossiTheDog
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
588a65b925fdebbe.jpeg

Kevin Beaumont @[email protected]

Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights.

I have Direct Messages disabled - you can send them, but I will never receive them.

Kevin Beaumont<p>Pinning this: if you DM me, I can’t see it, sorry - I have DMs disabled, they get yeeted into the abyss with the Star Wars Holiday Special.</p>
Kevin Beaumont<p>Lol, an hour after going public about their review situation, Bethesda finally gave Eurogamer a review copy 🙄 <a href="https://www.eurogamer.net/eurogamer-and-bethesda-starfield" target="_blank" rel="nofollow noopener noreferrer"><span class="invisible">https://www.</span><span class="ellipsis">eurogamer.net/eurogamer-and-be</span><span class="invisible">thesda-starfield</span></a></p>
Kevin Beaumont<p>Normal people who see the Starfield trailer: I may or may not play that. </p><p>Me: I’ve purchased the collectors edition, ordered about 4 other versions to see if any turned up early, built a new gaming PC, got a gaming laptop, got Starfield stickers, got a new monitor, booked time off work, read a book about sailing alone around the world referenced in the trailer. </p><p>I am not normal.</p>
Kevin Beaumont<p>Just asked my girlfriend to describe me. </p><p>She shouted KAMIKAZE! in a Worms voice. </p><p>She knows me well.</p>
Kevin Beaumont<p>Pleased to see National Cyber Force and FBI joining the Starfield Ceasefire initiative by nuking Qakbot in advance. 🫡</p>
Kevin Beaumont<p>Found the runway.</p>
Kevin Beaumont<p>Qakbot = ransomware entry. Everybody calls it banking trojan, but it really wasn't for a loooong time. </p><p>It was live on 700k endpoints (!) which should give you an idea of the scale of cybersecurity woes at many orgs (it's still really, really bad out there).</p>
Kevin Beaumont<p>Qakbot tango down. Thank you to everybody who worked on this. <a href="https://www.fbi.gov/news/stories/fbi-partners-dismantle-qakbot-infrastructure-in-multinational-cyber-takedown" target="_blank" rel="nofollow noopener noreferrer"><span class="invisible">https://www.</span><span class="ellipsis">fbi.gov/news/stories/fbi-partn</span><span class="invisible">ers-dismantle-qakbot-infrastructure-in-multinational-cyber-takedown</span></a></p>
Kevin Beaumont<p><a href="https://cyberplace.social/tags/GossiAirways" class="mention hashtag" rel="tag">#<span>GossiAirways</span></a> first night flight on the new monitor.</p>
Kevin Beaumont<p>Bethesda haven't provided Eurogamer, a big outlet, with a Starfield review copy. They have to Digital Foundry - with the requirement it isn't shared with Eurogamer. <a href="https://www.eurogamer.net/eurogamer-and-bethesda-starfield" target="_blank" rel="nofollow noopener noreferrer"><span class="invisible">https://www.</span><span class="ellipsis">eurogamer.net/eurogamer-and-be</span><span class="invisible">thesda-starfield</span></a></p>
Kevin Beaumont<p>btw - one bit of misinformation I've seen online. There's a TON of posts and reviews for this monitor saying DisplayPort 1.4 can only do 60fps in 8K ultra widescreen - I can't find a single one that says otherwise. </p><p>Here's my RTX 4090 happily doing 7680x2160 at 120hz in HDR, and The Last of Us running (~80fps average at full res in Ultra), Mastodon will downsize the image and compress.</p><p>Also, I realise this post is super privileged.</p>
Kevin Beaumont<p>ANNOUNCEMENT: all hacking paused from Friday until the end of September so we can play Starfield. Please let everybody know.</p>
Kevin Beaumont
Kevin Beaumont
Kevin Beaumont<p>15gb <a href="https://cyberplace.social/tags/Starfield" class="mention hashtag" rel="tag">#<span>Starfield</span></a> patch out, nothing groundbreaking. </p><p>Does confirm ROG Ally and Steam Deck compatibility.. but points out both devices are well below minimum spec so you’re in potato mode. </p><p>Patch notes: <a href="https://insider-gaming.com/details-on-first-starfield-early-access-patch/" target="_blank" rel="nofollow noopener noreferrer"><span class="invisible">https://</span><span class="ellipsis">insider-gaming.com/details-on-</span><span class="invisible">first-starfield-early-access-patch/</span></a></p>
Kevin Beaumont<p>I upgraded my crazy 32:9 super widescreen monitor to an even more crazy larger 32:9 one with 8K resolution. </p><p>Starfield is gonna shit a brick when it sees this thing - 7680x2160 resolution.</p>
Kevin Beaumont
Kevin Beaumont
Kevin Beaumont<p>Lol I shouldn’t toot about anything Starfield related.</p>
Kevin Beaumont<p>One thing I've learnt from <a href="https://cyberplace.social/tags/GossiAirways" class="mention hashtag" rel="tag">#<span>GossiAirways</span></a> is a new found respect for pilots of older aircraft. </p><p>Some of these are an absolute deathtrap - just crashed one as I pressed a button on the cockpit that actually turned out to be pilot's door release button.</p>

InfoSec about to be suspended again

1c303d426857fc46.jpeg

NATS (air traffic control) has crashed, on a bank holiday again.

