RSS Amplifier

Podcast

Basics Are Hard

I don't know why they call things "basic" when they are often hard to do. Musings on Cybersecurity, Information Technology, and other topics.

basicsarehard.substack.comSource feed ↗11 episodes

Live Last read · last published · next check

Written by

Latest episodes

The New HIPAA Security Rule Is Delayed to 2027 — What Healthcare Orgs Should Do Now

HHS pushed the updated HIPAA Security Rule back to at least July 2027 after comments called it too costly. The 2013 rule still applies — here's what to do now.

The First 24 Hours After a Business Email Compromise

Fraudulent wire or compromised inbox? What to do in the first 24 hours of a business email compromise — the bank call, the evidence, and evicting the attacker

The worms will continue until the ecosystem improves

458 packages. 5 ship to production. The rest are attack surface.

Building an AI App on Azure: What I Actually Learned

A serverless pipeline that watches RSS feeds, summarizes new posts with an LLM, and emails subscribers, built entirely with Azure Logic Apps, Terraform, and no long-lived secrets.

Mythos Zero Days Aren't the Real Problem

Vulnerability management hinges on good architecture practices. AI-powered vulnerability discovery doesn't solve for this in any meaningful way.

Your Google Workspace Has Hundreds of OAuth Grants. Do You Know What They Can Do?

The Vercel incident is a good reminder: do you actually control what OAuth apps can access your Google Workspace?

Supply chain attack alert: LiteLLM 1.82.8 is compromised.

Textbook PyPI supply chain attack, now targeting AI infrastructure. Treat your LLM stack like any other production dependency.

Your Free Email Might Be Pretty Expensive in a Data Breach

Since the widespread adoption of the Internet in the 1990s, many internet providers and online companies have offered free email to anyone able to come up with a username.

Easy Playbooks to Make Ransomware Criminals Cry

Here are the slides and playbooks discussed in the BlueTeamCon presentation, "Easy Playbooks to Make Ransomware Criminals Cry" on August 28, 2022.

You’ve got Mail (and Misdirected Funds): A live demo of email hacking

Presentation given at CypherCon, March 31, 2023

Threat Alert! How to Check and Secure your Google, Microsoft, and Apple Accounts

Have you ever felt that unsettling moment when you suspect your online accounts have been breached?