it

Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT Malware

Cybersecurity researchers have discovered a new phishing campaign that spreads a new fileless variant of known commercial malware called Remcos RAT. Remcos RAT "provides purchases with a wide range of advanced features to remotely control computers belonging to the buyer," Fortinet FortiGuard Labs researcher Xiaopeng Zhang said in an analysis published last week. "However, threat actors have




it

HPE Issues Critical Security Patches for Aruba Access Point Vulnerabilities

Hewlett Packard Enterprise (HPE) has released security updates to address multiple vulnerabilities impacting Aruba Networking Access Point products, including two critical bugs that could result in unauthenticated command execution. The flaws affect Access Points running Instant AOS-8 and AOS-10 - AOS-10.4.x.x: 10.4.1.4 and below Instant AOS-8.12.x.x: 8.12.0.2 and below Instant AOS-8.10.x.x:




it

Security Flaws in Popular ML Toolkits Enable Server Hijacks, Privilege Escalation

Cybersecurity researchers have uncovered nearly two dozen security flaws spanning 15 different machine learning (ML) related open-source projects. These comprise vulnerabilities discovered both on the server- and client-side, software supply chain security firm JFrog said in an analysis published last week. The server-side weaknesses "allow attackers to hijack important servers in the




it

The ROI of Security Investments: How Cybersecurity Leaders Prove It

Cyber threats are intensifying, and cybersecurity has become critical to business operations. As security budgets grow, CEOs and boardrooms are demanding concrete evidence that cybersecurity initiatives deliver value beyond regulation compliance. Just like you wouldn’t buy a car without knowing it was first put through a crash test, security systems must also be validated to confirm their value.




it

THN Recap: Top Cybersecurity Threats, Tools, and Practices (Nov 04 - Nov 10)

⚠️ Imagine this: the very tools you trust to protect you online—your two-factor authentication, your car’s tech system, even your security software—turned into silent allies for hackers. Sounds like a scene from a thriller, right? Yet, in 2024, this isn’t fiction; it’s the new cyber reality. Today’s attackers have become so sophisticated that they’re using our trusted tools as secret pathways,




it

New Ymir Ransomware Exploits Memory for Stealthy Attacks; Targets Corporate Networks

Cybersecurity researchers have flagged a new ransomware family called Ymir that was deployed in an attack two days after systems were compromised by a stealer malware called RustyStealer. "Ymir ransomware introduces a unique combination of technical features and tactics that enhance its effectiveness," Russian cybersecurity vendor Kaspersky said. "Threat actors leveraged an unconventional blend




it

New Phishing Tool GoIssue Targets GitHub Developers in Bulk Email Campaigns

Cybersecurity researchers are calling attention to a new sophisticated tool called GoIssue that can be used to send phishing messages at scale targeting GitHub users. The program, first marketed by a threat actor named cyberdluffy (aka Cyber D' Luffy) on the Runion forum earlier this August, is advertised as a tool that allows criminal actors to extract email addresses from public GitHub




it

New Flaws in Citrix Virtual Apps Enable RCE Attacks via MSMQ Misconfiguration

Cybersecurity researchers have disclosed new security flaws impacting Citrix Virtual Apps and Desktop that could be exploited to achieve unauthenticated remote code execution (RCE) The issue, per findings from watchTowr, is rooted in the Session Recording component that allows system administrators to capture user activity, and record keyboard and mouse input, along with a video stream of the




it

Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler Bugs

Microsoft on Tuesday revealed that two security flaws impacting Windows NT LAN Manager (NTLM) and Task Scheduler have come under active exploitation in the wild. The security vulnerabilities are among the 90 security bugs the tech giant addressed as part of its Patch Tuesday update for November 2024. Of the 90 flaws, four are rated Critical, 85 are rated Important, and one is rated Moderate in




it

WHY COMPETITION IS RELEVANT TO SELF-DEFENSE

Recently saw this on YouTube, from a grandmaster competition shooter who is also in law enforcement. I agree with him. I’ve said for years that while a shooting match is not a gunfight, a gunfight most certainly is a shooting match. Competition experience makes shooting under pressure the norm. Wyatt Earp competed in the informal […]




it

THE NEXT TIME AN ANTI-GUNNER SAYS CITIZENS’ RIFLES ARE USELESS AGAINST ARMIES…

…remind them of this. I was recently reading “Andrew Jackson and the Miracle of New Orleans” by Brian Kilmeade and Don Yeager. The War of 1812 was going badly for the Americans. The British had burned the White House, and a huge contingent of British troops was in Louisiana planning to march north in conquest. […]




it

Bripe and the world Bripes with you

This is, without doubt, the stupidest coffee device I have ever bought. But I have bought it.




it

Writing through cringe

For the first day of NaBloPoMo (National Blog Posting Month), I want to start with something difficult, and the reason why I’m participating in this monthly challenge.

