Posts Tagged ‘data security’

Latest Microsoft Patch Fixes TEN Zero Day Exploits

Wednesday, August 21st, 2024

“Patch Tuesday” is when Microsoft (and other software companies) regularly release patches for their software on the second Tuesday of a month. A “zero day exploit” is a serious, previously undisclosed security flaw in a shipping piece of software. Not every Patch Tuesday includes a zero day fix, and sometimes the release only fixes one or two.

The latest Microsoft Patch Tuesday fix, released last Tuesday, fixes ten zero day vulnerabilities, six of which were already being exploited in the wild.

Attackers are actively exploiting as many as six of the 90 vulnerabilities that Microsoft disclosed in its security update for August, making them a top priority for administrators this Patch Tuesday.

Another four CVEs in Microsoft’s update were publicly known before the Aug. 13 disclosure, which also make them zero-days of a sort, even though attackers have not yet begun exploiting them. Among them, an elevation of privilege (EoP) bug in Windows Update Stack, tracked as CVE-2024-38202, is particularly troubling because Microsoft does not yet have a patch for it.

The unpatched flaw allows an attacker with “basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security (VBS),” according to Microsoft. The company has assessed the bug as being only of moderate severity because an attacker would need to trick an administrator or user with delegated permissions into performing a system restore.

However, Scott Caveza, staff research engineer at Tenable, says that if an attacker were to chain CVE-2024-38202 with CVE-2024-21302 (an EoP flaw in the current update that affects Windows Secure Kernel), they would be able to roll back software updates without the need for any interaction with a privileged user. “CVE-2024-38202 does require ‘additional interaction by a privileged user,’ according to Microsoft,” he says. “However, the chaining of CVE-2024-21302 allows an attacker to downgrade or roll back software versions without the need for interaction from a victim with elevated privileges.”

Caveza says each vulnerability can be exploited separately, but when combined, they could potentially have a more significant impact.

In all, seven of the bugs that Microsoft disclosed this week are rated as critical. The company rated 79 CVEs — including the zero-days that attackers are actively exploiting — as “Important,” or of medium severity, because they involve some level of user interaction or other requirement for an attacker to exploit. “While this isn’t the biggest release, it is unusual to see so many bugs listed as public or under active attack in a single release,” said Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative (ZDI), in a blog post.

This is, to use a technical term, “bad.”

I’m not an expert in Windows security, but ten zero day exploits sounds like a new record.

And just who is exploiting this vulnerability in the wild? Well, in one case, North Korea.

A Windows zero-day vulnerability recently patched by Microsoft was exploited by hackers working on behalf of the North Korean government so they could install custom malware that’s exceptionally stealthy and advanced, researchers reported Monday.

Getting pwned by North Korea is like getting arrested for knocking over a liquor store because you posted a picture of yourself in front of the store holding up the stolen cash on Facebook.

The vulnerability, tracked as CVE-2024-38193, was one of six zero-days—meaning vulnerabilities known or actively exploited before the vendor has a patch—fixed in Microsoft’s monthly update release last Tuesday. Microsoft said the vulnerability—in a class known as a “use after free”—was located in AFD.sys, the binary file for what’s known as the ancillary function driver and the kernel entry point for the Winsock API. Microsoft warned that the zero-day could be exploited to give attackers system privileges, the maximum system rights available in Windows and a required status for executing untrusted code.

Microsoft warned at the time that the vulnerability was being actively exploited but provided no details about who was behind the attacks or what their ultimate objective was. On Monday, researchers with Gen—the security firm that discovered the attacks and reported them privately to Microsoft—said the threat actors were part of Lazarus, the name researchers use to track a hacking outfit backed by the North Korean government.

“The vulnerability allowed attackers to bypass normal security restrictions and access sensitive system areas that most users and administrators can’t reach,” Gen researchers reported. “This type of attack is both sophisticated and resourceful, potentially costing several hundred thousand dollars on the black market. This is concerning because it targets individuals in sensitive fields, such as those working in cryptocurrency engineering or aerospace to get access to their employer’s networks and steal cryptocurrencies to fund attackers’ operations.”

Monday’s blog post said that Lazarus was using the exploit to install FudModule, a sophisticated piece of malware discovered and analyzed in 2022 by researchers from two separate security firms: AhnLab and ESET. Named after the FudModule.dll file that once was present in its export table, FudModule is a type of malware known as a rootkit. It stood out for its ability to operate robustly in the deep in the innermost recess of Windows, a realm that wasn’t widely understood then or now. That capability allowed FudModule to disable monitoring by both internal and external security defenses.

Rootkits are pieces of malware that have the ability to hide their files, processes, and other inner workings from the operating system itself and, at the same time, control the deepest levels of the operating system. To work, rootkits must first gain system privileges and go on to directly interact with the kernel, the area of an operating system reserved for the most sensitive functions. The FudModule variants discovered by AhnLabs and ESET were installed using a technique called “bring your own vulnerable driver,” which involves installing a legitimate driver with known vulnerabilities to gain access to the kernel.

Earlier this year, researchers from security firm Avast spotted a newer FudModule variant that bypassed key Windows defenses such as Endpoint Detection and Response, and Protected Process Light. Microsoft took six months after Avast privately reported the vulnerability to fix it, a delay that allowed Lazarus to continue exploiting it.

Whereas Lazarus used “bring your own vulnerable driver” to install earlier versions of FudModule, group members installed the variant discovered by Avast by exploiting a bug in appid.sys, a driver enabling the Windows AppLocker service, which comes preinstalled in Windows. Avast researchers said at the time the Windows vulnerability exploited in those attacks represented a holy grail for hackers because it was baked directly into the OS rather than having to be installed from third-party sources.

As I’ve noted before, Internet security is hard. Neither Mac nor Linux are entirely free of such exploits, but they seem to be a lot less frequent. Log4J wasn’t a Linux kernel exploit, but everyone (rightly) freaked out over it because Log4j was used everywhere and it let attackers install malicious code on your server.

Microsoft patching ten zero day exploits suggests that there’s a big problem up in Redmond. You would think the zero day vulnerability numbers would be going down, not up. I wonder if we might be seeing that start of widespread AI use to find vulnerabilities in software.

NYTimes Hacked, Source Code Stolen

Sunday, June 9th, 2024

This seems like a story that should be getting a lot more coverage: The New York Times was evidently hacked and hundred of gigabytes of their source code released.

An anonymous hacker has claimed to have leaked 270 GB of internal data and source code from The New York Times (NYT) on the controversial image board 4chan.

The leak, reportedly containing over 5,000 repositories and 3.6 million files, was published on June 6, 2024. It has since raised widespread concern and speculation about the potential implications for the historic news organization.

The hacker, who has not been identified, posted a magnet link to the files on 4chan, encouraging users to download and share the data. According to the hacker, the leaked collection comprises uncompressed tar files with fewer than 30 encrypted repositories.

The leaked data reportedly contains a variety of source code, including the blueprints of well-known games like Wordle, email marketing campaigns, and ad reports. The hacker’s message was signed “With love from /aicg/,” a nod to a 4chan community.

While the leak’s legitimacy has not been independently verified, cybersecurity experts and media outlets have expressed serious concerns. The Register reported that it had seen a list of files in the purported leak but had not confirmed their authenticity.

Bryan Lunduke of The Lunduke Journal (who’s covered leaked/hacked material like this before) downloaded the files. He says they’re 334GB worth of files (maybe the size discrepancy is zipped vs unzipped) and thinks they’re real.

  • This dropped June 6.
  • “We are talking about a 334 gigabyte archive containing supposedly 3.6 million and some change files, individual source code files. Massive. Off-the-charts massive.”
  • He though it might just be every New York Times story ever published, but it doesn’t appear to be. Nor does it look like an email server dump.
  • “This is massive. It almost is making my brain hurt simply going through all of this.”
  • “I went through it. I read a bunch of it in depth. When I say a bunch of it, I mean I spent a long time on it and barely made a dent.”
  • “It truly does look to be over 3 something million source code files.”
  • “The first things I looked through were tremendously boring. It was just stupid JavaScript files dealing with Markdown.” JavaScript is a front-end programming language used for performing a huge variety of tasks in your browser. Markdown is an HTML-like text markup language used as a basis for rendering documents in a variety of different formats (standard web page, phone webpage, PDF, online help, etc.).
  • A lot of it appears to be internal website documents.
  • “It’s from a wide variety of stuff. I mean it’s all over the map. We’re talking onboarding documents and technical documents, hiring documents, switchboard documents, user attribute documents, a huge amount of documentation.”
  • Plus actual source code for iOS and Android applications.
  • Lunduke explains legal doctrine on leaked materials and reporting, saying he didn’t commit any crime to obtain the material, which should legally put him in the clear for talking about material therein relevant to the public interest. Normally I’d point out “Hacking is wrong, mkay,” but New York Times has itself published hacked/leaked/stolen material itself at least as far back as The Pentagon Papers, so this is a case of biter bit.
  • “There a reasonable assumption that publishing some of this leaked material would be of the public interest…There are a number of policies and other interesting things in place documented within this material that could be of the public interest.”
  • “This does appear to be real. I cannot fathom how all of this could have been created if it wasn’t real.” I am inclined to agree. But! It’s important to note that a real archive can be salted with false information for a variety of nefarious purposes, so caveat lector.
  • “It is an absolutely monstrous amount. Simply searching through it and scanning it is insane. There are over 5,000 individual mini-archives within this link each one appears to represent an individual source code repository, or at least a folder or subfolder within source code repositories.” He says it appears to be just the latest snapshot, and not all the versions you would find in a source code repository like GitHub.

