Shared posts

13 Jan 23:34

The Daily Stream: Yes, God, Yes Nails The Sinful Self Discovery Of The Early Internet Era

by BJ Colangelo

(Welcome to The Daily Stream, an ongoing series in which the /Film team shares what they've been watching, why it's worth checking out, and where you can stream it.)

The Movie: "Yes, God, Yes"

Where You Can Stream It: Netflix

The Pitch: Based on director Karen Maine's viral short film, in the year 2000, Alice ("Stranger Things" star Natalia Dyer) is a sexually inexperienced but extremely curious junior attending a strict, Iowa Catholic high school. Alice has been taught her entire life that all sex acts (including masturbation) outside of married, heterosexual attempts at making children, are sinful and will result in eternal damnation. Feeling severely judged by her best friend Laura (Francesca Reale) and her teacher, Father Murphy (Timothy Simons), Alice struggles to accept her burgeoning urges of sexual desire, her newly formed fetish for men with hairy forearms after a spicy chat on AOL, and how it all conflicts directly with everything she's ever been told about sex despite how natural it feels. In this pre-social media era where pornography is still difficult to come by, "Yes, God, Yes" is a trip down a pixelated memory lane.

Why It's Essential Viewing

Coming-of-age films are nothing new, but films that explore the reality that teen girls are just as sexually curious and experiencing just as strong urges as teen boys, surprisingly is. "Yes, God, Yes" was unceremoniously dropped on Netflix in October of 2020, and has gone severely underseen because of it. I first caught the movie looking for films to cover on my coming-of-age movie podcast, This Ends at Prom, and absolutely fell in love. I fortunately did not grow up attending Catholic school, but I did grow up in one of the most religious areas in Illinois. It didn't matter how open or affirming my parents were, I was surrounded by the constant social messaging that everything I felt was "wrong" and that I should feel guilty for existing this way. "Yes, God, Yes" perfectly explores that absolute bulls*** we feed teenagers under the guise of morality, like how rewinding the car scene from "Titanic" is a sin.

Alice spends most of the movie feeling like there's something wrong with her for experiencing sexual desire, and after an un-true rumor circulates about her "tossing a guy's salad" at a party, she attends a Kirkos retreat (a very lightly fictionalized version of the real-life Kairos retreats) to try to make sense of what she's going through. The retreat is Catholic cringe to the max, including a group visualization exercise to Peter Gabriel's "In Your Eyes" with the task of imagining the song is about Jesus' eyes. The ridiculousness of the retreat only furthers Alice's confusion, because it's hard to take anyone's word seriously when the nuns are reading "The Pelican Brief."

A Lesson In Hypocrisy

"Yes, God, Yes" is a serious coming-of-age film, but is deeply funny in the most unexpected ways. After Alice is punished with cleaning the mess hall after it is discovered that she didn't turn in her cell phone, the ultra-perfect Catholic Nina (Alisha Boe) brings her a s'mores since she didn't get to make them with the group. "We pretended each marshmallow was a mortal sin before burning it ... yours was lust," she says with a toothy smile. Even with alleged kind intent, everyone around Alice finds different ways to make her feel weird for her natural urges, and as Alice soon discovers, everyone around her is totally full of s***.

I don't think I need to educate anyone on the hypocrisy of all religious institutions in regard to sex, but "Yes, God, Yes" shreds it apart in some beautifully hilarious ways. If you loved Timothy Simons on "Veep," you will be absolutely obsessed with him as the sanctimonious Father Murphy. He feels like every "hip and cool" youth pastor you've ever seen, but without a hint of irony. It's a truly inspired performance, and one that makes Alice's vindication about realizing it's totally normal for a girl her age to be thinking about sex, even sweeter.

The Importance Of Affirming Adults And Self Acceptance

When things get to be too much at the retreat, Alice bails and heads toward town, stopping at what turns out to be a lesbian bar. While she's there, she crosses paths with bar owner Gina (Susan Blackwell) and for the first time in her life, an adult gives her the honest truth, and doesn't make her feel like an idiot for being human. This moment is without a doubt one of the best "come-to-Jesus" moments in a coming-of-age film, pun fully intended. "I literally thought I was going to hell for eating gum drops" is a line that lives rent free in my head. Typically these adult-guiding-teenager moments happen in films in the form of parental guidance or a teacher, but "Yes, God, Yes" is a beautiful example of the importances of intergenerational community.

"What if we just tried to be honest and treat each other with respect? That is what Jesus wanted, right?" I hate to compare the two, but "Yes, God, Yes" feels like a spiritual sibling to "Lady Bird," but one with a little less A24 polish and a lot more uncomfortable realism. With so many films available on Netflix, plenty slip through the cracks and go unwatched unless someone tells you to go and look for it. Well, friends. This is me telling you to track down "Yes, God, Yes," and enjoy one of the best coming-of-age films in years.

Read this next: The Daily Stream: Red Eye Is A Sturdy, Solid Thriller From The Late, Great Wes Craven

The post The Daily Stream: Yes, God, Yes Nails the Sinful Self Discovery of the Early Internet Era appeared first on /Film.

13 Jan 22:15

A history of 'Dragon's Lair'

by Jason Weisberger

Dragon's Lair! The fantasy adventure where you became a bumbling knight on a goofy quest to rescue a manic pixie dream girl from the clutches of a beautifully animated dragon! You control an occasional action as the hapless chump explores a dark and dangerous Wizard's castle, enchanted with monsters and traps! — Read the rest

13 Jan 22:14

How to make Windows 11 run better on old, cheap devices

by noreply@blogger.com (Unknown)
window 11

Microsoft is working on a new update for Windows 11 that will make the new operating system (OS) run better on dated and inexpensive hardware.

Windows 11 Build 22526 has currently been made available to members of the Insider early access programme with multiple enhancements and fixes, Techradar reported. It is yet not clear when the update will be rolled out to the public.


Though most of the new features are minor, the software giant is using this update to try out a new file location indexing system, hoping that the build will enable users to find out important files even faster using File Explorer.

The File Explorer of the recently released Windows 11 works very slow and is still prone to frequent crashes. Users often have to suffer due to the slowness of the Search functionality.

It takes a long time to return relevant searches if users have stored a huge number of files in the built-in hard drive.

The new update could help you cruise through large number of files more quickly.

More importantly, it will be very helpful for users who are running Windows 11 on cheap and dated devices that suffer lengthy load times affecting performance.

Other upgrades that will be released in the upcoming Windows 11 update include wideband speech support which will improve the audio quality of voice calls if you are using products such as Apple Airpods.

There will also be a new “windowed” system to the popular Alt + Tan functionality.

13 Jan 22:11

The Legend Of Vox Machina Trailer: A Super High-Intensity Team Of Heroes

by Anya Stanley

A brand new campaign begins for fans of Dungeons and Dragons and tabletop RPGs in general, no dice needed. The folks behind D&D web series "Critical Role" have created a new animated fantasy series based on the first campaign played on the show from 2015 to 2017, over 115 episodes. "The Legend of Vox Machina" is coming to Amazon Prime this month; the streaming giant ordered two seasons, totaling 28 episodes about a ragtag group of adventurous guns for hire -- and they curse, flip the bird, and bleed profusely. The first season (with 12 episodes) drops on Prime Video on January 28, 2022.

