c0rdis

571 posts

c0rdis banner
c0rdis

c0rdis

@c0rdis

ШΔΠDΣRΣR

가입일 Mayıs 2010
543 팔로잉325 팔로워
c0rdis 리트윗함
Zuk
Zuk@ihackbanme·
The recent WhatsApp accounts takeover is simple and genius. This is how it works: You're sleeping. A "hacker" tries to login to your account via WhatsApp. You get a text message with a pincode that says "Do not share this". You don't share it, yet you still get hacked. How?
English
109
1.9K
4.7K
1.3M
c0rdis 리트윗함
Ming Zhao
Ming Zhao@FabiusMercurius·
🕸️Inside the Ransomware Economy🕸️ Ryuk is the biggest Saas unicorn u've never heard of. $150M ARR. 3 yrs old. Maybe it’s taboo to learn business strategy from a cybergang. But the ransomware industry-- from supply chain operations to market microstructures-- is truly genius. 👇
Ming Zhao tweet media
English
20
351
902
0
c0rdis 리트윗함
Rami (drunkrhin0)
Rami (drunkrhin0)@drunkrhin0·
Want to learn about GraphQL hacking? A thread ⬇⬇⬇ (1/10)
English
16
321
880
0
c0rdis 리트윗함
𝚊𝚕𝚔𝚊𝚕𝚒
𝚊𝚕𝚔𝚊𝚕𝚒@alkalinesec·
IoT device browser doesn't let you enter file:///? Use view-source:file:///. It works 80% of the time, every time
𝚊𝚕𝚔𝚊𝚕𝚒 tweet media
English
46
1.1K
5.3K
0
c0rdis 리트윗함
Jake Williams
Jake Williams@MalwareJake·
Scenario: Your CEO is worried about supply chain security and tells you to implement a program to "stop us from being hit with another SolarWinds." What *specifically* do you do to secure your software supply chain? Please RT for reach. I'm interested in diverse opinions.
English
222
467
938
0
c0rdis 리트윗함
Sarah Jamie Lewis
Sarah Jamie Lewis@SarahJamieLewis·
I'm not that great a chess player, but a pretty good hacker...so after watching The Queen's Gambit I of course put my skills to great use and found a board setup I could give to a chess engine to have it segfault when it tries to search for the next best move... take that
Sarah Jamie Lewis tweet media
English
33
290
2K
0
c0rdis 리트윗함
Phil Venables
Phil Venables@philvenables·
Security Budgets - Supply and Demand Thinking Think of budgeting as a supply & demand problem. Work both sides to make it a risk management exercise. It will bring clarity of thought and illustrates to your business that you are thinking commercially. bit.ly/3joAqlp
Phil Venables tweet media
English
3
6
23
0
c0rdis 리트윗함
💻 Sherrod DeGrippo
💻 Sherrod DeGrippo@sherrod_im·
If you don't embrace absurdity, infosec might not be for you.
English
26
98
604
0
c0rdis 리트윗함
Jon Hencinski
Jon Hencinski@jhencinski·
We chased an attacker in #AWS and want to share the story. Our blog covers: 🔍 Initial lead w/ #CloudTrail 🕵️ Investigative approach 🤖 Use of orchestration "robots" to respond faster ✅ Steps to improve ☁️ #Mitre ATT&CK Cloud Tactics? 👍 Those too! expel.io/blog/finding-e…
Jon Hencinski@jhencinski

Highlights from chasing an attacker in #AWS this week: Initial lead: custom alert using #CloudTrail - SSH keygen from weird source IP enrichment helped Historical context for IAM user, "this isn't normal" #GuardDuty was not initial lead - Did have LOW sev high vol alerts

English
4
95
328
0