<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Cyber Scribble: Pulse]]></title><description><![CDATA[Cyber security news curated for a broad audience, shedding light on significant events, breaches, and trends shaping digital security landscapes.]]></description><link>https://www.cyberscribble.org/s/pulse</link><image><url>https://substackcdn.com/image/fetch/$s_!uI1g!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8b2d602-d09f-417c-a4ef-3e0ab38f2071_1080x1080.png</url><title>Cyber Scribble: Pulse</title><link>https://www.cyberscribble.org/s/pulse</link></image><generator>Substack</generator><lastBuildDate>Sun, 12 Apr 2026 06:10:11 GMT</lastBuildDate><atom:link href="https://www.cyberscribble.org/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[cyberscribble]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[cyberscribble@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[cyberscribble@substack.com]]></itunes:email><itunes:name><![CDATA[Unknown]]></itunes:name></itunes:owner><itunes:author><![CDATA[Unknown]]></itunes:author><googleplay:owner><![CDATA[cyberscribble@substack.com]]></googleplay:owner><googleplay:email><![CDATA[cyberscribble@substack.com]]></googleplay:email><googleplay:author><![CDATA[Unknown]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Temple and The Guard]]></title><description><![CDATA[A story about responsibility, hierarchy, and the consequences of overlooking the smallest voice.]]></description><link>https://www.cyberscribble.org/p/the-temple-and-the-guard</link><guid isPermaLink="false">https://www.cyberscribble.org/p/the-temple-and-the-guard</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Thu, 20 Nov 2025 12:14:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/CwcpkqQK7BY" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A story about responsibility, hierarchy, and the consequences of overlooking the smallest voice.</p><div id="youtube2-CwcpkqQK7BY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;CwcpkqQK7BY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/CwcpkqQK7BY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div>]]></content:encoded></item><item><title><![CDATA[You Are Fired! ]]></title><description><![CDATA[Better To Say It Face to Face, Not Inbox to Trash]]></description><link>https://www.cyberscribble.org/p/you-are-fired</link><guid isPermaLink="false">https://www.cyberscribble.org/p/you-are-fired</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Fri, 21 Feb 2025 01:53:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0EIf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0EIf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0EIf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!0EIf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!0EIf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!0EIf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0EIf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:334962,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberscribble.org/i/157590006?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0EIf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!0EIf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!0EIf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!0EIf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4c370b7-992d-424b-a43c-8aa77b934a29_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What are job termination  scams ?</h2><p>Job termination scams are a type of cyber attack where cybercriminals send fake emails that appear to be from a company's HR department, informing employees they have been terminated.</p><h2>How does these scams operate ?</h2><p>The scams operate by using deceptive emails to trick employees into taking actions that compromise their personal and company security;</p><p>Here is a detailed breakdown of how these scams operate</p><ol><li><p><strong>Initial Contact:</strong> Employees receive an email that appears to be from their HR department or another authoritative source<strong>. </strong>The email's subject line typically indicates termination or dismissal</p></li><li><p><strong>Deceptive Content:</strong> The email is crafted to look legitimate, often using the company&#8217;s logo and branding to reduce suspicion. The content is designed to invoke an immediate, emotional response, leveraging the shock and anxiety associated with job loss to make the recipient act impulsively.</p></li><li><p><strong>Malicious Attachments:</strong> The email includes an attachment, such as a PDF or Word document, or a link to a supposed termination notice or severance package details. The attachment or link points to malicious software.</p></li><li><p><strong>Malware Installation and Execution:</strong> Once the attachment is downloaded or the link is clicked, malware is installed on the employee&#8217;s device. This malicious software steals login credentials, which cybercriminals use to gain unauthorized access to the company&#8217;s network and sensitive data. </p></li><li><p><strong>Exploitation of Stolen Credentials:</strong> With stolen credentials, attackers can hijack email or other accounts to access sensitive corporate data and networks for theft and extortion. If the employee uses the same logins across multiple accounts, the attackers may launch credential stuffing campaigns to unlock those accounts as well</p></li></ol><h2>How do we recognize such scams ?</h2><ul><li><p>Urgent language designed to create a sense of panic and prompt immediate action without careful consideration</p></li><li><p>Suspicious attachments or links, especially if they come from unfamiliar sources or are related to sensitive topics like termination. Hovering over links may reveal subtle misspellings or unusual characters in the URL.</p></li><li><p>Email addresses that are similar but not identical to the company&#8217;s official domain</p></li></ul><h2>What measures can we take to stop them ?