Trailer For The Legend Of Vox Machina

The series is a labor of love; Critical Role fans, or "Critters," turned out en masse to back a Kickstarter campaign that broke records, netting $11,385,449 in pledges from over eighty thousand backers. Amazon Studios caught wind of the incredible Critter support and added the show to its already impressive adult animation slate that includes "Invincible," based on Robert Kirkman's comic of the same title.

Returning to their respective roles in the "Critical Role" campaign are stars Matthew Mercer as Sylas Briarwood, Ashley Johnson as the gnome Pike Trickfoot, Travis Willingham as the barbaric Grog Strongjaw, Laura Bailey as half-elf ranger Vex Vessar, Liam O'Brien as half-elf rogue Vax Vessar, Taliesin Jaffe as (deep breath) Percival "Percy" Fredrickstein Von Musel Klossowski de Rolo III, Marisha Ray as the druid Keyleth of the Air Ashari, and Sam Riegel in the role of the gnome bard Scanlan Shorthalt.

Mercer serves as showrunner and executive producer of the series, which was created in 2012 for his own Dungeons & Dragons campaign before becoming a live play web series. The eight Critical Role founders and stars also executive produce along with Brandon Auman and Titmouse's Chris Prynoski. "The Legend of Vox Machina" is further backed by Amazon Studios, Critical Role, and animation studio Titmouse, the folks behind Adult Swim series' "Metalocalypse," and "The Venture Bros.," and Netflix series "Big Mouth."

The synopsis, per Amazon:

They're rowdy, they're ragtag, they're misfits turned mercenaries for hire. Vox Machina is more interested in easy money and cheap ale than actually protecting the realm. But when the kingdom is threatened by evil, this boisterous crew realizes that they are the only ones capable of restoring justice. What began as a simple payday is now the origin story behind Exandria's newest heroes.

"The Legend of Vox Machina" arrives on Amazon Prime on January 28. 2022.

Read this next: The 15 Best Board Games Of 2021

The post The Legend of Vox Machina Trailer: A Super High-Intensity Team of Heroes appeared first on /Film.

13 Jan 21:41

PolarProxy 0.9 Released

by Erik Hjelmvik
PolarProxy 0.9

PolarProxy was previously designed to only run as a transparent TLS proxy. But due to popular demand we’ve now extended PolarProxy to also include a SOCKS proxy and a HTTP CONNECT proxy. PolarProxy automatically decrypts all proxied SSL and TLS traffic, regardless if the remote server is running on TCP 443 or some other port, as long as the traffic passes through PolarProxy. As from now we also release a Windows build of PolarProxy, alongside the Linux x64, ARM and ARM64 builds.

SOCKS Proxy

Use the command line argument “--socks [port]” to start PolarProxy’s SOCKS proxy server. This SOCKS proxy supports multiple versions of the SOCKS protocol, including SOCKS 4, SOCKS 4a, SOCKS 5 and SOCKS 5h.

As an example, the command below starts a SOCKS server on TCP port 1080 and passes a copy of the decrypted TLS traffic as a PCAP stream to tshark.

PolarProxy --socks 1080 -w - | tshark -r - -d tcp.port==443,http2
Note: The “-d tcp.port==443,http2” argument in the command above is used to tell tshark to parse traffic to port 443 as HTTP/2 instead of TLS. An alternative method would be to instead configure PolarProxy to output decrypted 443 traffic as if it was port 80, by supplying the “-p 443,80” argument to PolarProxy.

You can then use curl to run some HTTPS traffic through the SOCKS proxy:

curl --insecure --socks4 localhost https://www.netresec.com

After doing this you should see the decrypted HTTP/2 traffic in tshark’s output.

HTTP CONNECT Proxy

We’ve also added a HTTP proxy to PolarProxy 0.9, but it only supports the CONNECT request method. This means that normal unencrypted HTTP requests, like GET or POST requests, will be rejected by PolarProxy. Most web traffic is TLS encrypted nowadays anyway, so we don't consider this limitation to be a big issue.

The HTTP CONNECT proxy service is activated with the “--httpconnect” argument. Decrypted TLS traffic from PolarProxy’s HTTP CONNECT proxy can be forwarded to tshark just like in the SOCKS example, but the traffic from these proxies can also be accessed through PCAP-over-IP like this:

PolarProxy --httpconnect 8080 -p 443,80 --pcapoverip 57012

You can then connect to PolarProxy’s PCAP-over-IP service with NetworkMiner by clicking File, Receive PCAP over IP, select “Connect to IP/port”, enter “localhost” and click the “Start Receiving” button. You’ll now be able to see a real-time feed of all the traffic that PolarProxy decrypts. As an example, let’s download the PolarProxy logo over HTTPS to see if NetworkMiner can extract it from PolarProxy’s decrypted PCAP-over-IP stream:

curl --insecure --proxy localhost:8080 https://www.netresec.com/images/PolarProxy_313x313.png

The PolarProxy logo immediately shows up in NetworkMiner’s images tab:

NetworkMiner reading PCAP-over-IP from PolarProxy

Port-Independent TLS Protocol Detection

When PolarProxy is running as a transparent TLS proxy all incoming traffic can be expected to be TLS. But that’s not the case when, for example, PolarProxy is running as a SOCKS proxy. We have therefore added port-independent TLS protocol detection for proxied traffic, so that TLS traffic can be detected and decrypted even when it runs on other ports than the standard 443, 465, 853, 990, 993, 995 and 5061 ones.

There is one crucial limitation to the automatic SSL/TLS protocol detection though, it doesn’t support explicit TLS traffic that relies on opportunistic encryption features like STARTTLS, which bootstraps TLS into an already established application layer session.

Allow Non-TLS Traffic

SOCKS and HTTP CONNECT proxies can both be used to transport other protocols than TLS. PolarProxy blocks all non-TLS traffic by default, but this setting can be overridden with the “--allownontls” argument to allow any traffic to be proxied. The allow non-TLS override has no effect on PolarProxy’s transparent proxy though, because it will need to see a valid SNI field in order to know whereto the traffic should be forwarded.

Windows Build

There wasn’t much need for a Windows build of PolarProxy prior to the release of version 0.9, because the Windows firewall can’t be configured to redirect outgoing port 443 traffic to a local service. However, now that PolarProxy also includes SOCKS and HTTP CONNECT services, the situation is completely different. There are many ways to configure a Windows PC, as well as web browsers and other applications, to use a local proxy server.

You can use the Proxy settings window in Windows 10 and 11 to enable a local HTTP proxy like this:

Windows 10 Proxy Settings

Another option is to run “inetcpl.cpl” (Internet Options), open the “Connections” tab and click the “LAN settings” button to configure an HTTP proxy.

Windows Internet Options LAN Proxy Settings

You can, of course, also configure your browser to use a local SOCKS or HTTP proxy in Windows, just as you’d do on any other operating system.

