Uploaded September 2019 | Updated September 2026, 1 week ago
In this stream, we take a look at one of the core principles of the cloud: the shared responsibility model.
This is often touted as "how security works in the cloud" and while that's true, it's simple just how the cloud works. Security is a critical PART of operations and all of operations in the cloud works under this model.
We talk about the model, how AWS usually presents it, a simpler way to understand it, and how to make sure that AWS is fulfilling their responsibilities in the model.
Original stream on LinkedIn: linkedin.com/posts/marknca_activity-6582624339873669120-lRlz
Continuing the road to AWS re:Invent 2019: markn.ca/2019/aws-reinvent
In this stream, we take a look at one of the core principles of the cloud: the shared responsibility model.
This is often touted as "how security works in the cloud" and while that's true, it's simple just how the cloud works. Security is a critical PART of operations and all of operations in the cloud works under this model.
We talk about the model, how AWS usually presents it, a simpler way to understand it, and how to make sure that AWS is fulfilling their responsibilities in the model.
Original stream on LinkedIn: linkedin.com/posts/marknca_activity-6582624339873669120-lRlz
Continuing the road to AWS re:Invent 2019: markn.ca/2019/aws-reinvent
![Microsoft Windows PrinterNightmare Patch Highlight “Unperfect” Security Decisions #shorts
The PrinterNightmare vulnerability was patched out-of-band (on an emergency basis) but the patch doesnt completely address the issue.
Hackers can still easily use this to run their code on your systems if youre using a feature called Point and Print (and a lot of people are). Where does that leave defenders?
More in this short...
References:
- Brian Krebs has a post on the out-of-band patch; Microsoft Issues Emergency Patch for Windows Flaw, https://krebsonsecurity.com/2021/07/microsoft-issues-emergency-patch-for-windows-flaw/
- From BleepingComputer, Microsofts incomplete PrintNightmare patch fails to fix vulnerability, https://www.bleepingcomputer.com/news/microsoft/microsofts-incomplete-printnightmare-patch-fails-to-fix-vulnerability/
- Security Update Guide from the Microsoft Security Response Center, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
- Introduction to Point and Print - Windows drivers from the Microsoft docs, https://docs.microsoft.com/en-us/windows-hardware/drivers/print/introduction-to-point-and-print
Index:
- [0:00] The vulnerability
- [0:17] Point and Print
- [0:29] Make a choice
#shorts Microsoft Windows PrinterNightmare Patch Highlight “Unperfect” Security Decisions #shorts](https://i.ytimg.com/vi/ZmmoIMYMlVQ/mqdefault.jpg)
![Nation State Hackers Are Targeting Email Servers, Is It Time To Panic? #shorts
Microsoft warned that a nation state actor called HAFNIUM is actively targeting users of its Microsoft Exchange email server. Thankfully there are patches out for the four issues involved.
Problem solved, right?
Maybe not. We explore in this short...
Index;
- The question [0:00]
- Microsoft Exchange issue [0:05]
- Just patch [0:16]
#shorts Nation State Hackers Are Targeting Email Servers, Is It Time To Panic? #shorts](https://i.ytimg.com/vi/_jlM33jHwdY/mqdefault.jpg)
![Microsoft Edge Experiment “Super Duper Secure Mode” Aims To Reduce Openings for Hackers #shorts
The Microsoft Edge browser team is conducting an experiment in an attempt to increase the cybersecurity of the browser and how it handles javascript. At stake? One of the major performance features.
Learn more in this short...
References:
- coverage from TheRecord, Microsoft announces new Super Duper Secure Mode for Edge
, https://therecord.media/microsoft-announces-new-super-duper-secure-mode-for-edge/
- the research note from the team, Super Duper Secure Mode, https://microsoftedge.github.io/edgevr/posts/Super-Duper-Secure-Mode/
- more on the V8 (JavaScript engine) from Wikipedia, https://en.wikipedia.org/wiki/V8_(JavaScript_engine)
Index:
- [0:00] The experiment
- [0:12] Why?