</h2><ul><li><p>Employee Education and Training</p></li><li><p>Clear Communication Channels and Policies</p></li><li><p>Vigilance</p></li></ul><p>Above do work at times! </p><h2>The Case for Offline Communication</h2><div class="pullquote"><p>Cultivating a culture of trust where using <strong>offline methods</strong> like in-person meetings or phone calls for sensitive communications, such as terminations, can significantly reduce the risk of employees falling victim to such HR phishing scams</p></div><p>We think offline methods for sensitive communication is very effective and secure because</p><ul><li><p>Reduces such phishing risks</p></li><li><p>Prevents panic </p></li><li><p>Builds trust </p></li></ul><p>May be we are old school and biased! What do you all think ? </p>]]></content:encoded></item><item><title><![CDATA[Series of unfortunate events]]></title><description><![CDATA[From Tenerife to Microsoft-Crowd Strike]]></description><link>https://www.cyberscribble.org/p/series-of-unfortunate-events</link><guid isPermaLink="false">https://www.cyberscribble.org/p/series-of-unfortunate-events</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Sat, 20 Jul 2024 14:18:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bQZD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bQZD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bQZD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!bQZD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!bQZD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!bQZD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bQZD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:493882,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bQZD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!bQZD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!bQZD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!bQZD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ab64ba9-3e16-4e59-aefd-3cd36c517aa4_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Folks, how many of you remember the good old days when the IT guy would show up at your desk with a floppy disk or CD, bringing in the latest patches? It was the perfect time for a fun chit chat while the updates did their thing on the screen. One of those days, amid the usual laughter and tech talk, we got to hear about an unfortunate aircraft disaster in history which impacted us deeply. </p><h4>The Tenerife Airport Disaster </h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f6my!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f6my!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!f6my!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!f6my!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!f6my!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f6my!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:695574,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f6my!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!f6my!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!f6my!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!f6my!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdc8858f-589c-470e-8e94-725fb3191d5c_1792x1024.webp 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Tenerife airport disaster took place on March 27, 1977, when two Boeing 747 passenger jets collided on the runway at Los Rodeos Airport on the Spanish island of Tenerife. The collision happened as KLM Flight 4805 began its takeoff in dense fog while Pan Am Flight 1736 was still on the runway. The impact and subsequent fire resulted in the deaths of all 248 people on the KLM plane and 335 of the 396 people on the Pan Am plane, leaving only 61 survivors in the front section of the latter aircraft. With a total of 583 fatalities, this disaster remains the <a href="https://en.wikipedia.org/wiki/List_of_deadliest_aircraft_accidents_and_incidents">3rd most deadliest accident in aviation history</a>.</p><p>The most intriguing aspect of this unfortunate airline disaster incident is the events which lead to this incident. Let&#8217;s look at them one by one in detail.</p><h5>Event 1 : The Diversion</h5><p>On March 27, 1977, a terrorist bombing at Gran Canaria Airport forced multiple flights, including KLM Flight 4805 and Pan Am Flight 1736, to be diverted to Los Rodeos Airport on the Spanish island of Tenerife. </p><p><em>Event Probability: 1/1000</em></p><h5>Event2: The Capacity Limitation</h5><p>Los Rodeos was a regional airport that couldn't easily handle the traffic diverted from Gran Canaria, including five large airliners. With only one runway and one major taxiway, the diverted planes had to park on the taxiway, making it unusable for taxiing. </p><p><em>Event Probability: 1/100</em></p><h5>Event 3: The Fog</h5><p>As the diverted flights awaited clearance to return to Gran Canaria, dense fog began to settle over Los Rodeos Airport. The heavy fog significantly reduced visibility, making it challenging for pilots and air traffic controllers to see the runways and taxiways clearly.</p><p><em>Event Probability: 1/100</em></p><h5>Event 4: Miscommunication and Language Barriers</h5><p>With visibility severely compromised, clear and precise communication became crucial. However, a series of miscommunications and language barriers between the flight crews and air traffic control led to confusion about taxiing instructions and takeoff clearance. the crew mistakenly assumed they had received clearance from air traffic control. Despite the lack of explicit permission, Captain of KLM flight initiated the takeoff roll, believing the runway was clear.</p><p><em>Event Probability: 1/10</em></p><h5>Event 5: Runway Confusion</h5><p>At the same time, Pan Am Flight 1736, piloted by Captain was instructed to follow the KLM aircraft and exit the runway. Due to the poor visibility and unclear signage, the Pan Am crew missed the designated exit and continued down the runway, unaware of the KLM plane's intentions.</p><p><em>Event Probability: 1/100</em></p><h5>Event 6: The Collision</h5><p>As KLM Flight 4805 accelerated for takeoff, the Pan Am crew suddenly saw the KLM aircraft emerging from the fog, heading straight toward them. In a desperate attempt to avoid a collision, the Pan Am crew tried to turn sharply off the runway, but it was too late. The KLM aircraft collided with the Pan Am plane, resulting in a catastrophic explosion and fire. The exact timing of both planes being on the runway at the same moment was the result of all previous delays and errors compounding into this fatal incident.</p><p><em>Event Probability: 1/1000</em></p><h4>Combined Probability </h4><p>1/1000 * 1/100 * 1/100 * 1/10 * 1/100 * 1/1000</p><p> = 1 / 10000000000000</p><p>This clearly illustrates how unfortunate and rare this incident is (1 in 10 trillion), yet it occurred in our times and was able to claim 583 precious lives. </p><p>It has ingrained in us the importance of addressing risks as individual occurrences rather than assessing them on combined probabilities when assessing risks from a cost perspective.</p><p><strong>But to this day, in modern risk assessment world we do tend to make decisions based on combined probability than individual incident occurrence reduction. </strong></p><h4>Crowd Strike&#8217;s on Microsoft</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aeZ0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aeZ0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!aeZ0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!aeZ0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!aeZ0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aeZ0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:736404,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aeZ0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!aeZ0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!aeZ0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!aeZ0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d0db35-520d-4c6a-aee3-26779b35d6dc_1792x1024.