Sunday, March 12, 2023

What I'm Reading 3/12/2023 - I should probably make an interest to be more interesting edition

Key Proposals in Biden's Cybersecurity Strategy Face Congressional Challenges

https://www.darkreading.com/risk/key-proposals-in-biden-cybersecurity-strategy-face-congressional-challenges

Stealthy UEFI malware bypassing Secure Boot enabled by unpatchable Windows flaw

https://news.hitb.org/content/stealthy-uefi-malware-bypassing-secure-boot-enabled-unpatchable-windows-flaw

Open letter demands OWASP overhaul, warns of mass project exodus

https://www.csoonline.com/article/3689811/open-letter-demands-owasp-overhaul-warns-of-mass-project-exodus.html#tk.rss_all

Municipal CISOs grapple with challenges as cyber threats soar

https://www.csoonline.com/article/3688958/municipal-cisos-grapple-with-challenges-as-cyber-threats-soar.html#tk.rss_all

PoC exploit for recently patched Microsoft Word RCE is public (CVE-2023-21716)

https://www.helpnetsecurity.com/2023/03/06/cve-2023-21716-poc/

Adaptable ‘Swiss Army Knife’ Malware a Growing Threat


https://securityboulevard.com/2023/03/adaptable-swiss-army-knife-malware-a-growing-threat/

Critical Vulnerabilities Allow Hackers to Take Full Control of Wago PLCs


https://www.securityweek.com/critical-vulnerabilities-allow-hackers-to-take-full-control-of-wago-plcs/

Threat actors are using advanced malware to backdoor business-grade routers

https://arstechnica.com/information-technology/2023/03/threat-actors-are-using-advanced-malware-to-backdoor-business-grade-routers/

5 Critical Components of Effective ICS/OT Security

https://www.darkreading.com/ics-ot/5-critical-components-of-effective-ics-ot-security-

Ransomware's Favorite Target: Critical Infrastructure and Its Industrial Control Systems


https://www.darkreading.com/ics-ot/ransomware-s-favorite-target-critical-infrastructure-and-its-industrial-control-systems

Google over-hired talent to do ‘fake work’ and stop them working for rivals, claims former PayPal boss, Keith Rabois

https://www.yahoo.com/lifestyle/google-over-hired-talent-fake-114331193.html

What Weimar Germany Teaches Us about Universal Basic Income


https://fee.org/articles/what-weimar-germany-teaches-us-about-universal-basic-income/

3 Mistakes I Made as an Engineer, but Had To Become a Manager To See

https://www.developing.dev/p/3-mistakes-i-made-as-an-engineer

Want an unfair advantage in your tech career? Consume content meant for other roles

https://matthewgrohman.substack.com/p/want-an-unfair-advantage-in-your

North Korean hackers used polished LinkedIn profiles to target security researchers


https://cyberscoop.com/north-korea-hackers-linkedin-phishing/

Palo Alto Survey Reveals 90% of Organizations Cannot Resolve Cyberthreats Within an Hour

https://www.darkreading.com/cloud/palo-alto-networks-global-state-of-cloud-native-security-survey-reveals-90-of-organizations-cannot-detect-contain-and-resolve-cyberthreats-within-an-hour

Building Great OT Incident Response Tabletop Exercises

https://www.youtube.com/watch?v=XobogsaxcUY

Neil deGrasse Tyson - We Stopped Dreaming (Episode 1)

https://www.youtube.com/watch?v=CbIZU8cQWXc

In addition to this stuff I am finishing up Chapter 3 of Security Engineering by Ross Anderson https://www.amazon.com/s?k=security+engineering+3rd+edition&crid=2P1CTN6GXKHAV and working on NIST SP 800-37 Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final as I prepare for my CISSP-ISSMP.





















No comments: