Sign in

Mike

@theomegabit.xyz
300 followers 761 following 332 posts

AWS Pro | Cloud | Security @trek10.com | Tech enthusiast Musically trapped between a metallic headbang and a bass wobble | Photographer (bsky): @betapixels.photography

PostsRepliesMedia
Mike @theomegabit.xyz · 03/02/2026
I think I’m in the market for another mechanical keyboard. ~75% size. Butter keys. Backlit if possible. I currently have the Nuphy Air75 v1. What should I look at now?
100
Mike @theomegabit.xyz · 15/12/2025
Behind the curtain - AWS Lambda Managed Instances: A Security Overview #awssecurity #cloudsecurity www.offensai.com/blog/aws-lam...
offensai.com
AWS Lambda Managed Instances: A Security Overview
An initial security overview of AWS Lambda Managed Instances, exploring the Bottlerocket-based architecture, the 'Elevator' components, and security insights for this new compute model.
000
Mike @theomegabit.xyz · 02/12/2025
Nice Extended threat detection for EC2 and ECS aws.amazon.com/blogs/aws/am... AWS real-time risk prioritization (was preview now GA) aws.amazon.com/blogs/aws/aw... AWS Security Agent (for appsec/dev) aws.amazon.com/blogs/aws/ne... #awssecurity #aws #AWSreInvent
aws.amazon.com
Amazon GuardDuty adds Extended Threat Detection for Amazon EC2 and Amazon ECS | AWS News Blog
Today, we’re announcing new enhancements to Amazon GuardDuty Extended Threat Detection with the addition of two attack sequence findings for Amazon Elastic Compute Cloud (Amazon EC2) instances and Amazon Elastic Container Service (Amazon ECS) tasks. These new findings build on the existing Extended Threat Detection capabilities, which already combine sequences involving AWS Identity and Access […]
010
Mike @theomegabit.xyz · 30/11/2025
Anyone do the CompTIA SecAI beta test yet? How was it?
021
Mike @theomegabit.xyz · 17/09/2025
That’s a vulnerability for sure. #cybersecurity dirkjanm.io/obtaining-gl...
dirkjanm.io
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
010
Mike @theomegabit.xyz · 09/09/2025
Telling on themselves. lol. #cybersecurity www.huntress.com/blog/rare-lo...
huntress.com
An Attacker’s Blunder Gave Us a Look Into Their Operations | Huntress
An attacker installed Huntress onto their operating machine, giving us a detailed look at how they’re using AI to build workflows, searching for tools like Evilginx, and researching targets like software development companies.
020
Reposted by Mike
Josh Junon @bad-at-computer.bsky.social · 08/09/2025
Yep, I've been pwned. 2FA reset email, looked very legitimate. Only NPM affected. I've sent an email off to @npmjs.bsky.social to see if I can get access again. Sorry everyone, I should have paid more attention. Not like me; have had a stressful week. Will work to get this cleaned up.
1518657
Mike @theomegabit.xyz · 07/09/2025
You’re at a cybersecurity conference in 2025 and see a presenter still using Lastpass. First thought? Second?
010
Mike @theomegabit.xyz · 07/09/2025
Anyone used this much / have any feedback? #cybersecurity #mcp #aisecurity github.com/Agentity-com...
github.com
GitHub - Agentity-com/mcp-audit-extension: Audit and log all GitHub Copilot MCP tool calls in VSCode with ease.
Audit and log all GitHub Copilot MCP tool calls in VSCode with ease. - Agentity-com/mcp-audit-extension
021
Mike @theomegabit.xyz · 06/09/2025
We’ve definitely noticed a significant increase in .svg attachments in email lately. #cybersecurity www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
VirusTotal finds hidden malware phishing campaign in SVG files
VirusTotal has discovered a phishing campaign hidden in SVG files that create convincing portals impersonating Colombia's judicial system that deliver malware.