But don’t forget to configure your OS and/or browser to trust your PolarProxy instance’s root CA certificate first, as explained in the “Trusting the PolarProxy root CA” section of our PolarProxy documentation.

The Windows version of PolarProxy is a .NET framework-dependent application, which requires the .NET 6 runtime to be installed. The PolarProxy releases for other platforms (Linux x64, ARM and ARM64) are all self-contained applications, which are published with the .NET runtime built-in.

Visit our PolarProxy page to download and install PolarProxy.

13 Jan 21:39

How Harrison Ford Once Tried To Destroy The Millennium Falcon Set, According To Mark Hamill

by Miyako Pleines

A long time ago, on a movie set far, far away ... the Millennium Falcon was in danger of being destroyed by the person who called it home. Yes, it's true. Everyone's favorite hunk of space junk was almost single handedly dismantled by none other than Harrison Ford. If you don't know by now (and if you truly don't, I really can't help you), Ford plays the ever-cocky but always lovable smuggler Han Solo throughout the "Star Wars" saga. Formidable love interest to the iconic Princess Leia (Carrie Fisher), Han Solo is not a man to be messed with, and apparently, neither is the "Indiana Jones" star.

According to Mark Hamill, who plays Luke Skywalker (again, if you don't know this, what are you doing here?), Ford had a bit of a temper while filming "Star Wars." In an article for Showbiz Cheatsheet, Hamill's relationship with Ford is described as nothing short of besties. They apparently liked to dance alone together to bad of-the-moment pop songs in Hamill's dressing room. Be still your "Star Wars"-loving heart. Their close bond on set likely explains why it was Hamill who was able to calm a raging Ford and prevent him from destroying — or at least severely damaging — what is arguably one of the film's most important sets: the Millennium Falcon.  

The Millennium Falcon Vs. Harrison Ford And A Saw

In an interview for Empire, Hamill openly talked about Ford's apparent anger outburst one day on set. "You heard about Harrison taking a saw to the Millennium Falcon because he got so mad?" he asked. "People were coming up to me going, 'You gotta stop Harrison, he's sawing up the Falcon.'"

Truthfully, this sounds like a pretty Han Solo-y thing to do, which only adds to the long list of reasons why Ford was perfect for the role. I mean, can't you just see Han, blind with rage over some unfortunate Falcon malfunction, taking the galaxy equivalent of a saw and claiming he's going to chop his ship to pieces? Maybe a panicked C-3PO and Chewie rush onto the scene to stop him. Sounds like a great outtake to me. 

Anyway, it turns out Ford was angry (about what, we don't know) and decided to take his rage out on the fastest hunk of junk in the galaxy. Hamill was the one who stepped in and put a stop to the madness before any real damage could occur. "It was made of wood and he just took a saw to it," he said in the Empire interview. "I love Harrison. I got to stop him because I can make him laugh when he gets really, really mad." 

While Chewbacca is Han Solo's best friend on screen, it seems like the bond between Ford and Hamill was strong enough to stop a potentially catastrophic fit of rage from causing some setbacks during filming. We may never know the specifics of Harrison's apparent rage, but we sure are glad Hamill was able to step in and save the Falcon from its own captain's potentially destructive hands, though in all honesty, it would take much, much, more than a saw to bring the Falcon down for good. 

Read this next: Star Wars Movie Villains Ranked Least To Most Powerful

The post How Harrison Ford Once Tried to Destroy the Millennium Falcon Set, According to Mark Hamill appeared first on /Film.

13 Jan 21:23

Learn about 4 approaches to comprehensive security that help leaders be fearless

by Emma Jones

The last 18 months have put unprecedented pressure on organizations to speed up their digital transformation as remote and hybrid work continue to become the new normal. Yet even with all the change and uncertainty, having the right security support system in place means your organization can still move forward confidently to turn your vision into reality. I’ve seen our customers demonstrate this fearlessness every day, and I love learning from them as we stand together against ongoing threats.

According to the Microsoft Zero Trust Adoption report,1 security is the top concern for organizations moving to hybrid work, and it’s the number one reason that security professionals are adopting a Zero Trust approach. According to the report, only 31 percent of organizations that reported being ahead with their Zero Trust implementation were impacted by NOBELIUM, the perpetrators of the SolarWinds attack.2 Compare that to the 75 percent negatively affected by this devastating cyberattack that reported lagging behind in their Zero Trust implementation.

Zero Trust Adoption Report bar chart showcasing the varying levels of Zero Trust adoption across Microsoft Exchange, Zoom Credentials, SolarWinds, Robinhood, Intel, and Fireye.

Figure 1: Negative impacts of cyberattacks in relation to Zero Trust implementation.

Knowing that your organization is protected from such threats, both external and internal, helps build the confidence you need to succeed. Zero Trust is a strategy that will help you get there. At Microsoft Security, we’re embracing the new reality of hybrid work by providing comprehensive security with best-in-breed coverage—driven by AI and simplified for easy management—so you can be fearless in the pursuit of your vision. In this blog, I’ll share some of our customers’ stories and how they’ve empowered their teams to move forward with confidence during this time of unprecedented change.

1. Comprehensive means coverage of your entire environment

Microsoft unifies security, compliance, identity, and management to help you improve productivity and protect your entire digital estate. By providing an end-to-end solution, we’re able to integrate layers of protection across multiple clouds, platforms, endpoints, and devices—Windows, macOS, Linux, iOS, Android, Amazon Web Services (AWS), Workday, Salesforce, and more. This comprehensive approach reduces the risk of data breaches as well as compliance and privacy missteps. Once the user sets the polices, Microsoft solutions provide data governance that can help enact better security.

Flow chart showcasing identities and endpoints as their authentication and compliance requests are intercepted by the Zero Trust Policy for verification before being granted access to Networks and the data/apps/infrastructure they’re composed of.

Figure 2: Microsoft Zero Trust architecture.

More than providing products and services, we collaborate with our customers to understand their environments and build solutions that fit their needs. One such collaboration was with Siemens where they moved from traditional on-premises security to a scalable, flexible solution to fit the company’s complex environment. Having built its reputation for innovation across diverse industries—energy, healthcare, industrial automation, building control systems, and more—research and development continues to play a vital role in the company’s success. For that reason, protecting the company’s staff and intellectual property is always top of mind. And with offices in 200 countries, managing cybersecurity amid a global landscape of shifting compliance and security regulations provides an ongoing challenge.

“There aren’t many vendors on the planet that can create a solution capable of providing consolidated insights into large, complex environments like ours. That’s why we chose Microsoft.”—Thomas Mueller-Lynch, Service Owner Lead, Digital Identity, Siemens.

“The sheer size of Siemens challenges us as to how we provide the best possible security,” explained Peter Stoll, Cybersecurity Officer and Program Lead for Zero Trust at Siemens IT Worldwide. “We like to make sure we get the benefits of emerging technologies.”

