@GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social avatar

GossiTheDog

@GossiTheDog@cyberplace.social

Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions.

I have Direct Messages disabled - you can send them, but I will never receive them.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Clair Obscur: Expedition 33 also looked great btw

https://www.youtube.com/watch?v=IDyqGZy78Ng

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

thoughts:

They badly needed a good showcase as the Xbox brand is in self inflicted turmoil... and they got it I think. It was great.

Lots of big games and new IP to look forward to.

Not announcing a Pro console when PS5 are about to announce one for this year will probably lead to further console sales erosion but I think they've just given up on hardware now.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

New Dragon Age game. Looks good, I think? https://www.youtube.com/watch?v=4F3N4Lxw4_Y

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

First gameplay of next Assassin's Creed game, set in Japan as a stealth based reboot of the game. Looks fun.

https://www.youtube.com/watch?v=jx8WN9fY22M

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

S.T.A.L.K.E.R. 2: Heart of Chornobyl wasn't on my radar but it is now, gameplay looks interesting. https://www.youtube.com/watch?v=9RktmztDtwg

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

PSA: If you use ComfyUI_LLMVISION in ComfyUI, it was hacked by "Nullbulge Group" and had malware injected. It had Async remote access trojan for Windows embedded in it.

Github repo was https://github.com/AppleBotzz/ComfyUI_LLMVISION, has been pulled now.

"This repository provides integration of GPT-4 and Claude 3 models into ComfyUI, allowing for both image and text-based interactions within the ComfyUI workflow."

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Btw ComfyUI should be blocked in business environments as the setup of it is ripe for abuse - it's an AI 'stable diffusion' thing where every plugin allows native code execution by design, and there's absolutely no QA or guardrails at all.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Microsoft Flight Simulator 2024 looks incredible. Plus they added a game this time, e.g. careers. Day one, baby. https://www.youtube.com/watch?v=rvzlC4iCtns

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Mixtape looks like exactly my jam. https://www.youtube.com/watch?v=cCTH8R6RD74

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Fable looks great, Playground doing the british Lord's work https://www.youtube.com/watch?v=2FiBmVBaY0g

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Perfect Dark reboot looks.. good? Almost 20 years since the original. https://www.youtube.com/watch?v=ofUi9DR9sc4

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Snake.... snakeeeeeeeeeeee! Gameplay trailer. https://www.youtube.com/watch?v=VTVaEPHa9Bc

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

South of Midnight looks great, looking forward to it. https://www.youtube.com/watch?v=J4UHyaaWXuw

GossiTheDog, (edited ) to random
@GossiTheDog@cyberplace.social avatar

Two big updates:

Starfield House Varun DLC trailer, launches this year but undated: https://www.youtube.com/watch?v=iNM1HFzQC8c

(I tooted about that 6 weeks ago, they accidentally leaked it).

And the big one: surprise Starfield update dropping today: loads of new content in it, official mod support, mod marketplace, Creation Kit etc.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Here's the mod support, it's called Creations and drops today.

Anybody can upload free mods, Bethesda can drop their own mods, and vetted community creators can charge for mods.

I know, I know - paid mods, lame etc as the groupthink, but it should enable modders to make a living and.. well.. incentivises creating big and good mods as it rewards content creators financially.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

NoName DDoS target tracking plus CSV data -> @NoName57Bot

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

A company paid a ransomware group.. then had their info leaked by the same ransomware group anyway. Not isolated at all, eg UnitedHealthcare paid $20m and then got extorted again by the same person.

Stop paying ransomware groups. You are directly funding serious organised crime. https://www.bleepingcomputer.com/news/security/pandabuy-pays-ransom-to-hacker-only-to-get-extorted-again/

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Showed up

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Microsoft Copilot+ Recall launch recap.

video/mp4

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Very big cyber incident playing out at Snowflake, who describe themselves as “AI Data Cloud”. They have a free trial where anybody can sign up and upload data… and they have.

Threat actors have been scraping customer data using a tool called rapeflake, for about a month.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar
GossiTheDog,
@GossiTheDog@cyberplace.social avatar

One thing I didn't know until recently is Snowflake has a massive fanbase, Apple and Amiga style - if you critique Snowflake in any way people flip tables. The comments on my blog are fun. I mean, the clue is in the product name, really.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

IMHO it's fair to call out Snowflake's authentication isn't very good - it's the worst SaaS MFA solution I've seen as it has no top level, easy switch for org wide MFA enforcement.

Combined with putting all customers under *.snowflakecomputing.com sub domain is why their customers are getting owned - infostealers are just full of creds ready to go.

I gather Snowflake are discussing changes to fix, don't tell the fanboys (and yes, they're all dudes).

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

The next Doom will launch this year and be on PlayStation 5 too, along with Starfield.

Source: me.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Doom: The Dark Ages trailer, coming to PS5 day one. https://www.youtube.com/watch?v=CpgAOAOMUnA

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

For those who aren’t aware, Microsoft have decided to bake essentially an infostealer into base Windows OS and enable by default.

From the Microsoft FAQ: “Note that Recall does not perform content moderation. It will not hide information such as passwords or financial account numbers."

Info is stored locally - but rather than something like Redline stealing your local browser password vault, now they can just steal the last 3 months of everything you’ve typed and viewed in one database.

video/mp4

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

A reminder that a few weeks ago at RSA, Microsoft signed CISA's Secure By Design pledge... and then shipped an enabled by design keylogger that OCRs your screen constantly into AppData.

Edit: I should say that's less a reflection on Microsoft and more a reflection on CISA's Secure By Design pledge.. it's a good idea, but the scope is extremely limited.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

A few days ago, IT systems and services at Leicester City Council stopped working. Councillors were not told the cause. (Link: https://www.leicestermercury.co.uk/news/leicester-news/systems-outage-leicester-city-council-9151322)

At 7pm this Friday, they tweeted it is a "cyber incident". Services are still offline.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

On Thursday, my monitoring triggered for Leicester City Council’s network going offline again:

2024-06-07 21:03:32

They’ve not returned online since.

Their website now has a banner which says they are having “essential maintenance works”. The list of services is the same impacted by the ransomware incident.

#threatintel

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • cubers
  • magazineikmin
  • thenastyranch
  • rosin
  • Durango
  • InstantRegret
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • tacticalgear
  • osvaldo12
  • tester
  • modclub
  • normalnudes
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • anitta
  • megavids
  • cisconetworking
  • lostlight
  • All magazines