a

Palo Alto Advises Securing PAN-OS Interface Amid Potential RCE Threat Concerns

Palo Alto Networks on Friday issued an informational advisory urging customers to ensure that access to the PAN-OS management interface is secured because of a potential remote code execution vulnerability. "Palo Alto Networks is aware of a claim of a remote code execution vulnerability via the PAN-OS management interface," the company said. "At this time, we do not know the specifics of the




a

Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT Malware

Cybersecurity researchers have discovered a new phishing campaign that spreads a new fileless variant of known commercial malware called Remcos RAT. Remcos RAT "provides purchases with a wide range of advanced features to remotely control computers belonging to the buyer," Fortinet FortiGuard Labs researcher Xiaopeng Zhang said in an analysis published last week. "However, threat actors have




a

HPE Issues Critical Security Patches for Aruba Access Point Vulnerabilities

Hewlett Packard Enterprise (HPE) has released security updates to address multiple vulnerabilities impacting Aruba Networking Access Point products, including two critical bugs that could result in unauthenticated command execution. The flaws affect Access Points running Instant AOS-8 and AOS-10 - AOS-10.4.x.x: 10.4.1.4 and below Instant AOS-8.12.x.x: 8.12.0.2 and below Instant AOS-8.10.x.x:




a

Security Flaws in Popular ML Toolkits Enable Server Hijacks, Privilege Escalation

Cybersecurity researchers have uncovered nearly two dozen security flaws spanning 15 different machine learning (ML) related open-source projects. These comprise vulnerabilities discovered both on the server- and client-side, software supply chain security firm JFrog said in an analysis published last week. The server-side weaknesses "allow attackers to hijack important servers in the




a

The ROI of Security Investments: How Cybersecurity Leaders Prove It

Cyber threats are intensifying, and cybersecurity has become critical to business operations. As security budgets grow, CEOs and boardrooms are demanding concrete evidence that cybersecurity initiatives deliver value beyond regulation compliance. Just like you wouldn’t buy a car without knowing it was first put through a crash test, security systems must also be validated to confirm their value.




a

New GootLoader Campaign Targets Users Searching for Bengal Cat Laws in Australia

In an unusually specific campaign, users searching about the legality of Bengal Cats in Australia are being targeted with the GootLoader malware. "In this case, we found the GootLoader actors using search results for information about a particular cat and a particular geography being used to deliver the payload: 'Are Bengal Cats legal in Australia?,'" Sophos researchers Trang Tang, Hikaru Koike,




a

THN Recap: Top Cybersecurity Threats, Tools, and Practices (Nov 04 - Nov 10)

⚠️ Imagine this: the very tools you trust to protect you online—your two-factor authentication, your car’s tech system, even your security software—turned into silent allies for hackers. Sounds like a scene from a thriller, right? Yet, in 2024, this isn’t fiction; it’s the new cyber reality. Today’s attackers have become so sophisticated that they’re using our trusted tools as secret pathways,




a

New Ymir Ransomware Exploits Memory for Stealthy Attacks; Targets Corporate Networks

Cybersecurity researchers have flagged a new ransomware family called Ymir that was deployed in an attack two days after systems were compromised by a stealer malware called RustyStealer. "Ymir ransomware introduces a unique combination of technical features and tactics that enhance its effectiveness," Russian cybersecurity vendor Kaspersky said. "Threat actors leveraged an unconventional blend




a

5 Ways Behavioral Analytics is Revolutionizing Incident Response

Behavioral analytics, long associated with threat detection (i.e. UEBA or UBA), is experiencing a renaissance. Once primarily used to identify suspicious activity, it’s now being reimagined as a powerful post-detection technology that enhances incident response processes. By leveraging behavioral insights during alert triage and investigation, SOCs can transform their workflows to become more




a

North Korean Hackers Target macOS Using Flutter-Embedded Malware

Threat actors with ties to the Democratic People's Republic of Korea (DPRK aka North Korea) have been found embedding malware within Flutter applications, marking the first time this tactic has been adopted by the adversary to infect Apple macOS devices. Jamf Threat Labs, which made the discovery based on artifacts uploaded to the VirusTotal platform earlier this month, said the Flutter-built




a

New Phishing Tool GoIssue Targets GitHub Developers in Bulk Email Campaigns

Cybersecurity researchers are calling attention to a new sophisticated tool called GoIssue that can be used to send phishing messages at scale targeting GitHub users. The program, first marketed by a threat actor named cyberdluffy (aka Cyber D' Luffy) on the Runion forum earlier this August, is advertised as a tool that allows criminal actors to extract email addresses from public GitHub