When Siemens decided to make the move from on-premises security to a Zero Trust approach, it turned to Microsoft Security. Their IT team implemented a range of security solutions through their Microsoft 365 subscriptions, including Microsoft Azure Active Directory (Azure AD) with Conditional Access as a policy engine, Microsoft Information Protection, Microsoft Defender for Endpoint, Microsoft Defender for Identity, and other solutions—creating a blueprint for ongoing security enhancements. “We chose the best of suite approach with the Microsoft 365 E5 solution,” explained Mueller-Lynch. “Now we have an overview of our environment that helps us react in real-time and defend against attacks proactively.”

2. Comprehensive isn’t just coverage—it’s best-in-breed protection

Today’s organization not only requires security coverage across their threat landscape but also the confidence that comes with knowing that your provider has a proven track record. Microsoft is a leader in five Gartner Magic Quadrants and eight Forrester Wave categories, and we ranked the highest in the MITRE Engenuity® ATT&CK Evaluations. Microsoft was also named a Leader in IDC MarketScape for Modern Endpoint Security. With best-in-breed protection across the Zero Trust security fundamentals shown in Figure 2, Microsoft provides a security safety net that’s not only comprehensive and fully integrated, but durable for the future. Microsoft’s comprehensive solution has innovation at its heart.

Duck Creek Technologies serves the global property and casualty insurance industry by providing cloud-based, software as a service (SaaS) solutions that help insurance carriers operate faster and smarter. When the company’s existing security information and event manager (SIEM) neared the limits of its processing capabilities, Duck Creek needed to upgrade without losing critical data or reducing its ability to detect threats. “Security is a very big part of how we’ve created the relationships we have with our illustrious list of customers,” says John Germain, Vice President and Chief Information Security Officer, Duck Creek Technologies. “I wanted to be sure that the solution we shifted to was best-in-class. Because Microsoft steadily improves its products and solutions to stay ahead of competing offerings, I know we’re in good hands.”

Duck Creek made a quick and painless migration to both Microsoft Defender for Cloud and Microsoft Sentinel. The company also uses Microsoft Endpoint Manager to manage its mobile-device security policies. Combining this functionality, Duck Creek has created single-pane-of-glass visibility for its remote workforce. “We now have incredible visibility across our entire technology stack, all in one place,” says Germain.

3. Integration and AI power Zero Trust security

Like Siemens, shifting from on-premises security to a multi-layered Zero Trust approach required the investment platform company eToro to reassess its infrastructure. As a social investing platform with more than 17 million registered users across more than 100 countries, their IT team has a lot to cover. “When we were operating our traditional third-party antivirus in parallel with our Microsoft solutions, we noticed that Microsoft Defender for Endpoint was acting as our first barrier against attackers. And in 99 percent of incidents, it was the first to detect and act on threats,” says Shay Zakai, Director of Corporate IT, eToro.

That level of protection gave eToro the confidence to remove its third-party antivirus software and rely on Microsoft’s comprehensive, integrated layers for Zero Trust security. That native integration enables Microsoft’s intelligent tools to cut alert volume by 90 percent while automatically remediating up to 97 percent of endpoint attacks. Today, eToro makes ample use of multiple components within Microsoft Defender for Endpoint—threat and vulnerability management, attack surface reduction, endpoint detection and response (EDR), and automatic investigation and remediation—to protect their global operations.

“Microsoft Cloud App Security [Microsoft Defender for Cloud Apps] gives us the ability to analyze and classify information from Google Workspace and our other third-party apps in conjunction with Microsoft’s compliance tools,” Zakai explains. “That level of information gives us the power to restrict activities and enforce regulations as we see fit.”

eToro also integrates Microsoft Intune, a component of Microsoft Endpoint Manager, for their mobile device and mobile application management. By adopting Microsoft’s integrated, AI-driven security, eToro not only automated threat detection and remediation but also increased mobility for employees while reducing their operating costs. “Because of our adoption of Intune and Microsoft Defender for Endpoint, we had virtually no security concerns as we adapted to COVID-19,” says Zakai. “We were more than 90 percent ready to move to a work-from-home model on day one of the crisis.”

4. Simplicity is stronger

Most security professionals agree that security silos bring risks.3 Microsoft enables organizations to simplify and strengthen their security by consolidating up to 50 disparate products—integrating with other tools to streamline investigation and remediation. When MVP Healthcare decided to divest from the numerous redundant security licenses they’d been relying on, it turned to Microsoft Security for a simpler, more easily managed security posture. The company was using roughly 300 different vendor solutions, many of them designed for specialized functions, and Chief Information Officer (CIO) Michael Della Villa wanted to simplify.

After replacing their legacy security solutions with Microsoft Sentinel, Microsoft Defender for Cloud, Azure Firewall, and other Microsoft security solutions, MVP Healthcare’s IT team was freed up to concentrate on crucial tasks that require human attention. “Microsoft offers the cohesive solution we need,” Della Villa says. “We spent so much time trying to maintain the prior system that we weren’t actually using it. Now we easily get very detailed information from Microsoft Sentinel because it’s so well connected across all of our Microsoft solutions. The focus and clarity we’ve gained is a crucial benefit.”

MVP Healthcare also uses Microsoft Defender for Cloud to protect hybrid workloads. “Alerts from Microsoft Defender for Cloud, Microsoft Defender for Cloud Apps, and other solutions are chained together in an actionable way,” adds MVP Healthcare cybersecurity consultant James Greene. “The entire security suite is seamlessly connected. We appreciate that because we can build a comprehensive policy for dealing with security issues in one place.”

As a global leader in technology manufacturing for IoT systems, machine automation, and embedded computing, Advantech found itself the target of a widely publicized ransomware attack in November 2020. The attack was limited to corporate network servers and was quickly mitigated, but it served as a wakeup call. Future threats could affect factory production, delay customer deliveries, lead to theft of sensitive intellectual property, and even result in safety risks.

“We did many proof of concepts (POCs) with many different vendors, but no one met our needs,” says Kevin Lin, IT Manager at Advantech. “We wanted a comprehensive solution to create better efficiency and visibility. We needed security without affecting efficiency on the client side, or requiring specialist installation and configuration by administrators. We decided on Microsoft.”

According to Kevin, Microsoft Security offers a distinct advantage in its holistic approach to services and security. “Other solutions were a little siloed, specialized, and required individual testing—both for the product and support,” he says. “Many didn’t adequately address operational technology (OT) requirements for manufacturing plants, and we recognized that Advantech’s environment called for a comprehensive solution like Microsoft Security, not a collection of solutions.”

Advantech’s security team is now looking to further raise visibility into their IoT and OT risk with agentless, network-layer security provided by Microsoft Defender for IoT—including asset discovery, vulnerability management, and continuous threat monitoring with anomaly detection. “We didn’t have staff dedicated to figuring out our security situation in our manufacturing plants (where IT security isn’t their specialty),” Kevin says. “This attack alerted senior management that they needed to deploy OT security monitoring in our factory networks as well.”

