I think I’m in the market for another mechanical keyboard. ~75% size. Butter keys. Backlit if possible. I currently have the Nuphy Air75 v1. What should I look at now?
Mike
@theomegabit.xyz
AWS Pro | Cloud | Security @trek10.com | Tech enthusiast Musically trapped between a metallic headbang and a bass wobble | Photographer (bsky): @betapixels.photography
Behind the curtain - AWS Lambda Managed Instances: A Security Overview #awssecurity #cloudsecurity www.offensai.com/blog/aws-lam...
AWS Lambda Managed Instances: A Security Overview
An initial security overview of AWS Lambda Managed Instances, exploring the Bottlerocket-based architecture, the 'Elevator' components, and security insights for this new compute model.
offensai.com
Nice Extended threat detection for EC2 and ECS aws.amazon.com/blogs/aws/am... AWS real-time risk prioritization (was preview now GA) aws.amazon.com/blogs/aws/aw... AWS Security Agent (for appsec/dev) aws.amazon.com/blogs/aws/ne... #awssecurity #aws #AWSreInvent
Amazon GuardDuty adds Extended Threat Detection for Amazon EC2 and Amazon ECS | AWS News Blog
Today, we’re announcing new enhancements to Amazon GuardDuty Extended Threat Detection with the addition of two attack sequence findings for Amazon Elastic Compute Cloud (Amazon EC2) instances and Amazon Elastic Container Service (Amazon ECS) tasks. These new findings build on the existing Extended Threat Detection capabilities, which already combine sequences involving AWS Identity and Access […]
aws.amazon.com
That’s a vulnerability for sure. #cybersecurity dirkjanm.io/obtaining-gl...
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
dirkjanm.io
Telling on themselves. lol. #cybersecurity www.huntress.com/blog/rare-lo...
An Attacker’s Blunder Gave Us a Look Into Their Operations | Huntress
An attacker installed Huntress onto their operating machine, giving us a detailed look at how they’re using AI to build workflows, searching for tools like Evilginx, and researching targets like software development companies.
huntress.com
Yep, I've been pwned. 2FA reset email, looked very legitimate. Only NPM affected. I've sent an email off to @npmjs.bsky.social to see if I can get access again. Sorry everyone, I should have paid more attention. Not like me; have had a stressful week. Will work to get this cleaned up.
@bad-at-computer.bsky.social Hey. Your npm account seems to have been compromised. 1 hour ago it started posting packages with backdoors to all your popular packages.
You’re at a cybersecurity conference in 2025 and see a presenter still using Lastpass. First thought? Second?
Anyone used this much / have any feedback? #cybersecurity #mcp #aisecurity github.com/Agentity-com...
GitHub - Agentity-com/mcp-audit-extension: Audit and log all GitHub Copilot MCP tool calls in VSCode with ease.
Audit and log all GitHub Copilot MCP tool calls in VSCode with ease. - Agentity-com/mcp-audit-extension
github.com
We’ve definitely noticed a significant increase in .svg attachments in email lately. #cybersecurity www.bleepingcomputer.com/news/securit...
VirusTotal finds hidden malware phishing campaign in SVG files
VirusTotal has discovered a phishing campaign hidden in SVG files that create convincing portals impersonating Colombia's judicial system that deliver malware.
bleepingcomputer.com
Anyone going to @BlueTeamCon this yeah? #cybersecurity
https://media3.giphy.com/media/axu6dFuca4HKM/200.gif
media3.giphy.com
Sooo…..this password manager extension saga that is currently unfolding…. It still seems like 1Password should do /something/ if others are starting to. Or is it truly performative? www.reddit.com/r/1Password/...
Reddit - The heart of the internet
reddit.com
Anyone used Santa (either the old Google maintained variant or the new one) here? github.com/northpolesec... #cybersecurity
GitHub - northpolesec/santa: A binary and file access authorization system for macOS.
A binary and file access authorization system for macOS. - northpolesec/santa
github.com
Seems like a generally good thing here. I understand where he’s coming from with unnecessary panic. But is that enough of a reason to not put more pressure on companies who are generally not focused on transparency as a whole? #cybersecurity www.schneier.com/blog/archive...
Google Project Zero Changes Its Disclosure Policy - Schneier on Security
Google’s vulnerability finding team is again pushing the envelope of responsible disclosure: Google’s Project Zero team will retain its existing 90+30 policy regarding vulnerability disclosures, in which it provides vendors with 90 days before full disclosure takes place, with a 30-day period allowed for patch adoption if the bug is fixed before the deadline. However, as of July 29, Project Zero will also release limited details about any discovery they make within one week of vendor disclosure. This information will encompass: The vendor or open-source project that received the report ...
schneier.com
Amazon Q shipped a feature where a rando hacker told it to run aws iam delete-user, and AWS said “Sure thing, pal!” They caught it only because a journalist asked. This isn’t “move fast and break things," it's “move fast and let strangers write your roadmap.” www.lastweekinaws.com/blog/amazon-...
Amazon Q: Now with Helpful AI-Powered Self-Destruct Capabilities - Last Week in AWS Blog
Today 404Media released a truly stunning report that almost beggars belief. To break it down into its simplest form: A hacker submitted a PR. It got merged. It told Amazon Q to nuke your computer and ...
lastweekinaws.com
Some good reads in the latest AWS security digest #awssecurity awssecuritydigest.com/past-issues/...
AWS Security Digest - Issue 219
awssecuritydigest.com
Why is Inspector Code Security not integrated in Security Hub on day 1? #awssecurity docs.aws.amazon.com/inspector/la...
Audits suck. Is it time to move that workflow more left, yet? #grc github.com/ajdehn/AWS-A...
GitHub - ajdehn/AWS-Audit-Playbook: AWS audits, without screenshots
AWS audits, without screenshots. Contribute to ajdehn/AWS-Audit-Playbook development by creating an account on GitHub.
github.com
The every repeating cycle of “ship now” biting us (people in general) in the ass. Sometimes it’s worth slowing down if even for a moment. www.bleepingcomputer.com/news/securit...
Asana warns MCP AI feature exposed customer data to other orgs
Work management platform Asana is warning users of its new Model Context Protocol (MCP) feature that a flaw in its implementation potentially led to data exposure from their instances to other users and vice versa.
bleepingcomputer.com
There’s a decent amount of talk and research on specific AWS api calls that aren’t logged to cloudtrail but is there an all encompassing list (GitHub hopefully) that covers everything currently known? #awssecurity
Cool Cloud Security learning challenge from Wiz #cloudsecurity www.cloudsecuritychampionship.com
The Ultimate Cloud Security Championship
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
cloudsecuritychampionship.com
Minor annoyance - it looks like AWS renamed “Security Hub” of years past to “Security Hub CSPM” and then re-used “Security Hub” for this new functionality. #awssecurity aws.amazon.com/blogs/aws/un...
Unify your security with the new AWS Security Hub for risk prioritization and response at scale (Preview) | AWS News Blog
AWS Security Hub has been enhanced with new capabilities that integrate multiple AWS security services to automatically discover resources, evaluate risks, analyze attack paths, and provide AI-assisted recommendations, helping security teams prioritize critical issues and respond to threats at scale with improved visualization and remediation guidance.
aws.amazon.com
About time! But also, 🎉 aws.amazon.com/blogs/aws/aw...
AWS Certificate Manager introduces exportable public SSL/TLS certificates to use anywhere | AWS News Blog
You can now use AWS Certificate Manager to issue exportable public certificates for your AWS, hybrid, or multicloud workloads that require secure TLS traffic termination.
aws.amazon.com