Profile avatar
raphae.li
Writer. Contact me here: https://raphae.li
693 posts 6,238 followers 1,696 following
Regular Contributor
Active Commenter

Memo to the infosec community: Trump is now your HR manager.

New: Apple says it fixed two zero-day security bugs that may've been used in an "extremely sophisticated attack against specific targeted individuals on iOS.” Google's Threat Analysis Group, which investigates government-backed attacks, was credited with discovering one of the bugs.

"'I’d hire bodyguards and come,' I told my husband. 'I’d cancel and stay home,' he replied. This is the America we live in now. In Donald Trump’s America." New from @jilldlawrence.bsky.social: www.thebulwark.com/p/america-sh...

If this is true, that is straight-up wild. If this had happened during Obama or Bush's terms, it would've been a weeks-long newscycle.

News: CISA appears to have extended funding for the CVE program at the last minute. Story TK

time to have a lot of children to ensure the stability and success of my empire, I am a very smart student of history.

This story by @danamattioli.bsky.social is something else. www.wsj.com/politics/elo...

Only now catching up with this story. Any sense on whether the named operators are who the Chinese claim they are?

This is a fascinating insight from @reuters.com about North Korea’s very significant materiel support to Russia’s war against #Ukraine - as well as insights into targetable vulnerabilities in the Russian strategic logistic system. www.reuters.com/graphics/UKR...

Meanwhile: 4chan may have been hacked, but its staff is still trolling strong. I asked one of them for comment and they directed me to two different male bondage-themed videos. www.reuters.com/technology/c...

New: CISA confirms funding is running out for MITRE’s CVE database. The agency says it’s “urgently working to mitigate impact.” Story here with @ajvicens.bsky.social: www.reuters.com/technology/u...

New: There've been more developments following my and @chrisbing.bsky.social's June 2022 investigation into mercenary hacking. Two new legal actions just in the past month. First, a US lawyer is asking a judge to set aside a verdict he says was tainted by hacking: www.reuters.com/legal/us-law...

EXCLUSIVE: A whistleblower tells Congress and NPR that DOGE may have taken sensitive labor data and hid its tracks. "None of that ... information should ever leave the agency," said a former NLRB official.

A European Commission spokesperson just denied this report in an email to me: "We deny having given guidance to our staff recommending the use of burner phones while on official missions in the US." (Screenshot of full email below)

Easily my most jarring reaction from a Silicon Valley VC to my questions about @sentinelone.com was that he didn't have any insights to share as he was trying "not to follow all the u.s. news noise these days."

Harvard redid its whole homepage to push back against the administration’s demands. I mean, this is just a website but I think it’s kind of a great PR move: www.harvard.edu

France's former top cyber defender Guillaume Poupard has reacted to the news about Trump singling out Chris Krebs, calling it "stupefying" and a "triple ignominy." Not seeing that same level of fire from America's top cyber officials and execs. www.linkedin.com/posts/guilla...

💥 Whopper scoop from @andybounds.bsky.social: Brussels is issuing burner phones & basic laptops to commissioners & senior officials travelling to the US for IMF/World Bank spring meetings next week to avoid risk of espionage — a measure traditionally reserved for China. www.ft.com/content/20d0...

It hasn't filtered through to the everyday consumer yet, but those at the business end of the US economy are already getting clobbered with massive price increases. www.reuters.com/markets/us/t...

I was thinking about this Joe and Tracy anecdote from the supply chain crisis on gummy bears. Things are probably going to get really weird in a few weeks in unexpected ways:

EFF on the U.S. cybersecurity industry’s striking silence as one of its leading figures is attacked by the White House. ↘️

THREAD: When @thekrebscycle.bsky.social and his workplace, @sentinelone.com, were singled out by Donald Trump on Wednesday, I thought it was an opportunity to weigh the cybersecurity industry's rhetoric against their real world actions.

New: @ajvicens.bsky.social and I asked 33 leading information security companies for their reaction to Trump's order stripping @sentinelone.com employees and executives of their security clearances. Not one had anything to say about it. www.reuters.com/world/us/cyb...

The answer, my friends, is no. www.reuters.com/world/us/cyb...

Ideas

Big story from @oliverdarcy.bsky.social — the White House has been suppressing and censoring pool reports. www.status.news/p/white-hous...

If you work for a US cybersecurity provider (and I know a fair few of you follow me here) and Trump’s move against SentinelOne is coming up at work, I’m reachable via Signal at raphaelsatter.01 Other ways to reach me here: raphae.li

The Trump administration is now going after its first cybersecurity company, stripping @sentinelone.com of "any active security clearance." Will the infosec industry do any better than the legal industry in showing solidarity? www.whitehouse.gov/fact-sheets/...

NEW: Spyware maker NSO Group has hired a new lobbying firm with direct ties to the Trump administration. That, along with other connections, suggests a potential new strategy for business in the US. @vaspanagiotopoulos.com has the scoop: www.wired.com/story/nso-gr...