Helping you be fearless

Across the world with organizations of all sizes, from startups to multinational corporations, we see security teams behind the scenes quietly being fearless in achieving their goals. Despite the threats they face daily, these unsung leaders bravely continue the journey of helping their organizations digitally transform. They and you are the reason we want to show up for this important work. By providing not just comprehensive security, but best-in-breed protection with deep intelligence and simplified experiences—Microsoft Security is right there beside you. We want to help you secure everything and be fearless, and turn your vision into reality. To hear from our customers in their own words, visit Customer Stories to learn more. We look forward to our journey together, being fearless, and empowering each other to thrive!

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us at @MSFTSecurity for the latest news and updates on cybersecurity.


1Zero Trust Adoption Report, Microsoft Security, Hypothesis Group 2021. July 2021.

2The hunt for NOBELIUM, the most sophisticated nation-state attack in history, John Lambert, Microsoft Security. 10 November 2021.

3Why Security Can’t Live In A Silo, Douglas Albert, Forbes Technology Council, Forbes. 5 October 2020.

The post Learn about 4 approaches to comprehensive security that help leaders be fearless appeared first on Microsoft Security Blog.

13 Jan 18:38

This Is What Sparked Michael Bay's Obsession With Explosions

by Lindsay Duke

Director Michael Bay's love for pyrotechnics and movie explosions is a meme at this point. His films aren't just action films, they're pure "Bayhem." Everyone knows that if you're seeing one of his movies, be it a period piece romance like "Pearl Harbor" or sentient robots fighting in "Transformers," at the very least, the explosions are going to look good. "Robot Chicken" even had a bit where Michael Bay just puts out a film with no plot, just fireworks and big booms. Honestly, that might be kind of cathartic at this point, like ASMR relaxation videos for people who like to smash things to get their anxiety out. 

While it can seem to be a bit much at times, Bay's predication to pack as many action effects as possible on a screen seemingly comes from a truly organic love of the art of pyrotechnics. His film "Transformers: Revenge of the Fallen" even made it into the Guinness Book of World Records in 2009 "for the biggest explosion on film with actors present." But where did his fascination come from? 

A Lifelong Fascination

Like many filmmakers, Michael Bay got his start by making home movies. As a kid, he was apparently already a bit of a fire bug, loving to film little junior-sized explosions for his films. One stunt included setting firecrackers off on a toy train. He expounded on that experience with USA Today, speaking from the set of "Transformers: Revenge of the Fallen." 

"I actually set my bedroom on fire once," Bay admitted. "The fire department came. It was a little Super 8 movie where the aliens invaded. I got grounded. Two weeks."

That obviously didn't discourage him -- it just grew his desire to create bigger effects. The Pentagon and U.S. military were even roped into several of his projects, granting Bay and his crew access to helicopters and stealth fighters. You don't get much more true-to-life than filming so many scenes with live ammo that "buckets and buckets" of shells have to be picked up between takes. 

The realism is the point. Bay sees more than just a cool effect in the explosions he's so known for. Bay seems to be of the opinion that CGI shortcuts take something away from the audience experience, hence his preference for practical effects where possible. In another interview with Whalebone, he waxed poetic about the soul of a film, and how audiences find it through lighting, something hard to get right with computers:

"I think it takes a lot of the soul out of it, that's what it is. It takes the soul out of it. It kind of becomes a little bit too computerized. Everyone understands light because they see light all the time but they may not understand it. But they understand when it looks screwed up. They can't articulate it but they know, oh that looks fake. It looks fake because you know what everything looks like when you're walking around and you see how light hits things and sets kind of just make it, it becomes more plastic and just doesn't have that soul to it."

That's a genuinely thoughtful comment about something many people wouldn't put too much thought into. Bay seems to be referring to something akin to the uncanny valley, wherein people see humanlike robots or CGI characters that are almost lifelike, but something unnatural makes them uncomfortable with the sight. With something like an explosion, or fire, it might not generate the sort of disgust many feel when seeing a creepy CGI human, but it can take away from a film's experience. Some visuals are too clean, too precise to be believed. 

CGI Versus Practical Effects

The state of CGI versus practical effects is an ongoing balance for respecting both a budget and a vision. It's also made more complicated when the desire for realism comes at the risk to human lives, like on the set of the film "Rust," in which cinematographer Halyna Hutchins was fatally shot by actor Alec Baldwin, or when other crew members and performers from many other projects lost their lives and limbs for the sake of a shot.

The trick seems to be finding balance. Even Bay can't rely solely on practical effects. When looking at a list of the most influential visual effects in movies, you'll find films with exceptional post-production CGI, but most are also testaments to on-set practical effects. Movie magic requires both. Good practical effects and CGI deliver strong verisimilitude, which connects an audience to the story.

As for Bay, the director has come a long way from blowing up toys to blowing up bigger toys. He's been able to live the dream of every kid who has made their own practical effects for home movies, hoping to repeat things in their own backyard that they've seen in theaters. Consider this a PSA: you have to be careful when playing Film Director as a child. If you're not careful, that little joyous obsession with figuring out how to make fake blood for costumes, or cool lighting effects with mirrors and flashlights, can turn into joining the A/V club in high school or going to film school. There's the slim chance that you turn into the mightily successful Michael Bay. Just try to not set your house on fire.

Read this next: Ranking Every Jon Favreau Movie From Worst To Best

The post This is What Sparked Michael Bay's Obsession With Explosions appeared first on /Film.

13 Jan 18:35

In defense of Cyberpunk 2077's constant phone calls

by Ed Thorn

On a stretch of futuristic tarmac, something clicked. Yellow quest markers hadn't built my relationships in Cyberpunk 2077. When a job needed doing, then they'd steer me in the right direction. But for those initial sparks of story, my cellphone had been key. Chats and texts buzzed into my brain at all hours. "Hey V", "V, got a minute?", "V!"

Characters would get in contact with me, not the other way around. And I liked that. In fact, I'd say it helped build a living, breathing world more than Night City's towering skyscrapers and moving billboards. More than, perhaps, any other big RPG I've played over the last couple of years.

Read more

13 Jan 18:35

Study Finds Cannabinoids Prevent COVID-19 Infection

by BeauHD
MachineShedFred shares a report from Forbes: Compounds in cannabis can prevent infection from the virus that causes Covid-19 by blocking its entry into cells, according to a study published this week by researchers affiliated with Oregon State University. A report on the research, "Cannabinoids Block Cellular Entry of SARS-CoV-2 and the Emerging Variants," was published online on Monday by the Journal of Natural Products. The researchers found that two cannabinoid acids commonly found in hemp varietals of cannabis, cannabigerolic acid, or CBGA, and cannabidiolic acid, also known as CBDA, can bind to the spike protein of SARS-CoV-2, the virus that causes Covid-19. By binding to the spike protein, the compounds can prevent the virus from entering cells and causing infection, potentially offering new avenues to prevent and treat the disease. "Orally bioavailable and with a long history of safe human use, these cannabinoids, isolated or in hemp extracts, have the potential to prevent as well as treat infection by SARS-CoV-2," the researchers wrote in an abstract of the study. The study was led by Richard van Breemen, a researcher with Oregon State's Global Hemp Innovation Center in the College of Pharmacy and Linus Pauling Institute, in collaboration with scientists at the Oregon Health & Science University. Van Breeman said that the cannabinoids studied are common and readily available. "These cannabinoid acids are abundant in hemp and in many hemp extracts," van Breemen said, as quoted by local media. "They are not controlled substances like THC, the psychoactive ingredient in marijuana, and have a good safety profile in humans." Van Breemen added that CBDA and CBGA blocked the action of emerging variants of the virus that causes Covid-19, saying that "our research showed the hemp compounds were equally effective against variants of SARS-CoV-2, including variant B.1.1.7, which was first detected in the United Kingdom, and variant B.1.351, first detected in South Africa." [...] Although further research is needed, van Breemen noted that study shows the cannabinoids could be developed into drugs to prevent or treat Covid-19. CBDA and CBGA are produced by the hemp plant as precursors to CBD and CBG, which are familiar to many consumers. However, they are different from the acids and are not contained in hemp products." Van Breeman also noted that the research showed the cannabinoids were effective against new variants of the virus, which he said are "one of the primary concerns" in the pandemic for health officials and clinicians.

Read more of this story at Slashdot.

13 Jan 10:55

Iranian Hackers Exploit Log4j Vulnerability to Deploy PowerShell Backdoor

by noreply@blogger.com (Ravie Lakshmanan)
An Iranian state-sponsored actor has been observed scanning and attempting to abuse the Log4Shell flaw in publicly-exposed Java applications to deploy a hitherto undocumented PowerShell-based modular backdoor dubbed "CharmPower" for follow-on post-exploitation. "The actor's attack setup was obviously rushed, as they used the basic open-source tool for the exploitation and based their operations
13 Jan 10:53

Nvidia GeForce Now RTX 3080 review – cloud gaming at its best

by Damien Mason
Nvidia GeForce Now RTX 3080 review – cloud gaming at its best

Nvidia released the RTX 3080 over a year ago, but it's still next to impossible to upgrade your GPU without selling a kidney (which we definitely don't recommend). Fortunately, you can now rent one through the green team's cloud gaming service and it might surprise you that the GeForce Now RTX 3080 membership really does stack up against the real deal.

If you're familiar with the original Priority membership, then this works in the same way. For the uninitiated, though, GeForce Now's a little different to your usual cloud gaming service, relying on your own library rather than supplying you with a rotating roster of games like Xbox Game Pass Ultimate. This is designed to give you ownership of what you can play rather than sticking a deadline on when you can play until.

The RTX 3080 membership is perhaps the biggest upgrade to GeForce Now since Nvidia switched on RTX for Priority members in 2019. It now falls in line with the suped up resolutions and frame rates that even the latest consoles are capable of, including 1440p at 120fps on PCs, 1600p at 120fps on Mac, and up to 4K at 60fps with HDR on Nvidia Shield devices. And this is to say nothing of longer sessions of up to eight hours, better adaptive sync technology, and a lower system latency.

RELATED LINKS: RTX 2070 Super review, RTX 2060 Super review, Best graphics card
13 Jan 03:19

Looking for Something? How to grep Multiple Strings in Linux

by Ian Buckley

The Linux terminal is full of useful commands, but few are as powerful as the seemingly simple grep. It stands for Global Regular Expression Print, printing the results of user-defined system searches for collections of characters.

13 Jan 03:19

Your 'Olive Oil' Bottle Is Lying to You

by Claire Lower

Given my state of origin (Mississippi), it’s not surprising that my favorite cooking fats are bacon grease and butter. They make food taste like home, but they aren’t the fats I reach for if I’m oil-poaching a salmon filet, whipping up a quick vinaigrette, or making a vegan marinara (which, incidentally, is even…

Read more...

13 Jan 03:16

RetroArch aims to let you play real Nintendo 64 cartridges on PC emulators this year

by Dustin Bailey
RetroArch aims to let you play real Nintendo 64 cartridges on PC emulators this year

There are already an array of devices out there that can read your old game cartridges, dump the contents to a PC, and allow you to enjoy easy, legal emulation of your own collection. But the folks at RetroArch are annoyed that these devices are often expensive, out of stock, or otherwise difficult to find - and so they're building their own solution.

The Open Hardware project was revealed nearly a year ago as a proposed DIY standard for a USB device that directly integrates your cartridges into RetroArch. In a new blog post, the devs say "we stand by this goal to this day, however we felt that the DIY market alone will not help the cause significantly to bring emulation to the mainstream."

So RetroArch is partnering with "a hardware manufacturer for a commercial release - bringing the peripheral into everyone’s hands - while still keeping a free and open DIY route." The devs hope to bring this device into production in the middle of the year, with a full release to follow late in 2022, though they acknowledge that there are some major issues with global logistics at the moment.

13 Jan 03:14

Suspect detained over 2012 case in which a family found out what happens when you find a stranger in the Alps [Followup]

13 Jan 01:37

FCC Proposes Stricter Requirements for Reporting Data Breaches

by msmash
The Federal Communications Commission is the next US regulator hoping to hold companies more accountable for data breaches. From a report: Chairwoman Jessica Rosenworcel has shared a rulemaking proposal that would introduce stricter requirements for data breach reporting. Most notably, the new rules would require notifications for customers affected by "inadvertent" breaches -- companies that leave data exposed would have to be just as communicative as victims of cyberattacks. The requirements would also scrap a mandatory one-week waiting period for notifying customers. Carriers, meanwhile, would have to disclose reportable breaches to the FCC in addition to the FBI and Secret Service. Rosenworcel argued the tougher rules were necessary to account for the "evolving nature" of breaches and the risks they posed to victims. People ought to be protected against larger and more frequent incidents, the FCC chair said -- that is, regulations need to catch up with reality.

Read more of this story at Slashdot.

13 Jan 01:37

Teen Hacker Finds Bug That Lets Him Control 25+ Teslas Remotely

by BeauHD
An anonymous reader quotes a report from Ars Technica: A young hacker and IT security researcher found a way to remotely interact with more than 25 Tesla electric vehicles in 13 countries, according to a Twitter thread he posted yesterday. David Colombo explained in the thread that the flaw was "not a vulnerability in Tesla's infrastructure. It's the owner's faults." He claimed to be able to disable a car's remote camera system, unlock doors and open windows, and even begin keyless driving. He could also determine the car's exact location. However, Colombo clarified that he could not actually interact with any of the Teslas' steering, throttle, or brakes, so at least we don't have to worry about an army of remote-controlled EVs doing a Fate of the Furious reenactment. Colombo says he reported the issue to Tesla's security team, which is investigating the matter.

Read more of this story at Slashdot.