a

New Flaws in Citrix Virtual Apps Enable RCE Attacks via MSMQ Misconfiguration

Cybersecurity researchers have disclosed new security flaws impacting Citrix Virtual Apps and Desktop that could be exploited to achieve unauthenticated remote code execution (RCE) The issue, per findings from watchTowr, is rooted in the Session Recording component that allows system administrators to capture user activity, and record keyboard and mouse input, along with a video stream of the




a

Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler Bugs

Microsoft on Tuesday revealed that two security flaws impacting Windows NT LAN Manager (NTLM) and Task Scheduler have come under active exploitation in the wild. The security vulnerabilities are among the 90 security bugs the tech giant addressed as part of its Patch Tuesday update for November 2024. Of the 90 flaws, four are rated Critical, 85 are rated Important, and one is rated Moderate in




a

Iranian Hackers Use "Dream Job" Lures to Deploy SnailResin Malware in Aerospace Attacks

The Iranian threat actor known as TA455 has been observed taking a leaf out of a North Korean hacking group's playbook to orchestrate its own version of the Dream Job campaign targeting the aerospace industry by offering fake jobs since at least September 2023. "The campaign distributed the SnailResin malware, which activates the SlugResin backdoor," Israeli cybersecurity company ClearSky said




a

AWFUL VERSUS EMPTY

Why is it that in every recent Presidential election I’ve found myself saying, “We’re a nation of (now) some 330 million people, and these are the best two we can pick from to lead us?” In a recent piece, Wall Street Journal defined the choice as Awful versus Empty. (Google will get you there, though […]




a

ISRAEL DISARMED

Mark Smith is a brilliant attorney, gun-focused and one of our most articulate spokespersons for firearms owners civil rights. Check out his blog called The Four Boxes Diner. That’s a reference to Boxes of Liberty: the soapbox, the ballot box, the jury box, and finally the cartridge box. You also want to check out his […]




a

AFTER THE STORM(S)

Hurricane Milton was gonna be the big one, and while we weren’t in the crosshairs for this one like we were for Hurricane Helene a few weeks ago, we were still will within its field of fire. They were predicting Category 4 and possibly Category 5.  I’m told FEMA- approved “hurricane-resistant homes” are spec’d to […]




a

ANOTHER GREAT GUN GUY PASSES

I was saddened to be told of the recent death of my old friend Ed Lovette. He had a long and distinguished career in military, law enforcement, and the CIA. Ed was a thinking man’s instructor. We took each other’s classes. He went through my LFI-I course back in the day , and about thirty […]




a

WHY COMPETITION IS RELEVANT TO SELF-DEFENSE

Recently saw this on YouTube, from a grandmaster competition shooter who is also in law enforcement. I agree with him. I’ve said for years that while a shooting match is not a gunfight, a gunfight most certainly is a shooting match. Competition experience makes shooting under pressure the norm. Wyatt Earp competed in the informal […]




a

THE NEXT TIME AN ANTI-GUNNER SAYS CITIZENS’ RIFLES ARE USELESS AGAINST ARMIES…

…remind them of this. I was recently reading “Andrew Jackson and the Miracle of New Orleans” by Brian Kilmeade and Don Yeager. The War of 1812 was going badly for the Americans. The British had burned the White House, and a huge contingent of British troops was in Louisiana planning to march north in conquest. […]




a

ABOUT THE ELECTION

Don’t you hate it when the candidate “on your side” acts as if he’s trying to throw the fight? I voted for Donald Trump and urged others to do the same in 2016 and 2020, and as soon as early voting opens in my state will vote for him again in 2024. Not because he’s […]




a

THE LAW AND THE FACTS ARE ON OUR SIDE, BUT WE SHOULD BE USING EMOTION, TOO

Historically, both law and facts are on the gun owners’ side of the “gun control” debate, and the Other Side had relied largely on emotion.  I respectfully submit that emotion is something our side should play to, as well. I made that point recently at the 2024 Gun Rights Policy Conference in San Diego last […]




a

CATCH THE NEW SECOND AMENDMENT FOUNDATION VIDEO

The Second Amendment Foundation has released a 22-minute video celebrating its fifty years of fighting for gun owners’ civil rights. Some of those who’ve been along for most or all of the ride, including founder Alan Gottlieb, give insight into how far we’ve come.  See it here:




a

Wk3/4: Better late than dead

The difficulty of this weeknotes things is that entire weeks can go by without anything interesting happening. That’s…




a

Bripe and the world Bripes with you

This is, without doubt, the stupidest coffee device I have ever bought. But I have bought it.




