WEEKEND READS – rule 11 reader: Recent Episodes

Russ White

culture eats technology for breakfast

View Details

Instead, Broadcom is now experimenting with co-packaging the optics directly into the GPUs themselves.

With K-12 schools back in session across the nation, millions of students are adjusting to a new learning environment — a cellphone-free classroom or, in some cases, a phone-free school day.

Being at the core of the Internet places the DNS under a lot of pressure. New forms of DNS abuse emerge each year, disputes over domain names persist, and all the while, the Internet just keeps getting bigger.

The censorship war has hit a flashpoint. Late last month, Brazil banned Elon Musk’s social media site, X, after Musk refused a government order to suppress seven dissident accounts.

This raises a question. If someone is situated in South America and wants to access youtu.be, is their performance going to be impacted (assuming he has to do the entire recursive lookup with no cache)?

ODA focuses on identifying macroscopic Internet outages, such as outages that affect a significant portion of the population within either a geographic region or an Autonomous System (AS).

For practitioners, this study provides a rich set of criteria that can be used for evaluating their projects, as well as strong evidence of the importance of considering not only project execution, but also post-project outcomes and impacts in the evaluation.

As if we didn’t have a long enough list of problems to worry about, Lumen researchers at its Black Lotus Labs recently released a blog that said that it knows of three U.S. ISPs and one in India was hacked this summer.

While the usage of internationalized domain names (IDNs) has allowed organizations the world over to enter the global market using their native-language domain names, it can also enable cyber attackers to craft look-alikes of legitimate domains they wish to spoof.

In Texas, for example, the chatbot only consumes an estimated 235 milliliters needed to generate one 100-word email. That same email drafted in Washington, on the other hand, would require 1,408 milliliters (nearly a liter and a half) per email.

Fiber splicing is joining two optical fibers to create a continuous, low-loss, and highly efficient optical path.

Efforts to curb illegal online content through domain shutdowns are proving ineffective and carry significant risks, according to a new report by eco and its topDNS initiative.

The majority of open source project maintainers are not being paid for their work, spend three times as much time on security than they did three years ago, and have become less trusting of contributors following the xz backdoor, according to open source package security firm Tidelift.

View Details

A federal judge struck down a Biden administration rule on Tuesday that banned employers from using noncompete agreements, which would have affected the contracts of millions of Americans.

The Open Compute Project, the org best known for offering designs for hyperscale hardware, has rounded up AWS, Google, Meta, and Microsoft to help it test concrete.

Recent trends show that ransomware attacks continue to grow more advanced and persistent.

When you are designing applications that run across the scale of an entire datacenter and that are comprised of hundreds to thousands of microservices running on countless individual servers and that have to be called within a matter of microseconds to give the illusion of a monolithic application, building fully connected, high bi-section bandwidth Clos networks is a must

The National Institute of Standards and Technology (NIST) just released three finalized standards for post-quantum cryptography (PQC) covering public key encapsulation and two forms of digital signatures. In progress since 2016, this achievement represents a major milestone towards standards development that will keep information on the Internet secure and confidential for many years to come.

Linearity is one of the greatest success stories in mathematics. According to Encyclopedia Britannica, “Unlike other parts of mathematics that are frequently invigorated by new ideas and unsolved problems, linear algebra is very well understood.”

The Turing test could be useful for checking whether a customer service chatbot, for instance, is interacting with people in a way that those people are comfortable with, demonstrating what Jones calls a flexible social intelligence. Whether it can identify more general intelligence, however, is difficult to say.

But in at least some situations, the Supreme Court held this spring in a case called Lindke v. Freed,a it is illegal to block other users. If you are a government official, and you are using social media as part of your job duties, they may have a First Amendment right against being blocked

The recent emergence of generative artificial intelligence and the arrival of assistive agents based on this technology have the potential to offer further assistance to searchers, especially those engaged in complex tasks.

Design and engineering teams increasingly are turning to both classical AI and generative AI to rethink, reinvent, and remake the modern microchip.

In a groundbreaking development for quantum communication, researchers at Qunnect Inc. have successfully achieved the automated distribution of polarization-entangled photons over New York City’s existing fiber network.

The internet is currently controlled through searching, and if Google single-handedly dominates the means through which searching works, then Google effectively controls the internet.

View Details

Microsoft on Thursday disclosed four medium-severity security flaws in the open-source OpenVPN software that could be chained to achieve remote code execution (RCE) and local privilege escalation (LPE).

Cybersecurity researchers have discovered multiple critical flaws in Amazon Web Services (AWS) offerings that, if successfully exploited, could result in serious consequences.

As many as 10 security flaws have been uncovered in Google’s Quick Share data transfer utility for Android and Windows that could be assembled to trigger remote code execution (RCE) chain on systems that have the software installed.

SiFive has announced the launch of its latest core for datacenters, the P870-D, and claims it has a leg up on Arm’s Neoverse N2 in density for AI.

Unstoppable Domains (UD), a provider of Web3 domain names and digital identities, has been officially accredited by the Internet Corporation for Assigned Names and Numbers (ICANN).

CENTR, the association overseeing European country code top-level domain (ccTLD) registries, has announced the public release of its Domain Crawler Project code.

Remote SIM provisioning (RSP) for consumer devices is the protocol specified by the GSM Association for downloading SIM profiles into a secure element in a mobile device. The process is commonly known as eSIM, and it is expected to replace removable SIM cards.

The WhoisXML API research team analyzed more than 7.3 million domains registered between 1 and 31 July 2024 in this post to identify five of the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

Unit 42 monitors ransomware and extortion leak sites closely to keep tabs on threat activity. We reviewed compromise announcements from 53 dedicated leak sites in the first half of 2024 and found 1,762 new posts.

Cybersecurity researchers have disclosed a security flaw impacting Microsoft Azure Kubernetes Services that, if successfully exploited, could allow an attacker to escalate their privileges and access credentials for services used by the cluster.

To illustrate the complexity and severity of modern application attacks, let’s examine an attack against the infamous Log4Shell vulnerability (CVE-2021-44228) that sent shockwaves through the cybersecurity world in late 2021

When it comes to breach disclosures, today’s chief information security officers (CISOs) are struggling with an especially turbulent regulatory environment.

Data centers are part of the vital infrastructure behind consumer-facing services, and they now find themselves in the crosshairs. By weaponizing permitting and zoning laws, emissions and electricity regulations, and tax hikes, policymakers aim to sabotage operations altogether.

Inspired by recent presentations and discussions around Tetragon, we picked out the top security observability use cases – and what we find are extensive use cases deep across the security application landscape.

Over the past few years, TV makers have seen rising financial success from TV operating systems that can show viewers ads and analyze their responses.

View Details

Beware of Internet FORCES aiming to change your mind or direct your decisions! That acronym, coined by behavioral scientist Patrick Fagan, helps people know when they’re being “nudged.”

Enter your name into an internet search engine and the first few results will probably include detailed profiles of you compiled by “people-search” websites with names like Intelius, PeopleFinders, and Spokeo.

Following the July 19 outages caused by a bad update, the cybersecurity firm faces shareholder lawsuits and pressure to pay damages for at least one major customer, Delta Airlines. Will software liability follow?

Since 1998 — the last year Congress passed a major law to reform the tech industry and protect children in the virtual space — a lot has changed.

According to a damning report from 404 Media, backed with internal Slack chats, emails, and documents obtained by the outlet, Nvidia helped itself to “a human lifetime visual experience worth of training data per day,” Ming-Yu Liu, vice president of Research at Nvidia and a Cosmos project leader, admitted in a May email.

It has been an enduring fascination to see how we could use packet networking in the context of digital communications in space.

At a recent conference I attended, a speaker referenced media ecologist Neil Postman and his “rules” for evaluating the pros and cons of any given technological development.

In the 18th century, Wolfgang von Kempelen’s victorious mechanical Turk (1770) amazed the world, see Figs.1-4. However, there was a person hidden inside.

LibreQoS is an open source project and the subject of a popular recent APNIC Academy webinar. Responding to feedback given at the webinar, this post will look at the features of LibreQoS.

Huawei Cloud has developed a network monitoring tool that, when used in production on three of its own regions, was able to observe more of its infrastructure than existing tools, and revealed issues that previously evaded human efforts.

Decoupling authorization from your main application code makes authorization more scalable, easier to maintain, and simpler to integrate with your components. However, these benefits are difficult to realize if you don’t consciously plan for them within your authorization implementation.

In this episode of PING, Casper Schutijser and Ralph Koning from SIDN Labs in the Netherlands discuss their post-quantum testbed project.

View Details

Network observability tools provide information on the health and behavior of applications, offer insights into end-user experience, and detect anomalies that are indicative of security incidents.

Maestro is a general-purpose, horizontally scalable workflow orchestrator designed to manage large-scale workflows such as data pipelines and machine learning model training pipelines.

It might be time to get the pens and notebooks back out and shut off the keyboard for a while. Just pretend you’re back in the first grade and don’t have a minicomputer in your back pocket.

Intel has finally provided an update on instability issues on 13th-gen and 14th-gen CPUs. An update posted by Thomas Hannaford, Intel’s communications manager, pins the instability on an error in the microcode that requests incorrect voltage numbers, leading to instability in the processor.

Separation agreements Meta gave to employees during mass 2022 layoffs are illegal, a US judge has decided, and the reasoning could have implications far beyond Zuckercorp.

In 1940, thirteen percent of the U.S. population lived in suburbs. In 2010, it was half. An analysis by demographer Wendell Cox of population trends during the 2010s showed that 92 percent of all growth in major metropolitan areas was in the suburbs and exurbs ラ a trend that well preceded the pandemic.

Searchable Encryption has long been a mystery. An oxymoron. An unattainable dream of cybersecurity professionals everywhere.

Two US senators have urged the FTC to probe and potentially prosecute three automakers that allegedly unlawfully sold motorists’ personal data for pennies.

As the COVID-19 pandemic came to an end, a number of large companies pushed for their workers to return to the office five days a week — a policy that prompted many employees to “quiet quit” in protest.

At what was billed as a “fireside chat” at Tel Aviv University in June 2023, the very first question from the audience posed to OpenAI CEO Sam Altman and chief scientist Ilya Sutskever was, “Could open source LLMs (large language models) potentially match GPT-4’s abilities without additional technical advances, or is there a ‘secret sauce’ in GPT-4 unknown to the world that sets it apart from the other models?”

The blame game doesn’t stop there. One link in this chain of infamy hasn’t received the attention it deserves – but this link took what should have been a small hiccup and turned it into a global meltdown.

Now it seems that AI itself might be our best defense against AI fakery after an algorithm has identified telltale markers of AI videos with over 98% accuracy.

Rolls-Royce has cleared a key hurdle in the race to build Britain’s first mini-nuclear power plant as competition across Europe ramps up.

View Details

Recent events involving CrowdStrike’s Falcon security software have underscored a critical lesson across the industry: the importance of having a robust, secure release process.

My analysis of the event has a lot of similarities with my reflections on the Optus outage last year, the incident underscores the critical issue of resilience in IT infrastructure, particularly in systems that lack diversity.

But recovery is just the beginning. What’s sure to follow is a barrage of regulatory oversight, hard feelings among the IT community, and a tough reminder that even a small slip-up in a software update can have catastrophic global consequences.

Over the years, there has been a lot of discussion on if VLAN 1 in Cisco switches is special or not. Does it have any characteristics that other VLANs donメt?

Are you considering the switch from network engineer to cloud engineer? This post wo’t teach you everything needed to become a cloud expert, but hopefully, it will create a level of comfort and familiarity such that you can start your journey to the cloud from here.

The creation of voluntary standards is an idea that may seem easier than imposing regulations. But devising voluntary standards presents unique challenges, different from those which arise in devising standards which can be imposed on developers. The AI community should take note.

The landscape for digital rights has evolved rapidly over the last 15 years, and will only continue to shift and stratify more quickly in the years ahead. Iメll start with some horizon-scanning, though it is far from comprehensive.

Our research team analyzed more than 21.5 million domains registered between 1 April and 30 June 2024, as seen in the Newly Registered Domains (NRDs) Data Feed. We detected that the number of NRDs slightly increased compared with the previous quarter, at 2.6%.

The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could be exploited to trigger a denial-of-service (DoS) condition.

Analysys Mason, an industry consulting firm in the U.K. recently wrote an interesting report looking at long-term capex spending for the telecom industry. The prediction looks at both broadband and wireless spending.

View Details

On the other hand, these same minimal overheads imply that DNS over UDP cannot perform prompt detection of packet loss and cannot efficiently defend itself against various approaches to tampering with the DNS, such as source address spoofing, payload alteration and third-party packet injection. Perhaps most importantly, the way UDP handles large payloads is a problem.

User interface (UI) design is currently experiencing a transition from traditional graphical user interfaces (GUIs) to systems designed to recognize a personメs gestures and movements.

The U.S. Federal Trade Commission (FTC), along with two other international consumer protection networks, announced on Thursday the results of a study into the use of “dark patterns” — or manipulative design techniques — that can put users’ privacy at risk or push them to buy products or services or take other actions they otherwise wouldn’t have.

One of the most concerning aspects of social media is that much of its influence evades our notice. We don’t realize that we’re being influenced, or shaped to think a certain way, or view the world through a specific lens.

Chinese automobile conglomerate Geely has made significant strides since I last wrote about their Geesat LEO constellation for mobile vehicle connectivity.

Retail banking institutions in Singapore have three months to phase out the use of one-time passwords (OTPs) for authentication purposes when signing into online accounts to mitigate the risk of phishing attacks.

A threat actor that was previously observed using an open-source network mapping tool has greatly expanded their operations to infect over 1,500 victims.

With the first Zen 5 CPUs and SoCs set to ship later this month, AMD offered a closer look at the architectural improvements underpinning the platform’s 16 percent uplift in instructions per clock (IPC) during its Tech Day event in LA last week.

At least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week.

Everybody knows that companies, particularly hyperscalers and cloud builders but now increasingly enterprises hoping to leverage generative AI, are spending giant round bales of money on AI accelerators and related chips to create AI training and inference clusters.

Alphabet’s cloud computing division, Google Cloud, tried to sustain the European Union’s inquiry into Microsoft’s antitrust practices in the cloud computing sector by offering complainant Cloud Infrastructure Services Providers in Europe (CISPE) a package worth €470 million ($511 million), Bloomberg reported.

Just one problem: observability tools wonメt help us solve any of the problems above. Even real-user monitoring (RUM) wonメt give us the information we need.

View Details

The gang’s time from initial access to draining data out of a Veeam server is shockingly fast; after which the attackers went on to deploy actual ransomware in less than a day.

A critical security issue has been disclosed in the Exim mail transfer agent that could enable threat actors to deliver malicious attachments to target users’ inboxes.

The new fireball is the arrival of AI, its widespread acceptance and adoption, and the view that it is now a competitive imperative.

As a follow-up to the post yesterday on native VLANs, there was a question on what would happen to 802.1Q-tagged frames traversing an unmanaged switch.

State-controlled media on Tuesday covered the proceedings of the third China IPv6 Innovation and Development Conference, at which officials revealed that as of May 2024 the Middle Kingdom was home to 794 million users of the protocol, and that 64.56 percent of mobile traffic – plus 21.21 percent of fixed network traffic – is carried on networks that employ it.

In fact, since 2017, Google’s environmental reports show that the company’s electricity use, CO2 emissions, and carbon intensity have soared.

Using DevSecOps helps ensure the right level of security throughout both the development phase and the entire lifespan of the software.

While these tools and studies have merit, there is a need to understand what the developers want instead of what we think they want.

ORCA Computing engineers and builds quantum computers using the photonics quantum modality (i.e. photonic, or light based qubits), which operate at room temperature.

The power efficiency of a server fleet, that is, how much work servers perform for the energy they use, is influenced by multiple factors.

View Details

Anybody not involved in the telephone business will probably be surprised to find that the old TDM telephone networks are still very much alive and in place.

Intel has demonstrated an optical chiplet co-packaged with a CPU capable of supporting 4 Tbps data links to feed the increasing datacenter bandwidth requirements of AI and high performance computing (HPC) applications.

My one-liner for The AI Delusion is that the real danger today is not that computers are smarter than us but that we think computers are smarter than us and consequently trust them to make decisions they should not be trusted to make.

If the Senate passes an expansion of the Foreign Intelligence Surveillance Act, any Americanメs international communications could become an open book.

Anybody who builds fiber networks can describe the litany of state and local regulations involved in constructing fiber. Following are the primary kinds of such regulations ヨ and there are others in some places.

OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with root privileges in glibc-based Linux systems.

This only works for so long. Software can keep getting bigger and slower only for as long as computers keep getting faster, and the rate of improvement there has fallen off a cliff and shows no sign of recovery.

While data-driven insights propelled tech giants to unprecedented heights, they also led to privacy debacles. As a reaction, the last decade witnessed the emergence and strengthening of data protection regulations such as the General Data Protection Regulation (GDPR) in Europe and the California Consumer Privacy Act (CCPA) in California.

It is easy to overlook the role lithography plays in developing digital technologies. Every year, new and more advanced integrated circuits appear, pushing computing capabilities to more advanced levels.

While Broadcom claimed that many users would see their costs fall because of the changes in licensing, it was simultaneously telling its shareholders that the changes were expected to lead to double-digit revenue growth for its VMware portfolio throughout 2024.

View Details

Talking at Bernstein’s 40th Annual Strategic Decision Conference late last week, HP boss Enrique Lores acknowledged the pressures facing the print division, saying the number of printed pages has dropped by a fifth.

The petition makes three general arguments for issuing a pause on net neutrality, the first of which is that the FCC may not have the authority to reinstate net neutrality at all.

Each time someone interacts with a large language model (LLM), there is an energy cost in running the model for inference. In addition, there is an energy cost in the preparation and training of the model before it was brought to production.

On December 14, 2022, the European Parliament adopted the Directive on measures for a high common level of cybersecurity across the Union (Directive (EU) 2022/2555) hereinafter referred to as “NIS2”), which was published in the official journal on December 27, 2022

In my view, Thomas’ approach is inconsistent with the remainder of Article 28 and would not achieve the goals of NIS2 to improve cybersecurity across the EU member states.

This kind of marketing, historically, is quite effective – bigger numbers are easier for us customers to understand. But, as is the case with clock speeds and cores, it’s never as simple as the marketers make it sound.

And now that the OEMs are finally able to get some GPU allocations, they are beginning to drive sales, but they do not seem to be able to make money on this ridiculously expensive iron. Which is, well, ironic.

Dozens of policing agencies are currently using cell-site simulators (CSS) by Jacobs Technology and its Engineering Integration Group (EIG), according to newly-available documents on how that company provides CSS capabilities to local law enforcement.

TL;DR: AES-GCM is great, as long as every nonce (mnemonic: number used once) is truly unique. Once a nonce is reused, AES-GCM completely falls apart.

Topology Aware Routing is a feature of Kubernetes that prevents cluster traffic within one availability zone from crossing to another availability zone.

Our recent discovery in router firmware exposes a security flaw in routers’ Network Address Translation (NAT) mapping handling, which can be exploited by attackers to bypass TCP’s built-in randomization.

In a significant escalation against piracy, a French court has ordered Google, Cloudflare, and Cisco to tamper with their DNS resolvers to block access to approximately 117 pirate sports streaming domains.

View Details

The US Securities and Exchange Commission (SEC) wants to clarify guidelines for public companies regarding the disclosure of ransomware and other cybersecurity incidents.

Technical report 69, or TR-069, which defines how people’s broadband routers and other customer-premises equipment can be remotely provisioned and managed by ISPs automatically, is turning 20 years old.

Google and many other organizations, such as NIST, IETF, and NSA, believe that migrating to post-quantum cryptography is important due to the large risk posed by a cryptographically-relevant quantum computer (CRQC).

IPng’s network is built up in two main layers, (1) an MPLS transport layer, which is disconnected from the Internet, and (2) a VPP overlay, which carries the Internet.

Elon Musk doesn’t want you to share links from Substack, the blogging and newsletter platform that has grown in popularity over the last two years and serves as the primary mode of expression for independent Internet writers.

Quantum computers are probably coming, though we don’t know when—and when they arrive, they will, most likely, be able to break our standard public-key cryptography algorithms.

Domain name monitoring—that is, the detection of domains with names containing a brand-term (or other string) of interest—is a very well-established element of brand protection services.

To tackle these challenges, we developed ROuting SEcurity Tool (ROSE-T), the first open source tool to verify MANRS compliance automatically.

Today’s blog talks about a practice that doesn’t get discussed very often, which is the warehousing of spectrum. Warehousing is the practice where carriers sit on spectrum without using it or make only a minimal technical deployment to protect a spectrum license without actually using the spectrum as intended.

In this blog, we will analyze the modern practice of Phishing “Tests” as a cybersecurity control as it relates to industry-standard fire protection practices.

Recent research showed that 60% of participants fell victim to artificial intelligence (AI)-automated phishing, which is comparable to the success rates of non-AI-phishing messages created by human experts.

From a high level, optical interconnects perform the task their name implies: they deliver data from one place to another while keeping errors from creeping in during transmission. Another important task, however, is enabling data center operators to scale quickly and reliably.

This blog will provide an understanding of what AI jailbreaks are, why generative AI is susceptible to them, and how you can mitigate the risks and harms.

Experts on artificial intelligence raised concerns about the implications of AI’s rapid growth at a panel discussion in Washington, D.C. Tuesday.

View Details

In this episode of the RIPE Labs podcast, three Internet pioneers talk about how they helped grow the Internet out of its early infancy, back when its purpose – and much of the excitement around its development – lay in the promise of connecting researchers from around the world.

Meta, parent company of Facebook and Instagram, also now is in the AI-focused processor game. The company recently unveiled the next generation of custom-made chips to help power AI-driven rankings and recommendation ads on social media platforms.

Phishing threats have reached unprecedented levels of sophistication in the past year, driven by the proliferation of generative AI tools.

In recent news, more than 13,000 subdomains of brands were hijacked for a large spam campaign that “leverages the trust associated with these domains to circulate spam and malicious phishing emails by the millions each day, cunningly using their credibility and stolen resources to slip past security measures.”

Tenable Research has discovered a critical memory corruption vulnerability dubbed Linguistic Lumberjack in Fluent Bit, a core component in the monitoring infrastructure of many cloud services.

Pew Research Center conducted the analysis to examine how often online content that once existed becomes inaccessible. One part of the study looks at a representative sample of webpages that existed over the past decade to see how many are still accessible today.

As well as making EPP easier for registrars to use, such an API would help domain registries by increasing scalability and improving performance and security.

Three teams – in Boston, in China, and the Netherlands – have simultaneously announced that they’ve figured out ways to store entangled photons without breaking the entanglement, a critical step in building quantum repeaters, and, thus, scalable quantum networks.

Microsoft has a lot more than AI riding on Copilot+ PCs. Although AI is the current buzzword of the tech industry, Microsoft’s push into a new era of PCs has just as much to do with declining PC sales over the past several years, as well as Microsoft’s decade-long drive to get Windows on ARM working.

The IBM Power Virtual Server Private Cloud – announced Tuesday with little fanfare – is based on the IBM Power Virtual Servers Big Blue rents out in a manner that will be familiar to users of IaaS services.

We have a long-standing policy that when you redact text, the only way to do it securely is to use black bars. Sometimes, people like to be clever and try some other redaction techniques like blurring, swirling, or pixelation. But this is a mistake.

The relationship between shift length, fatigue and human error is well documented, but less clear is how the data center industry can define shifts that help minimize human error. The recommended best practices for other industries do not always translate into the data center world, where 24/7 service availability is the standard.

View Details

The European Union’s new Digital Markets Act (DMA) is a complex, many-legged beast, but at root, it is a regulation that aims to make it easier for the public to control the technology they use and rely on.

When optimizing the write performance of GreptimeDB v0.7, we discovered through flame graphs that the CPU time spent parsing Prometheus write requests accounted for about 12% of the total.

We think that waferscale computing is an interesting and even an inevitable concept for certain kinds of compute and memory. But inevitably, the work you need to do goes beyond what a single wafer’s worth of cores can deliver, and then you have the same old network issues.

Evidence is mounting that tech companies’ policies demanding staff return to the office are only serving to drive out the talent that became accustomed to remote work.

ZTDNS integrates the Windows DNS client and the Windows Filtering Platform (WFP) to enable this domain-name-based lockdown. First, Windows is provisioned with a set of DoH or DoT capable Protective DNS servers; these are expected to only resolve allowed domain names.

The use of Machine Learning and Deep Learning models allows us to understand the intention of the message, who is sending it, and if the sender is pretending to be someone they are not. It also allows us to learn what a legitimate message looks like and identify the parts of an email that indicate malicious intent, making it easier to predict those markers in the future.

That said, I have been running e-mail servers since well before Google existed as a company. I started off at M.C.G.V. Stack, the computer club of the University of Eindhoven, in 1995.

Alas, the feds did something you wouldn’t want your government to do. The Federal Trade Commission launched an investigation into MGM — the victim of the cyberattack — and demanded that MGM, which suffered an estimated $100 million loss from the hack, provide information about the breach.

If successful in the Google and Apple cases, the result will be far more clarity on non-priced harms and a much-needed update to how we evaluate consumer welfare in the digital age, all without throwing the baby out with the bathwater.

How do you profit off intelligence once it’s been commoditized? Will the AI transition let a thousand flowers bloom, or will the returns largely flow to a few tech behemoths and their infrastructure providers?

Broadcom has introduced a new series of 400G Ethernet adapters specifically tuned for resolving network bottlenecks when moving massive amounts of data around for AI processing.

Yes, this time is different. And the key difference is Joe Biden’s EPA. On May 9, that agency published a rule in the Federal Register that, if it survives legal challenges, will force the closure of every coal-fired power plant in America and prevent the construction of new baseload gas-fired plants. If the rule survives those challenges, it will strangle AI in the crib.

View Details

The FCC lawfully fined U.S. facilities-based wireless carriers nearly $200 million for selling highly intrusive location data about subscribers without their “opt-in” consent.

Geoff Huston explores the performance of the BBR and Cubic flow control algorithms on the Starlink network through comprehensive measurements.

An instruction set is a lingua franca between compilers and microarchitecture. As such, it has a lot in common with compiler intermediate languages, a subject on which Fred Chow has written an excellent overview

A new malware called Cuttlefish is targeting small office and home office (SOHO) routers with the goal of stealthily monitoring all traffic through the devices and gather authentication data from HTTP GET and POST requests.

But one need not know anything about aeronautics to understand that things are not going well for Boeing, and that the company’s approach is clearly broken. That much was made clear in a new Ars Technica piece from Eric Berger, walking readers through the race between Boeing and SpaceX to develop an astronaut capsule for space travel.

“Legal basis” requirements for data processing, justifying data processing activities and transfers, and adhering to data minimization principles began hitting organizations’ radars with the EU General Data Protection Regulation.

Given the fast-paced nature of AI evolution, we decided to circle back and see if there have been developments worth sharing since then. Eight months might seem short, but in the fast-growing world of AI, this period is an eternity.

Ransomware hit an all-time high last year, with more than 60 criminal gangs listing at least 4,500 victims – and these infections don’t show any signs of slowing.

Virtual private networking (VPN) companies market their services as a way to prevent anyone from snooping on your Internet usage. But new research suggests this is a dangerous assumption when connecting to a VPN via an untrusted network, because attackers on the same network could force a target’s traffic off of the protection provided by their VPN without triggering any alerts to the user.

But the insider history of Signal raises questions about the app’s origins and its relationship with government—in particular, with the American intelligence apparatus.

Distributed denial-of-service (DDoS) attacks continue to plague the Internet and pose a risk to the availability of critical digital systems that we increasingly depend on in our daily lives. Thijs van den Hout and his colleagues outline their contributions and lessons learned from 5 years of research on the topic of collaborative DDoS mitigation, as an improvement on the current strategies.

Cogent (CCOI) recently announced that it was offering secured notes for $206M. The unusual part is what it’s using as security: some of its IPv4 addresses and the leases on those IPv4 addresses.

View Details

Quantum sensing is poised to revolutionize virtually every aspect of our world. Quantum sensing’s distinctive ability to detect magnetic signatures is already aiding in navigation for countless fuel tankers worldwide, providing otherwise unachievable medical scans, and keeping all of our computer clocks in sync.

Surprisingly, most network attacks are not exceptionally sophisticated, technologically advanced, or reliant on zero-day tools that exploit edge-case vulnerabilities.

A growing number of data center operators and equipment vendors are anticipating the proliferation of direct liquid cooling systems (DLC) over the next few years. As far as projections go, Uptime Institute’s surveys agree: the industry consensus for the mainstream adoption of liquid-cooled IT converges on the latter half of the 2020s.

The recent discovery of a backdoor in XZ Utils (CVE-2024-3094), a data compression utility used by a wide array of various open-source, Linux-based computer applications, underscores the importance of open-source software security.

The IETF has had a long tradition of doing its technical work through a consensus process, taking into account the different views among IETF participants and coming to (at least rough) consensus on technical matters.

This is where Two-Factor Authentication (2FA) steps in as a powerful tool to bolster security. Let’s delve into the trends shaping the realm of 2FA and how they enhance digital security.

Global hybrid multi cloud applications (GHMAs) auto scale vertically and horizontally in response to spikes in request traffic and processing load. Auto scaling mechanisms for GHMAs are available on prem, in the public cloud, or in any combination globally.

IBM and Swiss startup LzLabs faced off in a London court on Monday in a dispute over the development of technology that allows the migration of mainframe applications to the cloud.

Zilog’s classic Z80 chip is soon to be dead, though it might not be gone forever if one open source project succeeds in its goal to clone the legendary processor.

The U.K. National Cyber Security Centre (NCSC) is calling on manufacturers of smart devices to comply with new legislation that prohibits them from using default passwords, effective April 29, 2024.

View Details

The Stanford Institute for Human-Centered Artificial Intelligence (HAI) has issued its seventh annual AI Index Report, which reports a thriving industry facing growing costs, regulations, and public concern.

At a time when no one expected progress on the U.S. federal privacy front, a new discussion draft for a comprehensive consumer privacy bill has emerged with bipartisan and bicameral support.

There is a new way for folks to track and spy on you. A recent article in the MIT Technology Review described how WiFi tracking has become a usable technology.

How would AI help produce victims? ‘Deep fake’ video technology. We previously saw, in ‘Human Impersonation AI Must be Outlawed,’ how extortion videos could target millions of individuals worldwide simultaneously every day.

A few weeks ago, I got a bit miffed reading yet another article that was too dismissive about memory safety, basically being mostly dismissive about the need for change.

Combined heat and power using waste heat recovery is a natural for AI/data centers deserves more consideration. We hope that we have lit that spark.

Larry Sanger remembers the promise of the web. He co-founded Wikipedia in 2001, with the hope that it could sustain a “free and open” Internet—a place where information, dissent, and creativity could thrive.

Everyone is in a big hurry to get the latest and greatest GPU accelerators to build generative AI platforms. Those who can’t get GPUs, or have custom devices that are better suited to their workloads than GPUs, deploy other kinds of accelerators.

To help both seasoned privacy practitioners and newcomers navigate this thicket, the IAPP has published a fully revised second edition of “Cybersecurity Law Fundamentals,” in which we distill the onslaught of laws, regulations, class-action lawsuits and enforcement actions. Here we summarize some of the trends we have noted.

Production of some models of Z80 processor – one of the chips that helped spark the personal computing boom of the 1980s – is set to end after an all-too-brief 48 years.

On the other hand, the media places less emphasis on negative news such as announcements that Amazon would abandon its cashier-less technology called “Just Walk Out,” because it wasn’t working properly.

And one of the key insights that the Meta AI research team had with the Llama family of models is that you want to optimize for the lowest cost, highest performance AI inference with any model and then deal with the inefficiencies that might result from AI training.

View Details

Huawei has released details of how it manages its own cloud with a dynamic traffic allocation system optimized by machine learning and developed in response to surging demand for its services during the COVID-19 pandemic.

A jury has ordered Amazon Web Services to pay $525 million for infringing distributed data storage patents in a case brought by a technology outfit called Kove IO.

The BBC has just shared another video from its archives, this one showing a report about computer addicts from way back in 1983, when computers were just starting to find their way into the workplace and home.

Microsoft is currently testing a new way to showcase ads on the Windows 11 Start Menu, and it’s meant to encourage users to download more applications.

Google announced on Wednesday it will invest $1 billion in two submarine cables to create new routes between the US and Japan.

While writing about Git, I’ve noticed that a lot of folks struggle with Git’s error messages. I’ve had many years to get used to these error messages so it took me a really long time to understand why folks were confused.

If the prognosticators at IDC are correct, four years from now as 2028 is coming to a close, the service providers as a group will comprise more than two thirds of server and storage revenues for that year.

Alibaba Cloud has detailed the telemetry tool it uses to look out for glitches in customers’ virtual networks, and revealed it’s reduced the number of personnel dedicated to troubleshooting by 86 percent since developing the system.

We know Google search results are being hammered by the proliferation of AI garbage, and the web giant’s attempts to curb the growth of machine-generated drivel haven’t helped all that much.

Information and decision-making power now flowed straight to the top. Decades later when the first crop was felled, vast fortunes were made, tree by standardized tree. The clear-felled forests were replanted, with hopes of extending the boom.

View Details

Future AMD processors could feature domain-specific accelerators – even some created by third parties, according to senior execs at the chip shop.

We tolerate such things even though we understand these practices usually harm those who willingly engage in them. Consider it one price we pay for relative freedom. But what should we do when these practices destroy the lives of innocent bystanders?

Thread hijacking attacks. They happen when someone you know has their email account compromised, and you are suddenly dropped into an existing conversation between the sender and someone else.

The first thing to note about the rumored “Stargate” system that Microsoft is planning to build to support the computational needs of its large language model partner, OpenAI, is that the people doing the talking – reportedly OpenAI chief executive officer Sam Altman – are talking about a datacenter, not a supercomputer

Now we’re going to go much deeper into the layers that relate to the PHY, which is PCS, PMA, and Autonegotiation. First though, let’s review the objectives of 1000BASE-T.

macOS has been gaining the unwanted attention of more and more backdoor operators since late 2023. In February 2024, Bitdefender uncovered RustDoor, which was written in Rust and possibly has ties to the operators of a Windows ransomware.

The PCIe 7.0 spec is on track for release next year and, for many AI chip peddlers trying to push the limits of network fabrics and accelerator meshes, it can’t come soon enough

In this article, we report on our longitudinal research study (between 2020 and 2023) of such dangling resource abuse. Across 12 cloud platforms, we identified 20,904 hijacks that hosted malicious content. We detected hijacked domains in 219 Top-Level Domains (TLDs) and abuses on popular clouds.

Three imminent improvements to the Ethernet standard will make it a better alternative to host AI workloads, and that will see vendors back the tech as an alternative to Nvidia’s InfiniBand kit, which is set to dominate for the next two years.

Cloud native architecture is a game changer for security at scale. Whether used on-premises or in the cloud, capabilities to ease the management of IT assets are improving. And while there’s a long way to go in simplifying interfaces and reducing skill-set barriers – this too will come in time.

It’s a tantalizing idea: that the same routers bringing you the internet could also detect your movements. “It’s like this North Star for everything ambient sensing,” says Sam Yang, who runs the health-sensor startup Xandar Kardian. For a while, he says, “investors just flocked in.”

Arista Networks has offered a look at how it expects to roll out Ethernet technology that will underpin the networks required to handle the demands of AI-based workloads.

View Details

Highway 9 Networks recently emerged from stealth mode with $25 million in seed funding and a vision to provide enterprise companies with SaaS-based private mobile networks that would eliminate gaps in coverage by incorporating cellular technology.

Hackers’ advantage: One of the biggest security weaknesses in U.S. digital networks and infrastructure is out-of-date, no-longer-supported technology.

Threat actors have been observed leveraging the QEMU open-source hardware emulator as tunneling software during a cyber attack targeting an unnamed “large company” to connect to their infrastructure.

There are some weighty ironies here. The AI “safety” experts had raised alarm about “implicit bias” in AI, only for Google to release an almost parodically racist chatbot.

Yet another DNS vulnerability has been exposed. The language of the press release revealing the vulnerability is certainly dramatic, with “devasting consequences” and the threat to “completely disable large parts of the worldwide Internet.”

It’s a good rule of nostril that if your litigation department is a source of revenue, your business model stinks.

In his January 12 SpaceX update, Elon Musk said the biggest goal for Starlink from a technical standpoint is to get the mean latency below 20 ms.

In a recent press release, John Deere announced an agreement with Starlink to provide broadband for smart farm equipment in areas where cellular coverage is not strong enough.

What is it that makes a PC an AI PC? Beyond some vague hand-waving at the presence “neural processing units” and other features only available on the latest-and-greatest silicon, no-one has come up with a definition beyond an attempt to market some FOMO.

DORA is a regulation that enhances the operational resilience of information and communication technology (ICT) and third-party providers the EU financial sector.

Authorities with the Los Angeles Police Department are warning residents in Los Angeles’ Wilshire-area neighborhoods of a series of burglaries involving wifi-jamming technology that can disarm surveillance cameras and alarms using a wireless signal.

Carmakers are offering all kinds of over-the-air subscriptions and features, many of which benefit the businesses that use them. But this also opens up a wider attack surface for vehicle attackers.

View Details

Of all the problems with electric cars, perhaps the least expected was the revelation that some home charging points provide a potential point of weakness for malign foreign powers to interfere with our National Grid.

More than 8,000 domains and 13,000 subdomains belonging to legitimate brands and institutions have been hijacked as part of a sophisticated distribution architecture for spam proliferation and click monetization.

MWC Qualcomm is going big on AI at MWC, where it’s showing off a 7 billion parameter large language model running on an Android phone, along with an online hub to help mobile devs blend models into their apps, and AI infused into its latest 5G modem and Wi-Fi 7 silicon.

In the first week of January, the pharmaceutical giant Merck quietly settled its years-long lawsuit over whether or not its property and casualty insurers would cover a $700 million claim filed after the devastating NotPetya cyberattack in 2017.

Law enforcement agencies shut down xDedic, a cybercrime-as-a-service (CaaS) marketplace specifically providing web servers to cybercriminals, back in 2019.

Use of the Rust programming language has been on the rise but is only expected to continue to gather steam as more security-focused organizations call for Rust developers — affectionately known as Rustaceans — to use more memory-safe languages.

If you live in the United States, the data broker Radaris likely knows a great deal about you, and they are happy to sell what they know to anyone.

This paper introduces Morris II, the first worm designed to target GenAI ecosystems through the use of adversarial self-replicating prompts.

On a recent Thursday afternoon, a Consumer Reports journalist received an email containing a grainy image of herself waving at a doorbell camera she’d set up at her back door.

Japan’s government has ordered local tech giants LINE and NAVER to disentangle their tech stacks, after a data breach saw over 510,000 users’ data exposed.

View Details

Exclusive Dell’s “return to office” mandate has left employees confused about which offices they can use and the future of their jobs – and concerned the initiative is a stealth layoff program that will disproportionately harm women at the IT giant.

FDC Pat Gelsinger wants to make Intel the world’s second largest chip manufacturer by 2030, and that means serving businesses the x86 giant has traditionally seen as competitors.

Intel revealed a new road map at its Intel Foundry Services (IFS) Direct event that will take the company into 2027. Itメs an extension of the road map Intel laid out nearly three years ago, shortly after Intelメs CEO Pat Gelsinger took the reins of the company.

It is not known who pilfered the information nor their motives, but this leak provides a first-of-its-kind look at the internal operations of a state-affiliated hacking contractor.

Apple has announced a new post-quantum cryptographic protocol called PQ3 that it said will be integrated into iMessage to secure the messaging platform against future attacks arising from the threat of a practical quantum computer.

Juniper Networks, currently in the process of being acquired by HPE, has been accused of violating US securities laws in a shareholder lawsuit.

In the labyrinth of IT systems, logging is a fundamental beacon guiding operational stability, troubleshooting, and security. In this quest, however, organizations often find themselves inundated with a deluge of logs.

You’d think that few types of software are as trustworthy as some of the best antivirus programs, but it turns out that perceptions can be deceiving. Avast, one of the most recognizable antivirus solutions for PCs, was found to be secretly collecting and selling user data to third-party corporations for a period of six years.

Just what “mal-information” means, apart from the other two concepts, remains unclear. Differences between the three terms seem to hinge on the presumed motives of (usually) unknown persons, so clear distinctions between them may not be conceptually useful. We could just as well call it all wrongthink.

This post will list some of the major decisions made and if I endorse them for your startup, or if I regret them and advise you to pick something else.

Databases play a strange role in software development. The vast majority of complex applications use one, but many developers don’t pay a lot of attention to it in their daily work.

DNS abuse is defined as being composed of five broad categories of harmful activity insofar as they intersect with the DNS — malware, botnets, phishing, pharming, and spam (when it serves as a delivery mechanism for the other forms of DNS abuse).

View Details

The European Court of Human Rights (ECHR) has ruled that laws requiring crippled encryption and extensive data retention violate the European Convention on Human Rights – a decision that may derail European data surveillance legislation known as Chat Control.

The Electric Power Research Institute (EPRI) says that “better than 80% of all electronic system failures that are attributed to power anomalies are actually the result of electrical wiring or grounding errors or are generated by other loads within the customer’s facility.”

With research making considerable progress in designing quantum computers, it is time to consider the scenario that usable quantum computing will become a reality in the future. In this post, we discuss the testbed that we are setting up to empirically evaluate the impact of quantum-safe cryptography algorithms on DNSSEC.

Late last year, Congress extended Section 702 of the Foreign Intelligence Surveillance Act (FISA) and, in doing so, secured the nation’s warrantless surveillance powers until April 2024. With that month fast approaching, House Republicans have unveiled a new package to reauthorize those same powers, within limits.

Google has announced that it’s open-sourcing Magika, an artificial intelligence (AI)-powered tool to identify file types, to help defenders accurately detect binary and textual file types.

The justification for HPE buying Juniper may be a mundane, economy-of-scale play or a move to gain Juniper’s AI networking technology. Or there may be a vision for something more ambitious.

The Russian launch of a satellite, with nuclear power and the likely ability to disable satellites, underscores how satellites are quite vulnerable to both natural and manmade ruin.

The Australian Square Kilometre Array Pathfinder (ASKAP) – a precursor project for the full Square Kilometre Array – has started work on techniques to help it cope with increased satellite traffic.

Russia, China and other U.S. adversaries are using the newest wave of artificial intelligence tools to improve their hacking abilities and find new targets for online espionage, according to a report Wednesday from Microsoft and its close business partner OpenAI.

The Domain Name System (DNS) is an essential protocol in the architecture of todayメs Internet. It routinely translates domain names into IP addresses and also often handles a multitude of invalid queries.

Lumen Technologies in the last year has doubled down on enterprise, launching its first network-as-a-service offering, the ExaSwitch interconnection platform, among other services.

Cybersecurity researchers have identified two authentication bypass flaws in open-source Wi-Fi software found in Android, Linux, and ChromeOS devices that could trick users into joining a malicious clone of a legitimate network or allow an attacker to join a trusted network without a password.

View Details

This year, I’ve had the opportunity to work alongside some of the highest- performing individuals in our profession. I’ve taken that opportunity to observe their work, look for patterns, and to try to identify the attributes that contribute to their success, not only as technologists but as humans.

OpenAI CEO Sam Altman’s dream of establishing a network of chip factories to fuel the growth of AI may be much, much wilder than feared.

Advanced persistent threat (APT) groups are more dangerous than your run-of-the-mill cybercriminals. They, after all, trail their sights not only on financial gain but loftier targets such as wreaking havoc on entire nations.

In this episode of PING, APNIC’s Chief Scientist Geoff Huston discusses the role of the Domain Name System (DNS) in directing where your applications connect to, and where content comes from.

As you awoke one morning from uneasy dreams you found yourself transformed in your bed into a software engineer. A calamity that I find all too familiar.

Whether you want to land a new job or make your contributions count, effective communication goes a long way.

At the beginning of the year, I wrote a bit about the resolution to “stay human” in 2024, in a world that is calling for artificial intelligence to be incorporated into more spheres of life, including law, automated driving, entertainment, and even relationships.

As with many other web3 evangelists, Andreessen Horowitz general partner Chris Dixon has identified some problems with the web.

In this article, we will conduct an in-depth exploration of an impactful vulnerability affecting various container runtimes.