  • The time stamps on the files look recent.
  • “Man, there’s some funky things going on here.”
  • I am most interested in how internal policies codify/enforce woke social justice priorities, if there are any special instructions for covering Donald Trump (or other Republicans), racial preferences in hiring policies, etc.

    I’m hoping for some juicy revelations…

    Paxton Takes On Big Data

    Wednesday, June 5th, 2024

    Texas Attorney general Ken Paxton is launching a new initiative to protect data privacy.

    Attorney General Ken Paxton announced today the launch of a new major initiative to protect citizens’ sensitive data from unauthorized exploitation by tech companies and artificial intelligence.

    The initiative was launched under the umbrella of the Attorney General Office Consumer Protection Division and established a team for “aggressive enforcement” of state privacy laws. It will also “ensure companies respect Texans’ privacy rights and safeguard their personal data.”

    According to a press release from Paxton’s office, the data protection team is set to be one of the largest privacy law enforcement teams in the entire United States.

    “Any entity abusing or exploiting Texans’ sensitive data will be met with the full force of the law,” said Paxton. “Companies that collect and sell data in an unauthorized manner, harm consumers financially, or use artificial intelligence irresponsibly present risks to our citizens that we take very seriously.

    “As many companies seek more and more ways to exploit data they collect about consumers, I am doubling down to protect privacy rights,” he continued. “With companies able to collect, aggregate, and use sensitive data on an unprecedented scale, we are strengthening our enforcement of privacy laws to protect our citizens.”

    Specifically, the new team will focus on enforcing the Data Privacy and Security Act, the Identify Theft Enforcement and Protection Act, the Data Broker Law, the Biometric Identifier Act, the Deceptive Trade Practices Act, and federal laws such as the Children’s Online Privacy Protection Act and the Health Insurance Portability and Accountability Act.

    “Texas has been a national leader in advancing conservative technology policy, and this initiative is the perfect complement to legislative wins in recent sessions as it will ensure Texas has the expertise and firepower to enforce laws that protect consumers and hold Big Tech accountable,” said David Dunmoyer—the Texas Public Policy Foundation Better Tech for Tomorrow campaign director.

    “Big Tech companies have gleefully flouted laws like the Children’s Online Privacy Protection Act for years, and in the absence of meaningful federal action, this initiative demonstrates Texas’ willingness to once again step into the breach and fight on behalf of Texans,” he continued. “This initiative will only further cement Texas’ national leadership in this space.”

    This is the latest development in Texas’ efforts to crack down on data privacy infringement. In mid-summer of last year, Gov. Greg Abbott signed the Texas Data Privacy & Security Act into law.

    The law applies to primarily businesses and entities who conduct business in the state of Texas or produce a product consumed by Texans, process or engage with the sale of personal data, and who are not considered “small businesses” unless the business has its hand in transactions of personal data.

    That enforcement effort sounds both needed and deserved, but the question is how you enforce those laws when they cows have not only left the barn, but have been sucked down and sliced up into thousands of vast international data farms far beyond the regulatory reach of the state of Texas.

    Big data lives and breathes on personal data that you’ve agreed to give up in variegated clauses scattered throughout the sprawling text swamps of terms and conditions for online sites you use for free.

    Have a Facebook account? Congratulations! Every bit of information you’ve shared with Facebook (your friends network, your interests, the sports teams you follow, the foods you favor, etc.) is now available to every partner of Facebook. And everyone partners with Facebook. If they have your email address or your phone number, they have your data.

    Ditto Google, with the additional proviso that Google has sucked up and cataloged pretty much every public database in the world, plus every single search query you’ve launched, ever, and every web page you’ve ever viewed through Chrome.

    Ditto Microsoft, for LinkedIn (yes, Microsoft bought LinkedIn), Windows, Explorer, Edge, Bing, etc.

    Ditto Twitter for everything you’ve ever tweeted or liked there.

    Ditto Sony, whose PlayStation Network data got hacked.

    Ditto Apple, though they seem to have better privacy protection provisions than most, mainly because they make their money off hardware. This doesn’t make them the good guys, just the least bad buys.

    Even Samsung sucks down data to target ads at you.

    And don’t forget state, location and federal government entities, whose data security is probably several orders of magnitude worse than the tech giants.

    Given that there’s so much personal data out there, so much legally acquired, how do you go about putting the genie back in the bottle? It’s a near impossible task, given that the tech giants not only hire armies of lawyers to defend themselves from lawsuits, but also lobbyists to write laws protecting them from said lawsuits.

    One place to start: Joining in a lawsuit where Facebook’s parent company Meta actually used stolen data to train AI, namely using a giant database of pirated books without paying authors. Paxton’s office could join one of the lawsuits against Meta, or file a new one on behalf of Texas authors whose work was used without compensation.

    Catching a tech giant with their pants down while actually breaking the law may give Paxton leverage to address other privacy concerns, and possibly the chance to do some eye-opening discovery…

    LinkSwarm For February 9, 2024

    Friday, February 9th, 2024

    The Senate’s bad border deal goes down badly, Big Brother is (still) watching you, Netanyahu tells everyone calling for a Gaza ceasefire to stick it in their murder tunnels, more Democrats arrested for (or convicted of) fraud, and a tiny bit of Disney news. It’s the Friday LinkSwarm!

  • Republicans took one look at the abomination of a “bipartisan” border deal and declared it dead on arrival.

    In a key vote on Wednesday, Senate Republicans moved to block the long-anticipated bipartisan border deal, which ties border-security provisions to aid for both Israel and Ukraine.

    The bill was blocked in a 49 to 50 procedural vote, with only four Republicans joining Democrats in backing the legislation. The bill needed 60 votes to advance.

    This setback comes after months of negotiations between Senate Republicans and Democrats on a measure President Joe Biden strongly requested. While the GOP wants more resources allocated toward the southern border, House Republicans and former president Donald Trump have made it clear they don’t want the legislation tied to foreign aid.

    Hours after the bill’s details were revealed Sunday night, House GOP leaders rejected the package and declared it “DEAD on arrival in the House.”

    Trump, who has made the border crisis a central issue of his 2024 presidential campaign, also weighed in on the border deal earlier this week. “Don’t be STUPID!!! We need a separate Border and Immigration Bill. It should not be tied to foreign aid in any way, shape, or form!” Trump posted on Truth Social.

    Before the Senate voted on the matter, Biden blamed Trump for Republicans’ fierce opposition to the bill.

    “Now, all indications are this bill won’t even move forward to the Senate floor,” Biden said Tuesday. “Why? A simple reason: Donald Trump.”

    Hey Biden, I’m already going to vote for Trump. You don’t need to keep giving me new reasons.

    The $118 billion Senate proposal includes about $60 billion in Ukraine funding, $14 billion in Israel aid, and $20 billion in border-security improvements, among various other items listed in the legislative package.

    Senators James Lankford of Oklahoma, Lisa Murkowski of Alaska, Susan Collins of Maine, and Mitt Romney of Utah were the only Republicans to vote in favor of the bill on Wednesday.

    Lankford should be ashamed to be in such company.

  • Texas isn’t taking the Biden Administrations abrogation of the rule of law lying down. “Texas Attorney General’s Legal Challenge to Biden Administration’s ‘Asylum Rule’ Will Proceed. A federal judge ruled Texas raised a plausible claim that the federal government is violating the Appointments Clause of the U.S. Constitution.”

    The Texas Office of the Attorney General (OAG) announced a procedural victory in one of its many ongoing lawsuits against the federal government this week, after a federal district judge ruled against a motion by the Department of Homeland Security (DHS) to dismiss a legal challenge to its “asylum rule,” saying Texas had a plausible constitutional challenge.

    According to the OAG, the federal government violated the Appointments Clause in the U.S. Constitution when the DHS granted power to review asylum cases to immigration officers — a power uniquely held under federal statute by immigration judges.

    “This case offers a rare opportunity to litigate the application of the Appointments Clause of the Constitution, which states that Congress may only vest the power to appoint “inferior Officers… in the President alone, the Courts of Law, or the Heads of Departments,” the OAG wrote in a press statement regarding the case.

    The office explained that by using asylum officers to perform jobs Congress assigned to judges when said officers were not appointed in the same manner, DHS violated the Constitution.

    The OAG also argues that asylum officers are granting more noncitizens asylum than otherwise would be entitled to it. This is causing surges at the border and population increases that are in turn increasing the state’s costs relating to the increases, the state says.

