Yves K. D.
banner
declerus.me
Yves K. D.
@declerus.me
Senior Cyber Security Analyst
Reposted by Yves K. D.
The Chinese Computer Emergency Response Center announced that a U.S. intelligence agency hacked an advanced materials unit and an energy-focused company, stealing important trade secrets and intellectual property via trojans. www.globaltimes.cn/page/202412/...
www.globaltimes.cn
December 19, 2024 at 6:12 AM
25m
I don't know why this is exciting... but the anticipation of it hitting the next million!

bsky-users.theo.io
December 12, 2024 at 2:00 PM
Reposted by Yves K. D.
Anyone else thinking that the emergence of the MCP server layer on top of Claude signals that LLMs are coming to data engineering for real? Who's interacting with a MCP server & agent framework already? Any hot takes? github.com/punkpeye/awe...
GitHub - punkpeye/awesome-mcp-servers: A collection of MCP servers.
A collection of MCP servers. Contribute to punkpeye/awesome-mcp-servers development by creating an account on GitHub.
github.com
December 11, 2024 at 7:04 AM
Reposted by Yves K. D.
Check out the Hacking 2024 bundle. You get 18 infosec books (including my book, HACKS: LEAKS, AND REVELATIONS), you pay what you want, and it raises money for charity. It ends in 2 weeks www.humblebundle.com/books/hackin...
Humble Tech Book Bundle: Hacking 2024 by No Starch
Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!
www.humblebundle.com
December 9, 2024 at 10:26 PM
Reposted by Yves K. D.
Exclusive: The backdoor inserted in v1.95.7 adds an "addToQueue" function which exfiltrates the private key through seemingly-legitimate CloudFlare headers.

Calls to this function are then inserted in various places that (legitimately) access the private key.
December 3, 2024 at 11:47 PM
Reposted by Yves K. D.
The AI chip race heats up as AWS unveils Trainium2 (T2) chips, designed to train and deploy large language models faster than Nvidia GPUs though Blackwell is expected to surpass them.

In a surprising move Apple announced it’s using AWS chips for search and exploring their use for Apple Intelligence
AWS' Trainium2 chips for building LLMs are now generally available, with Trainium3 coming in late 2025 | TechCrunch
At its re:Invent conference, AWS today announced the general availably of its Trainium2 (T2) chips for training and deploying large language models
techcrunch.com
December 3, 2024 at 9:41 PM
Reposted by Yves K. D.
I think iOS 18.2 RC will likely be released next week 🤔
November 29, 2024 at 2:09 PM
Reposted by Yves K. D.
Suspicious behavior on T-Mobile US’s network devices tipped off the company to a breach that was potentially part of a sprawling cyber-espionage campaign that has raised urgent questions about the exposure of a critical sector of the economy
T-Mobile Engineers Spotted Hackers Running Commands on Routers
Suspicious behavior on T-Mobile US Inc.’s network devices tipped off the company to a breach that was potentially part of a sprawling cyber-espionage campaign that has raised urgent questions about th...
www.bloomberg.com
November 27, 2024 at 3:30 PM
Great video
Lots of news about iOS 19, iPhone 17 Pro, iPhone Air and much more in the weekly Apple News update. Hope you enjoy and have a great week.

Full video here: youtu.be/5hEHV2Y7jBQ
iOS 19 Delays, iPhone 17 Full Redesign and iOS 18.2 RC Next
YouTube video by zollotech
youtu.be
November 27, 2024 at 11:37 AM
ZT & VPN aren’t mutually exclusive

Zero Trust isn’t just a buzzword—it’s a necessity. Zero Trust Network Access (ZTNA) can replace VPNs, reduce lateral movement, and harden existing devices, making them nearly impossible to exploit.
thehackernews.com/expert-insig...
Defensible Security Architecture and Engineering: Designing and Building Defenses for the Future
2024 Verizon DBIR shows 180% surge in vulnerability exploits. Learn Zero Trust principles to counter modern threats.
thehackernews.com
November 27, 2024 at 10:13 AM
By 2026 EU member state is obliged to offer an EU digital identity wallet (EUDIW) tink.com/blog/open-ba...
EUDIW is set to be built on the foundation of eUICC-supported-SAM.
#SecureApplicationForMobile
From authentication to authorisation: Navigating the changes with eIDAS 2.0
Discover how the eIDAS 2.0 regulation is set to transform digital identity and payment processes across the EU, promising seamless authentication, and enhanced security.
tink.com
November 26, 2024 at 8:27 PM
The eUICC-Supported-SAM initiative aims to transform our smartphones into our very own identities, complementing our physical Smartcards. This innovative approach promises to create a safer and more secure internet experience for all users.

youtu.be/gyiMbag0d1Y?...
Secure Application for Mobile (SAM) for mobile operators
YouTube video by GlobalPlatform TV
youtu.be
November 26, 2024 at 8:23 PM
Reposted by Yves K. D.