In the February 13th edition of the Wall Street Journal, Professor Thomas W. Hazlett offers a breathless endorsement of market concentration with the T-Mobile acquisition of Sprint, his go-to example.

View Details

Artificial intelligence and the chips that fuel its evolution have given rise to a new arms race between the US and China.

Alongside concerning recent security news, there has been a media-wide rise of references to ‘credential stuffing’. This is a term that doesn’t convey very much, but as it’s the accepted term inside the infosec community, it’s probably here to stay.

In October, the Consumer Financial Protection Bureau (CFPB) proposed a set of rules that if implemented would transform how financial institutions handle personal data about their customers.

In a far cry from the early 2000s, most U.S. adults today say they use the internet (95%), have a smartphone (90%) or subscribe to high-speed internet at home (80%), according to a Pew Research Center survey conducted May 19 to Sept. 5, 2023.

Cloudflare was a victim of the wide-ranging Okta supply-chain campaign last fall, with a data breach impacting its Atlassian Bitbucket, Confluence, and Jira platforms beginning on Thanksgiving Day.

Honeypots are usually used as an intrusion detection tool. Many security researchers, including Computer Security Incident Response Teams (CSIRTS), deploy honeypots, to learn about tools, tactics, and the attacker’s infrastructure.

AWS could rake in between $400 million and $1 billion a year from charging customers for public IPv4 addresses while migration to IPv6 remains slow.

Sustainability efforts and high-density AI-based applications are sparking new and revamped approaches to data center cooling.

In what is sure to have significant implications for millions of American workers, specifically gig economy workers and contractors, the Department of Labor (DOL) issued its long-awaited final worker classification rule in January.

This week the streets are filling up with futuristic flies. In the old days we killed them with pesticides, and now we pay over $3,500 to become one of them.

But cracking BitLocker? We doubt the company will be bragging too much about that particular application.

Apple has just released Vision Pro, a virtual-reality headset that ushers in a new era of spatial computing. It claims to blend the real and digital worlds, so users can interact in both simultaneously.

View Details

Everybody likes good news, especially at the beginning of the corporate year, and we are happy to report that TSMC’s revenues in the fourth quarter ended in December 2023 were only down 1.5 percent year on year to $19.62 billion, and were up 13.6 sequentially from the third quarter

HP CEO Enrique Lores admitted this week that the company’s long-term objective is “to make printing a subscription” when he was questioned about the company’s approach to third-party replacement ink suppliers.

The Internet Corporation for Assigned Names and Numbers (ICANN) has proposed creating a new top-level domain (TLD) and never allowing it to be delegated in the global domain name system (DNS) root.

What is cool about DNS over HTTPS is that, well, it uses HTTPS. Because HTTP clients are plentiful and well understood by many developers, it should make for a pretty simple implementation.

However, VPN is no longer good enough to secure remote work. For instance, VPN gives remote employees full network access to corporate resources when they login.

Universally, every person that I put the question to dismissed FWA wireless as a temporary technology with no real long-term legs.

Apple launched the original 128 kB Macintosh around 40 years ago, and in so doing changed the computer industry, in ways that a lot of people still don’t fully understand.

Europe’s aviation safety body is working with the airline industry to counter a danger posed by interference with GPS signals – now seen as a growing threat to the safety of air travel.

And as the wheels come off Moore’s law, and generational process improvements become less impactful, several emerging technologies to boost performance and density are taking precedence.

As the fields of cryptography and cybersecurity advance, homomorphic encryption stands out as a groundbreaking technology.

View Details

A study by Consumer Reports and non-profit The Markup concluded that for the average lone Facebook user, 2,230 companies, and in some cases more than 7,000, will hand over that person’s information to Facebook.

2023’s copious chatter about generative AI has not translated into surging semiconductor revenues across the industry, according to analyst firm Gartner.

According to a report by industry analyst Trendforce, the tech company will up the base memory requirement on Windows 12 to 16GB in accordance with its standard for running its AI assistant Copilot at minimum efficiency.

Imagine downloading an open weights AI language model, and all seems good at first, but it later turns malicious.

The supermassive leak contains data from numerous previous breaches, comprising an astounding 12 terabytes of information, spanning over a mind-boggling 26 billion records.

In order for CPU and AI Accelerators/GPUs to effectively work with each other for larger training models, the communication bandwidth of the PCIe-based interconnects between them needs to scale to keep up with the exponentially increasing size of parameters and data sets used in AI models.

It was one thing to support cell towers when they were used for rural cellphone coverage. But it’s a new equation to be asked to provide faster bandwidth to an ISP that will use the bandwidth to win over local customers.

Surveillance doorbell maker Amazon Ring on Wednesday announced it is discontinuing an option that allowed law enforcement agencies to request video footage without a warrant.

Jay Fink had an interesting little business. If you lived in California, you could give him access to your email account; he’d look through the spam folder for spam that appeared to violate the state anti-spam law and give you a spreadsheet and a file of PDFs.

It is not uncommon these days for threat actors to use malicious search ads to distribute malware. To do that, though, they would need to know how to bypass Google’s security measures by setting up decoy infrastructures.

DDoS attack trends for the second half of 2023 reveal alarming developments in the scale and sophistication of cyberthreats.

Quantum technologies promise all kinds of fascinating possibilities, but they also come with risks. In this episode, André Grilo, founder and CEO of QuantumNova, talks about why we need to start investing in post-quantum cryptography to protect ourselves against post-quantum threats.

View Details

Pressure to resolve incidents quickly that often comes from peers, leadership, and members of affected teams only adds to the chaos of incident management, causing more human errors. Coordinating incidents such as this through the process of having an Incident Commander role has shown more controllable outcomes for organizations around the world.

The Kimsuky Group, believed to be a North Korea-based advanced persistent threat (APT) group active since 2013, struck again several times this year.

QUIC supports connection migration, allowing the client to migrate an established QUIC connection from one path to the other. QUIC’s path validation mechanism can be used to attack the peer and make it consume an unbounded amount of memory.

The NVM Express consortium has updated its specifications by adding a Computational Storage Feature, creating a standardized way for applications to talk to storage devices that include some processing capability.

Post Office chief exec Nick Read left British politicians shocked with his evidence before a Parliamentary committee yesterday after he admitted he could not say when the public body at the center of the historic miscarriage of justice knew when its system was at fault.

We’re only a few weeks into 2024, and violations of people’s privacy are already making some big headlines! First we had the continued drama with the 23andMe data breach; then a major financial software company was shut down for inappropriately using private information; and then this week, the FTC took an unprecedented step and banned a data broker from selling people’s location data.

The new domain name registration volume rose 10.24% from the third to the fourth quarter of 2023. WhoisXML API researchers uncovered this finding, along with other DNS trends, after analyzing more than 31 million newly registered domains (NRDs) added from 1 October to 31 December 2023 as seen in the Newly Registered Domains Data Feed.

Here is how you know that the way chiplets are linked together to create what might have otherwise been a monolithic device is now more important than the way that the chiplets themselves are designed.

Leichtman Research Group, Inc. (LRG) conducted its annual survey on household broadband usage and found that 90% of U.S. homes now have broadband.

Two weeks before Apple launched the Macintosh, Sir Clive Sinclair launched his unprecedentedly powerful yet affordable Motorola-powered SOHO computer – starting a line of hardware and software that, remarkably, is still going.

Even though it could take significantly longer for quantum computers to become sufficiently powerful to threaten current cryptography, we have to be prepared for a worst-case scenario. In the context of DNS, DNSSEC may no longer guarantee authentication and integrity when powerful quantum computers become available.

Verizon filed an SEC form 8K today, indicating that it would take a $5.8 billion impairment charge in its Verizon Business wireline group in the fourth quarter of 2023.

View Details

Yes, the weekend has pretty much already passed, but still …

The WailingCrab malware has gained notoriety for its stealth. IBM X-Force security researchers recently published an in-depth analysis of the malware, which has been abusing Internet of Things (IoT) messaging protocol MQTT.

SpaceX successfully launched 21 satellites, including the first six Starlink satellites equipped with “Direct to Cell” capabilities.

MTL mode is a technique developed by Verisign researchers that can reduce the operational impact of a signature scheme when authenticating an evolving series of messages.

While Kubernetes adoption continues to soar, it has become a prime target for cyberattacks. Unfortunately, Kubernetes clusters are complex and can be difficult to secure. Safeguarding your Kubernetes environment requires a solid understanding of the common attack chains that pose a threat to your infrastructure.

Going into 2023, the big telcos had publicly announced plans to build 9.4 million fiber passings, but during the year, they collectively pared that back expectations to 6.5 million passings.

A new exploitation technique called Simple Mail Transfer Protocol (SMTP) smuggling can be weaponized by threat actors to send spoofed emails with fake sender addresses while bypassing security measures.

The Atomic Stealer, also known as “AMOS,” first emerged in September this year by spreading on Macs disguised as popular applications. This time around, it has been wreaking more havoc in the guise of a fake browser update dubbed “ClearFake.”

On December 27, The New York Times Company sued Microsoft and OpenAI for violations of their copyright. The Times contends that training chatbots on its content in order to create an information competitor is a violation of its copyright.

Since 2014, more than 800 new domain extensions have been added to the internet. In addition to the ubiquitous .com and country-code extensions such as the United Kingdom’s .uk and Japan’s .jp, unique spaces have been created for industry sectors, special interests, geographical regions and more.

Often the lifestyle entrepreneur builds his brand around projecting success; in fact, his real-life success rests partly on how well he can project it. As seen with founders such as Elizabeth Holmes of Theranos, the ability to attract investors rests on a cult of exclusivity and buzz around a brand’s value.

ChatGPT, the large language model developed by OpenAI, might seem like it generates novel content, but of course we know that it partakes in what’s generally called “scraping.” It takes pre-existing material on the Internet in response to the prompt a human user inserts.

This case had a bit of a weird result—even though the brand owner had a mark that was 20 years old, and the alleged cybersquatter, in the meantime, acquired a domain name on the open market identical to that mark, because the domain name was first registered (by an unrelated party) before the brand owner’s trademark rights arose, there was no relief under federal trademark law.

View Details

Thanks to Mark Prosser for a few links to add to the pile this week.

There’s a rumor flying around the Internet that OpenAI is training foundation models on your Dropbox documents.

Microsoft found that a popular form of video-based training reduces phish-clicking behavior by about 3%, at best. This number has been stable over the years, says Microsoft, while phishing attacks are increasing yearly.

The Internet Architecture Board (IAB) has warned that policy proposals requiring or enabling the automated scouring of people’s devices for illegal material – as floated by the European Union, the United Kingdom, and the United States – threaten the open internet.

Another update of the Ultimate PCAP is available. Again, there are some special new packets in there which I want to point out here. Feel free to download the newest version to examine those new protocols and packets by yourself. Featuring: SNMPv3, WoL, IPMI, HSRP, Zabbix, Pile of Poo, and Packet Comments.

The Genesis Market began operating in 2017, four years after Silk Road closed shop. Like its predecessor, though, the Federal Bureau of Investigation (FBI) and other law enforcement agencies took the Genesis Market down last April.

Miyake events are believed to be several orders of magnitude greater than the Carrington Event. It is not clear what causes the event.

The classical definition of a robot is something that senses, thinks, and actsラthatメs todayメs Internet. Weメve been building a world-sized robot without even realizing it.

The average cost of data breaches has been rising almost steadily since 2017. In 2017, the average cost was “merely” $3.62M. In 2023, it reached an all-time high of $4.45M in 2023. In the past three years, average breach costs increased by 15%.

Lars-Johan Liman, Netnod’s DNS nestor, makes a few personal reflections on the 20th anniversary of Netnod’s deployment of anycast – a technology that is a crucial part of the infrastructure of Netnod’s modern DNS services.

You know those little jokes that centre around a person with a PhD being on a plane, and someone asks for a doctor, and they say they aren’t that kind of doctor but the emergency involves their field of study?

The dark forest theory of the web points to the increasingly life-like but life-less state of being online.Dark Forest Theory of the Internet by Yancey Strickler Most open and publicly available spaces on the web are overrun with bots, advertisers, trolls, data scrapers, clickbait, keyword-stuffing “content creators,” and algorithmically manipulated junk.

After a decade or so of the general sentiment being in favor of the internet and social media as a way to enable more speech and improve the marketplace of ideas, in the last few years the view has shifted dramatically—now it seems that almost no one is happy.

When I first fell in love with the web, it was a radically different place. Aside from the many technical improvements that have been made, I feel like the general culture of the web has changed a lot as well.

And everyone is talking—correctly or not—in the language of therapy, peppering conversations with references to gaslighting, toxic people, and boundaries.

View Details

NTT Data has opened a hotel at which it plans to watch people sleep, as part of a plan to gather – and of course sell – data about the snoozing habits of ten million people.

Business and technical leaders should prepare to focus on memory safety in software development, the US Cybersecurity and Infrastructure Agency (CISA) urged on Wednesday.

A proposed fork of the OpenPGP standard, called “LibrePGP” and initiated by GnuPG’s maintainer Werner Koch, has made a series of statements on its own website1 in order to justify its existence.

Cisco has quietly introduced changes to the licensing model for its Catalyst range, and will bring it to more products over time.

ICANN’s response to the European Union’s Network and Information Security Directive (NIS2) is a litmus test on whether its policy processes can address the needs of all stakeholders, instead of only satisfying the needs of the domain industry.

One of the joys of operational privacy professionals is getting that random, Friday afternoon Slack from someone on the product team asking, “Can we [insert questionable action] with our customer data?”

Lackluster security controls in one of Google’s cloud services for data scientists could allow hackers to create applications, execute operations, and access data in Internet-facing environments.

The incident response process can be a maze that security professionals must quickly learn to navigate—which is no easy task. Surprisingly, many organizations still lack a coordinated incident response plan, and even fewer consistently apply it.

The suitability of a data center environment is primarily judged by its effect on the long-term health of IT hardware.

Most of the tech gifted this holiday will end up in a landfill. But Keegan McNamara makes laptops you can pass on to your grandchildren.

This blog acts as a quick guide on network penetration testing, explaining what it is, debunking common myths and reimagining its role in today’s security landscape.

A years-old Bluetooth authentication bypass vulnerability allows miscreants to connect to Apple, Android and Linux devices and inject keystrokes to run arbitrary commands, according to a software engineer at drone technology firm SkySafe.

View Details

Google has revealed a new multilingual text vectorizer called RETVec (short for Resilient and Efficient Text Vectorizer) to help detect potentially harmful content such as spam and malicious emails in Gmail.

Carding has been around since the 1980s but has evolved to the point that even less experienced cybercriminals can now launch campaigns.

Enter Cilium’s advanced Border Gateway Protocol (BGP) implementation, powered by the GoBGP control plane, a solution that not only addresses these challenges but also adds unprecedented flexibility to your network configurations.

The most curious part of this is how people working inside the macroculture are the only folks who don’t understand what’s going on.

Efforts to convince remote workers to return to corporate offices appear to have stalled, based on data from the government, academia, and private-sector organizations.

Once in your home, different individuals have differing authority based on who they are. Family members have access to your whole home.

HP is squeezing more margin out of print customers, the result of a multi-year strategy to convert unprofitable business into something more lucrative, and says its subscription model is “locking” in people.

Microsoft helped Chinese state-run media outlets disseminate propaganda as part of previously unreported partnership agreements, documents obtained by the Washington Free Beacon show.

Unfortunately, leadership training, education, and discussion tends to be reserved for people-managers. Of course, leadership skills are important for those directly responsible for teams of people.

Spying and surveillance are different but related things. If I hired a private detective to spy on you, that detective could hide a bug in your home or car, tap your phone, and listen to what you said.

The European Union’s Network and Information Security Directive (NIS1), introduced in 2016, aimed to strengthen cybersecurity among Member States. However, market fragmentation and growing digital threats led to the enactment of the NIS2 Directive.

Attackers could soon begin using malicious instructions hidden in strategically placed images and audio clips online to manipulate responses to user prompts from large language models (LLMs) behind AI chatbots such as ChatGPT.

View Details

Yet despite the constant accretion of new tools to solve new problems, the most common root cause of serious cybersecurity incidents remains failed processes.

The House of Representatives’ failure to spike a federal “kill switch” mandate means that outside of a political miracle, all new vehicles from 2026 onward will be required to incorporate “advanced drunk and impaired driving prevention technology.”

Gone are the days when a car was a dumb machine you turned on and drove from A to B. Today it’s a smartphone on wheels, and your data is possibly being taken for a ride.

APT29, believed to be an espionage group from Russia, became known for launching targeted attacks against organizations in Ukraine.

Mozilla has slapped its “Privacy Not Included” labels on several products from Google, Amazon and Microsoft – just in time for Christmas shopping.

Despite more than a decade of reminding, prodding, and downright nagging, a surprising number of developers still can’t bring themselves to keep their code free of credentials that provide the keys to their kingdoms to anyone who takes the time to look for them.

Special report Web advert blockers and other Chrome extensions will stop working by June 2024 unless they’ve been revamped to keep up with Google’s changes to its ubiquitous browser.

The Federal Bureau of Investigation (FBI) shut down BreachForums, a forum for English-speaking black hat hackers, on 21 March 2023, following the arrest of its owner Conor Brian Fitzpatrick.

A new study has demonstrated that it’s possible for passive network attackers to obtain private RSA host keys from a vulnerable SSH server by observing when naturally occurring computational faults that occur while the connection is being established.

This post covers an interesting case of suspected abuse in a generic Top-Level Domain (gTLD) registry between February and April 2023. It is a good example of an edge case, where the decision on whether or not to mitigate was not clear-cut, and different levels of evidence were available at different times.

For example, one thing to ask is: to what extent is the Internet resilient to this kind of event? In earlier analyses, to the extent we’ve been able to measure it, the answer has largely been: very. So let’s take a look at whether the same holds this time around.

Is a public cloud like AWS or Microsoft’s Azure the right place to host every deployment workload at every stage of its life? To be honest, I once thought that that was true – at least 95% of the time.

View Details

Bad queries tend to propagate to the root zone due to the hierarchical nature of DNS, so studying traffic at a root server can provide key insights into overall network usage.

This blog covers an interesting case of suspected abuse in a gTLD registry between February and April 2023.

YouTube wants its pound of flesh. Disable your ad blocker or pay for Premium, warns a new message being shown to an unsuspecting test audience, with the barely hidden subtext of “you freeloading scum.”

The shift towards chiplet architecture is inevitable for almost all high-end CPUs/GPUs, accelerators, and networking silicon vendors. It is not a question of ‘if’ but ‘when’.

The Global Coalition on Telecommunications (GCOT) purports to be about synching up how the five countries approach telecoms. The scope of corporation includes information sharing, joint R&D, funding alignment, the development of standards, skills, supply chain diversification, security, and 6G, so says the release.

Securing mainframes remains top of mind, with 61% of mainframe and IT professionals ranking security as the top problem they are facing, according to BMC’s annual survey of mainframe users for 2023.

Gartner has raised the specter of departments outside of tech running their own IT functions under the guise of low-code and digital democratization.

Though it’s tasked with regulating the information technologies of the future, the Federal Communications Commission remains stuck in the past.

Cybercriminals are leveraging the growing popularity of artificial intelligence to perpetrate attacks, capitalizing on the surge in interest following the release of chatbot technologies like ChatGPT.

In response to five class-action lawsuits, a Washington appeals court has decided that Honda and several other automakers did nothing wrong by storing text messages and call records from connected smartphones.

Even as the notoriously risk-averse Food and Drug Administration embraces artificial intelligence, however, another federal regulatory agency—the Securities Exchange Commission—has cracked down on AI.

Tracked as CVE-2023-23583 (CVSS score: 8.8), the issue has the potential to “allow escalation of privilege and/or information disclosure and/or denial of service via local access.”

View Details

With security, the battle between good and evil is always a swinging pendulum. Traditionally, the shrewdness of the attack has depended on the skill of the attacker and the sophistication of the arsenal.

While cyberattacks on websites receive much attention, there are often unaddressed risks that can lead to businesses facing lawsuits and privacy violations even in the absence of hacking incidents.

A new login technique is becoming available in 2023: the passkey. The passkey promises to solve phishing and prevent password reuse.

Security researchers have discovered what they believe may be a government attempt to covertly wiretap an instant messaging service in Germany — an attempt that was blown because the potential intercepting authorities failed to reissue a TLS certificate.

Artists suing generative artificial intelligence art generators have hit a stumbling block in a first-of-its-kind lawsuit over the uncompensated and unauthorized use of billions of images downloaded from the internet to train AI systems, with a federal judge’s dismissal of most claims.

Professional artists and photographers annoyed at generative AI firms using their work to train their technology may soon have an effective way to respond that doesn’t involve going to the courts.

Intel is shedding its silicon photonics transceiver module business as part of restructuring and cost-cutting measures, offloading it to manufacturing company Jabil.

Domain Name System (DNS) abuse stands has proven a constant in the internet threat landscape, posing risk to the overall digital trust.

SpaceX is equipping its new satellites with inter-satellite laser links (ISLLs). They now have over 8,000 optical terminals in orbit (3 per satellite) and they communicate at up to 100 Gbps.

View Details

Passkeys are appearing more and more in tech news, with support for them increasing. Since many administrators test out new technologies themselves first, we at CIS embarked on a short project to see what happened when an intern with our CTO team had the opportunity to implement passkeys.

Draft proposals setting a “remuneration obligation” for digital platforms started to pop up in the Brazilian congress after Australia adopted its own News Media Bargaining Code.

And can companies finally trust their data to cloud providers and actually trust that CC removes the need to worry about the cloud provider as a sub-processor with access to the data?

Google says it plans to prototype a technique to mask IP addresses via network proxies in future versions of its Chrome browser, a privacy protection similar to Apple’s iCloud Private Relay service for its Safari browser.

The cryptanalytic threat of quantum computing, particularly the “store data; decrypt later” approach, is drawing ever nearer. Unsurprisingly, the U.S. government is among those most alert to the danger.

A common critique of HTTP/3 and QUIC is that they primarily benefit the big players and companies (for example, Google and Meta), who often control one or even two of the endpoints (for example, Google controls popular services such as YouTube and search, as well as Chrome, the most used web browser)

Rhysida, a new ransomware currently plaguing users, may not be novel but it’s proving to be just as effective.

With the rise of generative AI, the computing industry now faces a significant challenge: to evolve our underlying building blocks to meet the increasing infrastructure demands.