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>During the second week of July 2024, we faced another incident that is still causing widespread inconvenience and mayhem at the time of writing this blog.</p><h5>The Incident</h5><p>The CrowdStrike and Microsoft incident began with a CrowdStrike update that caused compatibility issues with Windows, leading to widespread system crashes and blue screen errors (BSOD). </p><h5>The Impact</h5><p>This incident had a great impact at global level due to the widespread adaptability of Windows + Crowd Strike in modern critical infrastructure such as, </p><ul><li><p>Aviation</p></li><li><p>Healthcare </p></li><li><p>Border and Immigration Services</p></li><li><p>Manufacturing</p></li><li><p>Emergency Response Systems</p></li></ul><p>At this moment, it is also important to understand the events which lead to this incident one by one, </p><h5>Event 1 : Windows In Critical Infrastructure </h5><p>Windows is widely adopted in critical sectors such as healthcare, finance, and aviation due to its reliability and comprehensive support and extensive monopoly</p><p><em>Event Probability:  1/2</em></p><h5>Event 2: <strong>Crowd Strike in Windows</strong></h5><p>Crowd Strike's advanced threat detection and response capabilities have made it a preferred choice in the cybersecurity market, particularly in protecting endpoints.</p><p><em>Event Probability:  1/3</em></p><h5><strong>Event 3: Windows Update / 3rd party Update Compatibility Issues</strong></h5><p>Although compatibility issues between updates from different vendors are less frequent but still plausible due to the complexity of software environments.</p><p><em>Event Probability:  1/100</em></p><h5><strong>Event 4: Blue Screen Errors (BSOD) due to Updates</strong></h5><p>The specific occurrence of BSOD due to update conflicts is relatively rare but possible given the right circumstances.</p><p><em>Event Probability:  1/1000</em></p><h4>Combined Probability </h4><p>1/2 * 1/3* 1/100 * 1/1000</p><p> = 1 / 600000</p><p>Interesting there is nearly a 1 in million chance that this could become an occurrence</p><h4>The Mitigation </h4><div class="pullquote"><p><strong>Slow is smooth, and smooth is fast</strong></p><p><strong>Small is good, and good is efficient</strong></p></div><p>In our opinion , the steps one could take are, </p><blockquote><h3>Minimize the risks individually than writing them off collectively </h3></blockquote><p>We are thankful that there was no major significant human cost due to this incident, but it is important to also remember that Nature DOES NOT repeat lessons in a kind manner all the time.</p><h5>Reference</h5><p>[1] <a href="https://en.wikipedia.org/wiki/Tenerife_airport_disaster">Tenerife Airport Disaster</a></p><p>[2] <a href="https://www.scientificamerican.com/article/worldwide-tech-outage-started-with-defective-crowdstrike-update-to-microsoft/">Crowd Strike Incident</a></p><p>[3] <a href="https://www.usatoday.com/story/money/2024/07/20/how-microsoft-crowdstrike-update-large-impact/74477759007/">Crowd Strike Incident 2</a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Are We Being Penny Wise and Pound Foolish?]]></title><description><![CDATA[An Explosive Truth]]></description><link>https://www.cyberscribble.org/p/are-we-being-penny-wise-and-pound</link><guid isPermaLink="false">https://www.cyberscribble.org/p/are-we-being-penny-wise-and-pound</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Fri, 21 Jun 2024 10:56:29 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/934a8310-9eca-492d-9b0e-2c349331f835_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Today, as usual, we woke up in our bed, took our phone which was charging next to our head, and opened our social media feed. We saw a <a href="https://www.nbcnews.com/news/world/woman-s-headphones-explode-during-flight-china-australia-n733836">tragic story about an exploding headphone</a> in our social media timeline. The first thing we did after reading it was to scroll past it, put on our wireless headphones, and<a href="https://www.youtube.com/watch?v=A4VXwNyK-Zo"> listened to this nice song</a>. What a splendid morning indeed!</p><h4>Aegis and the Amulet </h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ghFp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ghFp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!ghFp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!ghFp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!ghFp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ghFp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:594418,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ghFp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!ghFp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!ghFp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!ghFp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba8a01b3-55ed-45ef-bdd4-bd1cfb495079_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Once upon a time, in the land of Elysia, there was an amazing hero named Aegis, famed for his cunning and bravery. No one stood a chance against him; he always emerged victorious in every battle and challenge in his life.</p><p>One day, the Oracle at Delphi invited him for a chat and warned him, &#8220;Beware, Aegis! Death will find you in the most unexpected ways.&#8221; Aegis replied, &#8220;It&#8217;s all good; I can defy death itself,&#8221; and walked off with confidence and pride.</p><p>The problem with warnings and cautions is that once you hear them, you see them everywhere. As usual, Aegis started seeing threats everywhere; even mundane events looked like potential dangers.</p><p>One evening, as Aegis was feasting with his companions, a humble traveler arrived at his camp asking for shelter and food. Aegis, being kind that day, invited the traveler to dine with him. As they dined, the traveler spoke highly of a powerful amulet that could protect its wearer from any harm.  </p><p>Intrigued by the stories he heard, Aegis inquired if he could see the amulet. The traveler produced a simple pendant from his pouch, presented it to Aegis, and said,</p><blockquote><p><strong>This amulet will protect you from any danger. All you have to do is wear it everywhere you go.</strong></p></blockquote><p>and gifted it to Aegis and left. </p><p>Aegis happily wore the amulet and felt a sense of invulnerability from that day onwards. Months went by, and Aegis started noticing strange occurrences around him. One by one, his companions fell ill or dropped dead.</p><p>Worried, Aegis brought the traveler back to his camp. This time, the traveler revealed himself to be the God of Death and laughed, saying,</p><blockquote><p><strong>One cannot defy death, Aegis. It is inevitable. You sought protection, but in your quest for safety, you invited me into your life</strong></p></blockquote><p>And moved on to claim Aegis life&#8230;</p><p>So Sad!