    “It is tremendously important for Texas and for our Constitutional order that this case is allowed to move forward,” Attorney General Ken Paxton said regarding the case. “The Biden Administration must not be permitted to ignore Congress and violate the Constitution. We take every opportunity to hold Biden accountable for his unlawful overreach.”

  • Know who else isn’t wild about Biden’s open borders? Border Patrol agents.

    Rank-and-file Border Patrol agents have slammed the Senate’s $118B Senate funding bill that would guarantee 1.5 million illegal migrants entry to the United States, while sending the majority of funds to Ukraine ($60B+) and Israel ($14.1B).

    Snip.

    “Now that I’ve seen more of it, they can respectfully go fuck themselves. The more I’m seeing the more it just puts what they’ve been doing in writing. You want to shut this down, it’s real easy. Team up [the Department of Defense] with DHS and let us enforce like we were supposed to,” one agent told the Caller, adding “I feel like we are the only nation in the world that is this dumb about the border. Maybe it’s because we haven’t.”

    Oh, and “Aliens from noncontiguous countries shall not be included in the sum of aliens encountered.” Did America’s enemies write this thing?

  • Ted Cruz had his own border security bill that wasn’t considered.

    Cruz went on to say he knew [the Biden border bill] “had zero chance of passage” and that the entire purpose of the bill was to give “political camouflage to Democrats running in November.”

    “Joe Biden can secure the border any day he wants,” Cruz said. “He doesn’t want to.”

    The Secure the Border Act, which passed in the lower chamber as as House Resolution (H.R.) 2, was introduced to the Senate by Cruz in September of 2023, a fact he highlighted Wednesday, saying to “give me Ukraine aid and H.R. 2 and I’ll vote for that.”

    H.R. 2 would have continued construction of the border wall, reinstated the “remain in Mexico” policy, and added border patrol agents and technology for both the southern and northern borders.

    “Democrats do not want to secure the border; they want this invasion,” Cruz continued. “The Americans who are dying as a result, they’re [Democrats] willing to look the other way.”

  • “Matt Taibbi Warns ‘Financial Big Brother Is Watching You.'”

    A few weeks ago, Ohio congressman and Judiciary Committee chairman Jim Jordan’s office released a letter to Noah Bishoff, the former director of the Financial Crimes Enforcement Network, or FinCEN, an arm of the Treasury Department. Jordan’s team was asking Bishoff for answers about why FinCEN had “distributed slides, prepared by a financial institution,” detailing how other private companies might use MCC transaction codes to “detect customers whose transactions may reflect ‘potential active shooters.’”

    The slide suggested the “financial company” was sorting for terms like “Trump” and “MAGA,” and watching for purchases of small arms and sporting goods, or purchases in places like pawn shops or Cabela’s, to identify financial threats.

    Jordan’s letter to Bishoff went on:

    According to this analysis, FinCEN warned financial institutions of “extremism” indicators that include “transportation charges, such as bus tickets, rental cars, or plane tickets, for travel to areas with no apparent purpose,” or “the purchase of books (including religious texts) and subscriptions to other media containing extremist views.”

    During the Twitter Files, we searched for snapshots of the company’s denylist algorithms, i.e. whatever rules the platform was using to deamplify or remove users. We knew they had them, because they were alluded to often in documents (a report on the denylist is_Russian, which included Jill Stein and Julian Assange, was one example).

    However, we never found anything like the snapshot Jordan’s team just published:

    The highlighted portion shows how algorithmic analysis works in financial surveillance.

    First compile a list of naughty behaviors, in the form of MCC codes for guns, sporting goods, and pawn shops.

    Then, create rules: $2,500 worth of transactions in the forbidden codes, or a number showing that more than 50% of the customer’s transactions are the wrong kind, might trigger a response.

    The Committee wasn’t able to specify what the responses were in this instance, but from previous experience covering anti-money-laundering (AML) techniques at banks like HSBC, a good guess would be generation of something like Suspcious Activity Reports, which can lead to a customer being debanked.

    If Facebook, Twitter, and Google have already shown a tendency toward wide-scale monitoring of speech and the use of subtle levers to apply pressure on attitudes, financial companies can use records of transactions to penetrate individual behaviors far more deeply. Especially if enhanced by AI, a financial history can give almost any institution an immediate, unpleasantly accurate outline of anyone’s life, habits, and secrets. Worse, they can couple that picture with a powerful disciplinary lever, in the form of the threat of closed accounts or reduced access to payment services or credit. Jordan’s slide is a picture of the birth of the political credit score.

    Tiabbi says worse revelations are to come…

  • “Netanyahu Rejects Hamas Cease-Fire Demands, Vows to Fight until ‘Absolute Victory.'”

    Israeli prime minister Benjamin Netanyahu rejected Hamas cease-fire demands on Wednesday, vowing to fight on until “absolute victory.”

    Netanyahu made the comments shortly after meeting with Secretary of State Antony Blinken, who arrived in the region Tuesday night after meeting with leaders of Qatar and Egypt in the most serious diplomatic push of the war to secure a cease-fire agreement. Through these diplomatic channels, Hamas presented Israel with a proposal for a three-stage cease-fire that would last for 135 days and culminate in the end of the war.

    “Surrendering to Hamas’s delusional demands that we heard now not only won’t lead to freeing the captives, it will just invite another massacre.”

    Indeed.

  • The Special Counsel’s report on Biden’s mishandling paints a picture of Biden’s mental decline we all know is true but which the media refuses to report.

    President Biden couldn’t even remember when he was vice president or when his son Beau had died, leading special counsel Robert Hur to conclude that he could not bring charges for mishandling of classified documents, because a jury would see the president “as a sympathetic, well-meaning, elderly man with a poor memory.”

    In a report, Robert Hur concluded that Biden “willfully retained and disclosed classified materials after his vice presidency when he was a private citizen.” But he declined to issue any charges, in part because Biden’s poor recollection would make him hard to convict.

  • If you want to see Fani Willis taken down only the way Ace of Spades can, then I direct your attention to “CashApp Cougar Fani Willis: Okay, Fine, So I Used Taxpayer Money to Hire a Human Meat-Mallet to Pound My Snizz Into Thin Tender Strips Like Veal Scallopini.” (Hat tip: Reader Tig if Brue.)
  • No less than 70 current and former employees of the New York City Housing Authority just caught federal charges for over $2 million in bribes. We call that “A good start.”
  • “ICE Operation Nabs a Dozen Illegal Aliens Convicted of Crimes Against Children.”
  • Radical, Soros-backed leftist Travis County DA has a primary opponent in Jeremy Sylestine.
  • “Former Houston Mayor Turner’s Senior Aide Sentenced Over Bribes Related to City Permits.”
  • Democratic Senator Chris Murphy of Connecticut admits that his favorite Americans aren’t Americans.
  • Open borders in the UK means giant lines for NHS dentists.
  • In order to push green graft, the Biden Administration has designated Martha’s Vineyard as “low income” so they can get EV subsidies.
  • The Austin City Council will vote on creating a giant slush fund for left-wing activists. Of course they’re calling it an “Environmental Investment Plan”…
  • Kentucky tranny gets no jail time for molesting a baby.
  • Pakistan had an election and both sides claim they won.
  • Is China exporting deflation to the world?
  • In China, 30 million WeChat accounts are shut down in a single day.
  • Did a “SIM swapping crew” steal $400 million from FTX the same day it declared bankruptcy? That timing seems…suspicious.
  • Members of the Austin American-Statesman took one look at the vast wave of layoffs hitting newsrooms across the country and decided “Now is the perfect time to go on strike!” (Note: Elon Musk should buy the name, fire everyone, and build a national quality newspaper from scratch.)
  • YouTube threatens Louis Rossmann and FUTO for violating the terms of service for the APIs they’re not using.
  • Microsoft Edge is stealing Chrome tabs.
  • Dell demands all workers (no matter how far away) return to the office. Those who don’t will be “placed on a ‘career limiting’ fully remote contract. In my experience, working for Dell is itself career limiting
  • Man shoots home invader…with a musket.

  • Disney is evidently moving all hand animation to other countries. “I feel like this is punishment for the Burbank studio for delivering a terrible movie [Wish].” More.
  • Disney makes $1.5 billion investment in Fortnite creator Epic Games. Fremium games are a very tricky space, and Fortnite has been around since 2017. There’s a strong possibility that Disney has bought high here.
  • Mojo Nixon, RIP.
  • Budget drag race community comes together to help fan with terminal brain tumor who’s also the happiest guy they know. “Don’t feel bad for me. Everyone’s terminal.”
  • Former Houston Texas receiver Andre Johnson finally assumes his rightful place in the NFL Hall of Fame.
  • Who do you think treats dogs better: Palestinians or Israelis?

    (Hat tip: Ace of Spades HQ.)

  • Hit the tip jar if you’re so inclined.