I’ve lost all affection for my writing voice, and I don’t entirely know why.

These days, it’s challenging for me to get excited about writing anything personal. Everything I post, aside from ink swatches, makes me cringe, even simple replies to others' posts. When I started writing online, it was so easy to share any little moss-bulb of detail, despite lacking confidence in my voice or purpose. It was enough to noodle in public; I had a stage (my website) and tap-tap-tapping its microphone didn’t make me feel immediately self-conscious.

A few years ago, I pushed — harder than I’ve pushed for many things in my life — for the “community” aspect of Micro.blog to be more than a shared timeline. I wanted it to be something I could lean back softly into, both an audience and support group, comprised of people who shared the same penchant for collecting and amplifying small treasures of moments.

The people exist (and they are wonderful, I read what they share with delight) but the community? I know now that what I was asking for doesn’t exist online in the same way it did, but I didn’t know that yet. I kept pushing and pushing, until one day I just … stopped. Everything I said seemed to repulse people instead of drawing them closer. It was easier to find what I needed and wanted in the friendships I was slowly and intentionally building offline than it was for me to do that online. And that was a first for me. Much of my life, up to that point, had been spent focusing on connecting online.

Because much of my life, up to that point, had been lived online.

I don’t really want to go back to living so much online. But sometimes I’m nostalgic for the feeling of being understood through my writing, shades of myself that I don’t know how to represent except through words.

It’s supremely cringey even to post this, but I’m going to push through in the hopes there’s some self-acceptance on the other side of it. I’m not ready to stop writing altogether. In some ways, I feel like I’ve barely begun.




it

Building community offline

I was overwhelmed by the response to my last post, and so grateful for the reminder that there is still connection to be found online, I just need to push through my own self-consciousness to find it. And I have many good models for this behavior, people who are quick with a kind and supportive word, people who do not shy away from nuance.

Today I spent the day offline in the company of people like this, a small group of friends that gathers once a month to share our love of stationery: pens, ink, paper, notebooks, planners, postal mail, and the like. We sit around a big table and journal together while chatting, snacking, and drinking lattes carefully crafted by FunkyPlaid. The middle of the table soon fills with stickers, stamps, inks, and washi tapes that we’ve brought to share with each other.

As I look around the table at these treasured people, I think about how much work goes into building community. Healthy communities take intention, upkeep, energy, and shared values. This gathering happens every month because we invest all of this into making it happen. As hosts, FunkyPlaid and I make sure people feel cared for with food and drink in a clean and welcoming space. As guests, everyone brings what they want to share, and expresses interest in what they are interested in (and refrains from expressing disdain for what they aren’t).

It’s a lot of work, joyful work. And this work results in a day each month to anticipate, and memories to hold close the rest of the month. I hope never to take this community for granted.




it

LA man wearing GPS ankle monitor is accused of a robbery string. Officials can't track him




it

SF Muni finally ditching floppies




it

Tribal digital sovereignty in today's dystopia




it

Anthropic Wants Its AI Agent to Control Your Computer




it

Nobody wants Copilot Pro AI for Office365, so Microsoft will force-bundle it and raise the price?




it

When Google's AI agent messes with ya'




it

Annoyed Redditors tanking Google Search results illustrates perils of AI scrapers




it

Man who made 'depraved' child images with AI jailed




it

X is the latest social media site letting 3rd parties use your data to train AI models




it

Username Over 52 Characters with No Password says Okta




it

1700 letters from the tax office: Daylight exit messed up




it

WNBA is totally annoying, here’s how to fix it for Caitlin Clark’s arrival

Professional women’s basketball is a cesspool of mediocrity full of women gatekeeping so the sport can’t change. Fortunately, incoming rookie Caitlin Clark is worth more than the entire WNBA due to her sponsorships. This means that unlike other players, Clark doesn’t work for the WNBA she works for her sponsors and her fans. Also, Clark […]

The post WNBA is totally annoying, here’s how to fix it for Caitlin Clark’s arrival appeared first on Penelope Trunk Careers.




















it

White label auction

Update: today at 2pm UK time.

Final prices 

Pornography - £1,000
The Head on the Door - £800
Show - £750
Wish - £600
The Top - £800
Japanese Whispers - £700
Paris - £850
Greatest Hits - £1,000


The White Label Auction In Aid of The BRIT Trust

Upcoming auction from Omega Auctions. 

8 from The Cure, all signed by Robert Smith.