a

Hot takes on an 11 year old game: Mass Effect 2

I completed Mass Effect 2 a couple of days ago for the first time. This article contains spoilers…





a

Record of Achievement

On the interesting properties of becoming the kind of person who buys vinyl records.




a

2022 in Video Games

I’ve played some computer games in 2022. Here are some words about some of them. Final Fantasy 14…





a

Trump Embraces RFK Jr.’s Views on Vaccines, Fluoride

In the waning days of his campaign, former President Donald Trump has further embraced some of Robert F. Kennedy Jr.’s incorrect or controversial views on health, including vaccines and fluoride.

The post Trump Embraces RFK Jr.’s Views on Vaccines, Fluoride appeared first on FactCheck.org.





a

Typo in Trump’s Name on Ballot Review Screen Is Not ‘Election Fraud’

A misspelling of former President Donald Trump's name occurred on an optional ballot review screen in Virginia, prompting an unfounded claim on social media of "election fraud." The error was a typo that appeared only on the ballot review screen, not on actual ballots, and would not affect any votes, election officials said.

The post Typo in Trump’s Name on Ballot Review Screen Is Not ‘Election Fraud’ appeared first on FactCheck.org.




a

Posts Spread Unfounded Claim of Race-Based Threat of Violence in Georgia

Posts shared on Facebook make an unfounded claim of racially motivated threats of violence in Gwinnett County, Georgia, "from now until the Inauguration." The county sheriff's office said it had "not received any information indicating threats to any group(s) on or after election day."

The post Posts Spread Unfounded Claim of Race-Based Threat of Violence in Georgia appeared first on FactCheck.org.




a

Trump Makes Unsupported Claim About ‘Massive CHEATING’ in Philadelphia

Former President Donald Trump posted to social media an unsupported claim about "massive CHEATING" in Philadelphia, which he claimed had drawn the attention of law enforcement. The Philadelphia Police Department, the Philadelphia district attorney, a Republican city council member and the Pennsylvania Department of State all refuted the claim.

The post Trump Makes Unsupported Claim About ‘Massive CHEATING’ in Philadelphia appeared first on FactCheck.org.




a

Raskin Didn’t Say He ‘Won’t Be Certifying the Election’

Social media users have spread a quote attributed to Democratic Rep. Jamie Raskin, claiming he said "we won’t be certifying the election" if former President Donald Trump wins. Raskin responded, saying the quote is "100% fabricated" and that "America is having a free and fair election and Congress will certify the winner." The origin of the posts appears to be a misleading account of Raskin's comments in February.

The post Raskin Didn’t Say He ‘Won’t Be Certifying the Election’ appeared first on FactCheck.org.




a

Google’s ‘Where to Vote’ Search Result Reflects Quirk of Candidate Surname, Not Bias

Social media users alleged bias against former President Donald Trump when a Google search on Election Day for “where to vote” returned an interactive map to find a person’s polling station when including the word “Harris” but not “Trump.” The reason is because “Harris” is a county in Texas, whereas “Trump” is not a location.

The post Google’s ‘Where to Vote’ Search Result Reflects Quirk of Candidate Surname, Not Bias appeared first on FactCheck.org.




a

Trump’s New York Case: What Happens Now?

Q: What will happen in Donald Trump’s New York state criminal case now that he is president-elect?

A: Trump is scheduled to be sentenced on Nov. 26, but the judge could decide that sentencing is no longer appropriate. If Trump does receive a sentence, it could be appealed, or the judgment could be deferred until 2029, when Trump would be out of office.

FULL QUESTION

What happens if Trump wins the election and then he gets sentenced at the end of the month?

The post Trump’s New York Case: What Happens Now? appeared first on FactCheck.org.




a

Posts Falsely Claim CBS News Reported ‘Cheating’ in Election

Some social media posts falsely claimed that CBS News reported there was "cheating" in the 2024 presidential election that benefitted President-elect Donald Trump. We found no evidence of such a report, and a CBS News spokesperson said the outlet "did not report or say there was cheating in the election."

The post Posts Falsely Claim CBS News Reported ‘Cheating’ in Election appeared first on FactCheck.org.




a

2024 Week 36 Notes: Planners Gotta Plan

The new 2024-25 COVID vaccines are available, so FunkyPlaid and I got ours on Friday. Because we went to a pharmacy, my health insurance didn’t cover them, so I had to use funds from my HRA. (We could have waited until our medical provider had appointments, but that would have been late September or early October — and with travel coming up soon, I was unwilling to wait.)

