Threat modelling with Santa

If there is one person who, like no other, knows that there is a lot to protect to keep people happy, then it’s Santa and his factory filled with elves, toys and sugary goodness. Not only are there plenty of things to protect, but there are also a lot of things to consider that might play out in unexpected ways, and jeopardize Christmas.
This is why Santa not only knows what to protect, but he also knows the limitations of the resources he needs to be able to keep children happy and make sure the process of making and delivery toys and candy stays operational.
Phishing scams are coming to town

The Christmas holiday period is a peak time for phisherfolk. Research from Check Point shows 17 percent of all malicious files distributed by email in November were related to orders and shipping around the Black Friday period.
This is expected to be worse still this month as attackers seek to take advantage of shipping and package notifications and more.
Security flaws could have had LEGO users bricking it

Research from Salt Labs has highlighted two API security vulnerabilities discovered within BrickLink, a digital resale platform owned by The LEGO Group.
BrickLink is the world's largest online marketplace to buy and sell second-hand LEGO. The API security flaws could have allowed for both large-scale account takeover (ATO) attacks on customers' accounts and server compromise to allow bad actors to take control of accounts and steal personal details.
Email is convenient but a letter might be better

If you're in the UK you might not have seen a letter for a while due to the postal workers' strike, but new research reveals that 62 percent of consumers are more likely to open a letter than an email.
The study, from mail solutions company Quadient, of 2,000 UK consumers shows 71 percent of respondents expect companies, such as banks or lawyers, to send important documents, like contracts or mortgage or pension statements, through the post rather than over email.
Kodi 21 gets an official name

The first release candidate of Kodi 20 'Nexus' was made available today, meaning the next version of the popular home theater software isn’t too far from seeing a stable release.
That’s not the only Kodi news however, as the team has begun talking about Nexus’s successor, Kodi 21 'O', including revealing its official codename.
Kodi 20 'Nexus' exits beta, is now available to download

Kodi 20 -- codename 'Nexus' -- is the next version of the hugely popular home theater software. After several alpha releases the Kodi Foundation put out the first beta build -- Beta 1 -- last month.
For obvious reasons, alpha and beta releases aren’t ideal for use on a daily basis, but we have some good news -- the team has decided the software is now stable enough to not require a second beta release.
Microsoft releases updated OneDrive app with a new Windows 11 aesthetic

Users of Microsoft's cloud storage have a new version of the OneDrive desktop client to install, compete with an updated look and feel.
After a period of testing during which the refreshed app was available to Insiders only, Microsoft has now released the new OneDrive app to everyone. The latest update gives the app a Windows 11-style makeover, including support for light and dark modes.
Microsoft releases Windows 11 Build 25267 -- the last test release of 2022

Windows Insiders in the Dev Channel have a new Windows 11 Build to play with today, and it’s the last one of the year. The next new builds will begin to arrive in January 2023.
Build 25267 comes with a good selection of improvements and fixes, as well as an improvement to how search looks on the taskbar.
MONTECH TITAN GOLD is an affordable ATX 3.0 and PCIe 5.0 power supply

While a power supply unit isn't exactly a fun component to buy, it is absolutely necessary when building a computer. A PSU is essential, and if you choose a poor quality offering, your system may experience instability, crashes, or even a dangerous fire. So, yeah, you should always get a quality PSU with a wattage rating that meets the power needs of all of your components.
Thankfully, a quality power supply with the latest bells and whistles doesn't have to break the bank. You see, today, MONTECH releases an affordable ATX 3.0 and PCIe 5.0 PSU called "TITAN GOLD" that offers up to 1200 watts. And yes, the modular PSU features the new 12VHPWR connector -- needed for some of the newest graphics cards.
Business Communication Compromise (BCC) predictions for 2023

In 2022, cybersecurity further became a top priority for businesses around the world following critical attacks on both the public and private sectors and of course, the use of cyber warfare as a Russian tactic in its invasion of Ukraine.
This year, organizations have spent significant time and resources attempting to mitigate the risks associated with Business Communication Compromise, including phishing attacks and Personally-Identifiable Information leakages. In 2023 we will see malicious actors increase the frequency of and escalate tactics and techniques around communication. Below are my top 5 predictions for Business Communication Compromise in 2023.
Get 'Go For DevOps' ($5 value) FREE for a limited time

With the help of Go for DevOps, you'll learn how to deliver services with ease and safety, becoming a better DevOps engineer in the process
Some of the key things this book will teach you are how to write Go software to automate configuration management, update remote machines, author custom automation in GitHub Actions, and interact with Kubernetes.
Unsafe on any site -- over three-quarters of Americans admit to risky online behavior

A new report finds that 78 percent of Americans indulge in risky online behaviors that open them up to cyber threats, such as reusing or sharing passwords, skipping software updates and more -- a 14 percent increase from just two years ago.
The Xfinity Cyber Health Report from Comcast combines data from a new consumer survey of 1,000 US adults, conducted by Wakefield Research, with national threat data collected by Xfinity's xFi Advanced Security platform.
Microsoft warns that the latest Windows updates are breaking virtual machines

There are few Patch Tuesdays that are not swiftly followed by the discovery of problems caused by the updates that have been released. This December is no different.
Microsoft has confirmed that after installing the KB5021249 update, some users may experience a range of problems with virtual machines on some Hyper-V hosts.
Public sector agencies struggle with cybersecurity intelligence data

A new study from Splunk, in collaboration with Foundry, finds that 49 percent of public sector agencies struggle to leverage data to detect and prevent cybersecurity threats.
The report shows 50 percent of the sector has issues leveraging data to inform cybersecurity decisions, and 56 percent of public sector agencies have difficulties leveraging data to mitigate and recover from cybersecurity incidents.
Enterprises wasting investment on identity management solutions

According to a new study 70 percent of companies report they're paying for identity tools they're not actively using.
The research from OneIdentity, which surveyed over 1,000 IT security professionals, shows 96 percent of companies are using multiple identity management tools, with 41 percent deploying at least 25 different systems to manage access rights.