<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Posts on </title>
    <link>https://justinmcafee.com/posts/</link>
    <description>Recent content in Posts on </description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 30 Jun 2026 00:00:00 -0500</lastBuildDate>
    <atom:link href="https://justinmcafee.com/posts/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>2026.06.30 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.06.30.news-you-should-know/</link>
      <pubDate>Tue, 30 Jun 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.06.30.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;errata&#34;&gt;Errata&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://arstechnica.com/security/2026/06/windows-and-linux-users-the-deadline-to-update-secure-boot-keys-is-near/&#34; target=&#34;_blank&#34;&gt;Windows and Linux users: The deadline to update Secure Boot keys is near - Ars Technica&lt;/a&gt; - June 24, three certificates that cryptographically verify that each piece of firmware and software that loads during system boot will expire. The Microsoft-signed certificates are the linchpins of Secure Boot, a Microsoft-designed chain of trust. Secure Boot checks the digital signatures of all firmware that loads during system startup to ensure it originates from a trusted provider, such as the manufacturer of the motherboard the system runs on.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.06.16 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.06.16.news-you-should-know/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.06.16.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;errata&#34;&gt;Errata&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/&#34; target=&#34;_blank&#34;&gt;Users cry foul after AMD stripped memory crypto from its consumer CPUs - Ars Technica&lt;/a&gt; -  Recently and without warning or notice, this lower-end line of AMD chips suddenly dropped the protection, and did so in a way that was impossible to detect on Windows machines and required a fair amount of technical work when using Linux.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Labyrinth of Knowledge - On AI Knowledge Drain</title>
      <link>https://justinmcafee.com/posts/2026/ai-knowledge-drain/</link>
      <pubDate>Wed, 10 Jun 2026 06:17:54 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/ai-knowledge-drain/</guid>
      <description>&lt;p&gt;There are a lot of issues to be called out around AI, but one that has recently begun to worry me the most isn&amp;rsquo;t ethical, moral, or even environmental. Rather, its practical.&lt;/p&gt;&#xA;&lt;p&gt;Once upon a time, the villages and towns were full of worker&amp;rsquo;s guilds. If a young man or woman wanted to pursue a career of interest, they would find themselves spending hours hanging on the elbows of conversations between persons of import and expertise. If they were brave, they might venture to speak up and ask a question, enduring the good natured ridicule of the absurdity of their inquiry. A master of the art, taking pity on the young acolyte, might then take the fledgling under their wing and begin to educate them in the crafts. As the guild grew, so did its libraries. Knowledge filled the shelves as scribes recorded the decisions of the masters and the outcomes of decision making and debate. Factions formed within the guilds around these decisions, but overall, the discussions were lively and well-intentioned.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.06.09 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.06.09.news-you-should-know/</link>
      <pubDate>Tue, 09 Jun 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.06.09.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;errata&#34;&gt;Errata&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html&#34; target=&#34;_blank&#34;&gt;FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins&lt;/a&gt; - Recent reports describe thousands of lookalike FIFA domains, banking malware hidden inside pirate streaming apps, and at least one operation that copies FIFA&amp;rsquo;s login page well enough to take over real accounts.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://arstechnica.com/security/2026/06/dashlane-explains-how-attackers-managed-to-download-encrypted-password-vaults/&#34; target=&#34;_blank&#34;&gt;Dashlane explains how attackers managed to download encrypted password vaults - Ars Technica&lt;/a&gt; - In response, Dashlane’s automated security systems operated as intended, triggering an automatic lockout of the targeted accounts to protect those users. Before the attack was fully mitigated, the threat actor was able to brute force and generate valid tokens for fewer than 20 personal plan customers, allowing them to register a new device on those accounts and download copies of users’ encrypted vaults.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Interpreting Scripture</title>
      <link>https://justinmcafee.com/posts/2026/interpreting-scripture/</link>
      <pubDate>Sat, 06 Jun 2026 12:30:53 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/interpreting-scripture/</guid>
      <description>&lt;p&gt;When we are studying scripture and come across a difficult section, we have one of three interpretations we might apply.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;The option that most agrees with the culture and modern thinking.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;The option that may or may not reject the world&amp;rsquo;s current belief system but is contradictory to the whole of scripture.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Digital Privacy and Surveillance Handout</title>
      <link>https://justinmcafee.com/posts/2026/digital-privacy-and-surveillance-handout/</link>
      <pubDate>Thu, 04 Jun 2026 16:13:39 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/digital-privacy-and-surveillance-handout/</guid>
      <description>&lt;h1 id=&#34;a-handout-for-the-chattanooga-voluntaryist-society-talk&#34;&gt;A handout for the Chattanooga Voluntaryist Society Talk&lt;/h1&gt;&#xA;&lt;p&gt;4 June 2026&lt;/p&gt;&#xA;&lt;p&gt;The Agora&lt;/p&gt;&#xA;&lt;h2 id=&#34;part-1-privacy-tools--defensive-tactics&#34;&gt;&lt;strong&gt;Part 1: Privacy Tools &amp;amp; Defensive Tactics&lt;/strong&gt;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;TAILS (The Amnesic Incognito Live System)&lt;/strong&gt;&#xA;TAILS is a security-focused operating system that boots entirely from a USB drive, bypassing the host computer&amp;rsquo;s hard drive. It automatically routes all internet traffic through the anonymous Tor network and stores nothing on the machine. Because it runs purely in temporary memory (RAM), every trace of your activity vanishes instantly the moment you shut down or unplug the drive.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Encrypted Messaging (Signal vs. Delta Chat)&lt;/strong&gt;&#xA;While both tools secure your conversations, they use completely different architectures. &lt;strong&gt;Signal&lt;/strong&gt; offers gold-standard end-to-end encryption for text and voice, operating on a centralized server but storing almost zero user metadata. &lt;strong&gt;Delta Chat&lt;/strong&gt; provides a decentralized alternative; it requires no phone number and sends encrypted messages over standard, existing email servers, leaving no central company or server for adversaries to target or subpoena.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;part-2-emerging-infrastructure--local-threats&#34;&gt;&lt;strong&gt;Part 2: Emerging Infrastructure &amp;amp; Local Threats&lt;/strong&gt;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Cell-Site Simulators (&amp;ldquo;Stingrays&amp;rdquo;)&lt;/strong&gt;&#xA;Stingrays are passive and active surveillance devices used by law enforcement that mimic legitimate cell phone towers. They trick all nearby mobile devices into connecting to them, allowing operators to map your precise location, track your movements in real time, and occasionally intercept unencrypted communications data without your knowledge.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Flock Safety &amp;amp; Automated License Plate Readers (ALPRs)&lt;/strong&gt;&#xA;Flock Safety operates a massive network of neighborhood and roadside cameras designed to automatically capture vehicle license plates, makes, models, and unique identifying features. This data is fed into a centralized, searchable cloud database, allowing police departments and private entities to track a vehicle’s geographical history and establish long-term patterns of life.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Vehicular Surveillance (Ford&amp;rsquo;s In-Cabin Patents)&lt;/strong&gt;&#xA;Modern cars are quietly becoming highly invasive tracking devices. Recent patent filings from major automakers like Ford highlight an aggressive push toward in-vehicle monitoring. These include &amp;ldquo;in-vehicle advertisement systems&amp;rdquo; designed to listen to passenger conversations via cabin microphones to serve targeted dashboard ads. Other automotive patents detail using internal cameras for facial recognition, biometric eye-tracking, and speed monitoring to autonomously share data with law enforcement or insurance providers.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;part-3-wireless-leakage--the-digital-footprint&#34;&gt;&lt;strong&gt;Part 3: Wireless Leakage &amp;amp; The Digital Footprint&lt;/strong&gt;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Cell Phone Emissions (Wi-Fi &amp;amp; Bluetooth Leakage)&lt;/strong&gt;&#xA;Even when you aren&amp;rsquo;t actively using your phone, it constantly broadcasts unique identifiers. Your device silently beacons out a list of Preferred Wi-Fi Networks (past SSIDs you’ve connected to), allowing passive scanners to map your historical movements. Simultaneously, active Bluetooth vulnerabilities and location data leaks from unsecure commercial apps broadcast your real-time coordinates to surrounding receivers.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Biometric Eye Scanning (Iris &amp;amp; Retina Tracking)&lt;/strong&gt;&#xA;Biometric surveillance is shifting from broad facial recognition to precision eye scanning. Iris recognition maps the complex, unique patterns of the colored ring of the eye from a distance for rapid identification, while retina scanning maps the blood vessels at the back of the eye for high-security access control. These technologies are increasingly deployed at border checkpoints and restricted public spaces for persistent, unalterable tracking.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;part-4-the-surveillance-economy&#34;&gt;&lt;strong&gt;Part 4: The Surveillance Economy&lt;/strong&gt;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Individualized &amp;ldquo;Surveillance Pricing&amp;rdquo; (Kroger&amp;rsquo;s Digital Tags)&lt;/strong&gt;&#xA;The retail landscape is shifting from standard pricing to algorithmic &amp;ldquo;surveillance pricing&amp;rdquo; via Electronic Shelf Labels (ESLs) like Kroger’s EDGE system. Rather than just changing prices based on the time of day, these digital shelf tags can be paired with embedded cameras, loyalty card profiles, and facial recognition technology. By analyzing a shopper&amp;rsquo;s demographics, buying history, or perceived wealth while they stand in the aisle, the algorithm calculates that specific individual&amp;rsquo;s &amp;ldquo;maximum willingness to pay&amp;rdquo; and dynamically alters the price on the shelf in real time.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;The Online-Offline Ad Loop (Google, Mastercard, &amp;amp; Visa)&lt;/strong&gt;&#xA;Big Tech bridges the gap between digital activity and physical spending by buying private financial data. Google has cut multi-million dollar deals with credit card networks like Mastercard to access real-world transaction logs. Through &amp;ldquo;Store Sales Measurement&amp;rdquo; tools, Google uses double-blind encryption to cross-reference your offline credit card swipes with your online search history and ad clicks, letting retailers track exactly whether an online ad successfully coerced you into buying a product in a physical store.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Commercial Data Brokers &amp;amp; Government Purchasing&lt;/strong&gt;&#xA;When legal warrants are difficult to obtain, agencies frequently bypass constitutional restrictions by purchasing bulk data directly from private data brokers. These brokers aggressively harvest location history, app usage, and behavioral profiles from ordinary smartphone software, bundling and selling the records to the highest bidder under tiered corporate pricing models.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Social Media Analytics &amp;amp; Predictive Spying&lt;/strong&gt;&#xA;Modern surveillance relies heavily on Open Source Intelligence (OSINT) scraped from social media networks. Advanced AI algorithms ingest massive amounts of public posts and metadata to perform automated sentiment analysis. By tracking public opinion and mapping user associations, these platforms build predictive models designed to forecast future actions, protests, or potential dissidence before they occur.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;-quick-reference-daily-operational-security-opsec-tips&#34;&gt;&lt;strong&gt;💡 Quick Reference: Daily Operational Security (OpSec) Tips&lt;/strong&gt;&lt;/h2&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;strong&gt;Minimize Wireless Footprints:&lt;/strong&gt; Turn off Wi-Fi and Bluetooth entirely when leaving trusted environments to prevent passive tracking from beaconing your preferred networks.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Starve Retail Trackers:&lt;/strong&gt; Avoid using store loyalty apps that tie your real-name identity to your minute-by-minute aisle movements. Opt for cash where possible to sever the online-offline ad loop.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Audit App Telemetry:&lt;/strong&gt; Deny &amp;ldquo;Always Allow&amp;rdquo; location access to smartphone apps, and use privacy-focused browsers or DNS ad-blockers to choke off the background data pipelines that feed commercial brokers.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check Vehicle Privacy Settings:&lt;/strong&gt; Look into your car&amp;rsquo;s infotainment menu and manufacturer privacy portals to explicitly opt out of data sharing, connected telematics, and insurance reporting pipelines.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Use Lockdown Mode:&lt;/strong&gt; Enable Lockdown Mode (on iOS) or absolute minimal-privilege profiles on Android/Linux devices when traveling through high-risk transit points to dramatically reduce your digital exploit surface.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;h4 id=&#34;i&#34;&gt;&lt;em&gt;I&amp;rsquo;m an experienced home cook, security engineer, people leader, and dedicated father and husband. I can be found on Mastodon at &lt;a href=&#34;https://www.digitaldarkage.cc/@iaintshootinmis&#34; target=&#34;_blank&#34;&gt;@IAintShootinMis@DigitalDarkAge.cc&lt;/a&gt; and on Signal at &lt;a href=&#34;https://signal.me/#eu/BFeobb9FnyiIKrUuczITmrJ9-9jmfoQPcIxkU1bcWd0w-yXl7-xII6YwEPNAAtPM&#34; target=&#34;_blank&#34;&gt;DigitalDarkAge.98&lt;/a&gt;. An RSS Feed of this blog is &lt;a href=&#34;https://www.justinmcafee.com/index.xml&#34; target=&#34;_blank&#34;&gt;available here&lt;/a&gt; and a copy of my current OPML file is &lt;a href=&#34;https://justinmcafee.com/files/IAintShootinMis@DigitalDarkAgeCC.opml&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/h4&gt;</description>
