DevTestSecOps
151 subscribers
515 photos
34 videos
37 files
725 links
Forwards and notes on development, testing, security, and operations from @q587p.

About me: studied as System Architect, worked as a SysAdmin, working now as an Test Automation Engineer. Also, I'm interested in hacking (and everything related to it).

జ్
Download Telegram
👏4😁3🥰2
🤣3💯21
Forwarded from HN Best Comments
Re: CEO fired developers to make room for AI. Developers create open source AI CEO

To be fair I think its far easier to automate leadership jobs despite how they believe in greater self-worth. As a developer I keep running into problems that require some measure of creativity to solve or workaround. And regardless of how many years I've been in the industry I'm not running out of issues. They just keep getting more obscure. On the other hand leadership communication and problem resolution seem like the exact opposite of creativity and innovation. Its all about time proven, reliable solutions. Same layoff notices, recommendations, design everywhere. Repetitive, boring, politically correct and therefore easy to automate. Accountability will likely become reason n1 for keeping leadership roles intact that is until people become accustomed to AIs everywhere. After all what's the difference between a bot showing a layoff notice at 5am or an AI generated message/video from a human doing the very same thing.

crnkofe, 1 day ago
🔥3👍2😁2
#DPRK #way

The DPRK built its cyber capability as a deliberate extension of its asymmetric deterrence doctrine, treating cyber operations as a cheap, deniable "all-purpose sword" alongside nuclear weapons to ensure regime survival against better-resourced adversaries and circumvent international sanctions.

* From roughly 2014 onward, cyber operations evolved from espionage and sabotage into a load-bearing revenue stream, bank heists, ransomware, and cryptocurrency theft, financing the very weapons programmes that international sanctions were designed to constrain.

* Even as the GRIB (ex-RGB) and NIA (ex-MSS) consistently lead DPRK cyber offensive operations, the units and bureaus beneath them are subject to constant reorganization, a deliberate control mechanism that keeps agencies competing for Kim Jong-un's favor, prevents consolidation of independent power, and complicates the attribution and sanctions-designation efforts of foreign governments.

* DPRK offensive cyber operations are distributed across APT clusters, with the former Lazarus umbrella now decomposed by Sekoia and Kudelski Security into six distinct sub-clusters, nearly all of which conduct lucrative operations, whether as their primary mandate or to self-fund espionage and sabotage campaigns.

* These APT intrusion sets are complemented by thousands of IT workers operating under false identities worldwide, who serve a dual function: remitting salaries to the regime and leveraging their insider access within contracted organizations to conduct further operations, with proceeds laundered through centralized exchanges, decentralized exchanges (DEXs), and P2P platform.

* The DPRK has constructed a complex network of educational and private intermediaries to enable its cyber operations, spanning academic institutions that both train operatives and function as operational nodes. This parallel web of third-country relays often extends to allies like China and Russia, as well as countries in Africa and Southeast Asia. Front companies across these regions participate in generating revenue and providing operational cover, while criminal networks are operationalized for money laundering.


https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
👀2🤔1