</p><p>We are going to stop our imagination here and move on to our main theme </p><h4>The Curious Cases Of Exploding Electronics </h4><p>Recently, there have been many incidents in which the electronics we use have been exploding around us. The Federal Aviation Administration has produced amazing data on this for air incidents[1].</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rrj6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rrj6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png 424w, https://substackcdn.com/image/fetch/$s_!Rrj6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png 848w, https://substackcdn.com/image/fetch/$s_!Rrj6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png 1272w, https://substackcdn.com/image/fetch/$s_!Rrj6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rrj6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png" width="1063" height="777" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:777,&quot;width&quot;:1063,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:115250,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Rrj6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png 424w, https://substackcdn.com/image/fetch/$s_!Rrj6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png 848w, https://substackcdn.com/image/fetch/$s_!Rrj6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png 1272w, https://substackcdn.com/image/fetch/$s_!Rrj6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F834875a9-04a1-4104-87a7-2c03709c0741_1063x777.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Remember, the above chart is ONLY for the aviation industry for the past 28 years. Additionally, the New York Fire Department (FDNY) has warned that exploding lithium batteries are the primary cause of deaths and fires in the city [2]. </p><h4>Why?</h4><p>For those wondering why these devices explode, the reason comes from the power source of our devices. In the modern world, our rechargeable devices are powered by lithium batteries, which have the capability to explode under the following conditions or reasons,</p><ul><li><p>Natural defects during manufacturing</p></li><li><p>Physical damage during use</p></li><li><p>Crushing or dropping devices</p></li><li><p>Overcharging</p></li><li><p>Extreme temperatures</p></li><li><p>Aging</p></li></ul><h4>What is Powered By &#8220;Lithium Batteries&#8220; </h4><ul><li><p>Smartphones</p></li><li><p>Laptops</p></li><li><p>Tablets</p></li><li><p>Electric vehicles</p><ul><li><p>Cars / e-scooters / trucks</p></li></ul></li><li><p>Air Pods / wireless headphones</p></li></ul><h4>Stay Calm , Be Wise </h4><p>Remember, it is important to stay calm and not become paranoid about this and avoid technology altogether. The key point to remember is that for our betterment and progress, we do need these devices. </p><p>However, </p><div class="pullquote"><p><strong>HOW AND WHERE WE NEED THEM</strong></p></div><p>is the question we all need to ask ourselves.</p><h4>Cyber Hygiene </h4><p>We are going to recommend a list of cyber hygiene practices that could minimize our chances of being in the line of fire:</p><ul><li><p>Purchase original equipment</p></li><li><p>Do not overcharge</p></li><li><p>Keep devices in safe places</p></li><li><p>Do not overuse</p></li><li><p>Monitor your charging</p></li><li><p>Stay informed</p></li></ul><p>Most importantly </p><div class="pullquote"><p>&#8220;<strong>DO NOT KEEP/USE THEM CLOSE TO YOUR HEAD or BED</strong>&#8221;</p></div><h4>Parting Thoughts </h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!43wW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!43wW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!43wW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!43wW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!43wW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!43wW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:592560,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!43wW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!43wW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!43wW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!43wW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F040e5a37-7340-40d5-b1cf-7d38d0480a36_1792x1024.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As usual, since we also need to entertain the philosophical ancestors in our heads, we're going to leave you with this thought as a parting gift</p><div class="pullquote"><p><strong>In our relentless pursuit of progress, safety, and longevity, have we unknowingly invited death into our midst?</strong></p></div><p>Sayonara surfers!</p><h4>References</h4><p>[1] <a href="https://www.faa.gov/hazmat/resources/lithium_batteries/incidents">FAA Lithium Battery Incidents</a></p><p>[2] <a href="https://www.nyc.gov/site/fdny/news/Y40203/fdny-warns-lithium-ion-batteries-now-leading-cause-fires-fire-deaths-new-york">New York Fire Department Warning</a></p><p>[3] <a href="https://www.tuvsud.com/en-us/resource-centre/blogs/mobility-and-automotive/understanding-the-new-eu-battery-regulation">EU Lithium Battery Regulation</a> </p><p></p>]]></content:encoded></item><item><title><![CDATA[Click Not Required: Unveiling the Stealth of Zero Click Attacks]]></title><description><![CDATA[I Didn't Click, Am I Really Safe?]]></description><link>https://www.cyberscribble.org/p/click-not-required-unveiling-the</link><guid isPermaLink="false">https://www.cyberscribble.org/p/click-not-required-unveiling-the</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Sun, 05 May 2024 22:18:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nEZl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In the context of spam/phishing messages, we're often wired to think, </p><div class="pullquote"><p><strong>'If I didn't click, I'm safe.'</strong> </p></div><p>While this holds true much of the time, there was a spyware named Pegasus that made headlines recently, proving otherwise</p><p>This notorious malicious software which was named after <a href="https://en.wikipedia.org/wiki/Pegasus">Greek mythological horse Pegasus</a> introduced the concept of &#8216;<strong>no-click</strong>&#8217; or &#8216;<strong>zero-click</strong>&#8217; hacking to devices we use, challenging our conventional understanding of digital safety</p><h3>Zero-click</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nEZl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nEZl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!nEZl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!nEZl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!nEZl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nEZl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:260156,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nEZl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!nEZl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!nEZl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!nEZl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F265d7f07-246b-42e1-ab17-417912f2f675_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Zero-click techniques are a type of cyber attack where an individual's device can be compromised <strong>without the need for the user to interact with a suspicious link or message.