    </item>
    <item>
      <title>2026.06.02 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.06.02.news-you-should-know/</link>
      <pubDate>Tue, 02 Jun 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.06.02.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;errata&#34;&gt;Errata&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/new-cifswitch-linux-flaw-gives-root-on-multiple-distributions/&#34; target=&#34;_blank&#34;&gt;New CIFSwitch Linux flaw gives root on multiple distributions&lt;/a&gt; - Some distributions Manizada confirms as vulnerable with their default configurations are:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Linux Mint 21.3 / 22.3&lt;/li&gt;&#xA;&lt;li&gt;CentOS Stream 9&lt;/li&gt;&#xA;&lt;li&gt;Rocky Linux 9&lt;/li&gt;&#xA;&lt;li&gt;AlmaLinux 9&lt;/li&gt;&#xA;&lt;li&gt;Kali Linux 2021.4–2026.1&lt;/li&gt;&#xA;&lt;li&gt;SLES 15 SP7&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/security/2026/05/27/fbi-crooks-enter-legal-offices-and-steal-data-via-usb-drive/5247212&#34; target=&#34;_blank&#34;&gt;FBI: Crooks enter legal offices and steal data via USB drive&lt;/a&gt; - It also warned last year that the callback phishing specialists had started physically walking into the law firms’ offices when remote social engineering attempts go south. The FBI’s latest advisory reaffirms these findings, with fresh attacks reported in Spring 2026.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.05.26 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.05.26.news-you-should-know/</link>
      <pubDate>Tue, 26 May 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.05.26.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://arstechnica.com/security/2026/05/texas-ag-sues-meta-over-claims-that-whatsapp-doesnt-provide-end-to-end-encryption/&#34; target=&#34;_blank&#34;&gt;Texas AG sues Meta over claims that WhatsApp doesn&amp;rsquo;t provide end-to-end encryption - Ars Technica&lt;/a&gt; - In a &lt;a href=&#34;https://www.texasattorneygeneral.gov/sites/default/files/images/press/WhatsApp%20Petition.pdf&#34; target=&#34;_blank&#34;&gt;complaint&lt;/a&gt; filed Thursday, Texas AG attorneys said Meta’s claims are false and that the company can and does read the unencrypted contents of WhatsApp messages. They said they are filing the action to “prevent WhatsApp and Meta from continuing to willfully deceive [Texans] by misrepresenting that their private communications were just that—private and inaccessible even to WhatsApp and Meta—when, in fact, WhatsApp and Meta have access to all WhatsApp users’ communications in their entirety.” According to Bloomberg, the January 16 email, sent to more than a dozen officials at other agencies, stated, “There is no limit to the type of WhatsApp message that can be viewed by Meta. The misconduct of Meta and its officers, including current and former high-level executives, involve civil and criminal violations that span several federal jurisdictions.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.05.19 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.05.19.news-you-should-know/</link>
      <pubDate>Tue, 19 May 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.05.19.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;errata&#34;&gt;Errata&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/security/2026/05/18/poland-builds-its-own-signal-amid-security-concerns/5241824&#34; target=&#34;_blank&#34;&gt;Poland builds its own Signal amid security concerns&lt;/a&gt; - Beyond Signal support staff impersonation, the agencies said the attacks can also involve outsiders persuading victims to surrender their verification codes or PINs, or abusing the platform&amp;rsquo;s Linked Devices feature via QR codes to take control of accounts.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/security/2026/05/19/do-fear-the-reaper-stealer-swipes-macos-users-passwords-wallets-then-backdoors-them/5242258&#34; target=&#34;_blank&#34;&gt;Do fear the Reaper - stealer swipes macOS users&amp;rsquo; passwords, wallets, then backdoors them&lt;/a&gt; - Assuming that the machine is located elsewhere and the user clicks on the fake tool installer, they open Apple’s Script Editor app via a sneaky link that’s heavily padded with ASCII art and fake terms to push the malicious command far below the visible portion of the window when it loads.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.05.12 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.05.12.news-you-should-know/</link>
      <pubDate>Tue, 12 May 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.05.12.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html&#34; target=&#34;_blank&#34;&gt;Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation&lt;/a&gt; - &amp;ldquo;Our analysis of exploits associated with this campaign identified a zero-day vulnerability implemented in a Python script that enables the user to bypass two-factor authentication (2FA) on a popular open-source, web-based system administration tool,&amp;rdquo; Google Threat Intelligence Group (GTIG) &lt;a href=&#34;https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access&#34; target=&#34;_blank&#34;&gt;said&lt;/a&gt; in a report shared with The Hacker News.&#xA;&amp;ldquo;For example, the script contains an abundance of educational docstrings, including a hallucinated CVSS score, and uses a structured, textbook Pythonic format highly characteristic of LLMs training data (e.g., detailed help menus and the clean _C ANSI color class),&amp;rdquo; GTIG added.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.05.05.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.05.05.news-you-should-know/</link>
      <pubDate>Tue, 05 May 2026 14:00:54 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.05.05.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;errata&#34;&gt;Errata&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://techcrunch.com/2026/04/30/after-dissing-anthropic-for-limiting-mythos-openai-restricts-access-to-cyber-too/&#34; target=&#34;_blank&#34;&gt;After dissing Anthropic for limiting Mythos, OpenAI restricts access to Cyber, too | TechCrunch&lt;/a&gt; - This version of Cyber can perform such tasks as penetration testing, vulnerability identification (and exploitation), and malware reverse engineering, the application implies. It’s intended to be a toolkit to help a company find security holes and test defenses. The fear is that the kit could be misused by the bad guys.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.04.28.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.04.28.news-you-should-know/</link>
      <pubDate>Tue, 28 Apr 2026 13:40:08 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.04.28.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;errata&#34;&gt;Errata&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/04/23/ncsc_passkey_tech_now_reliable/&#34; target=&#34;_blank&#34;&gt;NCSC: Passkeys now good enough to be the default standard • The Register&lt;/a&gt; - The UK&amp;rsquo;s National Cyber Security Centre (NCSC) has officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from passwords entirely.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/04/23/ncscs_first_foray_into_commercial/&#34; target=&#34;_blank&#34;&gt;NCSC&amp;rsquo;s first gadget blocks malware transfer over HDMI cables • The Register&lt;/a&gt; - Very little exists in the research literature about these kinds of attacks. A team based out of Montevideo&amp;rsquo;s Universidad de la República &lt;a href=&#34;https://arxiv.org/abs/2407.09717&#34; target=&#34;_blank&#34;&gt;published findings in 2024&lt;/a&gt; about the potential for highly technical individuals to intercept the electromagnetic radiation emitted from HDMI cables and use deep learning algorithms to reproduce text intended to be displayed on a monitor.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Greek Myths You Didn&#39;t Know You Were Referencing</title>
      <link>https://justinmcafee.com/posts/2026/greek-myth-references/</link>
      <pubDate>Thu, 23 Apr 2026 10:37:14 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/greek-myth-references/</guid>
      <description>&lt;p&gt;&lt;em&gt;This is part of a new series called,&amp;ldquo;Allusions for Engineers&amp;rdquo; which hopes to improve the cultural lexicon of technical or foreign peers who may not share a formal education in &amp;ldquo;classics&amp;rdquo; by western definitions. Other parts in this series include Biblical allusions, Norse, Modern/American, and others.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;Working with engineers, I often find their lexicon slightly…lacking. Not for complexity or precision, but for the classical references that make allusion and simile the marks of a well-rounded Western education. And that often leads to some well intentioned accusations that working with me is akin to &amp;lsquo;Picard and Dathon at El-Adrel&amp;rsquo;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.04.21 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.04.21.news-you-should-know/</link>
      <pubDate>Tue, 21 Apr 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.04.21.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;geopolitics&#34;&gt;Geopolitics&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://techcrunch.com/2026/04/15/sweden-blames-russian-hackers-for-attempting-destructive-cyberattack-on-thermal-plant/&#34; target=&#34;_blank&#34;&gt;Sweden blames Russian hackers for attempting &amp;lsquo;destructive&amp;rsquo; cyberattack on thermal plant | TechCrunch&lt;/a&gt; - Sweden’s minister of civil defense, Carl-Oskar Bohlin, said &lt;a href=&#34;https://www.svt.se/nyheter/inrikes/regeringen-om-cyberhotet-mot-sverige&#34; target=&#34;_blank&#34;&gt;during a press conference&lt;/a&gt; on Wednesday that the attempted attack happened in early 2025 and attributed the incident to hackers with “connections to Russian intelligence and security services.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.04.14 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.04.14.news-you-should-know/</link>
      <pubDate>Tue, 14 Apr 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.04.14.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/04/07/iran_hackers_disrupting_us_water_energy/&#34; target=&#34;_blank&#34;&gt;Iran intruders disrupting US water, energy facilities • The Register&lt;/a&gt; - &amp;ldquo;These PLCs were deployed across multiple US critical infrastructure sectors within a wide variety of industrial automation processes … Some of the victims experienced operational disruption and financial loss,&amp;rdquo; it continued. It&amp;rsquo;s also worth noting that the energy and utilities sector was the fifth-most targeted industry in the US last month, according to Check Point&amp;rsquo;s cyberattack tracking.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.04.07 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.04.07.news-you-should-know/</link>
      <pubDate>Tue, 07 Apr 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.04.07.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/04/03/trump_cisa_budget/&#34; target=&#34;_blank&#34;&gt;Trump wants to slash $707M from CISA&amp;rsquo;s budget • The Register&lt;/a&gt; - Trump&amp;rsquo;s 2027 spending plan says it will &amp;ldquo;refocus&amp;rdquo; CISA by &amp;ldquo;removing offices that are duplicative of existing and effective programs at the State and Federal level, such as certain targeted school safety programs.&amp;rdquo; Overall reduction to CISA budget will be $710M~&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.03.31 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.03.31.news-you-should-know/</link>
      <pubDate>Tue, 31 Mar 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.03.31.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;supply-chains&#34;&gt;Supply Chains&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/03/24/1k_cloud_environments_infected_following/&#34; target=&#34;_blank&#34;&gt;1K+ cloud environments infected via Trivy attack • The Register&lt;/a&gt; - &amp;ldquo;That 1,000-plus downstream victims will probably expand into another 500, another 1,000, maybe another 10,000,&amp;rdquo; he continued. &amp;ldquo;And we know that these actors are collaborating with a number of other actors right now.&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/03/24/trivy_compromise_litellm/&#34; target=&#34;_blank&#34;&gt;LiteLLM infected with credential-stealing code via Trivy • The Register&lt;/a&gt; - Two versions of LiteLLM, an open source interface for accessing multiple large language models, have been removed from the Python Package Index (PyPI) following a supply chain attack that injected them with malicious credential-stealing code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.03.24 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.03.24.news-you-should-know/</link>
      <pubDate>Tue, 24 Mar 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.03.24.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/03/18/japan_proactive_cyber_defense_enabled/&#34; target=&#34;_blank&#34;&gt;Japan to allow ‘proactive cyber-defense’ from October 1st • The Register&lt;/a&gt; - online the nation faces “the most complicated national security environment” since World War II, and because “society as a whole is proceeding with digitalization.”&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/03/18/linux_foundation_ai_slop_defense/&#34; target=&#34;_blank&#34;&gt;Linux Foundation wants to shield FOSS devs from AI bug slop • The Register&lt;/a&gt; - “OpenSSF has the active resources needed to support numerous projects that will help these overworked maintainers with the triage and processing of the increased AI-generated security reports they are currently receiving.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>Gospel of Trump</title>
      <link>https://justinmcafee.com/posts/2026/gospel-of-trump/</link>