A phishing campaign is currently targeting Facebook business accounts with password-stealing malware.

The US Immigration and Customs Enforcement (ICE) has used an AI-powered data-scanning tool called Giant Oak Search Technology (GOST) to scour social media looking for post containing “derogatory” comments about the nation.

View Details

When we were not looking – and forcing ourselves to not look at any IT news because we have other things going on – that is the moment when Nvidia decides to put out a financial presentation that embeds a new product roadmap within it.

SiFive today launched a pair of RISC-V CPU cores aimed at high-performance and AI/ML applications.

LPO is short for Linear Pluggable Optics (or Linear-drive Pluggable Optics), it is a potential technology to satisfy the low power consumption and high bandwidth demand of data centers like CPO (Co-packaged Optics).

One colocation provider has come up with a unique solution: It’s building small nuclear power plants for itself.

That’s no longer the case, however, as its latest variant, encased in compromised OfficeNote installation packages (currently in beta mode), can cause damage to any macOS devices.

In an era where every click, tap or keystroke leaves a digital trail, Americans remain uneasy and uncertain about their personal data and feel they have little control over how it’s used.

An investigation from the Wall Street Journal identified a company called Near Intelligence that purchased data about individuals and their devices from brokers who usually sell to advertisers. The company had contracts with government contractors that passed this data along to federal military and intelligence agencies.

The UK’s competition regulator is drafting remedies that could have big implications for Microsoft and AWS, should behavior that prevents or restricts customers from switching and using multi-clouds be identified.

View Details

Imagine a future in which AIs automatically interpret—and enforce—laws.

Using the proposed “Web Environment Integrity” means websites can select on which devices (browsers) they wish to be displayed, and can refuse service to other devices. It binds client side software to a website, creating a silo’d app.

When Alexa wouldn’t respond to his commands, he called the Amazon help desk to see what the issue was. Evidently, the company locked him out because of his apparent racism: “I was told that the driver who had delivered my package reported receiving racist remarks from my ‘Ring doorbell’ (it’s actually a Eufy, but I’ll let it slide).” Later, without any explanation or apology, Amazon allowed Jackson access again.

According to Harari, “AI has all it needs in order to cocoon us in a Matrix-like world of illusions,” and, even more chillingly, “you don’t really need to implant chips in people’s brains in order to control them or to manipulate them.”

Yet given how most of the internet is currently structured, our online expression largely depends on a set of private companies ranging from our direct Internet service providers and platforms, to upstream ISPs (sometimes called Tier 2 and 3), all the way up to Tier 1 ISPs (or the Internet backbone) that have no direct relationships with most users.

In the past decade, China was a black sheep when it came to social media. Whatever the new app was, odds were it was banned in China. X/Twitter? Banned. Facebook? Banned. Instagram? Banned.

You can see it in the discourse surrounding artificial intelligence (AI) over the last year: AI is going to change everything. Some think it’s going to do this for the better. Others think it’s a technological handmaiden for world destruction if its programming goes awry — or worse: AI becomes self-determining and sentient.

ChatGPT, the famous friend of students, is a good starting point if for no other reason than we’ve heard of it. One engineering prof estimates it can take up to 10 Gigawatt hours (GWh) to train the latest iteration of ChatGPT.

View Details

Dereferencing null pointers is one of the most common software errors. It is so infamous that Tony Hoare called the invention of null pointers his billion-dollar mistake.

To detect DDoS attacks in a telecommunications network we need to see the traffic that traverses the network, and we have multiple protocols for that purpose.

A recent trend in cloud-native development is the use of multi-architecture infrastructures, which can run workloads on either x86 or Arm architectures.

On 28 Aug., the California Privacy Protection Agency released its initial draft regulations for cybersecurity audits and risk assessments.

The Sun is about to turn upside down – magnetically speaking, of course.

Telecoms giant Vodafone is backing more than one horse in the OpenRAN arena, confirming a collaboration with Arm on energy efficient silicon for 5G base stations and continuing to work with Intel on OpenRAN silicon.

However, DNSSEC can cause problems when combined with a widely used method for synchronising secondary DNS servers with their primaries, Incremental Zone Transfer (IXFR).

Antitrust cases like the FTC’s hinge on “threshold” issues, fundamental elements that must be proven for a case to proceed. Here, those issues are threefold: market definition, documentary evidence, and the validity of the FTC’s legal theories.

While it is still somewhat early days to definitively answer this question, given most (public) comparisons between HTTP/2 and HTTP/3 are based on lab testing instead of real-world deployments, we have some data points that can shed some light.

If you work in academia — in network design, operations, security or forensics, or as an academic — we’ll need to talk. It’s about your students, and what they get up to online when you don’t watch.

View Details

Google has rolled out “Privacy Sandbox,” a Chrome feature first announced back in 2019 that, among other things, exchanges third-party cookies—the most common form of tracking technology—for what the company is now calling “Topics.”

By virtue of engineering pushing the acceptable boundaries of a system, failures occur. This is inevitable, and that’s also the joy and perils of engineering — discovering the acceptable limits of system resilience.

The resource-intensive inefficiencies inherent to telecom ordering, billing, and service level agreement (SLA) enforcement between carriers is an industry-wide problem that MEF and its member organizations have been working to solve for years.

Cybersecurity agencies from Japan and the U.S. have warned of attacks mounted by a state-backed hacking group from China to stealthily tamper with branch routers and use them as jumping-off points to access the networks of various companies in the two countries.

To help solve this problem, QUIC no longer relies (purely) on IP addresses to define connections. Instead, it assigns a number to each connection (a so-called Connection ID or CID).

You are a distributor that sells your supplier’s brands, so aside from worrying about your own company’s domains, you’ve got nothing else to worry about, right?

The adoption of ‘justified need’ address policy by the RIRs, plus classless inter-domain routing (CIDR), which permitted more fine-grained delegation of resources slowed the runout of IPv4, but exhaustion was inevitable.

Some details are emerging on Europe’s first exascale system, codenamed “Jupiter” and to be installed at the Jülich Supercomputing Center in Germany in 2024.

View Details

Since its discovery in 2019, cyber espionage group RedHotel has successfully stolen secret information from at least 17 target nations worldwide.

The vast majority of Internet users won’t notice any difference, but the update will support enhanced security for several Verisign-operated TLDs and pave the way for broader adoption and the next era of Domain Name System (DNS) security measures.

New research has found that close to 12,000 internet-exposed Juniper firewall devices are vulnerable to a recently disclosed remote code execution flaw.

At the birth of the registry model, Internet engineers could already foresee that the supply of IPv4 addresses would not sustain the predicted rate of consumption.

Attacks related to Domain Name System infrastructure – such as DNS hijacking, DNS tunneling and DNS amplification attacks – are on the rise, and many IT organizations are questioning the security of their DNS infrastructure.

An old Chinese state-linked threat actor has been quietly manipulating Cisco routers to breach multinational organizations in the US and Japan.

Can open source software be regulated? Should it be regulated? And if so, will it lead to enhanced security?

There are currently no restrictions on .AI registrations and it doesn’t help that the domain market is already a tough place to do business.

View Details

The average total cost of a data breach has reached an all-time high in 2023 of $4.45 million. This is an increase of 2.3% from last year’s $4.35 million.

Originally created as a secure sandbox to run compiled C/C++ code in web browsers, WebAssembly (Wasm) has been gaining traction and momentum on the server-side.

Specifically, the web giant’s Privacy Sandbox APIs, a set of ad delivery and analysis technologies, now function in the latest version of the Chrome browser. Website developers can thus write code that calls those APIs to deliver and measure ads to visitors with compatible browsers.

The German digital association, Bitkom, recently announced that the cost of IT equipment theft, data breaches, digital and industrial espionage, and sabotage is expected to reach a staggering 206 billion euros ($224 billion) in 2023.

The alarming rise of phishing attacks has been underscored by a recent study “Phishing Landscape 2023: An Annual Study of the Scope and Distribution of Phishing conducted” by the Interisle Consulting Group, revealing a tripling of such attacks since May 2020.

Japan is widely regarded as one of the most advanced economies for Internet penetration. Japan’s Internet usage rate (individuals) is 82.9% and the development rate of optical fibre is 99.3%.

The robot revolution began long ago, and so did the killing.

View Details

However, unlike most of the world, which is taking a flexible, adaptive Zero Trust Model approach of continuous controls for cyberdefense, the EU government is pursuing a vastly expanded version of the failed Common Criteria certification model coupled with regulatory extremism and exceptionalism strategies.

Enabled by SD-WAN, internet-first networking strategies are now the order of the day for wide-area connectivity and have been for some time.

The European Union’s Digital Services Act comes into effect today, August 25, and it’s unclear if the hoped-for consumer protections are going to have their desired impact.

Domain names ending in “.US” — the top-level domain for the United States — are among the most prevalent in phishing scams, new research shows.

I like monitoring stuff. That’s what I do at work and when my home ISP started giving me random problems I decided it would be nice to monitor my home network as well.

Although we cannot fix humans, we can put extra measures in place to minimize the risk of having wrongly issued certificates operational in the wild. In comes Certificate Transparency (CT), a concept introduced by Google in 2013.

View Details

This open-source hardware optimized implementation uses a novel ECC/Dilithium hybrid signature schema that benefits from the security of ECC against standard attacks and Dilithium’s resilience against quantum attacks.

Dig Security, the cloud data security leader, today released findings from its first-ever "State of Cloud Data Security 2023 Report." The analysis of more than 13 billion files stored in public cloud environments reveals how – and why – sensitive data is at risk in the modern enterprise.

Dr. Read Schuchardt, professor of communications at Wheaton College (IL), identifies five primary ways digital technology can erode our lives and relationships, or produce what he calls “vices of the virtual life”

View Details

A group of academics has devised a "deep learning-based acoustic side-channel attack" that can be used to classify laptop keystrokes that are recorded using a nearby phone with 95% accuracy.

Of all vertical industries, manufacturing saw a 42% increase in total victims between Q4 2021 and Q4 2022, underscoring the potential threat to global supply chains.

In this article, we discuss the constant back and forth that has been going on for the last 5 years or so in protecting the privacy of data through FL. Just when it looks like FL is able to keep local data private, out comes a study to deflate us.

View Details

Incredible as it may seem, US tax preparation companies using Google and Meta tracking technology have been sending sensitive information back to the megacorps, not to mention other tech firms, it is claimed.

The Federal Trade Commission (F.T.C.) sent a letter to OpenAI, the San Fransisco company responsible for creating ChatGPT, the Large Language Model that captured the world’s imagination in November of 2022.

Steganography is the art of hiding secret data in plain sight. It sounds kind of counter-intuitive, but you’d be surprised how effective it is.

View Details

Indian-born CEOs are closing their firms and fleeing back to India to escape charges of fraud in the annual lotteries for visas to import H-1B foreign contract workers, says a lawyer for many Indian-owned subcontractors and visa workers.

Over the past few years, Apple has pursued a meal-prepping app with a pear logo, a singer-songwriter named Frankie Pineapple, a German cycling route, a pair of stationery makers, and a school district, among others.

Reddit, a link-aggregating website that claims to be the “front page of the internet,” has turned into a hotbed for radicalization.

View Details

For example, at a certain level, your password must include today’s Wordle answer. And then there’s rule #27: “At least 50% of your password must be in the Wingdings font.”

On 12 June, the DFIR Report published an in-depth analysis of a Truebot intrusion that began with several page redirects via a Traffic Distribution System (TDS) and ended with dropping a Master Boot Record (MBR) killer wiper onto a victim's computer.

PL/I stands for Programming Language 1, and its aim was to be the Highlander of programming languages: there would be no need for 2, 3, or 4 if everything went to plan.

View Details

To help organizations avoid the potential perils that the .zip and similarly confusing ngTLD extensions (i.e., .app, .cab, .cam, .mobi, .mov, .pub, .rip, and .win) may pose, the WhoisXML API research team scoured the DNS for such domains created between 1 January and 31 May 2023 to see if any of them should be considered suspicious and treated with caution.

When you write some code and put it on a spacecraft headed into the far reaches of space, you need to it work, no matter what. Mistakes can mean loss of mission or even loss of life.

That’s right, no need to be picky — any CA can sign any domain name, so you can pick from literally hundreds since that is the number of trusted CA root certificates baked into your browser or included in most operating systems.

View Details

Enterprises can use multiple DNS providers to serve their zone. This increases the reliability of the service and will likely help them to keep their zone available if one provider is suffering from a critical failure. According to the Astrix Security Research Group, mid size organizations already have, on average, 54 Generative-AI integrations to core…

View Details

The US Federal Communications Commission (FCC)’s proposal to offer shared access to the 42 GHz band could open the door to a raft of new service providers and business models.

Artificial intelligence (AI) might be all fun and games now, but the coming effects will be devastating, one top investment bank says.

For a long time, arguments about the meaning of “DNS Abuse” prevented fruitful discussions within the ICANN community on when and how it is appropriate to act at the level of the DNS to address abuses online.

View Details

Artificial intelligence (or, at least, the Chat GPT program) makes stuff up, out of what seems to be a spirit of fun, or perhaps a desire to please.

The ad-tech industry is incredibly profitable, raking in hundreds of billions of dollars every year by spying on us.

This memo contains the thoughts and recountings of events that transpired during and after the release of information about the NSA by Edward Snowden.

View Details

https://labs.ripe.net/author/kathleen_moriarty/separating-fud-from-practical-for-post-quantum-cryptography/ First, there have been advances in capabilities for post-quantum computing. Second, the National Institute of Standards and Technology (NIST) will complete final rounds for selection of these new cryptographic algorithms in 2024.

https://circleid.com/posts/20230607-when-marketing-vendors-get-attacked-clients-suffer-third-party-risk-discovery-in-the-dns Organizations get bombarded with countless attacks from every direction, including via their supply chain. FortifyData’s recent record of the top third-party data breaches in 2023 brings to light how multidirectional threat sources can be.

https://circleid.com/posts/20230608-ransomware-attacks-skyrocket-median-cost-double A report from Verizon Business's 16th annual Data Breach Investigations Report (DBIR) reveals a startling surge in the frequency and cost of cyberattacks.

View Details

That is because IoT is a fundamentally different technology than existing systems—a technology with plenty of attack surfaces. Each sensor and device connected to an IoT network presents a possible security risk, opening up an attack vector into an individual or company's hardware, software, and/or data.

Like their mathematical counterparts, the unsolved problems in brand protection will present significant benefits for any service providers able to develop and offer comprehensive solutions.

The most annoying thing about ReDoS vulnerabilities is that they’re not caused by careless coding but by an obscure edge case in the regex engine. I place the blame squarely on the regex library and not the developer who used it.

View Details

When processing multiple transactions at the same time, the database needs to decide whether the transactions can see each other’s changes, how much they can see, etc.

While there are an estimated 30,000 daily cyber attacks on business websites, there are roughly ten times as many attacks against social media accounts every single day, equating to roughly 1.4 billion accounts every month.

Resecurity threat researchers discovered a new ransomware they’ve dubbed “Nevada” being sold on the RAMP underground community.

A mission-critical design objective of power autonomy, however, does not shield data center operators from problems that affect utility power systems.

At the moment, the most powerful Arm processor on the planet is the 48-core A64FX processor from Fujitsu, which was created as the heavily vectored

UK operator group BT plans to shed more than 40 percent of staff, all in the name of agility. The revelation appeared as a small bullet point in the telco’s full-year results – published on Thursday – under a section outlining BT’s transformation plans for the rest of this decade.

A computer that is not networked to anything and never turned on is likely safe from most cybersecurity attacks but is also not particularly useful. Deciding what risks are acceptable describes risk tolerance.

Samsung, Oppo and Nokia are among a range of Android phone makers with facial recognition scanning tech that can be “easily duped” by a printed 2D photo, according to tests undertaken by campaign group Which?

So what happens when you download a supposed VPN software installer but end up with a malware infection instead?

On May 22, Ireland’s Data Protection Commission published its anxiously anticipated decision in the Meta data transfers case, which includes a record-breaking 1.2 billion euro fine, a stop-transfer order with a carefully delineated timeline and an order to cease unlawful processing of EU data in the U.S. within six months.

Social networks are constantly battling inauthentic bot accounts that send direct messages to users promoting scam cryptocurrency investment platforms.

The European Union has been working on the world’s first comprehensive law to regulate artificial intelligence. The file is approaching the finish line two years after the legislative proposal was presented.

The digital domain encompasses the different spaces and spheres we use to relate and interact with the people and things that surround us using digital technologies.

Recent research conducted by the Independent Advisor reveals that a significant number of accounts, exceeding 340 million, have been compromised due to business data breaches within the first four months of 2023.

While-taken in isolation-each implementation may be secure, we reveal that in the interoperable world of OpenPGP, unforeseen cross-configuration attacks become possible.

View Details

The net’s long decline into “five giant websites, each filled with screenshots of the other four” isn’t a mystery. Nor was it by any means a forgone conclusion. Instead, we got here through a series of conscious actions by big businesses and lawmakers that put antitrust law into a 40-year coma.

The federal government should not have warrantless, backdoor access to private communication systems like Twitter.

My experiences in the War on Terror provided me with a glimpse of the AI revolution that is now remaking America’s political system and culture in ways that have already proved incompatible with our system of democracy and self-government and may soon become irreversible.

America has a monopoly problem. Most industries in the United States have consolidated in recent decades,1 and markups and profits have dramatically increased since around 1980.

If the fabric is error-free, and can send and receive between hosts at interface speed with no buffering or delay, a case can be made for a different kind of stream protocol, which implies perhaps less overhead per host to manage that stream of data.

The real problem Altman is trying to solve—and everyone knows this—is how to use the power of the federal government to prevent competitors from upsetting OPENAI’s current market position.

Even if we assume that the tendency towards pseudoscience and poor research isn’t inherent to the culture of AI research and just take for granted that, in a burst of enlightened self-awareness, the entire industry is going to spontaneously fall out of love with nonsense ideas and hyperbolic claims, the secrecy should still bother us.

As Tesla CEO and Twitter mogul Elon Musk tells it, I may be unproductive — despite the multiple articles and extensive work I produce each week — and immoral.

View Details

Communities installing WiFi that spans an entire property. From tennis courts to pools, from fields to lakes, Hotwire says the new hybrid work-from-home lifestyle means homeowners are working from everywhere within a community.

BGP is the Internet’s de facto routing protocol – but relatively few have a deep understanding of its vulnerabilities.

Since its invention by Bob Metcalf and David Boggs back in 1973, Ethernet has continuously been expanded and adapted to become the go-to Layer 2 protocol in computer networking across industries.

However, it is important to acknowledge that passwords have long been identified as one of the weakest elements in the security chain.

Ready to live on the edge? In my last network design post we talked about remote access VPN but in this instalment, we will take a detailed look at designs for the network edge.

Intel has launched a field-programmable gate array—Agilex 7 with R-Tile—that features PCIe 5.0 and CXL capabilities for processing networking workloads.

Speaking of the existential threat of AI is science fiction, and bad science fiction for that matter because it is not based on anything we know about science, logic, and nothing we even know about ourselves.

In a recent workshop I attended, reflecting on the evolution of the Internet over the past 40 years, one of the takeaways for me is how we’ve managed to surprise ourselves in both the unanticipated successes we’ve encountered and in the instances of failure when technology has stubbornly resisted to be deployed despite our confident expectations to the contrary!

In this episode of PING, Verisign Fellow Duane Wessels discusses notable changes in the DNS root zone in the last 13 years.

As technical people, we spend immense time and energy mastering the nuances of specific technologies. Esoteric knowledge is our currency, and we often measure our personal value against the yardstick of technical nuance

The term ‘platform engineering’ refers to the activity of designing and developing toolchains and internal work processes that enable the employees of an organisation to be self-sufficient in all software engineering activities.

Open source repositories — such as Python’s PyPI, the Maven Java repository, and the Node Package Manager (npm) for JavaScript — typically have a skeleton crew of engineers and volunteers to manage and secure the infrastructure

View Details

When it comes to understanding what exactly confidential computing entails, it all begins with a trusted execution environment (TEE) that is rooted in hardware.

So, just for fun, we pulled out the trust Excel spreadsheet and tried to estimate what the feeds and speeds of the MI300 and the MI300A GPUs, the latter of which will be at the heart of the El Capitan system might be. Y

The popular PC storage manufacturer, Western Digital, has confirmed that it experienced a network security breach earlier this year, in which an unauthorized third party gained control of several of its systems.

How bad is the human security weakness problem? Verizon’s 2022 Data Breaches Investigations Report says 82 percent of data breaches have human involvement.

On 13 April 2023, through our recently launched Threat Intelligence Data Feeds (TIDF), we identified more than 1 million suspicious and malicious domains that figured in phishing, malware distribution, spam, and other cyber attacks, such as brute-force and distributed denial-of-service (DDoS) attacks.

Although honeypots are an effective solution for tracking attackers and preventing data theft, they have yet to be widely adopted due to their setup and maintenance difficulties.

If you want to get a sense of what companies are really doing with AI infrastructure, and the issues of processing and network capacity, power, and cooling that they are facing, what you need to do is talk to some co-location datacenter providers.

IBM and its IT infrastructure spinoff Kyndryl were this week taken to court by an axed exec who had put decades of her life into the tech giant.

The advancements of coherent passive optical networks (CPON) will lead to a robust and noticeable boost to the customer experience in businesses and the home.

Publicly listed technology companies under pressure to make deep job cuts can underestimate the often negative impacts redundancies may cause, both financially and culturally, as well as the harm to shareholder returns.

It’s easy to think high-tech companies have a security advantage over other older, more mature industries.

A Social engineering attack is the process of exploiting weaknesses in human psychology to manipulate and persuade others to perform in a way that is harmful. Prior to the digital age, criminals would carry out these attacks in person, in what was known as a confidence game.

WhoisXML API sought to discover how the closure of the two banks and similar recent events are reflected in the DNS.

In early March, my colleague Merve Hickok testified before the House Oversight Committee at the first hearing on AI policy in this Congress.

View Details

Cybersecurity researchers have uncovered weaknesses in a software implementation of the Border Gateway Protocol (BGP) that could be weaponized to achieve a denial-of-service (DoS) condition on vulnerable BGP peers.

Enter OpenTelemetry, which provides a vendor-neutral standard for telemetry data, as well as the necessary tools to collect and export data from cloud-native applications.