Pornography 
The Head on the Door 
Show
Wish
The Top
Japanese Whispers 
Paris
Greatest Hits

Thanks, JC










it

Lost World Deluxe Digital Download

Update: Now available in the UK store too, but only until midnight tonight (Nov. 7th).

It's now available in the EU and AU shops as well.


Available from The Cure shop (US only, but there are ways around that):

THE CURE SONGS OF A LOST WORLD (DELUXE) DIGITAL DOWNLOAD (MP3 & FLAC)

US $4.99

DELUXE DIGITAL ALBUM FEATURES SONGS OF A LOST WORLD STANDARD TRACKLIST PLUS FIVE LIVE BONUS TRACKS RECORDED AT SHORELINE AMPHITHEATER IN 2023.

TRACKLIST:

1.ALONE

2.AND NOTHING IS FOREVER

3.A FRAGILE THING

4.WARSONG

5.DRONE:NODRONE

6.I CAN NEVER SAY GOODBYE

7.ALL I EVER AM

8.ENDSONG

9.ALONE : LIVE @ SHORELINE AMPHITHEATER 2023

10.AND NOTHING IS FOREVER : LIVE @ SHORELINE AMPHITHEATER 2023

11.A FRAGILE THING : LIVE @ SHORELINE AMPHITHEATER 2023

12.I CAN NEVER SAY GOODBYE : LIVE @ SHORELINE AMPHITHEATER 2023

13.ENDSONG : LIVE @ SHORELINE AMPHITHEATER 2023

LIVE @ SHORELINE AMPHITHEATER 2023




it

Interview with Ben from Polydor

From Music Week:

"Robert Smith is beyond passionate": Polydor's Ben Mortimer on The Cure's triumphant return to No.1

by George Garner

It was very much a case of Friday, The UK's In Love for The Cure, as the iconic group and their label Polydor celebrated an incredible charts results day on Friday, November 8. 

More than 32 years after their only previous No.1 album, Robert Smith’s band marked an emphatic return to the top of the chart with their 14th studio release – and first for 16 years – Songs Of A Lost World.

Indeed, Polydor co-president Ben Mortimer has told Music Week that even when held against their own lofty expectations, the response from the public has been "overwhelming". Songs Of A Lost World has effectively done seven times the first week sales of 2008's 4:13 Dream, and outsold three of their last four albums' entire lifetime sales in one week. 

So, how does it look when broken down?

Well, for one, The Cure outsold the rest of the Top 5 combined, with a stellar opening frame of 51,362 sales (19,838 CDs, 23,182 vinyl albums, 1,219 cassettes, 4,546 digital downloads and 2,577 sales-equivalent streams) according to Official Charts Company data.

First week sales of Songs Of A Lost World are, in fact, the fifth highest on debut for any album in 2024, trailing only Taylor Swift’s The Tortured Poets Department (270,091), Coldplay’s Moon Music (236,796), Sabrina Carpenter’s Short N’ Sweet (89,658) and Billie Eilish’s Hit Me Hard & Soft (67,111). 

For further context, let's turn to Music Week charts analyst Alan Jones' breakdown: “[The Cure] also exceed the to-date sales of The Cure’s last studio album, 2008’s 4:13 Dream, which debuted and peaked at No.33 on consumption of 7,360 units, 16 years ago last week, and has to-date consumption of 35,123 units. Songs Of A Lost World’s 597.85% increase on that album’s first frame is due to many factors, including the fact it has been so long since an album by The Cure; the multiplicity of its physical formats (two CD, two cassette and six vinyl); a live stream of their 1 November gig at The Troxy; a BBC Radio Two ‘In Concert’ performance; and the popularity of Songs Of A Lost World singles Alone and A Fragile Thing. The latter track has provided the band’s highest radio airplay chart position – No.26 – for more than 20 years last week, including attracting 59 plays from the aforementioned Radio Two so far.”

Robert Smith wanted to know how much we believed in the record before he'd commit to working with us, so we didn't hear a note until the deal was signed – which was a touch that I loved and respected

On top of this, Polydor have actually secured a chart double this week, with their act Gracie Abrams also topping the UK singles chart with That's So True jumping to No.1 on sales of 40,798.

Here, Polydor president Ben Mortimer, talks about working with Robert Smith, getting the band back to the top, and more...

Before we get into the campaign, what has it meant to you personally to work on The Cure's first new record in 16 years? And what has it been like working closely with Robert Smith?  