      <pubDate>Wed, 18 Mar 2026 12:00:30 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/gospel-of-trump/</guid>
      <description>&lt;p&gt;I am so exhaustively tired of having this conversation. I do not hate anyone. I don&amp;rsquo;t hate them for who they voted for. I don&amp;rsquo;t hate them for who they support politically. But I will be very clear about the following.&lt;/p&gt;&#xA;&lt;p&gt;I hope that if you find yourself worshiping false idols and chasing after the political power that Satan offers; that you and others will be reminded of my posts and that the Holy Spirit uses them to convict you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.03.17 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.03.17.news-you-should-know/</link>
      <pubDate>Tue, 17 Mar 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.03.17.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;iran&#34;&gt;Iran&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/03/11/iran_threatens_us_tech_companies/&#34; target=&#34;_blank&#34;&gt;Iran plots &amp;lsquo;infrastructure warfare&amp;rsquo; against US tech giants • The Register&lt;/a&gt; - Iran has reportedly designated Amazon, Google, IBM, Microsoft, Nvidia, Oracle, and Palantir facilities as legitimate targets of retaliatory strikes, according to an Al Jazeera report citing Iran’s state-affiliated Tasnim news agency. 29 locations in Bahrain, Israel, Qatar, and the United Arab Emirates that house offices, datacenters, and research facilities that Iran has set its sights on destroying. This comes a week after Iran said it deliberately targeted three AWS datacenters in the region.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.03.10 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.03.10.news-you-should-know/</link>
      <pubDate>Tue, 10 Mar 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.03.10.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;iran&#34;&gt;Iran&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/03/05/mudywater_backdoor_us_networks/&#34; target=&#34;_blank&#34;&gt;Iran intelligence backdoored US bank, airport networks • The Register&lt;/a&gt; - Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US companies&amp;rsquo; networks - including a bank, software firm, and airport, among others - since the beginning of February, with more activity in the days following the US and Israeli military strikes, according to security researchers. Plus, the compromised software company supplies its tech to defense and aerospace industries among others, and has a presence in Israel.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.03.03 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.03.03.news-you-should-know/</link>
      <pubDate>Tue, 03 Mar 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.03.03.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/02/25/chinese_law_enforcement_chatgpt_abuse/&#34; target=&#34;_blank&#34;&gt;OpenAI: Chinese agent used ChatGPT for smear ops • The Register&lt;/a&gt; - Chinese Gov Agent using ChatGPT to plan smear campaigns, write situation reports. Interesting look into how bad guys are bad guying.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/03/03/perplexity_comet_browser_hole_cal_invite/&#34; target=&#34;_blank&#34;&gt;Perplexity Comet browser hole was exploitable via cal invite • The Register&lt;/a&gt; - The second thing is that we show that once the 1Password extension is installed in the Comet browser and is unlocked, we can actually instruct Comet to go to the extension URL and then &lt;a href=&#34;https://labs.zenity.io/p/perplexedbrowser-how-attackers-can-weaponize-comet-to-takeover-your-1password-vault&#34; target=&#34;_blank&#34;&gt;hijack your 1Password account&lt;/a&gt; – full takeover of your 1Password account, which is the worst thing that can happen,&amp;quot; said Bargury.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.02.26 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.02.23.news-you-should-know/</link>
      <pubDate>Thu, 26 Feb 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.02.23.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/02/17/volt_typhoon_dragos/&#34; target=&#34;_blank&#34;&gt;China remains embedded in US energy networks &amp;lsquo;for the purpose of taking it down&amp;rsquo;&lt;/a&gt; - Three new threat groups began targeting critical infrastructure last year, while a well-known Beijing-backed crew - Volt Typhoon - continued to compromise cellular gateways and routers, and then break into US electric, oil, and gas companies in 2025. &amp;ldquo;Nothing that they were taking was useful for intellectual property,&amp;rdquo; Lee said. &amp;ldquo;Everything they were doing and learning was only useful for disrupting or causing destruction at those sites. Voltzite was embedded in that infrastructure for the purpose of taking it down.&amp;rdquo;&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.02.17 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.02.17.news-you-should-know/</link>
      <pubDate>Tue, 17 Feb 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.02.17.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/02/17/lenovo_privacy_lawsuit/&#34; target=&#34;_blank&#34;&gt;US lawyers file privacy class action against Lenovo • The Register&lt;/a&gt; - &amp;ldquo;When a user lands on the homepage of Website, [sic] the Website loads numerous first and third-party tracking implementations that measure and record user data,&amp;rdquo; it says, including the likes of TikTok, Facebook, Microsoft, and Google. This allows Lenovo to collect bulk personal data, it claims, and &amp;ldquo;Lenovo knowingly permits access to, or transfer of, such bulk US sensitive personal data to entities or persons that qualify as covered persons under the DOJ Rule, including its foreign parents that are directly or indirectly controlled by persons in China, such as the Lenovo Group.&amp;rdquo;&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.02.10 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.02.10.news-you-should-know/</link>
      <pubDate>Tue, 10 Feb 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.02.10.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/02/04/nitrogen_ransomware_broken_decryptor/&#34; target=&#34;_blank&#34;&gt;Nitrogen can&amp;rsquo;t unlock its own ransomware after coding error • The Register&lt;/a&gt; - Don&amp;rsquo;t rely on threat actors to be your backup, they may not even be able to unlock the data!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://thehackernews.com/2026/02/microsoft-warns-python-infostealers.html&#34; target=&#34;_blank&#34;&gt;Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers&lt;/a&gt; - &amp;ldquo;They are typically distributed via phishing emails and collect login credentials, session cookies, authentication tokens, credit card numbers, and crypto wallet data.&amp;rdquo;&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.02.03 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.02.03.news-you-should-know/</link>
      <pubDate>Tue, 03 Feb 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.02.03.news-you-should-know/</guid>
      <description>&lt;h3 id=&#34;general&#34;&gt;General&lt;/h3&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/01/29/faster_patching_please_cry_infoseccers/&#34; target=&#34;_blank&#34;&gt;Vulnerability exploits now dominate intrusions • The Register&lt;/a&gt; - A functional proof-of-concept exploit for React2Shell began circulating online within 30 hours of disclosure, for example.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://techcrunch.com/2026/01/29/fintech-firm-marquis-blames-hack-at-firewall-provider-sonicwall-for-its-data-breach/&#34; target=&#34;_blank&#34;&gt;Fintech firm Marquis blames hack at firewall provider SonicWall for its data breach | TechCrunch&lt;/a&gt; - Marquis said it believes that its August 2025 ransomware attack happened because the company’s firewall service provider SonicWall had its own data breach that exposed critical security information about its customers’ firewalls.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.01.27 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.01.27.news-you-should-know/</link>
      <pubDate>Tue, 27 Jan 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.01.27.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/&#34; target=&#34;_blank&#34;&gt;ShinyHunters claims Okta customer breaches, leaks data • The Register&lt;/a&gt; - On Friday, the criminals leaked data allegedly stolen from market-intel broker Crunchbase, streaming platform SoundCloud, and financial-tech firm Betterment, and confirmed to &lt;em&gt;The Register&lt;/em&gt; that they gained access to two of the three - Crunchbase and Betterment - by voice-phishing Okta single-sign-on codes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.01.20 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.01.20.news-you-should-know/</link>
      <pubDate>Tue, 20 Jan 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.01.20.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/01/12/no_fire_sale_on_firewalls/&#34; target=&#34;_blank&#34;&gt;DRAM shortage may drive firewall prices higher: analysts • The Register&lt;/a&gt; - Reports last week out of the &lt;a href=&#34;https://www.theregister.com/2026/01/06/memory_firm_profits_up_as/&#34; target=&#34;_blank&#34;&gt;Korea Economic Daily&lt;/a&gt; stated two of the country’s producers of DRAM are planning to raise prices by up to 70 percent this quarter. When combined with the 50 percent increase during 2025, the price of memory could double in cost year-over-year by mid-2026.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.01.13 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.01.13.news-you-should-know/</link>
      <pubDate>Tue, 13 Jan 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.01.13.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/01/05/resecurity_honeypot_shinyhunters/&#34; target=&#34;_blank&#34;&gt;Resecurity traps cybercrim in honeypot • The Register&lt;/a&gt; - &amp;ldquo;In our scenario, our goal was to allow the threat actor to conduct activity and feed them with synthetic data to observe their attack path and infrastructure,&amp;rdquo; the Resecurity team wrote. It Worked.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2026/01/07/stalkerware_slinger_pleads_guilty/&#34; target=&#34;_blank&#34;&gt;Stalkerware maker pleads guilty to sale of snooping software • The Register&lt;/a&gt; - Fleming is due to be sentenced later this year, when he&amp;rsquo;ll be facing up to 15 years in prison, a fine of $250,000, forfeiture of all property that was involved in the offense, and additional penalties.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026.01.06 News You Should Know</title>
      <link>https://justinmcafee.com/posts/2026/2026.01.06.news-you-should-know/</link>
      <pubDate>Tue, 06 Jan 2026 00:00:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2026/2026.01.06.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/12/29/wired_hack_subscriber_info_leaked/&#34; target=&#34;_blank&#34;&gt;Crims punish Wired subscribers by publishing personal info • The Register&lt;/a&gt; - The current leak is centered around readers of Wired magazine. The miscreants published 2.3 million emails, which had the names of 285,000 subscribers, 108,000 home addresses, and 32,000 phone numbers.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://haveibeenpwned.com/&#34; target=&#34;_blank&#34;&gt;Have I Been Pwned: Check if your email address has been exposed in a data breach&lt;/a&gt; - Use this. Sign up your family. Use unique passwords in a password manager.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to Present</title>
      <link>https://justinmcafee.com/posts/2025/how-to-present/</link>
      <pubDate>Mon, 06 Oct 2025 00:48:14 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/how-to-present/</guid>
      <description>&lt;h1 id=&#34;standard-con-presentation&#34;&gt;Standard Con Presentation&lt;/h1&gt;&#xA;&lt;h2 id=&#34;who-are-you&#34;&gt;Who Are You?&lt;/h2&gt;&#xA;&lt;p&gt;Give 3-5 sentences or bullets about who you are, how long you&amp;rsquo;ve been doing the relevant skill and a 1-2 sentence explanation of what you&amp;rsquo;re talking about.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-problem-did-you-solve&#34;&gt;What Problem Did You Solve?&lt;/h2&gt;&#xA;&lt;p&gt;Make this relatable. Tell a story, so the audience can connect with your problem.&#xA;Ask a question, have you ever had X happen?&#xA;Tell us /why/ we should care&lt;/p&gt;</description>
    </item>
    <item>
      <title>Of Civic Religion</title>
      <link>https://justinmcafee.com/posts/2025/ofcivicreligion/</link>
      <pubDate>Fri, 03 Oct 2025 10:55:04 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/ofcivicreligion/</guid>
      <description>&lt;p&gt;Recently a friend pointed me to Jean-Jacques Rousseau&amp;rsquo;s The Social Contract to help understand the idolatry/worship of Trump, MAGA, and the American government.&lt;/p&gt;&#xA;&lt;p&gt;Its worth reading if you get a moment. &lt;a href=&#34;https://www.earlymoderntexts.com/assets/pdfs/rousseau1762.pdf&#34; target=&#34;_blank&#34;&gt;Book 4, chapter 8&lt;/a&gt; discusses the idea that a society requires a sort of idolatry called the &amp;ldquo;Civic Religion&amp;rdquo; to exist to hold people into a cohesive society.&lt;/p&gt;</description>
    </item>
    <item>
      <title>3 Accounts Method</title>
      <link>https://justinmcafee.com/posts/2025/3accounts/</link>
      <pubDate>Thu, 10 Jul 2025 10:30:38 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/3accounts/</guid>
      <description>&lt;p&gt;For years, I&amp;rsquo;ve tried to come up with a normal and sane way to manage money that didn&amp;rsquo;t involve complicated technical solutions (usually with a high price tag&amp;hellip;I&amp;rsquo;m trying to &lt;em&gt;save&lt;/em&gt; money!). I&amp;rsquo;ve tried everything. &lt;a href=&#34;https://www.ynab.com/&#34; target=&#34;_blank&#34;&gt;YNAB&lt;/a&gt;, &lt;a href=&#34;https://mint.intuit.com/&#34; target=&#34;_blank&#34;&gt;Mint&lt;/a&gt;, &lt;a href=&#34;https://gnucash.org/&#34; target=&#34;_blank&#34;&gt;GNUCash&lt;/a&gt; and everything in between.&lt;/p&gt;&#xA;&lt;p&gt;Finally I settled on the 3 Accounts Method of my own design.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.04.22.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.04.22.news-you-should-know/</link>