020
Mike @theomegabit.xyz · 06/09/2025
Hello @BlueTeamCon 😀👋🏻 #blueteamcon
000
Mike @theomegabit.xyz · 21/08/2025
Anyone going to @BlueTeamCon this yeah? #cybersecurity
media3.giphy.com
https://media3.giphy.com/media/axu6dFuca4HKM/200.gif
000
Mike @theomegabit.xyz · 21/08/2025
Sooo…..this password manager extension saga that is currently unfolding…. It still seems like 1Password should do /something/ if others are starting to. Or is it truly performative? www.reddit.com/r/1Password/...
reddit.com
Reddit - The heart of the internet
000
Mike @theomegabit.xyz · 20/08/2025
Anyone used Santa (either the old Google maintained variant or the new one) here? github.com/northpolesec... #cybersecurity
github.com
GitHub - northpolesec/santa: A binary and file access authorization system for macOS.
A binary and file access authorization system for macOS. - northpolesec/santa
010
Mike @theomegabit.xyz · 08/08/2025
Seems like a generally good thing here. I understand where he’s coming from with unnecessary panic. But is that enough of a reason to not put more pressure on companies who are generally not focused on transparency as a whole? #cybersecurity www.schneier.com/blog/archive...
schneier.com
Google Project Zero Changes Its Disclosure Policy - Schneier on Security
Google’s vulnerability finding team is again pushing the envelope of responsible disclosure: Google’s Project Zero team will retain its existing 90+30 policy regarding vulnerability disclosures, in which it provides vendors with 90 days before full disclosure takes place, with a 30-day period allowed for patch adoption if the bug is fixed before the deadline. However, as of July 29, Project Zero will also release limited details about any discovery they make within one week of vendor disclosure. This information will encompass: The vendor or open-source project that received the report ...
000
Reposted by Mike
Corey Quinn @quinnypig.com · 23/07/2025
Amazon Q shipped a feature where a rando hacker told it to run aws iam delete-user, and AWS said “Sure thing, pal!” They caught it only because a journalist asked. This isn’t “move fast and break things," it's “move fast and let strangers write your roadmap.” www.lastweekinaws.com/blog/amazon-...
lastweekinaws.com
Amazon Q: Now with Helpful AI-Powered Self-Destruct Capabilities - Last Week in AWS Blog
Today 404Media released a truly stunning report that almost beggars belief. To break it down into its simplest form: A hacker submitted a PR. It got merged. It told Amazon Q to nuke your computer and ...
79526
Mike @theomegabit.xyz · 22/07/2025
Some good reads in the latest AWS security digest #awssecurity awssecuritydigest.com/past-issues/...
awssecuritydigest.com
AWS Security Digest - Issue 219
000
Mike @theomegabit.xyz · 16/07/2025
Why is Inspector Code Security not integrated in Security Hub on day 1? #awssecurity docs.aws.amazon.com/inspector/la...
000
Mike @theomegabit.xyz · 09/07/2025
Audits suck. Is it time to move that workflow more left, yet? #grc github.com/ajdehn/AWS-A...
github.com
GitHub - ajdehn/AWS-Audit-Playbook: AWS audits, without screenshots
AWS audits, without screenshots. Contribute to ajdehn/AWS-Audit-Playbook development by creating an account on GitHub.
000
Mike @theomegabit.xyz · 30/06/2025
Favorite talk so far at #fwdcloudsec?
000
Mike @theomegabit.xyz · 30/06/2025
#fwdcloudsec day 🙂
000
Mike @theomegabit.xyz · 28/06/2025
The every repeating cycle of “ship now” biting us (people in general) in the ass. Sometimes it’s worth slowing down if even for a moment. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Asana warns MCP AI feature exposed customer data to other orgs
Work management platform Asana is warning users of its new Model Context Protocol (MCP) feature that a flaw in its implementation potentially led to data exposure from their instances to other users and vice versa.
000
Mike @theomegabit.xyz · 28/06/2025
There’s a decent amount of talk and research on specific AWS api calls that aren’t logged to cloudtrail but is there an all encompassing list (GitHub hopefully) that covers everything currently known? #awssecurity
000
Mike @theomegabit.xyz · 28/06/2025
The T in IoT is for trash iank.org/posts/loftie...
iank.org
Remote Code Execution on 40,000 WiFi alarm clocks
While looking for an API to use with Home Assistant, I found a remote code execution vulnerability in a popular WiFi-connected alarm clock.