</strong>&nbsp;</p><p>Normally, we think of cybersecurity threats as something we have to "act" on, like opening a dubious email attachment or clicking a questionable link. However, with zero-click attacks, the malicious software can be installed simply through the device receiving the malicious message.</p><h3>The Silent Intrusion</h3><p>Individuals affected by the Pegasus breach received typical phishing or spam messages on their mobile devices, including:</p><ul><li><p>Bogus mobile boarding passes</p></li><li><p>Fraudulent package delivery notifications </p></li><li><p>Counterfeit Twitter news update messages</p></li><li><p>WhatsApp Missed Calls</p></li></ul><p>Although users <strong>were cautious and refrained from clicking on the links</strong>, believing themselves to be safe, this unfortunately was not the case.</p><h3>Zero Day</h3><p>The silent intrusion was made possible due to unknown weaknesses in software such as WhatsApp and iMessage. These weaknesses, professionally termed 'Zero-Day' vulnerabilities, allowed actors to install malicious software on your phone without even clicking a single link.</p><h3>Capabilities</h3><p>Pegasus is claimed to have/had following capabilities at minimum</p><ul><li><p>Intercept and read messages from applications like WhatsApp and iMessage.</p></li><li><p>Access call logs, contacts, and browser history.</p></li><li><p>Activate microphones and cameras to survey the physical environment.</p></li><li><p>Track the device's location.</p></li><li><p>Harvest information from apps, including credentials and data from banking and social media applications.</p></li></ul><h3>Victims</h3><ul><li><p>iPhones</p></li><li><p>Androids</p></li></ul><h3>The Fix</h3><p>It&#8217;s worth noting that both Apple and Google have made strides in patching vulnerabilities as they are discovered, improving the security of their devices to protect against such invasive software. However, the nature of zero-day vulnerabilities means that entirely securing against unknown exploits remains a challenge.</p><h3>Detecting Pegasus</h3><p>Amnesty International released an open-source utility called the Mobile Verification Toolkit, designed to detect traces of Pegasus[3]. While useful, this tool requires some expert capability and should be used with care.</p><h3>Cyber Hygiene Tips</h3><p>What can we do to protect ourselves from such attacks in the future? To be honest, zero-day attacks are difficult to defend against, since no one knows these vulnerabilities exist in the first place. However, we can minimize their impact and reach by adhering to 'cyber hygiene principles', which include</p><ul><li><p>Perform regular updates of operating systems and security patches</p></li><li><p>Use a reputable security software</p></li><li><p>Stay informed on cyber security and &#8220;hygiene&#8221; perspective </p></li></ul><h3>Stay Alert, Not Alarmed</h3><p>Our intention is not to provoke anxiety but to foster vigilance. This article aims to enhance awareness of potential cybersecurity threats, empowering you to stay alert and secure in the digital landscape.</p><h3>References</h3><p>[1] <a href="https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/">Amnesty Report</a></p><p>[2] <a href="https://www.secureworld.io/industry-news/cisa-iphones-pegasus-spyware-zero-days">CISA Advisory</a></p><p>[3] <a href="https://docs.mvt.re/en/latest/">Mobile Verification Toolkit</a></p>]]></content:encoded></item><item><title><![CDATA[Deepfake Alert: Could We Be Next? ]]></title><description><![CDATA[The Imminent Reality of Your Deepfake Video is closer than you think]]></description><link>https://www.cyberscribble.org/p/deepfake-alert-could-we-be-next</link><guid isPermaLink="false">https://www.cyberscribble.org/p/deepfake-alert-could-we-be-next</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Tue, 30 Apr 2024 11:28:02 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/aa6876b7-2374-47b1-aa3f-8edc0dc6ed71_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QpXk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QpXk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!QpXk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!QpXk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!QpXk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QpXk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:366744,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QpXk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!QpXk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!QpXk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!QpXk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91608546-e821-45ad-bdc3-66b647dcac7f_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Microsoft recently announced a groundbreaking technology capable of crafting highly realistic videos from a mere single image. At first glance, this innovation promises a wave of practical applications&#8212;imagine animating historical figures for educational purposes or revitalizing family photos in new and dynamic ways.</p><p>However, this technology also opens Pandora's box for hackers and pranksters. With just one image, a person could become the unintentional star of an online video without ever stepping in front of a camera. Now, your awkward driver's license photo could be used to deliver a TED Talk.</p><p>Let&#8217;s look in to the implications and impact of this technology in detail.</p><h3>What is Deepfake?</h3><p>Think of Deepfakes as a high-tech version of a common prank from the past. Some of us may recall a friend who would call us and mimic another friend's voice or a celebrity's, to trick us into doing something funny.</p><p>Deepfake technology takes this concept to the next level, allowing someone to create videos or audio clips that look and sound convincingly real, making the prank, or the potential deception, much more impactful and harder to detect.</p><h3>What is Different Now  ?