      <pubDate>Tue, 24 Jun 2025 13:30:30 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.04.22.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/04/16/dutch_ransomware_study/&#34; target=&#34;_blank&#34;&gt;Ransomware crooks search for &amp;lsquo;insurance&amp;rsquo; &amp;lsquo;policy&amp;rsquo; right away • The Register&lt;/a&gt; -  Researchers reviewed 3 years of ransomware forensics and found threat actor SOPs usually involve searching for &amp;ldquo;insurance&amp;rdquo; in company documents. If found, ransoms are around 2.8x the average. If there&amp;rsquo;s a double extortion attempt, the ransom is around 5.5x&amp;rsquo;s higher.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.05.27.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.05.27.news-you-should-know/</link>
      <pubDate>Tue, 24 Jun 2025 13:15:48 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.05.27.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://techcrunch.com/2025/05/21/wyden-att-t-mobile-and-verizon-werent-notifying-senators-of-surveillance-requests/&#34; target=&#34;_blank&#34;&gt;Wyden: AT&amp;amp;T, T-Mobile, and Verizon weren&amp;rsquo;t notifying senators of surveillance requests | TechCrunch&lt;/a&gt; - In the letter, Wyden, a longstanding member of the Senate Intelligence Committee, said that an investigation by his staff found that carriers were not notifying senators of legal requests — including from the White House — to surveil their phones. A report last year by the Inspector General,  revealed that the Trump administration in 2017 and 2018 secretly obtained logs of calls and text messages of 43 congressional staffers and two serving House lawmakers, imposing gag orders on the phone companies that received the requests.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.05.20.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.05.20.news-you-should-know/</link>
      <pubDate>Tue, 20 May 2025 13:15:08 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.05.20.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/05/15/coinbase_extorted_for_20m_support/&#34; target=&#34;_blank&#34;&gt;Hackers scam Coinbase users and ransom data for $20M • The Register&lt;/a&gt; - Coinbase said that at no point during the compromise could the attackers have accessed customers&amp;rsquo; funds, and confirmed the sources of the data were insiders bribed to steal information on behalf of the extortionists.&#xA;The company said the data does not include passwords or private keys, but depending on the use, the following details of its customers may be compromised:&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.05.13.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.05.13.news-you-should-know/</link>
      <pubDate>Tue, 13 May 2025 13:14:03 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.05.13.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/microsoft-ends-authenticator-password-autofill-moves-users-to-edge/&#34; target=&#34;_blank&#34;&gt;Microsoft ends Authenticator password autofill, moves users to Edge&lt;/a&gt; - App will stop storing passwords. Users have until August 1st to move passwords to another option.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;June 2025&lt;/strong&gt;: You can no longer save new passwords in Authenticator.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;July 2025&lt;/strong&gt;: Autofill will stop working in Authenticator; stored payment info will be deleted.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;August 2025&lt;/strong&gt;: Saved passwords and unsaved generated passwords will no longer be accessible in Authenticator.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/fbi-end-of-life-routers-hacked-for-cybercrime-proxy-networks/&#34; target=&#34;_blank&#34;&gt;FBI: End-of-life routers hacked for cybercrime proxy networks&lt;/a&gt; - Threat actors are breaking into edge devices, notably Linksys and Cisco EoL routers, and adding them to residential proxy botnets.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RSAC Cool Thing</title>
      <link>https://justinmcafee.com/posts/2025/rsa-cool-thing/</link>
      <pubDate>Sat, 03 May 2025 19:18:26 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/rsa-cool-thing/</guid>
      <description>&lt;p&gt;This years RSAC was a strange experience. AI and Quantum saturated the expo floor, while talks ranged from IT to OT and everything in between. And weird political overtones stifled the environment.&lt;/p&gt;&#xA;&lt;p&gt;Regardless of the weirdness, I decided to hit the expo floor and find the weird, the cool, and the special.&#xA;And I was successful! Two different companies jumped out at me. One, Oasis offered an actual &lt;em&gt;use case&lt;/em&gt; for quantum while Sepio offered a new endpoint security product.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.04.15.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.04.15.news-you-should-know/</link>
      <pubDate>Tue, 15 Apr 2025 14:27:55 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.04.15.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/04/09/pharmacist_accused_of_cyber_voyeurism/&#34; target=&#34;_blank&#34;&gt;Pharmacist accused of spying on women using work, home cams • The Register&lt;/a&gt; - Pharmacist spent nearly a decade installing malware on coworkers PCs, including remote web cam viewers and keyloggers. Pharmacist is currently employed at another healthcare system and is not jailed. While the employer is being sued for failing to protect their infrastructure and employees.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.04.08.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.04.08.news-you-should-know/</link>
      <pubDate>Tue, 08 Apr 2025 14:39:48 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.04.08.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/04/02/bletchley_webb_obituary/&#34; target=&#34;_blank&#34;&gt;One of the last Bletchley Park&amp;rsquo;s heroes Betty Webb dies • The Register&lt;/a&gt; - Webb along with a number of other prominent women in the cryptography field worked at Bletchley Park to help decrypt some 10k German intercepts per day. Women have a long history in the Computer Science and Cryptography fields, I would highly recommend Invisible Women by Caroline Perez, Hidden Figures by Shetterly, BROAD band: The Untold Story of the Women Who Made the Internet - Claire Evans,&lt;/p&gt;</description>
    </item>
    <item>
      <title>So You Downloaded a Thousand TikToks</title>
      <link>https://justinmcafee.com/posts/2025/so-you-downloaded-a-thousand-tiktoks/</link>
      <pubDate>Mon, 07 Apr 2025 13:05:07 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/so-you-downloaded-a-thousand-tiktoks/</guid>
      <description>&lt;p&gt;We&amp;rsquo;ve all been there, a friend sends over a funny TikTok, or you want to share it in your Signal chat and you know people aren&amp;rsquo;t likely to click the link. Plus who wants all that tracking and hidden redirects in a TT link? So what&amp;rsquo;s to be done? If you&amp;rsquo;re like me, a quick long press, and &amp;ldquo;Save Video&amp;rdquo; and you&amp;rsquo;re off to the group chat to laugh with your friends.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.04.01.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.04.01.news-you-should-know/</link>
      <pubDate>Tue, 01 Apr 2025 14:42:41 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.04.01.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/03/26/us_defense_contractor/&#34; target=&#34;_blank&#34;&gt;US defense contractor settles whistleblower suit for $4.6M • The Register&lt;/a&gt; - Out of a possible 110 points, MORSE awarded itself 104. A third party assessment of the environment found a catastrophic score of (-)142, Yes, 246 points in the opposite (bad) direction. As part of the settlement, MORSE is handing back $4.6 million to the Feds, and $851,000 of that is going to the ex-employee who blew the whistle.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.03.25.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.03.25.news-you-should-know/</link>
      <pubDate>Tue, 25 Mar 2025 14:45:46 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.03.25.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;us-pol&#34;&gt;US POL&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://techcrunch.com/2025/03/20/federal-judge-blocks-doges-access-to-social-security-administrations-banks-of-personal-information/&#34; target=&#34;_blank&#34;&gt;Federal judge blocks DOGE&amp;rsquo;s access to Social Security Administration&amp;rsquo;s banks of personal information | TechCrunch&lt;/a&gt; - Hollander said DOGE “never identified or articulated” a reason why it needs access to the “personal and private data of millions of Americans.”&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/03/18/cisa_rehired_doge/&#34; target=&#34;_blank&#34;&gt;CISA fires then rehires security crew, and puts them on hold • The Register&lt;/a&gt; - CISA employees are back, but benched. Placed on paid-leave, Red Teamers and other security staff are still in limbo.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.03.18.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.03.18.news-you-should-know/</link>
      <pubDate>Tue, 18 Mar 2025 14:45:54 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.03.18.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;privacy&#34;&gt;Privacy&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/03/17/amazon_kills_on_device_alexa/&#34; target=&#34;_blank&#34;&gt;Amazon kills off on-device Alexa processing for Echo owners • The Register&lt;/a&gt; - &amp;ldquo;We are reaching out to let you know that the Alexa feature &amp;lsquo;Do Not Send Voice Recordings&amp;rsquo; that you enabled on your supported Echo device(s) will no longer be available beginning March 28, 2025,&amp;rdquo; a copy of the email sent to Echo users relayed to &lt;em&gt;El Reg&lt;/em&gt; read.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.03.11.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.03.11.news-you-should-know/</link>
      <pubDate>Tue, 11 Mar 2025 14:46:00 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.03.11.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/03/06/uscis_social_media/&#34; target=&#34;_blank&#34;&gt;USCIS mulls policing social media of all would-be citizens • The Register&lt;/a&gt; - Social Media assessment that started under the Obama White House will be extended to all resident and documented aliens. Moves the social media scanning from before entry to all immigrants.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/03/07/badbox_botnet_returns/&#34; target=&#34;_blank&#34;&gt;Badbox is back and a million Android devices were backdoored • The Register&lt;/a&gt; - Infected Android machines part of extensive botnet. Devices exploiting residential IP space to serve malicious ads.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.03.04.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.03.04.news-you-should-know/</link>
      <pubDate>Tue, 04 Mar 2025 14:46:05 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.03.04.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/02/25/china_hacked_gop_emails/&#34; target=&#34;_blank&#34;&gt;China compromised GOP emails ahead of Republican convention • The Register&lt;/a&gt; - Notified in July of 2024, the Republic leadership opted to not notify the FBI or seek their assistance.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://apnews.com/article/cyber-command-russia-putin-trump-hegseth-c46ef1396e3980071cab81c27e0c0236&#34; target=&#34;_blank&#34;&gt;Hegseth orders suspension of Pentagon&amp;rsquo;s offensive cyberoperations against Russia | AP News&lt;/a&gt; - Hegseth can stop Pentagon, but not DHS:CISA or the CIA.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Post-Truth is Pre-Fascism</title>
      <link>https://justinmcafee.com/posts/2025/posttruthisprefascism/</link>
      <pubDate>Sun, 02 Mar 2025 01:38:15 -0600</pubDate>
      <guid>https://justinmcafee.com/posts/2025/posttruthisprefascism/</guid>
      <description>&lt;h1 id=&#34;notes-quotes-and-paraphrases-from-on-tyranny-twenty-lessons-from-the-twentieth-century---timothy-snyder&#34;&gt;Notes, Quotes, and Paraphrases from On Tyranny: Twenty Lessons from the Twentieth Century - Timothy Snyder&lt;/h1&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;&amp;ldquo;You submit to tyranny when you renounce the difference between what you want to hear and what is actually the case&amp;hellip;As observers of totalitarianism such as Victor Klemperer noticed, truth dies in four modes:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disillusioned with the Church™</title>
      <link>https://justinmcafee.com/posts/2025/disillusioned-with-the-church/</link>
      <pubDate>Sat, 01 Mar 2025 09:12:09 -0600</pubDate>
      <guid>https://justinmcafee.com/posts/2025/disillusioned-with-the-church/</guid>
      <description>&lt;p&gt;I have had a continuously growing unease about the churches in America. Setting aside the current political climate, it seems to be increasingly difficult to find a man or woman in a pulpit or a pew who believes in, much less advocates for Jesus&amp;rsquo; teachings.&lt;/p&gt;&#xA;&lt;p&gt;They may pay lip service to the Sermon on the Mount, but their lives will tell you a much different story. And as much as I had become dismayed at this fact, I was excited to see that scripture already offered an answer for it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.02.25.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.02.25.news-you-should-know/</link>
      <pubDate>Tue, 25 Feb 2025 14:49:29 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.02.25.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/02/19/decadeold_healthcare_security_snafu_settled/&#34; target=&#34;_blank&#34;&gt;Decade-old healthcare security SNAFU settled for $11M • The Register&lt;/a&gt; -  Health Net Federal Services (HNFS) and its parent company Centene Corporation, were found liable of lying on security attestations and ignoring 3rd party audits of their environment from 2015-2018. Fine amounts to 0.0067% of it&amp;rsquo;s 2023 revenue ($163Bn).&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/02/21/thailand_ready_to_welcome_7000/&#34; target=&#34;_blank&#34;&gt;Thousands of trafficked scammers await return to Thailand • The Register&lt;/a&gt; -&#xA;Prime Minister Shinawatra said around 7,000 individuals are awaiting transfer to Thailand after being rescued from call centers in Myanmar.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.02.18.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.02.18.news-you-should-know/</link>
      <pubDate>Tue, 18 Feb 2025 14:49:38 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.02.18.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://techcrunch.com/2025/02/14/meta-confirms-project-waterworth-a-global-subsea-cable-project-spanning-50000km/&#34; target=&#34;_blank&#34;&gt;Meta confirms &amp;lsquo;Project Waterworth,&amp;rsquo; a global subsea cable project spanning 50,000 kilometers | TechCrunch&lt;/a&gt; - Meta will string a cable from the US, Brazil, India, South Africa, and elsewhere. The US Gov&amp;rsquo;t has committed to the Indian government to assist in this project. Meta-owned Facebook and Insta currently account for 10% of all fixed-internet traffic, and 22% of all mobile traffic.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.02.11.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.02.11.news-you-should-know/</link>