DevEx drives business performance through increased efficiency, product quality, and employee retention.

Last January, thousands of users of two popular open source libraries, “faker” and “colors,” were shocked to see their applications breaking and showing gibberish data after being infected with a malicious package.

Netskope, a leader in Secure Access Service Edge (SASE), today unveiled new research confirming that attackers are finding new ways to evade detection and blend in with normal network traffic using HTTP and HTTPS to deliver malware.

In keeping with WhoisXML API’s mission to make the Internet a transparent and safe place for users, we expanded the list of IoCs in hopes of identifying social media pages that could already be serving or used to serve as fraud vehicles.

According to research carried out across a sample of over failed 17,000 hard drives, the failure occurred after only two years and 6 months. Does that make the HDD one of the weakest components inside your PC?

The Global Digital Compact (GDC) is a proposed initiative by the United Nations (UN) to address the global challenges and opportunities arising from the digital revolution.

What makes Wi-Fi 6E such a game changer is that it maximizes both user and IT experiences by offering enterprises more capacity and increased channel width.

Are you responsible for the safety and reliability of IT infrastructure and applications? You’ll absolutely need regular and accurate assessments.

BEC scams are bound to continue affecting organizations worldwide, given the continued rise in the number of complaints the FBI IC3 receives with each passing year.

One might make a de minimis argument that there is so much training data that the amount of any particular input document in any output is too small to matter.

View Details

The past decade has seen numerous reports of so-called cloud “repatriations”–the migration of applications back to on-premises venues following negative experiences with, or unsuccessful migrations to, the public cloud.

While agile software development is often associated with specific methodologies, such as Scrum, Kanban, and Extreme Programming it is not enough to just follow such a methodology.

The heady, exciting days of ChatGPT and other generative AI and large-language models (LLMs) is beginning to give way to the understanding that enterprises will need to get a tight grasp on how these models are being used in their operations or they will risk privacy, security, legal, and other problems down the road.

When deploying changes to an application, there are several strategies you can use.

The sad story of OAuth 2.0 and open standards.

Payment Card Industry Data Security Standard (PCI DSS) was developed and established to foster a safe cardholder data practice in the industry.

While the DNS (Web2) has been a reliable and trusted internet standard for decades, Web3 platforms (such as ENS, Handshake and Unstoppable) are a relatively new technology deployment that presents unique and different features.

In this blog post, we at the University Grenoble Alpes (France) analyse that event from the RIPE Atlas point of view and, more broadly, evaluate the extent of DNS manipulation when sending queries to DNS root servers.

Amazon Web Services has spent the past decade and a half testing this principle, and is being tested now as companies are skittish that national economies are going to push the world into recession.

Bluetooth, the technology that powers the wireless data connections between billions of devices, is going to become even more capable, with big increases planned for the data bandwidth of Bluetooth LE.

Just a few short years ago, lateral movement was a tactic confined to top APT cybercrime organizations and nation-state operators. Today, however, it has become a commoditized tool, well within the skillset of any ransomware threat actor.

Unsuspecting website visitors are often unaware when they have landed on a spoofed page or are re-directed to malware-hosting web servers designed to steal their sensitive data and information.

Ever wondered where the personally identifiable information (PII) phishers steal from victims end up? More likely than not, they’re put up for sale on the ever-growing number of online stolen card shops.

So when we got a call last week from someone asking us how big are Nvidia’s server and networking businesses in a finer-grained detail than just the broad “Compute & Networking” and “Datacenter” categories that Nvidia talks about, we didn’t hesitate to load up our spreadsheet for Big Green and take a stab at it.

Satellite comms firm Viasat has successfully hurled ViaSat-3 Americas into orbit, the first of three satellites designed to offer high speed global broadband coverage.

View Details

There has always been some concern about undersea fibers. Countries fear that sabotage of the fibers connected to their shores could result in being isolated from the Internet.

Do your employees use unauthorized SaaS apps? The average organization has over 100 SaaS apps, many unsanctioned by IT, posing a serious security risk.

A proposed permanent network of electromagnetic monitoring stations across the continental US, operating in tandem with a machine learning (ML) algorithm, could facilitate accurate predictions of geomagnetic disturbances (GMDs).

We may be seeing an equally dramatic transformation of chip design right now, this time with the use of AI to drive designs.

But for now it”s exciting to see what ChatGPT has already been able to do. At some level it”s a great example of the fundamental scientific fact that large numbers of simple computational elements can do remarkable and unexpected things.

He”s sharing the story of JSON, his discovery of JavaScript”s good parts, and his approach to finding a simple way to build software.

Back in January of this year, we studied the infrastructure of Ducktail, a malware that trailed its sights on Facebook business owners and advertisers.

The Philippines is an archipelago comprising three major island groups: Luzon, Visayas, and Mindanao with 7,641 islands at high tide and a population of 113 million spread across roughly 2,000 of those islands.

Cable operators are eager to take advantage of the forthcoming DOCSIS 4.0 rollout, as a survey from ATX Networks found nearly half (48%) of cable companies plan to activate DOCSIS 4.0 in their hybrid-fiber coaxial (HFC) networks by the end of 2025.

While Prolexic’s overall service and mitigation stacks are not changing, the new offering allows customers to define and adjust their own access control rules and provides analytics of existing ones.

However, alongside these more “traditional” or perhaps “structural” security concerns that cannot be swiftly shaken off, countries in the region have increasingly had to deal with the additional burden of cybersecurity threats.

Distributed denial-of-service (DDoS) is the attack method businesses are most concerned about, believing it will have the largest impact on the business.

A prominent example of a PET is fully homomorphic encryption, often mentioned in the same breath as differential privacy, federated learning, secure multiparty computation, private set intersection, synthetic data, zero knowledge proofs or trusted execution environments.

We already know that software can displace people. In 2019, Wells Fargo predicted that efficient software would replace 200,000 jobs in the banking industry.

There were a few efforts to flesh out what 6G might look like but they didn”t really get much further than “5G done properly” with a bit of utopian AI and ubiquitous sensing thrown in to sex it up a bit.

View Details

Tech companies are embedding these deeply flawed models into all sorts of products, from programs that generate code to virtual assistants that sift through our emails and calendars.

On the morning of October 14, 2020, I caught a firsthand glimpse of what itâ€s like for a traditional media outlet to go up against the vast agglomeration of economic and digital power known as Big Tech—and to do so without the benefit of what economist John Kenneth Galbraith defined as countervailing power.

Former Google CEO Eric Schmidt said that artificial intelligence could hurt American politics and needs to be reined in.

The National Assemblyâ€s decision to greenlight the bill followed months of debate about one section in particular — Article 7 — which permits the use of AI-assisted video surveillance technology by law enforcement during and up to six months after the Games.

Calling a business, civic organization, or even school a family may be well-intended but comes with unintended consequences that do an injustice to the necessary commitments that should be made to our actual families.

If normal means mass layoffs, empty office buildings, confusing return-to-office policies, AI panic, and the whiplash-y feeling that just when employees were starting to redraw some boundaries between work and home, an economic downturn has forced society to fret even more about work.

On April 11th, 2023, China’s top internet regulator proposed new rules for generative AI.

Many people stare down face recognition technology every day as they unlock their smartphones. But this technology also has applications in peopleâ€s places of work.

A variety of digital tools are being used to monitor workers across various industries, some of which use artificial intelligence (AI) to try to gain insights into workers†performance.

But increasing use of AI by employers has led some to question the fairness, quality and accuracy of hiring decisions made in this way – even as others tout AI as an improvement over human involvement.

View Details

In a 2023 survey of cybersecurity leaders, 51% said they believe an AI-based tool like ChatGPT will be used in a successful data breach within the next year.

When folks ask me for an estimate of the cost of building aerial fiber, I always say that the cost is dependent upon the amount of required make-ready needed. Make-ready is well-named – itâ€s any work that must be done on poles to be ready to string the new fiber.

On 10 February 2023, Reddit announced it suffered a security incident where a phishing campaign led an employee to a website that imitated the network’s intranet gateway.

This video looks at various Kubernetes vulnerabilities and their severity scores to help you understand how to evaluate CVEs so you can prioritize remediation. It also shows different options and sources of CVEs.

It is almost 25 years since the Internet was privatized by the U.S. government. ICANN was formed by Esther Dyson and Jon Postel as a California-based non-profit with the responsibility to administer the Internet.

The series glamourized Annaâ€s fraudulent endeavors and depicted her as clever, interesting, and mysterious; someone who we wanted to figure out and understand.

Even if cyber attack tactics, techniques, and procedures (TTPs) have become increasingly sophisticated over the years, age-old phishing remains the most-used attack vector to this day.

On a specific date and time in 2038, the old-world model of time in 32 bits as a positive integer value ‘wraps around†(when an integer value is too big for the container assigned in the computer) and returns nonsensical results.

Today, Microsoft is excited to announce that we are shifting to a new threat actor naming taxonomy aligned to the theme of weather.

From the coverage that ChatGPT, developed by OpenAI, has been receiving since its launch in November 2022, you would be forgiven for thinking that is the only technology story around.

The Domain Name System (DNS) root zone will soon be getting a new record type, called ZONEMD, to further ensure the security, stability, and resiliency of the global DNS in the face of emerging new approaches to DNS operation.

View Details

Four major US mobile operators have agreed to a series of undertakings designed to address concerns over airline safety and to allow them to use their C-band spectrum to its full extent.

The result of this effort, Intel Max Series GPU formerly known by the code name Ponte Vecchio, packs 100 billion transistors and 47 tiles onto five process nodes. Beyond that, they include two packaging innovations, EMIB 2.5D and Foveros 3D technology, and stack tiles atop one another for greater processor density.

According to various statistics, there are somewhere around 330 billion emails being sent every day, approximately 3.82 million per second. Who reads all these emails?

In the ongoing AI revolution, images and text are yesterdayâ€s news, leaving audio as a new frontier to explore, and incredible progress has already been made. Here are six examples of AI audio generation that will leave you speechless.

The secret to unlocking the full potential of quantum networking may be hiding at the center of a diamond, according to Amazon Web Services. This week, AWS popped the question to De Beers subsidiary Element Six in the hope of finding it.

Year-over-year global VC funding dropped precipitously in Q1 2023, with at least $76 billion (£61 billion) doled out to companies at all startup stages. That may sound like a lot but it’s a 53 percent drop from the same time last year, reports funding tracker Crunchbase.

People once prioritized logging in as much as logging out, but now, according to freelance UI designer Jesse Showalter, access to content is of utmost importance, even at the cost of constantly sharing our data. Logging out, by contrast, carries little value for companies or consumers.

Shorter certificate life cycles bring about benefits to improve security and reduce the risks associated with long-lived certificates.

Kumorai is a startup that aims to simplify the deployment and operation of compute, networking, and security infrastructure across public clouds.

Humans have always been interested in making machines that display intelligence.

One of the most effective ways for CISOs and CIOs to make the best use of their limited resources to protect their organizations is by conducting a cyber risk assessment.

Query name minimization (qmin) is a privacy feature that limits the amount of information sent in DNS queries to enhance privacy (RFC 9156).

Today, we are excited to announce the deps.dev API, which provides free access to the deps.dev dataset of security metadata, including dependencies, licenses, advisories, and other critical health and security signals for more than 50 million open source package versions.

Analysts from Dellâ€Oro Group warned 2023 could be ripe for CPE inventory corrections, thanks in part to lower than expected broadband deployment targets and a slowdown in activity that normally drives broadband growth.

Ciena is taking a new approach to routing with its freshly unveiled WaveRouter platform, aiming to meet the demands of the converged metro network in the multi-cloud era.

View Details

What it is about is how very few companies have access to the raw AI models that are transforming the world, the curated datasets that have been purged of bias (to one degree or another) that are fundamental to training AI systems using machine learning techniques, the model weights and checkpoints that are key to tuning a model, and the money to either build or rent the capacity to bring the neural network software and the data together to train an AI model.

Intel has announced a new processor with 144 cores designed for simple data-center tasks in a power-efficient manner.

Data center fires aren’t common, but they can be devastating. As use of lithium-ion batteries grows, enterprises need to be aware of the risks, Uptime Institute warns.

Russian intelligence services, together with a Moscow-based IT company, are planning worldwide hacking operations that will also enable attacks on critical infrastructure facilities.

Back in the old days, there was a CPU and chip designers crammed everything into that single CPU, which made sense for the greatest number of customers offset against the additional cost of adding extra functionality.

A picture is said to be worth a thousand words. A graph can be worth a thousand numbers.

Business software often is hard to implement. That means it takes a lot of work to get it into a usable state after purchasing it.

Quantum computing as a term has been banded around for years now as something between bleeding edge tech and theoretical academia. Itâ€s often sprinkled in when futurologists vaguely sketch out what the future might look like, along with neural lace brain attachments and nano-robots.

The Threat Intelligence Platform (TIP) research team used these as jump-off points to scour the DNS for connected domains and IP addresses that could be part of the ransomware affiliates†infrastructure.

Due to their powerful computing capabilities, the Cloud Security Alliance (CSA) has estimated that by April 2030, RSA, Diffie-Hellman (DH), and Elliptic-Curve Cryptography (ECC) algorithms will become vulnerable to quantum attacks.

The central bankers of the world want to curb inflation by putting a serious crimp in demand, and it looks like they may get what they want – sort of – in 2023 when it comes to datacenter infrastructure.

Liberty-owned UK broadband pusher Virgin Media has fallen on its face this morning, with users across the country reporting complete broadband failure for a number of hours, among them some of the reporters on this news desk.

View Details

Last year, around the Thanksgiving holiday, Ohio businessman Michael Larkin received a request for video from his Amazon Ring security system from Hamilton city police.

Once upon a time there live a tribe who lived on the plains. They were an adventurous tribe, constantly wanting to explore. At night they would see the moon drift lazily overhead, and became curious.

If I’ve written in this space before about “convenience of the employer” rules a lot of late, it’s because they are so pernicious. These rules essentially require taxpayers who switch from working in-person in one state to working remotely in another to continue paying income taxes to the state they used to work in, not the one they currently work in.

A federal judge yesterday ruled that Google intentionally destroyed evidence and must be sanctioned, rejecting the company’s argument that it didn’t need to automatically preserve internal chats involving employees subject to a legal hold.

From a national security perspective, banning TikTok seems to be a reasonable step in protecting U.S. citizens. After all, TikTok is merely a video sharing app that is widely used by children; thus, its ability to harm us far outweighs its utility.

And so as he prepared to face the powerful House Energy and Commerce Committee, Chew enlisted all the right people to help him get ready.

The newest generation of artificial intelligence products has inspired waves of excitement and funding since this past fall, when generative-A.I. apps like ChatGPT and DALL-E 2 debuted. But there’s a reason that many of the use cases the technology’s boosters have suggested feel like fixes in search of problems. This is solutionism.

View Details

Late posting due to a conference this weekend …

The rapid rise in IT power density, however, now means that plausible design assumptions regarding future power density and environmental conditions are starting to depart from these standard, narrow ranges.

Globalization is over, at least for the chip industry, and this will mean higher chip prices, according to semiconductor contract manufacturer giant TSMC.

Are your online customers being lured away? Learn why retailers must prevent audience hijacking tactics to keep shoppers focused and not distracted by unwanted or malicious in-browser interruptions.

I surveyed the status of RPKI ROA registration for IXPs operating in the Asia Pacific region and several IXPs in the European region on 17 February 2023. My first impression is that both regions lack a sense of unity, with RPKI ROA registration being inconsistent.

Active DNS measurement is fundamental to understanding and improving the DNS ecosystem. However, the absence of an extensible, high-performance and easy-to-use DNS toolkit has limited both the reproducibility and coverage of DNS research.

A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware — an HTTP listener written in C# dubbed Naplistener by the researchers — in attacks against victims operating in southern and southeast Asia.

The number of victims affected by a mass-ransomware attack, caused by a bug in a popular data transfer tool used by businesses around the world, continues to grow as another organization tells TechCrunch that it was also hacked.

Last week I shared how IPng Networks deployed a loadbalanced frontend cluster of NGINX webservers that have public IPv4 / IPv6 addresses, but talk to a bunch of internal webservers that are in a private network which isnâ€t directly connected to the internet, so called IPng Site Local [ref] with addresses 198.19.0.0/16 and 2001:678:d78:500::/56.

The prized retro audio components are mostly manufactured in Russia and China. Now, a small Georgia company is rebooting US production.

Researchers recently spotted phishing attacks using supposed ChatGPT sites to phish for personally identifiable information (PII), specifically credit card data.

Since cellular communications†inception, SIMs have been required so that remote devices can achieve authentication when connecting to a network. Protecting the security credentials stored has been fundamental, yet these must be easily issued to subscribers for placing into their devices.

The most common transport encryption protocols are Secure Sockets Layer (SSL) and its successor, Transport Layer Security (TLS).

In our latest report our head security engineer, Thomas Perkins, has revealed the excessive data collection of TikTok and that the app connects to mainland China based infrastructure.

The risk score for the average company worsened in the past year as companies fail to adapt to data exfiltration techniques and adequately protect Web applications.

This fundamental shift in policy raises a critical question: How can the government enforce such requirements? Experience across the regulatory landscape offers some cautionary lessons.

View Details

Fujitsu’s Arm-based A64FX processor may have driven the most powerful supercomputer in the world, but it looks like its successor will be a more general-purpose chip that will focus on energy efficiency.

Hi everyone! In this article we’re going to take a look at the different rendering pattern options available nowadays for web applications.

Spurred by unprecedented unit pricing, the IPv4 market in North America experienced its second-best year ever in market history.

Getting a new technology out to consumers will usually require good people and boat loads of resources – including money. Generally, lots of money.

The Global Domain Report 2023 shows the domain industry is absorbing the shock waves, proving that the market is resilient and domains are solid assets for digitalization.

A proposed rule change at the Federal Communications Commission (FCC) would expand the definition of a data breach for communications carriers. If approved by the agency, the rule would cover any incident that affects the confidentiality of customer information, even if no harm to customers results.

Threat actors with a connection to the Chinese government are infecting a widely used security appliance from SonicWall with malware that remains active even after the device receives firmware updates, researchers said.

Akamai has just mitigated a distributed denial of service (DDoS) attack of epic proportions. While it was short-lived, it was very intense, and it most likely could have easily taken the target server offline.

While compatible with RDP connection and local desktop logins, they offer no protection to remote command line access tools like PsExec, Remote PowerShell and their likes.

Is the current arrangement of keys on the keyboard the most efficient and intuitive solution? Open source aims to address this question with a circular one-handed keyboard.

Software-defined WAN offers a lot of potential benefits including price, efficiency, and performance, but itâ€s not right for all sites.

But given the expansive capabilities of today’s technology, combined with how integrated it is in every aspect of our lives, there’s a danger of either purposefully or inadvertently collecting unnecessary and private data.

You may be wondering what folks mean when they talk about a [BGP Free Core], and also you may ask yourself why would I decide to retrofit this in our network.

To that end, three vendors have announced new capabilities in the high-speed networking game. So, letâ€s run them down.

Privacy experts can now rely on a new standard, the ISO/IEC 27559:2022 privacy-enhancing data deidentification framework, in an area that has been the subject of much discussion and development.

View Details

Featuring 18 different participating member companies, the Ethernet Alliance interoperability demo in booth #5417 spans diverse Ethernet technologies ranging from 10 Gigabit Ethernet (GbE) to 800GbE

Every few months, an important ceremony takes place. It’s not splashed all over the news, and it’s not attended by global dignitaries. It goes unnoticed by many, but its effects are felt across the globe. This ceremony helps make the internet more secure for billions of people.

Major cloud platforms, such as Google Cloud Platform (GCP), fail to adequately log the event data that could facilitate the detection of compromises and the forensic analysis during post-compromise response, according to an analysis.

Software dependencies, or a piece of software that an application requires to function, are notoriously difficult to manage and constitute a major software supply chain risk. If you’re not aware of what’s in your software supply chain, an upstream vulnerability in one of your dependencies can be fatal.

As a primary working interface, the browser plays a significant role in today’s corporate environment. The browser is constantly used by employees to access websites, SaaS applications and internal applications, from both managed and unmanaged devices.

For years, the domain registrar and Web hosting company GoDaddy has experienced a cyber barrage of extraordinary scale, it has confirmed — affecting both the company and its many individual and enterprise clients.

The massive breach at LastPass was the result of one of its engineers failing to update Plex on their home computer, in what’s a sobering reminder of the dangers of failing to keep software up-to-date.

The Cyble analysis identified 10 indicators of compromise (IoCs) for this threat—six malware hashes and four URLs.

As global conflicts continue, cyber has become the fifth front of warfare. The world is approaching 50 billion connected devices, controlling everything from our traffic lights to our nuclear arsenal.

For decades, scholars and litigators have been talking about imposing legal liability on the makers of insecure software. But the objections of manufacturers were too strong, concerns about impeding innovation were too great, and the conceptual difficulties of the issue were just too complex.

So, who will the winners and losers in this new world be? According to Entner, “itâ€s not set in stone yet.†He noted the result partially depends on whether DOCSIS 4.0 is able to deliver better reliability than DOCSIS 3.1.

A never-before-seen complex malware is targeting business-grade routers to covertly spy on victims in Latin America, Europe, and North America at least since July 2022.

View Details

Privacy campaigners say such systems could be used as tools of oppression. In Moscow, Vyborov and countless others now face that oppression on a daily basis.

The general problem statement for technological standards is how to avoid the power imbalance of a single source for essential goods and services; in other words, standards are a line of defense against concentration risk. Interoperability is the goal, and multiple suppliers is the proof.

In this episode, they focus particularly on how social media has become a place where predators will search and highlight childrenâ€s vulnerabilities — which so many young people share online.

Tech policy, however, has its own set of “culture war issues” including net neutrality and encryption that largely serve as a distraction from the real issues at stake. Victims of child porn are now caught in the fray.

A major escalation in official online censorship regimes is progressing rapidly in Brazil, with implications for everyone in the democratic world. Under Brazil’s new government headed by President Lula da Silva, the country is poised to become the first in the democratic world to implement a law censoring and banning “fake news and disinformation” online, and then punishing those deemed guilty of authoring and spreading it.

In addition to federal agencies, could the major accounting firms provide algorithmic audits as they do in auditing financial statements of publicly listed companies?