    Russo-Ukranian War Update for June 22, 2022

    Wednesday, June 22nd, 2022

    The general course of the Russio-Ukrainian War seems the same (Russia grinding out slow gains in the Severodonetsk front, while Ukraine gains back territory on the wings near Kharkiv and Kherson), but there are a lot of interesting stories out on the periphery of the conflict.

    First, the requisite map snap:

    (These snapshots are not the end-all and be-all of the situation, but back when I was covering the war against the Islamic State, I found that they were helpful in jogging my memory reviewing the course of the war at later dates.)

    Now some links:

  • ISW’s assessment.

    Members of the Russian military community continue to comment on the shortcomings of Russian force generation capabilities, which are having tangible impacts on the morale and discipline of Russians fighting in Ukraine. Russian milblogger Yuri Kotyenok claimed that Russian troops lack the numbers and strength for success in combat in Ukraine. Kotyenok accused Russian leadership of deploying new and under-trained recruits and called for replenishment of forces with well-trained recruits with ground infantry experience—though the Russian military is unlikely to be able to quickly generate such a force, as ISW has previously assessed. Despite growing calls for increased recruitment from nationalist figures, Russian leadership continues to carry out coercive partial mobilization efforts that are only producing limited numbers of replacements while negatively impacting the morale and discipline of forcibly mobilized personnel. Ukraine’s Security Service (SBU) claimed that Russian authorities in Luhansk are arranging gas leaks in apartment buildings to force men who are hiding from mobilization into the streets. The Ukrainian Main Intelligence Directorate (GUR) additionally reported that Russian soldiers in occupied Tokmak, Zaporizhia Oblast, are appealing to local Ukrainian doctors to issue them certificates alleging medical inability to continue military service.

    Ukrainian forces conducted a drone strike (likely with a loitering munition, though this cannot be confirmed) on a Russian oil refinery in Novoshakhtinsk, Rostov Oblast, on June 22. Russian Telegram channel Voenyi Osvedomitel claimed that the strike, which targeted Russian infrastructure within 15 km of the Ukrainian border, originated from Donetsk Oblast. Ukrainian forces have not targeted Russian infrastructure for several weeks, and this strike is likely an attempt to disrupt Russian logistics and fuel supply to Russian operations in eastern Ukraine.

    Though they also note that Russia has been using its anti-air capabilities to better deal with Ukrainian drones.

  • Ukraine attacked long-occupied gas platforms off the coast of Crimea. It also reportedly hit occupied Snake Island, though there seems to be some dispute over this.
  • Did a Russian cyberattack trigger the Freeport LNG explosion on June 8?

    Well, a June 14 press release from Freeport LNG notes that “the incident occurred in pipe racks that support the transfer of LNG from the facility’s LNG storage tank area to the terminal’s dock facilities. … Preliminary observations suggest that the incident resulted from the overpressure and rupture of a segment of an LNG transfer line, leading to the rapid flashing of LNG and the release and ignition of the natural gas vapor cloud. Additional investigation is underway to determine the underlying precipitating events that enabled the overpressure conditions in the LNG piping.” The statement added that federal authorities were assisting with its investigation.

    However, what was not explained is how a critical overpressure event could have occurred without safety systems kicking into action. Two LNG pipeline experts I talked to, who both asked to remain anonymous due to potential retaliatory damage to their business interests, say that pipeline corrosion and other material failures can cause critical incidents. Still, the FBI’s investigative involvement, the specific nature of this explosion, and the scale of damage incurred do raise major questions. The experts suggested that piping from a storage tank to a terminal, as in this explosion, should have extensive safeguards to prevent overpressure events. One expert was highly confident that control of pipeline flows would be undertaken from a networked control facility.

    That brings us to the Russian cyber unit involved in the targeting reconnaissance against Freeport LNG.

    Named XENOTIME by researchers, the unit has utilized boutique TRITON/TRISIS malware developed by the Russian Ministry of Defense’s Central Scientific Research Institute of Chemistry and Mechanics. That malware is designed for the seizure of industrial control systems and the defeat of associated safety systems. In 2017, GCHQ (Britain’s NSA-equivalent signals intelligence service) outlined the need for network compartmentalization to protect safety systems against this malware better. In March 2022, the FBI warned that TRISIS malware remained a threat.

    XENOTIME is assessed by the U.S. and British governments as a critical infrastructure-focused, advanced persistent threat actor. The unit’s modus operandi involves targeting industrial control systems and supervisory control systems in order to effect unilateral control of a network. XENOTIME has caused specific concern in Western security circles for its targeting of safety systems that would otherwise mitigate threats to life during a cyberattack. XENOTIME’s activity has escalated in 2022. Evincing as much, an April 13 U.S. government cybersecurity warning noted, “By compromising and maintaining full system access to [industrial control system]/[safety] devices, [threat] actors could elevate privileges … and disrupt critical devices or functions.”

    Snip.

    While the Freeport LNG explosion remains under investigation, multiple sources told me they were struck by the overpressure event along a key pipeline transit route and the evident failure of safety systems to engage. This fits with XENOTIME’s modus operandi.

    That’s an “interesting but unproven” in my book… (Hat tip: Jim Geraghty at NRO.)

  • Switzerland Imports Russian Gold for First Time Since War.”

    More than 3 tons of gold was shipped to Switzerland from Russia in May, according to data from the Swiss Federal Customs Administration. That’s the first shipment between the countries since February.

    The shipments represent about 2% of gold imports into the key refining hub last month. It may also mark a change in perception of Russian bullion, which became taboo following the invasion. Most refiners swore off accepting new gold from Russia after the London Bullion Market Association removed the country’s own fabricators from its accredited list.

    While that was viewed as a de facto ban on fresh Russian gold from the London market, one of the world’s biggest, the rules don’t prohibit Russian metal from being processed by other refiners. Switzerland is home to four major gold refineries, which together handle two-thirds of the world’s gold.

    Almost all of the gold was registered by customs as being for refining or other processing, indicating one of the country’s refineries took it. The four largest — MKS PAMP SA, Metalor Technologies SA, Argor-Heraeus SA and Valcambi SA — said they did not take the metal.

    In March, at least two major gold refineries refused to remelt Russian bars even though market rules permit them to do so. Others, such Argor-Heraeus, said they would accept products refined in Russia prior to 2022, so long as there were documents proving that the gold had not been exported from Russia after beginning of the war, and that accepting them would not benefit Russia, a Russian person or entity anywhere in the world.

  • Though this piece is two weeks old, Frederick Kagan is not impressed with Russia’s Severodonetsk offensive.

    he fight for Severodonetsk is a Russian information operation in the form of a battle. One of its main purposes for Moscow is to create the impression that Russia has regained its strength and will now overwhelm Ukraine. That impression is false. The Russian military in Ukraine is increasingly a spent force that cannot achieve a decisive victory if Ukrainians hold on.

    Russian President Vladimir Putin is therefore trying to turn his invasion of Ukraine into a brutal contest of wills. He’s betting his army on breaking Ukrainians’ collective will to fight on in their country. His own won’t likely break. Fortunately, Ukraine doesn’t need it to. If Ukrainians can weather the current Russian storm and then counterattack the exhausted Russian forces they still have every chance to free their people and all their land.

    Putin amassed the wreckage of Russian combat forces into a lethal amalgam around the cities of Severodonetsk and Lysychansk in Ukraine’s eastern Luhansk Oblast. That amalgam is crawling forward using massive artillery barrages to obliterate everything in its path allowing Russia’s demoralized and frightened soldiers to walk into the rubble.

    The Ukrainian defenders are wisely withdrawing in the face of this reckless barbarism, but at a high price to their own morale and their will to continue the fight. Ukrainian soldiers and citizens are criticizing their government for not supporting the troops on the front lines. Ukrainians are starting to doubt that they can prevail for the first time since they won the Battle of Kyiv. Delays in the provision of Western aid and refusals by the U.S. and other countries to provide certain needed weapons systems are helping to fuel those doubts. And now voices are rising in the West calling on Ukraine to offer concessions.

    All of which is exactly what Putin needs. He cannot defeat Ukraine militarily as long as Ukrainians retain the will to fight and the West the will to back them. So he attacks the will of both by forcing his own troops into the most vicious and brutal offensive of this war, hoping to persuade everyone that he’s finally harnessed the mass and power of Russia that Stalin wielded to defeat Hitler—and thus that resistance to his demands is futile. Putin also holds hostage critical export supplies of Ukrainian food and fuel, hoping to impose high enough costs on the West to persuade it to abandon Ukraine.

    Neither Ukrainians nor their friends around the world must give in to Putin or be deluded by the current mirage of Russian success and power he is presenting in the Battle of Severodonetsk. For mirage it is. Russia’s drive in Luhansk is the desperate gamble of a dictator staking the last of the offensive combat power he can scrape together in hopes of breaking his enemies’ will to continue the fight. and let him claim that he’s taken all of Luhansk Oblast. It is a historical rhyme with Hitler’s determination to seize Stalingrad in 1942 or to hold Kharkov in defiance of his commander’s advice. There are no Russian large reserves coming behind this force to carry its successes forward. On the contrary, Putin has created it only by denuding other key axes of the forces they need to defend against Ukrainian counterattacks. This offensive will likely culminate soon because even this slow, grinding advance will exhaust the forces conducting it. Putin will then be unable to launch another for quite some time.