      <pubDate>Tue, 11 Feb 2025 14:49:51 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.02.11.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/01/29/ddos_attacks_aquabot_mitel/&#34; target=&#34;_blank&#34;&gt;Beware of DDoSes from Mirai-based botnet of Mitel phones • The Register&lt;/a&gt; - Mitel, the phone thats sat on hundreds of desks across the world may have default credentials, and may have been roped into a Mirai botnet as part of the new Aquabotv3. Just a reminder to patch everything. Everywhere. All the time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.01.28.news You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.01.28.news-you-should-know/</link>
      <pubDate>Tue, 28 Jan 2025 14:52:54 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.01.28.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/01/27/sweden_seizes_ship/&#34; target=&#34;_blank&#34;&gt;Sweden seizes vessel after another undersea cable damaged • The Register&lt;/a&gt; - Trans-Baltic cables between Latvia and Sweden were attacked the 26th. This makes the third cable in 2 months in the Baltics. The first being a Between Finland-and-Estonia and Finland-and-Sweden.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/01/24/lancang_mekong_anti_cyberscam_cooperation/&#34; target=&#34;_blank&#34;&gt;China and frieds say they&amp;rsquo;re hurting cyber-slave scam camps • The Register&lt;/a&gt; - China and other Asian nations (Cambodia, Laos, Myanmar, Thailand, Vietnam) are concentrating on cyber-scam slave camps. Many tech-support and romance scams are staffed by human slaves in border regions in Myanmar, Laos, Cambodia, and Thailand. China estimates 100k of its citizens are currently held in these camps.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.01.21.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.01.21.news-you-should-know/</link>
      <pubDate>Tue, 21 Jan 2025 14:53:01 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.01.21.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/01/19/openais_chatgpt_crawler_vulnerability/&#34; target=&#34;_blank&#34;&gt;ChatGPT crawler flaw opens door to DDoS, prompt injection • The Register&lt;/a&gt; - OpenAI&amp;rsquo;s web crawler has been weaponized by researches creating 20 - 5k requests per single API call to the crawler.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/01/17/gm_settles_ftc_charges/&#34; target=&#34;_blank&#34;&gt;GM settles charges it shared driver location data • The Register&lt;/a&gt; - GM collected up to the second GPS data of vehicles, then sold it to Insurance companies to justify raising their premiums&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.01.14.News You Should Know 2025</title>
      <link>https://justinmcafee.com/posts/2025/2025.01.14.news-you-should-know/</link>
      <pubDate>Tue, 14 Jan 2025 14:53:10 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.01.14.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;scams--breaches&#34;&gt;Scams &amp;amp; Breaches&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/scammers-file-first-get-your-irs-identity-protection-pin-now/&#34; target=&#34;_blank&#34;&gt;Scammers file first — Get your IRS Identity Protection PIN now&lt;/a&gt; - Get signed up for a IP PIN for the IRS, before someone else does your taxes.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/01/08/fcc_chief_urges_spectrum_auction/&#34; target=&#34;_blank&#34;&gt;FCC chief urges auction to fund &amp;lsquo;Rip and Replace&amp;rsquo; program • The Register&lt;/a&gt; - To fund the removal of Huawei and ZTE equipment from American networks, the FCC is considering a spectrum fire sale. The last sale of Advanced Wireless Services spectrum (for mobile operators) saw AT&amp;amp;T, Verizon, and T-Mobile, among others raise $45bn. Outgoing director Jessica Rosenworcel specifically called out Chinese-based Typhoon actors as being the catalyst for the sale.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Book Notes from The Managers Path: Chapter 1</title>
      <link>https://justinmcafee.com/posts/2025/book-notes-managers-path-fournier/</link>
      <pubDate>Thu, 09 Jan 2025 20:44:16 -0600</pubDate>
      <guid>https://justinmcafee.com/posts/2025/book-notes-managers-path-fournier/</guid>
      <description>&lt;h2 id=&#34;intro&#34;&gt;Intro&lt;/h2&gt;&#xA;&lt;p&gt;This book was recommended to me by one of the most intentional managers I&amp;rsquo;ve ever had the pleasure of working with. Matt R. brought me in as a Senior Cybersecurity Engineer at Cradlepoint and oversaw my transition to Manager of that same engineering team. Throughout my time with Matt, he worked diligently to hold me to the tenets laid about by Ms. Fournier in this book and to encourage me to be a better leader for my team. Overall, this book has been a constant reference for my career in leadership and I recommend it to anyone on a technical path who finds themselves considering or entering into the management field. Specifically for Engineers who are managing Engineers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2025.01.07.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2025/2025.01.07.news-you-should-know/</link>
      <pubDate>Tue, 07 Jan 2025 13:21:21 -0600</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.01.07.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;apple&#34;&gt;Apple&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/01/02/apple_siri_lawsuit/&#34; target=&#34;_blank&#34;&gt;Apple offers $95M settlement in Siri privacy lawsuit • The Register&lt;/a&gt; - Something as simple as a zipper or an individual raising their arms would cause Siri to start recording. Lopez, et al v. Apple Inc will be settled for $95 million if the N. California District Court approves. Apple CEO Tim Cook had previously told Congress that Siri&amp;rsquo;s recording features required a &amp;ldquo;clear, unambiguous trigger&amp;rdquo;, i.e.; &amp;ldquo;Hey Siri&amp;rdquo;&#xA;Siri-enabled Apple users from 2011-to an unknown date will likely be eligible diluting individual payouts.&#xA;95m dollars(USD) is roughly less than .001 of Apple&amp;rsquo;s Profits in 2024.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2024.12.31.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2024/2024.12.31.news-you-should-know/</link>
      <pubDate>Tue, 31 Dec 2024 12:30:04 -0600</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024.12.31.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;one-offs&#34;&gt;One Offs&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2024/12/27/microsoft_windows_11_security_update/&#34; target=&#34;_blank&#34;&gt;Microsoft flags Windows 11 24H2 install media issue • The Register&lt;/a&gt; - If you used a USB stick with October or November&amp;rsquo;s updates installed, your system won&amp;rsquo;t accept any additional updates. Make sure to re-write your USB stick using December 24&amp;rsquo;s&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2024/12/17/critical_rce_apache_struts/&#34; target=&#34;_blank&#34;&gt;Critical Apache Struts bug under active exploit • The Register&lt;/a&gt; - Guess who&amp;rsquo;s back, back again. Apache Struts, in-famous for being the source of the Equifax breach in 2017, is back with CVE-2024-53677 a rehash of a vulnerability discovered in Dec 2023. Struts File Upload component features the 9.5 out of 10 CVSS CVE&lt;/p&gt;</description>
    </item>
    <item>
      <title>2024.11.12.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2024/2024.11.12.news-you-should-know/</link>
      <pubDate>Tue, 12 Nov 2024 12:17:02 -0600</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024.11.12.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;geopolitics&#34;&gt;GeoPolitics&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2024/11/06/chinas_volt_typhoon_breached_singtel/&#34; target=&#34;_blank&#34;&gt;China&amp;rsquo;s Volt Typhoon breached Singtel, reports say • The Register&lt;/a&gt; - Volt Typhoon reportedly breached Singapore Telecom over the summer. Highlighting why Cyber Threat Intelligence can at times be beneficial for more advanced orgs.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2024/11/07/russia_tech_transfer_north_korea/&#34; target=&#34;_blank&#34;&gt;N Korea may receive tech in exchange for military support • The Register&lt;/a&gt; - DPRK has provided around 10,000 troops to Putin&amp;rsquo;s war in Ukraine. After DPRK successfully conducted a 90 minute missile flight the US and its allies are starting to wonder exactly what Pyongyang got in exchange for those troops.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Capacity</title>
      <link>https://justinmcafee.com/posts/2024/capacity/</link>
      <pubDate>Tue, 29 Oct 2024 14:58:39 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2024/capacity/</guid>
      <description>&lt;p&gt;No one likes the sappy &lt;em&gt;I&amp;rsquo;m such a good manager look at me manage with my great insights&lt;/em&gt; post. But every now and then I learn something and I think other people who are moving from a technical resource to a leader may gain insight or value from it. So I share here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2024.10.29.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2024/2024.10.29.news-you-should-know/</link>
      <pubDate>Tue, 29 Oct 2024 12:29:51 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024.10.29.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;breaches&#34;&gt;Breaches&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2024/10/23/satanic_data_thief/&#34; target=&#34;_blank&#34;&gt;&amp;lsquo;Satanic&amp;rsquo; data thief hits 350M Hot Topic shoppers • The Register&lt;/a&gt; - HotTopic, Torrid, and Lunchbox shoppers (around 350m) of them have had a few bits of info stolen; names, emails, physical addresses, dates of birth, last four digits of customers’ credit cards, card types, hashed expiration dates, and account holder names. Likely just watch out for My Neighbor Totoro-themed phishes and you&amp;rsquo;ll be ok.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2024.10.22.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2024/2024.10.22.news-you-should-know/</link>
      <pubDate>Tue, 22 Oct 2024 12:25:46 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024.10.22.news-you-should-know/</guid>
      <description>&lt;h1 id=&#34;politics&#34;&gt;Politics&lt;/h1&gt;&#xA;&lt;h2 id=&#34;world&#34;&gt;World&lt;/h2&gt;&#xA;&lt;h3 id=&#34;iran&#34;&gt;Iran&lt;/h3&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://thehackernews.com/2024/10/us-and-allies-warn-of-iranian.html&#34; target=&#34;_blank&#34;&gt;U.S. and Allies Warn of Iranian Cyberattacks on Critical Infrastructure in Year-Long Campaign&lt;/a&gt;&#xA;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/iranian-hackers-act-as-brokers-selling-critical-infrastructure-access/&#34; target=&#34;_blank&#34;&gt;Iranian hackers act as brokers selling critical infrastructure access&lt;/a&gt; - US and Allies are warning that Iran has ran a year long campaign to break into water, waste-water, electrical plants, government, healthcare, and telecom systems to serve as an Initial Access Broker, selling credentials to other nations, threat actors, etc&amp;hellip; These IAB&amp;rsquo;s aren&amp;rsquo;t damaging the networks, simply staging an maintaining a presence on the network until it can be sold or made useful.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RSS</title>
      <link>https://justinmcafee.com/posts/2024/rss/</link>
      <pubDate>Thu, 17 Oct 2024 22:50:14 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2024/rss/</guid>
      <description>&lt;h2 id=&#34;what-is-rss&#34;&gt;What Is RSS?&lt;/h2&gt;&#xA;&lt;p&gt;RSS or &lt;em&gt;Really Simple Syndication&lt;/em&gt; is a protocol left over from the early days of the second internet. Adopted widely in the early 2000s, RSS became a privacy conscious way for users to get updated information from disparate news sources, blogs, content creators, and the like without having to visit individual sites. An interested reader could simply drop an RSS link into an aggregator and curate an &amp;ldquo;OPML&amp;rdquo; file of interesting blogs, video content creators, news channels, and other interesting content. Simply subscribe, with no login, no sign-ups, and wait for the content to role in. The OPML file would be managed by the aggregator and with a single click (or pop-up notification), users could find all the new content they were interested in.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Yogurt, Chicken, and Child Labor</title>
      <link>https://justinmcafee.com/posts/2024/yogurt_chicken_and_childlabor/</link>
      <pubDate>Wed, 16 Oct 2024 23:54:11 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2024/yogurt_chicken_and_childlabor/</guid>
      <description>&lt;p&gt;&lt;em&gt;This post began as a diatribe by myself to an invisible audience in my travel journal. My infant daughter (Nibble,1f) is on vacation with us and has been eating copious amounts of Greek Yogurt to help combat the diarrhea caused by an antibiotic, cefdinir. In my musings, I wandered what it would have been like to travel with an infant suffering an ear infection with little to soothe her than the ineffective and near-witchcraft style medicine available prior to the age of antibiotics. I then began to write about what medicine may be like in the future and realized that along our current trajectory the Star-Trek-esque future we hope for likely isn&amp;rsquo;t a possibility.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>2024.10.08.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2024/2024.10.08.news-you-should-know/</link>
      <pubDate>Tue, 08 Oct 2024 13:18:49 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024.10.08.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;mobile-news&#34;&gt;Mobile News&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://thehackernews.com/2024/10/android-14-adds-new-security-features.html&#34; target=&#34;_blank&#34;&gt;Google Adds New Pixel Security Features to Block 2G Exploits and Baseband Attacks (thehackernews.com)&lt;/a&gt; - Google will now allow their Pixel phones to be configured to ignore 2G downgrade attacks caused by Stingrays (cell-site simulators) and other devices that emulate a cellular baseband (tower) controlled by their service provider. This will prevent attacks like those performed by Intellexa and Predator using the Triton malware. This will also prevent SMS Blasting which bypass carrier spam protections.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2024.09.10.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2024/2024.09.10.news-you-should-know/</link>