</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U3PL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U3PL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!U3PL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!U3PL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!U3PL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U3PL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp" width="724" height="413.7142857142857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:724,&quot;bytes&quot;:250956,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!U3PL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!U3PL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!U3PL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!U3PL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd717138c-07b5-402e-94e2-1379beef815b_1792x1024.webp 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Traditionally,  creating Deepfakes was almost a high-budget production, requiring a large amount of video data to convincingly mimic someone. This steep requirement generally reserved the honor of being Deepfaked for celebrities and public figures.</p><p>However, with Microsoft's latest innovation, the cost of entry into the Deepfake club has drastically reduced to just possessing a single image. Yes, that one awkward passport photo in your drawer is now enough to cast you in an unexpected role in a viral video. </p><p>It's just a click away</p><h3>Why People Do Deepfakes ?</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z7S_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z7S_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!Z7S_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!Z7S_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!Z7S_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z7S_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:913962,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z7S_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!Z7S_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!Z7S_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!Z7S_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8aa502d-0d90-4c7e-8958-48d2ba9a1691_1792x1024.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p>Personal Revenge </p><ul><li><p>Creating damaging videos / content to damage someone&#8217;s reputation</p></li></ul></li><li><p>Financial Gain </p><ul><li><p>Using you video to get access to gain financial benefit from institutions</p></li></ul></li><li><p>Entertainment </p><ul><li><p>For amusement </p></li></ul></li><li><p>To Spread Misinformation</p><ul><li><p>Political or Personal Agenda</p></li></ul></li></ul><h3>How Can I Be Deepfaked ?</h3><p>There are many ways to be Deeepfaked, We will list couple of most popular of them here </p><ul><li><p>Attacker creating a video that appears to show an individual engaging in illegal or morally questionable behavior. The attacker then threatens to release the video to the public</p></li><li><p>In a sophisticated financial scam, Deepfake technology could be used to impersonate an individual&#8217;s loved ones in a video, urgently requesting money for an emergency, compelling the victim to act quickly</p></li></ul><h3>What is Microsoft doing about it ?</h3><p>Microsoft has no plans to release it to the general public for now, providing one relief amidst ongoing concerns about potential misuse.</p><p>We are going take this moment to thank Microsoft for this, if they hadn't done the research and told us upfront, we wouldn't have even known this is a reality! </p><p>So we are gonna go ahead and say &#8220;Let's give a round of applause to Microsoft&#8221; </p><h3>How to Protect Yourself from Deepfake Exploitation ?</h3><ul><li><p>Verify before you Act or Believe </p><ul><li><p>Always verify the information ( Video/Audio) before acting on it </p></li></ul></li><li><p>Educate and Be Aware of &#8220;Deep Fakes&#8221;</p><ul><li><p>Educate everyone around you, Most importantly our non-tech savvy older generations</p></li></ul></li><li><p>Strengthen your online Privacy</p></li><li><p>Report / Remove Illegal Content</p></li><li><p>Take Legal Action </p></li></ul><h3>Where Can I Read More About This ?</h3><ul><li><p><a href="https://www.microsoft.com/en-us/research/project/vasa-1/">VASA - 1</a></p></li></ul><p></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Type at Your Own Risk: Your Keyboard Might Be Gossiping]]></title><description><![CDATA[Ahem, ahem! Next time you confess your undying love for V from BTS in a text, you might want to look over your shoulder. Your friendly keyboard app could be the biggest gossip hippie in the town! According to the vigilant dogs at Citizen Lab, University of Toronto, most pinyin keyboard apps are not just typing aides&#8212;they're potential tattletales, ready to spill your secrets to anyone listening in. So, before you pour your heart out, remember: loose keystrokes sink ships!]]></description><link>https://www.cyberscribble.org/p/type-at-your-own-risk-your-keyboard</link><guid isPermaLink="false">https://www.cyberscribble.org/p/type-at-your-own-risk-your-keyboard</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Wed, 24 Apr 2024 21:00:15 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b64b9947-9a85-4aed-96d4-f728b2a61ba8_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w2Mn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w2Mn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!w2Mn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!w2Mn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!w2Mn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w2Mn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:979412,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w2Mn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!w2Mn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!w2Mn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!w2Mn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d16d5d0-f38e-4132-9708-ef16465f5bd5_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Next time you confess your undying love for <a href="https://en.wikipedia.org/wiki/V_(singer)">V from BTS</a> in a text, you might want to look over your shoulder. Your friendly keyboard app could be the biggest gossip puppy in the town! </p><p>According to the vigilant dogs at <a href="https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/">Citizen Lab</a>, University of Toronto, most pinyin keyboard apps are not just typing aides, they're potential informants, ready to spill your secrets to anyone listening in. </p><p>Alright, we can hear you all screaming at the top of your lungs, "<strong>Hey, what is going on?</strong> <strong>I don't get it!</strong>" We totally get the confusion, Let&#8217;s see if we can clear the air</p><h4>What is Pinyin Keyboard Apps ? </h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBdx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBdx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!xBdx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!xBdx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!xBdx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBdx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:393368,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xBdx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!xBdx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!xBdx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!xBdx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30941750-de70-4fc2-9d6a-c1ef27fc9b13_1792x1024.webp 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the Western world, they're broadly known as IMEs&#8212;Input Method Editors. These are the keyboard apps you use on your mobile phones to type in languages like English, Chinese, Japanese, or various Indic scripts. Simply put, they help us communicate in languages with just a few taps in our mobile phones and other systems.