@quad9dns@mastodon.social avatar quad9dns , to random

The latest Quad9 Trends report with insights from our Director of for H2 2025 👉 https://quad9.net/news/blog/trends-h2-2025-cyber-insights/

ALT
@thejapantimes@mastodon.social avatar thejapantimes , to random

Chinese authorities have told domestic companies to stop using cybersecurity software made by more than a dozen firms from the U.S. and Israel due to national security concerns, sources said. https://www.japantimes.co.jp/business/2026/01/15/tech/china-us-israeli-cybersecurity/?utm_medium=Social&utm_source=mastodon

@infomaxkorea@mastodon.social avatar infomaxkorea Bot , to random

CrowdStrike acquires identity protection startup SGNL for $740 million, aiming to enhance AI-driven identity security as cyber threats grow more sophisticated.

https://en.infomaxai.com/news/articleView.html?idxno=99042

@insane@outerheaven.club avatar insane , to random

ALT
@m0bi@mastodon.com.pl avatar m0bi , to wolny internet Polish

📰 "Wielki upadek jakości oprogramowania: jak znormalizowaliśmy katastrofę

Plan katastrofy wart 10 miliardów dolarów.
Incydent z 19 lipca 2024 r. w firmie stanowi doskonały przykład znormalizowanej niekompetencji.

Jeden plik konfiguracyjny, w którym brakowało sprawdzenia granic tablicy, spowodował awarię 8,5 miliona komputerów z systemem Windows na całym świecie. Służby ratownicze nie działały. Linie lotnicze wstrzymały loty. Szpitale odwołały operacje.

Całkowite straty gospodarcze: minimum 10 miliardów dolarów.

Główna przyczyna? Oczekiwano 21 pól, ale otrzymano 20.

Jedno. Brakujące. Pole.

Nie było to nic skomplikowanego. Był to podstawowy błąd informatyczny, którego nikt nie naprawił. I przeszedł on przez cały proces wdrażania."

Całość [EN]:
https://techtrenches.substack.com/p/the-great-software-quality-collapse

wolnyinternet@szmer.info icon wolny internet

ALT
@heisec@social.heise.de avatar heisec , to random German

WIderstandsfähiges Windows: Antivirensoftware fliegt aus dem Kernel

Ein CrowdStrike-Erlebnis will Microsoft nicht noch einmal haben. Nun fliegt deswegen Antivirensoftware aus dem Windows-Kernel.

https://www.heise.de/news/WIderstandsfaehiges-Windows-Antivirensoftware-fliegt-aus-dem-Kernel-10462538.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

@jerry@infosec.exchange avatar jerry , to random

On this Friday the 13th, let us not forget the sacred lesson that Salt ‘N Peppa, the grand visionary of DevOps, taught us so many years ago: “push it! Push it real good!“

krypt3ia ,
@krypt3ia@infosec.exchange avatar

@jerry Deep within the bowels of right now, a finger hovers above an enter key.

@heisec@social.heise.de avatar heisec , to random German

APT- und Cybercrime-Gangs: Was der Namensabgleich durch die Hersteller bringt

Sicherheitssoftware-Hersteller kooperieren, um Bedrohungsakteure trotz unterschiedlicher Namensgebung eindeutig zu identifizieren. Was bringt das in der Praxis?

https://www.heise.de/hintergrund/APT-und-Cybercrime-Gangs-Was-der-Namensabgleich-durch-die-Hersteller-bringt-10438409.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

@heisec@social.heise.de avatar heisec , to random German

"Cozy Bear = Midnight Blizzard": Namen für Cybergangs sollen abgeglichen werden

Die IT-Sicherheitsszene nutzt unterschiedliche Namen für Cybergruppierungen, Verwirrung ist vorprogrammiert. Microsoft und CrowdStrike versprechen Hilfe.

https://www.heise.de/news/Cozy-Bear-Midnight-Blizzard-Namen-fuer-Cybergangs-sollen-abgeglichen-werden-10423107.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