  • I thought this would be a longer update, but I’m running out of day…

    Russo-Ukrainian War Update for March 8, 2022

    Tuesday, March 8th, 2022

    At this point, there seems to be no indication that Russian forces are measurably closer to their goal of controlling all of Ukraine.

    Here’s a LiveMap snapshot.

    From a pure strategic viewpoint, those Russian tendrils snaking toward Kiev from the northeast look like a bad idea, since there’s no way to protect their supply lines.

    (Always remember that the map is not the territory, and that both sides are working hard to put out propaganda, though the Russians seem to be manifestly incompetent at it.)

  • Here’s a fascinating thread reportedly leaked from an active Russian FSB (successor to the KGB) analyst about how badly everything is screwed up.

    I assume that’s Ramzan Kadyrov, corrupt head of the Chechen Republic, former resistance fighter against Russia who defected in 1999 and was appointed by Putin in 2007. Bit of a jihadist scumbag to boot, and just a generally nasty piece of work. I assume by “Kadyrov’s squad” they mean the Kadyrovtsy, the militia forces under his direct control.

    Some tweets about who could they even get post-Zelensky to sign a treaty (Medvechuk? Tsaryova? Yanukovich?) snipped.

    I don’t agree with every conclusion (I doubt the war will produce worldwide famine), but it’s still worth reading the whole thread.

  • Cheap Chinese tires blamed for Russian convoy unable to reach Kyiv.”

    Cheap Chinese tires have been blamed for a Russian convoy of armoured vehicles being unable to reach Kyiv.

    Yesterday, the Ministry of Defence issued an update revealing that a convoy of Russian tanks advancing on the capital of Ukraine remained 30km from the centre of the city having made little progress over the previous three days because of “Ukranian resistance, mechanical breakdown and congestion.”

    Karl Muth, an academic based at the University of Chicago and a self-described tire expert, took to Twitter to set out a theory blaming cheap Chinese tires for the slow advance of Russian vehicles.

    “Those aren’t Soviet-era heavy truck radials,” Muth said, commenting on a photo of a Russian army vehicle with ripped tires.

    Instead Muth believes the trucks use “Chinese military tires, and I believe specifically the Yellow Sea YS20.”

    “This is a tire I first encountered in Somalia and Sudan. it’s a bad Chinese copy of the excellent Michelin XZL military tire design,” he continued.

    Former pentagon staff member Trent Telenko also got stuck into the debate and said “poor Russian army truck maintenance practices” has created a risk of equipment failure.

    “When you leave military truck tires in one place for months on end. The side walls get rotted/brittle such that using low tire pressure setting for any appreciable distance will cause the tires to fail catastrophically via rips,” Telenko said.

  • Morgan Stanley analyst says that Russia is heading toward debt default as soon as April 15. Those are dollar-denominated bonds, which means they can’t be paid with devalued rubles.
  • Hundreds Of Thousands Of Global Hackers Are Banding Together To Disrupt Russian Military, Banking And Communication Networks.

    There are reportedly more than 400,000 “volunteer hackers” helping Ukraine fight its cyberwar against Russia.

    Victor Zhora, deputy chief of Ukraine’s information protection service, told Bloomberg last week that Ukraine was putting up a “cyber resistance” against its invasion that would work to try and weaken Russia.

    Zhora said: “Our friends, Ukrainians all over globe, [are] united to defend our country in cyberspace. [Ukraine is working to do] everything possible to protect our land in cyberspace, our networks, and to make the aggressor feel uncomfortable with their actions.”

    He also said that volunteers were helping Ukraine obtain intelligence in order to fight back at Russian military systems.

    They are also trying to get the message out to Russian citizens, who have been Fed a starkly different narrative from their government than the rest of the world has seen play out. Volunteers are working to “address Russian people directly by phone calls, by emails, by messages” and “by putting texts on their services and showing real pictures of war.”

    There aren’t 400,000 real hackers around the world. But 10,000 hackers and 390,000 script kiddies can sill do a lot of damage…

  • What breaks first?

    The Russian invasion of Ukraine will end when one or more of four things breaks:

    • the Russian supply lines;
    • the Ukrainian ability to effectively resist;
    • the Russian economy;
    • the patience of some armed individuals around Putin.

    We’re already seeing a lot of the first and third…

  • Is the Russian air force incapable of complex operations?

    More than a week into the Russian invasion of Ukraine, the Russian Air Force has yet to commence large-scale operations. Inactivity in the first few days could be ascribed to various factors, but the continued absence of major air operations now raises serious capability questions.

    One of the greatest surprises from the initial phase of the Russian invasion of Ukraine has been the inability of the Russian Aerospace Forces (VKS) fighter and fighter-bomber fleets to establish air superiority, or to deploy significant combat power in support of the under-performing Russian ground forces. On the first day of the invasion, an anticipated series of large-scale Russian air operations in the aftermath of initial cruise- and ballistic-missile strikes did not materialise. An initial analysis of the possible reasons for this identified potential Russian difficulties with deconfliction between ground-based surface-to-air missile (SAM) batteries, a lack of precision-guided munitions and limited numbers of pilots with the requisite expertise to conduct precise strikes in support of initial ground operations due to low average VKS flying hours. These factors all remain relevant, but are no longer sufficient in themselves to explain the anaemic VKS activity as the ground invasion continues into its second week. Russian fast jets have conducted only limited sorties in Ukrainian airspace, in singles or pairs, always at low altitudes and mostly at night to minimise losses from Ukrainian man-portable air defence systems (MANPADS) and ground fire.

    Snip.

    While the early VKS failure to establish air superiority could be explained by lack of early warning, coordination capacity and sufficient planning time, the continued pattern of activity suggests a more significant conclusion: that the VKS lacks the institutional capacity to plan, brief and fly complex air operations at scale. There is significant circumstantial evidence to support this, admittedly tentative, explanation.

    First, while the VKS has gained significant combat experience in complex air environments over Syria since 2015, it has only operated aircraft in small formations during those operations. Single aircraft, pairs or occasionally four-ships have been the norm. When different types of aircraft have been seen operating together, they have generally only comprised two pairs at most. Aside from prestige events such as Victory Day parade flypasts, the VKS also conducts the vast majority of its training flights in singles or pairs. This means that its operational commanders have very little practical experience of how to plan, brief and coordinate complex air operations involving tens or hundreds of assets in a high-threat air environment. This is a factor that many Western airpower specialists and practitioners often overlook due to the ubiquity of complex air operations – run through combined air operations centres – to Western military operations over Iraq, the Balkans, Libya, Afghanistan and Syria over the past 20 years.

    Second, most VKS pilots get around 100 hours’ (and in many cases less) flying time per year – around half of that flown by most NATO air forces. They also lack comparable modern simulator facilities to train and practise advanced tactics in complex environments. The live flying hours which Russian fighter pilots do get are also significantly less valuable in preparing pilots for complex air operations than those flown by NATO forces. In Western air forces such as the RAF and US Air Force, pilots are rigorously trained to fly complex sorties in appalling weather, at low level and against live and simulated ground and aerial threats. To pass advanced fast jet training they must be able to reliably do this and still hit targets within five to ten seconds of the planned time-on-target. This is a vital skill for frontline missions to allow multiple elements of a complex strike package to sequence their manoeuvres and attacks safely and effectively, even when under fire and in poor visibility. It also takes a long time to train for and regular live flying and simulator time to stay current at. By contrast, most VKS frontline training sorties involve comparatively sterile environments, and simple tasks such as navigation flights, unguided weapon deliveries at open ranges, and target simulation flying in cooperation with the ground-based air-defence system. Russia lacks access to a training and exercise architecture to rival that available to NATO air forces, which routinely train together at well-instrumented ranges in the Mediterranean, North Sea, Canada and the US. Russia also has no equivalent to the large-scale complex air exercises with realistic threat simulation which NATO members hold annually – the most famous of which is Red Flag. As such, it would be unsurprising if most Russian pilots lack the proficiency to operate effectively as part of large, mixed formations executing complex and dynamic missions under fire.

    Third, if the VKS were capable of conducting complex air operations, it should have been comparatively simple for them to have achieved air superiority over Ukraine. The small number of remaining Ukrainian fighters, conducting heroic air-defence efforts over their own cities, are forced to operate at low altitudes due to long-range Russian SAM systems and consequently have comparatively limited situational awareness and endurance. They ought to be relatively easily to overwhelm for the far more numerous, better armed and more advanced VKS fighters arranged around the Ukrainian borders. Ukrainian mobile medium- and short-range SAM systems such as SA-11 and SA-15 have had successes against Russian helicopters and fast jets. However, large Russian strike aircraft packages flying at medium or high altitude with escorting fighters would be able to rapidly find and strike any Ukrainian SAMs which unmasked their position by firing at them. They would lose aircraft in the process, but would be able to attrit the remaining SAMs and rapidly establish air superiority.

    Russia has every incentive to establish air superiority, and on paper should be more than capable of doing so if it commits to combat operations in large, mixed formations to suppress and hunt down Ukrainian fighters and SAM systems. Instead, the VKS continues to only operate in very small numbers and at low level to minimise the threat from the Ukrainian SAMs. Down low, their situational awareness and combat effectiveness is limited, and they are well within range of the MANPADS such as Igla and Stinger which Ukrainian forces already possess. The numbers of MANPADS are also increasing, as numerous Western countries send supplies to beleaguered Ukrainian forces. To avoid additional losses to MANPADS, sorties continue to be primarily flown at night, which further limits the effectiveness of their mostly unguided air-to-ground weapons.

    (Hat tip: Chuck Moss.)

  • How Russian propaganda has sold some of the Russian people on Project Z. But Russian troops are finding things quite a different story. Warning: Bodies, and at about 18 seconds in one, I think strewn body parts:

  • Report that Russian special forces are furious with Putin.

    “Sources have been telling me, sources that are well connected to the Russian Security Services, that the offensive is not going well, that some special forces, the Russian Spetsnaz, are furious because they have been sent into battle without proper support, and many of them have been killed. They say that the national guard forces and the regular army, the national guard forces include those Chechen units, that two of them are not coordinating on the field. And that the overall battle plan is somewhat disjointed in that it’s partly a plan for war and partly a plan for peacekeeping and so-called de-Nazification of this country. And it has led to a lack of cohesion,” Engel reported.

    “A lot of this goes back to the man who’s behind it all, Vladimir Putin, who I’m told is now increasingly isolated, is just taking advice from his inner circle, that there are only about three people who matter right now,” Engel continued. “And that speech, you mentioned it a short while ago, that Putin gave yesterday — bizarre location, speaking at Aeroflot, to a group of flight attendants. He sounded incredibly angry. He sounded detached. He was talking about how the Ukrainians here are machine-gunning people, that they’re driving around in cars packed with explosives, jihadi-style. And he went very deep and repeatedly on this theme that they’re fighting against the Nazis. It was the angriest I’ve ever seen him.”

    This is from a couple of days ago. Have Spetsnaz pissed off at you doesn’t seem like a good long-term survival strategy for a Russian leader. On the other hand, this report probably deserves some skepticism, since it fits too easily into what we would like to hear about the situation, so some salt is in order. (Hat tip: Director Blue.)

  • “Ukraine says it has RE-TAKEN Chuhuiv city and killed two high-ranking Russian commanders during the battle.” (Hat tip: Instapundit.)
  • After nearly two weeks of criticism, the Biden Administration just announced a ban on Russian oil and gas purchases.
  • “A Complete Summary Of All Russia Sanctions And Developments.” Read on for exciting blow-by-blow summaries of foreign exchange surcharges and debt repayment details…
  • Russia may nationalize foreign-owned factories.
  • Aeroflot stops flying to foreign destinations to keep most of their leased airliners from being repossessed.
  • What rolls down stairs/alone and in pairs/and up-armors your Russian truck? Caveat: They call this improvised armor, but it could also be on-hand materials for traction in muddy areas.
  • “Russia-Ukraine war to cripple semiconductor industry globally.” Ukraine supplies a lot of neon, which is used as a carrier gas in certain wavelength DUV lasers in photolithography. (Details here.)
  • Ukraine President Zelenskyy sounds like he may be ready to negotiate.
  • LinkSwarm for February 4, 2022

    Friday, February 4th, 2022

    The Carter-era “misery index” (inflation + unemployment) is rising, Canada’s truckers are still honking, more Democratic sleazebag activity, the far left is coming for your kids, China continues to misbehave, and a tragic cheese display collapse shocks onlookers. It’s the Friday LinkSwarm!

  • Biden continues to work his magic on the economy. Expected job numbers: +200,000. Actual job numbers: -300,000.

  • But! There are other stories stating that jobs numbers “beat” expectations. Why? Some super sketchy “seasonal” adjustments.

    Why the BLS is applying such a grotesque seasonal adjustment to it, is unclear (actually, if one assumes that the Biden admin tapped the BLS secretary on the shoulder, then it is very clear).

    It’s not just outside analysts who reach this conclusion: in Table C to its report, the BLS showed “December 2021-January 2022 changes in selected labor force measures, with adjustments for population control effects” and confirmed that if one had used an apples-to-apples basis for the January numbers, the number of Employed workers (from the Household Survey) would be down -272K. Instead, thanks to the population control effect adjustment of 1.471 million, the final number was 1.199 million!

    In summary, while the markets had been trading for months on fake data when the BLS failed to catch up to covid reality, and was applying stale seasonal adjustments, they are doing so again today, only in the opposite direction with the BLS now overextending itself in the opposite direction, with a January seasonal adjustment that has never been greater!

  • Inflation hit 5.8% in 2021, the most in 39 years. Pretty sure this year is going to be a lot worse.
  • How bad is inflation? Dwight sent over this link on an Austin restaurant shutting down that includes an eye-opening inflation tidbit. “He pointed out that a container of fryer oil that a year ago cost about $17 had risen to about $50.”
  • Canada’s freedom truckers seem to be making headway with regional governments, some of whom have promised to lift vaccine mandates, but asshole authoritarian Justin Trudeau is refusing to budge.
  • Video footage of a voting fraud mule making 53 trips among 20 ballot drop-boxes.
  • Regular BattleSwarm readers have already seen extensive evidence supporting the lab leak hypothesis for Flu Manchu, but National Review‘s Jim Geraghty has a new piece along those lines.

    There are two naturally occurring viruses that are par­ticularly similar to SARS-CoV-2. The first is RaTG13, which shares 96.2 percent of its genome with SARS-CoV-2, according to a paper released by the Wuhan Institute of Virology’s Shi Zhengli. This virus was collected from bat feces in a copper-mine shaft in Tongguan, Mojiang, Yunnan Province, China, that was the site of a small-scale deadly viral infection with some curious similarities to Covid.

    In April 2012, six miners were assigned to clean bat guano from the mine shaft. Four miners had been working at the site for two weeks, and two had been working there for four days when they all grew ill with a cough and fever and experienced difficulty breathing, aching limbs, heavy and bloody mucus and saliva, and headaches — symptoms of a viral respiratory infection that are similar to the effects of Covid. All six miners were admitted to a Kunming hospital in late April and early May, and three died — one after two weeks, one after a month and a half, and one after three months. The other three survived.

    Dr. Zhong Nanshan, a prominent Chinese pulmonolo­gist whose high-profile role has been compared to that of Dr. Anthony Fauci in the United States, consulted on the cases of the miners. Recognizing that the virus afflicting the miners could be comparable to SARS, researchers sent blood samples to the Wuhan Institute of Virology for antibody testing.

    In 2012 and 2013, teams of researchers from the Wuhan Institute of Virology conducted a study of coronaviruses in bats in that abandoned mine shaft — and one of the samples they collected was RaTG13.

    The second virus that is particularly similar to SARS-CoV-2 is really a cluster of three similar viruses discovered in Laos in autumn 2021. A team led by Marc Eliot, a virologist at the Pasteur Institute in Paris, collected saliva, feces, and urine samples from 645 bats in caves in northern Laos and found three new viruses that were each more than 95 percent identical to SARS-CoV-2, which they named BANAL-52, BANAL-103, and BANAL-236.

    Some skeptics of the lab-leak theory contend that the BANAL viruses proved that SARS-CoV-2 is likely a naturally occurring virus, and because Laos was roughly 1,000 miles from Wuhan, this pointed away from the notion that the Covid pandemic could be traced back to a leak from Wuhan Institute of Virology or any other labs in the city. But there is ample reason to believe that viruses from Laos — perhaps not the BANAL trio, but similar ones — were also shipped from Laos to the Wuhan Institute of Virology.

    In 2010, Wildlife Trust, a nonprofit international conservation organization dedicated to protecting wildlife, announced it was rebranding itself under the name EcoHealth Alliance. The organization’s president, Peter Daszak, declared that his group had become “the central organization defining the intersection of local conservation and global health” and touted itself as being “on the forefront of informing the public, businesses, and the scientific community about emerging diseases, including potential pandemics.” It is safe to say that EcoHealth Alliance is one of the largest, best funded, and best connected nonprofits, focusing upon “field research and develop[ing] tools to save ecosystems and predict and prevent pandemics.”

    EcoHealth Alliance/illegal gain of function section snipped.

    We know for a fact that the people collecting samples do not always follow the necessary safety procedures. And the risk of accidental infection does not disappear once the viruses and bats are brought back to the laboratories.