Place your bet below.

https://www.bbc.co.uk/news/live/uk-66637817

  • 11%BGP
  • 48%DNS
  • 41%Failed change
· 850 people · Closed
Kevin Beaumont<p>A reminder that lockdown mode on iPhone and iPad is excellent in my experience, doesn’t break much and is good step to enable for high risk individuals. <a href="https://support.apple.com/en-gb/HT212650" target="_blank" rel="nofollow noopener noreferrer"><span class="invisible">https://</span><span class="ellipsis">support.apple.com/en-gb/HT2126</span><span class="invisible">50</span></a></p>
Kevin Beaumont
Kevin Beaumont<p>. <span class="h-card"><a href="https://mastodon.world/@tomwarren" class="u-url mention">@<span>tomwarren</span></a></span> playing Destiny and Windows 11 prompt him to change his search engine to Bing. I’m getting these beg prompts in games too - had one in Skyrim.</p><p>Maybe we should start a GoFundMe for the trillion dollar company with record share price.</p>
Kevin Beaumont<p>Good news, we can all retire! </p><p>“Darktrace’s Cyber AI Loop prevents, detects, responds, and heals from cyber-attacks, all at once, at all times, everywhere an organization touches data and people, whether that’s outside on the attack surface or inside the organization.”</p>

Elon turned up at a VALORANT video game conference. Just saw a video of it, when people realised he was there he got mass boo’d 🤣

PSA re #Starfield as Bethesda haven't set expectations with this well - you cannot land and walk around the entire planet in one, it's not No Man's Sky.

You can set a landing spot anywhere, then there's invisible walls around your ship - a 2km x 2km tile. You explore around your ship. You can move landing spot around by taking off and landing somewhere else.

It's still a really big area and not a problem at all IMHO. But there's going to be a fanbase meltdown about it I suspect.

Replied to Kevin Beaumont

#GossiAirways successful* landing.

* skidded off the runway and nearly crashed into a wind turbine.

6c0215207eefcda5.png

Upgraded toot.io to the latest beta to test the new search feature.

The search is opt-in and users can enable it in the privacy and reach tab to have the posts findable.

Currently indexing 40,663,353 rows with ETA 7 hours. Lets see how this turns out.

#mastoadmin

#GossiAirways from Manchester Barton to somewhere in Wales (need to find somewhere soon as running out of daylight).

fe59c5b0c5d82f14.png

I installed Winamp. In 2023, it includes an "NFT library"

Replied to Kevin Beaumont

Back in December 2022, #Rackspace got hit with ransomware on their Hosted Exchange, via exploitation of ProxyNotShell - as I reported at the time.

Rackspace have so far spent north of $10m on incident response. This excludes ongoing legal and professional services costs.

Outside of the $10m there are other costs listed. I think it's safe to say the Microsoft Exchange incident cost Rackspace... a lot - they list it as a primary factor in decrease in revenue. https://www.expressnews.com/business/article/rackspace-expenses-ransomware-attack-18331049.php

3211943f5e7743bf.png

There's an open world Avatar game coming out in December, featuring a huge world, first person, go anywhere freedom.

I'm really curious about it as there's a lot going on. https://www.youtube.com/watch?v=HtGGzRQDq4I

null

If you want to do some AV evasion with Powerpoint, encrypt your doc with the password /01Hannes Ruescher/01 😄

0c95e07a29bcfad6.png
Replied to Kevin Beaumont

Here's an interactive demo (non-malicious code) on roughly what they're doing, except threat actor delivers Update.js to execute SocGholish. https://jsfiddle.net/pYpqW/

A bit of #threatintel - I see SocGholish aka FakeUpdates have started using .js files with data URI for download.

They store the entire Javascript file in a data: tag inside a HTML webpage, then call Javascript to download it as a file. Acts as proxy and EDR evasion attempt.

Giveaway: Mark-of-the-Web is set to about:internet

Advanced Hunting Query: https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/Find-DataUri-Javascript-SOCGholish.ahq


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK