
Ronald.phillips
Shared posts
Jurassic Park's Paleontologist Adviser May Have Inspired Its Main Character
Apple Announces macOS Sonoma With Desktop Widgets and Game Mode
Read more of this story at Slashdot.
Xbox FTC Settlement and Reimagining the Future of Safety on Xbox
At Xbox, we have the fundamental commitment to provide all players with a safe and secure experience on our platform – and this is especially true for our youngest players. We frequently iterate on our safety measures, in collaboration and with feedback from the community, regulators and partners. We recently entered into a settlement with the U.S. Federal Trade Commission (FTC) to update our account creation process and resolve a data retention glitch found in our system. Regrettably, we did not meet customer expectations and are committed to complying with the order to continue improving upon our safety measures. We believe that we can and should do more, and we’ll remain steadfast in our commitment to safety, privacy, and security for our community.
Our two decades of safety experience has taught us that all players want, and need, safety and privacy protections. Since 2005, when we launched the first console that could connect players online, we’ve continued to invest in tools and technologies to protect our community. That work evolved into a multifaceted safety strategy. Our suite of safety, privacy and security measures are designed to respect player privacy and safety, and empower players, as well as parents and caregivers, to have control over their gaming experiences.
Below we detail the changes we made to verify child accounts, however, our work on age validation doesn’t stop there. We see an opportunity to further advance safe digital experiences that are accessible, simple to use, and benefit all players. We are innovating on next-generation identity and age validation – a convenient, secure, one-time process for all players that will allow us to better deliver customized, safe, age-appropriate experiences. The long-term benefits will be felt by all players, especially children and their families. And while we see this as the future, we anticipate that the entire games industry will as well.
Over the coming months, we will test new methods to validate age and take feedback from our customers’ experience. The learnings from these trials will directly inform advancements in our player identity systems. We are incorporating Microsoft’s insights from across industries to develop a principled approach to secure digital identities that minimizes data collection, prioritizes security, and makes it easier for players to understand how their data is used.
We’ll continue to put players at the center – giving them full control over their online experiences and digital identities. We’ll continue to empower parents and caregivers to exercise appropriate oversight of the gaming experience for their children and families, in addition to tools like the Xbox Family Settings App and child accounts. Child accounts are built for underage players so that parents and caregivers can manage settings, privacy, spending and more. We will continue to be transparent and clear about the actions we take on our service, just as we did when we released our inaugural Transparency Report and second Transparency Report in May.
The Xbox community is our community – one we shape together. As we innovate and trial new experiences, we’ll work with the community to gather feedback so we can create a safer gaming experience together.
What the FTC settlement means for players
Since the FTC settlement, we have updated our account creation process, which now requires players to first identify date-of-birth and, if under 13 years old, obtain verified parental consent before providing us with any information such as phone number or email address. This updated process ensures that we can identify potential child accounts immediately and make clear to parents and caregivers the next steps to protect their children’s data and play safely on our network.
Over the coming months, players who are under the age of 13 and created an account prior to May 2021 will require parental reconsent – meaning a parent will be prompted to reverify the account and grant permission for their child to continue gameplay and activity on Xbox. We are committed to making this process as seamless as possible. We are working hard to ensure that when parents are prompted to reconsent, they will have the information needed to proceed without disruptions to their child’s access. To learn more about setting up a child account, please visit here.
During the investigation, we identified a technical glitch where our systems did not delete account creation data for child accounts where the account creation process was started but not completed. This was inconsistent with our policy to save that information for only 14 days to make it easier for gamers to pick up where they left off to complete the process. Our engineering team took immediate action: we fixed the glitch, deleted the data, and implemented practices to prevent the error from recurring. The data was never used, shared, or monetized.
To more clearly explain what information we collect and how we use it, we updated our Microsoft Privacy Statement, including a dedicated section about how Xbox processes user data. We have also updated our home screen to have a clearly labelled link to the Microsoft Privacy Statement. This link also appears in each area of the service where personal information is collected. Microsoft also provides a privacy dashboard that shares with families what data is collected and used. Players can adjust their privacy settings at any time and child accounts are set to the strongest privacy settings by default. To learn more about Xbox’s privacy features, please visit here.
Additional resources for families
We want all parents, caregivers, and families to know that, more than anything else, we have their children’s safety and privacy top of mind. We will continue to communicate the changes we are making to our practices and the data we collect so we can better protect children using our platform. We also continue to explore creative ways to educate players about online safety.
This past Safer Internet Day, we released Minecraft’s Privacy Prodigy, aimed at teaching young people about privacy and how to safeguard their sensitive personal information. This world is the second chapter in the CyberSafe series, following last year’s release of Minecraft CyberSafe: Home Sweet Hmm, reaching millions of players, with unprecedented downloads of support materials underscoring the demand by teachers and families to teach these critical skills and integrate safer online practices daily. CyberSafe: Home Sweet Hmm and CyberSafe: Privacy Prodigy are both available for free on Minecraft: Education Edition and Minecraft Bedrock.
Our updated Xbox Family Hub shares information about creating a family group, managing child accounts, and helps parents and caregivers understand the safety measures we have in place, such as the Xbox Family Settings App.
For more information on Microsoft privacy, safety, and responsible gaming, please see the below list of resources:
Related:Xbox Releases Second Transparency Report Demonstrating the Integral Role of Proactive Content Moderation
Xbox Celebrates Safer Internet Day with Minecraft’s New Privacy-Themed Learning World and Safety Tips for Parents
Xbox Shares Community Safety Approach in Transparency Report
The Flash's Sasha Calle Would Love To Keep Playing Supergirl In James Gunn's Rebooted DC Universe [Exclusive]

Andy Muschietti's "The Flash" is almost upon us. Only two more weeks until the movie is out in theaters and it has already garnered very strong word of mouth from the CinemaCon screening as well as advance fan and press screenings. The studio has very rudely not shown me the movie yet, so I can't join in on the quality discussion, but I can say that I'm very excited by all the positive word thus far.
I'm particularly excited to see what they do with this Supergirl business. I'm not very familiar with Sasha Calle's other work, but I'd be lying if I wasn't immediately enamored by her when they announced her casting by showing her reaction to hearing the news that she was cast during a Zoom meeting with Muschietti. Her obvious passion for the character and excitement at the opportunity was contagious and I was instantly down to see what they were going to do with her here.
Now, we know that the DC Extended Universe is forever altered by the events of "The Flash," but we don't know to what extent. I guess we won't know even after we've all seen "The Flash," since James Gunn and Peter Safran's big reshaping of the DC Universe is still in its early days.
The question remains: is there a place for Sasha Calle's Supergirl in the new DCU? This very question was asked of Calle by our own Jenna Busch-Henderson and her answer may not surprise you, but it is a good example of just how attached to this character she has become.
Calle Is 'Deeply In Love' With Supergirl

The gist of Jenna's question was about whether or not there have been any talks about her returning, especially considering Gunn has announced a "Supergirl" standalone movie based on the "Woman of Tomorrow" comics. This was her response:
"Oh, look, I hope to continue playing Supergirl. I love her. I'm so deeply in love with her. I think she's so incredible and so complex. And I think in this film, this is really the runway for her. We see this glimpse of her, but there's still so much to unpack in her story. I'm excited to take her apart and put her back in and just enjoy her with the world. I think there's so much story to tell, and I would love to continue playing Supergirl."
Obviously, that doesn't answer the larger question at hand, but at least Calle has put her love of the character and desire to return to the role on record. It's not like she'd come out and be like "Meh, I'll pass," of course, but it does sound like Calle has done a ton of homework for this character and is ready to be put back into the fight should Gunn and Safran want her back.
We'll know more as Gunn's own "Superman" movie moves forward and casting news start to come out for his "Gods and Monsters" phase of the DCU.
Read this next: Every DC Movie Made Prior To The DCEU Ranked From Worst To Best
The post The Flash's Sasha Calle Would Love to Keep Playing Supergirl in James Gunn's Rebooted DC Universe [Exclusive] appeared first on /Film.
Events Ripper Update
As I was using some of the indicators we already had (file and process names) to pivot into the timeline, I saw that I had Security Event Log records from 2020...now, that is weird! After all, it's not often that I see Security Event Log records going back a week or month, let alone 3 years!
Another indicator was the sessions.pl output from Events Ripper; I had logins lasting 26856 hours (1119 days), and others lasting -16931 hours (over 705 days). Given how the session span is calculated, I knew some was "off" in the Security (and very likely, other) Event Logs, particular the records associated with logon and logoff events.
I knew something was up, but I also knew that finding the "what was up" was also based largely on my experience, and might not be something a new or more junior analyst would be familiar with. After all, if an analyst was to create a timeline (and I'm seeing everyday that's a pretty big "if"), and if they were pivoting off of known indicators to build context, then how likely would it be that they had the experience to know that something was amiss?
So, naturally, I wrote an Events Ripper plugin (timechange.pl) to pull Security-Auditing/4616 event records from the Security Event Log and display the available information in a nice table. The plugin collects all of these events, with the exception of sub-second time changes (which can be fairly common), and displays them in a table showing the user, the time changed from, the time changed to, and via which process. I wrote the plugin, and it produced an entry on the next investigation...not one that had much impact on what was going on, as the system clock was updated by a few minutes, but this simply shows me how the use of plugins like this can be very valuable for elevating interesting and important artifacts to the analyst for review without requiring that analyst to have extensive experience.
Yuzu Switch Emulator Runs Zelda: Tears of the Kingdom at Solid Performance on Android; Ultrawide Mods Released

The Yuzu Nintendo Switch emulator has quickly become one of the most exciting emulators ever made, as the development team has continuously improved it since its public launch at a surprising speed, reaching another important milestone earlier this week when the emulator was launched on the Google Play Store for Android devices.
While the Android version of the emulator is not yet capable of running every Nintendo Switch game with perfect performance, it is definitely capable of running the latest games more than decently. The mobile version of the emulator can already run Zelda: Tears of the Kingdom at around 20 frames per second on a ROG Phone 6 Pro with default settings, which is quite impressive, considering the emulator has just been released.
TOTK Yuzu Android - Good job Yuzu Team! Surprised that this is running on default settings! (ROG 6 Pro)
by u/PlacidBeetle in yuzu
On a related note, those enjoying Zelda: Tears of the Kingdom on PC with the main version of the Yuzu Nintendo Switch emulator can now have a much better experience at ultrawide resolutions thanks to two new mods that were released online this week. The first mod, the Ultrawide UI fix, attempts to fix the interface alignment at ultrawide resolutions such as 3440 x 1440 and 5140 x 1440 resolutions, while the Any Aspect Ratio custom utility allows users to create a mod that patches the game to any aspect ratio possible. This mod is still in early development, so there are plenty of issues, but it's still impressive how something like this is already possible on PC with a game released less than a month ago on another platform.
The Yuzu Nintendo Switch emulator can be downloaded from its official website. The Android version is now available on the Google Play Store.
Millions of PC Motherboards Were Sold With a Firmware Backdoor
Read more of this story at Slashdot.
Millions of Gigabyte Motherboards Were Sold With a Firmware Backdoor
Air New Zealand To Weigh Passengers Before They Board the Airplane
Read more of this story at Slashdot.
Men Behind UK's Largest Pirate Service Jailed For 30+ Years
Read more of this story at Slashdot.
Yuzu Nintendo Switch Emulator New Version Brings Over 50% Improved Performance in Zelda: Tears of the Kingdom

The Yuzu Nintendo Switch emulator received a new update that further improves the emulation of The Legend of Zelda: Tears of the Kingdom, fixing an annoying visual issue and introducing a performance improvement of over 50% in certain scenarios.
The latest Early Access version, 3621, addresses the issue which causes missing menu images for weapons. As the issue is caused by Asynchronous Shared Building, the team introduced an option to reset the cache storage in the remove items section that appears when right-clicking on the game in the game list. Doing so will display the image correctly without clearing the shader.
The above fix isn't the only Zelda: Tears of the Kingdom improvement brought by the Yuzu Early Access 3621 version. The new update fixes audio desync and crackling, which can happen under certain conditions, and improves Open GL performance by over 50%, not only in the latest entry in the Zelda series but also in Pokémon Scarlet and Violet and other titles.
As it usually is with Early Access releases, the fixes introduced by version 3621 will only make their way into the main build of the Yuzu Nintendo Switch emulator in the coming days. If you cannot wait, you can get access to all Early Access releases by subscribing to the emulator's Patreon page.
More information on the Yuzu Nintendo Switch emulator can be found on its official website. The installer for the current latest build of the emulator can also be downloaded from there.
How Often You Really Need to Clean Your Reusable Water Bottle

Carrying a reusable water bottle is good for both you and the environment. But without regular cleaning, it may not be as helpful and healthy as you think, as bacteria and mold can easily make themselves at home.
Govee Permanent Outdoor Lights Review: Don't Buy Holiday Lights Again Until You've Seen These
The Govee permanent outdoor lights are awe-inspiring. Govee has come up with some pretty compelling products over the years, but these are on another level. Govee has gone from being the perky little upstart with cheap LED strips looking to disrupt the smart lighting market away from the incumbent Philips Hue, to absolutely dominating it with a range of innovative products.
10 Common Myths About Penetration Testing Debunked
Vulnerabilities in your computer systems aren’t necessarily problematic until intruders discover and exploit them. If you cultivate a culture of identifying loopholes before threat actors, you can resolve them, so they don't pose any significant harm. This is the opportunity that penetration testing offers you.
Windows XP activation algorithm cracked after 21 years
Volt Typhoon targets US critical infrastructure with living-off-the-land techniques
Microsoft has uncovered stealthy and targeted malicious activity focused on post-compromise credential access and network system discovery aimed at critical infrastructure organizations in the United States. The attack is carried out by Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering. Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.
Volt Typhoon has been active since mid-2021 and has targeted critical infrastructure organizations in Guam and elsewhere in the United States. In this campaign, the affected organizations span the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors. Observed behavior suggests that the threat actor intends to perform espionage and maintain access without being detected for as long as possible. Microsoft is choosing to highlight this Volt Typhoon activity at this time because of our significant concern around the potential for further impact to our customers. Although our visibility into these threats has given us the ability to deploy detections to our customers, the lack of visibility into other parts of the actor’s activity compelled us to drive broader community awareness and further investigations and protections across the security ecosystem.
To achieve their objective, the threat actor puts strong emphasis on stealth in this campaign, relying almost exclusively on living-off-the-land techniques and hands-on-keyboard activity. They issue commands via the command line to (1) collect data, including credentials from local and network systems, (2) put the data into an archive file to stage it for exfiltration, and then (3) use the stolen valid credentials to maintain persistence. In addition, Volt Typhoon tries to blend into normal network activity by routing traffic through compromised small office and home office (SOHO) network equipment, including routers, firewalls, and VPN hardware. They have also been observed using custom versions of open-source tools to establish a command and control (C2) channel over proxy to further stay under the radar.
In this blog post, we share information on Volt Typhoon, their campaign targeting critical infrastructure providers, and their tactics for achieving and maintaining unauthorized access to target networks. Because this activity relies on valid accounts and living-off-the-land binaries (LOLBins), detecting and mitigating this attack could be challenging. Compromised accounts must be closed or changed. At the end of this blog post, we share more mitigation steps and best practices, as well as provide details on how Microsoft 365 Defender detects malicious and suspicious activity to protect organizations from such stealthy attacks. The National Security Agency (NSA) has also published a Cybersecurity Advisory [PDF] which contains a hunting guide for the tactics, techniques, and procedures (TTPs) discussed in this blog.
As with any observed nation-state actor activity, Microsoft has directly notified targeted or compromised customers, providing them with important information needed to secure their environments. To learn about Microsoft’s approach to threat actor tracking, read Microsoft shifts to a new threat actor naming taxonomy.

Initial access
Volt Typhoon achieves initial access to targeted organizations through internet-facing Fortinet FortiGuard devices. Microsoft continues to investigate Volt Typhoon’s methods for gaining access to these devices.
The threat actor attempts to leverage any privileges afforded by the Fortinet device, extracts credentials to an Active Directory account used by the device, and then attempts to authenticate to other devices on the network with those credentials.
Volt Typhoon proxies all its network traffic to its targets through compromised SOHO network edge devices (including routers). Microsoft has confirmed that many of the devices, which include those manufactured by ASUS, Cisco, D-Link, NETGEAR, and Zyxel, allow the owner to expose HTTP or SSH management interfaces to the internet. Owners of network edge devices should ensure that management interfaces are not exposed to the public internet in order to reduce their attack surface. By proxying through these devices, Volt Typhoon enhances the stealth of their operations and lowers overhead costs for acquiring infrastructure.
Post-compromise activity
Once Volt Typhoon gains access to a target environment, they begin conducting hands-on-keyboard activity via the command line. Some of these commands appear to be exploratory or experimental, as the operators adjust and repeat them multiple times.
Volt Typhoon rarely uses malware in their post-compromise activity. Instead, they rely on living-off-the-land commands to find information on the system, discover additional devices on the network, and exfiltrate data. We describe their activities in the following sections, including the most impactful actions that relate to credential access.
Credential access
If the account that Volt Typhoon compromises from the Fortinet device has privileged access, they use that account to perform the following credential access activities.
Microsoft has observed Volt Typhoon attempting to dump credentials through the Local Security Authority Subsystem Service (LSASS). The LSASS process memory space contains hashes for the current user’s operating system (OS) credentials.


Volt Typhoon also frequently attempts to use the command-line tool Ntdsutil.exe to create installation media from domain controllers, either remotely or locally. These media are intended to be used in the installation of new domain controllers. The files in the installation media contain usernames and password hashes that the threat actors can crack offline, giving them valid domain account credentials that they could use to regain access to a compromised organization if they lose access.


Discovery
Microsoft has observed Volt Typhoon discovering system information, including file system types; drive names, size, and free space; running processes; and open networks. They also attempt to discover other systems on the compromised network using PowerShell, Windows Management Instrumentation Command-line (WMIC), and the ping command. In a small number of cases, the threat actors run system checks to determine if they are operating within a virtualized environment.
Collection
In addition to operating system and domain credentials, Volt Typhoon dumps information from local web browser applications. Microsoft has also observed the threat actors staging collected data in password-protected archives.
Command and control
In most cases, Volt Typhoon accesses compromised systems by signing in with valid credentials, the same way authorized users do. However, in a small number of cases, Microsoft has observed Volt Typhoon operators creating proxies on compromised systems to facilitate access. They accomplish this with the built-in netsh portproxy command.

In rare cases, they also use custom versions of open-source tools Impacket and Fast Reverse Proxy (FRP) to establish a C2 channel over proxy.
Compromised organizations will observe C2 access in the form of successful sign-ins from unusual IP addresses. The same user account used for these sign-ins may be linked to command-line activity conducting further credential access. Microsoft will continue to monitor Volt Typhoon and track changes in their activity and tooling.
Mitigation and protection guidance
Mitigating risk from adversaries like Volt Typhoon that rely on valid accounts and living-off-the-land binaries (LOLBins) is particularly challenging. Detecting activity that uses normal sign-in channels and system binaries requires behavioral monitoring. Remediation requires closing or changing credentials for compromised accounts. Suspected compromised accounts or affected systems should be investigated:
- Identify LSASS dumping and domain controller installation media creation to identify affected accounts.
- Examine the activity of compromised accounts for any malicious actions or exposed data.
- Close or change credentials for all compromised accounts. Depending on the level of collection activity, many accounts may be affected.
Defending against this campaign
- Mitigate the risk of compromised valid accounts by enforcing strong multi-factor authentication (MFA) policies using hardware security keys or Microsoft Authenticator. Passwordless sign-in, password expiration rules, and deactivating unused accounts can also help mitigate risk from this access method.
- Reduce the attack surface. Microsoft customers can turn on the following attack surface reduction rules to block or audit some observed activity associated with this threat:
- Block credential stealing from the Windows local security authority subsystem (lsass.exe).Block process creations originating from PSExec and WMI commands. Some organizations may experience compatibility issues with this rule on certain server systems but should deploy it to other systems to prevent lateral movement originating from PsExec and WMI.
- Block execution of potentially obfuscated scripts.
- Harden the LSASS process by enabling Protective Process Light (PPL) for LSASS on Windows 11 devices. New, enterprise-joined Windows 11 (22H2 update) installs have this feature enabled by default. In addition, enable Windows Defender Credential Guard, which is also turned on by default for organizations using the Enterprise edition of Windows 11.
- Turn on cloud-delivered protection in Microsoft Defender Antivirus to cover rapidly evolving attacker tools, techniques, and behaviors such as those exhibited by Volt Typhoon.
- Run endpoint detection and response (EDR) in block mode so that Microsoft Defender for Endpoint can block malicious artifacts, even when your non-Microsoft antivirus does not detect the threat, or when Microsoft Defender Antivirus is running in passive mode. EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post-compromise.
Detection details and hunting queries
Microsoft Defender Antivirus
Microsoft Defender Antivirus detects attempted post-compromise activity. Note, however, that these alerts can also be triggered by threat activity unrelated to Volt Typhoon. Turn on cloud-delivered protection to cover rapidly evolving attacker tools and techniques. Cloud-based machine learning protections block most new and unknown threats.
- Behavior:Win32/SuspNtdsUtilUsage.A
- Behavior:Win32/SuspPowershellExec.E
- Behavior:Win32/SuspRemoteCmdCommandParent.A
- Behavior:Win32/UNCFilePathOperation
- Behavior:Win32/VSSAmsiCaller.A
- Behavior:Win32/WinrsCommand.A
- Behavior:Win32/WmiSuspProcExec.J!se
- Behavior:Win32/WmicRemote.A
- Behavior:Win32/WmiprvseRemoteProc.B
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint alerts with the following titles can indicate possible presence of Volt Typhoon activity.
- Volt Typhoon threat actor detected
The following alerts may also be associated with Volt Typhoon activity. Note, however, that these alerts can also be triggered by threat activity unrelated to Volt Typhoon.
- A machine was configured to forward traffic to a non-local address
- Ntdsutil collecting Active Directory information
- Password hashes dumped from LSASS memory
- Suspicious use of wmic.exe to execute code
- Impacket toolkit
Hunting queries
Microsoft 365 Defender
Volt Typhoon’s post-compromise activity usually includes distinctive commands. Searching for these can help to determine the scope and impact of an incident.
Find commands creating domain controller installation media
This query can identify domain controller installation media creation commands similar to those used by Volt Typhoon.
DeviceProcessEvents
| where ProcessCommandLine has_all ("ntdsutil", "create full", "pro")
Find commands establishing internal proxies
This query can identify commands that establish internal proxies similar to those used by Volt Typhoon.
DeviceProcessEvents
| where ProcessCommandLine has_all ("portproxy", "netsh", "wmic", "process call create", "v4tov4")
Find detections of custom FRP executables
This query can identify alerts on files that match the SHA-256 hashes of known Volt Typhoon custom FRP binaries.
AlertEvidence
| where SHA256 in
('baeffeb5fdef2f42a752c65c2d2a52e84fb57efc906d981f89dd518c314e231c',
'b4f7c5e3f14fb57be8b5f020377b993618b6e3532a4e1eb1eae9976d4130cc74',
'4b0c4170601d6e922cf23b1caf096bba2fade3dfcf92f0ab895a5f0b9a310349',
'c0fc29a52ec3202f71f6378d9f7f9a8a3a10eb19acb8765152d758aded98c76d',
'd6ab36cb58c6c8c3527e788fc9239d8dcc97468b6999cf9ccd8a815c8b4a80af',
'9dd101caee49c692e5df193b236f8d52a07a2030eed9bd858ed3aaccb406401a',
'450437d49a7e5530c6fb04df2e56c3ab1553ada3712fab02bd1eeb1f1adbc267',
'93ce3b6d2a18829c0212542751b309dacbdc8c1d950611efe2319aa715f3a066',
'7939f67375e6b14dfa45ec70356e91823d12f28bbd84278992b99e0d2c12ace5',
'389a497f27e1dd7484325e8e02bbdf656d53d5cf2601514e9b8d8974befddf61',
'c4b185dbca490a7f93bc96eefb9a597684fdf532d5a04aa4d9b4d4b1552c283b',
'e453e6efc5a002709057d8648dbe9998a49b9a12291dee390bb61c98a58b6e95',
'6036390a2c81301a23c9452288e39cb34e577483d121711b6ba6230b29a3c9ff',
'cd69e8a25a07318b153e01bba74a1ae60f8fc28eb3d56078f448461400baa984',
'17506c2246551d401c43726bdaec800f8d41595d01311cf38a19140ad32da2f4',
'8fa3e8fdbaa6ab5a9c44720de4514f19182adc0c9c6001c19cf159b79c0ae9c2',
'd17317e1d5716b09cee904b8463a203dc6900d78ee2053276cc948e4f41c8295',
'472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d',
'3e9fc13fab3f8d8120bd01604ee50ff65a40121955a4150a6d2c007d34807642')
Microsoft Sentinel
Below are some suggested queries to assist Microsoft Sentinel customers in identifying Volt Typhoon activity in their environment:
- LSASS process memory dumping
- Potential Impacket execution
- Domain controller installation media creation commands similar to those used by Volt Typhoon
- Commands that set up internal proxies resembling the ones employed by Volt Typhoon
Microsoft customers can use the TI Mapping analytics (a series of analytics all prefixed with ‘TI map’) to automatically match the malicious hash indicators (related to the custom Fast Reverse Proxy binaries) mentioned in this blog post. These analytics are part of the Threat Intelligence solution and can be installed from the Microsoft Sentinel Content Hub if not currently deployed. More details on the Content Hub can be found here: https://learn.microsoft.com/azure/sentinel/sentinel-solutions-deploy.
Indicators of compromise (IOCs)
The below list provides IOCs observed during our investigation. We encourage our customers to investigate these indicators in their environments and implement detections and protection to identify past related activity and prevent future attacks against their systems.
Volt Typhoon custom FRP executable (SHA-256):
- baeffeb5fdef2f42a752c65c2d2a52e84fb57efc906d981f89dd518c314e231c
- b4f7c5e3f14fb57be8b5f020377b993618b6e3532a4e1eb1eae9976d4130cc74
- 4b0c4170601d6e922cf23b1caf096bba2fade3dfcf92f0ab895a5f0b9a310349
- c0fc29a52ec3202f71f6378d9f7f9a8a3a10eb19acb8765152d758aded98c76d
- d6ab36cb58c6c8c3527e788fc9239d8dcc97468b6999cf9ccd8a815c8b4a80af
- 9dd101caee49c692e5df193b236f8d52a07a2030eed9bd858ed3aaccb406401a
- 450437d49a7e5530c6fb04df2e56c3ab1553ada3712fab02bd1eeb1f1adbc267
- 93ce3b6d2a18829c0212542751b309dacbdc8c1d950611efe2319aa715f3a066
- 7939f67375e6b14dfa45ec70356e91823d12f28bbd84278992b99e0d2c12ace5
- 389a497f27e1dd7484325e8e02bbdf656d53d5cf2601514e9b8d8974befddf61
- c4b185dbca490a7f93bc96eefb9a597684fdf532d5a04aa4d9b4d4b1552c283b
- e453e6efc5a002709057d8648dbe9998a49b9a12291dee390bb61c98a58b6e95
- 6036390a2c81301a23c9452288e39cb34e577483d121711b6ba6230b29a3c9ff
- cd69e8a25a07318b153e01bba74a1ae60f8fc28eb3d56078f448461400baa984
- 17506c2246551d401c43726bdaec800f8d41595d01311cf38a19140ad32da2f4
- 8fa3e8fdbaa6ab5a9c44720de4514f19182adc0c9c6001c19cf159b79c0ae9c2
- d17317e1d5716b09cee904b8463a203dc6900d78ee2053276cc948e4f41c8295
- 472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d
- 3e9fc13fab3f8d8120bd01604ee50ff65a40121955a4150a6d2c007d34807642
The post Volt Typhoon targets US critical infrastructure with living-off-the-land techniques appeared first on Microsoft Security Blog.
Windows XP Activation Algorithm Has Been Cracked
Read more of this story at Slashdot.
10 Unexpected Benefits to Negotiate When You Sign a New Lease (Besides Rent)

Buying a home has consistently trended toward unaffordable in the last few years, but so has renting: The median rent across the U.S. in January 2020 sat at $1,585 and peaked at $2,053 just 2.5 years later. While rent prices have begun to level out and even drop in some areas, it’s still a burden for many.
The Whales Are Revolting Against Humanity And A Forgotten Jaws Rip-Off Warned Us

A wannabe "Jaws" rip-off theorized what would happen if a killer whale wreaked revenge on humanity -- "Orca" was a warning. Let's be honest: it's kind of a surprise that it's taken this long for killer whales to revolt against humans. We've poisoned their oceans, killed their young, and forced them into a life of showbiz in cramped theme park pools. Humans had a good run but it seems that orcas are the new mammals in charge.
Sailors working off the coast of Western Europe have reported a series of attacks by a group of orcas they said seemed to be "coordinated." This included striking and sinking a number of boats, although no human casualties have been reported. Some scientists said spikes in aggression may have been started by a female orca nicknamed White Gladis, who is believed to have suffered trauma after a collision with a sailboat.
While other experts are more skeptical and have noted that the vast majority of orcas are harmless to humans, this news has sparked many conversations about what these whales know and if they could possess a propensity for vengeance. We know that orcas are sophisticated animals who are fiercely devoted to their family pods. It doesn't seem unreasonable to imagine the true kings of the ocean getting revenge on the biped mouth-breathers who wronged them.
It would certainly make for fascinating entertainment, although pop culture typically views orcas as gentle giants and friends of cutesy human moppets, as with "Free Willy." "Jaws," they ain't, although "Orca" did dive into that possibility with fascinating results.
Orca Is A Blatant Jaws Rip-Off

It's easy to downplay just how much "Jaws" changed cinematic history. Steven Spielberg's beach thriller, adapted from a schlocky horror novel by Peter Benchley, exploded upon release and almost immediately became the highest-grossing film of all time. Alongside "Star Wars," it helped to define the entire concept of the summer blockbuster, and to this day, it's considered a classic.
As always happens in Hollywood, everyone saw the success of "Jaws" and decided to replicate it by essentially ripping off that film's concept of a killer shark attacking an unsuspecting community. "Mako: The Jaws of Death" focused on a man with a telepathic connection to sharks who sets out to protect them from cruel humans. "Grizzly" swapped out the shark for a bear with a taste for human flesh. Joe Dante and Joe Corman went more tongue-in-cheek with "Piranha," which earned the honor of being called "the best" of the "Jaws" rip-offs by Spielberg himself. Even the official "Jaws" sequels couldn't make lightning strike twice.
One mogul especially keen to cash in on the success of "Jaws" was Dino De Laurentiis, the infamous Italian producer who gave the world films as varied as "Blue Velvet," "Flash Gordon," "Army of Darkness," and the '70s "King Kong" remake where he climbs up the Twin Towers of the World Trade Center. He instructed his regular collaborator, producer Luciano Vincenzoni, to "find a fish tougher and more terrible than the great white."
That led him to the orca, an animal that, at the time, was seen as rather mysterious. There were, however, a number of documented orca attacks on humans in captivity, which included incidents such as a SeaWorld trainer being bitten on the legs and a Canadian aquarium trainer being dragged around the pool and almost drowning. And so, 1977's "Orca" was born.
Orca Is A Very Weird Movie

"Orca" was directed by Michael Anderson, the Oscar nominee behind "Around the World in 80 Days" and "The Dam Busters." With Richard Harris and Charlotte Rampling in the lead roles, it seemed at first like a far more prestige-driven project than that which it sought to copy. Of course, that didn't last long. The film follows a surly Irish Canadian sea captain named Nolan (Harris) who hunts marine animals for cash. After witnessing an orca attacking a shark -- see, "Orca" literally beats "Jaws" in this movie -- Nolan decides to entrap the whale. Things quickly go wrong when he harpoons a pregnant female, who then miscarries before dying herself. Her mate witnesses the murder and decides to wreak revenge on Nolan.
The orca's mission quickly becomes very intense. He dumps the corpse of his mate onto the shore as a warning sign to Nolan. He terrorizes the small town where Nolan lives, essentially destroying its fishing market until the villagers revolt against Nolan, and then blows up their fuel pipelines. At one point, he bites off Annie's (Bo Derek) leg, then wrecks Nolan's house. Soon, Nolan knows he has only one option left: to face the orca down, Spaghetti Western-style, atop the icebergs around the Newfoundland coast.
This story is already bonkers, with a whale basically becoming Dirty Harry without the guns, but it's made all the weirder by the direction of "Orca." Imagine the B-movie schlock of a Corman film, the portentous metaphors of "Moby-Dick," the revenge fantasy of "Death Wish," and the cinematographic elegance of a David Attenborough nature documentary, complete with a hauntingly beautiful score by Ennio Morricone. For a "Jaws" rip-off, it had some real ambition behind it.
Orca Is A Hardcore Tale Of Revenge And Guilt

The fingerprints of "Jaws" are obviously all over "Orca," and critics called that out the moment it was released. It certainly lacks Steven Spielberg's impeccable control of the camera and isn't helped by the fact that their leading man, Richard Harris, was reportedly extremely drunk during production (and kept performing his own stunts, which did not end well). Yet it's also aiming for something more literary than its biggest inspiration.
Nolan becomes the Ahab of "Moby-Dick" but reluctantly so, haunted by a whale who won't leave him be that represents the darkest recesses of his guilt. His descent into madness, a rare instance of a performance being positively aided by the actor's inebriation, feels raw and palpably real. The stakes are high, made all the more painful by the sheer visceral violence of "Orca." The scene where the female whale miscarries and dies is genuinely shocking, to the point where you wonder how the hell they got away with making it in the '70s.
Unlike other "Jaws" wannabes, which deliver their ocean madness with a wink and a nod, "Orca" takes its admittedly silly premise 100% seriously. It also sides entirely with the whale over the humans, even as Nolan reveals his own tragic backstory involving the deaths of his family. We're still living in the aftermath of "Jaws" and its demonization of sharks, which even Spielberg came to regret, with conservationists citing the film as a major reason for public fear of an animal that seldom ever kills humans.
With "Orca," the film wants you to root not just for the whale but for nature as a whole. Charlotte Rampling delivers monologues that wouldn't sound out of place at an animal rights protest while the whale all but blows up a coastal town, and he's not the bad guy here! By the end of "Orca," you get the sense that the humans got off lightly.
How Orcas Are Depicted In Film

"Orca" was a mild box office success, but it didn't come close to "Jaws" levels of money, nor did it inspire further orca-related revenge films. The orca's biggest moment in the cinematic spotlight came in 1993 with the family drama "Free Willy." That tale, of a captured orca forced into captivity at a theme park who befriends a young human boy, became an unexpected pop culture phenomenon. Several sequels followed, including a truly inexplicable kids' TV cartoon where the protagonist gains magical abilities to hear animals talk and Willy must fight an evil cyborg who dresses like the Phantom of the Opera.
Yet its legacy is complex. This was a film about the evils of capturing wild marine life for entertainment that was reliant on the involvement of a captured orca named Keiko. While the movie's success did lead to Keiko being freed and a failed reintegration into ocean life, it didn't quash the popularity of animal attractions at marine parks such as SeaWorld. Indeed, it may have bolstered them in some manner.
The most influential and perhaps most infamous film featuring an orca is "Blackfish," Gabriela Cowperthwaite's documentary on the captive orca Tilikum and the three people he killed, including a SeaWorld trainer named Dawn Brancheau. For many, this film was their first unflinching insight into the cruelty of holding such majestic creatures in captivity and training them to do shows. While SeaWorld claimed that "Blackfish" was "inaccurate and misleading," it was clear that the film made an impact.
Attendance to SeaWorld declined following its release, and legislation was introduced to ban orcas from being kept in captivity. In 2016, SeaWorld finally announced plans to end both the killer whale shows and its orca breeding programs. It was a long time coming. Orcas may not have been fully understood by the general public for decades, but culturally speaking, their intelligence and danger have never been hidden. When even a bonkers revenge film like "Orca" understands that point, you have to wonder why nobody saw the inevitable happening. If the whales truly come to wreck all of our s***, don't say we weren't warned.
Read this next: Every Steven Spielberg-Directed Horror Movie, Ranked
The post The Whales are Revolting Against Humanity and a Forgotten Jaws Rip-Off Warned Us appeared first on /Film.
6 Cybersecurity Strategies to Help Protect Your Small Business in 2023

Cybersecurity is a major concern for individuals as well as small businesses, and there are several strategies bad actors use to exploit small businesses and their employees. In fact, around 60% of small businesses that experienced a data breach were forced to close their doors within six months of being hacked.
From monitoring your network endpoints to routinely educating your employees, there are several proactive steps you can take to protect against cyber attacks. In this article, we’ll share six cybersecurity protection strategies to help protect your small business.
1. Implement Layered Security
According to the FBI’s Internet Crime Report, the cost of cybercrimes to small businesses reached $2.4 billion in 2021. Yet, many small business owners believe they are not in danger of an attack. Robust and layered security allows small businesses to contend with the barrage of hackers after their information.
According to IBM, there four main layers of security need to be addressed:
- System Level Security. This is the security of the system you are using. For instance, many systems require a password to access their files.
- Network Level Security. This layer is where the system connects to the internet. Typically, a firewall is used to filter network traffic and halt suspicious activity.
- Application Level Security. Security is needed for any applications you choose to use to run your business, and should include safeguards for both the internal and the client side.
- Transmission Level Security. Data when it travels from network to network also needs to be protected. Virtual private networks (VPNs) can be used to safeguard information.
As a business, you should always operate on the principle of least privilege. This ensures that access at each of these levels of security is limited to only those necessary to do the task at hand and reduces the potential for breaches. It also can “limit the blast radius” in the event of a breach.
The Human Element: Employee Training Is Your First Defense
The most common forms of cyberattack leverage social engineering, particularly in phishing attacks. This means that they target employees, often during busy times of the year, and attempt to gain their trust and get them to lower their guard. Training employees to spot potential phishing red flags—like incorrect domains, misspelling information, and falsely urgent requests—is a powerful tool in your arsenal.
Additionally, you’ll note that most of the things on this list just don’t work unless your employees understand how, why, and when to use them. In short, an educated staff is your best defense against cyberattacks.
2. Use Multi-Factor Authentication
Multi-factor authentication (MFA) has become increasingly common, and many organizations now require it. So what is it? Multi-factor authentication requires at least two different forms of user verification to access a program, system, or application. Generally, a user must input their password. Then, they will be prompted to enter a code they receive via email or text. Push notifications may substitute email or text codes, while biometrics like fingerprints can substitute a password.
The second step prevents unauthorized users from gaining entry even if login credentials have been compromised. Moreover, the code or push notification alerts the user of a potential breach—if you receive a notification when you did not initiate a login attempt, then you know your account has a vulnerability.
3. Make Sure Your Tech Stack Is Configured Properly
When systems are misconfigured, they are vulnerable. Some examples of misconfiguration are when passwords are left as their system default, software is outdated, or security settings are not properly enabled. As businesses scale and upgrade their tools, they naturally add more complexity to their tech stacks.
It’s important to run regular audits to make sure that IT best practices are being followed, and to make sure that all of your tools are working in harmony. (Bonus: regular audits of this type can result in OpEx savings since you may identify tools you no longer use in the process.)
4. Encrypt Your Data
Encryption uses an algorithm to apply a cipher to your data. The most commonly used algorithm is known as Advanced Encryption Standard (AES). AES can be used in authenticating website servers from both the server end and the client end, as well as to encrypt transferred files between users. This can also be extended to include digital documents, messaging histories, and so on. Using encryption is often necessary to meet compliance standards, some of which are stricter based on your or your customers’ geographic location or industry.
Once it’s encrypted properly, data can only be accessed with an encryption key. There are two main types of encryption key: symmetric (private) and asymmetric (public).
Symmetric (Private) Encryption Keys
In this model, you use one key to both encode and decode your data. This means that it’s particularly important to keep this key secret—if it were obtained by a bad actor, they could use it to decrypt your data.
Asymmetric (Public) Encryption Keys
Using this method, you use one key to encrypt your data and another to decrypt it. You then make the decryption key public. This is a widely-used method, and makes internet security protocols like SSL and HTTPS possible.
Server Side Encryption (SSE)
Some providers are now offering a service known as server side encryption (SSE). SSE encrypts your data as it is stored, so stolen data is unable to be read or viewed, and even your data storage provider doesn’t have access to sensitive client information. To make data even more secure when stored, you can also make it immutable by enabling Object Lock. This means you can set periods of time that the data cannot be changed—even by those who set the object lock rules.
Combined with SSE, you can see how it would be key to protecting against a ransomware attack: Cyberattackers may access data, but it would be difficult to decrypt with SSE, and with object lock, they wouldn’t be able to delete or modify data.
5. Have a Breach Plan
Unfortunately, as cybercrime has increased, breaches have become nearly inevitable. To mitigate damage, it is paramount to have a disaster recovery (DR) plan in place.
This plan starts with robust and layered security. For example, a cybercriminal may gain a user’s login information, but having MFA enabled would help ensure that they don’t gain access to the account. Or, if they do gain access to an account, by operating on the principle of least privilege, you have limited the amount of information the user can access or breach. Finally, if they do gain access to your data, SSE and Object Lock can prevent sensitive data from being read, modified, or deleted.
Hopefully, you’ve set things up so that you have all the protections you need in place before an attack, but once you’re or in the midst of an attack (or you’ve discovered a previous breach), it’s important that everyone knows what to do. Here are a few best practices to help you develop your DR plan:
Back Up Regularly and Test Your Backups
The most important thing to do is to make sure that you can reconstitute your data to continue business operations as normal—and that means that you have a solid backup plan in place, and that you’ve tested your backups and your DR plan ahead of time.
Establish Procedures for Immediate Action
First and foremost, employees should immediately inform IT of suspicious activity. The old adage “if you see something, say something,” very much applies to security. And, there should also be clear discovery and escalation procedures in effect to both evaluate and address the incident.
Change Credentials and Monitor Accounts
Next, it is crucial to change all passwords, and identify where and how the issue occurred. Each issue is unique, so this step takes careful information gathering. Having monitoring tools set up in advance of a breach will help you gain insight into what happened.
Support Employees
It may sound out of place to consider this, but given that employees are your first line of defense and the most targeted security vulnerability, there is a measurable impact from the stress of ransomware attacks. Once the dust has settled and your business is back online, good recovery includes both insightful and responsive training as well as employee support.
Is Cyber Insurance Worth It?
You may want to consider cyber insurance as you’re thinking through different disaster recovery scenarios. Cyber insurance is still a growing field, and it can cover things like your legal fees, business expenses related to recovery, and potential liability costs. Still, even the process of preparing your business for cyber insurance coverage can be beneficial to improving your business’ overall security procedures.
6. Use Trusted Services
Every business needs to rely on other businesses to operate smoothly, but it can also expose your business to risk if you don’t perform your due diligence. Whether it is a credit card processor, bank, supplier, or another support, you will need to select reliable, reputable, and businesses that also employ good security practices. Evaluating new tools should be a multi-faceted process that engages teams with different expertises, including the stakeholder teams, security, IT, finance, and anyone else who you deem appropriate.
And, remember that more tools are being created all the time! Often, they make things easier on employees while also solving security conundrums. Some good examples are single sign on (SSO) services, password management tools, specialized vendors that evaluate harmful links, automatic workstation backup that runs in the background, and more. Staying up-to-date on the new frontier of tools can solve long-standing problems in innovative ways.
Cybersecurity Is An Ongoing Process
The prevalence of cyber crime means it is not a matter of if a breach will happen, but when a breach will happen. These prevention measures can reduce your risk of becoming the victim of a successful attack, but you should still be prepared for when one occurs.
Bear in mind, cybersecurity is an ongoing process. Your strategies will need to be reviewed routinely, passwords need to be changed, and software and systems will need to be updated. Lastly, knowing what types of scams are prevalent and their signs will help keep you, your business, your employees, and your clients safe.
The post 6 Cybersecurity Strategies to Help Protect Your Small Business in 2023 appeared first on Backblaze Blog | Cloud Storage & Cloud Backup.
Microsoft Build 2023: Announcing new identity, compliance, and security features from Microsoft Security
At Microsoft Build 2023—an event for developers by developers—we’re going to announce exciting new features and technologies, share ideas, and help everyone boost their skills so we can all build a more secure future together. This year’s Microsoft Build offers a full program, both online and in-person, to suit every attendee, whether you’re a professional developer, data pro, or a brand-new coder. Not only is Microsoft Build a great opportunity to gain new knowledge and skills, but it’s also the place to meet and learn from other developers. If you haven’t registered yet, I invite you to visit the Microsoft Build event page.
Microsoft Build 2023
Browse virtual and in-person security sessions at Microsoft Build.
Below is a quick tour of a few security-related sessions and the new features and technologies they highlight.
New identity and access features in Microsoft Entra

Welcome to modern identity and access management with Microsoft Entra
Developers are in the business of building app features and capabilities. Most developers are not—and don’t want to be—identity security experts.
At Microsoft Build, we’re announcing the next generation customer identity access management platform: Microsoft Entra External ID, now in preview. Microsoft Entra External ID was purpose-built to personalize and secure access to applications while protecting any external identity and effectively controlling which resources they can access. It delivers a flexible, unified identity platform, personalized customer experiences, adaptive access policies, and built-in identity governance. In the session “Explore CIAM capabilities with External Identities in Microsoft Entra,” Yoel Horvitz, Senior Program Manager, Microsoft Azure Active Directory (Azure AD), and Namita Singh, Senior Software Engineer at Cloud Data Center Cybersecurity, Microsoft, will explore how easily you can create branded sign-up and sign-in app experiences. No more trade-offs between great security and great customer experiences. You’ll see how quickly you can add a strong sign-up or sign-in experience plus comprehensive onboarding flows that capture and validate customer information.
Partner identity scenarios (B2B Collaboration) remain in the same location on the Microsoft Entra admin portal within the Workforce tenant. Please note that there is no action for our current Azure AD business-to-consumer (B2C) customers required at this time as the next generation platform is currently in early preview only. We remain fully committed to support the current Azure AD B2C solution, and there are no requirements for B2C customers to migrate at this time and no plans to discontinue the current B2C service.
This next-generation expanded solution for customer and partner identities marks the next chapter in our customer identity solution, addressing critical customer feedback and building on top of our existing capabilities.
External ID now combines familiar B2B collaboration functionality in Microsoft Entra (generally available) with evolved and unified customer identity (CIAM) capabilities, targeting customer-facing applications, now in preview. Help us shape the future of this new platform with your participation in our preview.
Microsoft Entra Verified ID digital wallet SDK
Microsoft Entra Verified ID
Learn moreMicrosoft Entra Verified ID is an open standards-based verifiable credentials service that customers can use to automate the identity validation process while enabling privacy-protected interactions between organizations and users. You can integrate the upcoming release of the Verified ID Wallet Library into your mobile apps to store and share digital Verified ID cards. This allows you to issue verifiable credentials for dozens of use cases, such as reducing the risk for fraud and account takeovers, streamlining app sign-ins, creating self-service account recovery and helpdesk flows, and enabling rich partner rewards ecosystems. Be sure to check out the “Reduce fraud and improve engagement using Digital Wallets” session by Christer Ljung, Principal Program Manager, Microsoft, and Sydney Morton, Software Engineer, Microsoft, to learn more about Verified ID’s open source digital wallet SDK.
New capabilities for compliance and data automation in Microsoft Purview
General availability of machine learning-enabled source code classifier
Microsoft purview information protection
Learn moreMicrosoft Purview Information Protection helps organizations automate data classification, labeling, and protection across multiple platforms. More than 35 pre-trained classifiers help quickly identify and protect some of the most sensitive data, such as intellectual property and trade secrets, material non-public information, sensitive health and medical files, business sensitive financial information, and personally identifiable information for General Data Protection Regulation (GDPR) compliance. Plus, an improved ready-to-use source code classifier that supports more than 70 file extensions and 23 programming languages can detect embedded and partial source code.
New APIs available to help automate compliance workflows
Microsoft Purview ediscovery
Learn moreYou can take advantage of new Microsoft Graph APIs built specifically for Microsoft Purview eDiscovery and compliance scenarios to help organizations automate their litigation and investigation workflows. Join us for “Streamline eDiscovery with new innovations, including Microsoft Graph APIs,” a sequel to Microsoft Senior Product Marketing Manager Caitlin Fitzgerald’s Microsoft Build 2022 session, which will share recent examples of using APIs to ensure repeatable and predictable management of time-sensitive compliance processes.
Explore built-in security features in these Microsoft Build sessions
Unlocking the Power of Azure Security: Conversations with Experts, Q&A
In this Q&A session, Richard Diver, Technical Story Design Lead, Microsoft, will moderate a panel of experts who help secure the software supply chain within Microsoft Azure and other platforms. The session is based on a four-part blog series that includes Microsoft Azure’s defense-in-depth approach to cloud vulnerabilities and Cloud Variant Hunting. The panel will share Microsoft security best practices and how we’re enhancing our response process, extending our internal security research, and continually improving how we secure multitenant services.
Next-Level DevSecOps: Secure Supply Chain Consumption Framework, Q&A
The Secure Software Supply Chain Framework (S2C2F) is designed from the ground up to protect developers from accidentally consuming malicious and compromised packages. In this Q&A session, Mia Reyes, Director, Foundational Security—Cybersecurity, Microsoft, will moderate a panel of leads from our Secure Software Supply Chain team, including Adrian Diglio, Principal Product Marketing Manager, Microsoft, and Jasmine Wang, Product Manager, Microsoft, as they share the Secure Supply Chain Consumption Framework S2C2F. Learn how to patch your vulnerable components faster to prevent consumption of malicious or compromised packages. Download the Secure Supply Chain Consumption Framework Simplified Requirements guide to learn how you can improve your open source software (OSS) consumption practices.
According to Sonatype’s 2022 State of the Software Supply Chain report, supply chain attacks targeting OSS have increased by an average of 742 percent each year for the past three years.1
Microsoft Build 2023
Join us in Seattle for Microsoft Build from May 23 to 25, 2023. We’ll stream online sessions May 23 and 24, 2023 during Pacific Time hours. Register now to reserve your spot and visit the Microsoft Build 2023 website to explore the session catalog and plan your experience. We look forward to connecting with you!
To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and Twitter (@MSFTSecurity) for the latest news and updates on cybersecurity.
18th Annual State of the Software Supply Chain Report, Sonatype.
The post Microsoft Build 2023: Announcing new identity, compliance, and security features from Microsoft Security appeared first on Microsoft Security Blog.
Security Pros: Before You Do Anything, Understand Your Threat Landscape
Regardless of the use case your security organization is focused on, you’ll likely waste time and resources and make poor decisions if you don’t start with understanding your threat landscape.
The post Security Pros: Before You Do Anything, Understand Your Threat Landscape appeared first on SecurityWeek.
Malware On Android Still Remains At Large As More ‘Legit’ Apps Appear To Be Snooping Data And Extracting Files

Although Google Play Store is largely free of any issues with its tight security and strict policies, every now and then, an app or two manages to slip through the cracks, and while it might seem harmless at best, you cannot say the same as it ends up doing some sort of damage. And today, we have news of another app that posed as a screen recorder, but underneath all that, there was a lot more that made the app dangerous, including malware.
Android and Google Play Store are under fire again as dangerous malware stayed on the store without anyone taking notice
Thankfully, the app has been removed ever since, but Play Store was home to an app called iRecorder, and the app stayed on the storefront for almost two years before it got removed. Judging by the name, you would assume you are looking at a seemingly harmless app that allows you to record your screen and share it with friends. However, after the 2022 update, a remote-control backdoor was added to the app.
According to the source, this backdoor code was a variant called AhRat, based on AhMyth, which happens to be spyware that has been found in other Android apps hosted on Play Store before, as well. This time around, however, AhMyth was used in the app in question, and the source mentions how the code mentioned to record audio snippets from the device that had the app installed. However, it gets scary. This code was also able to extract files of various formats from within the infected device. Worse still is that this Android malware was hidden so that it would not be easily detected, as the app itself would behave normally with all its functionality intact.
Thankfully, the source has claimed that they have not found the AhMyth, or AhRat, (a lightweight variant) anywhere so far, and the app in question has also been removed from the Google Play Store after it was reported. One thing to note, however, is that since Android allows sideloading of apps, you might be able to find the infected version somewhere on the third-party app, and I would highly advise against sideloading the app.
This is an issue that is very common with Android, and this is one of the reasons why Apple is against sideloading because the company is not in favor of compromising the security of its devices and the users.
Source: ESET
Make a Bee-Friendly Watering Hole for Your Garden

While we’ve all been focused on growing a bee-friendly habitat in our gardens by planting pollinator friendly varieties, there’s something else that’s vital to the health of bees that often goes unmentioned: Bees need water. In their natural habitats, bees get water from ponds, pools, and puddles that naturally occur…
Cutting Through the Noise: What is Zero Trust Security?
With proactive steps to move toward Zero Trust, technology leaders can leverage an old, yet new, idea that must become the security norm.
The post Cutting Through the Noise: What is Zero Trust Security? appeared first on SecurityWeek.
The Rising Threat of Secrets Sprawl and the Need for Action
A Simple Question From Leonardo DiCaprio Completely Changed Killers Of The Flower Moon

David Grann's "Killers of the Flower Moon: The Osage Murders and the Birth of the FBI" is one of the finest nonfiction books of the 21st century. His account of a vile criminal conspiracy wherein members of the Osage tribe, who'd been awarded highly lucrative headrights to the oil deposits discovered on their land, were murdered by white Oklahomans is as absorbing as it is infuriating. Grann does a masterful job of blending the story of the Osage with the procedural tale of the investigation by the United States' newly formed Bureau of Investigation (soon to be the FBI). It's never less than gripping, but, even with the conviction of William Hale, who orchestrated the murder of his nephew's Osage wife and many of her family members, you're left fuming at the abject evil of these predators.
Grann's story is primarily driven by Tom White, a former Texas Ranger who's joined the FBI to probe the multitude of murders in and around the Osage's land. White was a virtuous lawman. He couldn't be bought. He was the perfect man to investigate the conspiracy, but as a film protagonist, that kind of character gets boring really quick (which is why Brian De Palma's "The Untouchables" provides Kevin Costner's Eliot Ness with a colorful beat-cop mentor in Sean Connery's Malone).
For Martin Scorsese, whose big-screen adaptation of Grann's book just premiered to mostly raves at the 2023 Cannes Film Festival, White proved to be something of a narrative dead end. So when Leonardo DiCaprio, who was set to play White, suggested a different way into the story, Scorsese leapt at it.
Turning A Procedural Into A Twisted Love Story

When Scorsese signed on to make "Killers of the Flower Moon," he envisioned DiCaprio as White because, well, he was the logical lead. Academy Award-winning screenwriter Eric Roth, who wrote one of the finest procedurals ever in "The Insider," set out to tell the tale of the White's meticulous take down of Hale.
But while the story was righteous in ways that are often showered with Oscars, something didn't sit right with DiCaprio. In an interview with Deadline, Scorsese recalled the moment the writing of the film took a completely unexpected turn. "Leo DiCaprio looked at me and said, 'Where's the heart in this movie?'" said the filmmaker. He immediately got it. Per Scorsese:
"Look, the minute the FBI comes in, and you see a character that would be played by Robert De Niro, Bill Hale, you know he's a bad guy. There's no mystery. So, what is it? A police procedural? Who cares! We've got fantastic ones on television."
Scorsese began researching, hoping to find some flaws in the man's character. There were none. The man was a boy scout. The director threw up his hands. "I finally said, 'What are we making? A film about Tom White, who comes in and saves everybody?'" (Jesse Plemons plays White in the final film.)
Scorsese then turned to the character of Ernest Burkhart, the enigmatic husband of Mollie Kyle, a full-blooded Osage who had a claim to considerable wealth. This would be DiCaprio's character, and it would transform the complexion of Scorsese's film.
A Portrait Of Unthinkable Betrayal

Ernest was William Hale's nephew, and he married Mollie at his nefarious uncle's urging. But the marriage wasn't strictly opportunistic. As Scorsese noted to Deadline, "The only person that has heart, besides Mollie Burkhart, is her husband Ernest, because they're in love."
This was backed up by Scorsese's meeting with the Osage at the Gray Horse settlement in Oklahoma. Upon learning that their romance was very real, the director realized he had a far more complex film on his hands. If Ernest truly loved Mollie, how could he follow his uncle's orders and try to poison her.
There wasn't much research on Ernest, which gave Scorsese and DiCaprio a tremendous amount of room to operate. They could perform their own, intimate investigation into an unthinkable betrayal. "If we did that," said Scorsese, "we'd take the script and turn it inside out, make it from the ground level out, rather than coming in from the outside. I said, 'Let's put ourselves in the mindset of the people who did this.'"
The early returns suggest that this approach was the right one, but we won't get to see for ourselves until "Killers of the Flower Moon" hits theaters on October 6, 2023. Judging from the trailer, you'll absolutely want to see this on the biggest screen possible.
Read this next: The 14 Best Film Acting Debuts Of All Time
The post A Simple Question From Leonardo DiCaprio Completely Changed Killers of the Flower Moon appeared first on /Film.
Watch the Microsoft Build keynotes here, starting at 12PM ET
After Google I/O and ahead of WWDC, it's Microsoft's turn to step up to the plate and host a developer conference. We'll learn a lot about where the company plans to go in the coming months, with the keynotes covering many of the major updates. The first keynote starts at noon ET today.
It won't be a surprise to anyone who's paid attentionto Microsoftthis year that AI is the focus of Build 2023. Today's keynotes will take place across three back-to-back sessions: "Microsoft Build opening," "The era of the AI Copilot" and "Next-generation AI for developers with the Microsoft Cloud."
In the first 25-minute session, Microsoft CEO Satya Nadella will discuss some of the ways in which the company "is creating new opportunities for developers across our platforms in this new AI era." The second session will feature Open AI president and co-founder Greg Brockman. You can watch today's keynotes right here:
Microsoft has lined up another keynote for Wednesday, titled "Shaping the future of work with AI." Again, the keynote will start at noon Eastern Time. Microsoft executive vice president and chief product officer Panos Panay will take the stage along with Rajesh Jha, executive vice president of experiences and devices. They'll discuss "how developers can shape the future of work with Microsoft 365 Copilot and unlock a new era of AI and productivity with Windows 11." You'll be able to check out that keynote below:
This article originally appeared on Engadget at https://www.engadget.com/watch-the-microsoft-build-keynotes-here-starting-at-12pm-et-023009440.html?src=rssRed Hat Pushes New Tools to Secure Software Supply Chain
Red Hat rolls out a new suite of tools and services to help mitigate vulnerabilities across every stage of the modern software supply chain.
The post Red Hat Pushes New Tools to Secure Software Supply Chain appeared first on SecurityWeek.
Iranian Hackers Using New Windows Kernel Driver in Attacks
Iranian threat actors use a Windows kernel driver called ‘Wintapix’ in attacks against Middle East targets.
The post Iranian Hackers Using New Windows Kernel Driver in Attacks appeared first on SecurityWeek.





