Remote
Red teamer, Incident Responder, vCISO.
0
Followers
0
Following
15
Posts
Joined November 08, 2022
GitHub:
Posts
RE: https://infosec.exchange/@wdormann/117011629918025521
Since Wiz found chaosDb in 2021 it's been obvious that cosmos is a disaster. Sadly, the same lack of defense in depth appears to be still prevalent.
Quoting
Wiz found a master key that could access every database in Azure's Cosmos DB. #cosmosescape
Whoops.
https://nitter.net/yuvalavra/status/2082864672294736324
Open quoted post
Open post
Replying to
@cR0w@infosec.exchange
@cR0w@infosec.exchange Would you rather tell your customers the service is down because an official MS patch went wrong, or their data is public because you failed to apply an available security fix and got hacked?
But yes, it would be nice if we weren't all beta testers for MS.
Perhaps they will need to do a better job of separating the critical security fixes from the lesser 'quality improvements'.
0
0
0
0
Open post
Replying to
@fj@mastodon.social
@fj@mastodon.social why is everyone suddenly calling Balogun's team USMNT? We're not waiting for EMNT V MXMNT...
#fifa2026
0
0
0
0
Open post
Replying to
@GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social bumblebee does something similar
https://github.com/perplexityai/bumblebee
1
0
1
0
Open post
anyone watching the #icehockey ? How did #Czechia and #denmark play in almost identical kits yesterday? Impossible to watch. 😆
##iihfworlds
0
0
1
0
Open post
Replying to
@dangoodin@infosec.exchange
@dangoodin@infosec.exchange I see this got a lot of answers, but why wouldn't you just use your phone? If you're worried about battery just bring a powerbank.
Is there something specific you want like wired headphones? Nostalgia?
I had the first MP3 playing phone in 2000 and never looked back.
0
0
0
0
Open post
Open post
Replying to
@xconde@social.chinwag.org
@xconde @GossiTheDog as long as they also check for abuse of the exploit and Inform you about it. Which would be handy to have a cve number attached to the report.
So, they should still fix and then notify but can't just say "cloud is not affected" if they mean, "cloud is no longer vulnerable"
3
0
0
0
Open post
Open post
Replying to
@zackwhittaker@mastodon.social
@zackwhittaker@mastodon.social but which repo? Is it arch btw? ;)
0
0
0
0
Open post
Replying to
@krejgo@mojos.eco
@krejgo@mojos.eco @randahl@mastodon.social you know Russia is much bigger than the USA right?
0
2
0
0
Open post
Replying to
@ocdtrekkie@mastodon.social
@ocdtrekkie seems like good timing - https://proton.me/business/blog/proton-workspace
0
0
0
0
Open post
Open post
Replying to
@implementcontrols@mastodon.social
@implementcontrols@mastodon.social
Get an agile electricity plan and schedule your backups for the cheap hours - could bring down costs quite a bit - average is only 17p ATM and middle of night potentially -6p :)
https://agileprices.co.uk/
0
0
0
0
Open post
Replying to
@implementcontrols@mastodon.social
@implementcontrols@mastodon.social nice review!
0
0
0
0
Remote instance
infosec.exchange
Open on original server