After Microsoft, now Cloudflare discloses an incident where it lost customer logs... for Microsoft this was weeks of logs... for Cloudflare only 3.5 hours

blog.cloudflare.com/cloudflare-i...
Cloudflare incident on November 14, 2024, resulting in lost logs
On November 14, 2024, Cloudflare experienced a Cloudflare Logs outage, impacting the majority of customers using these products. During the ~3.5 hours that these services were impacted, about 55% of t...
blog.cloudflare.com
November 26, 2024 at 6:21 PM
Reposted by Yves K. D.
iOS 19 is rumored to introduce a ChatGPT-like Siri, designed to handle more complex requests. Other features, apart from the new Siri, are reportedly delayed until iOS 19.4, set to launch in Spring 2026.

According to Mark Gurman
November 25, 2024 at 2:09 PM
Reposted by Yves K. D.
Microsoft has deployed a fix to restore email and calendar services to thousands of users who reported outages early Monday, reaching about 98% of customers—but when exactly the programs will completely come back online is still unclear.
Microsoft Outage: Outlook And Teams Restoration Time Unclear As Company Deploys Fix
Microsoft said it’s working to fix a Monday morning email and calendar outage but has not said exactly when service will be restored.
www.forbes.com
November 25, 2024 at 7:43 PM
Reposted by Yves K. D.
Here are my top 3 favorite iPhone gestures! The two-finger select is always a great party trick:
November 19, 2024 at 7:25 PM
Reposted by Yves K. D.
📺 Siri can control way more than just your garage! Inspired after hearing @joannastern.bsky.social and @gruber.foo discuss smart home, here's how I control over 100 HomeKit devices with Siri, including water hoses, ceiling fans, shades, lights, and yes, even the garage: youtu.be/wyFCipx4-14
How Siri Controls My 100% Apple Smart Home
YouTube video by Stephen Robles
youtu.be
November 20, 2024 at 2:25 PM
Reposted by Yves K. D.
cool to see other people had the same idea. i hope we see lots of competing takes on this
November 25, 2024 at 6:34 PM
Reposted by Yves K. D.
Benedict Evans writes an annual presentation on the big technology trends for the next year which is always insightful. The theme for 2025 is “AI eats the world”.
Presentations — Benedict Evans
Every year, I produce a big presentation exploring macro and strategic trends in the tech industry. For 2024, ‘AI, and everything else’.
www.ben-evans.com
November 24, 2024 at 8:11 PM
Really interesting paper about the future of smartcard and mobile based secure identify
#SAM #eUICC #eSIM #Smartcard #identity #Security
trustedconnectivityalliance.org/wp-content/u...
trustedconnectivityalliance.org
November 24, 2024 at 8:58 AM
Reposted by Yves K. D.
i’m starting to think labellers might be more powerful than blocklists. When you hit the “report” button, it gives you a workflow to report to any labeller. in fact, bluesky’s moderation service *is* a labeller

here’s a labeller for US politics
bsky.app/profile/uspo...
bsky.app
November 23, 2024 at 9:52 PM
Smartcards are widely used for physical access to secure facilities and notably in finance. They have evolved from magnetic bands to secure element chips that store critical security information like asymmetric cryptographic private keys.
November 23, 2024 at 7:14 PM
Reposted by Yves K. D.
Wondering how to use Bluesky feeds, blocklists, and filters? Are you worried that Bluesky will inevitably turn evil? Are you wondering what the Alf thing is about, but are too afraid to ask?

I try to answer your questions here:

little-flying-robots.ghost.io/the-great-bl...
The Great Bluesky Migration: I Answer (Some) Of Your Questions
For the last year and a half, us Bluesky users have frequently reminded one another that we are merely posters on a niche microblogging website. It's intended as a warning about hubris. A protective ...
little-flying-robots.ghost.io
November 21, 2024 at 8:06 PM
Reposted by Yves K. D.
NEW: Apple is racing to develop a more conversational version of its Siri digital assistant, aiming to catch up with OpenAI’s ChatGPT and other voice services. The company plans to introduce the revamped LLM Siri next year and launch it by spring 2026. www.bloomberg.com/news/article...
Apple Readies More Conversational Siri in Bid to Catch Up in AI
Apple Inc. is racing to develop a more conversational version of its Siri digital assistant, aiming to catch up with OpenAI’s ChatGPT and other voice services, according to people with knowledge of th...
www.bloomberg.com
November 21, 2024 at 9:07 PM