    Lab accidents happen. The first argument against the lab-leak theory that can be safely dismissed is the notion that Chinese scientists were simply too careful or too diligent to ever let a virus escape their lab. Accidents occur even in the most well-trained and highly regarded research facilities in the world. In June 2014, the U.S. Centers for Disease Control and Prevention determined that they had unintentionally exposed personnel to potentially viable anthrax. A month later, the U.S. Food and Drug Administration found samples of smallpox, dengue, and spotted fever just sitting in a storage room. A decade earlier, the Chinese CDC’s National Institute of Virology in southern Beijing had accidentally released SARS. Twice.

    In February 2019, Lynn Klotz, a senior science fellow at the Center for Arms Control and Non-Proliferation, laid out a report in Bulletin of the Atomic Scientists detailing that from 2009 to 2015, a federal program “received a total of 749 incident reports from select-agent research facilities,” including “1) needle sticks and other through the skin exposures from sharp objects, 2) dropped containers or spills/splashes of liquids containing pathogens, and 3) bites or scratches from infected animals.”

    China obviously places the same importance on lab safety as it puts into quality control. Lets pick it up where more CCP perfidy kicks in:

    Finally, there is the undeniably suspicious behavior of the Chinese government since the first cases were reported in Wuhan in December 2019. Until January 21, 2020, the Wuhan Regional Health Commission insisted that “no clear evidence of human-to-human transmission has been found.” On January 4, 2020, former CDC director Dr. Robert Redfield was incredulous during a phone call with his Chinese counterpart, George Gao. Redfield described asking his old friend Gao, “George, you don’t really believe that mother and father and daughter all got it from an animal at the same time, do ya?” Gao insisted there was no evidence of human-to-human transmission. But Redfield recounted that two days later, Gao broke down during a call, “audibly and tearfully distraught after finding ‘a lot of cases’ in the community who had never visited the wet market.”

    In late January and early February, the Chinese government ordered all labs processing samples of the strange new virus to destroy them. On January 3, China’s National Health Commission ordered institutions not to publish any information related to the unknown disease and ordered labs to transfer any samples they had to designated testing institutions, or to destroy them. The justification for this order was public safety, although it is hard to see the public-safety benefit in suppressing information about the disease.

    It took a year to get a World Health Organization investigative team into Wuhan, and when that team arrived, it encountered angry refusals to turn over raw data about the earliest cases. According to the New York Times, “disagreements over patient records and other issues were so tense that they sometimes erupted into shouts among the typically mild-mannered scientists on both sides.” The Chinese government has refused to allow another team of investigators to enter Wuhan or the labs in the city. The Chinese government does not care if it looks guilty.

    A much-hyped U.S. intelligence-community investigation completed in August offered almost nothing useful, declaring, “All agencies assess that two hypotheses are plausible: natural exposure to an infected animal and a laboratory-associated incident.” Ninety days of effort, with all the resources of the U.S. government, generated nothing new.

    To paraphrase Ebright, in the autumn of 2019, there were three institutions in the entire world that were doing gain-of-function research on novel coronaviruses found in bats. One was in Galveston, Texas, one was in Chapel Hill, N.C., and the third was in Wuhan, China.

    In theory, the pandemic could have started with some random Chinese person who didn’t have any connection to the bat coronavirus research conducted at the Wuhan Institute of Virology or the Wuhan CDC. This person would have a spectacularly unlucky run-in with a bat or other animal, and that random Chinese person caught the exceptionally rare naturally occurring animal virus that infects, sickens, and spreads among human beings like wildfire. This same hyper-contagious bat virus would have the exceptionally unusual trait of being ex­tremely difficult to find in bats.

    This extraordinarily unlucky person would then travel to the metaphorical doorstep of one of the three labs in the world doing gain-of-function research on novel coronaviruses found in bats and start infecting other people in the city of Wuhan. Under the natural-origin theory, the Wuhan laboratories just happen to be mind-bogglingly unlucky that events played out in a way that so closely mimics the consequences of a lab accident.

    That would be a remarkable series of coincidences.

    Read the whole thing.

  • Data point. “Younger, working-age people began dying in greater numbers as vaccine mandates hit.”
  • More data:

  • Cyber-attack China hack?
  • Also in China: The Genocide Olympics get underway.
  • “Youngkin Governs For Parents Who Say: Get Away From Our Kids, You Freaks.”

    Glenn Youngkin is governing Virginia according to the implicit campaign slogan that powered his victory: stop messing with our kids, you freaks! That’s the polite version, anyway. Other Republican officials should follow his lead and solidify the GOP as the party of parents.

    Youngkin ran as a conservative champion of normalcy, especially in schools. His campaign was assisted when his opponent declared parents should not have a say in what their children are taught, thereby confirming everything Youngkin was running on.

    Since being sworn in, Youngkin has banned school mask mandates, banned teaching racist ideas from sources such as critical race theory, and requested the new state attorney general, Jason Miyares, to investigate the apparent coverup by Loudoun County officials of a rape committed by a skirt-wearing boy in a girls’ bathroom. He has also started cleaning house in the bureaucracy.

    These measures have provoked pushback from the usual suspects. Left-wing teachers are now worried they’ll get in trouble for teaching the race essentialism derived from critical race theory. Some counties have defied the governor over school mask mandates, and are punishing students who choose not to wear them. But Youngkin is holding firm, knowing this is what he was elected to do.

    Across the nation, parents are in revolt against the Democrat-led educational establishment, and Republicans should eagerly join the fray. After all, it was the Democrat-loving teachers unions that fought to keep schools shut down long after we knew that children were at almost no risk from Covid-19. Likewise, it has mostly been Democrats and their allies forcing children to wear masks when school is open, even though (as a few on the left are finally admitting) masks are particularly harmful for children, while offering no real benefits.

    There are other indignities and cruelties, of course, from shutting down outdoor playgrounds to forcing schoolchildren to study or eat lunch outdoors in freezing temperatures. And these miseries have been inflicted long after any plausible ability to defend them as emergency measures, or to plead ignorance of the consequences. Under pressure from the teachers unions and education bureaucracy, Democrats have chosen to sacrifice the well-being of children. Even many liberals now want an alternative to the endless school shutdowns, masks, and other pandemic security theater.

  • Speaking of leftists trying to get their hands on your children: “BLM ‘Week of Action’ Teaching Students Nationwide to Affirm Transgenderism, Disrupt Nuclear Family.”

    Students across the country as young as kindergarten-age are learning that “everybody gets to choose their own gender” and are receiving kid-friendly lessons on disrupting “Western nuclear family dynamics” as part of this week’s national Black Lives Matter at School Week of Action.

    The activist-driven curriculum for the Week of Action, which kicked off Monday, is based off the 13 “Black Lives Matter Guiding Principles.” Those principles include a commitment to restorative justice, being transgender affirming and queer affirming, creating space for black families that is “free from patriarchal practices,” and “the disruption of Western nuclear family dynamics and a return to the ‘collective village’ that takes care of each other.”

    Black Lives Matter at School offers kid-friendly versions of the 13 principles designed for elementary and middle-school students.

    The Week of Action also includes a list of four national demands: end zero-tolerance discipline policies; mandate black history and ethnic studies; hire more black teachers; and fund counselors, not cops, according to a “starter kit” on the Black Lives Matter at School website.

    In the starter kit, New York City kindergarten teacher Laleña Garcia, author of a children’s book about BLM principles, writes that while “discussing big ideas with little people” it is necessary to “consider age-appropriate language so that our students or children can grasp the concepts.” For example, she suggests not talking about police violence with “our youngest children.”

    When discussing BLM’s principle of being transgender affirming, Garcia offers the following kid-friendly language: “Everybody has the right to choose their own gender by listening to their own heart and mind. Everyone gets to choose if they are a girl or a boy or both or neither or something else, and no one else gets to choose for them.”

    When discussing the BLM principle of a “Black Village,” which includes the goal of disrupting the Western nuclear family structure, Garcia suggests teaching kids that “there are lots of different kinds of families; what makes a family is that it’s people who take care of each other; those people might be related, or maybe they choose to be a family together and to take care of each other. Sometimes, when it’s a lot of families together, it can be called a village.”

  • Speaking of Democratic policies endangering kids: Repeat child sex offender illegal alien arrested at the border.
  • Now Twitter is kicking off accounts critical of teacher’s unions. Check out The Chalkboard Review.
  • Even in San Francisco, the backlash against the Soros-backed-Democrat-DA crime wave has begun: “S.F. police will no longer cooperate with DA Boudin over police shooting investigations.”

    San Francisco Police Chief Bill Scott said he intends to sever an agreement with the San Francisco District Attorney’s Office spelling out the D.A.’s lead role in investigating police use-of-force incidents, in-custody deaths and police shootings.

    The agreement was originally struck in 2019 following intense debate in San Francisco over the role the city’s police department should play in investigating its own officers following a rash of police shootings. Police and the District Attorney’s Office renewed the agreement last year.

  • Illinois Democratic Governor J.B. Pritzker gave $300,000 in federal Flu Manchu relief funds to #BlackLivesMatter.
  • Speaking of which, there’s more crooked Pritzker shenanigans.