The click-based economy has made the world more efficient in some ways, but it turned this miraculous global information databank into a frenzied real estate auction with every website scrabbling to climb to the top of the search results, collect the most clicks, and retain the most eyeballs.

A former ASML worker accused of stealing trade secrets for advanced chip-making equipment from his employer is now suspected of spying for the Chinese government.

China’s attempts to influence technical standards groups have mostly been uncoordinated, unsophisticated and unsuccessful – but the US needs to keep watch on Beijing’s activities, especially at the International Telecommunications Union.

View Details

https://cacm.acm.org/magazines/2023/3/270206-a-turning-point-for-cyber-insurance/fulltext
Insuring against the consequences of cybersecurity seems too good to be true given the underlying problem has perplexed researchers and practitioners for going on 50 years.

https://cacm.acm.org/magazines/2023/3/270207-mapping-the-privacy-landscape-for-central-bank-digital-currencies/fulltext
Payment records paint a detailed picture of an individual’s behavior. They reveal wealth, health, and interests, but individuals do not want the burden of deciding which are sensitive or private.

https://cacm.acm.org/magazines/2023/3/270211-the-ai-tech-stack-model/fulltext
Presently, enterprises have implemented advanced artificial intelligence (AI) technologies to support business process automation (BPA), provide valuable data insights, and facilitate employee and customer engagement.

https://www.theregister.com/2023/02/22/google_milestone_quantum/
Google is claiming a new milestone on the road to fault-tolerant quantum computers with a demonstration that a key error correction method that groups multiple qubits into logical qubits can deliver lower error rates, paving the way for quantum systems that can scale reliably.

https://telecoms.com/520115/mwc-2023-whats-the-point-of-5g/
Four years into the 5G era, the technology is still struggling to find an identity. 3G was about the introduction of mobile data, which matured in the form of 4G, but what is 5G all about?

https://www.theregister.com/2023/02/24/europe_gigabit_transformation_consultation/
The European Union yesterday decided it’s time to start “laying the ground for the transformation of the connectivity sector” in the region with three initiatives – one of which codifies the idea that Big Tech should pay for the networks that carry its traffic.

https://circleid.com/posts/20230222-brand-impersonation-online-is-a-multidimensional-cybersecurity-threat
Brand impersonation happens much more often than people realize. In CSC’s latest Domain Security Report, we found that 75% of domains for the Global 2000 that contained more than six characters from the brand names were not actually owned by the brands themselves.

https://circleid.com/posts/20230221-european-union-wants-to-fix-the-gdpr
In light of this, the European Commission is proposing a new law before the summer to improve how EU countries’ privacy regulators enforce the GDPR.

https://www.bloomberg.com/news/articles/2023-03-01/chatgpt-and-ai-are-all-companies-want-to-talk-about-in-earnings-calls
A lot of the companies tossing around the phrase AI are just taking advantage of the hype. Some are speaking aspirationally about how they see AI transforming their businesses — one day, some day.

https://www.theregister.com/2023/03/03/online_privacy_tracking/
But according to a trio of privacy researchers, opting out doesn’t always work – visitor data still gets collected.

https://telecoms.com/520384/mwc-2023-recap-whats-the-point-of-telecoms/
When we asked the operator figure what the point of telecoms is they said it’s “very uncertain”. The danger of becoming a ‘dumb-pipe’ utility seems greater than ever.

https://circleid.com/posts/20230227-domains-under-the-most-abused-tlds-same-old-dns-abuse-trends
While threat actors can use any domain across thousands of top-level domains (TLDs), they often have favorites. For instance, you may be familiar with Spamhaus’s 10 most-abused TLDs for spamming.

https://www.freecodecamp.org/news/oss-security-best-practices/
Typosquatting, also known as URL hijacking, is a form of cyber attack where an attacker registers a domain name that is similar to a well-known website, but with a slight typo.

https://www.theregister.com/2023/02/28/mit_researchers_interference_busting_radios/
Radio interference can be a pain to deal with, regardless of whether it’s a rogue baby monitor interrupting your Wi-Fi or a stadium full of smartphone signals drowning each other out.

https://circleid.com/posts/20230228-internet-shutdowns-on-the-rise-worldwide-says-report
From the Middle East to South Asia to Africa, shutdowns are becoming a norm of authoritarianism—an accepted means of silencing criticism, stifling dissent, and controlling the population.

View Details

A decade ago, waferscale architectures were dismissed as impractical. Five years ago, they were touted as a fringe possibility for AI/ML. But the next decade might demonstrate waferscale as one of only a few bridges across the post-Mooreâ€s Law divide, at least for some applications.

This is not a ‘silver bullet’, however. In comparison to the sophisticated deception available in traditional IT security, deception in ICS still faces some challenges.

As a numbers guy, Iâ€m always intrigued by the Ookla Speedtest Global Index since it provides an interesting look at broadband speeds in the U.S. and around the world.

Two new separate sets of research released this month underscore real, hidden dangers to physical operations in today’s OT networks from wireless devices, cloud-based applications, and nested networks of programmable logic controllers (PLCs) — effectively further dispelling conventional wisdom about the security of network segmentation as well as third-party connections to the network.

As organizations strengthen their defenses and take a more proactive approach to protection, attackers are adapting their techniques and increasing the sophistication of their operations.

As the security of the Android Platform has been steadily improved, some security researchers have shifted their focus towards other parts of the software stack, including firmware.

Some of Europeâ€s biggest telcos have outlined their goals for the progression of Open RAN technology this year and beyond, including a suggestion of commercial launches in the near future.

Networks connected to the Internet rely on other networks – a.k.a, Autonomous Systems, or ASes – to transmit data. Consequently, the connectivity of a network depends on the connectivity of other networks. AS Hegemony is a metric to evaluate these interdependencies based on BGP data collected from public large-scale measurement platforms (RIPE RIS and Route Views).

Most recently, one tinkerer named Peter Fairlie took to YouTube armed with a Flipper Zero to answer a repeatedly asked question: can the device change a traffic light from red to green? As it turns out, the answer is “yes,” but not in the way you might think.

Roughly 109,000 technology industry employees from 392 companies have been laid off since the start of the year, according to the industry employment tracking website Layoffs.Fyi.

The next time you buy a flashy new outfit after browsing Instagram, or tap the heart button on a particularly compelling TikTok video, you might discover that the person who posted it isn’t real—and you might not care at all.

Privacy regulations around the world frequently include requirements for websites and apps to obtain informed consent from users prior to collecting, processing, or sharing their personal information, or to provide easy opportunities for users to opt-out of certain uses of their data.

View Details

In Emoi Services LLC v. Owners Insurance Company, the Ohio Supreme Court recently found software is an intangible item that cannot experience direct physical loss or damage and, therefore, the plaintiffâ€s inability to access or use its software during a ransomware attack was outside the scope of its “businessowners” policy.

Searching Google for downloads of popular software has always come with risks, but over the past few months, it has been downright dangerous, according to researchers and a pseudorandom collection of queries.

Here’s a provocative question: Is it possible, given the vast array of security threats today, to have too many security tools?

This debate has proved futile for two reasons. First, the characteristics of any specific application will dictate which venue is more expensive — there is no simple, unequivocal answer. Second — the question implies that a buyer would choose a cloud or on-premises data center primarily because it is cheaper. This is not necessarily the case

The RISC-V architecture looks set to become more prevalent in the high performance computing (HPC) sector, and could even become the dominant architecture, at least according to some technical experts in the field.

Major US carriers are exaggerating the availability of fixed wireless services and leaving under-served communities at risk of missing out on billions in federal funding that would pay for improved services.

But not all small ISPs are expanding, or are only expanding in small increments. Today I want to talk about the reasons Iâ€ve been given by ISPs that have decided to not expand.

It was another bad week for tech professionals amid further bloodletting by an industry feeling the squeeze of inflation and higher interest rates as Microsoft, Zoom and Yahoo all dished out the pink slips.

To measure the impact of sound on office workers, researchers asked 231 of the agencyâ€s employees working in four buildings across the US to wear two devices for three days.

As adults, many people hold onto items with the thought they might need it in the future, or they hope their children will want it one day.

This post is an introduction and comparison of network automation tools Paramiko, Netmiko, NAPALM, Ansible and Nornir.

In our paper, ‘Mind Your MANRS: Measuring the MANRS Routing Ecosystem‘, we at CAIDA (UC San Diego), in collaboration with Georgia Tech, and IIJ Research Lab, provided the first independent look into the MANRS ecosystem by using publicly available data to analyse the routing behaviour of participant networks.

View Details

Threat actors have been targeting Zoom and its users since the platformâ€s launch, and itâ€s easy to see why—the latest stats show it accounts for 3.3 trillion annual meeting minutes worldwide.

To get a sense of how fragile the innovation business is, keep in mind the popular wisdom that teaches us how nine out of ten startups will fail.

Over a 30-month period, cybercriminal gangs and threat groups posted more than 200,000 advertisements seeking workers with skills in software development, maintaining IT infrastructure, and designing fraudulent sites and email campaigns.

On 24-27 April, a 33-year-old international organisation of ICT organisations will convene a meeting at London under ETSI auspices after a four-year hiatus.

As the topic of domain-driven design (DDD) recently came up at my current job, I decided to get more familiar with the topic by reading Eric Evanâ€s book “Domain-Driven Design: Tackling Complexity in the Heart of Softwareâ€. This was a mistake.

Big Tech results reinforced concerns a boom in cloud services is easing, limiting a lucrative source of profit when a slowing economy has hit the companies’ other businesses and prompting a bet on artificial intelligence as the next growth driver.

And all of that is on a computer, on a network, and attached to the Internet. Like everything else, these systems will be hacked through vulnerabilities in those more conventional parts of the system.

The unemployment rate in the technology job market decreased for the second month in a row, dropping to 1.5% in January from 1.8% in December.

Wi-Fi 6 hardware is now common, and thereâ€s a good chance you have both a Wi-Fi 6 network and Wi-Fi 6 compatible devices. But people are already talking about something new: Wi-Fi 6E, which promises to reduce Wi-Fi congestion further.

Anybody who can read a financial report knows they are paying too much for compute, storage, networking, and software at Amazon Web Services

In a letter to the US Environmental Protection Agency (EPA) Monday a small group of Democrats called on the agency to enact policies designed to force US crypto-mining operations to report their annual energy consumption.

The way things sit now, if you were somehow allergic to computers, you’d be hard pressed to really banish them from your life, no matter where you found yourself.

Organizations using older versions of VMWare ESXi hypervisors are learning a hard lesson about staying up-to-date with vulnerability patching, as a global ransomware attack on what VMware has deemed “End of General Support (EOGS) and/or significantly out-of-date products” continues.

With reports that more than half of US states have banned or restricted access to TikTok on government devices, many cybersecurity professionals are asking, “How can you take a well-intentioned policy from vision to execution?” The answer is operational governance.

Enterprise spending on cloud infrastructure services slowed in the fourth quarter of 2022, but that didn’t stop the big three platforms from taking two-thirds of the entire market.

View Details

Yann LeCun, Metaâ€s chief AI scientist, is not impressed by ChatGPT, the wildly popular artificial intelligence technology that is making headlines daily.

German antitrust enforcers known for leveling charges against high-profile tech companies have a new target for accusations of dominant market position abuse: PayPal.

Data anonymization is an important tool for organizations to protect the personal data of individuals, while averting the onerous requirements of the EU and U.K.

Phishing is a big deal, with a State of Phishing report from security firm SlashNext claiming that there were more than 255 million phishing attacks in 2022, a 61% increase from the year before.

The goal of the CGA is to highlight and reduce damages done to all utilities when working underground.

More than 91% of malware utilizes DNS communication at some point during its attack lifecycle, making DNS an invaluable choke point in the fight against cyber threats.

When it comes to operating systems and now CPU instruction sets, there is proprietary, there is licensable and modifiable with a standard base of functionality with room for some originality, and there is true open source.

Since 2017, China has held at least seven of these competitions—called Robot Hacking Games—many with multiple qualifying rounds.

Extortion, and especially “sextortion†emails, are becoming more frequent, and they can be extremely alarming when received. Such emails work by using threats to extort money, evoking intense fear.

2022 was an impactful year in the fight against ransomware. Ransomware attackers extorted at least $456.8 million from victims in 2022, down from $765.6 million the year before.

ECTA also denounced the Commission for not subjecting its proposals to public consultation, and for attempting to overrule the European Electronic Communications Code (EECC). It called on the Commission to rework the proposals to account for the positive impact made by altnets on investment and citizens†interests. It also demanded that the Commission prepare an impact assessment and conduct a public consultation.

These panic-inducing scenarios are familiar to most modern IT and security leaders and share something in common. Each hypothetical breakdown is the result of employees — and the digital public as a whole — being lulled into a false sense of security regarding their online behaviors.

Analyst Gartner predicts that worldwide shipments of PCs, tablets and mobile will drop 4.4% this year, which would mean the second consecutive year of decline. But there is perhaps some light at the end of the tunnel.

Hundreds of CISOs, CSOs, and security leaders, whether from small or large companies, don’t know either. No matter the organization’s size, the certifications, tools, people, and processes: secrets are not visible in 99% of cases.

Itâ€s been a bad few months for password managers — albeit mostly just for LastPass. But after the revelations that LastPass had suffered a major breach, attention is now turning to open-source manager KeePass.

View Details

The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could lead to a denial-of-service (DoS) condition.

Going into 2023, phishing is still as large a concern as ever. “If it ainâ€t broke, donâ€t fix it,†seems to hold in this tried-and-true attack method.

This follow-up post describes what techniques exist to enumerate subdomains in a DNSSEC-enabled zone and what countermeasures exist to prevent it. DNSSEC itself is not explained further, however, some relevant record types are briefly described.

In 1987 economics Nobel Laureate Robert Solow said that the computer age was everywhere—except in productivity data. A similar thing could be said about AI today: It dominates tech news but does not seem to have boosted productivity a whit.

Names such as Novelli, orangecake, Pirat-Networks, SubComandanteVPN, and zirochka are unlikely to mean anything to a vast majority of enterprise security teams.

Decision-makers might wonder — is investing time and resources in Resource Public Key Infrastructure (RPKI) worth it? What is the effectiveness of RPKI Route Origin Validation (ROV)? In the last year, a number of interesting reports were published.

In pursuit of ever-higher compute density, chipmakers are juicing their chips with more and more power, and according to the Uptime Institute, this could spell trouble for many legacy datacenters ill equipped to handle new, higher wattage systems.

Today Kaspersky researchers reported on a new domain name system (DNS) changer functionality used in the infamous Roaming Mantis campaign.

Academic researchers have discovered serious vulnerabilities in the core of Threema, an instant messenger that its Switzerland-based developer says provides a level of security and privacy “no other chat service†can offer.

Blockchain domain names, domains that are stored on blockchain or cryptocurrency exchanges, are part of a growing, unregulated, and decentralized internet.

I know there is instant hope among students that this software can churn out the dreaded school essay – but that doesnâ€t look likely.

In this post, you will learn about the single most important and useful tool in Computer Networks – Wireshark.

Amid volatile times and gloomy predictions for 2023, low-code/no-code (LCNC) adoption continues to grow rapidly.

There is a ton of data captured, but the main takeaway seems to be around the additional cybersecurity threats presented by the boom in IoT products – with households filling up with connected gizmos, it would appear hackers are being provided with extra vectors of attack to try and scam people or steal data.

But want to know what long-term problem is keeping the smart members of the network leadership of enterprises up at night? Itâ€s an empty chair. Their chair, at the table that makes the plans that set network requirements and directions today and for years to come.

View Details

As this technology is perfected, AI writing may render most of the English composition curriculum and other writing skills irrelevant. Like penmanship being displaced by word processors, and memorization by books or databases, writing itself may soon be seen as an archaic novelty.

How to properly balance the commercial rights of a complainant with the free speech rights of a respondent has challenged a generation of Uniform Domain Name Dispute Resolution Policy (UDRP) panelists.

New York City Mayor Eric Adams responded to criticism over increasing the use of facial recognition technology by declaring, Big Brother is protecting you!

Whether someone will get a loan for buying a house is dependent on the opaque policy instantiated in some black box algorithm. Ditto whether someone’s parole application will get approved, some startup entrepreneur will get capital for his venture, or someone on an organ donation waitlist will get his life-saving treatment.

Blaise Arcas, the head of Google’s AI group in Seattle, recently argued that although large language models (LLMs) may be driven by statistics, statistics do amount to understanding.

Crypto bros still blather on about how their Bitcoin, Ethereum or what have you will go to the Moon. They also insist that with their diamond hands, they’re going to Hold On for Dear Life (HODL) no matter what happens.

I believe the conventional idea of “writing a program” is headed for extinction, and indeed, for all but very specialized applications, most software, as we know it, will be replaced by AI systems that are trained rather than programmed.

omona College business and investments prof Gary Smith warns Salon readers not to be too gullible about what human-sounding chatbots really amount to.

I don’t know about you, but there are days when I wake up with an urgent need to escape from this digital jungle, this plastic world, in which we have exchanged feelings for tons of made-up ones and zeros.

View Details

However, since growing online content consumption put networks under increasing pressure during the peaks of the Coronavirus lockdowns, some political support in Europe seems to have been garnered (e.g. France, Italy, and Spain).

On the other hand, the digital sphere has become a dangerous space. The Ukrainian war pulled cyber into real military fighting.

The recent adoption at the end of December of the new EU Directive for a high level of cybersecurity across the Union—commonly referred to as “NIS2â€â€”paved the way for important updates to the domain name system (DNS).

Domain names are associated with the full spectrum of internet content, from legitimate use by brands or individuals, to infringing or criminal activity. CSC has observed that certain TLDs get used more for egregious content.

Heata has developed a novel way to use the waste heat generated by servers: mounting them on domestic hot water tanks to cut energy bills for homeowners.

It’s time for you and your colleagues to become more skeptical about what you read. That’s a takeaway from a series of experiments undertaken using GPT-3 AI text-generating interfaces to create malicious messages designed to spear-phish, scam, harrass, and spread fake news.

Randy Anders is VP of North American sales with HughesNet for Business. He said HughesNet has been providing SD-WAN to enterprise customers for several years, using its GEO satellite connectivity.

The US Federal Aviation Administration (FAA) has given airlines until February 2024 to fix altimeters that may clash with C-band 5G spectrum.

Itâ€s a good idea to use one of the best password managers to keep your logins safe, but now a security company is warning that one of the most popular password managers in the world is not safe to use.

In early January, development-pipeline service provider CircleCI warned users of a security breach, urging companies to immediately change the passwords, SSH keys, and other secrets stored on or managed by the platform.

Security teams have traditionally used mean time to repair (MTTR) as a way to measure how effectively they are handling security incidents. However, variations in incident severity, team agility, and system complexity may make that security metric less useful.

In a recent paper, my fellow researchers from Freie Universität Berlin, The Fraunhofer Institute for Open Communication Systems, and HAW Hamburg and I revisited QUIC connection setup performance.

Getty Images is suing Stability AI, creators of popular AI art tool Stable Diffusion, over alleged copyright violation.

United Kingdom leaders are pushing forward with a massive online censorship bill that, thanks to the lobbying of a group of lawmakers over the weekend, has been made significantly harsher with threats of imprisonment for tech platform managers who run afoul of the complicated regulations.

The laptops of 2023 will get new chips and new graphics. Many will get new touchpads, some will get new fans, and a few will get funky styluses. But some of the coolest, weirdest, and most exciting updates are coming to screens.

View Details

Want to be Bigger? Faster? Stronger? Such questions are a staple in exercise and health media, but those same questions are raised in the tech industry as well.

TAU-SAT3, launched Tuesday on a SpaceX rocket from Cape Canaveral in Florida, will pave the way towards quantum communication via a nanosatellite, Tel Aviv University reported on Wednesday.

If you deal with Web Performance, youâ€ve probably heard about HTTP resource prioritization. This is especially true since last year, as Chromium added so-called “Priority Hints†with the new fetchpriority attribute, which allow you to tweak said prioritizations.

Last Fall, SpaceX broadened the definition of Gen2 to include three configurations, designated F9-1, F9-2, and Starship.

eBPF brought with it a vast amount of software, including software-defined networking (SDNs), observability projects, and security-based software.

Historically, the only option to connect processor cores and memory have been proprietary interconnects such as InfiniBand, PCI Express and other protocols that connect compute clusters with offloads but for the most part that wonâ€t work with AI and its workload requirements.

Over the next few months, we found as many car-related vulnerabilities as we could. The following writeup details our work exploring the security of telematic systems, automotive APIs, and the infrastructure that supports it.

Within seven years of this pamphlet, Congress passed the Telecommunications Act of 1934, which put some regulatory restraints on the large Bell Telephone monopoly that was gobbling up telephone systems across the country.

Confidential computing segregates data and code from the host computer’s system and makes it harder for unauthorized third parties to access the data.

Three big analyst firms published stats this week that made for grim reading. The consensus from Gartner, IDC, and Canalys is that fourth quarter shipments came in at somewhere around 65-68 million units, down almost 30% compared to last year.

Public announcement of the 433-qubit IBM Quantum Osprey processor at the 2022 IBM Quantum Computing Summit on Nov. 9 represents another evolutionary milestone in the development of universal quantum computers.

A research paper that claimed a quantum breakthrough that could “challenge RSA-2048” encryption received significant attention in the past week, followed by significant criticism as experts weighed in.

ReversingLabs urges organizations, specifically npm and PyPI package users, to double down on securing their networks, and part of that could be better detection and blocking of access to suspicious and malicious web properties related to threats like IconBurst and Material Tailwind.

Having been involved in this sector for over fifteen years now, the rate of change in the market dynamics continues to surprise me—from its early years when MarkMonitor and NetNames clearly led the space for several years, then seeing well-funded startups such as Yellow Brand Protection and Incopro challenge that, followed by a period of heavy M&A, it is now extremely diverse.

Last week, Ireland’s Data Protection Commission fined Meta 390 million euros — 210 million euros against Facebook and 180 million euros against Instagram.

View Details

Undersea cables between the U. S. and Cuba have long been intertwined with politics.

People like to tout NISTâ€s SP 800-207 [Zero Trust Architecture] as the hot new thing, but the fact is, zero trust network models have been around for over a decade.

As Russian ground troops prepared to enter Ukraine in February 2021, Ukrainian governmental departments, online media organizations, financial firms, and hosting providers were slammed with a surge of distributed denial-of-service (DDoS) attacks.