“First off, I am the hugest fan. Disintegration got me through a tough period in my early teens. I've always loved the band's ability to be so mournful and despairing and marry it with such beautiful melodic pop songs, so it meant huge amounts to me personally to get to work on this. And working with him has been a privilege. Robert is so dedicated to his craft, he's beyond passionate about the band and its legacy. He wanted to know how much we believed in the record before he'd commit to working with us. So we didn't hear a note until the deal was signed, which was a touch that I loved and respected. He is hands on in every part of his business in the most inspiring way.”

The Cure have returned, obviously, to a massively different music landscape compared to the one they operated in with 4:13 Dream. What were Polydor’s hopes and expectations for week one given there's not been a new album for so long, and have the actual sales surprised you? 

“I had a feeling it would do well. We're lucky enough to work The Cure catalogue, so are well aware of how well their music streams and across so many generations. But this has been an overwhelming response that in truth we didn't completely predict. But then again it's an incredible record, with 5/5s across the board. As predictable as this sounds, the greatest music always finds its way to people in the end.” 

It’s interesting how you achieved the result without a very long pre-order period compared to most albums. What did you have to work with in terms of data/fanbase for the campaign? There's obviously their incredible catalogue too – how have you reactivated that in the run-up? 

“Whether intentionally or not, the band have been running the smartest teaser campaign. It would be worthy of a Music Week marketing award! He teased the record was coming years ago. Something he says he regrets, but it created a sense of folklore around the album, and the band have been playing songs from it on tour for several years. Clips have been all over the internet. All of this created feverish demand amongst the fanbase.” 

There looks set to be huge international success with the album as well, what role did Polydor play in connecting all the dots globally for that to happen? Did you have any specific territories outside of the UK that you really wanted to target?

“They're huge in Europe, Australia, North, Central and South America. As soon as we told our partners this was coming there was palpable excitement and demand. We zoned in on Germany, France, Holland, and several other key markets, and they've all delivered. It's testament to the power of the global company.”  

The Troxy show was another big moment of the launch week, not least because they played the whole album in full. Why are intimate launch shows still so effective in your mind? 

“Our partnership with YouTube on the live stream made it possible. And they recorded insane levels of traffic on it. They're a stadium and festival band, so to see them this intimate, was a special experience even for those on the live stream. Playing for over three hours… It was truly my 2024 highlight.”

On top of The Cure, Polydor also have the No.1 single this week with Gracie Abrams. What does that say about Polydor right now in terms of your roster, and your ability to get top results for veteran and new artists alike? 

"The Polydor roster is well renowned as one of the best in the UK business. We have long relationships with so many artists whose careers continue to flourish. Lana Del Rey is nine albums in, Michael Kiwanuka is four. The Cure and Snow Patrol recent successes are current examples of how seriously we take career longevity. Gracie's first number No.1 single shows how we are equally committed to the next generation of artists coming through. They are after all the lifeblood of our business."

(Photo, L-R): Ali Tant, Robert Smith, Jim Chancellor, Ben Mortimer, Faye Jordan and Fred Stuart) 




it

Robert's interview with NPR




it

Songs of a Lost World chart positions

Songs of a Lost World debuts at:

Australia - #5

Austria - #1

Belgium (Flemish and Wallonian) - #1

Canada - #12

Denmark - #1

Dutch - #1

France - #1

Germany - #1

Ireland - #3

Italy - #2

New Zealand - #3

Scotland - #1

Spain - #2

Sweden - #1

Switzerland - #1

UK - #1

US - #4




it

Time management for political sysadmins

Can you put me in contact with the "tech team" of a political campaign?

I am offering my "time management for sysadmins" training pro-bono to any Dem or anti-Trump digital team, sysadmins, devops team, SRE, etc. Contact me via LinkedIn, DM me on Twitter or email me if you know my email address.




it

Oct 15 NYC DevOps Meetup: "Introduction to Site Reliability Engineering" by Nathen Harvey

This month's nycdevops meetup speaker is Nathen Harvey of Google, who will give a talk titled "Introduction to Site Reliability Engineering".

The talk starts at 5pm sharp! (NY is in US/Eastern)

Please RSVP! See you there!

https://www.meetup.com/nycdevops/events/272956481/

(This is a virtual meetup. Everyone around the world is invited!)




it

Updated BP Texas City Animation

This isn't directly sysadmin-related, but it made me think of how a really good outage retrospective can teach others how to prevent problems in the future.

"On the 15th anniversary of the incident, the U.S. Chemical Safety Board is announcing a forthcoming interactive training application based on one of the worst industrial disasters in recent U.S. history--the March 23, 2005, explosion at the BP refinery in Texas City, Texas, which killed 15 workers, injured 180 others, and caused billions of dollars in economic losses. This updated animation will be included in the training, which will focus on OSHA's Process Safety Management standard. Look for it soon at CSB.gov."

Content warning: Death