/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Nathan McNulty

@nathanmcnulty
10 posts
2025-10-27
When you registered your security keys, the domain was twitter. com Authentication requests from any domain that is not twitter. com, like x. com, are ignored (phishing resistant!) So, you must register new passkeys for x. com by November 10th when twitter. com goes away
2025-10-27 View on X
PCMag

X prompts users to re-enroll their security keys for 2FA, and will lock accounts that are not updated by Nov. 10, allowing it to retire the Twitter.com domain

If you're using a hardware security key as your two-factor authentication (2FA) method on X, you'll need to re-enroll by Nov. 10 or your account will be locked.

2024-08-22
It's in Edge already, and I'm pretty sure it was enabled by default at one point... [image]
2024-08-22 View on X
The Verge

Microsoft says Recall will be available to Windows Insiders in October 2024, after delaying the AI feature's launch in June over security and privacy concerns

Microsoft says it's planning to allow Windows testers to try out its controversial Recall AI feature in October.

2024-07-20
Heads up for those running Crowdstrike :( For those in charge of any AV/EDR infrastructure, it's worth spending time thinking about how to best control and validate updates Be sure to consider how quickly you can respond and prevent something this this from rolling out broadly
2024-07-20 View on X
The Verge

BSODs hit thousands of Windows PCs due to “a defect” in an update from CrowdStrike, taking banks, airlines, and more businesses offline; Microsoft is aware

or CrowdStrike Microsoft : HELPFUL LINKS  —  Get notified of outages that impact you  —  Building reliable applications on Azure The Record : IT teams scramble to recover from Crow...

Heads up for those running Crowdstrike :( For those in charge of any AV/EDR infrastructure, it's worth spending time thinking about how to best control and validate updates Be sure to consider how quickly you can respond and prevent something this this from rolling out broadly
2024-07-20 View on X
Wall Street Journal

A profile of CrowdStrike, founded in 2011 and used by 300 companies in the Fortune 500; Gartner: CrowdStrike has ~15% of the global security software market

The little-known company is very popular in Corporate America, contributing to the severity of the global IT outage

2024-07-19
Heads up for those running Crowdstrike :( For those in charge of any AV/EDR infrastructure, it's worth spending time thinking about how to best control and validate updates Be sure to consider how quickly you can respond and prevent something this this from rolling out broadly
2024-07-19 View on X
The Verge

BSODs hit thousands of Windows PCs due to “a defect” in an update from CrowdStrike, taking banks, airlines, and more businesses offline; Microsoft is aware

Thousands of Windows machines are experiencing a Blue Screen of Death (BSOD) issue at boot today, impacting banks …

2024-05-16
I did not have this on my bingo card for 2024, but here we are! [image]
2024-05-16 View on X
The Register

VMware makes its Workstation Pro and Fusion Pro desktop hypervisor products free for personal use

Here's how to take advantage of VMware's Fusion Pro 13's price cut Thom Holwerda / OSnews : VMware Workstation Pro and Fusion pro go free for personal use Pradeep Viswav / MSPoweru...

2024-03-09
I'm often hard on Microsoft because I know they can do better and sometimes decide not to I try really hard to have a well balanced view Stealing source code is not as big of a deal as you think. Most Microsoft employees have access, and they don't consider it a security risk.
2024-03-09 View on X
The Verge

Microsoft says Russian state-sponsored hackers Midnight Blizzard accessed some of its “source code repositories and internal systems” following the January hack

and the Attack Isn't Over Pranav Dixit / Business Today : Microsoft discloses source code theft by Russian hackers Michael Kan / PCMag : Microsoft: Russian Hackers Accessed Company...

2023-11-22
I'll still take Windows Hello with a flawed fingerprint implementation that requires physical access over a user choosing a password that can be used anywhere Some next level research here though, will be important as orgs transition to Hello away from passwords :)
2023-11-22 View on X
Blackwing Intelligence

At Microsoft's request, researchers find multiple flaws in the top three fingerprint sensors in laptops and used for Windows Hello fingerprint authentication

Authors:  —  TL;DR  —  Microsoft's Offensive Research and Security Engineering (MORSE) asked us to evaluate the security …

2021-09-23
This can be mitigated by actually configuring the autodiscover process via policy Ignore that this says Outlook 2016 as it applies to all current releases: https://support.microsoft.com/ ... Not only are you securing the connection, you are also providing a faster configuration experience https://twitter.com/...
2021-09-23 View on X
The Record

Researchers say an Exchange Autodiscover bug can be used to obtain Windows users' domain and app credentials; Microsoft is investigating

Security researchers have discovered a design flaw in a feature of the Microsoft Exchange email server that can be abused to harvest Windows domain and app credentials from users a...

2019-09-19
@github would not issue CVE's for Microsoft applications as @Microsoft is already a CNA that issues their own. GitHub is allowed to issue CVE's for reported vulnerabilities assuming the vendor in question is not already a CNA (as far as I understand).
2019-09-19 View on X
TechCrunch

GitHub buys code analysis tool Semmle, which helps identify security vulnerabilities and has Microsoft, Google among clients; Semmle raised $31M in VC funding

Microsoft's GitHub today announced that it has acquired Semmle, a code analysis tool that helps developers and security researchers …