Prosecutors said the five IT officials of the public administration department had failed to check the security of the system and update it with the most recent antivirus software.

What exactly is the edge? What makes something an edge appliance? These are trickier questions than you might think, and depending on who you ask — and honestly, what theyâ€re trying to sell you — the answers can vary wildly.

Youâ€ve likely been hearing about the World Wide Web Consortiumâ€s (W3C) Web Authentication (WebAuthn) and considering whether youâ€re ready to implement it in your environment.

In this episode of PING, Luuk Hendricks and Willem Toorop from NLNet Labs discuss applying Express Data Path (XDP) to the DNS protocol.

A recent report spelled it out in stark detail. Across all industries, the average ransom paid is a hefty $812,360. Yet for manufacturing, that average skyrockets to a stunning $2,036,189 — about two and a half times the average.

This article is a continuation of a series that presents the Overlay Multilink Network Interface (OMNI) and Automatic Extended Route Optimization (AERO) services.

Quantum computing has a crucial weakness that may severely delay, if not kill outright, its chances of becoming a way of running algorithms that classical computers cannot handle: its susceptibility to noise.

Organizations tolerate all this complexity (and the delays and costs that come with it) since they see no alternative. But what if there was an easier way? Iâ€ll examine the two fundamental shifts driving software development and IT operations and see why current processes are so cumbersome.

WhoisXML APIâ€s IP intelligence now includes Regulatory Compliance IP Data Feeds available as separate IP geolocation and IP netblocks files.

While the vast majority of software in usage today doesnâ€t use a microservice architecture, it has been hailed as the best way to build “cloud native†software for almost a decade now.

Instead of jumping straight from a 32GB DIMM to a 64GB one, DDR5, for the first time, allows for half steps in memory density. You can now have DIMMs with 24GB, 48GB, 96GB, or more in capacity.

Integer factorization has been one of the most important foundations of modern information security.

View Details

Today, we released the latest issue of The Domain Name Industry Brief, which shows that the third quarter of 2022 closed with 349.9 million domain name registrations across all top-level domains, a decrease of 1.6 million domain name registrations, or 0.4%, compared to the second quarter of 2022.

Since 2019, unpatched ESXi servers have been targets of ongoing in-the-wild attacks based on two vulnerabilities in the ESXiâ€s OpenSLP service: CVE-2019-5544 and CVE-2020-3992.

In many cases, once a high-risk security vulnerability has been identified in a product, a bigger challenge emerges: how to identify the affected component or product by its assigned name in the National Vulnerability Database (NVD).

A developer’s cryptographic signing key is one of the major linchpins of Android security. Any time Android updates an app, the signing key of the old app on your phone needs to match the key of the update you’re installing.

Hashing is one of the pillars of cybersecurity. From securing passwords to sensitive data, there are a variety of use cases for hashing.

Cloud gaming needs wide access to 5G networks to thrive. Performance requirements for streaming the latest AAA titles on mobile devices are already high and are likely to increase as the industry adopts AR and VR devices, with the future growth of AR and VR devices also incentivizing telecom providers to bundle and/or upsell.

Did you know over 93% of all malware employs DNS as a mechanism to identify and contact its command and control (C2) to receive instructions? This is why a truly holistic cybersecurity strategy must include protection from malicious domains.

Today, we are glad to release the third version of the threat matrix for Kubernetes, an evolving knowledge base for security threats that target Kubernetes clusters.

The software industry is making headway against a group of pernicious vulnerabilities that are responsible for the vast majority of critical, remotely exploitable, and in-the-wild attacks, software-security experts said this week.

PCI DSS 4.0 was released in March 2022 and will replace the current PCI DSS 3.2.1 standard in March 2025. That provides a three-year transition period for organizations to be compliant with 4.0.

Arista Networks has a new high-end data-center switch as well as several smaller ones designed to provide more configuration and upgrade choices to fit the specific needs of individual organizations.

However, I’m going to ask an awkward question, one that has been burning in my mind for a while. What really happens to that data once you click “delete” on a cloud service?

Ofcomâ€s data shows that 97 percent of UK homes now have access to superfast broadband, defined as a downstream connection of 30 Mbps or more. While 27 percent of those who can access superfast broadband have yet to take up such services, Ofcom doesnâ€t seem particularly keen to persuade them to do so.

The European Telecommunications Standards Institute (ETSI) has unveiled a new Industry Specification Group (ISG) to undertake preliminary work on the potential use of terahertz frequencies in 6G communications.

NuGet, PyPi, and npm ecosystems are the target of a new campaign that has resulted in over 144,000 packages being published by unknown threat actors.

View Details

Simply put, we have been right all along, and we now have the conflicting circuit court precedent to prove it. The Supreme Court needs to consider the Fourth Circuitâ€s arguments and address this split between circuits.

Do we let Big Tech have access to our private communications and free email accounts because itâ€s so easy? Once youâ€ve said yes — and who among us has not? — itâ€s not a stretch to think that Big Data already has almost all your information, so why get picky at the next juncture?

Internet infrastructure services—the heart of a secure and resilient internet where free speech and expression flows—should continue to focus their energy on making the web an essential resource for users and, with rare exceptions, avoid content policing.

Then Elon announced Apple, the most powerful company in the world, threatened to remove Twitter from the app store.

A California judge has cleared the way for a potentially massive class-action lawsuit against Google, which stands accused – again – of anticompetitive practices surrounding its Play store.

There is a growing trend in American culture of what the literary theorist Peter Brooks calls “storification.â€

Targeted advertisingâ€s days may be numbered. The Wall Street Journal and Reuters report that the European Data Protection Board has ruled that Meta cannot continue targeting ads based on userâ€s online activity without affirmative, opt-in consent.

The Council of the European Union this week adopted new language for regulations governing internet systems that may put the security of your browser at greater risk.

Since the dawn of digital marketing, people have been asked to provide their personal information in exchange for information online. This “information swap” is still a common digital tactic.

View Details

In this article, I will explain how SSHFP DNS records can help mitigate such risks and share the results of our large-scale analysis.

A vulnerability in IBM Cloud databases for PostgreSQL could have allowed attackers to launch a supply chain attack on cloud customers by breaching internal IBM Cloud services and disrupting the hosted system’s internal image-building process.

Amazon Web Services has signaled that the future of cloud computing cannot rely alone on general-purpose chips with its new Graviton3E silicon, joining AMD and Intel in introducing specialized central processing units that are meant to perform certain applications faster and more efficiently.

A recent statement from Italyâ€s data protection authority, the Garante, opens a new chapter in the never-ending story of profiling cookies.

While analyzing its capabilities, Akamai researchers have accidentally taken down a cryptomining botnet that was also used for distributed denial-of-service (DDoS) attacks.

Biometrics is supposed to be one of the underpinnings of a modern authentication system. But many biometric implementations (whether that be fingerprint scanes or face recognition) can be wildly inaccurate, and the only universally positive thing to say about them is they’re better than nothing.

Geolocation providers usually focus on locating end user devices at the edge of the Internet. But what about the machines that make up the infrastructure in the middle?

There are certainly plenty of myths in the industry about OpenRAN, and today I hope to eradicate one of them: OpenRAN will be deployed anywhere and everywhere, including the busy city centres.

The SMO provides a central interface for application configuration and provisioning. It also automates both infrastructure management processes and the creation of new services through southbound APIs (O2-IMS & O2-DMS).

There is a common misconception that all problems have clear, straightforward solutions — as long as you look hard enough. While this is a bold and ambitious goal, it’s misguided when applied to cybersecurity.

How valuable is it to keep older solutions like this running? Well, organizations don’t enjoy running old legacy systems just for the pleasure of it, but they’re often forced to keep them running because it’s their only option, or at least the only cost-effective option available to them.

Securing critical infrastructure is complicated because of the vast network of facilities and management systems. Threats targeting this sector can have dire consequences, and when attacks do happen, they’re often accompanied by a media storm.

The European tech industry saw $400 billion in value wiped out this year and an 18% decline in venture capital funding, according to a report from venture capital firm Atomico.

Fondly referred to as “spinning rust†among some computer nerds, mechanical hard drives seem almost quaint compared to hyper-fast SSDs. Yet, the idea that mechanical hard drives are ready for the trash pile may be more than a little premature.

Conventional wisdom says that trying to attach system memory to the PCI-Express bus is a bad idea if you care at all about latency. The further the memory is from the CPU, the higher the latency gets, which is why memory DIMMs are usually crammed as close to the socket as possible.

View Details

Nearly every application has at least one vulnerability or misconfiguration that affects security and a quarter of application tests found a highly or critically severe vulnerability, a new study shows.

75% of lookalike domains are registered with unrelated third parties and target these companies.

China’s antitrust watchdog, the State Administration for Market Regulation (SAMR), has proposed a revision of the nation’s competition law that targets tech firms.

A new report claims that Metaâ€s tracking Pixel has been used to collect your financial information when using popular tax filing services to send in your return.

Did you know that a Magniber ransomware infection can cost you a ransom of as much as US$2,500?

New York State has banned a practice becoming more common in the crypto-mining industry – the rescuing and repurposing of mothballed fossil fuel plants to exclusively provide energy for mining digital currency.

DDoS attacks target certain networks, flooding them with unwanted traffic from many different sources and causing interruptions to online services for legitimate users.

John the Ripper (JtR) is a popular password-cracking tool. John supports many encryption technologies for Windows and Unix systems (Mac included).

While in the near future most devices in the car will be connected through zonal switches, cameras are the exception. They will continue to connect to processors over point-to-point protocol (P2PP) links using proprietary networking protocols such as low-voltage differential signaling (LVDS), Maximâ€s GMSL or TIâ€s FPD-Link.

Before we start, let’s get one thing perfectly clear: The entire and only reason for writing reports like this one is to avoid repeating the same mistake—no more, no less. Assigning guilt, placing blame, exposing incompetence, or getting people fired is not CSRB’s job. It investigates; the rest of us act.

U.S. regulators have imposed a ban on electronic equipment created by several major Chinese tech corporations, citing national security concerns.

View Details

So in terms of the daily lived experience of most people reading this, truly autonomous vehicles just aren’t going to happen.

When the federal government gets together with social media giants to censor critics of the government, is that free speech or censorship?

If you own an advanced Android phone, you may find that Google Assistant will interrupt conversations to offer its own “insights”. Google is also pursuing “prebunking” of what it considers “misinformation” with preemptive propaganda campaigns.

The outcomes of such a system are incentives to not be the new person on a team, to not ask questions, to not work on new and unfamiliar efforts, and to not work together at all generally. Those behaviors become embedded in an organization’s DNA, despite whatever is advertised publicly.

Today’s business headlines herald a harsh reality for Big Tech: tumult at Twitter; meltdown at Meta; atrophy at Alphabet; adjustments at Amazon. Layoffs, sliding stock and shrinking valuations are hallmarks of the moment.

To understand the sudden downfall of the now-collapsed crypto exchange FTX, you have to go back to the beginning.

Twitter was their home. Elon broke into their home. Then he kicked out their friends, and told everyone left to do their laundry.

View Details

Internet users are being tricked into installing browser extensions that can hijack their web searches.

An offshore company that is trusted by the major web browsers and other tech companies to vouch for the legitimacy of websites has connections to contractors for U.S. intelligence agencies and law enforcement, according to security researchers, documents and interviews.

Silicon Valley startup Eliyan thinks its technology for enabling chiplet-based designs can best those from semiconductor giants Intel and TSMC by providing better performance, higher efficiency, fewer manufacturing issues, and more supply chain options.

While the number of cleartext passwords is an improvement compared with the 96,361 passwords exposed in 2020 and the more than 100,000 sent in the clear in 2019, there is still room for improvement, says Jessica Bair Oppenheimer, director of technical alliances at Cisco Secure.

Qualcomm and Arm have been engaged in one of those very entertainingly bitter court fist-fights that the industry throws up when friends fall out over money.

Unbound 1.16.0 adds support for Extended DNS Errors (EDEs) as codified in RFC 8914.

I suspect this reflects a significant change in the economics of the sector. For the last 20 years, Silicon Valley has had the wind at its back thanks to rapid adoption of new technologies like the internet and smartphones. As a result, the industry fared better than the broader economy during and after the 2008 recession.

By playing unexpected moves outside of KataGo’s training set, a much weaker adversarial Go-playing program (that amateur humans can defeat) can trick KataGo into losing.

New research released this week reveals the process used by third party advertisers to target online users can be viewed or manipulated by online adversaries using only their target’s email address.

On August 4, 2022, Microsoft publicly shared a framework that it has been using to secure its own development practices since 2019, the Secure Supply Chain Consumption Framework (S2C2F), previously the Open Source Software-Supply Chain Security (OSS-SSC) Framework.

This raises an important question: How do you take what is good about these patterns for creating innovation? Specifically, how do you apply open source principles and practices as appropriate? That’s what we’ve sought to accomplish with Red Hat Research.

Thousands of smartphone applications in Apple (AAPL.O) and Google’s (GOOGL.O) online stores contain computer code developed by a technology company, Pushwoosh, that presents itself as based in the United States, but is actually Russian, Reuters has found.

Thatâ€s opened major questions about how these now-forever-roaming workers are connected to information resources and to each other.

A novel attack method has been disclosed against a crucial piece of technology called time-triggered ethernet (TTE) that’s used in safety-critical infrastructure, potentially causing the failure of systems powering spacecraft and aircraft.

View Details

https://www.darkreading.com/risk/build-security-around-users-a-human-first-approach-to-cyber-resilience

User-first security must begin with an understanding of how people use computing technology. We have to ask: What is it that makes users vulnerable to hacking via email, messaging, social media, browsing, file sharing?

How does the industry effectively assess software security, enabling an approved list (allowlist) of software and libraries on distributed systems across multiple industries?

The COVID pandemic pushed a lot of school coursework to the internet, with an increased reliance on true/false and multiple-choice tests that can be taken online and graded quickly and conveniently.

Top chipmakers Nvidia, Intel, ARM, and AMD are providing the hardware hooks for an emerging security concept called confidential computing, which provides layers of trust through hardware and software so customers can be confident that their data is secure.

Rather than ensuring security, the focus across the software development life cycle (SDLC) is beating the competition to market. In fact, innovation is often seen at odds with security — the former believed to be fast-paced and productive, and the latter a roadblock that stifles quick-moving application development.

Responding to a recent surge in AI-generated bot accounts, LinkedIn is rolling out new features that it hopes will help users make more informed decisions about with whom they choose to connect.

Several models have been proposed to the Multi-State Information Sharing and Analysis Center (MS-ISAC) and other ISACs for a role in software assurance for supply chains using the Software Bill of Material (SBOM) information and associated digital signatures.

A lack of precision in our terminology leads to misunderstandings and confusion about the activities we engage in, the information we share, and the expectations we hold.

As has happened with other Web technologies designed for legitimate use, the InterPlanetary File System (IPFS) peer-to-peer network for storing and accessing content in a decentralized fashion has become a potent new weapon for cyberattacks.

Tests show that deploying malware in a persistent manner on load balancer firmware is within reach of less sophisticated attackers.

This fall, Microsoft claimed to have addressed anticompetitive cloud infrastructure complaints from a few smaller cloud services providers in Europe.

The findings suggest a loose but visible alignment between Russian government priorities and activities and ransomware attacks leading up to elections in the six countries.

Meta, formerly Facebook, once seemed an impenetrable fortress, but it’s now showing big cracks.

As a security researcher, common vulnerabilities and exposures (CVEs) are an issue for me — but not for the reason you might think.

That will be one of the reasons crypto has been plummeting for most of this year but recent events have intensified the sense of crisis.

View Details

The recent rise of HTTP request smuggling has seen a flood of critical findings enabling near-complete compromise of numerous major websites. However, the threat has been confined to attacker-accessible systems with a reverse proxy front-end… until now.

Eternity typically keeps its activities on the down low—in the Dark Web. Still, we sought to determine if LilithBot and Eternity also engaged in dealings on the Surface Web.

The Financial Conduct Authority, the UK's financial services regulator, has begun discussions with the aim of understanding the impact of Big Tech on industry competition.

View Details

Data security in the public cloud has been a concern since the computing medium emerged in the mid-2000s, but cloud providers are allaying fears of theft with a new concept: confidential computing.

Fewer than half of 5G users say they've experienced improvements in speed or reliability over 4G according to a new survey, but that is not going to stop some in telecoms pushing ahead with efforts to deliver an enhanced version branded 5.5G.

So we should all be concerned that Mark Cox, a Red Hat Distinguished Software Engineer and the Apache Software Foundation (ASF)'s VP of Security, this week tweeted, "OpenSSL 3.0.7 update to fix Critical CVE out next Tuesday 1300-1700UTC."

View Details

A Chinese law that went into effect six months ago required online service providers to file details of the algorithms they use with China’s centralized regulator, the Cyberspace Administration of China (CAC).

How is deep learning going to assist rather than replace the average creative worker? If replacement is the goal — valid, by the way, if a net positive for humanity — are we paying the people responsible for work the models have been trained on?

Since the WSJ and a viral TikTok video made quiet quitting a cultural phenomenon, it seems as though every news outlet, Fortune 500 CEO, lifestyle coach, or entry-level employee has something to say about quiet quitting.

View Details

New research has disclosed what's being called a security vulnerability in Microsoft 365 that could be exploited to infer message contents due to the use of a broken cryptographic algorithm.

Telcos deal with a considerable amount of multivendor devices. Although many hope/expect that these are equipped with state-of-the-art telemetry technologies, most of the time they’re not

Concerns over a critical authentication bypass vulnerability in certain Fortinet appliances heightened this week with the release of proof-of-concept (PoC) exploit code and a big uptick in vulnerability scans for the flaw.

View Details

https://potsandpansbyccg.com/2022/10/06/pinpointing-urban-broadband-gaps/ The City of Chicago asked some researchers at the University of Chicago for help to identify the neighborhoods and the number of households that are not connected to broadband.

https://circleid.com/posts/20221006-solving-the-.us-registrant-data-directory-services-rdds-conundrum Recently ten Democratic Members of Congress wrote a letter to Alan Davidson, head of the NTIA, requesting that the “NTIA immediately cease the public disclosure of personal information about users of .US” country code top-level domain (ccTLD).

https://circleid.com/posts/20221005-four-steps-to-an-effective-brand-protection-program This makes a comprehensive, holistic brand protection program crucial for any brand owner, including monitoring to identify potentially damaging third-party content, and using enforcement strategies to take down infringing material

View Details

Meta Platforms Inc. Chief Executive Officer Mark Zuckerberg outlined sweeping plans to reorganize teams and reduce headcount for the first time ever, calling an end to an era of rapid growth at the social media giant.

A food delivery drone operated by Alphabet subsidiary Wing landed on overhead power lines in Brisbane, Australia, and caught fire. As a result, the network was shut down by energy firm Energex to respond to the incident, leaving thousands without power.

If you know about DNS, you've probably heard of the Time-to-Live (TTL) field. But mistakes with TTL are more common than you might think. Here we look at the quirks of DNS record sets, parent/child domains and how to avoid TTL problems.

View Details

Indeed, Juniper Research predicts that operator 5G FWA revenue will reach $24 billion worldwide by 2027, driven essentially by the use of the technology as a fibre replacement for consumer services.

Floppy disks may have gone the way of the dodo and joined other extinct media such as punched cards and paper tape, but some people are apparently still using them, and one company even continues to sell them.

Many companies also have changed how they operate, from having to deal with a more remote hybrid workforce to adapting to supply chains that have yet to completely rebound from the battering they took during the pandemic.

View Details

Arm says Nvidia’s Grace processor will be among the first chips to use its upcoming Neoverse V2 CPU cores.

The early deceased Heinz Rutishauser (1918–1970) of ETH Zurich is considered the most important Swiss pioneer from the early era of computer science.

According to Dell’Oro, datacenter switching set a new record for revenues for any second quarter in history and also for any first six months of any year since it has been keeping records.

View Details

Smartphone shipments are forecast to shrink globally by 6.5 percent this year as many households feeling the pinch of inflation decide to prioritize paying for food, energy and other essentials over refreshing handsets.

SmartNICs have long been the domain of hyperscale and cloud datacenters, but they remain relatively uncommon in enterprise environments due in large part to the lack of software compatibility.

The last few years have demonstrated that breaches occur, no matter how much security organizations put in place.

View Details

CXL is supported by pretty much every hardware vendor and built on top of PCI Express for coherent memory access between a CPU and a device, such as a hardware accelerator, or a CPU and memory.

Challenges pertaining to outdated infrastructure could easily be compounded by the fact that many IT and security teams don’t seem to have a plan in place to mobilize if and when a cyberattack occurs.

Chinese military researchers are threatening that Musk's Starlink satellites must be destroyed.

View Details

However, a recent study from cybersecurity training platform Hoxhunt revealed that the skill of distinguishing between legitimate and phishing emails varies based on job functions.

How will the market change in the future? Estimates of cloud market share are highly variable, with one of the biggest challenges being that different providers report different products and services in the “cloud” revenue category.

All companies should be using two-factor authentication at least to secure their systems, but relying on text messages alone is foolish, cybersecurity experts say.

View Details

I dabble with DNS for work, and I’m frequently checking if CNAMEs are properly configured. CNAMEs are Canonical NAMEs, kind of like nicknames, that indicate that one domain name is a nickname for another domain name.

Overall, A and MX queries are successfully resolved most frequently, while AAAA and PTR manifest lower success rates. Specifically, the failure rate of AAAA queries is surprisingly over 64.2% — two out of three AAAA queries failed.

Growth in hyperscaler data centers and processor-intensive enterprise workloads, such as high-performance computing (HPC) and AI, is set to drive broadscale adoption of SmartNICs.

View Details

The US Federal Trade Commission on Thursday announced an effort to formulate privacy rules to deter unwelcome online monitoring and shoddy data security.

Cloud computing has security issues. The problem is underscored by the complexity of cloud and the lack of visibility into what’s happening with workloads inside software containers that host the components of modern applications.

Cisco's enterprise-class firewalls have at least a dozen vulnerabilities — four of which have been assigned CVE identifiers — that could allow attackers to infiltrate networks protected by the devices, a security researcher from vulnerability management firm Rapid7 plans to say in a presentation at the Black Hat USA conference on Aug. 11.