It is bizarre and enraging to see how agencies supposedly dedicated to public health are flailing in this moment. I’m extremely fortunate to have a job that provides health insurance, an HRA, and sick leave, and I can afford KN95 masks and rapid antigen tests. What about people who are uninsured or underinsured?

I know it’s a bummer to read this, but it’s a bigger bummer to try to survive during yet another COVID surge. Let’s take care of our health, for ourselves and for our communities.

Concentrating on

This time of year is Planner Season, when the 2025 planners are released and people like me (and maybe you too) gobble them up and then spend the rest of this year hoping that next year we have lives exciting enough to plan.

Ever the optimist, my planner line-up for 2025 is:

Cultivating

✍???? Drafting two stories, one for performance (I hope ????????) and one for a collection.

???? Still knitting that gift for someone.

???? Food I made that was yummy:

  • Peperonata with peppers from a coworker’s CSA box, plus peppers from our own CSA box. CSA boxes are great!
  • Gluten-free vegan apple crisp. I am not a huge fan of apples in their primary form; I prefer them as a cinnamon delivery device. So this recipe from Minimalist Baker, apples chopped up and baked with oats and sugar? That works.
  • Sliced heirloom tomatoes on toast spread thinly with mayonnaise. Truffle salt if you’re feeling fancy. (I was.)

???????? Learning Italian with Duolingo.

???? The workweek was short because of the holiday on Monday, but also long because of everything. I’m still trying to create better boundaries around that.

Consuming

????️ One of my planner pals shared a sample of Bungukan Kobayashi’s Yagentoshiro Reflex Violet, a dusky blue with iridescent purple shimmer.

???? “girlfriend” by Hemlocke Springs is on repeat on my brain radio.

???? You don’t need to be a Rolling Stones fan to enjoy the “I Can’t Get No Legal Action” episode of the Judge John Hodgman podcast.

???? Still working my way through the crossword puzzle books I’ve hoarded and enjoying the daily Cross|word on Puzzmo. Also, Minute Cryptic is quite humbling.

???? One last episode of “Fargo” to go, then we’ll start the latest season of “Slow Horses”.

???? What I’m reading and quoting:

From “What would an adequate COVID response look like?” by Julia Doubleday:

Right now, state representatives are deliberately avoiding mention of COVID, while propagandizing the safety of infection and/or the end of the pandemic by refusing to mask. It is hard to imagine how successful a pandemic response might be if public officials were actually trying to end the pandemic. We quite literally have public health and political and media figures working to hide three pieces of critical information: public knowledge of the virus, public knowledge of mitigation measures that would reduce viral spread, and public knowledge of the severity of the virus (which would motivate desire to reduce viral spread).

Other links:

One more thing

Today I’m journaling about this quote from Seneca: “Life, if well lived, is long enough.”




a

2024 Week 37 Notes: R&R

Look at this absolutely good girl: my canine sister, Willa.

Concentrating on

Rest, relaxation, and quality time with loved ones! We’re visiting family in Pennsylvania this week and attending a wedding in Kentucky on Friday.

When packing, I restricted myself to three notebooks and three pens because I tend to overpack and then immediately regret as I am schlepping around a stationery store in my backpack.

Cultivating

✍???? Drafting two (very different) stories. I’m looking forward to time off work to let my creative writing brain percolate.

???? Food I made that was yummy:

  • Pork chops in garlic mushroom sauce, with mashed potatoes and salad on the side. I am not a huge fan of pork chops, but I got them in our CSA box, so I looked for a recipe that incorporated other things I am a huge fan of, like garlic and mushrooms.

???????? When my brain is full of Italian, I switch over to music lessons in Duolingo. It’s fun!

???? No.

Consuming

????️ Only three pens means only three inks: De Atramentis Charles Dickens, Sailor Manyo Hinoki, and Robert Oster Sydney Lavender.

???? I heard “White Gloves” by Khruangbin for the first time in a while and forgot how much I enjoy their music.

???? Recently FunkyPlaid and I tried to watch the show “Kaos” and lasted about ten minutes. I had listened to the Pop Culture Happy Hour episode on the show and thought I might enjoy it.

???? No time for games this week. I’m looking forward to some Puzzmo!

???? We started watching “My Brilliant Friend”, the adaptation of Elena Ferrante’s Neapolitan quartet, which I read last year and loved.

