Its the same at most orgs. Very rare for a vuln remediation program to utilize a truly risk based approach. They would have to trawl through and understand thousands of vulns and the context of your org. There's probably a market for some tool to accomplish this if the larger players haven't attempted already.
HN user
chelmzy
https://chelmzy.tech
chelmzy@protonmail.com
Mostly about threat detection engineering.
I think AI adoption is going to be catastrophic and my only hope is that we can slow down and tread carefully. Chances that occurs are slim. I'm certainly not pro AI. It just really angers me to see people still denying the impact.
This has been my experience as well. I see very bright people lampooning LLMs because it doesn't perform up to their expectations when they are easily in the top 1% of talent in their field. I don't think they understand the cognitive load in your average F500 role is NOT very high. Most people are doing jack shit.
Most people would consider Joe's networth to be $200k.
It is. There are a few different methods. If the devices aren't configured to spoof their USB information they typically have manufacturer information in the usb device name, serial, or vendorID. Otherwise searching usb devices by the deviceclass they are using is another good indicator. I've found that these typically show as USB device class 01h (audio) and 08h (mass storage) which is kinda rare. Just have to filter through legitimate USB products.
Don't use these on your corporate devices or the infosec department will think you are a DPRK remote worker.
Until September 30th so better hurry.
Crazy he wouldn't go for a Bolt. I just bought a 2019 Chevy Bolt w/ 11k miles for $14.5k (so a bit over 10k after federal rebate). It has a brand new battery because all the Bolts were recalled for battery issues. Has around 250m range. Feel like I won the lottery. Still plenty of them available https://www.donohooauto.com/searchused.aspx?Make=Chevrolet&M...
This is what I try to explain to people who ask "If LLMs are so good why haven't they replaced workers?". Well it takes a long time for the railroads to be built. What use is a locomotive without rails?
Does anyone know how to query what actions have been imported from the Actions Marketplace (or anywhere) in Github enterprise? I've been lazily looking into this for a bit and can't find a straight answer.
What hardware? I have been considering doing the same.
Not particularly. The only thing I have noticed in the past decade is the decline of the "American Hacker". Most groups are foreign but will partner with younger Americans for social engineering (ex. Scattered Spider). You just don't have people like Albert Gonzalez/Stephen Watt in America now. However, I suspect that many American hackers have shifted to targeting overseas countries that are not friendly with the US.
It's radicalizing as a twenty something who hasn't had social media in over a decade. Almost everything revolves around it or some friend Discord server. I hate it.
I am suspicious of the acquisition and critical of its founders. But at the same time I'm sitting here looking a Wiz logs and dashboards. The product is certainly real.
Crypto AG confirmed this sort of thing to be possible.
I had the same experience but in the Netherlands. This was after flying through Miami and London with the same tool. Totally forgot it was on me.
Most sane SIEM engineers would implement masking for this. Not sure if CS still uses Splunk but they did at one point. No excuse really.
I think the key difference is they have influence because of the content they make in that space. Whereas a lot of these influencers are just talking about themselves the entire time.
We're talking about influencers here. Not artists.
Good. I hope we return to a time where people made stuff because they want to. Not because they see it as a payday.
Would it be possible to add a location filter for native ranges of the plants?
I'm sure there are negative impacts of vaping and it should definitely be more heavily regulated. But the neutering of Juul only to allow dozens of Chinese clones to take their place was such a huge blunder.
Its typically used for detecting malware, detecting data loss prevention, or forensics. "Drive by crap like port scanning for sshd" isn't even relevant to why companies mitm SSL. And yes I see it detect but not stop active threats on a daily basis.
I don't know about rigged. But there is a lot of RTA (real time assistance) usage on the sites. Essentially clients that inform you of the best decisions to make according to GTO principles.
He's talking out of his ass. But newish competitors are Devo/Sumo Logic.
If they could drop their dependencies on Google Services for Seek I would be ecstatic. The identification works perfect but I would love to be able to view/post locations.
The local gangs use it in my city. Mostly to talk shit.
All 2FA is security theater.
Might be the worst take I have seen on this website. Anyone with first hand experience in corporate information security will not agree with you. Fact of the matter is 2FA stops majority of credential/phishing based attacks. Because majority of attackers are casting a wide net and will simply give up. Is it perfect? No. But to say its all security theater is ignorant.