13 Jan 01:37

'UltraRAM' Breakthrough Could Combine Memory and Storage Into One

by BeauHD
Scientists from Lancaster University say that we might be close to combining SSDs and RAM into one component. "UltraRAM," as it's being called, is described as a memory technology which "combines the non-volatility of a data storage memory, like flash, with the speed, energy-efficiency, and endurance of a working memory, like DRAM." The researchers detailed the breakthrough in a recently published paper. Tom's Hardware reports: The fundamental science behind UltraRAM is that it uses the unique properties of compound semiconductors, commonly used in photonic devices such as LEDs, lasers, and infrared detectors can now be mass-produced on silicon. The researchers claim that the latest incarnation on silicon outperforms the technology as tested on Gallium Arsenide semiconductor wafers. Some extrapolated numbers for UltraRAM are that it will offer "data storage times of at least 1,000 years," and its fast switching speed and program-erase cycling endurance is "one hundred to one thousand times better than flash." Add these qualities to the DRAM-like speed, energy efficiency, and endurance, and this novel memory type sounds hard for tech companies to ignore. If you read between the lines above, you can see that UltraRAM is envisioned to break the divide between RAM and storage. So, in theory, you could use it as a one-shot solution to fill these currently separate requirements. In a PC system, that would mean you would get a chunk of UltraRAM, say 2TB, and that would cover both your RAM and storage needs. The shift, if it lives up to its potential, would be a great way to push forward with the popular trend towards in-memory processing. After all, your storage would be your memory -- with UltraRAM; it is the same silicon.

Read more of this story at Slashdot.

12 Jan 20:39

Reasons Why I'd Let Drash Bully Me And Steal My Water Supply

by BJ Colangelo

Warning: spoilers ahead for "The Book of Boba Fett." Proceed with caution.

If it wasn't obvious from my piece from last week about Jabba the Hutt's Lady Cousin from "The Book of Boba Fett" being 2022 goals, or my piece critiquing the skincare regimen of our titular lead, I analyze the "Star Wars" galaxy with utmost seriousness. The third chapter of "The Book of Boba Fett" focuses on the crime ridden streets of Mos Espa and introduces us to some new characters played Danny Trejo, Stephen Root, and Phil LaMarr. Most importantly, in my opinion, is the introduction of a street-gang of half-human, half-machine hooligans, lead by Sophie Thatcher as "Drash." When "The Book of Boba Fett" was first announced, people began wildly speculating about the cool biker chick in the previews. As the /Film resident "Yellowjackets" recapper, I'm well-versed in the talent of Thatcher, and I'm pleased to confirm that she is once again playing a character that I'd welcome kicking sand in my face.

The "Star Wars" universe is not without its fair share of bad b******, but it is severely lacking in characters I like to call, "Women I Would Let Bully Me." Sure, characters like Princess Leia, Ahsoka Tano, Jyn Erso, and Rey Palpatine Skywalker are women that I aspire to emulate, but what about the characters who could hurt my feelings like a junior high bully or punch me in the face and make me feel like they were doing me a favor? Asajj Ventress and Captain Phasma are currently tied for supremacy in this niche category, but after this week's episode of "The Book of Boba Fett," Drash is motorbiking her way to the top of the list.

Drash Is Cooler Than Me, You, And Everyone We Know

I don't know where on Tatooine it's possible for Drash to secure a razor sheared wolf-cut shag hairdo, which makes me believe she's cutting her own hair with a blade like the certifiable badass she is. My head canon is that the blade she used to stab Black Krrsantan was readily available because it's the blade she uses to keep her hair perfectly coiffed. Drash also has the arm of a droid, because while funds are tight and work is slim on the streets of Mos Espa, Drash has prioritized mechanically enhancing her body and keeping her speeder bike well-maintained. Drash gets it: you're not hardcore unless you live hardcore.

When Stephen Root's water-mongering Lortha Peel approaches Boba Fett with a passive-aggressive request that he do something about the "insolent youths" stealing his water supply, he outs himself as Mos Espa's resident NIMBY and even blames Boba Fett because "this never happened under the other Daimyos." If a young woman and her buddies can make a grown man so hard-pressed he files a formal complaint with the Daimyo, she's officially the type of bad influence I'm immediately going to root for. Peel describes the crew as a "scourge" on the streets, and now I'm wondering what the equivalent of "OK, Boomer" is for "Star Wars."

Survival Criminals Are Not Criminals

When Fett finally approaches Drash and her gang, they're hanging around the space equivalent of a trashcan fire and dressed like my new favorite pop punk band from 2006. He asks them where they got their water and without missing a beat, Drash replies, "We stole it." FEARLESS! Fett announces they've committed a crime, but Drash pushes back, informing him that she views him as nothing more than a crime boss, that there's no work available to earn wages, and Peel overcharges for his stock because he's taking advantage of resource scarcity. Fett sees she's got guts, and he offers the group a job working for him, hoping Drash can fight as well as she talks dank. Good news, she can, and she helps keep Black Krrsantan at bay when he comes intending to kill Boba Fett, and successfully cuts off Mok Shaiz' majordomo when he flees a confrontation with Fett like the spineless coward he is. Drash isn't a criminal, she's a survivor, and she's doing what is necessary to stay that way.

This may be Drash's first appearance in the series, but now that she's the leader of Fett's personal line of defense, we'll likely see a lot more bad b**** action. If there's any justice in the world, we'll get a scene of Drash putting the head of a Pyke on a pike as a sign of victory after the seemingly inevitable war, because "Star Wars" deserves more women who bring absolute brutality.

Read this next: The 12 Best Boba Fett Moments In Star Wars Shows And Movies

The post Reasons Why I'd Let Drash Bully Me and Steal My Water Supply appeared first on /Film.

12 Jan 20:35

How Long Can You Keep Using the Same N95 Mask?

by Meredith Dietz

Omicron continues to overwhelm hospitals and healthcare workers already worn out by Delta. At this stage of the pandemic, and with the healthcare system once again teetering on the edge, experts are urging people to ditch their cloth masks in favor of N95 or KN95 respirators. But these masks are more expensive than…

Read more...

12 Jan 20:35

Move Over HDR Half Life 2.5, It’s Half-Life: Ray Traced

by Jeremy Hellstrom

It might be time to dig out Half Life for another replay, assuming you aren't still dealing with the addition of Xen to Black Mesa.   Over on GitHub, Sultim "sultim_t" Tsyrendashiev has…

12 Jan 20:35

Chrome Will Limit Access To Private Networks, Citing Security Reasons

by msmash
Google says that its Chrome browser will soon block internet websites from querying and interacting with devices and servers located inside local private networks, citing security reasons and past abuse from malware operations. From a report: The change will take place through the implementation of a new W3C specification called Private Network Access (PNA) that will be rolled out in the first half of the year. The new PNA specification adds a mechanism inside the Chrome browser through which internet sites can ask systems inside local networks for permission before establishing a connection. If local devices, such as servers or routers fail to respond, internet websites will be blocked from connecting.

Read more of this story at Slashdot.

12 Jan 18:35

As Kazakhstan Descends Into Chaos, Crypto Miners Are at a Loss

by Gian M. Volpicelli
The central Asian country became No. 2 in the world for Bitcoin mining. But political turmoil and power cuts have hit hard, and the future looks bleak.
12 Jan 18:34

Why You Should Worry About Attacks on Mobile Software Supply-Chain Security

by Amy Schurr

Escalating software supply-chain attacks pose a serious threat to the public sector and businesses. Adversaries exploit vulnerabilities in third-party code to compromise a supplier to the vast digital ecosystem downstream. The ripple effect causes widespread disruption, financial loss and reputational damage and even endangers national security. 

