/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Kevin Beaumont

@gossithedog
368 posts
2024-09-28
So many boomerangs on this saga - can be uninstalled, can't be uninstalled, can be uninstalled 🤣 I remember when I blogged that it was developed under SFI, Microsoft then said it wasn't, now say it was 😅 but overall good changes.  Will be interested to see how it works in practice.
2024-09-28 View on X
The Verge

Microsoft details how it has overhauled its controversial AI-powered Recall feature, including making it opt-in and giving users an option to uninstall

In response to security concerns, Microsoft is detailing how it has overhauled its controversial AI-powered Recall feature …

2024-08-29
Thank you all!  I'm hoping following Fediverse accounts here is coming.  Please continue to support making text based social media a real, sustainable town square @mosseri @zuck
2024-08-29 View on X
TechCrunch

Threads now lets users see and like fediverse replies on other posts besides their own, and will syndicate posts submitted via the Threads API to the fediverse

Threads is deepening its ties to the fediverse, also known as the open social web, which powers services like X alternative Mastodon …

2024-07-25
Hell of a journey here this year - TCS migrated to CrowdStrike, announced a strategic partnership, all their systems got nuked, then they got a $10 Uber Eats voucher (which got withdrawn as it got flagged as fraud) [image]
2024-07-25 View on X
The Guardian

Insurer Parametrix estimates that the global outage sparked by CrowdStrike's faulty update will cost US Fortune 500 companies, excluding Microsoft, $5.4B

Banking and healthcare firms, major airlines expected to suffer most losses, according to insurer Parametrix

If you want to know the bubble the cybersecurity industry exists in.. this comment (they're the CEO of a security vendor) combined with the likes (which include from CrowdStrike staff). [image]
2024-07-25 View on X
The Guardian

Insurer Parametrix estimates that the global outage sparked by CrowdStrike's faulty update will cost US Fortune 500 companies, excluding Microsoft, $5.4B

Banking and healthcare firms, major airlines expected to suffer most losses, according to insurer Parametrix

2024-07-24
- channel updates are currently deployed globally, instantly, to all CrowdStrike customers. They plan to change this at a later date to operate in waves. This is smart (and what Microsoft do for similar EPP updates).
2024-07-24 View on X
The Register

CrowdStrike says the problematic July 19 software update that brought down 8.5M Windows PCs was deployed into production due to “a bug in the Content Validator”

CrowdStrike has blamed a bug in its own test software for the mass-crash-event it caused last week.

- content validate for these specific files appears to be CrowdStrike's side, which raises some questions in terms of abuse locally - none of this is Microsoft's fault. CrowdStrike made a boo boo, it happens. - it's also not the analysts fault who produced the channel update
2024-07-24 View on X
The Register

CrowdStrike says the problematic July 19 software update that brought down 8.5M Windows PCs was deployed into production due to “a bug in the Content Validator”

CrowdStrike has blamed a bug in its own test software for the mass-crash-event it caused last week.

The initial Post Incident Review is out from CrowdStrike. It's good and really honest. There's some wordsmithing (eg channel updates aren't code - in reality their parameters control code). Some take aways:
2024-07-24 View on X
The Register

CrowdStrike says the problematic July 19 software update that brought down 8.5M Windows PCs was deployed into production due to “a bug in the Content Validator”

CrowdStrike has blamed a bug in its own test software for the mass-crash-event it caused last week.

- I do think Microsoft needs to work with vendors and industry groups like MITRE on engine safety. There should be some kind of independent safety mark and testing, to allow customers to make informed decisions about the level of trust and risk they place in security vendors.
2024-07-24 View on X
The Register

CrowdStrike says the problematic July 19 software update that brought down 8.5M Windows PCs was deployed into production due to “a bug in the Content Validator”

CrowdStrike has blamed a bug in its own test software for the mass-crash-event it caused last week.

- Ultimately it's a collective error, - CrowdStrike's response has been really good post error. - They clearly realise they need to prioritise safety now.
2024-07-24 View on X
The Register

CrowdStrike says the problematic July 19 software update that brought down 8.5M Windows PCs was deployed into production due to “a bug in the Content Validator”

CrowdStrike has blamed a bug in its own test software for the mass-crash-event it caused last week.

2024-07-23
If anybody is wondering where cyber insurance stands on CrowdStrike - I have friends at 3 different insurers, and they all say they won't cover the claims as they're outside the policy.
2024-07-23 View on X
Reuters

FlightAware: Reeling from CrowdStrike-related outages, Delta has canceled 5,000+ flights since Friday, including 1,159 flights on Monday and 400+ on Tuesday

Delta Air Lines (DAL.N) CEO Ed Bastian on Monday said it will take the U.S. carrier another couple of days before its operations recover …

2024-07-22
Re the 'it's Microsoft fault for letting EDR drivers do dumb shit' argument - there are safety mitigations MS made but many EPP vendors work around them (including CS) - MS tried to make the space much safer back about 15 years ago, but vendors like Mcafee pushed against it
2024-07-22 View on X
Reuters

Reeling from CrowdStrike-related outages, Delta has canceled 5,000+ flights, including 1,384 on Sunday and 700+ for Monday so far, according to FlightAware

Delta Air Lines (DAL.N) struggled to restore normal operations on Sunday after last week's crippling global cyber outage …