@arstechnica@mastodon.social avatar arstechnica , to random

Feds charge 16 Russians allegedly tied to botnets used in cyberattacks and spying
An example of how a single malware operation can enable both criminal and state-sponsored hacking.
https://arstechnica.com/security/2025/05/feds-charge-16-russians-allegedly-tied-to-botnets-used-in-cyberattacks-and-spying/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

chrispy ,
@chrispy@chaos.social avatar

@arstechnica
"... according to an analysis of the operation by firm ."
Doesn't ring this name a bell? Ahh, this one:
https://en.m.wikipedia.org/wiki/2024_CrowdStrike-related_IT_outages
How did they manage to stay in business? Oh, maybe they were rewarded for THE largest of ever by a digital tool (due to the thousands of canceled flights :winkekatze: )

@heiseonline@social.heise.de avatar heiseonline , to random German

"Organisatorische Veränderungen": Microsoft entlässt Tausende Mitarbeiter

Trotz Milliardengewinn und optimistischer Aussichten entlässt der US-Konzern Microsoft drei Prozent seines weltweiten Personals. Tausende verlieren ihre Jobs.

https://www.heise.de/news/Organisatorische-Veraenderungen-Microsoft-entlaesst-Tausende-Mitarbeiter-10382577.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

aerofreak ,
@aerofreak@hessen.social avatar

@heiseonline

Sie können den Hals einfach nicht voll genug kriegen.

@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@arstechnica@mastodon.social avatar arstechnica , to random

Microsoft reiterates “non-negotiable” TPM 2.0 requirement for Windows 11
Microsoft won't lower Windows 11's requirements to save older Windows 10 PCs.
https://arstechnica.com/gadgets/2024/12/microsoft-reiterates-non-negotiable-tpm-2-0-requirement-for-windows-11/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

adacosta ,
@adacosta@twit.social avatar

@arstechnica I see two outcomes here, caves, provides an additional 5 years of security updates for or doesn't provide any support, brace for whatever shit storm happens. We all saw what happened with anyway. Microsoft avoided the backlash unscathed, mostly due to it being mostly a business issue. Ultimately, people will upgrade, but I think elephant in the room will be the But the upgrades people choose in the future might actually be from Cupertino.

@arstechnica@mastodon.social avatar arstechnica , to random

Researchers hack electronic shifters with a few hundred dollars of hardware

If you've got a Shimano Di2 groupset, be sure to update its firmware.

https://arstechnica.com/security/2024/08/researchers-hack-electronic-shifters-with-a-few-hundred-dollars-of-hardware/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

ste ,
@ste@noc.social avatar

@arstechnica

My shifters are running so I'll be fine...

@arstechnica@mastodon.social avatar arstechnica , to random

Microsoft says Delta’s ancient IT explains long outage after CrowdStrike snafu

"Delta, unlike its competitors... has not modernized its IT infrastructure."

https://arstechnica.com/tech-policy/2024/08/microsoft-says-deltas-ancient-it-explains-long-outage-after-crowdstrike-snafu/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

jackcole ,
@jackcole@mstdn.social avatar

@arstechnica Yeah, Delta isn't behind SWA, which is still using Windows 2.0 on Intel 486 machines. So the problem for Delta wasn't that their IT infrastructure was behind, it was that they were no far enough behind to escape
Not the winning argument thinks it is. Shifting blame to is right up there with kill the messenger and "who me?"

@solene@bsd.network avatar solene , to random

People criticize , but I remember a night where a leap second happened. Most java servers suddenly stopped working on systems 12 years ago due to that leap second. (there were consuming 100% and doing nothing).

The fix was quite easy (changing current date to the current date... or rebooting system) but this kind of shit can happen on any system.