Consider the enormous impact the SolarWinds software supply chain attack had on the private sector and U.S. federal, state and local governments then think of the thousands of web and mobile applications that are under attack. Notable mobile apps that suffered data breaches in 2021 include Apple iMessage, Klarna, ParkMobile, Samsung SecureFolder and Slack. 

As developers increasingly rely on code libraries and open-source components to quickly build mobile apps and enterprises deploy more third-party apps, the complexity of the software supply chain grows. The Apple App Store™ and Google Play™ house some 6 million apps and don’t include countless other custom mobile apps companies develop in house or obtain from vendors and consultants. That makes for a massive threat landscape in which a single weak link can lead to an attacker infiltrating systems around the globe.

The NowSecure Mobile Risk Tracker displays the current security, privacy and compliance risks of apps by industry type.

Breaches Unleash Extensive Damage

Skyrocketing reports of software supply-chain security incidents demonstrate the struggle to manage software supply-chain risk. The European Union Agency for Cybersecurity (ENISA) estimated a 4x increase in supply-chain attacks in 2021. Sonatype research revealed a 650% increase in next-generation cyberattacks against open-source tools over a one-year period. And Forrester forecasts that 60% of cybersecurity incidents in 2022 will result from issues with third parties.

Software supply-chain attacks have far-reaching impacts and organizations face considerable challenges and expense to remediate them. A CloudBees survey revealed 64% of C-suite executives said it would take more than four days to mitigate a software supply-chain security incident. But some may not even know when their businesses are attacked. And a BlueVoyant report found more than one-third of leaders have no way of knowing if or when a cybersecurity issue with a third party arises.

Sixty percent of security issues will be caused by third parties

The cost of software supply-chain breaches is ten times higher than traditional breaches

U.S. Government Strengthens Cyberdefenses

Alarmed by growing risk to the software supply chain, the U.S. government has acted to fight the threat. In 2021, the White House issued an Executive Order mandating cybersecurity requirements for federal agencies, systems integrators, vendors and contractors. “The United States faces persistent and increasingly sophisticated malicious cyber campaigns that threaten the public sector, the private sector, and ultimately the American people’s security and privacy,” the EO states. “The federal government must take action to rapidly improve the security and integrity of the software supply chain, with a priority on addressing critical software.”

Organizations must rapidly improve the security and integrity of the software supply chain. – White House Executive Order

In addition, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) recently offered guidance to the private sector about mitigating software supply-chain risk. And as part of the cybersecurity EO directive, NIST has defined critical software and is updating a set of best practices for secure software delivery and software labeling.

Announcing the World’s First Dynamic Software Bill of Materials (SBOM) for Mobile Apps

Early Access Program Enables Organizations to Access Dynamically Generated SBOMs for Any Mobile App Binary

Sign Up Now

Safeguard the Mobile App Supply Chain

Security and DevSecOps leaders should adopt cyber supply chain risk management strategies to safeguard their mobile applications from attack. Here are a few initial steps to take.

  • Create and maintain a Software Bill of Materials (SBOM) to uncover risks hiding in open-source and third-party components that your development team uses to build mobile apps. 
  • Ask your software vendors to provide SBOMs and confirmation that their mobile apps are safe to use. 
  • Gain visibility into your existing mobile app portfolio by conducting an inventory and vetting for security, privacy and compliance issues. 
  • Perform continuous monitoring to stay on top of new vulnerabilities or dependency changes that introduce security, privacy or compliance risks.

Get started by exploring NowSecure solutions for mobile app supply-chain risk management and get a free SBOM report to uncover areas of risk hiding in your mobile apps.

About NowSecure

NowSecure offers a comprehensive suite of automated mobile app security and privacy testing solutions, mobile penetration testing and training services to reduce risk. Trusted by many of the world’s most demanding organizations, NowSecure protects millions of app users across banking, insurance, high tech, retail, healthcare, government, IoT and others. As the recognized expert in mobile app security, NowSecure was recently named a mobile security testing leader by IDC, a DevSecOps transformational leader by Gartner, a Deloitte Technology Fast 500 winner and a TAG Distinguished Vendor.

The post Why You Should Worry About Attacks on Mobile Software Supply-Chain Security appeared first on NowSecure.

12 Jan 18:33

2021 was a very good year for the PC market

by Jon Fingas

If you thought the PC market's pandemic-era renaissance would continue throughout 2021... you guessed correctly. Canalys estimates PC shipments jumped 15 percent year-over-year to 341 million despite supply shortages. Simply put, many of the customers in 2021 were adding new PCs rather than replacing existing ones. Remote students and seniors were purchasing first computers, for example, while multiple systems were "more common" in some areas.

PC market share in 2021
Canalys

Some PC brands had a better time than others, though. Lenovo, HP, Dell, Apple and Acer held on to their respective top-five positions in shipments, but Apple and Acer were the shining stars after growing deliveries over 20 percent compared to 2020. Frontrunners Lenovo and HP had the slowest growth of the leaders in 2021, and saw their shipments fall in the very last quarter where other rivals grew. Their size didn't help them capitalize on expanded demand for computers, to put it another way.

It also seems likely that 2022 will be similarly bright. Principal Analyst Rushabh Doshi predicted the new year would be one of "digital acceleration" as people shift toward high-end PCs and accessories that help with remote work. It's too soon to say how accurate that prediction might be, but it coincides with a PC revival we saw at CES — competition appears to be as fierce as ever.

12 Jan 18:33

Release: Sam & Max: Beyond Time and Space

Title: Sam & Max: Beyond Time and Space
Genre: Adventure
Discount: 25% off for the owners of Sam & Max Save the World until 25th January 2022, 2 PM UTC.



12 Jan 18:32

New SysJoker Espionage Malware Targeting Windows, macOS, and Linux Users

by noreply@blogger.com (Ravie Lakshmanan)
A new cross-platform backdoor called "SysJoker" has been observed targeting machines running Windows, Linux, and macOS operating systems as part of an ongoing espionage campaign that's believed to have been initiated during the second half of 2021. "SysJoker masquerades as a system update and generates its [command-and-control server] by decoding a string retrieved from a text file hosted on
12 Jan 18:31

Hackers Use Cloud Services to Distribute Nanocore, Netwire, and AsyncRAT Malware

by noreply@blogger.com (Ravie Lakshmanan)
Threat actors are actively incorporating public cloud services from Amazon and Microsoft into their malicious campaigns to deliver commodity remote access trojans (RATs) such as Nanocore, Netwire, and AsyncRAT to siphon sensitive information from compromised systems. The spear-phishing attacks, which commenced in October 2021, have primarily targeted entities located in the U.S., Canada, Italy,
12 Jan 18:31

God of War PC impressions: this game deserves a second wind

by Chris Carter

Kratos on DLSS It’s still super weird to boot up what is ostensibly a “PlayStation game,” then see the Xbox...

The post God of War PC impressions: this game deserves a second wind appeared first on Destructoid.