- [0:33] Computing platform
#shorts Microsoft Edge Experiment “Super Duper Secure Mode” Aims To Reduce Openings for Hackers #shorts](https://i.ytimg.com/vi/_xppPCiTaRM/mqdefault.jpg)
![Update Your iPhone Now (iOS 14.4.1) #shorts
Apple has issued an out-of-band or unexpected update to iOS (and macOS) to address a cybersecurity issue.
No need to panic but it is time to update before hackers take advantage.
This short shows you how...
Index:
- The update [0:00]
- Details [0:06]
- How to update [0:08]
#shorts Update Your iPhone Now (iOS 14.4.1) #shorts](https://i.ytimg.com/vi/a1qrg2D67GM/mqdefault.jpg)
![REvil-ed Ransomware Group Goes Kaput? #shorts
REvil has been one of the top ransomware groups for the past few months but theyre suddenly offline. No note, no warning, just gone.
More in this short...
References:
- Tweet from Lawrence Abrams, https://twitter.com/LawrenceAbrams/status/1414929050729074714?s=20
- Kevin Beaumont on the issue, https://twitter.com/GossiTheDog/status/1414947622633279493?s=20
- Coverage from the NY Times, https://www.nytimes.com/2021/07/13/us/politics/russia-hacking-ransomware-revil.html
- Bank Info Security on the list of Kaseya victims, https://www.bankinfosecurity.com/list-victims-kaseya-ransomware-attack-grows-a-17013
- The Avaddon shutdown where keys were made available, https://www.bleepingcomputer.com/news/security/avaddon-ransomware-shuts-down-and-releases-decryption-keys/
Index:
- [0:00] ⏰
- [0:09] Gone for good?
- [0:17] Keys
- [0:29] Why?
- [0:43] 🔦
#shorts REvil-ed Ransomware Group Goes Kaput? #shorts](https://i.ytimg.com/vi/aYbeyNKCALk/mqdefault.jpg)

![No Privacy With Google Chrome on iOS #shorts
Google recently added the privacy label for Google Chrome on iOS and the results should shock no one: the app tracks a lot.
We explore the issue in this short...
Index:
- Privacy labels [0:00]
- Google lists everything [0:05]
- Why use it? [0:16] No Privacy With Google Chrome on iOS #shorts](https://i.ytimg.com/vi/b7g4w8OhWFQ/mqdefault.jpg)


![Pegasus Spyware Runs Roughshod over Human Rights #shorts
The Pegasus Project is a collaborative effort by a number of media and advocacy organizations around to the world. With their work, they are shining a light on nation state use a specific malware tool: Pegasus spyware.
Learn more in this short...
References:
- from the Washington Post, Takeaways from the Pegasus Project, https://www.washingtonpost.com/investigations/2021/07/18/takeaways-nso-pegasus-project/
- also from the Washington Post, Private Israeli spyware used to hack cellphones of journalists, activists worldwide, https://www.washingtonpost.com/investigations/interactive/2021/nso-spyware-pegasus-cellphones/
- The Guardians coverage, The Pegasus project, https://www.theguardian.com/news/series/pegasus-project
- from PBS, THE PEGASUS PROJECT Live Blog: Major Stories from Partners, https://www.pbs.org/wgbh/frontline/article/the-pegasus-project-live-blog-major-stories-from-partners/
- Amnesty International with, Pegasus Project: Apple iPhones compromised by NSO spyware, https://www.amnesty.org/en/latest/news/2021/07/pegasus-project-apple-iphones-compromised-by-nso-spyware/
- Independent Peer Review of Amnesty Internationals Forensic Methods for Identifying Pegasus Spyware - The Citizen Lab, https://citizenlab.ca/2021/07/amnesty-peer-review/
- Apple Now Has Over 1 Billion Active iPhones Worldwide, 1.65 Billion Total Devices, https://www.macrumors.com/2021/01/27/apple-active-devices-worldwide-january-2021/
Index:
- [0:00] The Pegasus Project
- [0:16] Nation states
- [0:28] Security research
#shorts Pegasus Spyware Runs Roughshod over Human Rights #shorts](https://i.ytimg.com/vi/cnizxXIJrgU/mqdefault.jpg)