    The more we learn about the Jenny Thornley affair, the more it appears that senior members of the Pritzker administration, including potentially the governor and his wife, may have facilitated a fraud on the state by a now-indicted former campaign aide to enrich her and then obstructed efforts to bring her to justice.

    This is a tangled web, so stay with me as I set forth a timeline of events and characters, according to the Chicago Tribune.

    The former executive director of the Illinois State Police Merit Board, Jack Garcia, discovered evidence that one of the employees under his direction, Jenny Thornley, was stealing money from the people of the state

    Garcia is a well-known, skilled investigator who previously supervised the divisions of internal investigations and forensic services, before becoming the first deputy director of the Illinois State Police. Thornley was a campaign aide for Gov. J.B. Pritzker (her husband, Jared, was also a senior political appointee at the Illinois comptroller’s office) and close enough to Pritzker and his wife, M.K., that she had their personal telephone numbers.

    After assembling the evidence and building the case, Garcia scheduled meetings to fire Thornley and refer her for prosecution on the morning of Feb. 3, 2020. However, on the eve of that day, Thornley contacted (at least) the governor’s wife (pictured, at left) and asked her to intervene, alleging that Garcia had assaulted her sexually a week or so earlier.

    The governor’s chief counsel promptly called the merit board (which is an independent agency created “to remove political influence” from State Police hiring, promotion and discipline) to “advise” it to: (a) cancel her firing and the referral for prosecution, (b) suspend Garcia (the experienced investigator who uncovered the Thornley fraud) and (c) retain an outside counsel proposed by the governor’s office. The merit board went along, but also suspended Thornley, and Garcia voluntarily took and passed a lie detector test.

    Then Thornley sued to stop the investigation of her own claim of sexual harassment.

    The outside counsel, Christina Egan, nonetheless completed an investigation by July 2020 (at the cost of $500,000 paid by the people of Illinois), confirming the evidence Garcia assembled that Thornley had stolen money and committed forgery, and finding no evidence of Thornley’s sexual assault allegation. The State Police Merit Board then reinstated Garcia, fired Thornley, referred her for prosecution. She has now been indicted for theft and forgery.

    However, after Thornley was fired, someone with clout in the Pritzker administration somehow granted her disability payments reserved for people that are actually state employees. These payments (amounting to some $71,000) went on for more than a year, ending days before she was indicted for theft and fraud. These extensive payments were for “injuries” sustained from an “assault” that Egan determined had not occurred.

  • Speaking of Democratic family corruption: “Smoking gun documents tie Nancy Pelosi’s son to fraud and bribery scheme to remove permit violations against squalid San Francisco flop house owned by his ex-girlfriend and probed by the FBI.”
  • Speaking of Pelosi corruption:

  • Speaking of crooked Democratic governors, Washington state’s Jay Inslee (he of the spectacular presidential race flameout) wants to criminalize voicing allegations of election fraud. “Shut up and do the will of the party, comrade!” (Hat tip: Stephen Green at Instapundit.)
  • But that’s not the only stupid idea he has! He also wants to drive out all the state’s billionaires with a wealth tax.
  • One swampy hand washes the other. “ATF Asks Judge to Order Hunter Biden Gun Inquiry Closed.”
  • Is national concealed carry coming?
  • “‘You Have Blood On Your Hands,’ Former Official Calls on Harris County Judge, Commissioners to Resign.”

    The criminal justice system in Harris County is broken,” said Aimee Castillo, sister of murder victim Josh Sandoval.

    Suspect Devan Kristopher Jordon was out on three felony bonds when he allegedly shot Sandoval during a home invasion robbery last May. Jordon had also missed a court date the week prior to the murder, but authorities did not issue an arrest warrant.

    “I think the criminal justice system is just a revolving door. They murder, they go in, and they come out, and they go in,” said Glenda Martin, Sandoval’s mother. “I think it’s a horrible thing.”

    Commissioner Tom Ramsey (R-Pct. 3) presented a resolution honoring Sandoval’s life and noted that the suspect was also affiliated with the same crime ring allegedly responsible for the murder in Houston of an off-duty New Orleans police officer last August.

    “There are people who are hurting people who are being allowed to walk around and they should not be period. That is the point,” intoned Commissioner Jack Cagle (R-Pct. 4).

    The fieriest moments of the meeting, however, came later from Steve Radack, former constable and former commissioner who said Democrats on the commissioners court had “blood on their hands.”

    “I never dreamed that after serving 32 years on this court that there would be three members of this court — Hidalgo, Garcia, and Ellis — who would kiss the rears of hardened criminals, who victimize law-abiding citizens, including law enforcement officers,” said Radack. “I’m calling on you three to resign from office so the healing can begin.”

  • Hmmm. “Two Texas inmates killed at Beaumont federal prison in fight involving MS-13.”
  • Speaking of criminal scumbags, Michael Avenatti was convicted of defrauding Storm Daniels of $300,000. This is, what, his fourth felony conviction?

  • On the “Washington Football Team”

  • Heh:

  • This is a pretty crazy IT hiring story. You’ll just have to read it…
  • Get a rope. “Tulsa police find stolen $300,000 1967 Ford Mustang Shelby stripped and hidden in field.” (Hat Tip: IowaHawk.)
  • The scam of New York City sidewalk sheds.
  • Heh:

  • Quel formage!

  • Minneapolis names some snowplows. I do rather like Ctrl Salt Delete…
  • “Joe Biden Beats Out Brussels Sprouts For America’s Least Favorite Vegetable.”
  • “I said all the frisbees!”

  • Log4J and Internet Castles Made of Sand

    Thursday, December 16th, 2021

    If you work outside of a tech company, chances are you’ve spent this week primarily concerned with getting ready for Christmas. If you work inside a tech company, there’s a significant chance your company spent much of this week patching a critical vulnerability in an open source Java logging library called Log4J.

    Here’s a non-technical explanation of the problem:

    It’s a vulnerability that was discovered in a piece of free, open source software called log4j. This software is used by thousands of websites and applications, to perform mundane functions most people don’t think about, such as logging information for use by that website’s developers, for debugging and other purposes.

    Every web application needs functionality like this, and as a result, the use of log4j is ubiquitous worldwide. Unfortunately, it turns out log4j has a previously undiscovered security vulnerability where data sent to it through that website — if it contains a special sequence of characters — results in log4j automatically fetching additional software from an external website and running it. If a cyberattacker exploits this, they can make the server that is running log4j run any software they want — including software that can completely take over that server. This is known as a Remote Code Execution (RCE) attack.

    To use a technical phrase, this is Really Bad.

    The net result is that, left unaddressed, cyberattackers right now can completely take over thousands of websites and online applications, allowing them to steal money, data, and access. The security community has been completely focused on this vulnerability for the past two days, and updating servers running log4j as quickly as possible to protect against this vulnerability.

    The good news is that mitigations are relatively easy to implement. The bad news is that left unmitigated, the vulnerability is extremely easy to exploit. iCloud, Minecraft, Baidu, and many other sites have been confirmed to be vulnerable so far, and you’ll likely hear more about many other sites being vulnerable in the coming days.

    And those companies are just the tip of the iceberg. LAMP stacks (Linux, Apache, MySQL, and PHP) are used as the technological underpinnings for a wide variety of web applications of all sizes. (It’s not universal, as NGINX has taken over as a market leader from Apache, and there are still a few all-Microsoft houses that use IIS, and neither of them have the vulnerability.)

    Open Source has been a revolutionary invention because it provides rapid development by armies of distributed developers, and Linus’s Law states that “with enough eyes, all bugs are shallow.” But there are tens of thousands of Open Source components out there running critical infrastructure that haven’t had nearly as many eyes on the code as the Linux kernel. It’s simply the nature of the beast. XKCD had a cartoon for this occasion:

    Internet applications gain usefulness from widespread adoption and the number of other components they tie into and support. You know what creates new vulnerabilities? A larger user base and the number of other components they tie into and support, which creates more attack surfaces for malicious actors to exploit.

    The flaw isn’t the fault of Random Guy in Nebraska, the fault is the company adopting software that they can’t possibly test for all the use-cases they’re going to use it for. Surprise! Just about every high tech company in the world is in the same boat. Pretty much everyone uses a wide panoply of open source tools for their Internet applications, and no one can test all the permutations of how each component might be put to use.

    You can’t eliminate the risk, you can only minimize and mitigate it. You can use containerization strategies (Docker, Kubernetes, Container D, etc.) to minimize attack surfaces and limit contagion. You can run all your code through security scanning tools on your CI/CD platform of choice. You can do constant testing and keep rolling backups of everything to limit risk and speed recovery. (You can also train your employees not to click on random email links without verifying the sender is who they say they are, and not to give any any account information or passwords over the phone, and train them enough so that the lessons stick, even though phising and human engineering weren’t factors in the Log4J vulnerability.)

    But there still a good chance that the platform you’re using today is different than the platform you’ll be using ten years from now, and you’ll have to go through the same learning lessons discovering new vulnerabilities for the new platform all over again.

    Castles made of sand all fall into the sea eventually…