The best protection against this is software diversity, so all your systems do not crash at the same time for the same reason :flan_laugh:

@itsfoss@mastodon.social avatar itsfoss , (edited ) to random

When a Linux user comes across Windows or CrowdStrike. 😝

@thejapantimes@mastodon.social avatar thejapantimes , to random

Widespread catastrophic failure is inevitable when companies are so reliant on just a few dominant cloud vendors. https://www.japantimes.co.jp/commentary/2024/07/21/world/crowdstrikes-global-outage/

@chandlerc@hachyderm.io avatar chandlerc , to random

For folks seeing the (bad) analysis from the hateful jerk on twitter, and are comfortable reading there, here is a superb breakdown of that analysis by a literal world expert:

https://x.com/taviso/status/1814762302337654829

@privacyguides@neat.computer avatar privacyguides , (edited ) to random
hszakher ,
@hszakher@mastodon.world avatar

@privacyguides >> We [] currently estimate that 's update affected 8.5 million devices, or less than one percent of all Windows machines,<< this is like saying "only 1% of victim's body is damaged, with a bullet to the head wound 😬

Carlos , to random

Interessantes zu dem Ausfall von gestern.
Wie u.a. Golem schreibt:

„Die jüngste Update-Panne von Crowdstrike, durch die unzählige Windows-Systeme nicht mehr starten können, betrifft viele Organisationen auf der ganzen Welt – darunter Banken, Krankenhäuser, Börsen und auch Flughäfen.“
(https://archive.ph/WT2U4#selection-1047.0-1055.1)

Und dazu dann die AGB von Crowdstrike:

„DIE CROWDSTRIKE-ANGEBOTE UND CROWDSTRIKE-TOOLS SIND NICHT FEHLERTOLERANT UND NICHT FÜR DEN EINSATZ IN GEFÄHRLICHEN UMGEBUNGEN AUSGELEGT ODER VORGESEHEN, DIE EINE AUSFALLSICHERE LEISTUNG ODER EINEN AUSFALLSICHEREN BETRIEB ERFORDERN. WEDER DIE ANGEBOTE NOCH DIE CROWDSTRIKE-TOOLS SIND FÜR DEN BETRIEB VON FLUGZEUGNAVIGATION, NUKLEARANLAGEN, KOMMUNIKATIONSSYSTEMEN, WAFFENSYSTEMEN, DIREKTEN ODER INDIREKTEN LEBENSERHALTENDEN SYSTEMEN, FLUGVERKEHRSKONTROLLE ODER ANWENDUNGEN ODER ANLAGEN BESTIMMT, BEI DENEN EIN AUSFALL ZU TOD, SCHWEREN KÖRPERVERLETZUNGEN ODER SACHSCHÄDEN FÜHREN KÖNNTE.“
(https://www.crowdstrike.com/terms-and-conditions-de/)

Scheint ja fast so, als würde nicht nur der Otto Normalverbraucher irgendwelche AGBs einfach so wegklicken.
Wird bestimmt noch spannend in diversen Rechtsabteilungen 😏

@nixCraft@mastodon.social avatar nixCraft , (edited ) to random

For IT folks: Did you manage to recover from the CrowdStrike issue? Are you still facing BSoD?

__End3r__ ,
@__End3r__@mastodon.social avatar

@nixCraft What a problem? I use *nix, i found out about here on mastodon

@shanselman@hachyderm.io avatar shanselman , to random

Context- someone on the birdside are blaming on DEI hiring

Here’s the thing folks. I’ve been coding 32 years. When something like this happens it’s an organizational failure. Yes, some human wrote a bad line. Someone can “git blame” and point to a human and it’s awful. But it’s the testing, the Cl/CD, the A/B testing, the metered rollouts, an oh shit button to roll it back, the code coverage, the static analysis tools, the code reviews, the organizational health, and on and on 1/3

@kevinthomas@defcon.social avatar kevinthomas , to random

In the ever-evolving landscape of cybersecurity, another chilling chapter has been written. Hidden amidst the news cycle, a devastating revelation emerged: has fallen victim to a colossal attack, compromising the personal of 12.9 million individuals. This exposes our digital infrastructure’s vulnerabilities.

Names, addresses, medical histories, and more—intimate details of millions—now rest in the hands of cybercriminals. The sheer scale of this attack highlights the urgent need for a seismic shift in our approach to cybersecurity.

A critical component is recognizing the importance of machine-to-machine (M2M) identity access management. In our interconnected world, ensuring each machine has a secure identity is paramount. This added security layer can prevent unauthorized access and mitigate breach risks.

Investment in cutting-edge technology and unwavering commitment to security must become our new standard.