      <pubDate>Tue, 10 Sep 2024 11:39:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024.09.10.news-you-should-know/</guid>
      <description>&lt;h2 id=&#34;privacy-news&#34;&gt;Privacy News&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2024/09/03/clearview_ai_dutch_fine/&#34; target=&#34;_blank&#34;&gt;Data watchdog fines Clearview AI $33M • The Register&lt;/a&gt; - Clearview scrapes photos from all over the internet, adds them to its database, then sells the data to advertisers and governments, some who use it without appropriate legal permissions (think 4th amendment/warrantless surveillance issues)&lt;/p&gt;&#xA;&lt;h2 id=&#34;election-news&#34;&gt;Election News&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2024/09/03/spamouflage_trolls_us_elections/&#34; target=&#34;_blank&#34;&gt;Spamouflage trolls pretend to be American patriots on X • The Register&lt;/a&gt; - #China - People’s Republic of China propaganda crew ramps up X and TikTok work claiming to be American citizens and “frustrated Conservatives”. The threat actor group is using AI generated content of Pres. Biden, VP Harris, and fmr Pres. Trump. Overall, users are able to identify that something isn’t “right” about the accounts, though the propagandist are getting better.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Fix It One Level Deeper</title>
      <link>https://justinmcafee.com/posts/2024/2024-09-08/</link>
      <pubDate>Sun, 08 Sep 2024 00:41:10 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024-09-08/</guid>
      <description>&lt;h2 id=&#34;the-concept&#34;&gt;The Concept&lt;/h2&gt;&#xA;&lt;p&gt;Recently I read a great article called &lt;a href=&#34;https://matklad.github.io/2024/09/06/fix-one-level-deeper.html&#34; target=&#34;_blank&#34;&gt;Try to Fix It One Level Deeper&lt;/a&gt; by Alex Kladov, in which he discusses a unique (to me) approach to squashing software bugs. Instead of just fixing the bug at hand, Alex encourages the reader, and his team to dig one level deeper. Really determine why the bug exists at all. Is this parameter really being mishandled? Or should we even be asking for this parameter?&lt;/p&gt;</description>
    </item>
    <item>
      <title>2024.08.27.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2024/2024.08.27.news-you-should-know/</link>
      <pubDate>Tue, 27 Aug 2024 10:10:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024.08.27.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://thehackernews.com/2024/08/hardware-backdoor-discovered-in-rfid.html&#34; target=&#34;_blank&#34;&gt;Hardware Backdoor Discovered in RFID Cards Used in Hotels and Offices Worldwide (thehackernews.com)&lt;/a&gt; - Hardware backdoor means even with appropriate controls, threat actors can still attack hotel and office doors around the globe. The FM11RF08S backdoor enables any entity with knowledge of it to compromise all user-defined keys on these cards, even when fully diversified, simply by accessing the card for a few minutes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2024.08.20.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2024/2024.08.20.news-you-should-know/</link>
      <pubDate>Tue, 20 Aug 2024 10:12:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024.08.20.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/cisa-warns-of-jenkins-rce-bug-exploited-in-ransomware-attacks/&#34; target=&#34;_blank&#34;&gt;CISA warns of Jenkins RCE bug exploited in ransomware attacks (bleepingcomputer.com)&lt;/a&gt; - Jenkins vulnerabilities from January being used by threat actors for Remote Code Execution. Patches should be applied in every environment. Exploitation of this vuln and proof of concepts hit the web less than 48hrs after the issue was identified.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Alerting</title>
      <link>https://justinmcafee.com/posts/2024/alerting/</link>
      <pubDate>Thu, 06 Jun 2024 14:22:27 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2024/alerting/</guid>
      <description>&lt;h1 id=&#34;so-you-want-to-build-a-soc&#34;&gt;So You Want To Build A SOC&lt;/h1&gt;&#xA;&lt;h3 id=&#34;or-how-to-lose-your-mind-in-10-weeks&#34;&gt;Or How To Lose Your Mind In 10 Weeks&lt;/h3&gt;&#xA;&lt;p&gt;A number of companies I&amp;rsquo;ve worked for have security tools in place, but they&amp;rsquo;re almost always half-configured, half-utilized, and no one has a good idea what&amp;rsquo;s missing or what should be there. Luckily, there&amp;rsquo;s a solution, or at least a tool that can help us move towards a solution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troubleshooting</title>
      <link>https://justinmcafee.com/posts/2024/2024-06-05/</link>
      <pubDate>Wed, 05 Jun 2024 23:47:36 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024-06-05/</guid>
      <description>&lt;h1 id=&#34;troubleshooting&#34;&gt;Troubleshooting&lt;/h1&gt;&#xA;&lt;h4 id=&#34;a-quick-primer&#34;&gt;A Quick Primer&lt;/h4&gt;&#xA;&lt;h3 id=&#34;the-back-story&#34;&gt;The Back Story&lt;/h3&gt;&#xA;&lt;p&gt;A friend called and requested some assistance with her electrical. She had moved into a new (to her) house recently and she feared the electrical had gotten the landlord/flipper special. &lt;em&gt;Spoiler&lt;/em&gt; turns out she was right, at least to a point. And now one of the circuits in the kitchen was no longer working. I don&amp;rsquo;t know if you&amp;rsquo;ve ever tried to cook in the dark but its not a pleasant experience.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Thoughts for a New Leader</title>
      <link>https://justinmcafee.com/posts/2024/thoughts-for-a-new-leader/</link>
      <pubDate>Fri, 10 May 2024 13:13:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2024/thoughts-for-a-new-leader/</guid>
      <description>&lt;p&gt;What follows is a list of thoughts crafted in an airport terminal in San Jose, California hours after completing my first attendance at the RSA Conference. This also happens to be the anniversary of my first year as a people leader in the security engineering space. (I had previously mentored and led soldiers in the US Army and in various other civilian industries including Optical Lens Manufacturing and Operational Incident Response.)&lt;/p&gt;</description>
    </item>
    <item>
      <title>RSA Day 3 </title>
      <link>https://justinmcafee.com/posts/2024/rsa-day-3/</link>
      <pubDate>Thu, 09 May 2024 00:56:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2024/rsa-day-3/</guid>
      <description>&lt;p&gt;(Posting this a day late as I was crazy exhausted yesterday after walking nearly ten miles! I literally laid down in the room at 22:30 and woke up at 04:30 still in my clothes, lights on, etc&amp;hellip;. I think I was effectively conferenced out, and that was only Day 3!)&lt;/p&gt;</description>
    </item>
    <item>
      <title>RSA Day 2</title>
      <link>https://justinmcafee.com/posts/2024/rsa-day-2/</link>
      <pubDate>Mon, 06 May 2024 23:57:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2024/rsa-day-2/</guid>
      <description>&lt;p&gt;Today was a great opportunity to see what RSA was all about. We walked over early to get badges and get checked in. The conference provided us with a decent swag pack, an RSA branded bag, water bottle (something I hadn&amp;rsquo;t been able to find at any of the airports along the way), a notebook, a pen, a shirt, and for newbies, a &amp;ldquo;First Timer&amp;rdquo; pin.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RSA Day 1</title>
      <link>https://justinmcafee.com/posts/2024/rsa-day-1/</link>
      <pubDate>Sun, 05 May 2024 23:42:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2024/rsa-day-1/</guid>
      <description>&lt;p&gt;Today was a travel day to RSA 2024. It started off simple enough, boarding at my municipal airport, then a puddle jumper to the nearest metro-airport, Atlanta.&lt;/p&gt;&#xA;&lt;p&gt;Luckily, as if there wasn&amp;rsquo;t enough anxiety around Boeing aircraft, our initial plan was inoperable and a secondary plane had to be found delaying our flight. Considering Boeing&amp;rsquo;s in the business of killing whistleblowers this week, and they make roughly 90% in Delta&amp;rsquo;s fleet (Atlanta is Delta&amp;rsquo;s home turf) it didn&amp;rsquo;t look like I was going to make it west on a non-Boeing flight.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hello_World</title>
      <link>https://justinmcafee.com/posts/2024/2024-05-02/</link>
      <pubDate>Thu, 02 May 2024 00:59:01 -0500</pubDate>
      <guid>https://justinmcafee.com/posts/2024/2024-05-02/</guid>
      <description>&lt;h1 id=&#34;hello-world&#34;&gt;Hello World&lt;/h1&gt;&#xA;&lt;h2 id=&#34;welcome-to-my-little-slice-of-internet-freedom&#34;&gt;Welcome to my little slice of internet freedom.&lt;/h2&gt;&#xA;&lt;p&gt;I hope to start moving a number of my writings here and making this a comfortable place for musings, software configuration guides, security issues and the like.&lt;/p&gt;&#xA;&lt;p&gt;After all the fight I had to get Hugo, Alpine, Proxmox, Nginx, and LetsEncrypt configure, this better be worth the trouble. Then again, is anything ever really? If anything I learned a hundred ways to not do things and thats got to be worth something.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Email</title>
      <link>https://justinmcafee.com/posts/2023/email/</link>
      <pubDate>Fri, 22 Dec 2023 18:22:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/email/</guid>
      <description>&lt;h1 id=&#34;300-emails-it-was-24-hours&#34;&gt;300 Emails? It was 24 hours!&lt;/h1&gt;&#xA;&lt;p&gt;I would have never thought as a front line manager of a small team that I could receive as much email as I do. It’s so overwhelming, I’ve taken to putting my Out of Office as “Due to the volume of email, I will be deleting all email received in my absence. Please hold important correspondence til my return on 3 January 2024”!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Velociraptor Offline Collector</title>
      <link>https://justinmcafee.com/posts/2023/velociraptor-offline-collector/</link>
      <pubDate>Fri, 01 Dec 2023 07:37:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/velociraptor-offline-collector/</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a living document and may be incomplete.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Updated 1DEC2023&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Locating Evidences of Execution using Prefetch, Velociraptor, and Zimmerman’s PECmd&lt;/p&gt;&#xA;&lt;p&gt;Prefetch is a common Windows artifact used for determining the first and last incidences of a program being executed. This file is a binary blob stored at &lt;code&gt;$:\Windows\Prefetch&lt;/code&gt; and consists of a series of files named &lt;code&gt;APPLICATION-GUID.pf&lt;/code&gt;. These files contain the name of the executable, the last &lt;code&gt;n&lt;/code&gt; run date time groups a hash of the executable and path, and a list of files accessed by the &lt;code&gt;.exe&lt;/code&gt; in the first few seconds of loading.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Show And Tell</title>
      <link>https://justinmcafee.com/posts/2023/show-and-tell/</link>
      <pubDate>Sun, 12 Nov 2023 15:13:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/show-and-tell/</guid>
      <description>&lt;p&gt;Once a week, our security team gathers everyone into a meeting and shares the last week’s worth of security related news and any new security initiatives.&lt;/p&gt;&#xA;&lt;p&gt;This one hour may be the most valuable meeting we attend and has the greatest impact on successful security outcomes.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://justinmcafee.com/images/pexels-lisa-fotios-11366392.jpg&#34;&gt;&lt;img src=&#34;https://justinmcafee.com/images/pexels-lisa-fotios-11366392.jpg&#34; alt=&#34;A woman&amp;rsquo;s hand holds a cellphone showing a BBC news article discussing Russian hacking.&#34;&gt;&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>2023.10.17.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2023/2023.10.17.news-you-should-know/</link>
      <pubDate>Tue, 17 Oct 2023 08:40:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/2023.10.17.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://therecord.media/cdw-investigates-ransomware-gang-claim&#34; target=&#34;_blank&#34;&gt;CDW investigating ransomware gang claims of data theft (therecord.media)&lt;/a&gt; - #Ransomware #ThreatActor - CDW acknowledges breach of a subsidiary of a division of a business area. Threat actors miffed over $1m offer after $80m demand.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/&#34; target=&#34;_blank&#34;&gt;HTTP/2 ‘Rapid Reset’ zero-day exploited in biggest DDoS yet • The Register&lt;/a&gt; - #Research #ThreatActor - Largest ever DDoS…from smallest ever botnet? 20k bots (multitudes smaller than previous botnets) were able to abuse HTTP/2 streaming to request hundreds of assets from a server over a single TCP stream (a feature of HTTP/2) then cancel those request midstream and request a hundred assets again. Which doesn’t count toward the max request limit. The only theoretical limit to this attack is target bandwidth.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LibWebP (CVE-2023-4863)</title>
      <link>https://justinmcafee.com/posts/2023/libwebp-cve-2023-4863/</link>
      <pubDate>Thu, 28 Sep 2023 17:17:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/libwebp-cve-2023-4863/</guid>
      <description>&lt;p&gt;Here is a non-exhaustive list of possible mitigations to prevent the exploitation of CVE &lt;a href=&#34;https://nvd.nist.gov/vuln/detail/CVE-2023-4863&#34; target=&#34;_blank&#34;&gt;2023-4863&lt;/a&gt; in the LibWebP library. This library has a heap buffer overflow available across all operating systems, most browsers, an exceptional number of Electron framework applications.&lt;/p&gt;&#xA;&lt;p&gt;This CVE is rated a 10 after previously being rated 8.8. This was due to an original disclosure from Google stating that Chrome was the only effected application. After investigation, it was discovered that all instances of the LibWebP library were vulnerable across all platforms.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2023.03.21.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2023/2023.03.21.news-you-should-know/</link>
