Daily Shaarli
December 16, 2021
A newfound species of millipede has more legs than any other creature on the planet — a mind-boggling 1,300 of them. The leggy critters live deep below Earth's surface and are the only known millipedes to live up to their name.
Work has been completed on the largest battery energy storage system (BESS) to have been paired with solar PV to date, with utility Florida Power & Light (FPL) holding a ceremony earlier this week.
Construction on the Manatee Energy Storage Center in Florida’s Manatee County was completed in just 10 months, having begun in February this year. The 409MW / 900MWh BESS is colocated with FPL’s existing 74.5MW Manatee Solar Energy Center ground-mounted PV plant.
Allowing solar energy to be used in evenings and at night or on cloudy days, the utility company — a subsidiary of electric utility holding company NextEra Energy — has placed 132 battery containers onto a 40-acre plot of land.
The BESS will charge at off-peak times with abundant solar energy and then discharge to the local grid at peak times, when power is most expensive and often at its most carbon intensive.
It will reduce the runtime of local fossil fuel power plants and will aid FPL in a plan to ease two 1970s-era natural gas power plants totalling more than 1,600MWh into retirement.
Tinker
@TinkerSec
A lot of folks think that this "patching" is "4D Chess" but it's really a basic behavior in a turf war.
The "turf" is your systems.
And you are not part of this "war".
I'll run through how it works and why unauthorized hackers do this as a standard TTP...
If you run a scan on your environment to see if you're patched for #log4j...
...and find that you are already patched.
Make sure you were the one that patched it.
Say I'm a mid level, decently skilled hacker.
I'm not a script kiddie. I have some experience. But, I'm not part of some nation state group or anything like that.
I just have a small bot net that I need to grow.
I see a major vuln w/a simple exploit like this #Log4J!
Awesome!
So I scan for vulnerable systems, find one, and hack into it.
But I find someone else is here!
This is normal. #Log4J is a hot topic right now. Everyone and their cat is hacking the internet.
What to do? I don't want this other hacker here.
I want this system to myself.
So I lay down a backdoor. Maybe a simple user account with root privileges accessible via SSH or maybe a backdoor implant that I have ready built.
I kick out the other hacker. Maybe by killing his connection process or system firewalling his IP.
Then...
Then... to make sure that hacker doesn't come back and to make sure that no other groups come in behind me by using the same #Log4J vulnerability that I used...
I patch the system.
I'm not patching the system to hide from sysadmins or to remove the system from some corporate patch management program.
I'm just covering my ass.
I'm just protecting my new found asset from other hackers.
This is my botnet now, so I need to maintain information security.
Tinker
@TinkerSec
·
13h
Alright, I'm officially over #Log4J.
Not saying anything in my org is patched.
Just saying I'm done worrying about it & am moving on w/my life.
Y'all need to stop living in fear.
Just accept that exploits happen & if it's your company's time to be breached, it's their time.
Craig Wright, an Australian computer scientist who claims to be Satoshi Nakamoto, the inventor of Bitcoin, has been cleared of six out of seven civil charges during a trial in a Miami court on Dec. 7 that put him up against the estate of his deceased business partner.
Trial and claims: The plaintiff of the civil court case declared that Wright and David Kleiman, a computer forensics expert and Wright’s friend, pre-mined 1.1 million bitcoin together (worth $54 billion), fueling an argument over whether Wright owed half of his assets to Kleiman’s family.
Instead of trying to make the aircraft long and mostly cylindrical like most commercial and business jets, the 500L comes in an unusual teardrop form. With a fairly fat and blunt nose and a pointy tail, the fuselage comes out to a nearly perfect aerodynamic shape. With sharp wings and tail, landing gear that folds away cleanly inside the plane’s shape, and even the engine tucked neatly away, the plane cuts through the sky a lot more easily than other planes.
While not mentioned on Otto’s website, it appears that even the propeller is helping minimize drag. By pulling air from where the teardrop shape comes together in the rear, the propeller may even be sucking on the boundary layer like an experimental NASA design I’ve written about before, helping further reduce drag.
The air intakes for the engine, on the other hand, are spaced out from the skin of the teardrop a bit, likely because boundary layers are very unpredictable sources of air for a combustion engine, whether it’s a turbine or a piston engine. //
To take better advantage of this aerodynamically clean design, Otto Aviation chose to use RED Aircraft GmbH’s AO3 engine. Like a jet engine, it runs on Jet-A fuel (basically kerosene), but it’s a turbocharged 12-cylinder piston engine. This helps reduce operation costs, as Jet-A’s economics of scale makes it cheaper to purchase and it’s more widely available. Like a jet, it’s also capable of operating at up to Flight Level 500, or 50,000 feet above sea level. But, despite similar performance, it’s designed to use only 50% of the fuel of a comparable jet engine.
During routine maintenance, Electricite de France (OTCPK:ECIFF) ("EDF") found pipe defects on the safety injection systems for two nuclear facilities; both are shut down awaiting repair.
Two additional reactors, using the same technology, will be shut down briefly later this month for inspection. //
With yet another source of energy offline, European natural gas for January delivery continues its relentless march higher; prices now reaching $44 / mmbtu, Europeans will pay 900% more for natural gas in January 2022 than January 2021.
In the US, where natural gas prices have risen almost 50% year over year, consumers are paying less than $4 / mmbtu. //
French month ahead electricity prices for January have risen to ~$620 / mwh on the back of the EDF news, compared to average power prices in the US at ~$100 / mwh.
A preliminary study made public Wednesday studied blood samples in the lab from 30 people who had gotten two Moderna shots, and it found that the antibodies in their blood are at least about 50 times less effective at neutralizing the omicron variant of the coronavirus.
Previous research had indicated the Pfizer-BioNTech vaccine is also less protective against omicron. //
But there was good news too. An additional 17 people in the study had received a Moderna booster. And the antibodies in their blood were highly effective at blocking the omicron variant — essentially about as effective as they are at blocking the delta variant, Montefiori says.
“The HSE assessed its cybersecurity maturity rating as low,” PWC wrote. “For example, they do not have a CISO or a Security Operations Center established.”
PWC also estimates that efforts to build up the HSE’s cybersecurity program to the point where it can rapidly detect and respond to intrusions are likely to cost “a multiple of the HSE’s current capital and operation expenditure in these areas over several years.” //
“The term ‘Security Maturity’ refers to the street smarts of an individual or organization, and this maturity generally comes from making plenty of mistakes, getting hacked a lot, and hopefully learning from each incident, measuring response times, and improving.
Let me say up front that all organizations get hacked. Even ones that are doing everything right from a security perspective get hacked probably every day if they’re big enough. By hacked I mean someone within the organization falls for a phishing scam, or clicks a malicious link and downloads malware. Because let’s face it, it only takes one screw up for the hackers to get a foothold in the network.
Now this is in itself isn’t bad. Unless you don’t have the capability to detect it and respond quickly. And if you can’t do that, you run the serious risk of having a small incident metastasize into a much larger problem.
Think of it like the medical concept of the ‘Golden Hour:’ That short window of time directly following a traumatic injury like a stroke or heart attack in which life-saving medicine and attention is likely to be most effective. The same concept holds true in cybersecurity, and it’s exactly why so many organizations these days are placing more of their resources into incident response, instead of just prevention.”