Pseudorandom Thoughts
419 subscribers
96 photos
8 files
337 links
我将开口,同时爽到爆。
Download Telegram
最新指示:安全公司一定要搞好安全
💊18
这玩意和配套的基础设施如果能早8年出来,电信诈骗还会不会这么猖獗?


《国家网络身份认证公共服务管理办法》
https://mp.weixin.qq.com/s/mmiDDv_Aoxi3QWF8S2dETg
昨天晚饭前在附近的松树林里闲逛,看到从蚂蚁窝中拱出的朴实无华的棕色蘑菇,感到好奇还用手拔了一颗。

咨询菌类大佬,答曰是假灰托鹅膏,常与松树共生。搜了下似乎有剧毒,还好饭前洗了手,否便样衰了
💊13🎉1
Forwarded from vx-underground
It's so incredibly depressing seeing young people, such as Kai West a/k/a IntelBroker, throw away their lives.

Let's think about it for a second.

If Mr. West is found guilty (which he probably will), he is facing 20 years (or more) in federal prison.

Think about how insanely long 20 years is. When Mr. West is released from prison he will be about 45 years old. He will have spent a good portion of his adult life in a prison cell.

I myself personally will be well into my 50s. My son will be in his 20s.

Many of you, who I know interacted with Mr. West, will be well into your 30s, or 40s. Many of you will have settled down and be married with children.

Celebrities we know right now will become irrelevant or die. Many current politicians will succumb to old age and die. If Mr. West has any beloved pets they will be dead.

Assuming Mr. West's parents are in their 40s right now, when he is released they'll be considered senior citizens. Mr. West will spend every Christmas, New Year's, Birthday, and even funerals, behind bars thousands of miles away from his friends and family.

Think of how many Threat Groups and Threat Actors appeared 20 years ago. How many do you remember? How many of you remember zf0? Presumably very few.

In 20 years Breached and Raid will likely be a distant memory that will be brought up on occasion or when discussing the history of cybercrime. IntelBroker may or may not be discussed. Regardless, as life carries on he will be locked in a cell.

That sucks so much
🎉2💊1
《关键信息基础设施商用密码使用管理规定》

https://mp.weixin.qq.com/s/CMh619o2wZX3RKsamwOD4A
祝各位防守队成员入口全收敛,终端全覆盖,数据零出域,主防零失分,报告有表彰,态感抓0day,云墙全挡出,白班有零食,夜班玩一晚,交班error: You have an error in your sql syntax; check the manual that corresponds to your
MySQL server version for the right syntax to use near ' '' at line 1
🎉5💊1
我要是G侧APT/黑产团队,直接对着附件的表格干活,你不就炸了么(
Forwarded from Sukka's Notebook
恭喜 TailScale 拿到了 192.200.0.0/24 和 2606:B740:49::/48 。TailScale 的 API、控制平面从 2025 年 7 月 15 日(UTC+0)起将开始使用来自该 IP 段内的静态 IP。
最近在忙着搞蓝队运营的活各处调研,看到GCP的Security Posture管理直接nm破防了,人家一整套CSPM已经做到去跟合规标准对齐而且还跟进到最新最热大模型产品了,policy, constraint和detector按层次一条条id列好实现,乃至于直接给IaC做校验。

反观国内的CSPM/ASPM,项目经理是要求会喝酒的,安全开发是写漏洞的,接口是封闭的,告警是洪泛的,BAS是不分青红皂白的,交付上来就是堆人,然而高级的蓝队帕鲁要去跟开发网络运维和领导开会扯皮,低级的蓝队帕鲁没日没夜盯屏盯成dumb,有电脑中级高手打进来了要严肃问责,全天无事发生领导又觉得你没有工作量,钱用多了审计部门还要你“老实交代”,本质上还是做人的system,领导觉得安全你就不用搞了,领导觉得慌了又要你尽可能节约地排个一堆设备一堆拓扑一堆框框的PPT给他安全感,而没有个理性的量化的指标。
💊11