Daniel Krivelevich

51 posts

Daniel Krivelevich

Daniel Krivelevich

@Dkrivelev

Entrepreneur, Investor, Advisor | 🇮🇱 | Co-Founder & CTO @ Cider Security

Beigetreten Eylül 2013
145 Folgt160 Follower
Daniel Krivelevich
Daniel Krivelevich@Dkrivelev·
Term Shit - כש- @YoavVilner ואני החלטנו להיכנס לעומק של הנושאים החשובים *באמת* באקוסיסטם של הטק בישראל. הסרטון המלא בתגובות.
עברית
4
3
21
6K
Daniel Krivelevich retweetet
Ehud Ben-Gera
Ehud Ben-Gera@EBGera·
1/13 כשאנחנו נאבקים על הזמנת רכב חדש או פלייסטיישן, התירוץ על ״בעיות בשרשרת האספקה״ נזרק לאויר. יזם סייבר שמע את התירוץ ורץ להקים חברה. הקרב העמוס על הגנת סייבר לשרשרת האספקה🥊
Ehud Ben-Gera tweet media
עברית
18
9
166
0
Daniel Krivelevich retweetet
Omer Gil
Omer Gil@omer_gil·
Playing with some PPE attack vectors in my CI/CD env 👀
English
0
2
11
0
Daniel Krivelevich retweetet
Clint Gibler
Clint Gibler@clintgibler·
⚠️ GitHub Org Identity Management Risks When not using SSO * User personal emails could be compromised * IdP removal does not remove from GH org Deactivating user in IdP prevents GitHub website auth- PATs & SSH keys still work @omer_gil @yaronavital cidersecurity.io/blog/research/…
English
0
6
21
0
Daniel Krivelevich retweetet
Clint Gibler
Clint Gibler@clintgibler·
🛡️ CI/CD Credential Hygiene @TupleType examines 3 common issues: 1. Unrotated static credentials 2. Overly accessible credentials 3. Credentials exposed in console logs And strengths/weaknesses of: * Jenkins * GitHub Actions * CircleCI * GitLab CI/CD cidersecurity.io/blog/research/…
English
0
10
22
0
Daniel Krivelevich retweetet
Mark Manning
Mark Manning@antitree·
This doesn't push my agenda of hating on Jankins but it's a good in-depth analysis of a few CI tools and how they handle creds. cidersecurity.io/blog/research/…
English
3
8
24
0
Daniel Krivelevich retweetet
Omer Gil
Omer Gil@omer_gil·
Great blog post by @TupleType about credential hygiene risks in engineering environments, with comparison of the different security solutions offered by the main vendors - GitHub Actions, CircleCI, Jenkins and GitLab CI/CD. cidersecurity.io/blog/research/…
English
0
1
3
0
Daniel Krivelevich retweetet
Hiroki (rung) SUEZAWA
I re-read CI/CD top10, I would like to introduce their new term. It's the PBAC(Pipeline-Based Access Controls). Source code management like GitHub and CI/CD has different security aspects to each branch and step. [🧵1/2] cidersecurity.io/top-10-cicd-se… #Top10CICD
English
1
7
22
0
Daniel Krivelevich
Daniel Krivelevich@Dkrivelev·
Looking forward to some fruitful followup collaborations with the industry on this #Top10CICD
English
0
0
0
0
Daniel Krivelevich retweetet
Clint Gibler
Clint Gibler@clintgibler·
🗡️ Exploiting Jenkins build authorization Jenkins default settings assign every build to “run as SYSTEM" 😱 To harden, use the “Authorize Project” and “Role-Based Authorization Strategy” plugins By @TupleType medium.com/cider-sec/expl…
English
1
11
31
0
Daniel Krivelevich retweetet
Asi Greenholts
Asi Greenholts@TupleType·
Exploiting Jenkins build authorization. A default configuration we often see unchanged in production environments causes all jobs to run with the highest privileges medium.com/cider-sec/expl…
English
0
4
9
0