</p><h4>What is wrong with them now  ? </h4><p>Good Citizens at Citizen Lab have uncovered, when those keyboard apps tap into cloud services for handy features like predicting text and autocorrect, there&#8217;s a little hiccup, Due to some security loopholes, it&#8217;s not just your phone catching the wind of your epic typing skills, </p><blockquote><p>some uninvited eavesdroppers might be getting the memo too!</p></blockquote><p>So next time you&#8217;re dishing out your hottest takes on this article, just remember: your keyboard might be letting us in on the joke too.</p><h4>Which Apps Are Affected  ? </h4><p>There is a big list published<a href="https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/"> in this Article</a> but We are gonna let you all know the most popular ones that MAY be affected</p><ul><li><p>QQ Pinyin</p></li><li><p>Samsung Keyboard</p></li><li><p>Sogu IME</p></li><li><p>Baidu IME</p></li><li><p>iFlytek IME</p></li><li><p>Sogou IME Custom Version</p></li></ul><h4>Does this mean Hackers have my data and passwords ?</h4><p>We cannot verify if someone has/is eavesdropped/eavesdropping on you, but according to Citizen Lab, </p><div class="pullquote"><p>Certain apps do have security weaknesses which can enable malicious actors to do so. </p></div><h4>What Are  the Recommendations ? </h4><ol><li><p>QQ pinyin keyboard users should switch to alternative keyboards immediately.</p></li><li><p>Users of Sogou, Baidu, or iFlytek keyboards should update their keyboards and operating systems.</p></li><li><p>Baidu IME keyboard users should switch keyboards or disable "cloud-based" features.</p></li><li><p>Avoid enabling "cloud-based" prediction features on keyboards or IMEs if concerned about privacy.</p></li><li><p>Users concerned about privacy should not grant "Full Access" to their keyboards or IMEs.</p></li></ol><h4>Where Can I find More Information</h4><p>[1]<a href="https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/"> vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers</a></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Chirp's Faux Pas: Hardcoded Credentials - not a smart move? or a false positive ?]]></title><description><![CDATA[Smart homes, where everything from the locks to the light is controlled with a swipe of your phone. Ah, the marvels of modern technology! But guess what? There's been a little hiccup in the paradise lately As per to CISA&#8217;s latest advisory , Chirp Systems]]></description><link>https://www.cyberscribble.org/p/chirps-faux-pas-hardcoded-credentials</link><guid isPermaLink="false">https://www.cyberscribble.org/p/chirps-faux-pas-hardcoded-credentials</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Tue, 23 Apr 2024 18:18:01 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b38a6b6f-721a-4ee5-865e-d492d626cf92_1024x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Smart homes, where everything from the locks to the light is controlled with a swipe of your phone. The marvels of modern technology! But guess what? There's been a little hiccup in the paradise lately</p><p>As per to <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-067-01">CISA&#8217;s latest advisory</a> , <a href="https://www.chirpsystems.com/">Chirp Systems</a> , who is known for their smart locks and their cool smart phone app &#8220;<a href="https://play.google.com/store/apps/details?id=com.chirp.access">Chirp Access</a>&#8221; hardcoded some credentials into their application. Now, for the uninitiated, that's like leaving the keys to your house under the welcome mat. </p><p>Alright, We see you are panicking to see whether you are affected ! as usual We are going leave here with set of toddler questions and answers</p><h4>Am I Affected ?</h4><p>We are not your cyber doctor, but easiest way to find out is </p><ul><li><p>open your phone </p></li><li><p>search for apps &#8220;Chirp Access&#8221;</p></li><li><p>You MAY be affected</p></li></ul><h4>I have &#8220;Chirp Access&#8221; app on my phone ! What is next ? </h4><p>Ok this is where it gets weird , Chirp system has <a href="https://statement.chirpsystems.com/chirp-systems-icsa-24-067-01-response.html">released a press release</a> , </p><blockquote><p>&#8220;Dear customers, We have conducted our own little nice investigation on this and found zero evidence of any issues! </p></blockquote><p>The wonders of modern security theater! </p><h4>I am confused, Any advice ? </h4><p>The best approach forward is to observe the developments on this field both from Chirp System side as well as on CISA side. In the mean time, finding alternative ways to secure your door would be beneficial.</p><h4>Shout outs! </h4><p>We are going to give a shoutout to &#8220;Matt Brown who reported this vulnerability to CISA&#8221;. a little kudo&#8217;s to Chirp Systems for taking time to respond to the events.</p><p></p>]]></content:encoded></item><item><title><![CDATA[MITRE cooperation hacked through Ivanti flaw]]></title><description><![CDATA[So, MITRE's NERVE network, where all the cool research and collabs happen, got gate crashed by a foreign nation-state threat actor.]]></description><link>https://www.cyberscribble.org/p/mitre-cooperation-breached-through</link><guid isPermaLink="false">https://www.cyberscribble.org/p/mitre-cooperation-breached-through</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Mon, 22 Apr 2024 17:54:59 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/20ad7274-0e1e-46e9-bfc4-fa38badaf2bd_1792x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1XeW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1XeW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!1XeW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!1XeW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!1XeW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1XeW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:589842,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1XeW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!1XeW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!1XeW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!1XeW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdfb5250-c878-4a0a-a398-289e5a883810_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>So, MITRE's NERVE network, where all the cool research and collabs happen, got gate crashed by a foreign nation-state threat actor. MITRE has contacted authorities and notified affected parties and is working to restore operational alternatives for collaboration in an expedited and secure manner</p><p>I am going to leave some basic questions and answers bellow to provide more clarity</p><h4>Who is MITRE ?