      <pubDate>Wed, 22 Mar 2023 14:40:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/2023.03.21.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.forbes.com/sites/conormurray/2023/03/13/what-to-know-about-silicon-valley-banks-collapse-the-biggest-bank-failure-since-2008/?sh=491b3baf4c27&#34; target=&#34;_blank&#34;&gt;Silicon Valley Bank collapsed&lt;/a&gt; this month causing credit ratings of major banks to drop and another to fail. While a multitude of information about this is available we find it most interesting because threat actors are using the collapse as pretext for scam emails. These emails are sent to trusted third-party businesses asking for updates to the accounts payable or EFT details to threat actor controlled accounts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2023.02.28.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2023/2023.02.28.news-you-should-know/</link>
      <pubDate>Tue, 28 Feb 2023 11:48:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/2023.02.28.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.mwcbarcelona.com/agenda/session/sec-con-2023-securing-telecoms-in-times-of-conflict&#34; target=&#34;_blank&#34;&gt;Mobile World Congress&lt;/a&gt; will feature highlights of &lt;a href=&#34;https://www.telemediaonline.co.uk/mwc-23-how-mobile-networks-are-being-used-in-the-war-in-ukraine/&#34; target=&#34;_blank&#34;&gt;mobile networks being utilized in the Russo-Ukrainian conflict&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Discussions will be held around Ukraine and Russia’s use of civilian mobile network infrastructure, the dangers of geo-location data, and the largest roaming disablement in mobile networking history.&lt;/p&gt;&#xA;&lt;p&gt;NIST is accepting comments on the &lt;a href=&#34;https://www.nist.gov/system/files/documents/2023/01/19/CSF_2.0_Concept_Paper_01-18-23.pdf&#34; target=&#34;_blank&#34;&gt;newest version of the Cyber Security Framework&lt;/a&gt; {PDF}&lt;/p&gt;</description>
    </item>
    <item>
      <title>Malicious OneNote</title>
      <link>https://justinmcafee.com/posts/2023/malicious-onenote/</link>
      <pubDate>Tue, 24 Jan 2023 23:12:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/malicious-onenote/</guid>
      <description>&lt;h1 id=&#34;anatomy-of-a-malicious-email-attachment&#34;&gt;Anatomy of a Malicious Email Attachment&lt;/h1&gt;&#xA;&lt;h2 id=&#34;with-microsofts-recent-changes-to-macros-within-the-office-and-m365-suite-threat-actors-have-changed-their-ttps-to-utilize-the-onenote-one-file-type-for-malicious-code-delivery&#34;&gt;With Microsoft’s recent changes to macros within the Office and M365 suite, Threat Actors have changed their TTPs to utilize the OneNote (.one) file type for Malicious Code Delivery&lt;/h2&gt;&#xA;&lt;h3 id=&#34;tldr-one-files-are-a-binary-blob-capable-of-embedding-any-file-type-threat-actors-are-utilizing-the-prolific-nature-of-onenote-to-execute-malicious-code-on-endpoints-block-one-files-from-incoming-email-and-dissociate-commonly-abused-file-extensions&#34;&gt;TL;DR (.one) files are a binary blob capable of embedding any file type. Threat actors are utilizing the prolific nature of OneNote to execute malicious code on endpoints. Block (.one) files from incoming email and dissociate commonly abused file extensions.&lt;/h3&gt;&#xA;&lt;h3 id=&#34;the-problem&#34;&gt;The Problem&lt;/h3&gt;&#xA;&lt;p&gt;Microsoft recently modified the way legacy Office applications and M365 applications handle macros within documents. With the restrictions on macros tightening, threat actors have been forced to find new techniques to deliver malicious code to the endpoint.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2023.01.17.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2023/2023.01.17.news-you-should-know/</link>
      <pubDate>Tue, 17 Jan 2023 11:37:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/2023.01.17.news-you-should-know/</guid>
      <description>&lt;p&gt;Microsoft is set to &lt;a href=&#34;https://www.reddit.com/r/sysadmin/comments/10dvneq/microsoft_ticking_timebombs_january_2023_edition/&#34; target=&#34;_blank&#34;&gt;introduce significant changes&lt;/a&gt; to the Windows enterprise over the next year. With multiple security settings going from &lt;em&gt;recommended&lt;/em&gt; to &lt;em&gt;enforced&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Highlights include the EOL for AD Connector 2.0.x, changes to MFA, and the end of standalone Office Apps for 2016/19.&lt;/p&gt;&#xA;&lt;p&gt;Caniphish’s Sebastian Salla published a &lt;a href=&#34;https://caniphish.com/phishing-resources/blog/scanning-spf-records&#34; target=&#34;_blank&#34;&gt;review of thousands of misconfigured SPF&lt;/a&gt; records today allowing emails to be sent on behalf of foreign governments, the Massachusetts Institute of Technology, the University of Miami, among others.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2023.01.10.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2023/2023.01.10.news-you-should-know/</link>
      <pubDate>Tue, 10 Jan 2023 12:46:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/2023.01.10.news-you-should-know/</guid>
      <description>&lt;p&gt;House &lt;a href=&#34;https://www.congress.gov/117/bills/hr2617/BILLS-117hr2617enr.pdf&#34; target=&#34;_blank&#34;&gt;omnibus spending bill&lt;/a&gt; brings three interesting cybersecurity measures.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Section 7030 will require cybersecurity to be a key consideration in the adoption of technology and specifically 5g technologies for members of the &lt;a href=&#34;https://www.state.gov/digital-connectivity-and-cybersecurity-partnership/&#34; target=&#34;_blank&#34;&gt;Digital Connectivity and Cybersecurity Partnership&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;The “No TikTok on Government Devices Act” bans the use of the Chinese-owned ByteDance company’s TikTok social media platform on goverment owned devices with power being given to the Director of the Cybersecurity and Infrastructure Security Agency (CISA) to dictate how application management is performed.&lt;/li&gt;&#xA;&lt;li&gt;Section 3305 will require the FDA to ensure cybersecurity requirements are placed on medical devices. This is a change in posture from the FDA’s previous encouragement to follow cybersecurity best practices. &lt;a href=&#34;https://www.lawfareblog.com/one-small-legislative-step-cybersecurity&#34; target=&#34;_blank&#34;&gt;Lawfare gives a breakdown of Section 3305.&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Chair of the Senate Select Committee on Intelligence, and former techie, Sen. Mark Warner (D-VA) gave an &lt;a href=&#34;https://techcrunch.com/2023/01/08/senator-mark-warner-on-cyber-security-musks-twitter-and-legislating-killer-robots/&#34; target=&#34;_blank&#34;&gt;interview via TechCrunch&lt;/a&gt; at the 2023 Consumer Electronics Show. In the interview, Warner discusses his legislation preventing the use of Huawei technologies, TikTok on federal devices, and the FTC’s handling of acquisitions and monopolies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2023.03.01.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2023/2023.03.01.news-you-should-know/</link>
      <pubDate>Tue, 03 Jan 2023 10:17:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2023/2023.03.01.news-you-should-know/</guid>
      <description>&lt;p&gt;Google Chrome 110, &lt;a href=&#34;https://www.msn.com/en-us/news/technology/google-chrome-will-stop-working-properly-on-millions-of-windows-pcs-next-week/ar-AA15UH8U?ocid=entnewsntp&amp;amp;cvid=e97ee339d5574c05a0f97dc700dd616c&#34; target=&#34;_blank&#34;&gt;slated for release on Feb 7th&lt;/a&gt; will drop support for Windows 7 and Windows 8.1. This matches Microsoft’s end-of-life date for Windows 7 and 8.1 extended support.&lt;/p&gt;&#xA;&lt;p&gt;Raspberry Robin targets &lt;a href=&#34;https://www.securityjoes.com/post/raspberry-robin-detected-itw-targeting-insurance-financial-institutes-in-europe&#34; target=&#34;_blank&#34;&gt;financial institutions in Europe&lt;/a&gt;, current victim profiles seem to show Threat Actors targeting Spanish and Portugeuse speaking institutions. The offensive framework recently underwent updates to provide polymorphic code, preventing hashes or signatures to have much effect against detection. Regardless, researches have identified threat actor infrastructure to develop indicators of compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2022.20.12.News You Should Know</title>
      <link>https://justinmcafee.com/posts/2022/2022.20.12.news-you-should-know/</link>
      <pubDate>Tue, 20 Dec 2022 13:14:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2022/2022.20.12.news-you-should-know/</guid>
      <description>&lt;p&gt;Most of the Information Security community has fled Twitter in favor of a Mastodon instance &lt;a href=&#34;https://infosec.exchange&#34; target=&#34;_blank&#34;&gt;Infosec.Exchange&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Mastodon is a federated replacement for Twitter and has balloned from 100k user to over 2.5m users since Musk’s takeover of the Twitter platform. As most vendors, businesses, consultants, and infosec personalities made the move to Mastodon, so has the public zeitgeist of up-to-date security news and disclosures. To keep tabs, you can check out the public feeds &lt;a href=&#34;https://infosec.exchange/tags/cti&#34; target=&#34;_blank&#34;&gt;CTI&lt;/a&gt; and &lt;a href=&#34;https://infosec.exchange/tags/ThreatIntel&#34; target=&#34;_blank&#34;&gt;ThreatIntel&lt;/a&gt; (These tags do not require an account to view.)&lt;/p&gt;</description>
    </item>
    <item>
      <title>Racism, Fascism, and other Human Problems on Mastodon</title>
      <link>https://justinmcafee.com/posts/2022/racism-fascism-and-other-human-problems-on-mastodon/</link>
      <pubDate>Sun, 27 Nov 2022 07:38:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2022/racism-fascism-and-other-human-problems-on-mastodon/</guid>
      <description>&lt;p&gt;I am continually fascinated by the amount of users from the Twitter Diaspora who are decrying the lack of robust fixes for socialogical issues within the Fediverse at large, but specifically within the Mastodon social media realm.&lt;/p&gt;&#xA;&lt;p&gt;It is not any surprise to those of us that have studied human behavior or history that bigots and other practicers of vile “-isms” are to be found on the fediverse as every where else.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mastodon Privacy for Small Instances</title>
      <link>https://justinmcafee.com/posts/2022/mastodon-privacy-for-small-instances/</link>
      <pubDate>Sat, 26 Nov 2022 21:50:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2022/mastodon-privacy-for-small-instances/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://justinmcafee.com/images/mastodon-privacy-for-small-instances-3.jpg&#34;&gt;&lt;img src=&#34;https://justinmcafee.com/images/mastodon-privacy-for-small-instances-3.jpg&#34; alt=&#34;A screenshot of the author&amp;rsquo;s Mastodon instance available at digitaldarkage.cc. Screenshot shows the instances logo, as well as a user count of 5 and a tagline of &amp;ldquo;A return to an older and better internet&amp;rdquo;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Mastodon, one of many social media platforms on the Fediverse, has attracted a lot of attention since the purchase of Twitter by Elon Musk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Impostor Syndrome</title>
      <link>https://justinmcafee.com/posts/2022/impostor-syndrome/</link>
      <pubDate>Fri, 11 Nov 2022 09:55:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2022/impostor-syndrome/</guid>
      <description>&lt;blockquote&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;h1 id=&#34;do-you-not-know-my-son-with-how-little-wisdom-the-world-is-governed&#34;&gt;&amp;ldquo;Do you not know, my son, with how little wisdom the world is governed?”&lt;/h1&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;h3 id=&#34;axel-oxenstierna-lord-high-chancellor-of-sweden-to-his-son-who-feared-holding-his-own-as-a-peace-delegate-at-the-peace-of-westphalia&#34;&gt;― Axel Oxenstierna, Lord High Chancellor of Sweden to his son who feared holding his own as a peace delegate at the Peace of Westphalia&lt;/h3&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;I find that people in the Information Security field often believe that others are smarter than them, or more educated or experienced than them. But my experience has been the opposite.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Host Identification through WPAD (Web Proxy Auto Discovery) DNS Queries</title>
      <link>https://justinmcafee.com/posts/2022/host-identification-through-wpad-web-proxy-auto-discovery-dns-queries/</link>
      <pubDate>Tue, 22 Feb 2022 19:56:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2022/host-identification-through-wpad-web-proxy-auto-discovery-dns-queries/</guid>
      <description>&lt;p&gt;DNS is by far my favorite passive way to identify required resources and to perform reconnaissaince against a host.&lt;/p&gt;&#xA;&lt;p&gt;DNS is one of the least secured protocols and runs as a fairly untrusted&lt;/p&gt;&#xA;&lt;p&gt;WPAD can be a great resource for identifying hosts home domains without a lot of DNS&lt;/p&gt;</description>
    </item>
    <item>
      <title>HEAR Model</title>
      <link>https://justinmcafee.com/posts/2021/hear-model/</link>
      <pubDate>Sat, 17 Jul 2021 21:47:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2021/hear-model/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://justinmcafee.com/images/pexels-oladimeji-ajegbile-3118214.jpg&#34;&gt;&lt;img src=&#34;https://justinmcafee.com/images/pexels-oladimeji-ajegbile-3118214.jpg&#34; alt=&#34;&#34;&gt;&lt;br&gt;&#xA;&lt;br&gt;&#xA;Photo by Oladimeji Ajegbile from Pexels&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This method of Bible study was handed down to me in 2008 at The University of Tennessee Chattanooga’s Baptist Collegiate Ministries (UTC-BCM).&lt;/p&gt;&#xA;&lt;p&gt;At the time Robbie Gallaty was leading Brainerd Baptist and had an intense focus on discipleship and relationship in the church family.&lt;/p&gt;</description>
    </item>
    <item>
      <title>EndleSSH by Chris Wellens (github:skeeto)</title>
      <link>https://justinmcafee.com/posts/2021/endlessh-by-chris-wellens-githubskeeto/</link>
