I think the ICO did a brilliant job with that report, it’s bang on the money.
They basically hadn’t implemented MFA for all Citrix Netscaler users,
hadn’t patched for ZeroLogon on customer systems (a vuln I worked on at MS two years before the Advanced incident, that I personally made sure sure was widely publicised),
didn’t do vuln management on customer systems,
ignored pentest findings,
then descoped customer systems to lie about Cyber Essentials Plus coverage to customers.
Back in 2022, there was wide scale disruption to the NHS (healthcare) in the UK due to LockBit ransomware at Advanced.
They have paid a £3m fine to the ICO, who have published their 58 page PDF investigation. Worth a read for findings.
https://cy.ico.org.uk/media2/gdlfddgc/advanced-penalty-notice-20250327.pdf
The £3m fine is due to failures to run Vulnerability Management correctly and failure to enforce MFA.
A thread about some other things:
Project: mpengine-x64-pdb 1.1.24090.11
File: mpengine.dll
Address: 75a810cc4
Revert
SVG:
dark https://tmr232.github.io/function-graph-overview/render/?graph=https%3A%2F%2Fraw.githubusercontent.com%2Fv-p-b%2Fghidra-function-graph-datasets%2Frefs%2Fheads%2Fmain%2F%2Fmpengine-x64-pdb%2F75a810cc4.json&colors=dark
light https://tmr232.github.io/function-graph-overview/render/?graph=https%3A%2F%2Fraw.githubusercontent.com%2Fv-p-b%2Fghidra-function-graph-datasets%2Frefs%2Fheads%2Fmain%2F%2Fmpengine-x64-pdb%2F75a810cc4.json&colors=light
Our first keynote from Natalie is live! Want to find fully-remote bugs? Learn more about her workflow and lessons learned from a true expert in the field. Bonus: during the Q&A you can learn that even just finding a single obscure file format can be what it takes to find a bug: https://www.youtube.com/watch?v=UOr1F-Tx1Zg
I have a question: In Signal, imagine that a new device gets added to your phone as a Linked Device. What sort of notification would you receive on your primary device (phone)? Are there photos of the current workflow here? This article https://www.npr.org/2025/03/25/nx-s1-5339801/pentagon-email-signal-vulnerability asserts that recently Signal added UI to prevent user getting phished and unknowingly adding a linked device. What did they add?
@xgranade Relevant article: LLMs use a lot of the same techniques as psychics' "cold reading" to convince people they know more than they do.
If it annoys you— as it somewhat does me— that the precise definition of the Rust programming languages is "vibes" and "three separate PDFs, none of them authoritative" and "well, whatever the reference compiler does is the language", this is pretty neat news. https://mastodon.social/@rustfoundation/114229759326166359
When you do this, you think you’re showing how savvy, smart, or “realistic” you are. What you’re actually doing is wasting the time of, and demoralizing, the people who are actually working to try to stop the thing you’ve already surrendered to.
Protip: if someone posts a technical or legal analysis of something the administration is doing or proposing and your response is that legalities are irrelevant and a waste of time, the problem is YOU.
You know who wants you to think laws don’t matter anymore and that pushback is hopeless? Fascists.
Don’t act like a fascist.
Conservative folklore peeps in Hungary: "Folktales carry our Traditional Values and the Ancient Wisdom of Our Ancestors. They follow a strict set of Traditional Rules"
Literal Hungarian folktales I found in archives:
- Princess Rosalia Lemonfarts
- The Diamond Prince in a Rubber Suit
- The Magic Flying Penis
- Rapunzel, but it's a bloke who makes a rope from his body hair
- Saint Peter got drunk and puked the first 🌈
- The Princess who became a Prince