View Details

The distributed, peer-to-peer (P2P) InterPlanetary File System (IPFS) has become a hotbed of phishing-site storage: Thousands of emails containing phishing URLs utilizing IPFS are showing up in corporate inboxes.

Walmart's advice to companies trying to control the hefty cost of running workloads on the three largest cloud providers comes down to one word: choice.

With nearly half of all breaches involving external attackers enabled by stolen or fake credentials, security firms are pushing a high-fidelity detection mechanism for such intrusions: canary tokens.

View Details

Hackers are now ​​moving faster than ever when it comes to scanning vulnerability announcements from software vendors.

However, open source has an urgent security problem. Open source is more ubiquitous and susceptible to persistent threats than ever before.

You’ve done everything to secure your network, and you still face threats. That’s what most enterprises say about their network security, and they’re half right.

View Details

This legislation dutifully provides trial lawyers with endless opportunities to sue Big Tech companies for something indefinable: childhood addiction to websites and phone apps. It puts the state government in charge of defining such addiction.

Recently Google employee Blake Lemoine caused a media storm over the LaMDA chatbot he was working on, that he claims is sentient (it feels things like a human being).

The problem with blockchain is that it’s not an improvement to any system—and often makes things worse.

View Details

Chris Siebenmann has written a short blog piece that reflects on the trend to see Certificate Transparency (CT) as the answer to ‘the problem’; the problem being how to tell if a validly signed and current certificate has somehow had to be repudiated.

For US$2,500, threat actors can employ Matanbuchus, a malware-as-a-service (MaaS) package found delivering Cobalt Strike beacons through phishing and spam messages.

As global and societal events such as supply chain shortages occur, there’s a corresponding increase in fraud related to fake domain registrations (websites) that capitalize on the event—creating unsafe situations for consumers.

View Details

The Chinese regime and other malign actors are trying to exert their influence over global technological standards, but the UK government’s response has been “incoherent and muted,” a committee of MPs has warned.

Researchers have discovered a new attack technique that exploits the speculative execution feature of modern CPUs to leak potentially sensitive information from the kernel's memory.

The findings, which NJIT researchers will present at the Usenix Security Symposium in Boston next month, show how an attacker who tricks someone into loading a malicious website can determine whether that visitor controls a particular public identifier, like an email address or social media account, thus linking the visitor to a piece of potentially personal data.

View Details

After more than a decade when cryptocurrencies and related technologies have surged, boomed, and busted in a regulatory vacuum, lawmakers in both the US and Europe are writing new rules for a sector that has grown dangerously large in both value and reach,

With the emergence of privacy regulations that assign penalties based on a business’ profit, or those that calculate a value for each compromised record, it is possible to calculate the cost of a breach based on those metrics.

What is the most expensive component in the more generic, non-accelerated servers that comprise the majority of their server fleets? Main memory, correct again.

View Details

We kick off this edition of the weekend reads with a few articles on security. Misconfigured cloud storage buckets and a failure to implement good password practices are, as always, a major source of security issues.

We found that only 15 websites were following best practices. The remaining 105 either leave users at risk for password compromise or frustrated from being unable to use a sufficiently strong password (or both).

A misconfigured Amazon S3 bucket resulted in 3TB of airport data (more than 1.5 million files) being publicly accessible, open, and without an authentication requirement for access, highlighting the dangers of unsecured cloud infrastructure within the travel sector.

An unlucky fat-fingering precipitated the current crisis: The client had accidentally deleted the private key needed to sign new firmware updates.

View Details

For decades, hopeful techies have been promising a world where absolutely every object you encounter—bandages, bottles, bananas—will have some kind of smarts thanks to supercheap programmable plastic processors.

To be clear, current artificial intelligence systems are decades away from being able to experience feelings and, in fact, may never do so.

The fact that LaMDA in particular has been the center of attention is, frankly, a little quaint. LaMDA is a dialogue agent. The purpose of dialogue agents is to convince you that you are talking with a person.

View Details

Research by Citrix shows business leaders don't entirely trust their employees when it comes to hybrid work.

The best result for big tech is if laws are absent or useless. The latest survey of big tech lobbying in the US reveals a flotilla of nearly 500 salespeople/lawyers touring the US state legislatures, trying to either draw up tech friendly legislation to insert into privacy bills, water then down through persuasion, or just keep them off the books.

Last month, the 11th Circuit Court of Appeals held that several parts of Florida’s social media law, S.B. 7072, were likely unconstitutional.

View Details

The Iranian state-sponsored threat actor tracked under the moniker Lyceum has turned to using a new custom .NET-based backdoor in recent campaigns directed against the Middle East.

A service level agreement (SLA) is a contract between a cloud provider and a user. The SLA describes the provider’s minimum level of service, specified by performance metrics, and the compensation due to the user should the provider fail to deliver this service.

Grooming techniques used in various frauds are getting more common and more elaborate. Fraudsters are coming up with narratives that involve complicated lies and may have different stages, depending on the type of fraud.

View Details

Seven months from now, assuming all goes as planned, Google Chrome will drop support for its legacy extension platform, known as Manifest v2 (Mv2). This is significant if you use a browser extension to, for instance, filter out certain kinds of content and safeguard your privacy.

But both the tools used and the threat posed by common cybercriminals pale in comparison to the tools used by more professional groups such as the famous hacking groups and state-sponsored groups.

A European team of university students has cobbled together the first RISC-V supercomputer capable of showing balanced power consumption and performance.

View Details

In the hands of police and other government agencies, face recognition technology presents an inherent threat to our privacy, free expression, information security, and social justice.

From social credit scores and online censorship to electronic billboards that display a citizen's "violations" like jaywalking, surveillance is a part of everyday life for millions of Chinese people.

But there's a much bigger threat to democracy coming out of Silicon Valley and it's this: America's largest financial and tech increasingly act as independent countries, routinely exporting jobs, money and technology to our most significant global adversary.

View Details

Alongside the announcement of Ryzen 7000 processors, AMD revealed a new technology coming to the platform: Smart Access Storage.

The web of global intermediary liability laws has grown increasingly vast and complex as policymakers around the world move to adopt stricter legal frameworks for platform regulation.

Like other kinds of computing, if you put garbage data into a machine learning training run and then pour new data through it, what comes out as the answer is puréed garbage.

View Details

This edition of weekend reads begins with a few straight security stories of interest. I knew key loggers existed in the wild, but the logging of keystrokes before a web form is submitted is apparently a lot more common than I realized—

They found that 1,844 websites gathered an EU user's email address without their consent, and a staggering 2,950 logged a US user's email in some form. Many of the sites seemingly do not intend to conduct the data-logging but incorporate third-party marketing and analytics services that cause the behavior.

Illustrating that security is often a game of "whack-a-mole," web skimmers are obfuscating their operation—

Microsoft security researchers recently observed that web skimming campaigns now employ various obfuscation techniques to deliver and hide skimming scripts.

View Details

Leading off this weekend, an article by Simon Sharwood on the impact of the centralization of the Internet. I wrote a somewhat longer article on the Public Discourse a while back on the same topic.

The internet has become smaller, the result of a rethinking of when and where to use the 'net's intended architecture. In the process it may also have further concentrated power in the hands of giant technology companies.

Is softwarization really going to change the way we build networks from the ground up? I suspect things will change, but they've always changed. I also suspect we'll be hearing about how software is going to eat the world ten years from now, and IPv6 still won't be fully deployed.

DOCSIS 4.0 is set to deliver faster speeds for cable network operators, but the next generation technology will also spur an operational sea change, telecom consultant Sean McDevitt told Fierce.

View Details

The steepening trajectory towards event-driven and real-time API architecture is imminent.

The idea of this declaration has a lot to do with the “Past of the Internet.” When the Internet was developing in the 1980s and 1990s, it was seen primarily as a tool that would expand individual freedoms worldwide, strengthen democracy, and create prosperity through innovation and economic progress.

I’m not sure that most people understand the extent to which our online experience has moved to the cloud – and this movement to the cloud means we’re using a lot more bandwidth than in the recent past.

View Details

Cloudflare, a company that specializes in web security and distributed denial of service (DDoS) attack mitigation, just reported that it managed to stop an attack of an unprecedented scale.

Cloud operators provide price incentives so that users gravitate towards newer generations (and between server architectures). Figure 1 shows lines of best fit for the average cost per virtual central processing unit (vCPU, essentially a physical processor thread as most processor cores run two threads simultaneously) of a range of AWS virtual instances over time.

Passwordless sign-ins are already a practical reality, but they're sometimes clunky — and three of the biggest tech companies believe they can reduce the friction.

View Details

In January a federal judge denied Facebook’s motion to dismiss the Federal Trade Commission’s amended complaint seeking to force the company to sell off Instagram and WhatsApp.

Tech companies earn staggering profits by targeting ads to us based on our online behavior. This incentivizes all online actors to collect as much of our behavioral information as possible, and then sell it to ad tech companies and the data brokers that service them.

And often, when doing business in these countries, company’s interests in revenue and profits conflict with America’s national security interests, a conflict that profit always seems to win.

View Details

Video meetings dampen brainstorming because we are so hyper-focused on the face in that box that we don’t let our eyes and minds wander as much, a new study found.

Have you recently been on a video confefence call, hit the "mute" button and then offered up some nasty comments about a client or a colleague — or even the boss?

Comcast and other broadband providers are utilizing 10G technology in their quest to deliver “multigigabit symmetrical speeds” to the consumer market.

View Details

Our current encryption standards protect our bank accounts, financial markets, and most of our infrastructure, not to mention the logistics/supply-chain management system in the US Defense Department. But what happens when quantum computers can decipher the current asymmetric encryption that protects our vital systems?

Local governments all over the country are choosing ISP partners and making grants from ARPA funds to help bring better broadband. Today’s blog is a warning to handle the awards of such monies in a way as to be safe from challenges from ISPs you don’t choose to fund.

In a resounding victory for companies whose business model depends on web scraping, the U.S. Ninth Circuit Court of Appeals held this week that such activity does not violate the U.S. Computer Fraud and Abuse Act.

View Details

Agencies of the US Government have issued a joint warning that hackers have revealed their capability to gain full system access to industrial control systems that might help enemy states sabotage critical infrastructure.

Whether you consider them black swan cyber events or not, the SolarWinds attack and the Log4Shell exploit stressed some of the key ways in which organizations can prepare themselves and prevent crises.

The serious lesson from that is to acknowledge but forgive errors. "He's said, many times, that he knew at that moment it was going to be OK," Ellis says. "Creating a safe culture requires a lot of practices, and one of them is closure. Humor is a great way to provide closure because you rarely laugh about something that is still creating tension."

View Details

Quantum computing startups are all the rage, but it’s unclear if they’ll be able to produce anything of use in the near future.

A few years ago, Ken Crum started getting uncomfortable with how much of his life seemed to be online. The long-time computer programmer was particularly concerned by what companies appeared to know about him.

In a future release of Windows 11, you’re going to see significant security updates that add even more protection from the chip to the cloud by combining modern hardware and software.

View Details

These guidelines are not about finding a perfectly secure solution but about practical, immediate possible actions with respect to email, instant messaging, voice and video chats, and other important security measures to consider.

The governance of an IXP can deeply affect its development. The difficulty of stating a clear management policy for IXP is the main challenge that limits the growth, sustainability and success of IXPs. In the past years, there have not been enough initiatives that support creating such policies for IXP management.

European telecommunication service providers are being pushed to pick up the pace regarding 5G adoption. However, the next-gen technology requires immense data capacity and transmission speeds, thus setting up the new infrastructure is no easy task for telcos.

View Details

An FBI intelligence memo from March 18 obtained by CBS has revealed that currently 140 or more Russian–based IP addresses are conducting “abnormal scanning activity” of companies in the U.S. energy sector.

In this second part, I lay out a set of recommendations for ways to help ensure that these entanglements of industry and academia don’t grant companies undue influence over the conditions of knowledge creation and exchange.

AvosLocker is a ransomware-as-a-service (RaaS) gang that first appeared in mid-2021. It has since become notorious for its attacks targeting critical infrastructure in the United States, including the sectors of financial services, critical manufacturing, and government facilities.

View Details

A Chinese national was recently caught entering China with 160 Intel processors strapped to his body, an act that customs officials amount to smuggling.

In 2022, Facebook has 2.91 billion active users, making it the most-used social media platform. But to me, it will always pale in comparison to early MySpace.

As a CSIRT consultant, I cannot overemphasize the importance of effectively managing the first hour in a critical incident.

View Details

If you work in advertising or marketing, you’re probably aware of Apple’s privacy efforts over the last year. Apple now requires apps ask customers if they want to 'opt-in' to allow behavioral data tracking.

Among gamers and parents and even within the medical community, there’s disagreement about whether gaming addiction is real.

When discussing our relationship with technology, for whatever reason—whether it’s due to aimless maximum engagement algorithms, the ruthless economic incentive structure of the global market, or just our own sheer inability to think critically in the face of incessant propaganda—we’re led to believe that there are only two possible paths from here: 1. Integration with Technology or 2. Luddism.

View Details

We should instead be choosing authentication processes that appropriately match site risks; using a password should be the last thing you want to rely on.

Public companies would have to report material cybersecurity incidents no later than four business days after they occur if a rule proposed by the Securities and Exchange Commission (SEC) on Wednesday takes effect.

Researchers have disclosed a new technique that could be used to circumvent existing hardware mitigations in modern processors from Intel, AMD, and Arm, and stage speculative execution attacks such as Spectre to leak sensitive information from host memory.

View Details

The big ISPs all lobbied hard against the net neutrality rules, but the CEO of every big ISP was on the record at least once saying that the net neutrality rules were not a big deal and that they could live with net neutrality. So why did the big carriers lobby so hard about what the FCC was doing?

VESA, which makes the DisplayPort spec, today announced a certification program aimed at helping consumers understand if a DisplayPort 2.0 cable, monitor, or video source can support the max refresh rates and resolutions the spec claims.

Over the past week, the Akamai researchers said, they have detected multiple DDoSes that used middleboxes precisely the way the academic researchers predicted. The attacks peaked at 11Gbps and 1.5 million packets per second.

View Details

The notion that email security should be prioritized is emphasized during this time where more and more businesses are still working in a remote or hybrid dynamic environment.

After quizzing 8,000 job applicants and 2,250 hiring managers in the U.S., Germany, and Great Britain, researchers at Harvard Business School, working with the consultancy Accenture, discovered that many tens of millions of people are being barred from consideration for employment by résumé screening algorithms that throw out applicants who do not meet an unfeasibly large number of requirements, many of which are utterly irrelevant to the advertised job.

We developed attacks that exploit the transparency of the DNS lookups to tunnel injection payloads over DNS records. These attacks exploit two key factors. Firstly, DNS resolvers do not alter the DNS records received in lookups, so the malicious payload is preserved intact

View Details

To some degree, cyber AI suffers from the pressures exerted by the quest for never-ending sales growth.

The websites for several banks in Ukraine, the Ministry of Defense, and Armed Forces were hit with a distributed denial-of-service (DDoS) attack on Feb. 15.

Threat actors are using software and developer infrastructure, platforms, and providers as valuable entry points into governments, corporations, and critical infrastructure.

Cybercriminals and nation-state actors adapted to defenders' tactics and became more efficient in 2021, with attackers relying more on data leaks combined with ransomware to extort increasing sums of money from companies — and in some cases using data leaks without encrypting data to force a company to pay, according to two analyses published this week.

View Details

The main purpose of algorithms, like digital programs and datacenters more broadly, is not to make money or influence thoughts, but to control people—in a direct and alien way hostile to our core beliefs and principles.

But as I testified to the Senate last week, you can basically reidentify anything. “Anonymity” is an abstraction.

Many people think that NoSQL databases are the “next big thing” in technology, and that we should write all of our core applications using them. However, NoSQL databases actually predate relational databases, and common relational databases were established to solve the problems that NoSQL brings.

View Details

A new DeadBolt ransomware group is encrypting QNAP NAS devices worldwide using what they claim is a zero-day vulnerability in the device's software.

A simulated phishing attack against more than 82,000 workers found that emails with a personal impact resulted in more clicks and that technical teams — such as IT workers and DevOps teams — clicked just as often and reported suspected phishing attacks less often compared with nontechnical teams

Google on Tuesday announced that it is abandoning its controversial plans for replacing third-party cookies in favor of a new Privacy Sandbox proposal called Topics, which categorizes users' browsing habits into approximately 350 topics.

View Details

DigiTimes reports that processor prices are set to increase “substantially” in 2022 due to a boost in foundry costs. Specifically, processors based on the sub-7nm process nodes are expected to be more expensive moving forward.

For the past four months, Apple’s iOS and iPadOS devices and Safari browser have violated one of the Internet’s most sacrosanct security policies. The violation results from a bug that leaks user identities and browsing activity in real time.

Although the advisory discussed above is specific to Russian threat actors, the lessons learned and approaches to preparedness, detection, and prevention are generically applicable to a wide range of threats for both IT and OT.

View Details

When you’re out and about, and especially when you’re traveling, you might find yourself feeling quite a bit of anxiety when logging into public Wi-Fi.

There are a lot of resources out there on Twitter, Reddit, and YouTube about this epic vulnerability. I wanted to create this post to summarize the main things I learned, ways to test it as pentester, and the mitigation controls that help prevent the exploitation of this vulnerability.

A Romanian vulnerability researcher has discovered more than 70 flaws in combinations of cloud applications and content delivery networks (CDNs) that could be used to poison the CDN caches and result in denial-of-service (DoS) attacks on the applications.

View Details

Unfortunately, when engineers are entrusted with the task of delivering smooth video streaming to our users, we face numerous challenges from ‘last-mile’ wireless connections.

Exploit code has been released for a serious code-execution vulnerability in Log4j, an open source logging utility that's used in countless apps, including those used by large enterprise organizations, several websites reported last Thursday.

The Tuesday outage at an Amazon Web Services data center affected services from several collaboration software vendors, highlighting how reliant companies have become on cloud providers for a variety of workplace tools.

View Details

In a highly anticipated decision, a judge of the United States International Trade Commission ruled in August that Google infringed five patents owned by speaker maker Sonos. The case charged Google with copying Sonos' patented technology in its Google Home smart speakers.

If you’ve followed the news over the last few years, you’re probably convinced that we’re living in a golden age of conspiracy theories and disinformation.

Americans, and not just Americans, are well aware of how deep the dysfunction of the ruling factions runs. Many older ones remember the abuses of the Intelligence Community and the warnings against the Military-Industrial Complex; they have lived long enough to see the political resistance to the Community and the Complex shift, under pressure of deliberate policies, from the Left to the Right.

View Details

It is refreshing to find instances in the IT sector where competing groups with their own agendas work together for the common good and the improvement of systems everywhere. So it is with the absorption of the Gen-Z Consortium by the CXL Consortium.

What is open core? Is a project open core, or is a business open core? That's debatable. Like open source, some view it as a development model, others view it as a business model.

From the recent writeup of the DNS work at the IETF its clear that there is a large amount of attention being focused on the DNS. It’s not just an IETF conversation, or a DNS OARC conversation, but a conversation that involves a considerable amount of research activity as well.

View Details

SpaceX had filed a new application with the Federal Communications Commission for a smaller dish, which just received approval yesterday.

Threat actors are increasingly banking on the technique of HTML smuggling in phishing campaigns as a means to gain initial access and deploy an array of threats, including banking malware, remote administration trojans (RATs), and ransomware payloads.

IBM unveiled a 127-qubit quantum computing chip called Eagle this week, showing off a new asset in the race to build the most powerful quantum computer.

View Details

Kaspersky today publishes its Distributed Denial of Service (DDoS) Q3 2021 report, which found when compared to Q3 2020, the total number of DDoS attacks increased by nearly 24%, while the total number of smart attacks (advanced DDoS attacks that are often targeted) increased by 31% when compared to the same period last year.

IP fragmentation is a process that breaks large packets into smaller packets to allow them to more easily traverse a network. The process is common in the DNS, which is predominantly UDP based.

If you’ve been perusing cryptocurrency forums or video-game news recently—or spying everything from New York Times job listings to zany Twitter threads claiming that the traditional job interview is about to be replaced by blockchain-based “quests, adventures and courses to prove your worth”—you might have run into the term “Web3.”

View Details

We've had too many face-palm-worthy incidents of organizations hearing "hey, I found your data in a world readable S3 bucket" or finding a supposedly "test" server exposed that had production data in it.

Virtually all compilers — programs that transform human-readable source code into computer-executable machine code — are vulnerable to an insidious attack in which an adversary can introduce targeted vulnerabilities into any software without being detected, new research released today warns.

2021 has already been a banner year for cybercriminals — the record-largest ransomware payment of $40 million was made by an insurance company this year. And the attacks won't stop.

View Details

From Facebook to LinkedIn to Indeed, ads are popping up that promise well-paying jobs — if applicants provide their Social Security numbers and other details up front. Scammers then use the information to apply for unemployment benefits.

The coronavirus pandemic giveth to Amazon retail business and its Amazon Web Services cloud business, and the pandemic taketh away from the Amazon retail business.

Companies should recognize that collaboration platforms aren't isolated, secure channels where traditional threats don't exist.

View Details

If your organization includes Android devices as part of its bring-your-own-device (BYOD) policy or uses embedded systems, then a recent root expiration for Let’s Encrypt digital certificates may potentially place your organization at risk.

In a threat hunting approach, when we find some malicious file, binary, or a program, we need to collect the artifacts from them and search within our whole environment to find any possible traces of malicious activity.

In other words, how to fool advanced threat detection systems, past the all-seeing eye of which, according to marketers, no extra byte can slip through. I am talking about systems that use big data analytics as one of the main tools for detecting suspicious activity like SIEM and XDR.

View Details

Mark Zuckerberg, unlike Einstein, did not dream up Facebook out of a sense of moral duty, or a zeal for world peace. This summer, the population of Zuckerberg’s supranational regime reached 2.9 billion monthly active users, more humans than live in the world’s two most populous nations—China and India—combined.

The greatest risk of monopolies is that they’ll obstruct the ideas that will make our homes truly smart. Our “Jetsons” future is on the line.

Given these concerns, it seems especially bizarre that Amazon was willing to reference the price of competing smart thermostats sold via its platform during the launch. Its smart thermostat is “less than half the average cost of a smart thermostat sold on Amazon.com,” the company’s senior vice president of devices and services, Dave Limp, said.