???? What I’m reading and quoting:

Some links

One more thing

I was a bit anxious to travel during a COVID surge, so in addition to getting the new vaccine as soon as I could, I invested in a Flo Mask Pro to wear in airports, planes, and any other crowded spaces. I’m so glad I did; it was very comfortable to wear all day, once I got used to how it felt. My glasses didn’t fog up at all, which is a minor miracle. I did get some looks (you know the kind) but that was a small price to pay for a greater chance of avoiding Covid and/or Long Covid. I only saw a handful of other people masked.




a

Quote of the Day

Brother Diaz had no words. Honestly, he was finding it difficult to breathe down here. He was feeling dizzy. As if the ground might suddenly fall away. He struggled to loosen his collar once again. All he'd wanted was a comfortable living, somewhere sunny. To be taken seriously by the frivolous, regarded as wise by the unwise, and considered important by the unimportant. Instead, for reasons he couldn't comprehend, he found himself called on to consort with scarred knights and part-time painter's models, to face unspecified perils dire enough to threaten creation, all while not getting too close to the cages in which his congregation were kept.

- JOE ABERCROMBIE, The Devils

For more info about this title, follow this Amazon Associate link.

Oh, this is going to be good!!!




a

Quote of the Day

Balthazar delivered a weighty sigh, but nobody noticed.

His current predicament gave him a great deal to sigh about: the ghastly mattress, the dreadful food, the frigid damp and unspeakable odour of his lodgings, the outrageous denial of clothing, the abominable absence of intelligent conversation, the heart-rending loss of his beautiful, beautiful books. But after long reflection he had come to the conclusion that the very worst thing about being forced to join the Chapel of the Holy Expediency . . . was the mortifying embarrassment.

That
he, Balthazar Sham Ivam Draxi, learned adept of the nine circles, suzerain of the secret keys, conjurer of unearthly powers, the man they dubbed the Terror of Damietta--or at least had dubbed himself the Terror of Damietta in the hope that it would stick--one of the top three necromancers in Europe, mark you--possibly four, depending on your opinion of Sukastra of Bivort, who he personally considered an absolute hack--should have been apprehended by buffoons, tried and condemned by dullards, then pressed into humiliating servitude alongside such abject morons as these.

He glanced sideways with an expression eloquently communicating his utter disgust, but nobody was looking. The ancient vampire, presumably rendered decrepit by being starved of blood, slumped in a chair looking as fashionably bored as a wisp-haired skeleton could. The elf stood, thin as a length of pale wire, face obscured by a shag of unnaturally ashen hair, motionless but for a constant and deeply irritating nervous twitching of her long right forefinger. Their chief jailer, Jakob of Thorn, looked on from the corner with arms tightly folded: a war-worn old knight who appeared to have spent a sizeable portion of his life being crushed in a mangle, an experience that had clearly squeezed all sense of humour out of the man. Then there was the supposed spiritual shepherd of this congregation of the disappointing: Brother Diaz, a perpetually panicked young idiot from a little-known and less-regarded monastic order, who wore the expression of a man who cannot swim on the deck of a rapidly foundering ship.

An ineffectual priest, an enervated knight, a misanthropic elf, and an antique vampire. It sounded like the start of a bad joke to which the tragic punchline was yet to be revealed. One might at least have hoped for an awe-inspiring venue: some sculpture-crusted sanctum whose marble floor was inset with the ideograms of saints and angels. Instead, they got a draughty little box in the guts of the Celestial Palace, whose one window had a view of a nearby wall sporting a muddle of leaky drainpipes.

The choice of Balthazar's farce of a trial had been atonement for his trespasses through service to Her Holiness or burning at the stake. At the time it had seemed a no-brainer, but he was beginning to suspect that, in the long run, immolation might prove to have been the less painful option.


- JOE ABERCROMBIE, The Devils

For more info about this title, follow this Amazon Associate link.

Balthazar's POV is by far my favorite thus far. He's the most entertaining necromancer in speculative fiction since Steven Erikson's Bauchelain and Korbal Broach!




a

Intel 2024 = Sow's Ear




a

The FTC comes after neobank Dave for misleading marketing, hidden fees




a

Yet another danger of cryptocurrencies ...




a

LA man wearing GPS ankle monitor is accused of a robbery string. Officials can't track him




a

Law enforcement operation takes down 22,000 malicious IP addresses worldwide




a

SF Muni finally ditching floppies




a

Tribal digital sovereignty in today's dystopia