010
Mike @theomegabit.xyz · 27/06/2025
Anyone going to @fwdcloudsec.org #cloudsecurity
010
Mike @theomegabit.xyz · 27/06/2025
Cool Cloud Security learning challenge from Wiz #cloudsecurity www.cloudsecuritychampionship.com
cloudsecuritychampionship.com
The Ultimate Cloud Security Championship
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
010
Mike @theomegabit.xyz · 17/06/2025
Minor annoyance - it looks like AWS renamed “Security Hub” of years past to “Security Hub CSPM” and then re-used “Security Hub” for this new functionality. #awssecurity aws.amazon.com/blogs/aws/un...
aws.amazon.com
Unify your security with the new AWS Security Hub for risk prioritization and response at scale (Preview) | AWS News Blog
AWS Security Hub has been enhanced with new capabilities that integrate multiple AWS security services to automatically discover resources, evaluate risks, analyze attack paths, and provide AI-assisted recommendations, helping security teams prioritize critical issues and respond to threats at scale with improved visualization and remediation guidance.
000
Mike @theomegabit.xyz · 17/06/2025
About time! But also, 🎉 aws.amazon.com/blogs/aws/aw...
aws.amazon.com
AWS Certificate Manager introduces exportable public SSL/TLS certificates to use anywhere | AWS News Blog
You can now use AWS Certificate Manager to issue exportable public certificates for your AWS, hybrid, or multicloud workloads that require secure TLS traffic termination.
010
Mike @theomegabit.xyz · 12/06/2025
The internet says the internet is down
000
Mike @theomegabit.xyz · 12/06/2025
Sweet Jesus #cloudsecurity specterops.io/blog/2025/06...
specterops.io
OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys - SpecterOps
Critical vulnerabilities in OneLogin's AD Connector leaked authentication credentials, enabling account impersonation.
000
Mike @theomegabit.xyz · 12/06/2025
The new site-to-site secrets manager inclusion is pretty sweet. #awssecurity aws-cloudsec.com/p/issue-101
aws-cloudsec.com
Issue 101 - by AWS-CloudSec Weekly Newsletter
7 days of Cloud Security, recapped in 7 minutes or less!
010
Mike @theomegabit.xyz · 11/06/2025
You too can take some device over in these 12 easy steps. www.thestack.technology/absurd-12-st...
thestack.technology
"Absurd" 12-step malware dropper spotted in npm package
Supply chain attack effort used steganography, a "dizzying wall of Unicode characters" and more.
000
Mike @theomegabit.xyz · 06/06/2025
I can’t wait for my $1.50. hackread.com/hackers-leak...
hackread.com
Hackers Leak 86 Million AT&T Records with Decrypted SSNs
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
000
Mike @theomegabit.xyz · 05/06/2025
A nice little read detailing Twitters newer encrypted DMs (xchat) TL;DR - it’s not replacement for Signal File in the “No shit” department. mjg59.dreamwidth.org/71646.html
000
Mike @theomegabit.xyz · 03/06/2025
Price lock for a not great price. If you’re in the markets this is available in now and have absolutely no other choice, ok, less terrible. But any market with any other options make this not competitive. www.theverge.com/news/678897/...
theverge.com
T-Mobile launches fiber internet service in the US with a five-year price lock | The Verge
Now T-Mobile’s fiber service can better compete with Verizon and AT&T.
000
Mike @theomegabit.xyz · 02/06/2025
Good. One less spreadsheet I have to maintain #cybersecurity www.reuters.com/sustainabili...
reuters.com
'Forest Blizzard' vs 'Fancy Bear' - cyber companies hope to untangle weird hacker nicknames | Reuters
Microsoft, CrowdStrike, Palo Alto and Alphabet's Google on Monday said they would create a public glossary of state-sponsored hacking groups and cybercriminals, in a bid to ease confusion over the menagerie of unofficial nicknames for them.
000
Mike @theomegabit.xyz · 30/05/2025
This seems like a great idea. (No sarcasm) www.theverge.com/news/675446/...
theverge.com
Microsoft wants Windows Update to handle all apps | The Verge
A dream come true for IT admins
000
Mike @theomegabit.xyz · 29/05/2025
Wild #cybersecurity www.wsj.com/business/nor...