Here's CrowdStrike's mini root cause analysis of what happened yesterday: https://www.crowdstrike.com/ ... It's basically exactly as commonly thought, i.e. a bad content update was pushed which caused the CrowdStrike driver to crash Bunch of clear learnings for CrowdStrike, e.g. testing
2024-07-22 View on X
Reuters

Reeling from CrowdStrike-related outages, Delta has canceled 5,000+ flights, including 1,384 on Sunday and 700+ for Monday so far, according to FlightAware

Delta Air Lines (DAL.N) struggled to restore normal operations on Sunday after last week's crippling global cyber outage …

Here's CrowdStrike's mini root cause analysis of what happened yesterday: https://www.crowdstrike.com/ ... It's basically exactly as commonly thought, i.e. a bad content update was pushed which caused the CrowdStrike driver to crash Bunch of clear learnings for CrowdStrike, e.g. testing
2024-07-22 View on X
CrowdStrike

CrowdStrike says a Falcon sensor configuration update on Windows triggered a logic error that resulted in a system crash and BSOD, remediated after 78 minutes

Thankfully, Macs weren't affected by last week's catastrophic … Anthony Ha / TechCrunch : TechCrunch Minute: What caused last week's major tech outage? CrowdStrike : Likely eCrime ...

2024-07-21
Here's CrowdStrike's mini root cause analysis of what happened yesterday: https://www.crowdstrike.com/ ... It's basically exactly as commonly thought, i.e. a bad content update was pushed which caused the CrowdStrike driver to crash Bunch of clear learnings for CrowdStrike, e.g. testing
2024-07-21 View on X
CrowdStrike

CrowdStrike says a sensor configuration update to Windows systems triggered a logic error that resulted in a system crash and BSOD on impacted systems

What Happened?  —  On July 19, 2024 at 04:09 UTC, as part of ongoing operations, CrowdStrike released a sensor configuration update to Windows systems.

Here's CrowdStrike's mini root cause analysis of what happened yesterday: https://www.crowdstrike.com/ ... It's basically exactly as commonly thought, i.e. a bad content update was pushed which caused the CrowdStrike driver to crash Bunch of clear learnings for CrowdStrike, e.g. testing
2024-07-21 View on X
The Official Microsoft Blog

Microsoft estimates that CrowdStrike's update affected 8.5M Windows devices, or less than 1% of all Windows machines

On July 18, CrowdStrike, an independent cybersecurity company, released a software update that began impacting IT systems globally.  Although this was not a Microsoft incident …

2024-06-15
Somewhere in Microsoft, there's an employee who has the task of sending the exec briefing email saying they had to move up the announcement due to guy with a “PorgHub” avatar scooping them on Mastodon.. which is really the perfect nightcap on the Recall rollout.
2024-06-15 View on X
The Verge

Microsoft delays Recall to test it with the Windows Insider Program and won't ship it with Copilot+ PCs next week, after saying it would make the feature opt-in

will arrive via Windows Update later this year Richi Jennings / Security Boulevard : Recall ‘Delayed Indefinitely’ — Microsoft Privacy Disaster is Cut from Copilot+ PCs Katie Bartl...

On the whole I thought Brad Smith came across well and the CSRB stuff was well handled. The Recall stuff.. not so much. The devices launch Tuesday and it feels like the SLT just don't understand the details, which is pretty astonishing.
2024-06-15 View on X
Washington Post

Brad Smith tells a US House committee that Microsoft “accepts responsibility” for the issues the CSRB found, its business in China serves US interests, and more

if they haven't shown good cybersecurity performance Jessica Lyons / The Register : Microsoft answered Congress' questions on security. Now the White House needs to act Sean Lyngaa...

Microsoft President Brad Smith just testified to the US House that Recall is a good example of Secure By Design, and that they have the time to get it right (it's supposed to launch in 3 working days). [image]
2024-06-15 View on X
Washington Post

Brad Smith tells a US House committee that Microsoft “accepts responsibility” for the issues the CSRB found, its business in China serves US interests, and more

if they haven't shown good cybersecurity performance Jessica Lyons / The Register : Microsoft answered Congress' questions on security. Now the White House needs to act Sean Lyngaa...

2024-06-14
Somewhere in Microsoft, there's an employee who has the task of sending the exec briefing email saying they had to move up the announcement due to guy with a “PorgHub” avatar scooping them on Mastodon.. which is really the perfect nightcap on the Recall rollout.
2024-06-14 View on X
The Verge

Microsoft delays Recall to test it with the Windows Insider Program and won't ship it with Copilot+ PCs next week, after saying it would make the feature opt-in

Microsoft is planning to launch its new Copilot Plus PCs next week without its controversial Recall feature that screenshots everything you do on these new laptops.

On the whole I thought Brad Smith came across well and the CSRB stuff was well handled. The Recall stuff.. not so much. The devices launch Tuesday and it feels like the SLT just don't understand the details, which is pretty astonishing.
2024-06-14 View on X
Washington Post

Brad Smith tells a US House committee that Microsoft “accepts responsibility” for the issues the CSRB found, its business in China serves US interests, and more

Microsoft President Brad Smith faced the the House Homeland Security Committee amid sharp criticism the company's practices put government clients at risk.