      <pubDate>Fri, 29 Jan 2021 21:30:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2021/endlessh-by-chris-wellens-githubskeeto/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://live.staticflickr.com/5123/5294003122_b25c62b4a9_b.jpg&#34; alt=&#34;Los Angeles CA ~ La Brea Tar Pits&#34;&gt;&lt;a href=&#34;https://www.flickr.com/photos/7156765@N05/5294003122&#34; target=&#34;_blank&#34;&gt;&amp;ldquo;Los Angeles CA ~ La Brea Tar Pits&amp;rdquo;&lt;/a&gt; by &lt;a href=&#34;https://www.flickr.com/photos/7156765@N05&#34; target=&#34;_blank&#34;&gt;Onasill ~ Bill Badzo - - 70M Views&lt;/a&gt; is licensed under &lt;a href=&#34;https://creativecommons.org/licenses/by-nc-nd/2.0/?ref=ccsearch&amp;amp;atype=html&#34; target=&#34;_blank&#34;&gt;CC BY-NC-ND 2.0&lt;/a&gt; &lt;a href=&#34;https://creativecommons.org/licenses/by-nc-nd/2.0/?ref=ccsearch&amp;amp;atype=html&#34; target=&#34;_blank&#34;&gt;&lt;img src=&#34;https://search.creativecommons.org/static/img/cc_icon.svg?image_id=a80650f6-390e-4c1d-a3a6-9d05b81e8d5d&#34; alt=&#34;&#34;&gt;&lt;img src=&#34;https://search.creativecommons.org/static/img/cc-by_icon.svg&#34; alt=&#34;&#34;&gt;&lt;img src=&#34;https://search.creativecommons.org/static/img/cc-nc_icon.svg&#34; alt=&#34;&#34;&gt;&lt;img src=&#34;https://search.creativecommons.org/static/img/cc-nd_icon.svg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;I recently completed the SANS SEC503: Network Intrusion Detection course and while there is more than enough information to melt your brain, I picked up a few tricks I&amp;rsquo;d never seen before. I&amp;rsquo;d like to share one of the quickest and most practical here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Eisenhower Matrix</title>
      <link>https://justinmcafee.com/posts/2018/the-eisenhower-matrix/</link>
      <pubDate>Fri, 07 Dec 2018 11:11:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/the-eisenhower-matrix/</guid>
      <description>&lt;p&gt;The Eisenhower Matrix was formalized and popularized by Business Thinker Stephen Covey in his book “7 Habits of Highly Effective People” based on a quote and life advice from President Dwight D. Eisenhower.&lt;/p&gt;&#xA;&lt;p&gt;Eisenhower, a General famous for his mastery of Operation Torch, the invasion of Northern Africa during World War II and later the approving authority for NASA, understood the importance of prioritization at every level. From commanding troops on the battlefield, to beating the Soviets in space, Eisenhower understood the long and short game and used it to become one of the most successful Presidents in America’s history.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Productive Man’s Guide To Journaling</title>
      <link>https://justinmcafee.com/posts/2018/the-productive-mans-guide-to-journaling/</link>
      <pubDate>Fri, 07 Dec 2018 11:06:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/the-productive-mans-guide-to-journaling/</guid>
      <description>&lt;h3 id=&#34;who-am-i-and-why-should-you-care&#34;&gt;Who Am I and Why Should You Care?&lt;/h3&gt;&#xA;&lt;h3&gt;&lt;a href=&#34;https://justinmcafee.com/images/address-adult-african-1061576.jpg&#34;&gt;&lt;img src=&#34;https://justinmcafee.com/images/address-adult-african-1061576.jpg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;I am a specialist in process analysis and design with a background in automation. After serving six years in a Special Operations military occupational specialty, I brought my skills to the private sector.&lt;/p&gt;&#xA;&lt;p&gt;Since then I have specialized in helping small businesses and charitable organizations with process definition, documentation, and engineering. This skill has helped insure that my clients are able to prioritize and focus costs on what matters most while saving time and money.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Food List</title>
      <link>https://justinmcafee.com/posts/2018/food-list/</link>
      <pubDate>Tue, 09 Oct 2018 08:54:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/food-list/</guid>
      <description>&lt;blockquote&gt;&#xA;&lt;p&gt;Originally published in 2016, here is a list of the things I keep in my home pantry. Note, we have re-acquired chickens and now hold around 125-150 birds at any given time.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://justinmcafee.com/images/bazaar-bottles-business-15964.jpg&#34;&gt;&lt;img src=&#34;https://justinmcafee.com/images/bazaar-bottles-business-15964.jpg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;I keep 12-15 cans of the following in my pantry at all times and rotate the oldest forward. Throughout the week we make a list on the fridge of any cans we use. Weekly my wife and I go to the store and replace what ever we’ve taken out of the stores.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Psychologist Programs</title>
      <link>https://justinmcafee.com/posts/2018/psychologist-programs/</link>
      <pubDate>Wed, 22 Aug 2018 12:56:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/psychologist-programs/</guid>
      <description>&lt;p&gt;+++&#xA;title = &amp;ldquo;Psychologist Programs&amp;rdquo;&#xA;date = 2018-08-22T12:56:00Z&#xA;+++&lt;/p&gt;&#xA;&lt;p&gt;I was hired by a psychologist to fix a program that seemed to have &amp;ldquo;strange output&amp;rdquo; written by one of his ex-grad students. It was a program that reads a data file, asks about 50 questions, does some calculations, and comes up with some score based on this PhD&amp;rsquo;s research. It&amp;rsquo;s on a research 3B2 at the university. He demonstrates the program and sure enough there seemed to be strange flashing words on the screen when it moves from question to question, and they don&amp;rsquo;t seem nice. I agree to do it, should be pretty straightforward, so he&amp;rsquo;ll pay me by the hour to determine how big the fix is and then we&amp;rsquo;ll agree to a fee.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Moment Between Shoulder Blades</title>
      <link>https://justinmcafee.com/posts/2018/a-moment-between-shoulder-blades/</link>
      <pubDate>Wed, 22 Aug 2018 07:28:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/a-moment-between-shoulder-blades/</guid>
      <description>&lt;p&gt;At the end of every summer&lt;/p&gt;&#xA;&lt;p&gt;I come to a place where I don’t&#xA;want to be&lt;/p&gt;&#xA;&lt;p&gt;The years move by faster&lt;/p&gt;&#xA;&lt;p&gt;the summers move quicker than they ever&#xA;have before&lt;/p&gt;&#xA;&lt;p&gt;and the time we had slips quicklythrough our hands&lt;/p&gt;&#xA;&lt;p&gt;But every once and a while&lt;/p&gt;&#xA;&lt;p&gt;you find a second&lt;/p&gt;</description>
    </item>
    <item>
      <title>Rules for IT Professionals</title>
      <link>https://justinmcafee.com/posts/2018/rules-for-it-professionals/</link>
      <pubDate>Thu, 07 Jun 2018 10:27:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/rules-for-it-professionals/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://justinmcafee.com/images/check-class-desk-7103.jpg&#34;&gt;&lt;img src=&#34;https://justinmcafee.com/images/check-class-desk-7103.jpg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;0: Everyone Lies, users especially so.&lt;/p&gt;&#xA;&lt;p&gt;1: Check the simple things before you move on to the hard stuff. ALL of the simple things.&lt;/p&gt;&#xA;&lt;p&gt;2: Question all assumptions.&lt;/p&gt;&#xA;&lt;p&gt;3: Don&amp;rsquo;t give up easily.&lt;/p&gt;&#xA;&lt;p&gt;4: When all else fails, see #1.&lt;/p&gt;&#xA;&lt;p&gt; I&amp;rsquo;ll add more as they become available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Micro Sports Betting</title>
      <link>https://justinmcafee.com/posts/2018/micro-sports-betting/</link>
      <pubDate>Tue, 15 May 2018 06:21:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/micro-sports-betting/</guid>
      <description>&lt;h2 id=&#34;as-old-betting-laws-fall-new-technology-may-prevail&#34;&gt;As Old Betting Laws Fall, New Technology May Prevail&lt;/h2&gt;&#xA;&lt;p&gt;Bottom of the eighth, bases&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://justinmcafee.com/images/architecture-art-audience-139762.jpg&#34;&gt;&lt;img src=&#34;https://justinmcafee.com/images/architecture-art-audience-139762.jpg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;are loaded, scores tied with two outs. The batter steps to the plate as the pitcher and catcher sign quickly to each other. The crowd, already on edge, stares intently at their phones. Panicked tapping ensues as bets are placed. Two to one strike. Five to one bunt. Three to one foul ball. As the batter winds up for the pitch, screens freeze; betting is now locked. “THWAP” The ball goes flying through the air as do millions of microtransactions. Fractions of a Bitcoin, known as a satoshi, are won and lost in the time it takes to swing a bat. As the debits complete, fans peck at their phones, eager to log their bets before the next batter reaches the plate.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Orwell Comes Knocking</title>
      <link>https://justinmcafee.com/posts/2018/orwell-comes-knocking/</link>
      <pubDate>Sat, 12 May 2018 07:15:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/orwell-comes-knocking/</guid>
      <description>&lt;h1 id=&#34;as-america-continues-its-free-wheeling-descent-into-the-hell-that-is-a-police-state-efforts-ramp-up-to-protect-the-common-man&#34;&gt;As America continues its free-wheeling descent into the hell that is a Police state, efforts ramp up to protect the common man.&lt;/h1&gt;&#xA;&lt;h2 id=&#34;department-of-homeland-security-officials-have-requested-bids-for-a-media-monitoring-service-that-would-have-the-ability-to-scan-more-than-290000-news-sources-in-and-outside-the-us-and-store-journalists-editors-correspondents-social-media-influencers-and-bloggers-in-a-database-that-must-be-searchable-for-content-and-sentiment&#34;&gt;Department of Homeland Security officials have requested bids for a Media Monitoring Service that would have the ability to scan more than 290.000 news sources in and outside the US, and store journalists, editors, correspondents, social media influencers, and bloggers in a database that must be searchable for “content” and “sentiment”.&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://justinmcafee.com/images/surveillance.jpg&#34;&gt;&lt;img src=&#34;https://justinmcafee.com/images/surveillance.jpg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why I&#39;m Leaving Facebook and You Should Too</title>
      <link>https://justinmcafee.com/posts/2018/why-im-leaving-facebook-and-you-should-too/</link>
      <pubDate>Tue, 27 Mar 2018 10:43:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/why-im-leaving-facebook-and-you-should-too/</guid>
      <description>&lt;h1 id=&#34;why-im-leaving-facebook-and-you-should-too&#34;&gt;Why I’m Leaving Facebook and You Should Too.&lt;/h1&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://preview.ibb.co/jG2xvS/computer_content_control_270700.jpg&#34; alt=&#34;computer_content_control_270700&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;after-years-of-abusive-privacy-invasions-by-the-social-media-giant-the-recent-leak-regarding-cambridge-analytica-is-causing-a-hemorrhage-of-users-and-advertiser-dollars&#34;&gt;After years of abusive privacy invasions by the social media giant, the recent leak regarding Cambridge Analytica is causing a hemorrhage of users and advertiser dollars.&lt;/h2&gt;&#xA;&lt;p&gt;Earlier this month, Facebook &lt;a href=&#34;https://www.usatoday.com/story/tech/news/2018/03/27/facebook-ceo-mark-zuckerberg-testify-before-congress-cambridge-analytica/462620002/&#34; target=&#34;_blank&#34;&gt;acknoweldged that data from over 50,000,000 users had been illicitly obtained&lt;/a&gt; by data mining and political consulting firm, &lt;a href=&#34;https://en.wikipedia.org/wiki/Cambridge_Analytica&#34; target=&#34;_blank&#34;&gt;Cambridge Analytica&lt;/a&gt;. The data, while legally obtained by the social media site, Facebook, had been taken from &lt;em&gt;friends of friends&lt;/em&gt; who did not consent to the collection by Cambridge Analytica. After the breach of trust was disclosed to Facebook, the company failed to notify affected users, instead opting to allow Cambridge Analytica to promise to delete the illicitly obtained information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Statement Regarding Intel Bug</title>
      <link>https://justinmcafee.com/posts/2018/statement-regarding-intel-bug/</link>
      <pubDate>Wed, 03 Jan 2018 07:06:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/statement-regarding-intel-bug/</guid>
      <description>&lt;h4 id=&#34;i-am-at-a-loss-for-words-as-the-reality-of-the-intel-bug-settles-in-the-tech-community-has-been-shaken-for-years-we-have-falsely-assumed-the-security-of-virtualization-technologies-the-convenience-and-ease-of-spinning-up-and-blowing-away-vms-virtual-machines-in-server-farms-has-become-standard-practice-across-the-globe-even-mcafee-media-solutions-utilizes-virtualization-to-manage-our-web-and-vpn-servers-helping-us-reduce-costs-and-insure-greater-up-times&#34;&gt;I am at a loss for words. As the reality of the Intel bug settles in, the tech community has been shaken. For years we have falsely assumed the security of virtualization technologies. The convenience and ease of ‘spinning up’ and ‘blowing away’ vms (virtual machines) in server farms has become standard practice across the globe. Even &lt;a href=&#34;https://www.mcafeemediasolutions.com&#34; target=&#34;_blank&#34;&gt;McAfee Media Solutions&lt;/a&gt; utilizes virtualization to manage our web and vpn servers; helping us reduce costs and insure greater up times.&lt;/h4&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://justinmcafee.com/images/amd-1310766_1920.jpg&#34; alt=&#34;&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Undersecretary of State Goldstein Recommends VPNs to Iranians Amidst FBI Criminalization of Anonymity Tools. </title>
      <link>https://justinmcafee.com/posts/2018/undersecretary-of-state-goldstein-recommends-vpns-to-iranians-amidst-fbi-criminalization-of-anonymity-tools./</link>
      <pubDate>Tue, 02 Jan 2018 11:29:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2018/undersecretary-of-state-goldstein-recommends-vpns-to-iranians-amidst-fbi-criminalization-of-anonymity-tools./</guid>
      <description>&lt;p&gt;As bloody protests continue in the Islamic Republic of Iran, Iranian officials have blocked internet access to Facebook, Instagram, and other social media websites. Amid the protests, the US Undersecretary of State Steven Goldstein has voiced concern over the behavior of Iranian officials and encouraged Iran to stop limiting external access to the countries users.&lt;/p&gt;</description>
    </item>
    <item>
      <title></title>
      <link>https://justinmcafee.com/posts/2025/2025.04.29.news-you-should-know/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://justinmcafee.com/posts/2025/2025.04.29.news-you-should-know/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/2025/04/23/ripple_npm_supply_chain/&#34; target=&#34;_blank&#34;&gt;Ripple NPM supply chain attack hunts for private keys • The Register&lt;/a&gt; - Threat actors were able to publish 5 new versions of the official Ripple NPM package, all with malicious code to steal keys. Ripple holders should consider rotating keys if they&amp;rsquo;ve made use of any of the packages.&#xA;Effected are NPM hosted packages for 4.2.1-4 and 2.14.2.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