000
Mike @theomegabit.xyz · 29/05/2025
Duo IAM 👀 duo.com/blog/meet-th...
duo.com
Meet the New Duo IAM – Duo Blog | Duo Security
Duo dramatically expands offering with new directory and phishing-resistant functionality to address the sharp rise in identity-based attacks.
010
Mike @theomegabit.xyz · 28/05/2025
The carrier that is arguably the biggest dumpster fire with regards to security (T-Mobile) is defaulting to an overly permissive screen recording permission 9to5mac.com/2025/05/28/t...
9to5mac.com
T-Life app has screen recording on by default, T-Mobile says not a privacy risk
An update to T-Mobile’s T-Life app is rolling out at present, and customers are finding that it has screen recording...
000
Mike @theomegabit.xyz · 28/05/2025
Handy #awssecurity #awscloud #cloudsecurity aws.amazon.com/about-aws/wh...
aws.amazon.com
Amazon Inspector enhances container security by mapping ECR images to running containers - AWS
Discover more about what's new at AWS with Amazon Inspector enhances container security by mapping ECR images to running containers
000
Mike @theomegabit.xyz · 27/05/2025
Original post: infosec.exchange/@jerry/11458...
000
Mike @theomegabit.xyz · 27/05/2025
Why would you not deploy this in the management account (or a security tooling account) considering what the tool is? #awssecurity www.token.security/blog/aws-bui...
token.security
AWS Built a Security Tool. It Introduced a Security Risk.
In the previous post of this series, we explored four dangerous misconceptions regarding how to securely set up cross-account access in AWS environments. In this final post of the series, we’ll walk through a real-world case where even AWS got it wrong.
000
Mike @theomegabit.xyz · 23/05/2025
Any thoughts or feedback on Material.security and/or Abnornal.ai with regards to at least email security? Broader functionality they both provide? #cybersecurity #emailsecurity
000
Mike @theomegabit.xyz · 20/05/2025
It was nice of AWS to make this deprecation page. It was also a kick in the teeth to make it the least scalable or accessible page. What in the world… this page is useless. #aws aws.amazon.com/products/lif...
aws.amazon.com
AWS Product Lifecycle | AWS
Explore important AWS product lifecycle changes, end-of-support dates, and migration paths.
000
Mike @theomegabit.xyz · 20/05/2025
Thoughts on LEV…a new enhancement to KEV overall? #cybersecurity www.securityweek.com/vulnerabilit...
securityweek.com
Vulnerability Exploitation Probability Metric Proposed by NIST, CISA Researchers  - SecurityWeek
The Likely Exploited Vulnerabilities (LEV) equations can help augment KEV- and EPSS-based remediation prioritization.
000
Mike @theomegabit.xyz · 13/05/2025
No idea what the issue was but I ended up having to replace the chrome folder within application support directory in the user directory and that seemed to fix it. So….a corrupt chrome profile basically.
000
Mike @theomegabit.xyz · 13/05/2025
Anybody else very high CPU usage from Chrome after updating to either the latest version of macOS 15.5 and/pr in combination with the Chrome 136?
000
Mike @theomegabit.xyz · 28/04/2025
“The pursuit of market share at the expense of security exposes entire customer ecosystems to significant risk and will result in an unsustainable situation for the economic system” ~ Pat Opet, JPMorgan CISO Well said #cybersecurity www.securityweek.com/jpmorgan-cha...
securityweek.com
JPMorgan Chase CISO Fires Warning Shot Ahead of RSA Conference
The doors to the RSA Conference 2025 swing open here this week with two competing narratives as AI evangelism sets an unmistakable tone for the conference.
000
Mike @theomegabit.xyz · 23/04/2025
We’re all just living in a theater called security. #cybersecurity medium.com/@ringr8870/t...
medium.com
The Atlassian OAuth Disaster Nobody’s Talking About
If your company integrates with Jira or Confluence using Atlassian’s official OAuth 2.0 (3LO) flow — you should be worried. Really worried.
000