</h4><ul><li><p>Not for profit Organization based in US</p></li><li><p>Funded primarily by US Government </p></li><li><p>Provides services in defense, cybersecurity, healthcare and transportation</p></li><li><p>Their popular initiatives </p><ul><li><p><a href="https://cve.mitre.org/">CVE</a></p></li><li><p><a href="https://cwe.mitre.org/">CWE</a></p></li><li><p><a href="https://attack.mitre.org/">MITRE ATT &amp; CK</a></p></li></ul></li></ul><h4>What is Ivanti Flaw ?</h4><p>A known weakness in <a href="https://www.ivanti.com/products/connect-secure-vpn">Ivanti Connect Secure </a>VPN solution which enables unauthorized access to sensitive data primarily through <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21893">server side request forgery</a></p><h4>What is  the impact for MITRE ?</h4><p>As per to MITRE , one of their <a href="https://www.mitre.org/news-insights/impact-story/it-takes-nerve-bring-isolated-labs-people-together">Unclassified Research Prototype NERVE</a> was breached</p><h4>References</h4><p>[1] <a href="https://www.mitre.org/news-insights/news-release/mitre-response-cyber-attack-one-its-rd-networks">MITRE press release</a></p><p>[2] <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b">CISA advisory on Ivanti Flaw</a></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISA joins MSVP working group]]></title><description><![CDATA[Who is CISA ? CISA is the US organization responsible for federal cybersecurity and national coordinator for critical infrastructure security and resilience What is MVSP ? MSVP stands for Minimum Viable Security Product Why do we need a MVSP ? Ensure a product is &#8220;]]></description><link>https://www.cyberscribble.org/p/cisa-joins-msvp-working-group</link><guid isPermaLink="false">https://www.cyberscribble.org/p/cisa-joins-msvp-working-group</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Thu, 04 Apr 2024 11:29:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9d51c08b-9838-4f04-8637-5b8d734fb83a_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><a href="https://www.cisa.gov/">CISA</a> just joined the <a href="https://mvsp.dev/">Minimum Viable Secure Product</a> (MVSP) Working Group, and it is a great news! They've been actively working on their Secure by Design initiative, and now they're diving into the details of asking the right questions to software manufacturers.</p><h4>Who is CISA ?</h4><p>CISA is the US organization responsible for federal cybersecurity and national coordinator for critical infrastructure security and resilience</p><h4>What is MVSP ?</h4><p>MSVP stands for Minimum Viable Security Product </p><h4>Why do we need  a MVSP ?</h4><p>Ensure a product is &#8220;<a href="https://cyberscribble.substack.com/p/secure-by-default-from-mythology">Secure by Default</a>&#8221; for end-users and enterprises</p><h4>What is MVSP Working Group?</h4><p>Picture this: the MVSP Working Group is like a gathering of tech titans, with heavyweights like Google and Netflix teaming up to tackle the colossal task of "Secure by Design" and "Security by Default." It's like the Avengers assembling to save the digital world from cyber chaos!</p><h4>What does this mean for us?</h4><p>CISA joining MSVP working group would benefit the &#8220;Secure by Default&#8221; initiative in multitude ways </p><ul><li><p>Access  to expertise</p></li><li><p>Larger influence and advocacy</p></li><li><p>Resource  sharing</p></li><li><p>Better standardization </p></li><li><p>Promotes transparency and collaboration  </p></li></ul><h4>The irony! </h4><p>Oh, We are loving the irony here! So, since we're dubbing it the "Minimum Viable Security Product," does that mean the security is just gonna be... well, minimum? &#128517; But hey!, we kid, we kid! Who needs maximum security when you can have the bare minimum, right?</p><h4></h4>]]></content:encoded></item><item><title><![CDATA[Cyber Security Framework 2.0 released by NIST]]></title><description><![CDATA[What is &#8220;Cyber Security Framework&#8221; ? The NIST Cybersecurity Framework is a set of guidelines, best practices, and standards designed to help organizations manage and improve their cybersecurity posture. Alright that was a bit of bummer , let it me break it down in superhero terms]]></description><link>https://www.cyberscribble.org/p/cyber-security-framework-20-released</link><guid isPermaLink="false">https://www.cyberscribble.org/p/cyber-security-framework-20-released</guid><dc:creator><![CDATA[Unknown]]></dc:creator><pubDate>Mon, 26 Feb 2024 14:12:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/a2445e59-4137-40c7-abe1-8452290d9df8_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Yo, check it&#8212;NIST just dropped <a href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf">CSF 2.0,</a> and it's making waves! &#127754; With added governance, it's like cybersecurity meets the boardroom! We all know boardrooms and cybersecurity are like the ultimate frenemies. They're like lovers who can't stand each other, but deep down, they know they need each other to survive. It's a match made in... well, maybe not heaven, but definitely in the digital realm. CSF2.0 is going to reduce the gap on this front for sure! or MAY BE NOT ! ha ha ha</p><p>Anyway as usual, some baby questions to take the first steps </p><h4>What is &#8220;Cyber Security Framework&#8221; ?</h4><p>The NIST Cybersecurity Framework is a set of guidelines, best practices, and standards designed to help organizations manage and improve their cybersecurity posture.</p><p>Alright that was a bit of bummer , let it me break it down in superhero terms</p><p>Cybersecurity Framework is like a treasure map for companies. It gives them step-by-step instructions on how to protect their digital stuff, like their websites and important data, from bad guys who try to break in and cause trouble. </p><h4>Who is behind &#8220;Cyber Security Framework&#8221; ?</h4><p>National Institute of Standards and Technology (NIST), which is a part of the U.S. Department of Commerce is behind this initiative</p><h4>What is new in 2,0 ?</h4><ul><li><p>Introduces a sixth function &#8220; Govern&#8221; </p></li><li><p>&#8220;Implementation Examples&#8221; are a cool addition </p></li><li><p>Better &#8220;Integration with other frameworks&#8221; such as CIS , ISO27001</p></li><li><p>Emphasize on &#8220;Supply chain security&#8221; </p></li></ul><h4>Whom does it concern ?</h4><ul><li><p>Executives (  CEO, CTO, COO etc. )</p></li><li><p>Cyber security professionals </p></li><li><p>Risk managers</p></li><li><p>Regulators and policy makers</p></li></ul><h4></h4><p></p><h4></h4><p></p><p></p>]]></content:encoded></item></channel></rss>